REGQUALITYREVIEW

Evidence for systems that carry regulated work.

Operating domain

Operating domain: Quality-system governance and controlled content

Risk that policies, procedures, specifications, instructions, forms, records, roles, and management oversight do not remain approved, current, available, attributable, and connected to the regulated work they govern.

What this domain asks

Risk that policies, procedures, specifications, instructions, forms, records, roles, and management oversight do not remain approved, current, available, attributable, and connected to the regulated work they govern.

The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.

Buyer questions

  • Which content and record types are authoritative in the proposed system, and which remain in another repository?
  • How are effective dates, supersession, periodic review, distribution, controlled copies, and archival governed?
  • How does a document change identify affected training, forms, processes, products, markets, and open records?
  • Can the organization export readable content, metadata, audit trails, relationships, and signatures without vendor assistance?
  • What evidence supports electronic-signature, audit-trail, access-control, and record-retention behavior for the intended use?
  • Which governance decisions remain configuration, SOP, and human responsibilities rather than product controls?

Mapped workflows

Controlled Documents

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for controlled documents within this domain.

Training Management

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for training management within this domain.

Change Control

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for change control within this domain.

Audit And Inspection Management

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for audit and inspection management within this domain.

Computerized-System Validation Support

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for computerized-system validation support within this domain.

Analytics And Management Review

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for analytics and management review within this domain.

Authority context

FDA QMSR

The QMSR amends FDA's device current good manufacturing practice requirements in 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, while retaining FDA-specific statutory and regulatory requirements. FDA began using a new device inspection process when the rule became effective.

FDA 21 CFR Part 11

Part 11 defines criteria under which FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records trustworthy, reliable, and generally equivalent to paper records and handwritten signatures.

FDA drug CGMP

Parts 210 and 211 establish current good manufacturing practice requirements for drug manufacture, processing, packing, and holding, including organization, facilities, equipment, components, production controls, laboratory controls, records, reports, returned products, and complaints.

ISO 13485:2016

ISO 13485 specifies quality-management-system requirements for organizations involved in one or more stages of the medical-device lifecycle and emphasizes regulatory requirements, risk-based processes, supplier control, documentation, and product realization.

ICH Q10

ICH Q10 describes a pharmaceutical quality-system model across development and commercial manufacturing, including management responsibilities, process and product monitoring, CAPA, change management, management review, knowledge management, and quality risk management.

EU GMP Chapter 4

Chapter 4 describes expectations for the generation, control, review, approval, distribution, maintenance, and retention of GMP documentation and records, including paper, electronic, photographic, and other media.

EU GMP Annex 11

Annex 11 applies GMP principles to computerized systems and addresses lifecycle risk management, personnel, suppliers, validation, data, accuracy checks, storage, printouts, audit trails, change control, incident management, periodic evaluation, security, signatures, continuity, and archiving.

Relevant operating models

Evidence boundary

RegQuality Review is not a regulator, certification body, law firm, or validation authority. Its records support research and decision review; they do not establish compliance for an organization, system, release, configuration, or intended use. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.