Device Nonconformity, Corrective Action, and Continual Improvement Procedure Template & Guide (ISO 9001 + ISO 13485)

Device Nonconformity, Corrective Action, and Continual Improvement Procedure Template & Guide (ISO 9001 + ISO 13485)

$249

One integrated procedure template and guide satisfying ISO 9001:2015 Clause 8.7 and Clause 10 alongside ISO 13485:2016 Clause 8.3 and Clause 8.5 — for organizations running general product and medical devices through one improvement system. Includes the integration decision record.

ISO 9001:2015 + ISO 13485:2016 · $249 · Editable Word format

If you make both general product and medical devices, you have a problem neither single-standard template solves: two standards, two clause structures, one corrective action register, and a set of decisions nobody wrote down.

This is one procedure, not two documents in a folder. Where both standards require the same thing in different words, it is stated once. Where one is stricter, the stricter requirement is written as the house standard. Where a requirement exists in only one, it is marked and scoped.

Scope determination comes first. Every finding is assigned general, device, or uncertain at intake, using stated criteria — and uncertain defaults to device scope until Regulatory determines otherwise. That third category is the one that earns its place. A component nonconformity on a part your customer incorporates into a device sits inside a device quality agreement whether or not the person raising the ticket realized it.

The divergences are real and they run in both directions. ISO 13485 requires corrective action without undue delay and requires verification that the action does not adversely affect regulatory compliance or device safety and performance — neither has an ISO 9001 equivalent. ISO 9001 requires the risk and opportunity register to be updated when corrective action is taken — ISO 13485 has no such step. ISO 13485 keeps preventive action as a documented-procedure requirement; ISO 9001 removed it in 2015. ISO 13485 adds rework, concessions with regulatory confirmation, and advisory notices; ISO 9001 has nothing comparable. Taking the stricter of each is a defensible position, and it is the one this procedure takes — but it is a decision, and a decision that is not recorded looks like an accident.

Appendix D is what you cannot easily build yourself. Every genuine divergence between the two standards on this subject, what this procedure does about each, and what the alternative was — followed by the decisions to confirm before adoption. An integrated procedure that never records its integration decisions looks, to anyone examining it, like a document that merged two standards by accident. Appendix D is the evidence the merging was deliberate, and it is the first thing worth showing when someone asks how you satisfy both.

What’s included

Everything in both single-standard templates, integrated into one document — 48 pages, editable Word format — plus:

  • Scope determination section with a three-way criteria table including the uncertain default
  • Inline device markers so the reader never has to work out which standard they are reading
  • Merged severity model covering quality effect, regulatory effect, and device safety and performance
  • The corrective action clock applied to both scopes, so general product gets the device discipline
  • The risk and opportunity register update applied to both scopes, so device findings get the ISO 9001 discipline that ISO 13485 never required
  • Preventive action retained for both scopes
  • Device-only sections marked and scoped — rework, concessions with regulatory confirmation, advisory notices, external party notification
  • Dual cross-reference — every obligation mapped across ISO 9001, ISO 13485, 21 CFR Part 820, and where addressed
  • Process interaction map — editable SVG plus embedded image, showing both scopes on one sheet
  • Appendix C with two worked examples — one general, one device. Both are low-severity findings that a value-based severity model would have waved through; one carried a systemic quality exposure, the other a regulatory one
  • Appendix D — the integration decision record

Who it’s for

Organizations running an integrated management system across a device line and a non-device line. Contract manufacturers with mixed portfolios. Consultants supporting clients through integration. Anyone who has been maintaining two corrective action procedures and knows the second one is out of date.

What it does for you

  • Stop maintaining two procedures. One document, one register, one review cycle, one training event.
  • Close the scope gap. The most common failure in an integrated system is a device finding running down the general path because scope was assigned late or not at all.
  • Show your work. Appendix D turns "we merged two standards" into a documented set of decisions with reasoning attached.
  • Get the stricter discipline in both directions. The device timing clock and regulatory verification applied generally; the ISO 9001 risk register update applied to device scope.
  • Two audiences, one training session. Staff learn one process, with the device additions marked rather than separated.

Clauses addressed

9001: 8.7, 10.1–10.3 · 13485: 8.3, 8.5

Buy — $249

Other variants of this procedure

VariantPrice
ISO 9001$149
ISO 13485$149
ISO 14001:2026$149
ISO 45001$149
ISO 7101$149
HSE (14001 + 45001)$249
Q/EMS (9001 + 14001)$249
Integrated (9001 + 14001 + 45001)$249

Questions

Is this a template or a finished procedure?

Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — severity thresholds, roles, systems, intervals, retention periods. You are editing a working document rather than filling in a hollow outline.

What format?

Editable Microsoft Word (.docx), with a PDF copy. Where a process interaction map is included, it ships as an editable SVG alongside the embedded image. Adapt it, rebrand it, adopt it into your document control system. Yours to use.

Will this pass an audit?

A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over an operation that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.

Does it cover the whole standard?

No. Each covers the improvement clause of its standard in full, plus control of nonconforming output where the standard has such a clause. They are one procedure in a management system, and they reference the neighboring processes — document control, internal audit, complaint handling, risk management, management review — rather than replacing them.

What is the difference between correction and corrective action, and why does it matter here?

Correction addresses the thing in front of you: scrap it, rework it, contain it, tell the customer. Corrective action removes the cause so it does not happen again. Every standard in this family requires both, and treats them as separate obligations. The common failure is one form doing both jobs, which lets a disposition record close a finding without any cause ever being examined. These templates keep them as two records with a stated trigger between them, which is usually the single biggest change an organization makes when adopting one.

We already have a corrective action form. Is that not enough?

A form captures what happened. A procedure decides what happens next — which findings get a cause analysis and which do not, who is allowed to decide, how long the organization has, what evidence closes it, and what happens when the check fails. Most systems have a good form sitting on top of an unstated process, which is why closure rates look healthy while the same findings keep coming back.

We use different clause numbering and a different document system.

Every cross-reference is in a table at the back rather than baked into the body text, precisely so you can renumber without unpicking the procedure.

Which one do I need?

Take the template for the standard you are certified to. If you run more than one management system through one improvement process, take the matching combined variant — Device for ISO 9001 with ISO 13485, HSE for ISO 14001 with ISO 45001, Integrated for all three of quality, environment, and safety. If you are unsure, the free Nonconformity and Corrective Action Maturity Check will show you where your current process actually sits before you spend anything.

Can you help us implement it?

Yes. Call Management Systems International at 760-434-9141 to schedule a planning session.

About Management Systems International

MSI is a veteran-owned, woman-owned ISO consulting firm founded in 1998. Diana Lynn has 28 years of experience, has supported more than 80 organizations through successful ISO certification, has attended more than 200 certification and surveillance audits, and has trained more than 600 professionals across manufacturing, technology, medical device, government, healthcare and other regulated industries.

Questions before you buy? Call 760-434-9141.

© 2026 Management Systems International, LLC · All rights reserved