REGQUALITYREVIEW

Evidence for systems that carry regulated work.

Capability record

CAPA

CAPA is treated as a decision-bearing workflow, not a checkbox. The maintained record connects documented organization positioning to authority context, operating domains, buyer questions, and evidence limitations.

Define the operating boundary

A useful definition names the triggering event, required inputs, governing source, accountable owner, decision or action, exception path, evidence retained, and downstream handoff. Buyers should adapt those elements to their own population, jurisdictions, policies, systems, and control model before writing requirements.

The most important distinction is between a label and an operational capability. A provider may document CAPA while depending on customer-supplied policy, licensed content, third-party data, integration partners, manual review, or services. The demonstration should expose those dependencies rather than hiding them behind a completed interface.

What a demonstration should prove

  1. Begin with representative source records and a named policy, standard, or controlled rule.
  2. Show the normal path, an ambiguous case, missing data, an exception, an override, and a material source change.
  3. Identify who can change rules, who can approve or reject, and how accountability is preserved.
  4. Trace every output back to inputs, versions, timestamps, user actions, and governing evidence.
  5. Export the resulting record and reconcile it with downstream systems and retained obligations.

Authority and operating context

FDA QMSR

The QMSR amends FDA's device current good manufacturing practice requirements in 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, while retaining FDA-specific statutory and regulatory requirements. FDA began using a new device inspection process when the rule became effective. QMSR changes the inspection and record context in which U.S. device manufacturers operate. Buyers need systems that can preserve the organization's controlled processes and evidence; no vendor can make the organization compliant by configuration alone.

FDA 21 CFR Part 11

Part 11 defines criteria under which FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records trustworthy, reliable, and generally equivalent to paper records and handwritten signatures. Electronic quality and regulatory platforms frequently process predicate-rule records. Buyers must evaluate technical controls, procedural controls, intended use, record retention, audit trails, access, signatures, and system lifecycle together rather than accept a generic Part 11 badge.

FDA drug CGMP

Parts 210 and 211 establish current good manufacturing practice requirements for drug manufacture, processing, packing, and holding, including organization, facilities, equipment, components, production controls, laboratory controls, records, reports, returned products, and complaints. eQMS products organize records supporting drug CGMP processes, but software boundaries must align with manufacturing, laboratory, ERP, MES, and supplier systems. A feature list alone cannot establish that regulated processes are controlled.

ISO 13485:2016

ISO 13485 specifies quality-management-system requirements for organizations involved in one or more stages of the medical-device lifecycle and emphasizes regulatory requirements, risk-based processes, supplier control, documentation, and product realization. The standard is a central organizing reference for medical-device QMS design and is incorporated into the U.S. QMSR. Buyers need systems that can express their own processes and evidence without treating a vendor template as the standard itself.

ICH Q10

ICH Q10 describes a pharmaceutical quality-system model across development and commercial manufacturing, including management responsibilities, process and product monitoring, CAPA, change management, management review, knowledge management, and quality risk management. Q10 provides an operating model that crosses organizational and software boundaries. An eQMS can support records and coordination, but buyers must test how the system connects monitoring, investigation, CAPA, change, knowledge, and management oversight.

ICH Q9(R1)

ICH Q9(R1) provides principles and examples for systematic quality risk management across the pharmaceutical product lifecycle and addresses formality, risk-based decision-making, subjectivity, product availability, and managing risk through assessment, control, communication, and review. Risk scoring fields are not equivalent to a sound risk-management process. Buyers should examine how systems preserve scientific rationale, uncertainty, ownership, review, escalation, and linkage to decisions over time.

EU GMP Chapter 4

Chapter 4 describes expectations for the generation, control, review, approval, distribution, maintenance, and retention of GMP documentation and records, including paper, electronic, photographic, and other media. Controlled content, executed records, metadata, review, retention, and retrieval are foundational eQMS concerns. Buyers must distinguish document-authoring convenience from regulated record control and maintain awareness of the pending revision path.

EU MDR

The MDR establishes rules for placing medical devices on the EU market and covers economic operators, conformity assessment, quality systems, clinical evidence, technical documentation, UDI, registration, vigilance, post-market surveillance, and market surveillance. MDR work crosses QMS, product lifecycle, regulatory registration, UDI, technical documentation, clinical evidence, and post-market systems. Buyers need explicit system boundaries and reliable traceability across them.

EU IVDR

The IVDR establishes rules for in vitro diagnostic devices, including classification, conformity assessment, quality systems, performance evidence, technical documentation, UDI, registration, vigilance, post-market surveillance, and performance studies. IVD quality and regulatory records require device-specific classification, evidence, registration, and post-market workflows. Generic pharma or medical-device templates may not cover performance-study and IVD data needs.

Operating domains

Quality events, CAPA, change, and effectiveness

Risk that deviations, nonconformances, investigations, corrective and preventive actions, and changes are handled as isolated tickets rather than a controlled chain from detection through root cause, risk, implementation, and effectiveness review.

Audit, inspection, and evidence readiness

Risk that the organization cannot retrieve a coherent, accurate, and reviewable evidence chain for an auditor, inspector, certification body, notified body, or internal governance review without manual reconstruction.

Supplier quality and external operations

Risk that suppliers, laboratories, contract manufacturers, service providers, and other external parties are selected, qualified, monitored, changed, and governed without sufficient evidence or connection to product and process risk.

Complaints, post-market quality, and safety handoffs

Risk that complaints, adverse-event indicators, product-quality complaints, vigilance, field actions, recalls, post-market surveillance, and regulatory reporting are delayed or fragmented across quality, safety, medical, regulatory, and commercial systems.

Evidence and comparison limits

Official provider documentation can establish product positioning. Provider confirmation can clarify package or availability. Independent observation requires a disclosed scenario, environment, date, inputs, and reproducible result. None of those sources alone establishes buyer-specific legal, clinical, regulatory, quality, or operational fitness.

Buyer questions

  • What exact outcome and evidence should CAPA produce?
  • Which source, version, and customer facts govern the workflow?
  • Which decisions remain human and who is accountable for them?
  • What is native, configured, integrated, service-delivered, or planned?
  • How does a changed source affect open and historical records?

Recent changes

FDA Quality Management System Regulation takes effect — Device manufacturers must align their controlled quality systems and inspection evidence; software alignment can support but cannot establish organizational compliance.