When your design review says “verification” but your DHF says “validation” — that’s a nonconformity waiting for your next notified body audit. Manage ISO 13485:2016 terminology with version control, approval workflows, and audit trails.
Answer: ISO 13485:2016 defines 3 distinct design activities — review (Clause 7.3.5), verification (Clause 7.3.6), and validation (Clause 7.3.7). Mixing these terms in a QMS document is one of the most common notified body nonconformity findings. Compliance Glossary manages ISO 13485 terminology with version-controlled approval workflows mapped to Clause 4.2.4 document control requirements.
ISO 13485:2016 is precise about its terminology. Medical device teams produce design history files, risk management reports, process validation protocols, and post-market surveillance plans — all containing terms that have specific, standards-defined meanings. Getting them wrong isn’t a style issue. It’s a nonconformity.
These mix-ups happen because ISO 13485 uses everyday words with precise technical definitions. Common terminology problems in medical device documentation:
Compliance Glossary features support the following ISO 13485:2016 clauses (for terminology control specifically — not full QMS document control):
| ISO 13485 Clause | Requirement | Compliance Glossary Feature |
|---|---|---|
| 4.2.4 — Control of documents | Documents must be reviewed, approved, and version-controlled. Changes must be identified. | Version history — every term edit creates a new version with timestamp, author, and mandatory change reason. Previous versions preserved. |
| 4.2.5 — Control of records | Records must remain legible, identifiable, and retrievable. Retention periods must be defined. | Audit trail — append-only change log for every term. Who changed what, when, and why. Exportable as CSV for audit evidence packages. |
| 5.5.3 — Internal communication | Communication processes must be established regarding QMS effectiveness. | Cross-space glossary — one controlled vocabulary shared across all Confluence spaces. Engineering, regulatory, quality, and manufacturing teams see the same approved definitions. |
| 7.3 — Design and development | Design control procedures covering planning, inputs, outputs, review, verification, validation, and transfer. | Design control terms — pre-defined terms for each design phase with clause-specific definitions. Scanner flags when documentation uses terms inconsistently across DHF pages. |
| 8.2.2 — Complaint handling | Documented procedures for timely complaint handling, investigation, and regulatory reporting decisions. | Consistent terminology — standardized definitions for complaint, adverse event, field safety corrective action, and recall. No ambiguity when classifying incoming reports. |
Critical ISO 13485:2016 terms grouped by QMS domain. Each term includes the relevant clause reference and standards-aligned definition.
| Category | Terms | Key Clauses |
|---|---|---|
| Quality System | 10 | 4.1, 4.2, 5.6, 8.2.2, 8.2.4, 8.5.2, 8.5.3 |
| Design & Development | 8 | 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9 |
| Risk Management | 4 | 7.1, 7.3.3 (ISO 14971 alignment) |
| Production | 7 | 7.5.1, 7.5.2, 7.5.3, 7.5.9 |
| Monitoring | 6 | 8.2.1, 8.2.2, 8.2.3, 8.5.1 |
The in-app Regulation Packs tab includes an ISO 13485 medical-device QMS starter vocabulary. It installs as draft terms and should be reviewed against your licensed ISO 13485 standard before audit use.
Build out your ISO 13485 term set in Confluence (using one of the available CSV templates as a starting structure), customize definitions to match your device classification and regulatory markets, and set terms to “approved” after quality management review. When harmonized standards change (e.g., new edition of ISO 14971:2019 or IEC 62304), update the affected terms — the scanner flags every Confluence page still using outdated definitions.
Define your QMS terms (nonconformity, corrective action, preventive action, management review) with exact definitions from your quality manual. The compliance scanner checks SOPs and work instructions for terminology drift. During notified body audits, export the full glossary with approval history as objective evidence of document control. See how FDA and GxP teams use the same workflow for 21 CFR Part 11 alignment.
Design history files reference dozens of controlled terms across design inputs, outputs, reviews, verification, and validation. When a design change triggers updates to your DHF, the scanner catches when someone writes “design review” where the activity is actually “design verification” — before your notified body auditor does. Keep design control terminology precise across all seven stages defined in Clause 7.3.
| Auditor Question | Spreadsheet Answer | Compliance Glossary Answer |
|---|---|---|
| “Who approved this definition?” | “Let me check Slack/email...” | Timestamped approval with reviewer name |
| “What did it say before the change?” | “We might have an old version somewhere” | Full version history with diffs |
| “Is this term used consistently across your QMS?” | “We’d need to check every document manually” | One-click scan across all Confluence pages |
| “Show me your document control process for definitions” | “We updated it, see the modified date” | Mandatory change reason + four-eyes approval |
| “Export your controlled vocabulary as evidence” | Manual copy-paste into audit report | One-click CSV export with full audit chain |
Verification (Clause 7.3.6) confirms that design outputs meet design inputs — objective evidence, usually via test, inspection, or analysis. Validation (Clause 7.3.7) confirms that the finished device meets user needs and intended use under actual or simulated use conditions. Verification asks “did we build it right?”; validation asks “did we build the right thing?”. Different activities, different evidence, different timing.
Clause 4.2.4 (Control of documents) requires documents to be reviewed, approved, version-controlled, and their changes identified. Clause 4.2.5 (Control of records) covers retention and retrievability of records. Compliance Glossary supports both for terminology specifically: version history with mandatory change reason aligned to 4.2.4, append-only audit trail aligned to 4.2.5. The app covers terminology only — full QMS document control still depends on your broader Confluence setup and SOPs. See ISO 13485:2016 for the authoritative clause text.
No. ISO 13485:2016 is a standalone quality management system standard for medical devices. It shares structural roots with ISO 9000:2015/9001 but is independent — it emphasizes regulatory compliance, risk management, and product safety over continual improvement and customer satisfaction. A medical device manufacturer certified to ISO 9001 is not automatically ISO 13485-compliant. Notified bodies audit against 13485, not 9001.
Stop managing definitions in spreadsheets that can’t satisfy Clause 4.2.4. Build your term set in the app, approve, scan your QMS documentation. Need help getting started? See the installation guide and documentation.
Evaluate in Confluence Browse Available TemplatesCompliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
FDA Terminology Management — 43 terms for 21 CFR Part 11 alignment, built for pharma and medtech teams
Pharma Terminology Management — GxP-aligned terminology control for pharmaceutical QA/RA teams
DORA CFO Personal Liability — cross-persona view: why terminology discipline matters to finance leaders under DORA
AI Act Terminology Governance — regulation hub: Article 3 definitions and terminology control for AI systems
GxP Documentation Principles — Good Practice documentation standards for life sciences and device teams
ALCOA+ Documentation Principles — how data integrity principles map to terminology management
Four-Eyes Principle — approval workflows for compliance, QA, GRC, legal, security, and regulatory teams, mapped to SOX, MiFID II, and FDA GMP
Compliance Guide — what auditors check and how we help, mapped to real regulatory standards
Glossary App Comparison — how Confluence glossary apps compare for compliance, QA, GRC, legal, security, and regulatory teams