ISO 13485 Medical Devices — Quality Management Systems
Confirms that a medical device organisation controls design, manufacture and traceability to the level regulators require.
This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →
What this certification proves
ISO 13485 shares ancestry with ISO 9001 but has a different purpose. ISO 9001 is about satisfying the customer. ISO 13485 is about meeting regulatory requirements and keeping patients safe — and where the two conflict, regulation wins.
That difference shows up everywhere. Continual improvement is not the organising idea; maintaining effectiveness is. Records are kept for the lifetime of the device, not a convenient period. Design changes must be evaluated for their effect on regulatory approval before they are made. And traceability must be strong enough that, if a defect is found, you can identify every unit that shared the cause.
⚠️ ISO 13485 does not follow Annex SL. Its clauses run 4 to 8, not 4 to 10, so it does not share a skeleton with 9001 or 14001 the way the others do.
Who this is for
- Medical device manufacturers, including contract manufacturers
- Organisations exporting devices — required or expected in most markets
- Distributors, importers and sterilisation services in the device supply chain
- Organisations preparing for regulatory approval in Korea, the EU or elsewhere
🌱 How this relates to ESG
S SocialMaps onto the S (Social) pillar — patient safety and product safety.
- GRI 416 (Customer Health and Safety) — product safety assessment and non-compliance incidents
- Korea's K-ESG guideline, S domain «consumers» — product and service safety management
- Regulatory prerequisite rather than a voluntary ESG action in most markets — this is worth stating plainly rather than presenting it as an ESG achievement
- Complaint handling, vigilance reporting and recall records are the substantive evidence behind any product-safety disclosure
What certification gives you
- Expected or required for regulatory approval in most device marketsRequest audit duration and fees →
- Traceability strong enough to identify every affected unit if a defect is foundSee the 8-step process →
- Design control and design history files are structured, which is what regulators examineCheck a certified organisation →
- Risk management (ISO 14971) is embedded across the whole product lifecycleCertification mark rules →
- Recognised by distributors and hospital procurement worldwideSee our accreditations →
How the requirements are structured
This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.
| Clause | Title | In plain terms |
|---|---|---|
| 4 | Quality management system | General requirements and documentation, including the medical device file for each device. |
| 5 | Management responsibility | Policy, planning, responsibility and authority, and management review. |
| 6 | Resource management | Competence, infrastructure and the work environment and contamination control. |
| 7 | Product realisation | Risk management, design and development, purchasing, production and service, traceability and identification, and control of monitoring equipment. |
| 8 | Measurement, analysis and improvement | Complaint handling, reporting to regulatory authorities, internal audit, nonconforming product, and corrective and preventive action. |
※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.
Before you apply, please check
Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.
- Is there a medical device file for each device or device family?
- Is risk management (ISO 14971) applied across the whole lifecycle, with records?
- Are design and development inputs, outputs, review, verification, validation and transfer documented?
- Is there a procedure for evaluating whether a design change affects regulatory approval before it is made?
- Is traceability sufficient to identify all units sharing a cause?
- Is there a complaint handling procedure and a procedure for reporting to regulatory authorities?
- Are records retained for the lifetime of the device as required?
- Have you carried out at least one internal audit yourselves? (required before the audit)
You can apply for ISO 13485 certification here
Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.
Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317
※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.
Which audit division handles this
Audits against this standard are carried out by our 의료기기심사본부. See the organisation chart →
