Academy→Quality→ISO 13485 — Medical Device Quality Management System
ISO 13485 — Medical Device Quality Management System
ISO 13485 is the international standard for Quality Management Systems in the medical device industry. It builds on ISO 9001 but adds mandatory requirements for design controls, risk management (ISO 14971), device history records, complaint handling, and post-market surveillance — all aimed at consistently producing safe and effective medical devices.
Why companies use it
- ·Required for CE marking under the EU Medical Device Regulation (MDR 2017/745) and IVDR (2017/746)
- ·Accepted by regulatory authorities worldwide including the FDA, Health Canada, and TGA as evidence of QMS compliance
- ·Customers (OEM medical device manufacturers) require ISO 13485 certification from their component and contract suppliers
- ·Provides the documented evidence framework needed to demonstrate device safety to notified bodies during audits
What hiring managers look for
- ·ISO 13485 signals that a candidate understands the heightened accountability of medical device quality — defects can harm patients
- ·Experience with design controls (DHF, DHR, DMR) shows ability to maintain the documentation trail regulators demand
- ·Familiarity with risk management per ISO 14971 is expected at any medical device company
- ·Candidates who have lived through a notified body audit understand the real burden of compliance, not just the theory
Typical interview questions
What are the key differences between ISO 9001 and ISO 13485?
Explain the relationship between ISO 13485 and ISO 14971 in a medical device development project.
What is a Design History File (DHF) and what must it contain?
How does the complaint handling process under ISO 13485 differ from a standard CAPA process?
Describe your experience preparing for or supporting an ISO 13485 notified body audit.
Common mistakes
- ·Treating ISO 13485 as "ISO 9001 with extra paperwork" — the validation, traceability, and risk requirements are fundamentally stricter
- ·Not linking design outputs back to design inputs in the DHF, leaving gaps auditors will flag
- ·Ignoring post-market surveillance — ISO 13485 requires an ongoing system, not a one-time check after launch
- ·Failing to classify complaints correctly — not every complaint triggers a mandatory adverse event report (MDR/EUDAMED), but missing one that does is a serious regulatory failure
- ·Applying ISO 14971 risk management as a gate review rather than as a continuous activity throughout the product lifecycle
Real engineering example
Related interview guides
Related topics
More in Quality
Preparing for an interview?
Browse our role-specific interview guides written by engineers who know what hiring managers at ASML, NXP, and Philips look for.
Browse Interview Guides →