4 Changed after its last passing verification
The requirement was last changed after the date of its latest passing verification, so the pass was recorded against an earlier version. Many teams call this a suspect link. It is a signal, not proof: a later change means the pass may no longer apply, and the reviewer decides whether the change is substantive, editorial or already covered, and records it.
- the test
- a requirement whose revision differs from the revision its latest pass was run against (when both are pasted), or else whose last-changed date is strictly later than the date of its latest passing verification
- the question
- What changed on that date, was the impact on the verification assessed, and has it been re-verified or the decision not to re-verify recorded?
- asked of
- the requirement owner
- columns it reads
- Last Changed, the result dates and Revision and the results: Requirement Revision
A signal, not proof: a later change means the pass may no longer apply, and the reviewer decides whether the change is substantive, editorial or already covered (the review sheet has a column for it). Where the requirements carry a revision and the results the revision each test ran against, the revisions are compared instead of dates, and the line says which was used. By date it is strictly later: the same day is not raised, and only the date of a time is read. See suspect links.
The clauses behind it, by standard
each shown when you tick its standard- ISO 26262: Part 8, 6.4.3 and Part 8, 8.4.5
- IATF 16949: 8.3.6.1
- IEC 62304: 5.6.6 and 5.7.3
- ISO 13485: 7.3.9
- FDA QMSR: 820.10 and 820.35
- AS9100D: 8.3.6
The clause text
Changes to design and development are controlled through documented procedures. For each change the organization judges how significant it is for the device and its intended use, looking at function, performance, usability, safety and the regulatory requirements that apply. Every change is identified, then reviewed, verified, validated where appropriate and approved before it is put into effect. The review of a change weighs its effect on constituent parts, on product being made or already delivered, on the inputs and outputs of risk management, and on the processes used to realize the product. The organization keeps records of each change, of its review and of any actions the review found necessary.
Held text: ISO 13485:2016, our statement of the clause, not the instrument verbatim.
what an assessor asks to see Design change procedure with a significance assessment covering function, performance, usability, safety and regulatory impact; Change records showing review, verification, validation and approval before implementation; Evaluation of effect on parts, product in process, delivered product, risk management and realization processes; Regulatory assessment of whether the change requires notification or approval
where it usually breaks Significance assessed only for regulatory notification, not for safety or usability; Effect on delivered product never evaluated; Changes implemented in production before verification is complete
Section 820.10 establishes the substantive QMS requirements by incorporating ISO 13485:2016 SECTIONS 4 THROUGH 8 in full. Manufacturers must implement: ISO 13485:2016 SECTION 4 General QMS requirements + documentation (Quality Manual + Medical Device File + control of documents + records); SECTION 5 Management responsibility + customer focus + quality policy + planning + responsibility / authority / communication + management review; SECTION 6 Resource management (provision of resources + human resources + infrastructure + work environment + contamination control); SECTION 7 Product realization (planning + customer-related + design and development - the medical-device 'design controls' parallel + purchasing + production and service provision + control of monitoring + measuring equipment); SECTION 8 Measurement + analysis + improvement (monitoring + measurement + control of nonconforming product + analysis of data + improvement - including CAPA Sections 8.5.2 + 8.5.3). NB: ยง820.10 also clarifies that ISO 13485:2016 internal-audit + management-review requirements (Sections 8.2.4 + 5.6) apply to the QMSR.
Held text: 21 CFR Part 820 (QMSR), our statement of the clause, not the instrument verbatim.
what an assessor asks to see ISO 13485 Section 4-8 compliance file; Internal audit programme + records; Management review records + frequency; Cross-reference matrix between QMSR + ISO 13485 + EU MDR/IVDR + FDA Part 11
where it usually breaks ISO 13485 implemented in parts without full Section 4-8 coverage; Internal audit infrequent or scope-limited; Management review absent + meeting minutes incomplete
Section 820.35 establishes FDA-specific record-control requirements that supplement ISO 13485:2016 Section 4.2.5. SPECIFIC REQUIREMENTS: (a) RECORD RETENTION - records must be retained for a period of time equivalent to the design + expected life of the device + IN ANY CASE NOT LESS THAN 2 YEARS FROM THE DATE OF RELEASE FOR COMMERCIAL DISTRIBUTION BY THE MANUFACTURER. (b) AUDIT TRAIL - records must include audit trail meeting the criteria of FDA 21 CFR Part 11 (Electronic Records + Electronic Signatures) where electronic records are maintained - the audit trail must be: secure + computer-generated + time-stamped + tamper-evident + record who-what-when-where-why for every CRUD operation on regulated records. (c) UNIQUE DEVICE IDENTIFICATION (UDI) - records must include UDI per FDA Unique Device Identification Rule (21 CFR Part 830) where applicable - UDI on labelling + linked to records. (d) MEDICAL DEVICE REPORTING (MDR) - records of MDR submissions under 21 CFR Part 803 (Medical Device Reporting) must be maintained as part of QMSR records. (e) CORRECTIONS AND REMOVALS - records of corrections + removals under 21 CFR Part 806 must be maintained. (f) ACCESSIBILITY - records must be ACCESSIBLE TO + READILY AVAILABLE FOR REVIEW BY FDA inspectors during inspections; manufacturers must provide records in human-readable + electronic form within reasonable time upon FDA request.
Held text: 21 CFR Part 820 (QMSR), our statement of the clause, not the instrument verbatim.
what an assessor asks to see Record-retention policy specifying device-life-or-2-year-minimum + FDA inspection-readiness; Audit trail Part 11 conformance test + design specification; UDI traceability per Part 830; MDR + Part 806 records retention
where it usually breaks Records retention shorter than 2 years from commercial distribution release; Audit trail not Part 11 compliant; UDI traceability gap; MDR + Part 806 records not retained or not inspection-ready
Changes made during or after design and development are identified, reviewed and controlled to ensure no adverse impact on conformity, with documented information retained on the changes, review results, authorization and actions taken to prevent adverse impacts; 9100 adds a process with criteria for notifying the customer before implementation of changes affecting customer requirements, and that design changes are controlled under the configuration management process.
Held text: AS9100D, our statement of the clause, not the instrument verbatim.
what an assessor asks to see Design change records with review, authorization and impact actions.; Customer notification criteria and records.; Configuration management linkage.
where it usually breaks Changes affecting customer requirements implemented without prior notification.; Design changes outside configuration control.
Once a product has had its first approval, every design change, supplier proposals included, is assessed for its possible effect on fit, form, function, performance and durability, is validated against customer requirements and is approved inside the organization before it is put into production. If the customer requires it, the organization first obtains documented approval from the customer, or a documented waiver. For products that contain embedded software, the change record documents the revision levels of both the software and the hardware.
Held text: IATF 16949:2016, our statement of the clause, not the instrument verbatim.
what an assessor asks to see Change evaluation and internal approval records before implementation.; Customer approvals or waivers where required.; Software and hardware revision levels in change records.
where it usually breaks Supplier-proposed changes implemented without evaluation.; Software revision not recorded with the change.
Safety requirements are managed under configuration and change management with traceability to their source and to their verification, and are verified for correctness, completeness and consistency against the level above. Requirement text not held.
Held text: ISO 26262:2018, our statement of the clause, not the instrument verbatim.
what an assessor asks to see Requirements management tool records with traceability and verification status
where it usually breaks Requirements held in documents with no traceability
Accepted changes are implemented, the affected work products updated and verified, the confirmation measures repeated as needed and the change documented with its effect on the safety case. Requirement text not held.
Held text: ISO 26262:2018, our statement of the clause, not the instrument verbatim.
what an assessor asks to see Implemented change records with updated work products and verification
where it usually breaks Change implemented and the safety case left unchanged
Whenever software items are integrated, suitable regression tests are run to show that the software already integrated has not acquired new defects. Applies to classes B and C.
Applies to software safety class B and C: a line of another class does not carry it.
Held text: IEC 62304:2015, our statement of the clause, not the instrument verbatim.
what an assessor asks to see Regression test records.
where it usually breaks No regression testing after late integrations.
If changes are made during system testing, tests are rerun, adjusted or added to confirm that the change fixes the problem and that it has caused no unintended side effects, and the risk management activities in 7.4 are carried out. Applies to classes A, B and C.
Applies to software safety class A, B and C: a line of another class does not carry it.
Held text: IEC 62304:2015, our statement of the clause, not the instrument verbatim.
what an assessor asks to see Retest and regression records tied to each change; 7.4 analysis.
where it usually breaks Fix verified only by rerunning the failing test.