ISO 13485 systems built to survive FDA-aligned customer audits
AQM is the quality partner for medical-device manufacturers, contract manufacturers, sterilization providers, and IVD operations — building QMS that satisfy ISO 13485 certification AND the FDA-aligned customer audits that decide whether you keep the supply agreement. Built on more than 25 years of QM experience anchored in Southern California's medical-device cluster: Orange County, San Diego, and the Inland Empire.
ISO 13485 is the entry point. Surviving an FDA-aligned customer audit at your Class II contract manufacturer is the test. We engineer for the test.
Supporting life science organizations across Southern California's med-tech corridor
The Medical-Device Corridor
Who We Serve in the Medical Device Cluster
The medical-device supply chain is layered — device makers, contract manufacturers, sterilization providers, and the IVD ecosystem all need ISO 13485, but they read the standard differently. Find your operational profile below.
Class I/II/III Device Manufacturers
The companies whose name is on the device. Whether you are a Class I exempt manufacturer, a Class II 510(k) operation, or a Class III PMA company, ISO 13485 is the baseline QMS. Your audits will probe design controls (Design History Files), risk management (ISO 14971), CAPA, and post-market surveillance. We build the QMS so each holds up under FDA-aligned audit pressure.
- Rigorous Design History File (DHF) configuration control
- Full lifecycle Risk Management integration (ISO 14971)
- Aligned post-market surveillance and adverse event loops
Contract Manufacturers (CMOs)
Building devices on behalf of someone else. The audit pattern flips: your customers' QA teams audit you the way the FDA audits them. Customer supplier audits hit hardest on traceability, lot control, change management, and complaint flow-up. ISO 13485 plus disciplined customer-spec management is the architecture we build for.
- Meticulous lot, batch, and unique device identification (UDI) traceability
- Strict change-control management preventing unauthorized deviations
- Fast integration with customer complaint and CAPA systems
Sterilization & Processing Providers
Ethylene oxide, gamma, e-beam, and contract sterilization operations. ISO 13485 plus process validation expectations (often layered with ISO 11135, 11137, 17665) define the audit conversation. We focus on process validation discipline and the change-control records that demonstrate continuous compliance.
- Integration of specialized sterilization standards (ISO 11135/11137)
- Indestructible equipment calibration and software validation trails
- Documented parameter control charts and validation records
IVD & Diagnostics Manufacturers
In vitro diagnostic manufacturers, including molecular and point-of-care. ISO 13485 + EU IVDR + customer-specific quality agreements layer together. Audits get sharp on reagent traceability, software-of-medical-device (when applicable), and clinical-evaluation evidence.
- Absolute reagent lot, cold-chain, and raw materials traceability
- Software validation and cybersecurity risk integration
- EU IVDR compliance documentation and clinical file readiness
Standards & Adjacent Expectations
ISO 13485 is our service. These are what it has to align to.
AQM consults on ISO 13485 — the QMS standard for medical-device organizations. But ISO 13485 doesn’t live in isolation. We build those adjacent FDA, ISO 14971, and EU alignments directly into your QMS. We do NOT perform FDA submissions or 510(k) work — that is a regulatory affairs scope, separate from QMS building.
ISO 13485 Consulting
Complete QMS design, documentation drafting, internal auditing, and pre-assessment readiness for medical device manufacturers, CMOs, and sterilizers. We guide you from greenfield baseline directly through registrars and Notified Body audits.
FDA QSR Alignment
We bake FDA Quality System Regulation (21 CFR Part 820 / QMSR) requirements directly into your ISO 13485 procedures — design controls (820.30), CAPA (820.100), and supplier controls (820.50). Satisfy FDA investigators and ISO auditors from a single system.
Risk Management Integration
We map active ISO 14971 risk files to drive your design controls, production choices, and CAPA priorities. Ensure risk evaluations are a functional operational discipline, not just static paperwork stored for audit day.
EU MDR & IVDR Alignment
We build structural QMS pathways that pass European Notified Body audits under MDR (devices) and IVDR (diagnostics), ensuring post-market surveillance (PMS), clinical evaluations, and UDI parameters align flawlessly.
Customer Audit Readiness
What Your Customer’s QA Team Actually Probes
If you are a contract manufacturer, your customers audit you the way the FDA audits them. If you are a device maker, the FDA may audit you directly, and your customers’ QA teams will audit you regardless. Across more than 25 years of QM experience inside the Southern California medical-device cluster, we’ve watched these audits focus heavily on these six points.
1. Design History File (DHF) completeness
Every product, every revision, traceable from user need to verification to validation to manufacturing transfer. Gaps in the DHF are gaps in the audit conversation. We build DHF discipline into design controls, not as an afterthought.
2. Risk management file integration (ISO 14971)
Risk analyses that drive design controls and CAPA priorities — not separate documents stored for audits. Auditors look for the connection between risk file and operational decisions.
3. CAPA discipline & effectiveness
CAPA is consistently the top observation category in FDA Form 483s. Auditors probe whether root causes are identified specifically, whether corrective actions actually close the loop, and whether effectiveness checks verify the change held. We build RCCA depth and effectiveness verification into the CAPA process.
4. Supplier control records (820.50)
Your suppliers’ QMS records have to support yours. Customer auditors probe supplier qualification, supplier change notification, and incoming inspection. We engineer supplier control programs that prove flow-down of requirements without overburdening procurement.
5. Complaint handling & post-market surveillance
Complaint records, MDR/Vigilance reporting, post-market signals feeding back into design and CAPA. Auditors look for the loop closing — not just complaint files sitting in isolation.
6. Training records & competency qualifications
Especially for design, manufacturing, and quality roles. Auditors look for documented training tied to specific procedures, with effectiveness checks. "Read and acknowledge" sign-offs don’t survive scrutiny anymore.
A typical decade with a medical-device client
AQM's medical-device clients usually engage us across product cycles, not single certifications. The arc below sketches the typical pattern.
Year 1 — ISO 13485 first certification
Six to nine months of consulting through gap analysis, QMS build, design-controls documentation, CAPA process design, internal audits, and the certification body audit. The deliverable is the certificate; the foundation is a QMS that has to hold up to customer supplier audits and (where applicable) FDA inspections.
Year 2 — First surveillance + first customer supplier audit
Surveillance from the certification body, often paired with a customer QA team's supplier audit. Most clients retain us through both. The surveillance is light; the customer supplier audit is where the depth gets tested.
Year 2–3 — New product introduction (NPI)
A new product launches. New Design History File. New risk analyses. New CAPA flows. The QMS holds, but the implementation discipline has to scale to the new product. Most NPI cycles use AQM for documentation review and pre-launch internal audits.
Years 3–5 — Multi-product maintenance + customer scaling
Annual internal audits, surveillance audit prep, complaint trend analysis, supplier-control reviews, training refreshes. Sometimes a new sterilization provider or contract manufacturer comes online and needs to be qualified. The retainer becomes a steady rhythm.
Year 6+ — Recertification, EU MDR/IVDR, and new markets
The three-year recertification hits. By now most clients are in two or three certifications, often expanding into a new prime customer or new process. The relationship continues because the regulatory environment keeps moving.
Medical-Device Questions We Hear Most
No. AQM consults on ISO 13485 QMS implementation, internal auditing, and training. FDA submissions are a regulatory affairs scope — different specialty, different professionals. We work alongside the RA team you hire (or recommend one) to ensure the QMS we build aligns with the submission story.
They're closely aligned but not identical. ISO 13485 is the international QMS standard for medical-device organizations. FDA QSR (21 CFR 820) is the US-specific regulation. About 90% of the content overlaps. The differences are in language, in some specific record requirements, and in management responsibility framing. We build QMS that satisfy both simultaneously — you don't run two parallel systems.
MDR (devices) and IVDR (diagnostics) layer on top of ISO 13485 with additional requirements on clinical evaluation, post-market surveillance, unique device identification (UDI), and Notified Body interactions. We build ISO 13485 with MDR/IVDR alignment baked in — you don't need a separate QMS for EU vs. US markets.
ISO 14971 is the risk management standard. ISO 13485 references it as the expected risk framework. Your risk management file (RMF) feeds into design controls, CAPA prioritization, and post-market signals. We design the integration during the QMS build — not as a separate document set.
The pattern is similar; the rhythm is different. Customer audits happen more frequently (often annually) and probe how their product specifically is being made. The questions are sharper on lot traceability, complaint flow-up to the customer, change management discipline, and specific procedural conformance. FDA audits are less frequent but go deeper on systemic CAPA and design-control discipline. We build QMS that satisfy both rhythms.
Often, yes — especially if you supply to higher-class device makers, sell into EU markets, or sell to large hospital systems. Class I exempt status removes 510(k) submission requirements but rarely removes customer demands for ISO 13485 certification. We'll tell you on the first call whether your customer base will likely require it.
Six to nine months from kickoff to the certification body audit, similar to other ISO certifications. Greenfield manufacturers without an existing QMS land on the longer end; companies upgrading from ISO 9001 to ISO 13485 are often faster. Class III manufacturers and multi-product organizations may take longer due to DHF and risk-file scope.
Get Started
The medical-device conversation usually starts with classification
Tell us what your product is, who classifies it (FDA, EMA, customer), where it's manufactured, and what certifications you have or need. We'll map ISO 13485 against your real customer audit pattern. No quote on the call — we'll send a scoped proposal within a week if we're the right fit.