Illustrative case study

Building an ISO 13485 QMS: An Illustrative Case Study

Illustrative scenario: a small manufacturer builds its ISO 13485 QMS from a company profile, a quality manual and a chained set of core procedures, then runs its first internal audit.

Demo scenario. This is a demonstration scenario on a fictional company. It shows how the QMS workflow runs in MDRpilot. It does not describe a real customer, certification body or audit outcome.

The device

A fictional 12-person manufacturer of Class I and Class IIa non-active devices with one production site and two critical suppliers, preparing for its first ISO 13485 certification audit and an MDR QMS assessment.

1. Problem

  • Procedures copied from different templates, with inconsistent role names and retention periods
  • No single list of controlled documents
  • Training records kept per person in spreadsheets
  • Complaints and CAPA handled by email

2. Workflow in MDRpilot

  1. Company facts are entered once in the profile: legal name, address, sites, markets, general manager, management representative, quality manager, regulatory responsible and record retention period.
  2. The quality manual wizard produces a manual draft for ISO 13485 with scope and justified exclusions.
  3. Core procedures are drafted in order: document control, record control, organisation, risk management, CAPA. Before each one, only the procedure-specific questions are asked, such as numbering scheme, backup and destruction rules, root-cause method or CAPA closure approver.
  4. Undecided points appear as [TO BE CONFIRMED] in the drafts, and the fact card lists the facts used and those still to confirm.
  5. Documents go through review, approval and release; the document register lists them.
  6. Training matrix, complaints and CAPA records are started in the operational modules.
  7. An internal audit is planned and recorded; the audit simulator is used to rehearse.

3. Evidence

  • Approved quality manual and core procedures with revision history
  • Document register exported as XLSX
  • Training matrix with records for key roles
  • First internal audit report with findings and resulting CAPAs

4. Gaps found

GapRequirement
Record retention period not decidedISO 13485 clause 4.2.5 and MDR Article 10(8)
Supplier evaluation criteria missingISO 13485 clause 7.4.1
No procedure for regulatory reporting and vigilanceISO 13485 clause 8.2.3 and MDR Article 87
PRRC not designatedMDR Article 15

5. Resolution

  • The retention period is decided by management and entered in the profile; every procedure that refers to it updates on its next revision.
  • Supplier evaluation criteria are defined and both critical suppliers are evaluated.
  • A vigilance procedure is added and linked to the complaint process.
  • A PRRC is designated and the qualification evidence is filed.

6. Audit readiness

  • Every procedure uses the same role names and retention period because they come from the profile
  • The document register shows status for all controlled documents
  • The first internal audit and management review are recorded before the certification audit

Where this fits in the workflow

  1. Requirements
  2. Evidence
  3. Documents
  4. Risk
  5. Clinical
  6. PMS
  7. QMS
  8. Audit

Each step reads from the same product record. A test report linked to a GSPR row can verify a risk control, a change to the device class flags the documents that depend on it, and the audit readiness view counts what is still open across all of them.

See it with your own device

Create an account, add your company and one real device. The Suite demo runs for 3 days and the first procedure opens straight away, not an empty dashboard.