731 901 601
Key requirements of ISO 13485 – what sets it apart from ISO 9001?

Key requirements of ISO 13485 – what sets it apart from ISO 9001?

Companies holding ISO 9001 certification that are entering the medical devices sector or expanding their operations into this sector often assume that ISO 13485 certification will simply complement their existing system. The reality is more complex – ISO 13485 is not an extension of ISO 9001, but a separate standard with a different philosophy and specific requirements not found in the quality standard for other industries.

A different philosophy – effectiveness rather than continuous improvement

The most significant difference between ISO 13485 and ISO 9001 is philosophical rather than technical. ISO 9001 is built around the concept of continuous improvement – an organisation is expected to constantly improve its quality management system and performance. ISO 13485 replaces this concept with a requirement to maintain the effectiveness of the system – the priority is to ensure consistent compliance with regulatory requirements and product safety, rather than constantly changing processes. In the medical devices industry, too frequent changes to processes can pose a risk to patients – hence the standard emphasises stability and predictability rather than innovation.

The second fundamental difference is the role of regulatory requirements. ISO 9001 treats legal requirements as one of the contextual factors influencing the system. ISO 13485 makes them a central element – the full title of the standard is ‘Requirements for regulatory purposes’, reflecting the fact that the quality management system must be built around compliance with applicable medical device regulations, rather than merely taking them into account.

A different philosophy – effectiveness rather than continuous improvement

The third difference concerns risk management. In ISO 9001, risk management is a general requirement, integrated into the system’s planning. In ISO 13485, risk management in accordance with ISO 14971 is a specific requirement, applicable at every stage of the product lifecycle – from design, through production, to post-market surveillance. The risk management plan, risk assessment, risk reduction plan and monitoring of residual risk must be documented and linked to the product documentation.

Specific requirements of ISO 13485 – what is not included in ISO 9001

Process validation. ISO 13485 requires the validation of all manufacturing processes whose results cannot be fully verified by subsequent inspection or testing of the finished product. In practice, this applies to sterilisation, welding, bonding, lamination, aseptic processes and many others. Validation must include installation qualification (IQ), operational qualification (OQ) and process qualification (PQ), and the results must be documented and verified following any significant change to the process or equipment.

Requirements concerning the manufacturing environment and cleanliness. For medical devices requiring controlled manufacturing conditions (cleanrooms, particle control, microbiological control), the standard requires documented environmental requirements, regular measurements and procedures for dealing with deviations. These requirements are particularly extensive for sterile devices.

Control of non-conforming products. The requirements of ISO 13485 in this regard are considerably more detailed than those of ISO 9001. Every non-conforming product must be identified, documented, assessed for risk and subjected to a specific procedure. If a non-conforming product has already been supplied to a customer, the procedure must include an assessment of whether customers and regulatory authorities need to be notified, and whether the product should be recalled.

Traceability. The standard requires the ability to trace the history, use and location of every medical device – down to the components, raw materials and manufacturing conditions for each batch. The traceability requirements in ISO 13485 are significantly more stringent than those in ISO 9001 and are linked to the MDR requirements concerning the UDI (Unique Device Identifier).

Post-market surveillance (PMS). ISO 13485 requires that the quality management system include the collection and analysis of data relating to the device after it has been placed on the market – complaints, adverse events and market signals. The results of this analysis must be taken into account when updating the risk assessment and risk management plan. This is directly linked to the MDR requirements concerning the PMS and PMCF (Post-Market Clinical Follow-up) systems.

Documentation – stricter requirements than in ISO 9001

Documentation under ISO 13485 is subject to significantly stricter requirements than those set out in the quality standard for other sectors. The standard requires a Device History Record (DHR) to be maintained for every unit or batch produced, containing comprehensive information on the manufacturing process, the materials used and the results of inspections. In addition, technical documentation for the device is required, covering specifications, drawings, validation results and risk assessment.

Particular emphasis is placed on change control – any change to the product design, manufacturing process, raw materials or suppliers must undergo a documented assessment of its impact on the safety and effectiveness of the product and, depending on the results of this assessment, may require revalidation, an update to the technical documentation or notification to the notified body. This is one of the areas where companies transitioning from ISO 9001 to ISO 13485 most frequently encounter difficulties – existing change management procedures are usually too simplistic for the requirements of the medical industry.

Read other posts

Changes to the International Feed Transport Database (IDTF)

Changes to the International Feed Transport Database (IDTF)

The International Feed Transport Database (IDTF) in feed transport in accordance with GMP Plus. read more
Food safety in transport and warehousing – requirements of the IFS Logistics standard

Food safety in transport and warehousing – requirements of the IFS Logistics standard

A food manufacturer may hold IFS Food certification and manage safety at its facility to the highest standards – but if the logistics company handling its deliveries does not meet the relevant requirements, product safety comes to an end at the exit gate. read more
What does your company really gain by implementing FSSC 22000 v7?

What does your company really gain by implementing FSSC 22000 v7?

A new version of the standard always means a bit of extra work. Documents to update, training to conduct, audits to schedule. read more
More posts