Medical Device QMS

ISO 13485 Terminology Management for Confluence

When your design review says “verification” but your DHF says “validation” — that’s a nonconformity waiting for your next notified body audit. Manage ISO 13485:2016 terminology with version control, approval workflows, and audit trails.

Answer: ISO 13485:2016 defines 3 distinct design activities — review (Clause 7.3.5), verification (Clause 7.3.6), and validation (Clause 7.3.7). Mixing these terms in a QMS document is one of the most common notified body nonconformity findings. Compliance Glossary manages ISO 13485 terminology with version-controlled approval workflows mapped to Clause 4.2.4 document control requirements.

The Terminology Problem

ISO 13485:2016 is precise about its terminology. Medical device teams produce design history files, risk management reports, process validation protocols, and post-market surveillance plans — all containing terms that have specific, standards-defined meanings. Getting them wrong isn’t a style issue. It’s a nonconformity.

Real audit finding pattern: Team writes “design review” in their procedure but performs “design verification” activities. Under ISO 13485 Clause 7.3.5 (design review), 7.3.6 (design verification), and 7.3.7 (design validation), these are three distinct activities with different requirements. Auditor raises a major nonconformity: the QMS documentation does not reflect actual practice.

These mix-ups happen because ISO 13485 uses everyday words with precise technical definitions. Common terminology problems in medical device documentation:

Mapping to ISO 13485

Compliance Glossary features support the following ISO 13485:2016 clauses (for terminology control specifically — not full QMS document control):

ISO 13485 ClauseRequirementCompliance Glossary Feature
4.2.4 — Control of documentsDocuments must be reviewed, approved, and version-controlled. Changes must be identified.Version history — every term edit creates a new version with timestamp, author, and mandatory change reason. Previous versions preserved.
4.2.5 — Control of recordsRecords must remain legible, identifiable, and retrievable. Retention periods must be defined.Audit trail — append-only change log for every term. Who changed what, when, and why. Exportable as CSV for audit evidence packages.
5.5.3 — Internal communicationCommunication processes must be established regarding QMS effectiveness.Cross-space glossary — one controlled vocabulary shared across all Confluence spaces. Engineering, regulatory, quality, and manufacturing teams see the same approved definitions.
7.3 — Design and developmentDesign control procedures covering planning, inputs, outputs, review, verification, validation, and transfer.Design control terms — pre-defined terms for each design phase with clause-specific definitions. Scanner flags when documentation uses terms inconsistently across DHF pages.
8.2.2 — Complaint handlingDocumented procedures for timely complaint handling, investigation, and regulatory reporting decisions.Consistent terminology — standardized definitions for complaint, adverse event, field safety corrective action, and recall. No ambiguity when classifying incoming reports.

ISO 13485 Terminology — Organized by QMS Domain

Critical ISO 13485:2016 terms grouped by QMS domain. Each term includes the relevant clause reference and standards-aligned definition.

Quality System (10 terms)

QMS
Quality Policy
Quality Objectives
Management Review
Document Control
Record Control
Internal Audit
Nonconformity
Corrective Action
Preventive Action

Design & Development (8 terms)

Design Input
Design Output
Design Review
Design Verification
Design Validation
Design Transfer
Design History File
Design Change

Risk Management (4 terms)

Risk Analysis
Risk Evaluation
Risk Control
Residual Risk

Production (7 terms)

Process Validation
Sterilization
Traceability
Unique Device Identification
Labeling
Packaging
Servicing

Monitoring (6 terms)

Customer Feedback
Complaint Handling
Adverse Event
Post-Market Surveillance
Field Safety Corrective Action
Recall
CategoryTermsKey Clauses
Quality System104.1, 4.2, 5.6, 8.2.2, 8.2.4, 8.5.2, 8.5.3
Design & Development87.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9
Risk Management47.1, 7.3.3 (ISO 14971 alignment)
Production77.5.1, 7.5.2, 7.5.3, 7.5.9
Monitoring68.2.1, 8.2.2, 8.2.3, 8.5.1

ISO 13485 starter pack — available in app

The in-app Regulation Packs tab includes an ISO 13485 medical-device QMS starter vocabulary. It installs as draft terms and should be reviewed against your licensed ISO 13485 standard before audit use.

How Teams Use It

Regulatory Affairs

Build out your ISO 13485 term set in Confluence (using one of the available CSV templates as a starting structure), customize definitions to match your device classification and regulatory markets, and set terms to “approved” after quality management review. When harmonized standards change (e.g., new edition of ISO 14971:2019 or IEC 62304), update the affected terms — the scanner flags every Confluence page still using outdated definitions.

Quality Assurance

Define your QMS terms (nonconformity, corrective action, preventive action, management review) with exact definitions from your quality manual. The compliance scanner checks SOPs and work instructions for terminology drift. During notified body audits, export the full glossary with approval history as objective evidence of document control. See how FDA and GxP teams use the same workflow for 21 CFR Part 11 alignment.

Design Control Teams

Design history files reference dozens of controlled terms across design inputs, outputs, reviews, verification, and validation. When a design change triggers updates to your DHF, the scanner catches when someone writes “design review” where the activity is actually “design verification” — before your notified body auditor does. Keep design control terminology precise across all seven stages defined in Clause 7.3.

Why Not Spreadsheets?

Auditor QuestionSpreadsheet AnswerCompliance Glossary Answer
“Who approved this definition?”“Let me check Slack/email...”Timestamped approval with reviewer name
“What did it say before the change?”“We might have an old version somewhere”Full version history with diffs
“Is this term used consistently across your QMS?”“We’d need to check every document manually”One-click scan across all Confluence pages
“Show me your document control process for definitions”“We updated it, see the modified date”Mandatory change reason + four-eyes approval
“Export your controlled vocabulary as evidence”Manual copy-paste into audit reportOne-click CSV export with full audit chain

Frequently Asked Questions

What is the difference between verification and validation in ISO 13485?

Verification (Clause 7.3.6) confirms that design outputs meet design inputs — objective evidence, usually via test, inspection, or analysis. Validation (Clause 7.3.7) confirms that the finished device meets user needs and intended use under actual or simulated use conditions. Verification asks “did we build it right?”; validation asks “did we build the right thing?”. Different activities, different evidence, different timing.

Which ISO 13485 clause covers document control?

Clause 4.2.4 (Control of documents) requires documents to be reviewed, approved, version-controlled, and their changes identified. Clause 4.2.5 (Control of records) covers retention and retrievability of records. Compliance Glossary supports both for terminology specifically: version history with mandatory change reason aligned to 4.2.4, append-only audit trail aligned to 4.2.5. The app covers terminology only — full QMS document control still depends on your broader Confluence setup and SOPs. See ISO 13485:2016 for the authoritative clause text.

Is ISO 13485 the same as ISO 9001?

No. ISO 13485:2016 is a standalone quality management system standard for medical devices. It shares structural roots with ISO 9000:2015/9001 but is independent — it emphasizes regulatory compliance, risk management, and product safety over continual improvement and customer satisfaction. A medical device manufacturer certified to ISO 9001 is not automatically ISO 13485-compliant. Notified bodies audit against 13485, not 9001.

Sources

ISO 13485-Ready Terminology Management

Stop managing definitions in spreadsheets that can’t satisfy Clause 4.2.4. Build your term set in the app, approve, scan your QMS documentation. Need help getting started? See the installation guide and documentation.

Evaluate in Confluence Browse Available Templates

Related Resources

Compliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence

FDA Terminology Management — 43 terms for 21 CFR Part 11 alignment, built for pharma and medtech teams

Pharma Terminology Management — GxP-aligned terminology control for pharmaceutical QA/RA teams

DORA CFO Personal Liability — cross-persona view: why terminology discipline matters to finance leaders under DORA

AI Act Terminology Governance — regulation hub: Article 3 definitions and terminology control for AI systems

GxP Documentation Principles — Good Practice documentation standards for life sciences and device teams

ALCOA+ Documentation Principles — how data integrity principles map to terminology management

Four-Eyes Principle — approval workflows for compliance, QA, GRC, legal, security, and regulatory teams, mapped to SOX, MiFID II, and FDA GMP

Compliance Guide — what auditors check and how we help, mapped to real regulatory standards

Glossary App Comparison — how Confluence glossary apps compare for compliance, QA, GRC, legal, security, and regulatory teams