# Quality Manual Development Guide Research basis: **2026-07-23**, extended **2026-07-26** for laboratory lanes. This guide explains an evidence-controlled authoring process. It does not reproduce standard text or prescribe a universal manual format. The authoring process applies to any management-system documentation this skill covers. Where it says "QMS scope," a laboratory's equivalent is the **scope of laboratory activities** — per location and per method or examination — and a laboratory manual should point to the accredited scope schedule rather than restate it. Read `references/iso-17025.md` or `references/iso-15189.md` alongside this guide. ## Boundary and copyright A quality manual template cannot establish an effective QMS, conformity, certification, FDA compliance, MDSAP acceptance, EU conformity, or legal applicability. It cannot replace authorized management, RA/QA, legal, notified-body, regulatory-authority, MDSAP Auditing Organization, or certification-body decisions. ISO publications are copyrighted. Obtain ISO 13485 from [ISO](https://www.iso.org/standard/59752.html), a national member, or an authorized source. Do not paste standard text into the manual. Summarize the organization's actual processes and reference its controlled authorized copy. ## Purpose of a manual A useful manual or equivalent policy architecture: - identifies the approved QMS scope; - identifies controlled processes and their interactions; - states governance, authorities, and responsibilities; - explains the documentation/evidence hierarchy; - points to organization-specific controlled procedures and records; and - distinguishes the applicable standard, regulatory, audit, and product sources. The manual should be the length and structure needed for the organization. Page count, a fixed procedure list, or mirroring standard headings does not prove adequacy. ## Development workflow ### 1. Establish an authorized source baseline Create a controlled source ledger before drafting. At minimum record: - ISO 13485:2016, Edition 3, and authorized location; - the applicable EN adoption/amendment/corrigendum if European harmonisation is being used; - current FDA QMSR/eCFR sources if U.S. operations are in declared scope; - current MDSAP Audit Approach if MDSAP is in declared scope; - current consolidated MDR or IVDR, OJEU harmonised-standard decisions, and relevant MDCG guidance if EU work is in declared scope; - ISO 14971/EN A11 and product-specific standards where applicable; and - current product/jurisdictional regulations and guidance. For each source, capture publisher, title, edition/version/date, official URL or authorized location, access date, owner, currency-review date, impact assessment, status, and approval. ### 2. Freeze purpose and scope Record: - legal entities and sites; - product types/families and controlled intended-use references; - lifecycle activities performed at each site; - outsourced processes and interfaces; - markets being considered; - organizational and physical boundaries; - assurance purpose (ISO certification, FDA, MDSAP, EU, internal); and - limitations and unresolved applicability decisions. Do not let an agent decide applicability. `Undetermined` remains a blocker until an authorized human approves a decision and rationale. ### 3. Map actual process interactions Interview accountable process owners and inspect actual records. Build a process map from the organization's work—not from copied standard headings. For each process record: - inputs and outputs; - owner, authority, delegate, and escalation; - controlled procedure/system; - implementation records; - interfaces to risk and change control; - measures and review method; - source/version basis; - status and approval. Include management, support, product lifecycle, assurance, feedback, and improvement processes. Show how complaints/postmarket data update risk, design, production, suppliers, CAPA, and management review. ### 4. Build a controlled cross-reference Create a matrix that links manual statements to: - controlled procedure IDs and revisions; - forms and record series; - product/device/technical files; - risk and traceability evidence; - system/software validation; - process owners and approvals; - source/version criteria; and - open gaps/change/CAPA records. Do not describe a referenced document as effective until its approval, effective date, training, and availability are evidenced. ### 5. Draft policy-level content Use the fail-closed template in `assets/templates/quality-manual-template.md`. Keep statements factual and organization-specific: - “The approved process is defined in ``.” - “Evidence is retained in ``.” - “`` owns the decision, with approval in ``.” - “Applicability remains undetermined pending ``.” Avoid: - “The organization is compliant” or “audit ready”; - “This template satisfies ISO/FDA/EU requirements”; - generic quality policies presented as approved; - fixed timelines or retention periods without source/risk basis; - unsupported “not applicable” statements; - old QSR clause maps presented as current QMSR; and - claims that an ISO certificate covers FDA, MDSAP, or EU product conformity. ### 6. Review against evidence Perform independent review in two directions: 1. **Manual to evidence:** every material statement points to a current controlled source, procedure, owner, and record set. 2. **Evidence to manual:** sampled implementation records match the described scope, roles, interactions, and controls. Sample across products, sites, shifts/time periods, suppliers, systems, changes, and risk as justified. Record limitations and open gaps. ### 7. Approve, train, release, and maintain Before release: - resolve placeholders; - obtain technical, RA/QA, document-control, and authorized management approvals; - complete source and applicability reviews; - close or formally control open document/process gaps; - approve process map and cross-reference; - complete affected-person training; - verify controlled point-of-use access; - assign effective date and obsolete prior revisions; and - record maintenance/currency-review triggers. Review when products, sites, roles, processes, suppliers, systems, standards, regulations, audit programs, certificates, or postmarket evidence change—not only on an arbitrary calendar date. ## Suggested content architecture ### Controlled-document front matter Include document ID, revision, owner, status, effective date, confidentiality, controlled location, change record, superseded revision, reviewers, approvers, dates, and approval evidence. ### Purpose, limits, and definitions State the intended organizational use and hard boundaries. Use definitions from approved organizational and regulatory sources; do not copy protected standard text. ### QMS scope and applicability State entities, sites, products, activities, outsourced processes, and interfaces. Reference the approved scope/applicability intake. List unresolved decisions as blockers. ### Source/version basis Identify exact ISO, FDA, MDSAP, EU, and product sources separately. Include owner and currency-review controls. ### Governance and roles Describe top-management authority, authorized management representative, RA/QA, process owners, document/record control, release authorities, audit independence, complaint/reportability roles, CAPA/change approval, delegates, and escalation. ### Process architecture At a policy level, describe and cross-reference: - document/record/external-source control; - risk management; - design/development and transfer/change; - suppliers and outsourced processes; - production, service, acceptance/release, and traceability; - process/equipment/test/software validation; - feedback, complaints, postmarket, and vigilance; - nonconformity, CAPA, and effectiveness; - internal audit and management review; - competence/training; and - integrated change control. ### Product evidence architecture Explain how product/family files point to requirements, specifications, risk, design, validation, production, release, distribution, clinical/performance, postmarket, complaint, vigilance, and change evidence. Preserve jurisdiction-specific records rather than claiming one file concept replaces another. ### Appendices Use controlled appendices or references for: - procedure/record index; - source ledger; - scope/product/site register; - organization chart/authorities; - process interaction map; - risk-design-production-postmarket traceability matrix; - supplier/outsourced-process register; - validation/software inventory; - open gap/change/CAPA register; and - certificate/audit scope and status register. ## Regime-specific cautions ### FDA QMSR QMSR became effective **2026-02-02**. Describe current Part 820 and relevant FDA processes; do not present the former QSR/QSIT structure as current. Link to current [21 CFR Part 820](https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-820) and [Compliance Program 7382.850](https://www.fda.gov/media/80195/download?attachment). An ISO certificate does not exempt a manufacturer from FDA inspection. ### MDSAP Reference current **MDSAP AU P0002.010** (2026-02-02) and declared participating jurisdictions. Do not describe an ISO-only audit as MDSAP or an FDA inspection as using the MDSAP plan. ### EU MDR/IVDR Reference the current consolidated regulation, applicable conformity-assessment route, technical documentation, postmarket/vigilance, economic-operator, and notified-body evidence separately. Verify notified-body designation scope in NANDO. MDCG guidance is nonbinding and must be version-controlled. ### Certification and accreditation Record the certification body's scope and, if accredited certification is sought, the accreditation scope relevant to ISO 13485 technical areas. This does not establish notified-body designation or product conformity. For a laboratory, the manual describes a system that an accreditation body assesses — the laboratory is accredited, not certified, and the manual must not say otherwise. Record the accreditation body, the scope schedule reference, authorized signatories and what each may sign, and the rules for using accreditation symbols and endorsement wording. Verify current recognition-arrangement phrasing before reproducing it: Global Accreditation Cooperation Incorporated replaced ILAC and IAF on 2026-01-01, so legacy "ILAC MRA" or "IAF MLA" wording may be transitional rather than current. ## Review questions - Does the scope match actual sites, products, and activities? - Are all applicability decisions owned and approved by authorized humans? - Does every statement link to current controlled evidence? - Are records sampled, not just procedures listed? - Are risk, design, production, suppliers, validation/software, and postmarket connected? - Are complaint/vigilance and CAPA decisions owned by authorized roles? - Do changes link to validation, training, source/version, and product impacts? - Are ISO, FDA, MDSAP, EU, and product-specific claims clearly separated? - Are certificate, notified-body, and accreditation scopes accurately bounded? - Does the manual avoid compliance, conformity, certification, and readiness claims? Use `scripts/gap_analyzer.py` and `scripts/validate_evidence_manifest.py` only to identify structural gaps before substantive human review.