ISO 13485 Management Review: The Proven First-Time Playbook

Direct Answer

An ISO 13485 management review is the top-management meeting required by Clause 5.6 of the standard, held at planned intervals to evaluate the quality management system's continuing suitability, adequacy, and effectiveness. Clause 5.6.1 requires a documented procedure for it, Clause 5.6.2 names twelve required inputs, Clause 5.6.3 requires documented decisions and actions, and the whole thing is captured as a maintained record. Under the FDA QMSR rule effective February 2, 2026, those records are now FDA-inspectable — so the first review a medical device organization holds sets the pattern, and the stakes, for every review that follows.

The Stakes

Why Your First ISO 13485 Management Review Sets the Pattern

Top-led. Periodic. Decisive.

Most quality problems in a medical device company do not announce themselves in a defect report. They surface — or fail to surface — in the management review, the one meeting where top management is required to look the whole quality system in the eye. Run it well the first time and you build a decision-making mechanism your organization will reuse for years. Run an ISO 13485 management review as a box-ticking ritual and you create a template for a recurring audit finding. After 28 years of attending certification audits, MSI's client experience suggests the same truth again and again: the agenda you adopt for your first ISO 13485 management review is the highest-leverage decision in the entire exercise, because you will reuse it, refine it, and be audited against it.

The stakes rose sharply on February 2, 2026, when the FDA's Quality Management System Regulation (QMSR) took effect and made ISO 13485:2016 the operative regulatory text for U.S. device makers. The records produced in an ISO 13485 management review — once explicitly shielded from FDA inspection — are now fair game. This playbook walks through the substance of the ISO 13485 management review: the documented procedure Clause 5.6.1 requires, the twelve required inputs, the outputs you must document, agenda design, records, common first-time mistakes, and the QMSR-era posture every device organization should now adopt. The goal is not a perfect first review. It is a first review that produces the right record, makes the right decisions, and creates a working pattern you can sustain.

ISO 13485 Management Review Tool Kit: Present an Audit-Ready Review Without the Guesswork

Definition

What Is an ISO 13485 Management Review?

Review. Decide. Record.

An ISO 13485 management review is a structured executive meeting, led by top management, at which the quality management system is examined against the twelve required Clause 5.6.2 inputs, the decisions and actions Clause 5.6.3 requires are made, and the results are documented as a maintained record under Clause 4.2.5. Clause 5.6 requires top management to conduct this review at documented planned intervals to ensure the system's continuing suitability, adequacy, and effectiveness.

Cadence for an ISO 13485 management review is a judgment call the standard leaves to you. Clause 5.6 requires “planned intervals,” and MSI client experience suggests annually for the first review is typical, with quarterly or semi-annual cadence becoming common as the system matures and as risk signals demand closer attention. Whatever interval you choose, document it — an undocumented interval is itself a finding.

The definition of “top management” matters more than most first-timers expect. ISO 13485 defines top management — a definition carried from ISO 9000:2015, the fundamentals-and-vocabulary standard the QMSR also incorporates by reference — as the person or group who direct and control the organization at the highest level. For a small startup, that may be the CEO and the head of quality; for an established manufacturer, a defined executive committee. The standard does not allow Clause 5.6 to be delegated downward in substance. Your management representative or Quality Director may organize and prepare the review, but top management must lead the ISO 13485 management review and own the decisions. A review chaired solely by the management representative — with the CEO logged as “absent, reviewed minutes” — is a documented gap, and under the QMSR that gap is now visible to an FDA investigator. For the deeper mechanics of building the procedure itself, MSI's step-by-step management review procedure guide is the companion to this playbook, and its analysis of why the record must prove what the room already knew explains the failure mode that costs most organizations a finding.

Clause 5.6.1

Does an ISO 13485 Management Review Require a Documented Procedure?

Procedure. Record. Proof.

Yes. Clause 5.6.1 requires the organization to document procedures for management review — a requirement ISO 9001 does not impose. An ISO 13485 management review therefore produces two distinct pieces of evidence: the documented procedure that says how the review is run, and the record that proves it was run that way. Organizations that build only the record fail Clause 5.6.1 even when every meeting goes flawlessly.

This is the single most-missed requirement in the whole clause, and the reason is structural rather than careless. Teams migrating from a general quality system carry an ISO 9001 habit with them: in ISO 9001, management review needs no documented procedure at all, only documented information as evidence of the results. ISO 13485 is more prescriptive by design, because it was written for regulatory purposes rather than general commercial use. It names documented procedures outright in several places, and management review is one of them. So a device organization that inherits a 9001-shaped approach arrives at its certification audit with excellent ISO 13485 management review minutes and no procedure — and takes a finding for a document it never knew it owed. MSI's guide to what makes an effective ISO procedure traces exactly why the weighting shifts between standards.

The standard does not dictate what the procedure must contain, which leaves organizations guessing. In MSI's experience across 200+ audits attended, a documented ISO 13485 management review procedure that survives scrutiny answers seven questions without ambiguity: who convenes the review and on what authority; what the planned interval is and what triggers an off-cycle review; who must attend for the meeting to be valid; who owns each of the twelve Clause 5.6.2 inputs and by when the data must be produced; how decisions and actions are recorded against the four Clause 5.6.3 output categories; how actions are tracked to verified closure and fed forward as input (i); and how the resulting records are controlled and retained under Clause 4.2.5. Write those seven answers down and the procedure exists. Leave any of them to custom and the quality of every future ISO 13485 management review depends on who happens to be in the room.

One clarification worth making because it causes real confusion in audits: an ISO 13485 management review tool kit is not a procedure. A deck and a minutes form are the record — the evidence the review happened and what it decided. The procedure is the governing document that says how the review will be run before anyone opens the deck. Both are required, and an auditor will ask for both. The same distinction applies across every documented process in a device QMS, which is why MSI's work on risk management procedure structure and on procedure-first ISO compliance keeps returning to the same point: the document that describes the process and the record that proves it ran are two different artifacts with two different audit tests.

The Document Clause 5.6.1 Asks For

Stop Writing Procedures From a Blank Page

Clause 5.6.1 wants a documented procedure, not another meeting. MSI's ISO Procedure Templates and Guides library covers ten procedure topics across ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101 — written to one architecture so the set interlocks, delivered as editable Word, with the judgment calls already made. The Leadership and Commitment procedure is the one your management review record depends on. Twenty-eight years of practice, written down.

Browse the ISO Procedure Template Library →

Clause 5.6.2

The Twelve Required Inputs to an ISO 13485 Management Review

Feedback. Findings. Changes.

Clause 5.6.2 is unusually specific for an ISO standard: it names twelve inputs, and every ISO 13485 management review record must address all of them or document why one is not applicable. Missing an input is one of the most common and most preventable ISO 13485 management review findings. The twelve are:

(a) Feedback — including from post-market surveillance. (b) Complaint handling. (c) Reporting to regulatory authorities — adverse events, vigilance, and similar. (d) Audits — internal, external, and supplier. (e) Monitoring and measurement of processes. (f) Monitoring and measurement of product. (g) Corrective action. (h) Preventive action. (i) Follow-up actions from previous management reviews. (j) Changes that could affect the quality management system. (k) Recommendations for improvement. (l) Applicable new or revised regulatory requirements.

Two of these deserve special attention in the QMSR era. Input (c), reporting to regulatory authorities, and input (l), new or revised regulatory requirements, are exactly where an FDA investigator now expects to see evidence of a risk-based conversation — not a line that reads “no changes.” The QMSR itself is the obvious example of an (l) input every U.S. device maker should have on the record. And input (g), corrective action, is where your corrective, risk, and improvement loop proves it is working rather than merely documented — the mechanics of which MSI covers in its explanation of how CAPA works under ISO 13485. Treat each input as a question the review must answer with evidence, and the record writes itself.

Clause 5.6.3

The Required Outputs: What an ISO 13485 Management Review Must Decide

Improve. Resource. Respond.

Inputs describe the system; outputs change it. Clause 5.6.3 requires that the ISO 13485 management review record the decisions and actions related to four areas: improvement needed to maintain the suitability, adequacy, and effectiveness of the QMS and its processes; improvement of product related to customer requirements; changes needed to respond to new or revised regulatory requirements; and resource needs. A review that reports data but decides nothing has not met Clause 5.6.3.

The discipline that converts an ISO 13485 management review from a compliance event into a working mechanism is action assignment: every decision needs a named owner and a due date. Anonymous action items — “the team will investigate” — are recurring audit findings waiting to happen, because at the next review nobody can show they were closed. Under the QMSR, FDA investigators reviewing management review records now look specifically for evidence that resource allocation, remediation timing, and supplier actions reflect stated risk priorities. In other words, your outputs must show that leadership acted on risk, not just noticed it. Feed those outputs into the next review as input (i), follow-up actions, and you have built the closed loop the standard is really asking for — the same loop MSI teaches in its management review training.

Know the Difference

ISO 13485 vs. ISO 9001 Management Review: What Actually Differs

Same logic. Different map.

Both standards require a management review, but they file it differently — and the difference trips up teams moving from a general quality system to a medical device one. In ISO 9001 , management review lives in Clause 9.3, inside the harmonized structure shared by ISO 14001, ISO 45001, and ISO 7101. ISO 13485 predates that harmonization and deliberately kept its own architecture, so its management review sits in Clause 5.6, under Management Responsibility. The clause numbers differ; the underlying logic does not. That structural split is unchanged by the coming edition: the ISO 9001 FDIS ballot closed on July 9, 2026 with publication expected in September 2026, management review stays at Clause 9.3, and ISO 13485 is on its own revision track entirely — so a device organization planning its review architecture today is planning against a stable target. MSI tracks what the new edition changes for leadership in its coverage of what companies get wrong about ISO 9001.

Where ISO 13485 genuinely diverges is regulatory gravity. Its management review inputs make regulatory reporting and new or revised regulatory requirements explicit, named items — not general “external issues” — because a medical device QMS answers to regulators, not only customers. That same DNA runs through the standard: the medical device file as a documented knowledge base (Clause 4.2.3) and competence tied to defined roles (Clause 6.2) reflect an industry where traceability is a legal obligation. And as the previous section covered, ISO 13485 demands a documented procedure for the ISO 13485 management review where ISO 9001 does not. MSI's decoder-ring guide to the five standards maps exactly how the shared logic reads across the different clause structures, and its overview of the ISO 13485 medical device standard covers the wider architecture this clause sits inside.

Organizations that hold both ISO 9001 and ISO 13485 can, and usually should, run a single integrated ISO 13485 management review that satisfies Clause 5.6 and Clause 9.3 at once — provided the record clearly covers every input each standard demands. That proviso is where integrated reviews fail. The asymmetry runs in both directions: an organization building its agenda from ISO 13485 alone drops three ISO 9001 inputs, while one building from ISO 9001 alone drops six ISO 13485 requirements. Building from whichever standard the preparer knows best is precisely how the other standard's unique requirements go missing. MSI's combined ISO 9001 and ISO 13485 management review tool kit resolves all thirty-two sections in one agenda and records which standard governs each divergence.

The Meeting

Designing an Agenda That Survives Every Future Review

Structured. Timed. Repeatable.

A first ISO 13485 management review typically runs three to four hours. The exact length matters less than the structure — the agenda you adopt now becomes the reusable, auditable template for every review that follows. Build it deliberately, mapping each agenda item to a Clause 5.6.2 input so nothing is missed, and end with the Clause 5.6.3 decisions.

A workable first-review agenda looks like this: welcome, attendance, and confirmation of quorum; review of open actions from any prior review; then a walk through the twelve inputs in order — feedback and complaints, regulatory reporting, the results of internal, external, and supplier audits, process and product monitoring data, the status of corrective and preventive actions, changes affecting the QMS, recommendations for improvement, and new or revised regulatory requirements; followed by the decision block where the four categories of Clause 5.6.3 outputs are agreed with owners and dates; and a close that confirms the next review interval. Keep the data pre-circulated so the ISO 13485 management review is for deciding, not for reading. MSI's internal audit planning approach feeds this agenda directly, because a well-run audit program is what makes inputs (d), (e), and (f) meaningful rather than perfunctory — and the audit programme itself changed in 2026, as MSI covers in its guide to the ISO 19011:2026 internal audit procedure.

One structural choice is worth making before you draft anything: whether your ISO 13485 management review agenda is built from the clause or from last year's meeting. Agendas assembled from habit inherit last year's omissions, and the requirement an organization has never performed is precisely the one a habit-built agenda cannot surface — because there is no line item asking for it. Building each section from the clause text, with the clause reference printed beside it, makes the omission visible while you are still preparing rather than while an auditor is reading.

Built From the Clause, Not Last Year's Agenda

Find the Management Review Tool Kit That Matches Your Certification Scope

Device-only, or ISO 9001 and ISO 13485 together? The two agendas are not the same document, and picking the wrong one is how requirements go missing. MSI's ISO Management Review Tool Kits page lays out every version — ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001, ISO 7101, and three integrated combinations — with a scope table so you can pick the row that matches your certificate. Each is a matched pair: a presentation deck to present from and a Word minutes form to record into, generated from the same numbered section list, with the clause reference printed under every section title.

Compare the Management Review Tool Kits →

Before the Meeting

Preparing the Data: Who Brings What to the Review

Assign. Circulate. Distill.

An ISO 13485 management review is only as good as the data that arrives before it. The most reliable preparation MSI uses is to assign every one of the twelve Clause 5.6.2 inputs a named data owner, weeks ahead of the meeting. Quality owns audit results and corrective and preventive action status; regulatory owns reporting to authorities and the running list of new or revised regulatory requirements; production and engineering own process and product monitoring; purchasing owns supplier audit outcomes; and sales or customer service owns feedback and complaint trends. When ownership is explicit, no input shows up empty on the day.

Then pre-circulate the package so the meeting is spent deciding, not reading aloud. The discipline that separates a strong first review from a weak one is distillation: raw data dumps invite a shrug, while trends, comparisons, and flagged risks invite a decision. A complaint count is data; a complaint trend against a threshold, with a risk note, is a decision waiting to happen — and under the QMSR, it is exactly the risk-based signal an FDA investigator now looks for in the record. Feed the review from a disciplined internal audit program and clean documented information, and inputs (d) through (h) arrive already shaped for judgment rather than transcription. That single habit — turning data into signal before the meeting — does more to raise the caliber of an ISO 13485 management review than any other preparation step.

Organizations that are not yet certified, or that are still building the underlying processes, hit a different wall when preparing an ISO 13485 management review: some inputs have no data because the process that would generate them does not exist. There is no customer satisfaction trend if satisfaction was never measured. The correct move is not to omit the section — it is to record the absence as the finding and set the goal, which is what an honest first review looks like. MSI's ISO 13485 gap analysis is the fastest way to establish which inputs your system can currently feed and which ones need building first.

The New Reality

The QMSR Era: Your Management Review Record Is Now FDA-Inspectable

Inspectable. Risk-based. Documented.

The single biggest change to the ISO 13485 management review in a generation is not in the standard — it is in U.S. law. On February 2, 2026, the FDA's Quality Management System Regulation (QMSR) took effect, amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference. Management review records, once explicitly exempt from FDA inspection, are now fair game.

Under the old Quality System Regulation, §820.180(c) shielded management reviews, internal audit reports, and supplier audit reports from FDA review during inspections. ISO 13485 contains no such exception — so when the FDA incorporated ISO 13485 by reference, that shield disappeared. The agency also confirmed on its QMSR FAQ that records generated before February 2, 2026 fall within inspectional remit too. The rule itself was published as a final rule in the Federal Register on February 2, 2024, with a two-year runway, and a set of technical amendments published in December 2025 conformed 179 sections across 18 parts of Title 21 to it. For a full breakdown of the rule, see MSI's guide to the FDA QMSR rule and 21 CFR Part 820 alignment.

The inspection method changed with it. The FDA retired the decades-old Quality System Inspection Technique (QSIT) and, effective the same day, adopted Compliance Program 7382.850, Inspection of Medical Device Manufacturers. Instead of QSIT's four subsystems, investigators now work through six QMS Areas — Change Control; Design and Development; Management Oversight; Measurement, Analysis, and Improvement; Outsourcing and Purchasing; and Production and Service Provision — plus four other applicable requirements. Your management review lives inside the Management Oversight area, and the crucial shift is this: the FDA now expects management review records to demonstrate risk-based discussion, not merely performance metrics. Resource allocation, remediation timing, and supplier actions in your record should visibly reflect stated risk priorities. Internal audit programs and agendas still built around the old QSIT subsystems should be reorganized around the ISO 13485 clause structure — a migration MSI maps step by step in its guide to navigating the transition from QSIT to ISO 13485:2016. MSI covers the inspection shift in depth in its analysis of how the QMSR reshapes change control and audit-report inspectability, and how a mature system earns a stronger appraisal in its look at the FDA Voluntary Improvement Program. The authoritative regulation text lives in the eCFR Part 820.

The Evidence

Building an Audit-Ready and Inspection-Ready Record

Capture. Attribute. Retain.

A defensible ISO 13485 management review record is not a set of slides — it is a maintained record under Clause 4.2.5 that a registrar auditor and, now, an FDA investigator can follow without a guide. At minimum it captures the date and attendees (with top management clearly present and leading), the data reviewed against each of the twelve inputs, the decisions and actions made against the four output areas, the owner and due date for each action, and confirmation of the next review interval. Where an input is not applicable, the record says so and why — silence is read as omission.

ISO 13485 management review record organization is, after 28 years of audits, the single weakness MSI most often flags — the review usually happens, but proving it cleanly is where teams lose points. Keep the minutes, the pre-read data, and the resulting action log traceable to one another and to the review date, and store them so they can be produced quickly; under the QMSR, the FDA can request records in advance of or in lieu of an on-site inspection, which makes fast retrieval a real capability rather than a nicety. Set a retention period that matches your device's lifetime and regulatory expectations, and confirm that electronic records carry the controls — access, versioning, and audit trail — that make them defensible; a management review minute that cannot be shown to be authentic and unaltered is a weak record regardless of what it says. For the wider discipline of structuring records so they hold up, MSI's guide to building powerful QMS documentation is the deeper reference, and its explanation of what the ISO 13485 standard requires overall puts Clause 4.2.5 in context.

Leadership Owns Clause 5.6

Why Top Management Cannot Delegate the Review

Present. Engaged. Accountable.

An ISO 13485 management review lives or dies on top-management engagement — the same Clause 5 leadership commitment that decides whether the whole QMS works in practice. The QMSR sharpened this: the FDA's inspection program treats management review records as a direct window into how leadership thinks, prioritizes, and responds to risk. A review where executives are physically present but disengaged produces a record that reads exactly that way to an investigator. Ownership is not a formality; it is the substance the standard and the regulator are both testing for.

There is a harder version of this problem, and every experienced quality leader has met it: the review runs correctly, the inputs are complete, the record is clean — and the same issue reappears three cycles later. When that happens, the failure is upstream of the meeting. What the floor already knows is not reaching the room, because it died at a handoff nobody logged. MSI's independent operational assessment is built for exactly that condition: it follows real work orders through every station, signature, and handoff, and interviews the people who touched them against the record — locating the precise point where a problem was visible and did not move. It is commissioned by the executive who owns the outcome, which is what allows the finding to name where the knowing stopped.

Device-Only Scope

Give Your Leaders a Review They Can Own From Day One

When top management walks into the review with the right structure in front of them, engagement follows. MSI's Medical Device ISO 13485 Management Review Tool Kit gives leaders the agenda, the twelve-input template, the decision worksheet, and the inspection-ready record format — the same structure MSI has used across 80+ certifications supported and with 600+ professionals trained. Certified to ISO 9001 as well? The combined edition is the better fit and covers both clause sets in one agenda.

Get the ISO 13485 Management Review Tool Kit →

Avoid These

Common First-Time ISO 13485 Management Review Mistakes

Skips. Silos. Silence.

MSI's experience shows that a poorly structured ISO 13485 management review can generate more than five findings on its own. The good news is that first-time mistakes cluster into a short, avoidable list.

No documented procedure. Clause 5.6.1 requires one, and organizations arriving from an ISO 9001 background routinely have excellent minutes and no procedure at all. Missing an input. The most common finding is simply skipping one of the twelve Clause 5.6.2 inputs — often regulatory reporting or preventive action — because it felt “not applicable” without saying so on the record. Delegating the chair. A review led by the management representative with top management absent is a documented gap that the QMSR now exposes to inspectors. Reporting without deciding. Presenting metrics but recording no Clause 5.6.3 decisions fails the output requirement outright. Anonymous actions. Decisions without an owner and a date cannot be shown closed at the next review. Building on QSIT. Agendas and audit programs still organized around the retired four-subsystem model now sit out of step with the FDA's clause-based inspection. Startups feel these mistakes most acutely — MSI's look at why most medical startups misread ISO 13485 traces where the pattern begins.

The MSI Difference

How ISO Consulting De-Risks Your First Review

Proven. Practical. Permanent.

The fastest way to get a first ISO 13485 management review right is to run it against structure that has already survived audits — and to have someone at the table who has sat through 200+ of them. That is what MSI's ISO consulting practice provides: it translates Clause 5.6 into a review your leadership team can actually run, and leaves the capability behind.

Management Systems International (MSI) has supported organizations through certification across 28 years, with a track record of 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Those numbers matter here for one specific reason: MSI has watched registrars and, increasingly, FDA investigators read management review records for all of it, which is a different kind of knowledge from having read the clause. ISO 13485 is a standard MSI knows from the inside — its distinctive shape, built for regulatory traceability through the medical device file (Clause 4.2.3) and competence tied to defined roles (Clause 6.2), is exactly the terrain where an experienced hand pays for itself. MSI's decoder-ring approach to the standards reads Clause 5.6 with the same logic as every other management review requirement, just with the map ISO 13485 uses, and its industries served page shows where that experience has been earned.

Whether you are preparing a first review, tightening an existing one for the QMSR era, or building the wider system around it, a structured planning session early — rather than a rushed start — is the most reliable way to scope the work and avoid rework. MSI client experience suggests the first professionally structured review pays for itself many times over, because it prevents the cluster of findings a self-built first attempt so reliably produces and sets a defensible pattern the organization reuses for years. To talk through fit, call MSI at 760-434-9141.

Take the Next Step

Run It. Document It. Defend It.

A complete ISO 13485 management review needs two things: the documented procedure Clause 5.6.1 requires, and the record Clause 5.6.3 requires. MSI builds both. Start with the management review tool kit that matches your certification scope for the deck and minutes form, and the ISO procedure template library for the governing procedure the review record depends on.

Choose Your Management Review Tool Kit →

Want MSI to build and maintain the whole system? Explore SurePath for turnkey certification or SureResults for year-round maintenance, or call 760-434-9141.

Questions Answered

ISO 13485 Management Review: Frequently Asked Questions

Ask. Answer. Apply.

How often is an ISO 13485 management review required?

Clause 5.6 requires an ISO 13485 management review at “documented planned intervals.” The standard does not fix a frequency, but annually is typical for a first review, with quarterly or semi-annual cadence common as the system matures. Whatever interval you choose must be documented, because an undocumented interval is itself an audit finding.

Does ISO 13485 require a documented management review procedure?

Yes. Clause 5.6.1 requires the organization to document procedures for management review — a requirement ISO 9001 does not impose. An ISO 13485 management review therefore needs two artifacts: the documented procedure describing how the review is convened, prepared, conducted, and recorded, and the record proving it happened that way. A tool kit deck and minutes form are the record, not the procedure; auditors ask for both.

What are the required inputs to an ISO 13485 management review?

Clause 5.6.2 names twelve: feedback, complaint handling, reporting to regulatory authorities, audits, monitoring and measurement of processes, monitoring and measurement of product, corrective action, preventive action, follow-up from previous reviews, changes affecting the QMS, recommendations for improvement, and new or revised regulatory requirements. Every ISO 13485 management review must address all twelve or document why one is not applicable.

Can one management review satisfy both ISO 13485 and ISO 9001?

Yes, and organizations certified to both usually should — but only if the agenda is built from both clause sets rather than whichever one the preparer knows best. An ISO 13485 management review agenda used alone omits three ISO 9001 inputs, and an ISO 9001 agenda used alone omits six ISO 13485 requirements. Build the combined agenda from Clause 5.6 and Clause 9.3 together, and record which standard governs each divergence.

Are management review records subject to FDA inspection under the QMSR?

Yes. As of February 2, 2026, the FDA's QMSR incorporates ISO 13485:2016 by reference, and the old §820.180(c) exemption that shielded management review, internal audit, and supplier audit records is gone. Under Compliance Program 7382.850, investigators can now review these records — and they expect them to show risk-based discussion, not just performance metrics.

Who must attend an ISO 13485 management review?

Top management — the person or group who direct and control the organization at the highest level — must lead the review, not merely receive the minutes. The management representative may prepare and organize it, but Clause 5.6 cannot be delegated downward in substance. Process and functional owners typically attend to present their data against the relevant inputs.

What outputs must an ISO 13485 management review produce?

Clause 5.6.3 requires documented decisions and actions on four areas: improvement to maintain the QMS's suitability, adequacy, and effectiveness; improvement of product related to customer requirements; changes to respond to new or revised regulatory requirements; and resource needs. Each decision should carry a named owner and a due date so it can be verified closed at the next ISO 13485 management review.

References & Authoritative Sources

1. International Organization for Standardization — ISO 13485 Medical Devices (Clause 5.6 Management Review).

2. U.S. FDA — Quality Management System Regulation (QMSR) and its FAQ, effective February 2, 2026.

3. Federal Register — Medical Devices; Quality System Regulation Amendments (final rule, February 2, 2024) and the December 2025 technical amendments.

4. U.S. FDA — Compliance Program 7382.850, Inspection of Medical Device Manufacturers.

5. eCFR — 21 CFR Part 820.

6. ISO — ISO 9001 Quality Management and ISO 31000 Risk Management. (ISO 13485 risk management aligns with ISO 14971; top-management definitions derive from ISO 9000:2015.)

7. ISO — ISO 14001 Environmental Management (for integrated management reviews).

8. International Medical Device Regulators Forum — IMDRF Guidance and Technical Documents (regulatory convergence and MDSAP audit model).

9. Global Accreditation Cooperation (Global ACI) — the single international accreditation organisation that assumed the former roles of IAF and ILAC on January 1, 2026.

10. American Society for Quality — ISO 13485 quality resources.

11. NIST — Baldrige Performance Excellence Program.


About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com · 760-434-9141


Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 13 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply