Syntic

Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.

Regulatory & QualityFree Safe

quality-manager-qms-iso13485

Security Scan Summary

Status: Safe

Source: Syntic Skills registry

Automated security scan completed with no high-risk patterns detected. Manual review is still required.

About This Skill

Use when working with medical device quality systems: preparing for ISO 13485 audits, managing regulatory compliance documentation, setting up corrective actions, or audit preparation.

Downloadable SKILL.md

Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.

SKILL.md
---
name: quality-manager-qms-iso13485
description: Use when working with medical device quality systems: preparing for ISO 13485 audits, managing regulatory compliance documentation, setting up corrective actions, or audit preparation.
category: Regulatory & Quality
version: 1.0.0
tools: []
---

# Quality Manager - QMS ISO 13485 Specialist

ISO 13485:2016 Quality Management System implementation, maintenance, and certification support for medical device organizations.

## QMS Implementation

1. Conduct a gap analysis against ISO 13485:2016 requirements — document current state vs. required state for each clause using a Gap Analysis Matrix (clause, current state, gap, priority, action).
2. Prioritize gaps by regulatory criticality, risk to product safety, and resource requirements.
3. Develop an implementation roadmap with milestones.
4. Establish the Quality Manual per Clause 4.2.2: QMS scope with justified exclusions, process interactions, procedure references.
5. Create required documented procedures (see Mandatory Documented Procedures below).
6. Deploy processes with training.
7. Validate: gap analysis complete; Quality Manual approved; all required procedures documented and trained.

**QMS document structure**: Level 1 Quality Manual (e.g. QM-001); Level 2 Procedures (e.g. SOP-02-001); Level 3 Work Instructions (e.g. WI-06-012); Level 4 Records (e.g. training records).

## Document Control (Clause 4.2.3)

Number new/revised documents `[TYPE]-[AREA]-[SEQUENCE]-[REV]` (e.g. `SOP-02-001-01`), draft from an approved template, route to subject matter experts for review, resolve comments, obtain required approvals, and update the Document Master List. Validate: correct numbering; all reviewers signed; Master List updated.

**Type prefixes and approval authority**: QM = Quality Manual (Management Rep + CEO); POL = Policy (Department Head + QA); SOP = Procedure (Process Owner + QA); WI = Work Instruction (Supervisor + QA); TF = Template/Form (Process Owner); SPEC = Specification (Engineering + QA).

**Area codes**: 01 Quality Management, 02 Document Control, 03 Training, 04 Design, 05 Purchasing, 06 Production, 07 Quality Control, 08 CAPA.

**Change control**: Administrative (Document Control — typos, formatting); Minor (Process Owner + QA — clarifications); Major (full review cycle — process changes); Emergency (expedited + retrospective — safety issues).

**Review schedule**: Quality Manual and Procedures — annual (unscheduled on organizational change, audit finding, or regulation change); Work Instructions and Forms — 2 years (unscheduled on process change or user feedback).

## Internal Audit (Clause 8.2.4)

**Annual program**: identify processes/areas requiring coverage; weight audit frequency by risk factors (previous findings, regulatory changes, process changes, complaint trends); assign qualified, independent auditors; build and get management approval for the schedule; communicate to process owners; track completion. Validate: all processes covered; auditors qualified and independent; schedule approved. Cover clauses such as Document Control (4.2.3/4.2.4), Management Review (5.6), Design Control (7.3), Production (7.5), and CAPA (8.5.2/8.5.3).

**Individual audit execution**: prepare a plan with scope, criteria, and schedule; notify the auditee at least 1 week prior; review procedures and prior results; prepare a checklist; hold an opening meeting; collect evidence via document review, record sampling, process observation, and interviews; classify findings; hold a closing meeting; issue the audit report within 5 business days.

**Auditor qualification**: ISO 13485 awareness + auditor training; minimum 1 audit as observer; independent of the area audited; competent in the audited process.

**Finding classification**: Major NC — absence or breakdown of the system, or regulatory violation (30 days for CAPA); Minor NC — single lapse or deviation (60 days for CAPA); Observation — risk of future NC (track at next audit).

## Process Validation Protocol (Clause 7.5.6)

Validate special processes whose output cannot be verified by inspection, where deficiencies appear only in use (e.g. sterilization, welding, sealing, software):

1. Form a validation team of subject matter experts.
2. Write a validation protocol: process description and parameters, equipment and materials, acceptance criteria, statistical approach.
3. Execute IQ — verify equipment installed correctly, document specifications.
4. Execute OQ — test parameter ranges, verify process control.
5. Execute PQ — run production conditions, verify output meets requirements.
6. Write a validation report with conclusions.
7. Validate: IQ/OQ/PQ complete; acceptance criteria met; report approved.

**Revalidation triggers**: equipment change (assess impact, revalidate affected phases); parameter change (OQ + PQ minimum); material change (assess impact, PQ minimum); process failure (full revalidation); periodic (typically every 3 years).

**Special process examples and critical parameters**: EO Sterilization (ISO 11135 — temperature, humidity, EO concentration, time); Steam Sterilization (ISO 17665 — temperature, pressure, time); Radiation Sterilization (ISO 11137 — dose, dose uniformity); Sealing (internal — temperature, pressure, dwell time); Welding (ISO 11607 — heat, pressure, speed).

## Supplier Qualification (Clause 7.4)

1. Categorize the supplier: A — Critical (affects safety/performance); B — Major (affects quality); C — Minor (indirect impact).
2. Request quality certifications, product specifications, quality history.
3. Evaluate on quality system, technical capability, quality history, financial stability.
4. For Category A: conduct an on-site audit and require a quality agreement.
5. Calculate a qualification score and decide: >80 Approved; 60-80 Conditional approval; <60 Not approved.
6. Add to the Approved Supplier List.

**Evaluation weighting**: Quality System 30% (ISO 13485=30, ISO 9001=20, documented=10, none=0); Quality History 25% (reject rate <1%=25, 1-3%=15, >3%=0); Delivery 20% (on-time >95%=20, 90-95%=10, <90%=0); Technical Capability 15% (exceeds=15, meets=10, marginal=5); Financial Stability 10% (strong=10, adequate=5, questionable=0).

**Category requirements**: A — on-site audit, annual review, quality agreement; B — questionnaire, semi-annual review, quality requirements; C — assessment, issue-based, standard terms.

**Performance metrics**: Accept Rate target >98% (accepted lots / total lots × 100); On-Time Delivery target >95%; Response Time target <5 days; Documentation target 100% complete CoCs.

## Management Review Inputs (Clause 5.6.2)

Audit results (QA Manager); customer feedback — complaints, surveys (Customer Quality); process performance metrics (Process Owners); product conformity — inspection data, NCs (QC Manager); CAPA status (CAPA Officer); previous review actions (QMR); changes affecting the Quality Management System — regulatory, organizational (RA Manager); recommendations (all managers).

## Record Retention

> **QMSR transition (effective 2026-02-02)**: FDA's Quality Management System Regulation (QMSR) final rule (89 FR 7496) amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference and removed the legacy QSR subsection structure. Section numbers below (820.30/.181/.184/.198) no longer exist in the CFR — retained only as a familiar index. Current authority is **ISO 13485:2016 §4.2.5** (retain "for at least the lifetime of the medical device as defined by the organization, but not less than two years"), with additions in retained 21 CFR 820.35. Cite the ISO 13485 clauses, not the 820.x numbers, in current documentation.

| Record Type | Minimum Retention | Current authority (legacy QSR shown for index) |
|-------------|-------------------|------------------|
| Device Master Record | Life of device + 2 years | ISO 13485 §4.2.3/§4.2.5 (legacy 820.181) |
| Device History Record | Life of device + 2 years | ISO 13485 §4.2.5 + 21 CFR 820.35 (legacy 820.184) |
| Design History File | Life of device + 2 years | ISO 13485 §7.3.10/§4.2.5 (legacy 820.30) |
| Complaint Records | Life of device + 2 years | ISO 13485 §8.2.2/§4.2.5 + 21 CFR 820.35(b) (legacy 820.198) |
| Training Records | Employment + 3 years | Best practice |
| Audit Records | 7 years | Best practice |
| CAPA Records | 7 years | Best practice |
| Calibration Records | Equipment life + 2 years | Best practice |

> **Decision discipline**: these checklists and workflows structure Quality System conformity assessment — they do not certify ISO 13485 / QMSR compliance. Final compliance determinations and record-retention decisions are yours to make and must be reviewed and signed off by the named QMR; route FDA-specific regulatory-classification questions to Regulatory Affairs and confirm current 21 CFR 820 / ISO 13485:2016 text at fda.gov before relying on any citation here.

## Decision Frameworks

**Permissible exclusions (Clause 4.2.2)** require justification: 6.4.2 Contamination control (product not affected); 7.3 Design and development (organization does not design products); 7.5.2 Product cleanliness (no requirements); 7.5.3 Installation (none); 7.5.4 Servicing (none); 7.5.5 Sterile products (none).

**Nonconformity disposition**: if nonconforming product can be reworked, rework and re-inspect against acceptance criteria; if not, evaluate for use-as-is (with risk/regulatory justification), scrap, or return-to-supplier, and route product-release decisions to the Material Review Board (MRB).

Bundle Download

Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.

Install Targets

Syntic App

  1. 1. Create a dedicated folder for this skill in your local skills library.
  2. 2. Place SKILL.md into that folder.
  3. 3. Restart Syntic and invoke this skill on matching tasks.

Syntic Code (CLI)

  1. 1. Save SKILL.md in your local Syntic Code skills directory.
  2. 2. Keep related files in the same skill folder.
  3. 3. Run in a safe environment and validate outputs.

Source

https://github.com/alirezarezvani/claude-skills/blob/main/ra-qm-team/skills/quality-manager-qms-iso13485/SKILL.md

Open Source Link
Regulatory & Quality

Related Skills