MSI's ISO 9001 and 13485 management review procedure

ISO 9001:2026 and 13485 Integrated Leadership and Commitment Procedure Template

$249

An editable integrated leadership and management review procedure for organizations running a general product line and a medical device line under one quality system. Built to ISO 9001:2026 with ISO 13485:2016 requirements marked by scope. Includes the transition edition and MSI's QuickStart.

ISO 9001 moved. ISO 13485 did not. This is built to ISO 9001:2026 and includes the transition edition. ISO 9001:2026 published in September 2026. ISO 13485:2016 is unchanged — the management representative, the independence requirement at 5.5.1, the twelve review inputs at 5.6.2 and the regulatory output at 5.6.3 c) all stand exactly as before. Nothing in your device scope moves because of this edition. The purchase includes a transition edition marking every point the 2026 edition changed the general scope, so one purchase serves you now and after you transition.

What is actually in the integrated document

30 pages covering the governance layer of both standards — scope determination, context, interested parties, the quality management system, leadership, policy, roles and authorities, the management representative, objectives, planning of changes, resources, communication, monitoring and management review. Written as a filled-in worked example, with every requirement marked [G] for general scope, [D] for device, or unmarked where it serves both.

Thirty pages is a lot. That is why MSI’s QuickStart comes with it. The QuickStart is seven pages listing thirty-six decisions across five stages, in the order where each one builds on the last, with the section of the procedure where each is explained. Name the people, set the boundaries, set direction, set the operating rhythm, set the records. It is included in this purchase.

Why one procedure rather than two

An organization running a general product line and a device line does not run two quality systems. It runs one, with a device scope inside it. Two separate leadership procedures produce two management reviews, two context determinations that stop agreeing, and a management representative whose authority is unclear outside the device scope. This procedure determines scope first — general, device, or uncertain, with uncertain defaulting to device pending determination — then marks every requirement by the scope it serves. Appendix D records thirteen genuine divergences between the two standards, what this procedure does about each, and what the alternative was.

The three things an integrated leadership procedure gets wrong

01 · The management representative, dropped or over-applied

ISO 9001:2015 removed the management representative requirement and ISO 9001:2026 has not brought it back. ISO 13485 5.5.2 still requires one, with defined authority and the duty to promote awareness of regulatory requirements throughout the organization. Procedures written from the quality side drop the role; procedures written from the device side apply it to everything. This one keeps it, scopes it to the device line, states why, and recommends a competent alternate.

02 · The two regulatory review inputs

ISO 13485 5.6.2 c) and l) — reporting to regulatory authorities, and new or revised regulatory requirements — read like regulatory topics sitting inside a quality clause, so they land in neither system. Almost no merged review agenda has a line for either. This procedure names a producing role and a source record for both.

03 · A merged review that covers one list

ISO 9001 clause 9.3.2 and ISO 13485 clause 5.6.2 name different inputs. A single review built from one list quietly fails the other standard. The merged input table here carries every input either standard requires, marked by scope, each with a producing role, a frequency and a record.

What the 2026 edition changed — and the new divergence it created

01 · Understood was dropped from ISO 9001 5.3, and ISO 13485 still requires it

This is a divergence that did not exist before this year. ISO 9001:2026 requires responsibilities and authorities to be assigned and communicated. ISO 13485 5.5.1 still requires them defined, documented and communicated, with independence where it applies. The house standard takes the stricter position and keeps the understanding check across both scopes, recorded as decision D-13.

02 · Retained became available on the general scope

“Shall retain” does not appear in ISO 9001:2026. Records are available as documented information. Device-scope retention under ISO 13485 4.2.5 is unaffected and still governed by the regulatory floor, so the records table carries both tests and marks which applies where.

03 · Leadership grew from ten obligations to twelve

ISO 9001 clause 5.1.1 adds promoting quality culture and ethical behavior, which ISO 13485 does not name at all, and separates opportunity-based thinking from risk-based thinking. The whole list is relettered, so every 5.1.1 reference in the commitment mapping has moved. The house standard extends the culture obligation to the device scope, because a culture that discourages reporting is a patient-safety exposure before it is a conformity one.

What’s included

  • The complete integrated governance procedure — 16 numbered sections covering ISO 9001 clauses 4.1–4.4, 5.1–5.3, 6.2, 6.3, 7.1, 7.4, 9.1, 9.3 and ISO 13485 clause 5 in full, reconciled, editable Microsoft Word
  • The transition edition — every 2026 change marked, with a front sheet that leads on what did not move, since the device scope is unaffected
  • MSI’s QuickStart — seven pages turning this procedure into an ordered worklist of thirty-six decisions across five stages
  • A scope determination section that runs before anything else — general, device or uncertain, with uncertain defaulting to device
  • A commitment mapping — all twelve ISO 9001:2026 leadership obligations against ISO 13485’s five acts, showing which map and which are general-scope only
  • The management representative section — appointment, authority, alternate, and the regulatory-awareness duty under 5.5.2 c)
  • A merged management review input table — every input either standard requires, marked by scope, each with a producing role, a frequency and a source record
  • Quality culture and ethical behavior under ISO 9001 5.1.1 i), extended to both scopes as the house standard
  • Planning of changes built as a gate, with the seven ISO 9001 6.3 considerations plus the ISO 13485 5.4.2 regulatory and product outcome test
  • A records table with no blanks — owner, location, availability and retention for each, with the device-scope regulatory retention floor stated
  • A maturity ladder — nine elements, four levels each, described as observable behavior
  • Appendix A — Management Review Record with the merged input set
  • Appendix B — Change Record and Log
  • Appendix C — Work instruction and worked example
  • Appendix D — Integration decision record: thirteen divergences, what this procedure does, and the alternative for each
Every appendix, form and worked example is part of the document. Nothing is sold separately.

Who it’s for

Quality and regulatory managers, operations leaders and consultants at organizations certified to both ISO 9001 and ISO 13485 under one quality system — typically a manufacturer with a general industrial line and a device line, or a contract manufacturer serving both markets. Particularly useful where the two certifications were achieved separately and the procedures have never been reconciled. Not sure where your system sits? The free Leadership and Commitment Maturity Check has a Device path that scores the integration itself, not just one standard.

Questions

Does ISO 9001:2026 affect my device certificate?

No. ISO 13485:2016 is unchanged. Every requirement in your device scope stands exactly as before, and the transition edition included with this purchase leads on that point so you can see it at a glance. What moves is the general scope, and the transition edition marks every change.

Thirty pages. Where do I start?

With the QuickStart, which is included. It lists thirty-six decisions across five stages, in the order that lets each build on the last, with the section where each is explained. Stage 1 is naming the people, because nothing else is decided until someone owns it — and in a device organization that includes the management representative and a competent alternate.

What is Appendix D and why does it matter?

Where the two standards genuinely differ, a combined procedure has to choose. Appendix D records all thirteen divergences, what this procedure does about each, and what the alternative was. Without that record, a merged procedure reads to an auditor like two standards stapled together by accident. With it, every difference is a decision you can defend.

Is QMSR reflected?

Yes. Since 2 February 2026 ISO 13485:2016 is incorporated into 21 CFR Part 820, which makes device-scope procedures regulatory instruments and their records inspectable. The procedure is written on that basis, and the records table marks which retention floor applies.

Does it cover the whole of both standards?

No. It covers the governance layer — context, leadership, policy, objectives, planning, resources, communication, monitoring and management review, plus ISO 13485 clause 5 in full. It references neighboring processes such as risk management, design controls, competence, internal audit and CAPA rather than replacing them.

What format is it?

Editable Microsoft Word (.docx), with the process interaction map supplied separately as an editable SVG. The license permits the buying organization to use it across its own sites and issue it to employees, contractors and auditors, and permits consultants to adapt it for engagements they deliver.

Can you help us implement it?

Yes. Call MSI at 760-434-9141 to schedule a planning session.