REGQUALITYREVIEW

Evidence for systems that carry regulated work.

2026 research note

Standards-to-workflow crosswalk

A source-linked map from authority records to workflows, evidence obligations, and system capabilities.

REGQUALITY REVIEWStandards-to-workflow crosswalkMethod and limitations included
Executive summary

A source-linked map from authority records to workflows, evidence obligations, and system capabilities.

The maintained dataset joins 32 organization records, 18 normalized capabilities, 10 operating models, 12 authority records, and 9 operating domains. Counts describe the research corpus; they are not a market-size or quality score.

The authority records

FDA QMSR

United States · Effective. The QMSR amends FDA's device current good manufacturing practice requirements in 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, while retaining FDA-specific statutory and regulatory requirements. FDA began using a new device inspection process when the rule became effective.

FDA 21 CFR Part 11

United States · Current. Part 11 defines criteria under which FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records trustworthy, reliable, and generally equivalent to paper records and handwritten signatures.

FDA drug CGMP

United States · Current. Parts 210 and 211 establish current good manufacturing practice requirements for drug manufacture, processing, packing, and holding, including organization, facilities, equipment, components, production controls, laboratory controls, records, reports, returned products, and complaints.

ISO 13485:2016

International; use and legal effect depend on regulatory scheme, contract, and certification context · Published and confirmed. ISO 13485 specifies quality-management-system requirements for organizations involved in one or more stages of the medical-device lifecycle and emphasizes regulatory requirements, risk-based processes, supplier control, documentation, and product realization.

ICH Q10

International; adopted or implemented through ICH regulatory members · Step 4 final guideline. ICH Q10 describes a pharmaceutical quality-system model across development and commercial manufacturing, including management responsibilities, process and product monitoring, CAPA, change management, management review, knowledge management, and quality risk management.

ICH Q9(R1)

International; adopted or implemented through ICH regulatory members · Step 4 final guideline. ICH Q9(R1) provides principles and examples for systematic quality risk management across the pharmaceutical product lifecycle and addresses formality, risk-based decision-making, subjectivity, product availability, and managing risk through assessment, control, communication, and review.

EU GMP Chapter 4

European Union and European Economic Area GMP context · Current operative chapter; revision was consulted in 2025 and was not treated as final in this record. Chapter 4 describes expectations for the generation, control, review, approval, distribution, maintenance, and retention of GMP documentation and records, including paper, electronic, photographic, and other media.

EU GMP Annex 11

European Union and European Economic Area GMP context · Current revision 1; a proposed revision was consulted in 2025 and was not treated as final in this record. Annex 11 applies GMP principles to computerized systems and addresses lifecycle risk management, personnel, suppliers, validation, data, accuracy checks, storage, printouts, audit trails, change control, incident management, periodic evaluation, security, signatures, continuity, and archiving.

EU MDR

European Union and European Economic Area · In force as amended. The MDR establishes rules for placing medical devices on the EU market and covers economic operators, conformity assessment, quality systems, clinical evidence, technical documentation, UDI, registration, vigilance, post-market surveillance, and market surveillance.

EU IVDR

European Union and European Economic Area · In force as amended. The IVDR establishes rules for in vitro diagnostic devices, including classification, conformity assessment, quality systems, performance evidence, technical documentation, UDI, registration, vigilance, post-market surveillance, and performance studies.

eCTD v4.0

Implemented regionally by ICH regulatory authorities · Step 4 implementation package; regional implementation is active and differs by authority. eCTD v4.0 defines a harmonised structure and exchange model for regulatory submissions, with regional controlled vocabularies, module-one requirements, validation criteria, transmission specifications, and implementation timelines maintained by authorities.

ISO IDMP

International; phased European Union implementation described in this record · Published standards; EU implementation remains phased. The ISO IDMP family standardizes the identification and description of substances, dose forms and routes, units of measurement, regulated pharmaceutical products, and regulated medicinal products. EMA is implementing these concepts through substance, product, organization, and referential master-data services.

The operating-domain lens

Quality-system governance and controlled content

Risk that policies, procedures, specifications, instructions, forms, records, roles, and management oversight do not remain approved, current, available, attributable, and connected to the regulated work they govern. The crosswalk links 6 capabilities and 7 authority records.

Quality events, CAPA, change, and effectiveness

Risk that deviations, nonconformances, investigations, corrective and preventive actions, and changes are handled as isolated tickets rather than a controlled chain from detection through root cause, risk, implementation, and effectiveness review. The crosswalk links 6 capabilities and 7 authority records.

Audit, inspection, and evidence readiness

Risk that the organization cannot retrieve a coherent, accurate, and reviewable evidence chain for an auditor, inspector, certification body, notified body, or internal governance review without manual reconstruction. The crosswalk links 9 capabilities and 7 authority records.

Computerized systems, validation, and data integrity

Risk that a quality or regulatory system is not fit for intended use, remains insufficiently controlled through change, or cannot preserve complete, consistent, accurate, attributable, legible, contemporaneous, original, and available records across its lifecycle. The crosswalk links 7 capabilities and 5 authority records.

Supplier quality and external operations

Risk that suppliers, laboratories, contract manufacturers, service providers, and other external parties are selected, qualified, monitored, changed, and governed without sufficient evidence or connection to product and process risk. The crosswalk links 9 capabilities and 6 authority records.

Regulatory product and registration lifecycle

Risk that product, substance, device, market, registration, license, activity, authority, commitment, correspondence, and approval information is fragmented or too unreliable to support global regulatory decisions and market continuity. The crosswalk links 7 capabilities and 5 authority records.

Submission content and technical conformance

Risk that regulated content cannot be planned, authored, approved, assembled, validated, transmitted, received, and maintained in the correct format and lifecycle for the relevant authority and procedure. The crosswalk links 6 capabilities and 4 authority records.

Structured product data and labeling governance

Risk that medicinal-product, device, substance, pack, presentation, identifier, label, and artwork data is inconsistent across source systems, submissions, authority databases, markets, safety processes, and supply operations. The crosswalk links 7 capabilities and 4 authority records.

Complaints, post-market quality, and safety handoffs

Risk that complaints, adverse-event indicators, product-quality complaints, vigilance, field actions, recalls, post-market surveillance, and regulatory reporting are delayed or fragmented across quality, safety, medical, regulatory, and commercial systems. The crosswalk links 11 capabilities and 6 authority records.

How to use the crosswalk

Determine applicability with qualified owners, identify affected records and workflows, map each expectation to an accountable decision and retained evidence, then use capability and organization pages to frame a technology evaluation. A mapping is editorial navigation—not a conformity or legal conclusion.

Methodology

  1. Define the market boundary, exclusions, operating models, and capability taxonomy before classifying organizations.
  2. Require an approved official source for organization inclusion and each documented capability.
  3. Keep authority sources, provider claims, independent observations, editorial synthesis, and unknowns in separate evidence states.
  4. Use one primary operating model per organization while retaining adjacent scope in the narrative record.
  5. Preserve source URLs, review dates, material changes, limitations, and correction history.

Limitations

  • The maintained population is substantial but not claimed to be a complete global market.
  • Official public documentation may omit available capabilities or lag product and service changes.
  • Documented positioning does not measure product depth, configured availability, independent performance, implementation effort, customer outcome, or commercial terms.
  • Authority mappings are editorial research aids and do not establish buyer-specific applicability or product conformity.
  • No organization may purchase inclusion, classification, finding, or correction outcome.

Reproducibility and updates

The report is reproduced from the provider registry, normalized facts and evidence, authority and domain records, and the publication taxonomy. A material change requires a dated source and editorial explanation. Historical values remain available through the change ledger rather than disappearing when the current record changes.

Research boundary

RegQuality Review is not a regulator, certification body, law firm, or validation authority. Its records support research and decision review; they do not establish compliance for an organization, system, release, configuration, or intended use.