ISO 13485 design and development

How to Manage the Design and Development of Medical Devices According to ISO 13485:2016

ISO 13485:2016 requires medical device manufacturers to establish, document, and maintain a controlled design and development process. The process should cover design planning, inputs, outputs, reviews, verification, validation, transfer, design changes, and design and development records.

The objective is to ensure that the medical device consistently meets its specified requirements, intended use, safety requirements, applicable regulatory requirements, and user needs.

For organizations developing medical devices, ISO 13485 design and development controls provide the framework for moving from an initial product concept to a verified, validated, and manufacturable device.

Talk to our experts

What Is Design and Development Under ISO 13485?

Design and development is the process of converting requirements and user needs into a medical device that can be manufactured and used safely for its intended purpose.

Under ISO 13485, manufacturers need to establish controls for the design and development process appropriate to their products and regulatory requirements.

The process generally includes:

  1. Design and development planning
  2. Design inputs
  3. Design outputs
  4. Design reviews
  5. Design verification
  6. Design validation
  7. Design transfer
  8. Control of design changes
  9. Design and development files

These activities should be documented and maintained as objective evidence of conformity.

ISO 13485 Design and Development Process

1. Design and Development Planning

The first step is to establish a documented plan for the design and development project.

The plan should define, as applicable:

  • Design and development stages
  • Activities to be performed
  • Responsibilities and authorities
  • Required reviews
  • Verification activities
  • Validation activities
  • Resources
  • Required records
  • Interfaces between different teams
  • Applicable regulatory requirements
  • Methods for controlling design changes

The plan should be updated as the project progresses.

For complex medical devices, clearly defining responsibilities between engineering, regulatory, quality, clinical, manufacturing, and other teams can help prevent gaps later in the development process.

2. Design and Development Inputs

Design inputs establish what the medical device needs to achieve.

Inputs should be documented, reviewed, and approved before they are used as the basis for design activities.

Depending on the device, design inputs can include:

  • Intended use
  • User needs
  • Functional requirements
  • Performance requirements
  • Safety requirements
  • Applicable regulatory requirements
  • Usability requirements
  • Biocompatibility requirements
  • Software requirements
  • Environmental requirements
  • Packaging and labeling requirements
  • Risk control requirements
  • Manufacturing requirements

Risk management should be integrated into the design process.

For example, identified hazards and risk controls can become specific design inputs that must subsequently be verified.

Why Are Design Inputs Important?

Poorly defined inputs can create problems throughout the development process.

If a safety requirement, performance requirement, regulatory requirement, or user need is missed during the input stage, the resulting design may fail verification, validation, or regulatory review.

Therefore, manufacturers should make design inputs clear, measurable, traceable, and reviewable wherever practical.

3. Design and Development Outputs

Design outputs are the results of the design process.

They should provide information that allows the device to be manufactured, inspected, tested, and controlled.

Examples can include:

  • Product specifications
  • Drawings
  • Material specifications
  • Component specifications
  • Software specifications
  • Manufacturing specifications
  • Inspection requirements
  • Acceptance criteria
  • Packaging specifications
  • Labeling requirements
  • Test methods
  • Product configuration information

Design outputs should be suitable for comparison against the design inputs.

A key principle is traceability between inputs and outputs.

For example:

Design input → Design output → Verification → Validation

This traceability helps demonstrate that the requirements defined at the beginning of development have been addressed.

4. Design and Development Reviews

Design reviews provide formal opportunities to evaluate whether the development activities are progressing as planned.

Reviews can involve relevant functions such as:

  • Design engineering
  • Quality assurance
  • Regulatory affairs
  • Manufacturing
  • Clinical teams
  • Risk management
  • Usability engineering

The review should evaluate the suitability of the design and identify problems that need to be addressed.

Manufacturers should maintain records of design reviews, including participants, findings, decisions, and required actions.

5. Design Verification

Design verification asks: “Did we design the device correctly according to the specified requirements?”

Verification confirms that design outputs meet the specified design inputs.

Depending on the device, verification activities may include:

  • Laboratory testing
  • Inspection
  • Measurement
  • Calculations
  • Software testing
  • Electrical safety testing
  • Mechanical testing
  • Biocompatibility testing
  • Packaging testing
  • Performance testing
  • Document reviews

The specific verification activities depend on the device and its applicable requirements.

Example

Suppose a medical device has a design input specifying that a component must withstand a defined mechanical load.

A suitable verification test can determine whether the final design meets that specified requirement.

6. Design Validation

Design validation asks: “Did we design the right device for its intended use and user needs?”

Validation evaluates whether the resulting device meets user needs and the intended use under specified or representative conditions.

Depending on the device, validation may involve:

  • Clinical evaluation or clinical investigation activities
  • Simulated-use testing
  • Usability validation
  • Software validation
  • Performance evaluation
  • Packaging and transportation validation
  • User testing
  • Other applicable validation activities

Where applicable, validation should use representative product and consider the intended operating conditions.

Manufacturers should establish acceptance criteria before conducting validation and maintain documented evidence of the results.

Design Verification vs Design Validation

One of the most common areas of confusion in medical device design controls is the difference between verification and validation.

Design VerificationDesign Validation
Confirms design outputs meet design inputsConfirms the device meets user needs and intended use
Focuses on design requirementsFocuses on intended use and user needs
Often involves technical testingCan involve simulated-use, usability, clinical or performance activities
“Did we design it correctly?”“Did we design the right device?”

Both activities are important and should be appropriately planned and documented.

7. Design Transfer

Once the design has been developed and validated, the manufacturer needs to transfer the design into production.

Design transfer ensures that the approved design is correctly translated into manufacturing specifications and processes.

Activities may include:

  • Production documentation
  • Manufacturing instructions
  • Equipment requirements
  • Inspection methods
  • Acceptance criteria
  • Process validation where applicable
  • Training
  • Supplier requirements
  • Packaging requirements
  • Production testing

A successful design transfer helps ensure that the device produced commercially is consistent with the validated design.

8. Control of Design Changes

Medical device designs can change because of:

  • Component changes
  • Supplier changes
  • Manufacturing improvements
  • Risk controls
  • Software updates
  • Regulatory requirements
  • Product improvements
  • Field issues
  • Customer feedback

These changes need to be controlled.

A documented design change process should determine:

  • What is changing?
  • Why is the change required?
  • What risks are associated with the change?
  • Does verification need to be repeated?
  • Does validation need to be repeated?
  • Are regulatory submissions affected?
  • Does labeling need to change?
  • Who must review and approve the change?

Not every change requires the same level of testing. The impact of the change should be evaluated and documented.

9. Design and Development File

Manufacturers should maintain records demonstrating conformity with the design and development requirements.

The design and development file can include evidence related to:

  • Design plans
  • Design inputs
  • Design outputs
  • Design reviews
  • Verification
  • Validation
  • Risk management
  • Design transfer
  • Design changes
  • Approvals
  • Regulatory requirements

The exact structure and terminology of the file can vary depending on the organization’s QMS and applicable regulatory requirements.

How Risk Management Fits Into Medical Device Design

Risk management should not be treated as a separate activity performed only after product development.

Risk considerations should be integrated throughout the design process.

For example:

Hazard identification → Risk evaluation → Risk control → Design input → Design output → Verification → Validation

This creates a connection between risk management and design controls.

Manufacturers should be able to demonstrate that identified risks have been appropriately addressed and that relevant risk controls have been implemented and verified.

Schedule a Compliance Consultation

Accelerate Market Access with End-to-End Regulatory Guidance

Benefits of Implementing Effective ISO 13485 Design Controls

A controlled design and development process can help manufacturers:

  • Reduce design-related risks
  • Improve product consistency
  • Identify design problems earlier
  • Strengthen regulatory documentation
  • Improve traceability
  • Support verification and validation
  • Improve manufacturing transfer
  • Control product changes
  • Support regulatory submissions
  • Establish stronger lifecycle controls

The goal is not simply to create more documentation. The goal is to create a controlled development process that produces evidence that the medical device meets its defined requirements and intended use.

How Operon Strategist Can Help

Implementing ISO 13485 design and development controls can be challenging, particularly for startups and manufacturers developing their first medical device.

Operon Strategist provides medical device regulatory consulting and quality management support to help manufacturers establish compliant design and development processes.

Our services can include:

Whether you are developing a new medical device or improving an existing QMS, our team can help align your design and development process with applicable regulatory and quality requirements.

Need Help With ISO 13485 Design and Development?

A well-controlled design process can make the difference between a medical device that is simply developed and one that is properly documented, verified, validated, manufacturable, and ready for regulatory review.

If you need support with ISO 13485 design and development, medical device design controls, QMS implementation, or design documentation, Operon Strategist can help.

Contact our team to discuss your medical device development and regulatory requirements.

Ensure Seamless Regulatory Compliance for Your Device

Get Your Medical Device Market-Ready with Expert Regulatory Support

FAQ's

Design and development under ISO 13485 is a controlled process for converting user needs, intended use, regulatory requirements, and other inputs into a medical device that meets defined requirements and can be manufactured consistently.

The main stages include design planning, design inputs, design outputs, design reviews, design verification, design validation, design transfer, control of design changes, and maintenance of design and development records.

Verification determines whether design outputs meet specified design inputs. Validation determines whether the resulting device meets user needs and its intended use under specified or representative conditions.

Yes. ISO 13485:2016 includes specific requirements for controlling design and development activities for organizations where design and development is applicable to their operations.

Documents and records can include design plans, inputs, outputs, reviews, verification and validation records, risk management documentation, design transfer records, design changes, and other evidence required by the organization’s QMS and applicable regulatory requirements.