The risk-based approach
ISO 13485:2016 brought risk into the whole system, not just the product file. That means the control effort must be proportionate. An organisation applying the same level of control everywhere is not applying the risk-based approach: it is opting out of it, and substituting exhaustiveness.