Overdue Calibration Finder

ISO 13485: what it asks of a calibration register

ISO 13485 7.6 asks for calibration or verification at set intervals or before use against traceable standards, documented procedures, recorded adjustments, visible status, and, where equipment turns out not to conform, an assessment and record of whether earlier results are still valid and action on any product affected.

Named, not quoted: 21 CFR 820, the US quality system regulation for medical devices.

Findings that cite it

FindingClause
1. Overdue: the due date worked out is earlier than the as-at dateISO 13485 7.6
3. No due date can be worked out: no interval or no last calibration recordedISO 13485 7.6
4. Out of tolerance as found, with no impact assessment recordedISO 13485 7.6
ISO 13485 8.3.1
ISO 13485 8.5.2
5. Overdue and used for product acceptanceISO 13485 8.3.1
7. Traceability not recorded in this registerISO 13485 7.6
8. Calibrated in house with no procedure namedISO 13485 7.6
9. Certificate reference not recorded in this registerISO 13485 4.2.5
10. Lost, quarantined or out of service but marked for product acceptance, or lost with no impact assessmentISO 13485 8.3.1

ISO 13485: every clause cited

4 of the 67 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the standard verbatim.

ISO 13485 4.2.5Control of records

Records are kept to show that requirements have been met and that the quality management system is operating effectively. A documented procedure sets the controls needed for identifying, storing, securing and keeping the integrity of records, for retrieving them, for how long they are retained and for their disposition. The organization defines and applies ways of protecting confidential health information held in records, in line with the regulatory requirements that apply. Records must stay legible, easy to identify and retrievable, and any change to a record must remain identifiable. The organization keeps records for no less than the device lifetime the organization has defined, or longer where regulatory requirements say so, and in any case for no less than two years after the organization released the device.

What a certification body auditor asks to see: Records control procedure with retention schedule; Retention periods justified against defined device lifetime and regulatory minima; Method for protecting confidential health information in complaint, clinical and servicing records; Evidence of record integrity controls (audit trails, change identification) for electronic records
Where registers usually fall short: Retention set at a flat number of years that is shorter than the device lifetime; Health information in complaint files handled with no defined protection; Corrections to records overwrite the original value
Source: ISO 13485:2016, medical device quality management
ISO 13485 7.6Control of monitoring and measuring equipment

The organization decides what monitoring and measuring must be done, and what equipment is needed, to give evidence that product conforms, and documents procedures so that monitoring and measuring can be, and actually are, done in a way consistent with the requirements. Where valid results depend on it, measuring equipment is: calibrated or verified, or both, at set intervals or before use, against measurement standards that trace back to national or international standards (if none exist, whatever basis is used for calibration or verification is recorded); adjusted or re-adjusted as needed, with each adjustment recorded; identified so its calibration status can be seen; protected from adjustments that would invalidate the results; and protected from damage and deterioration. Calibration and verification are done according to documented procedures. If equipment turns out not to conform, the organization assesses and records whether earlier measurement results are still valid, and acts on the equipment and on any product affected. Records of calibration and verification are kept. The organization also documents procedures for validating software used in monitoring and measuring, applied before first use and after any change, in proportion to the risk, including the effect on product conformity, and keeps records of the validation results, conclusions and actions.

What a certification body auditor asks to see: Monitoring and measuring equipment register with calibration status and intervals; Calibration procedures and records with traceability to national or international standards; Out-of-tolerance investigation records assessing previous results and affected product; Validation procedure and records for measurement and test software
Where registers usually fall short: Out-of-tolerance findings closed by recalibration with no impact assessment on product measured since the last good calibration; Test software and automated inspection systems never validated; Equipment used before initial calibration
Source: ISO 13485:2016, medical device quality management
ISO 13485 8.3.1Control of nonconforming product: general

The organization makes sure product that fails to meet requirements is identified and controlled so it is not used or delivered by mistake. A documented procedure sets the controls, and the responsibilities and authorities, for identifying, documenting, segregating, evaluating and disposing of nonconforming product. Evaluating a nonconformity includes deciding whether an investigation is needed and whether any outside party responsible for the nonconformity must be told. Records are kept of what each nonconformity was and of the action taken afterwards, covering the evaluation, any investigation and the reasons behind the decisions made.

What a certification body auditor asks to see: Nonconforming product procedure defining responsibilities and authorities; Nonconformance records covering identification, segregation, evaluation, investigation decision, external notification decision, disposition and rationale; Evidence of physical segregation or equivalent control
Where registers usually fall short: Rationale for disposition decisions not recorded; Supplier-caused nonconformities not notified to the supplier; Nonconforming product held in the same location as conforming stock with only a label
Source: ISO 13485:2016, medical device quality management
ISO 13485 8.5.2Corrective action

The organization acts to remove the causes of nonconformities so they do not happen again. It does this promptly and in proportion to the effects of the nonconformities found. A documented procedure sets the requirements for: reviewing nonconformities, complaints included; finding what caused them; deciding whether action is needed so they do not recur; planning, documenting and carrying out the action required, updating documentation where appropriate; checking that the action does not harm regulatory compliance or the device's safety and performance; and reviewing whether the corrective action worked. Records are kept of investigation results and of the action taken.

What a certification body auditor asks to see: Corrective action procedure covering all listed elements; Corrective action records with cause analysis, action plan, verification of no adverse effect on regulatory compliance or device safety and performance, and effectiveness review; Timeliness evidence proportionate to the effect of the nonconformity
Where registers usually fall short: Corrective action closed on implementation with no effectiveness review; No check that the action itself does not create a new risk or regulatory impact; Complaints excluded from the corrective action review
Source: ISO 13485:2016, medical device quality management