Requirements Traceability Gap Findertrace sheet

4 Changed after its last passing verification

The requirement was last changed after the date of its latest passing verification, so the pass was recorded against an earlier version. Many teams call this a suspect link. It is a signal, not proof: a later change means the pass may no longer apply, and the reviewer decides whether the change is substantive, editorial or already covered, and records it.

the test
a requirement whose revision differs from the revision its latest pass was run against (when both are pasted), or else whose last-changed date is strictly later than the date of its latest passing verification
the question
What changed on that date, was the impact on the verification assessed, and has it been re-verified or the decision not to re-verify recorded?
asked of
the requirement owner
columns it reads
Last Changed, the result dates and Revision and the results: Requirement Revision

A signal, not proof: a later change means the pass may no longer apply, and the reviewer decides whether the change is substantive, editorial or already covered (the review sheet has a column for it). Where the requirements carry a revision and the results the revision each test ran against, the revisions are compared instead of dates, and the line says which was used. By date it is strictly later: the same day is not raised, and only the date of a time is read. See suspect links.

The clauses behind it, by standard

each shown when you tick its standard

The clause text

ISO 13485 7.3.9Control of design and development changes

Changes to design and development are controlled through documented procedures. For each change the organization judges how significant it is for the device and its intended use, looking at function, performance, usability, safety and the regulatory requirements that apply. Every change is identified, then reviewed, verified, validated where appropriate and approved before it is put into effect. The review of a change weighs its effect on constituent parts, on product being made or already delivered, on the inputs and outputs of risk management, and on the processes used to realize the product. The organization keeps records of each change, of its review and of any actions the review found necessary.

Held text: ISO 13485:2016, our statement of the clause, not the instrument verbatim.

what an assessor asks to see Design change procedure with a significance assessment covering function, performance, usability, safety and regulatory impact; Change records showing review, verification, validation and approval before implementation; Evaluation of effect on parts, product in process, delivered product, risk management and realization processes; Regulatory assessment of whether the change requires notification or approval

where it usually breaks Significance assessed only for regulatory notification, not for safety or usability; Effect on delivered product never evaluated; Changes implemented in production before verification is complete

Every ISO 13485 clause we hold

FDA QMSR 820.10Quality management system requirements: ISO 13485 incorporated by reference

Section 820.10 establishes the substantive QMS requirements by incorporating ISO 13485:2016 SECTIONS 4 THROUGH 8 in full. Manufacturers must implement: ISO 13485:2016 SECTION 4 General QMS requirements + documentation (Quality Manual + Medical Device File + control of documents + records); SECTION 5 Management responsibility + customer focus + quality policy + planning + responsibility / authority / communication + management review; SECTION 6 Resource management (provision of resources + human resources + infrastructure + work environment + contamination control); SECTION 7 Product realization (planning + customer-related + design and development - the medical-device 'design controls' parallel + purchasing + production and service provision + control of monitoring + measuring equipment); SECTION 8 Measurement + analysis + improvement (monitoring + measurement + control of nonconforming product + analysis of data + improvement - including CAPA Sections 8.5.2 + 8.5.3). NB: ยง820.10 also clarifies that ISO 13485:2016 internal-audit + management-review requirements (Sections 8.2.4 + 5.6) apply to the QMSR.

Held text: 21 CFR Part 820 (QMSR), our statement of the clause, not the instrument verbatim.

what an assessor asks to see ISO 13485 Section 4-8 compliance file; Internal audit programme + records; Management review records + frequency; Cross-reference matrix between QMSR + ISO 13485 + EU MDR/IVDR + FDA Part 11

where it usually breaks ISO 13485 implemented in parts without full Section 4-8 coverage; Internal audit infrequent or scope-limited; Management review absent + meeting minutes incomplete

Every FDA QMSR clause we hold

FDA QMSR 820.35Control of records: retention, audit trail and the records FDA adds

Section 820.35 establishes FDA-specific record-control requirements that supplement ISO 13485:2016 Section 4.2.5. SPECIFIC REQUIREMENTS: (a) RECORD RETENTION - records must be retained for a period of time equivalent to the design + expected life of the device + IN ANY CASE NOT LESS THAN 2 YEARS FROM THE DATE OF RELEASE FOR COMMERCIAL DISTRIBUTION BY THE MANUFACTURER. (b) AUDIT TRAIL - records must include audit trail meeting the criteria of FDA 21 CFR Part 11 (Electronic Records + Electronic Signatures) where electronic records are maintained - the audit trail must be: secure + computer-generated + time-stamped + tamper-evident + record who-what-when-where-why for every CRUD operation on regulated records. (c) UNIQUE DEVICE IDENTIFICATION (UDI) - records must include UDI per FDA Unique Device Identification Rule (21 CFR Part 830) where applicable - UDI on labelling + linked to records. (d) MEDICAL DEVICE REPORTING (MDR) - records of MDR submissions under 21 CFR Part 803 (Medical Device Reporting) must be maintained as part of QMSR records. (e) CORRECTIONS AND REMOVALS - records of corrections + removals under 21 CFR Part 806 must be maintained. (f) ACCESSIBILITY - records must be ACCESSIBLE TO + READILY AVAILABLE FOR REVIEW BY FDA inspectors during inspections; manufacturers must provide records in human-readable + electronic form within reasonable time upon FDA request.

Held text: 21 CFR Part 820 (QMSR), our statement of the clause, not the instrument verbatim.

what an assessor asks to see Record-retention policy specifying device-life-or-2-year-minimum + FDA inspection-readiness; Audit trail Part 11 conformance test + design specification; UDI traceability per Part 830; MDR + Part 806 records retention

where it usually breaks Records retention shorter than 2 years from commercial distribution release; Audit trail not Part 11 compliant; UDI traceability gap; MDR + Part 806 records not retained or not inspection-ready

Every FDA QMSR clause we hold

AS9100D 8.3.6Design and development changes

Changes made during or after design and development are identified, reviewed and controlled to ensure no adverse impact on conformity, with documented information retained on the changes, review results, authorization and actions taken to prevent adverse impacts; 9100 adds a process with criteria for notifying the customer before implementation of changes affecting customer requirements, and that design changes are controlled under the configuration management process.

Held text: AS9100D, our statement of the clause, not the instrument verbatim.

what an assessor asks to see Design change records with review, authorization and impact actions.; Customer notification criteria and records.; Configuration management linkage.

where it usually breaks Changes affecting customer requirements implemented without prior notification.; Design changes outside configuration control.

Every AS9100D clause we hold

IATF 16949 8.3.6.1Design and development changes - supplemental

Once a product has had its first approval, every design change, supplier proposals included, is assessed for its possible effect on fit, form, function, performance and durability, is validated against customer requirements and is approved inside the organization before it is put into production. If the customer requires it, the organization first obtains documented approval from the customer, or a documented waiver. For products that contain embedded software, the change record documents the revision levels of both the software and the hardware.

Held text: IATF 16949:2016, our statement of the clause, not the instrument verbatim.

what an assessor asks to see Change evaluation and internal approval records before implementation.; Customer approvals or waivers where required.; Software and hardware revision levels in change records.

where it usually breaks Supplier-proposed changes implemented without evaluation.; Software revision not recorded with the change.

Every IATF 16949 clause we hold

ISO 26262 Part 8, 6.4.3Management of safety requirements

Safety requirements are managed under configuration and change management with traceability to their source and to their verification, and are verified for correctness, completeness and consistency against the level above. Requirement text not held.

Held text: ISO 26262:2018, our statement of the clause, not the instrument verbatim.

what an assessor asks to see Requirements management tool records with traceability and verification status

where it usually breaks Requirements held in documents with no traceability

Every ISO 26262 clause we hold

ISO 26262 Part 8, 8.4.5Implementing and documenting the change

Accepted changes are implemented, the affected work products updated and verified, the confirmation measures repeated as needed and the change documented with its effect on the safety case. Requirement text not held.

Held text: ISO 26262:2018, our statement of the clause, not the instrument verbatim.

what an assessor asks to see Implemented change records with updated work products and verification

where it usually breaks Change implemented and the safety case left unchanged

Every ISO 26262 clause we hold

IEC 62304 5.6.6Conduct regression tests

Whenever software items are integrated, suitable regression tests are run to show that the software already integrated has not acquired new defects. Applies to classes B and C.

Applies to software safety class B and C: a line of another class does not carry it.

Held text: IEC 62304:2015, our statement of the clause, not the instrument verbatim.

what an assessor asks to see Regression test records.

where it usually breaks No regression testing after late integrations.

Every IEC 62304 clause we hold

IEC 62304 5.7.3Retest after changes

If changes are made during system testing, tests are rerun, adjusted or added to confirm that the change fixes the problem and that it has caused no unintended side effects, and the risk management activities in 7.4 are carried out. Applies to classes A, B and C.

Applies to software safety class A, B and C: a line of another class does not carry it.

Held text: IEC 62304:2015, our statement of the clause, not the instrument verbatim.

what an assessor asks to see Retest and regression records tied to each change; 7.4 analysis.

where it usually breaks Fix verified only by rerunning the failing test.

Every IEC 62304 clause we hold

See the specimen runTrace your own export