MSs ISO Procedure Templates and Guides

ISO 13485 Document and Records Control Procedure Template and Guide

$149

A complete, working document and records control procedure, written as a filled-in worked example rather than a hollow outline. Editable Word file, 35–55 pages, with a change notice, a register, a desk-level work instruction, and the full maturity ladder.

A complete, working ISO 13485 document and records control procedure — not an outline with blanks. Fifty-two pages covering Clause 4.2.4 and Clause 4.2.5 as the two separate requirements they are. Every section is written out, every decision is made and explained, and the only things left for you are the values that are genuinely yours to set.

Written for device organizations as a filled-in worked example, not adapted from a quality base. That distinction matters more here than anywhere else in ISO 13485, because the requirements that go missing are the ones a quality procedure has no reason to contain.

52

pages, editable Word

31

clauses cross-referenced

26

MSI notes in the margin

4

appendices, every one usable

Since 2 February 2026, this is a regulatory document. The FDA Quality Management System Regulation incorporates ISO 13485:2016 by reference into 21 CFR Part 820. For US-marketed devices your document and record controls are the operative form of a federal requirement, and the records they govern are inspectable.

Three things device document control procedures routinely omit

01

Two retention clocks, not one

ISO 13485 sets one period for obsolete documents and a different period for records, both derived from the lifetime of the device as you define it in the medical device file. Most procedures carry a single flat period. And if that device lifetime has never been written down, neither clock can be calculated — which means both are being guessed, and nobody in the organization knows it.

02

Record content specified by regulation, not by the standard

The standard is silent on what certain records must contain. 21 CFR 820.35 is not. Complaints, servicing, unique device identification and labeling release all carry required data elements that no clause checklist points at, which is exactly why they are missing from so many device quality systems. This procedure builds the required elements into named form fields rather than leaving them to a reminder.

03

The medical device file and the design and development file

Both are required documented information with no ISO 9001 equivalent. Both are collections rather than documents, and both are routinely held outside Quality by the people who create them — which is how they end up outside document control entirely. Section 6 brings their indexes inside it as controlled objects, so completeness is demonstrable rather than assumed.

What’s included

  • The complete Clause 4.2.4 and 4.2.5 procedure — sixteen numbered sections, editable Microsoft Word
  • A channel-enumerated trigger covering every route a document can be initiated by, including the request made verbally to a supervisor
  • One accountable owner, with a named alternate for every gating role
  • Approval and release treated as two acts, not one — with the release point defined in a single sentence
  • Two retention clocks, both derived from the device lifetime you define, with the basis stated
  • Regulatory record content from 21 CFR 820.35 built into the forms themselves
  • Confidential health information protection and the permissive confidentiality marking
  • Electronic record and signature controls, including validation before use and after change
  • A records table with no blanks — location, owning role, retention period and basis, for every record
  • External document control with named detection arrangements, not a list that nobody watches
  • A bounded emergency route — named authorizer, stated reason, expiry date, log
  • A process interaction map naming every boundary this process crosses — including the regulatory reporting, vigilance and traceability interfaces — and the failure produced when each is left undefined
  • A maturity ladder — eight elements, four levels each, described as observable behavior
  • Key performance indicators with target, measurement method, owner and reporting route
  • A full clause cross-reference mapping 31 clause references across both the standard and the regulation
  • Appendix A — Document and Record Change Notice, built to function as the release gate
  • Appendix B — Master Documented Information Register
  • Appendix C — Work Instruction with a worked example
  • Appendix D — a decision record naming every point where this procedure resolves a divergence, and what the alternative was

Every appendix, form and worked example is part of the document. Nothing is sold separately.

Why this is not a template pack

Most procedure templates restate the clause. “Documented information shall be reviewed and approved for suitability and adequacy” is an assertion, not a mechanism — it repeats what the standard already told you and leaves the decisions to you. This procedure makes the decisions and shows its reasoning.

It is built to seven marks: a real trigger, one accountable owner, stated decision criteria rather than intentions, records produced as a byproduct of the work, a defined exception path, trainable in one sitting, and a built-in review trigger that fires on events rather than on the calendar.

Who it’s for

Quality and regulatory managers at device manufacturers, contract manufacturers and specification developers — certified to ISO 13485, pursuing certification, or running a device quality system to the standard without holding a certificate. Particularly useful where the existing procedure was adapted from an ISO 9001 base, which is where the regulatory record content and the two retention clocks usually go missing.

Not sure yet? The free Document and Records Control Maturity Check scores your process across eight elements in about six minutes, with a device path that adds the requirements having no ISO 9001 equivalent. Your score appears without entering anything.

Preparing for an FDA inspection or a notified body audit?

MSI’s QMS Interviews course prepares your team for the questions they will actually be asked. This matters more since QMSR took effect — the records this procedure governs are now inspectable, and the people who create them are the people who will be asked about them.

QMS Interviews courseFree Maturity Check

Questions

Is this a template or a finished procedure?

Both, deliberately. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set. You are editing a working document rather than filling in a hollow outline.

Why not just adapt an ISO 9001 procedure?

Because the clause numbers do not map and the obligations differ. ISO 13485 predates the harmonized ten-clause structure, splits documents and records into two separate clauses, sets two retention clocks rather than one, and carries record content requirements that come from regulation rather than from the standard. Adapting a quality procedure is how those requirements go missing in the first place.

Does it address the QMSR?

Yes. The procedure is written on the basis that ISO 13485:2016 is incorporated by reference into 21 CFR Part 820, and the cross-reference maps obligations across both the standard and the regulation rather than treating the regulation as an afterthought.

What if we have not defined our device lifetime?

Then neither retention clock can be calculated, and the procedure says so directly rather than letting you paste in a default. Section 8 names the decision, explains what it drives, and points at where it belongs. It is a short conversation to have once and an expensive one to discover during an inspection.

What format is it?

Editable Microsoft Word (.docx). Adapt it, rebrand it, and adopt it into your own document control system. The license permits the buying organization to use it across its own sites and issue it to employees, contractors and auditors, and permits consultants to adapt it for engagements they deliver.

Do we need to be certified to use this?

No. Nothing in this procedure assumes a certificate. An organization running a device quality system to ISO 13485 because a customer requires it, because a regulator requires it, or because it is the sensible way to work, uses it exactly the same way.

Will this pass an inspection?

A procedure does not pass an inspection; an organization does. What this gives you is a procedure that addresses every requirement of both clauses with a named owner and a named record, and a records inventory with no blanks in it. Conformity is demonstrated by implementation and evidence. Unfilled placeholders are unmet requirements, so fill them.

Do I get updates?

The file you download is the current revision at the time of purchase, and it carries MSI’s revision and effective date in the footer. Replace both with your own release date when you adopt it — the first instruction in the document tells you to, because a procedure carrying somebody else’s revision date is not under your control.

Need more than one procedure?

This is one procedure from a larger library. If you are building or maintaining a full documentation system, view the complete ISO 13485 procedure package — the procedures, guides and tools assembled together.

Prefer to purchase by invoice? Contact us and we will send an invoice you can pay by your organization’s normal process.

The procedure is written throughout for a fictional organization called Perennia Corp, used for illustration and not connected with any real organization of the same or a similar name. Replace it with your own name and work through the bracketed placeholders. This is a professional work product provided for adaptation and use within your organization. It is not a certification requirement, an inspection checklist, or a substitute for the applicable standard, the applicable regulation, or the judgment of a competent professional. © Management Systems International, LLC. All rights reserved.