Define the business before drafting the system

A medical device QMS should describe how an organization controls its actual work. Start by defining the legal entity, licensed activities, sites, products, device classes, markets, outsourced processes, and contractual partners. A manufacturer that designs sterile devices has a different control set from an importer, an authorized representative, or a distributor that also provides maintenance.

Map decisions, records, and handoffs

Draw the operating flow from the first product or supplier decision through distribution, service, complaints, and change. For each process, identify the input, decision, output, owner, record, and escalation point. This produces a QMS architecture that follows work rather than a table of contents copied from the standard.

Handoffs deserve particular attention. A complaint received by a distributor must reach the authorized representative or manufacturer with enough information and time for a reportability decision. A supplier change must reach Quality and Regulatory Affairs before purchasing approves it. A service finding that suggests a trend must enter complaint and risk review. If these paths are informal, the organization will create records after the decision instead of using records to control it.

Keep the document structure lean

To turn this analysis into a product-specific plan, review Technical File and Regulatory Readiness Review and the related regulatory insight.

Use a clear hierarchy: policy and scope, quality manual, core procedures, work instructions where the task needs detail, and records that prove execution. Each controlled document needs an owner, approval, version, effective date, review status, and a reliable way to prevent obsolete copies from directing work. One strong procedure can govern a connected process; repeating the same requirement across several documents creates contradictions.

Implement in dependency order

Document control and training come first because every later process depends on current instructions and competent people. The next group normally includes supplier control, purchasing, product or service acceptance, storage and transport, traceability, complaints and vigilance, nonconformity and CAPA, change control, internal audit, and management review. Manufacturers add design, production, validation, monitoring and measuring equipment, and other controls that match their processes.

Implementation means running the process. Use realistic events: a new employee needs authorization, a supplier changes a component, a shipment arrives outside its specified condition, a customer reports repeated failure, or a safety notice arrives from another market. Follow the procedure, generate the record, and review whether the resulting decision is complete and timely.

Design records around evidence

A useful record allows an independent reviewer to reconstruct what happened. It identifies the event, product or process, evidence reviewed, decision criteria, decision maker, approval, action, due date, completion, and effectiveness result. A signature cannot repair missing reasoning, and a completed action is difficult to defend when no retrievable evidence connects it to the original issue.

Keep forms focused. Ask whether every field supports a decision, legal requirement, traceability need, or later trend analysis. Long forms invite copied text. Short forms can also fail when they omit the awareness date, product identity, risk rationale, or regulatory disposition. Test a draft form with the people who will use it and revise it before formal release.

The Basier six-gate QMS build roadmap

This roadmap uses exit evidence rather than a generic calendar. The time required depends on establishment scope, device complexity, resources, and licensing needs.

  1. Scope gate: approved list of activities, products, sites, parties, applicable requirements, and justified exclusions.
  2. Ownership gate: process map, role matrix, and agreements that define each handoff.
  3. Control gate: released document structure, version control, and role-based competence records.
  4. Operation gate: core processes run on real cases with complete, retrievable evidence.
  5. Assurance gate: internal audit across the scope, root-cause CAPA, and management review with decisions and resources.
  6. Sustainability gate: trends, effectiveness checks, and controlled updates when products, processes, or SFDA requirements change.

An approved procedure is not exit evidence. At the operation gate, the organization should be able to retrieve a case, follow it from intake to closure, interview the people involved, and obtain consistent answers. At the assurance gate, the audit should test process connections and management should resolve risks or resource gaps.

Trace one product through the complete system

Choose one product and follow its evidence trail: supplier or manufacturer qualification, receipt, storage, distribution, staff competence, complaint, vigilance decision, CAPA, change, and effectiveness review. Missing links show where the QMS exists as separate files rather than a controlled process. This end-to-end test is more informative than confirming that every procedure title exists.

References: [1] [2] [3] [4]

Official sources

Turn the requirements into a clear plan for your case

Start with an assessment of the device and available evidence before deciding on submission.

Technical File and Regulatory Readiness Review