A complete, working ISO 13485 document and records control procedure — not an outline with blanks. Fifty-two pages covering Clause 4.2.4 and Clause 4.2.5 as the two separate requirements they are. Every section is written out, every decision is made and explained, and the only things left for you are the values that are genuinely yours to set.
Written for device organizations as a filled-in worked example, not adapted from a quality base. That distinction matters more here than anywhere else in ISO 13485, because the requirements that go missing are the ones a quality procedure has no reason to contain.
52 pages, editable Word | 31 clauses cross-referenced | 26 MSI notes in the margin | 4 appendices, every one usable |
Since 2 February 2026, this is a regulatory document. The FDA Quality Management System Regulation incorporates ISO 13485:2016 by reference into 21 CFR Part 820. For US-marketed devices your document and record controls are the operative form of a federal requirement, and the records they govern are inspectable.
01
ISO 13485 sets one period for obsolete documents and a different period for records, both derived from the lifetime of the device as you define it in the medical device file. Most procedures carry a single flat period. And if that device lifetime has never been written down, neither clock can be calculated — which means both are being guessed, and nobody in the organization knows it.
02
The standard is silent on what certain records must contain. 21 CFR 820.35 is not. Complaints, servicing, unique device identification and labeling release all carry required data elements that no clause checklist points at, which is exactly why they are missing from so many device quality systems. This procedure builds the required elements into named form fields rather than leaving them to a reminder.
03
Both are required documented information with no ISO 9001 equivalent. Both are collections rather than documents, and both are routinely held outside Quality by the people who create them — which is how they end up outside document control entirely. Section 6 brings their indexes inside it as controlled objects, so completeness is demonstrable rather than assumed.
Every appendix, form and worked example is part of the document. Nothing is sold separately.
Most procedure templates restate the clause. “Documented information shall be reviewed and approved for suitability and adequacy” is an assertion, not a mechanism — it repeats what the standard already told you and leaves the decisions to you. This procedure makes the decisions and shows its reasoning.
It is built to seven marks: a real trigger, one accountable owner, stated decision criteria rather than intentions, records produced as a byproduct of the work, a defined exception path, trainable in one sitting, and a built-in review trigger that fires on events rather than on the calendar.
Quality and regulatory managers at device manufacturers, contract manufacturers and specification developers — certified to ISO 13485, pursuing certification, or running a device quality system to the standard without holding a certificate. Particularly useful where the existing procedure was adapted from an ISO 9001 base, which is where the regulatory record content and the two retention clocks usually go missing.
Not sure yet? The free Document and Records Control Maturity Check scores your process across eight elements in about six minutes, with a device path that adds the requirements having no ISO 9001 equivalent. Your score appears without entering anything.
Preparing for an FDA inspection or a notified body audit?
MSI’s QMS Interviews course prepares your team for the questions they will actually be asked. This matters more since QMSR took effect — the records this procedure governs are now inspectable, and the people who create them are the people who will be asked about them.
Both, deliberately. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set. You are editing a working document rather than filling in a hollow outline.
Because the clause numbers do not map and the obligations differ. ISO 13485 predates the harmonized ten-clause structure, splits documents and records into two separate clauses, sets two retention clocks rather than one, and carries record content requirements that come from regulation rather than from the standard. Adapting a quality procedure is how those requirements go missing in the first place.
Yes. The procedure is written on the basis that ISO 13485:2016 is incorporated by reference into 21 CFR Part 820, and the cross-reference maps obligations across both the standard and the regulation rather than treating the regulation as an afterthought.
Then neither retention clock can be calculated, and the procedure says so directly rather than letting you paste in a default. Section 8 names the decision, explains what it drives, and points at where it belongs. It is a short conversation to have once and an expensive one to discover during an inspection.
Editable Microsoft Word (.docx). Adapt it, rebrand it, and adopt it into your own document control system. The license permits the buying organization to use it across its own sites and issue it to employees, contractors and auditors, and permits consultants to adapt it for engagements they deliver.
No. Nothing in this procedure assumes a certificate. An organization running a device quality system to ISO 13485 because a customer requires it, because a regulator requires it, or because it is the sensible way to work, uses it exactly the same way.
A procedure does not pass an inspection; an organization does. What this gives you is a procedure that addresses every requirement of both clauses with a named owner and a named record, and a records inventory with no blanks in it. Conformity is demonstrated by implementation and evidence. Unfilled placeholders are unmet requirements, so fill them.
The file you download is the current revision at the time of purchase, and it carries MSI’s revision and effective date in the footer. Replace both with your own release date when you adopt it — the first instruction in the document tells you to, because a procedure carrying somebody else’s revision date is not under your control.
Need more than one procedure?
This is one procedure from a larger library. If you are building or maintaining a full documentation system, view the complete ISO 13485 procedure package — the procedures, guides and tools assembled together.
Prefer to purchase by invoice? Contact us and we will send an invoice you can pay by your organization’s normal process.
The procedure is written throughout for a fictional organization called Perennia Corp, used for illustration and not connected with any real organization of the same or a similar name. Replace it with your own name and work through the bracketed placeholders. This is a professional work product provided for adaptation and use within your organization. It is not a certification requirement, an inspection checklist, or a substitute for the applicable standard, the applicable regulation, or the judgment of a competent professional. © Management Systems International, LLC. All rights reserved.
Notifications