Define the operating boundary
A useful definition names the triggering event, required inputs, governing source, accountable owner, decision or action, exception path, evidence retained, and downstream handoff. Buyers should adapt those elements to their own population, jurisdictions, policies, systems, and control model before writing requirements.
The most important distinction is between a label and an operational capability. A provider may document change control while depending on customer-supplied policy, licensed content, third-party data, integration partners, manual review, or services. The demonstration should expose those dependencies rather than hiding them behind a completed interface.
What a demonstration should prove
- Begin with representative source records and a named policy, standard, or controlled rule.
- Show the normal path, an ambiguous case, missing data, an exception, an override, and a material source change.
- Identify who can change rules, who can approve or reject, and how accountability is preserved.
- Trace every output back to inputs, versions, timestamps, user actions, and governing evidence.
- Export the resulting record and reconcile it with downstream systems and retained obligations.
Authority and operating context
FDA QMSR
The QMSR amends FDA's device current good manufacturing practice requirements in 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, while retaining FDA-specific statutory and regulatory requirements. FDA began using a new device inspection process when the rule became effective. QMSR changes the inspection and record context in which U.S. device manufacturers operate. Buyers need systems that can preserve the organization's controlled processes and evidence; no vendor can make the organization compliant by configuration alone.
FDA 21 CFR Part 11
Part 11 defines criteria under which FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records trustworthy, reliable, and generally equivalent to paper records and handwritten signatures. Electronic quality and regulatory platforms frequently process predicate-rule records. Buyers must evaluate technical controls, procedural controls, intended use, record retention, audit trails, access, signatures, and system lifecycle together rather than accept a generic Part 11 badge.
FDA drug CGMP
Parts 210 and 211 establish current good manufacturing practice requirements for drug manufacture, processing, packing, and holding, including organization, facilities, equipment, components, production controls, laboratory controls, records, reports, returned products, and complaints. eQMS products organize records supporting drug CGMP processes, but software boundaries must align with manufacturing, laboratory, ERP, MES, and supplier systems. A feature list alone cannot establish that regulated processes are controlled.
ISO 13485:2016
ISO 13485 specifies quality-management-system requirements for organizations involved in one or more stages of the medical-device lifecycle and emphasizes regulatory requirements, risk-based processes, supplier control, documentation, and product realization. The standard is a central organizing reference for medical-device QMS design and is incorporated into the U.S. QMSR. Buyers need systems that can express their own processes and evidence without treating a vendor template as the standard itself.
ICH Q10
ICH Q10 describes a pharmaceutical quality-system model across development and commercial manufacturing, including management responsibilities, process and product monitoring, CAPA, change management, management review, knowledge management, and quality risk management. Q10 provides an operating model that crosses organizational and software boundaries. An eQMS can support records and coordination, but buyers must test how the system connects monitoring, investigation, CAPA, change, knowledge, and management oversight.
ICH Q9(R1)
ICH Q9(R1) provides principles and examples for systematic quality risk management across the pharmaceutical product lifecycle and addresses formality, risk-based decision-making, subjectivity, product availability, and managing risk through assessment, control, communication, and review. Risk scoring fields are not equivalent to a sound risk-management process. Buyers should examine how systems preserve scientific rationale, uncertainty, ownership, review, escalation, and linkage to decisions over time.
EU GMP Chapter 4
Chapter 4 describes expectations for the generation, control, review, approval, distribution, maintenance, and retention of GMP documentation and records, including paper, electronic, photographic, and other media. Controlled content, executed records, metadata, review, retention, and retrieval are foundational eQMS concerns. Buyers must distinguish document-authoring convenience from regulated record control and maintain awareness of the pending revision path.
EU GMP Annex 11
Annex 11 applies GMP principles to computerized systems and addresses lifecycle risk management, personnel, suppliers, validation, data, accuracy checks, storage, printouts, audit trails, change control, incident management, periodic evaluation, security, signatures, continuity, and archiving. Annex 11 shapes how buyers assess both the product and the supplier lifecycle. A provider feature list is insufficient without evidence for intended use, risk, validation, data integrity, security, change, continuity, and ongoing evaluation.
EU MDR
The MDR establishes rules for placing medical devices on the EU market and covers economic operators, conformity assessment, quality systems, clinical evidence, technical documentation, UDI, registration, vigilance, post-market surveillance, and market surveillance. MDR work crosses QMS, product lifecycle, regulatory registration, UDI, technical documentation, clinical evidence, and post-market systems. Buyers need explicit system boundaries and reliable traceability across them.
EU IVDR
The IVDR establishes rules for in vitro diagnostic devices, including classification, conformity assessment, quality systems, performance evidence, technical documentation, UDI, registration, vigilance, post-market surveillance, and performance studies. IVD quality and regulatory records require device-specific classification, evidence, registration, and post-market workflows. Generic pharma or medical-device templates may not cover performance-study and IVD data needs.
ISO IDMP
The ISO IDMP family standardizes the identification and description of substances, dose forms and routes, units of measurement, regulated pharmaceutical products, and regulated medicinal products. EMA is implementing these concepts through substance, product, organization, and referential master-data services. IDMP readiness is a data-governance and operating-model question, not just a product feature. Buyers need to examine source ownership, data quality, terminology services, submission interfaces, stewardship, and change propagation.
Operating domains
Quality-system governance and controlled content
Risk that policies, procedures, specifications, instructions, forms, records, roles, and management oversight do not remain approved, current, available, attributable, and connected to the regulated work they govern.
Quality events, CAPA, change, and effectiveness
Risk that deviations, nonconformances, investigations, corrective and preventive actions, and changes are handled as isolated tickets rather than a controlled chain from detection through root cause, risk, implementation, and effectiveness review.
Audit, inspection, and evidence readiness
Risk that the organization cannot retrieve a coherent, accurate, and reviewable evidence chain for an auditor, inspector, certification body, notified body, or internal governance review without manual reconstruction.
Computerized systems, validation, and data integrity
Risk that a quality or regulatory system is not fit for intended use, remains insufficiently controlled through change, or cannot preserve complete, consistent, accurate, attributable, legible, contemporaneous, original, and available records across its lifecycle.
Supplier quality and external operations
Risk that suppliers, laboratories, contract manufacturers, service providers, and other external parties are selected, qualified, monitored, changed, and governed without sufficient evidence or connection to product and process risk.
Regulatory product and registration lifecycle
Risk that product, substance, device, market, registration, license, activity, authority, commitment, correspondence, and approval information is fragmented or too unreliable to support global regulatory decisions and market continuity.
Structured product data and labeling governance
Risk that medicinal-product, device, substance, pack, presentation, identifier, label, and artwork data is inconsistent across source systems, submissions, authority databases, markets, safety processes, and supply operations.
Complaints, post-market quality, and safety handoffs
Risk that complaints, adverse-event indicators, product-quality complaints, vigilance, field actions, recalls, post-market surveillance, and regulatory reporting are delayed or fragmented across quality, safety, medical, regulatory, and commercial systems.
Evidence and comparison limits
Official provider documentation can establish product positioning. Provider confirmation can clarify package or availability. Independent observation requires a disclosed scenario, environment, date, inputs, and reproducible result. None of those sources alone establishes buyer-specific legal, clinical, regulatory, quality, or operational fitness.
Buyer questions
- What exact outcome and evidence should change control produce?
- Which source, version, and customer facts govern the workflow?
- Which decisions remain human and who is accountable for them?
- What is native, configured, integrated, service-delivered, or planned?
- How does a changed source affect open and historical records?
Recent changes
First four EUDAMED modules become mandatory — Medical-device organizations need controlled data ownership and change propagation across quality, product, certificate, operator, and regulatory records.
FDA issues final Computer Software Assurance guidance — Buyers should evaluate intended-use, risk, supplier evidence, testing, change control, and customer responsibilities instead of relying on an unbounded validated-software claim.
FDA Quality Management System Regulation takes effect — Device manufacturers must align their controlled quality systems and inspection evidence; software alignment can support but cannot establish organizational compliance.
Revised EU Variations Guidelines begin to apply — RIM systems and procedures need effective-dated classification, form, submission, implementation, and annual-update logic with clear provenance.
EU consultation closes on draft GMP Chapter 4, Annex 11, and new Annex 22 — Life-sciences firms can use the drafts for forward planning while keeping current requirements and proposed controls clearly separated in policies, projects, and vendor evaluations.