Skip to content
Sinfony

ISO 13485 · Medical devices

ISO 13485 asks for evidence of effectiveness, not evidence of volume.

The confusion is old and it is expensive. You read "documented" and understand "written down somewhere"; you read "trained" and understand "has signed". The standard asks for something else, and it says so more than once.

"Effectiveness"

The word appears on training, on corrective action, on preventive action and on management review. Every time, the standard does not ask that an action exist: it asks for evidence that it produced the intended effect.

Documentation volume proves nothing; evidence of effectiveness is what the standard requires.Documentation volumeproves nothingEvidence of effectivenessrequired four timesThe standard asks for the second, not the first.
ISO 13485:2016, quality management systems for medical devices.

It is the thread running through the standard, and the one that thick document systems satisfy least well. A large document set proves that you wrote. It never proves that you obtained a result. And the gap between the two is exactly what your notified body will come looking for.

The belief that costs you

"The standard requires one procedure per requirement."

It requires documented processes, which is not the same thing: a process can be described once, at the right level, and cover several requirements. The standard also states that the extent of documentation depends on the size of the organisation, the type of activities and the complexity of the processes. In other words, it explicitly asks you to calibrate — and calibrating is not maximising.

What the standard actually says

Three requirements, commonly misread.

The risk-based approach

ISO 13485:2016 brought risk into the whole system, not just the product file. That means the control effort must be proportionate. An organisation applying the same level of control everywhere is not applying the risk-based approach: it is opting out of it, and substituting exhaustiveness.

Competence, not a signature

The standard asks you to determine the competence needed, provide the training, then evaluate its effectiveness. A signed reading sheet proves none of that. An assessment at the workstation does satisfy the requirement — and it incidentally reveals the procedures nobody can actually apply.

Corrective action

Determine the cause, evaluate the need for action, implement, and verify that the action has no adverse effect on device conformity. That last condition is decisive: it rules out the reflex answer of adding a control, when that control degrades something else.

Our conviction

What cannot be carried out at the workstation is not compliant, however written and signed.

An operator who cannot apply the procedure as written applies their own. The gap already exists; the document merely hides it. And ISO 13485 asks you precisely to evaluate effectiveness — that is, to go and look. The standard is on our side: it does not ask you to take your system's word for it, it asks you to check it at the workstation.

What you gain

A shorter system is a more defensible one.

Certification

The most common certification findings are about missing evidence of effectiveness, not missing documents. Investing in evidence rather than in volume treats the actual cause.

Time to market

Every additional procedure lengthens the change control loop. A calibrated document set shortens the delay between a design change and its industrial implementation.

Onboarding

The time a new joiner needs to become autonomous is directly proportional to the volume they must absorb. It is one of the few indicators that measures document system quality without any detour.

Which leaves the question every quality manager asks at this point: how do you justify cutting back to a notified body? The answer is one word, and it is the standard's own: traceability of the decision. We set out the method here.

Frequently asked

ISO 13485, plainly.

Does your system evidence its effectiveness, or its volume?

Two days is enough to measure the gap between what your procedures describe and what your teams actually do.