Leaders in the Two Standards
Every Device Company Runs On
ISO 13485 defines the quality management system a medical device company operates; ISO 14971 defines the risk management that runs through every decision inside it. Neither works alone: a 13485 system without living risk management is paperwork, and a risk file without a QMS to act on it is analysis. Auditors, notified bodies, and now FDA read them as one interlocking machine. We implement, certify, and repair that machine for device and IVD companies at every stage.

Device quality standards exist because the failure mode is not a recall notice. It is a patient.
Every major clause of 13485 has a 14971 counterpart it cannot function without. Auditors probe exactly these seams, because a gap here means the system is two binders pretending to be one machine.
Design inputs, outputs, verification, validation, and transfer under control.
Hazards identified before design freezes; risk controls become design inputs, verified like any other.
Validated processes, controlled conditions, traceability through the DHR.
Manufacturing risk analyzed with the same rigor as design risk, driving validation depth and controls.
Corrective and preventive action with root cause and effectiveness checks.
Every CAPA asks whether the risk file was wrong: new hazard, underestimated severity, or a control that failed.
Post-market feedback, complaint handling, and reporting into the QMS.
Field data flowing back into the risk file on a defined cadence, with benefit-risk re-confirmed, not assumed.

ISO 14971 done right shows up in the drawings, not just in the file.
FDA’s Quality Management System Regulation replaced the old Quality System Regulation, incorporating ISO 13485:2016 by reference. One harmonized standard now anchors your FDA inspections, your notified body audits, and your MDSAP certificate — which makes doing it well a single, compounding investment.
FDA-specific requirements remain layered on top: records for complaints and servicing, UDI, and FDA’s own definitions where they differ.
Inspections anchor to 13485’s clause logic, management responsibility gets sharper teeth, and risk-based thinking stops being an EU-only expectation.
A certificate is not a transition. Companies that mapped clauses on paper but never operationalized risk-based thinking are the first findings of the QMSR era.
One QMS, honestly built, now serves FDA, Europe, and MDSAP jurisdictions at once. Redundant procedures can finally be retired.

Built so the parallel procedures can finally be retired, not maintained twice.
When a notified body or FDA investigator pulls your risk management file, they are checking that seven things exist, connect, and stay alive. Most findings trace to one of them being a snapshot instead of a system.
Scope, criteria for acceptability, and responsibilities — written before the analysis, not reverse-engineered after.
Systematic, device-specific hazards and hazardous situations, including reasonably foreseeable misuse.
Severity and probability assigned with a defensible method, at the level of harm, not just failure mode.
Inherent safety first, then protective measures, then information for safety — with verification of each control’s implementation and effectiveness.
Individual and overall residual risk judged against the plan’s criteria, with the benefit-risk rationale written down.
The synthesis: plan executed, criteria met, residual risk acceptable — signed by someone accountable.
The clause that fails most audits: field data actually flowing back into the file, on a cadence, changing conclusions when it should.

The most common 14971 finding is a perfect risk file that stopped learning the day it was signed.
For companies pursuing first certification — or rebuilding after a bruising audit — the route is known. What we add is pace, sequence, and the judgment of people who have walked it dozens of times.
Current state against 13485 and 14971, clause by clause, honestly graded.
The document structure and risk framework designed for your size and class.
Procedures and risk files written with the teams who will own them.
The system runs long enough to generate real records — auditors need evidence, not intentions.
A full-system shakedown by our auditors before the registrar’s stage 1.
Stage 1 and stage 2 supported on-site, findings answered, certificate landed.

Stage 1 and 2 prepared, findings answered, the certificate on the wall.
Your leads are device quality veterans: former quality heads and lead auditors who have built 13485 systems from scratch, defended them in notified body and MDSAP audits, and written 14971 files for devices from class I to implantables.
Certified lead auditors who know exactly which seams a registrar or FDA investigator will probe first.
A class IIb implant and a class I instrument need different depth. We size the system to the risk, not the template.
Transition experience on both sides of February 2026 — including the FDA-specific layers a 13485 certificate does not cover.
Risk work done with your engineers at the bench, not to them from a spreadsheet.

13485 and 14971 sit at the center of a device company’s regulatory life. These are the services most often engaged alongside them.
The full ISO 14971 discipline — files, FMEAs, and the living loop — as its own engagement.
Explore Risk →The right-sized quality system build that a 13485 certificate then formalizes.
Explore QMS →The European regulation your 13485 system must carry — technical files, PMS, and notified body strategy.
Explore EU MDR →Tell us where you stand — pursuing first certification, transitioning to QMSR, or repairing a system that grew apart from its risk file. We’ll match you with a senior device quality lead, with a response within one business day. All inquiries are strictly confidential.