The Regulatory Toolkit Blog
The Workbench
Notes from building the shelf — on the craft of regulatory documents: what makes a template worth taking, a checklist worth trusting, and a tool worth running.
Latest Craft What ‘software validated’ has to specify before the claim means anything ISO 13485 asks whether software is validated in three separate clauses, not one. Answering 4.1.6 and stopping covers a third of what the standard asks.
28 July 2026
What a correction-and-removal record has to decide before the 10-day clock starts
Craft
21 CFR 806.10 gives a risk-driven correction ten working days to reach FDA. 806.20 still requires a record even when the risk test isn't met.
28 July 2026
What a post-market surveillance plan has to prove before the report gets written
Craft
MDR Article 83 requires an active surveillance system, not a complaint inbox. The plan, the PMSR/PSUR, and Article 88 trend reports are three separate things.
27 July 2026
Where the UDI has to resurface after it leaves the label
Craft
Part 830 defines what makes a UDI valid. Since the QMSR, 820.35 requires it to reappear in the complaint file and the service record.
27 July 2026
What a nonconforming-product record has to decide before it's closed
Craft
ISO 13485 Clause 8.3 can close a nonconformance with rework, scrap, or a documented concession — no CAPA required. The record has to prove which one, and why.
27 July 2026
What a training record has to show, not just track
Craft
ISO 13485 Clause 6.2 asks for evaluated training effectiveness, scaled to risk — not a completed roster. It's the field most competency matrices leave blank.
26 July 2026
What a device classification tool has to check, and where most stop
Craft
Class I, II or III answers one question. Whether that class’s exemption still applies is a second, separate check — and it’s the one a black-box tool skips.
26 July 2026
What a management review record has to contain
Craft
Twelve required inputs, four required outputs — ISO 13485:2016 Clause 5.6 turns a meeting most teams treat as a formality into a specific, checkable record.
26 July 2026
What a supplier qualification file has to prove
Craft
A supplier file that stops at initial approval is missing what the clause actually asks for — and what the QMSR quietly retired underneath it.
25 July 2026
What a complaint record has to decide before it becomes a CAPA
Craft
A complaint log looks like intake paperwork. It is actually two separable decisions — and the record for the second one just got spelled out.
25 July 2026
What a Refuse-to-Accept review actually checks
Craft
FDA's 15-day acceptance review tells you a 510(k) is complete enough to read. It was never built to tell you whether the science inside it holds up.
25 July 2026
What a risk management file has to prove, hazard by hazard
Craft
ISO 14971 asks a risk file to trace each hazard to residual risk. A 2021 amendment closed the gap that used to make Europe's bar stricter.
24 July 2026
The design file that has to answer to two regulators
Craft
FDA just retired the term Design History File. What the file has to prove hasn't changed — but its structure now has to serve two regulators at once.
24 July 2026
What a document-control SOP actually controls
Craft
Most document-control SOPs describe an approval workflow and stop. The clause that matters is what happens after a document stops being current.
24 July 2026
What an internal audit plan has to decide before the auditor walks in
Craft
A fixed annual rotation through every clause looks thorough and finds almost nothing. A real audit plan is a risk assessment first, a schedule second.
23 July 2026
How a template goes stale, and how we watch for it
The Shelf
Publishing a template once is the easy part. The harder discipline is noticing the moment its source moves — and this year handed the industry a clear example.
23 July 2026
What a CAPA tracker has to track — and what most logs skip
Craft
A CAPA log looks like a spreadsheet with statuses. A working one is proof a problem will not recur — and most logs skip the column that proves it.
23 July 2026
The anatomy of a Q-Submission request that gets a useful answer
Craft
FDA will answer exactly the question you ask, and no more. Most Q-Submission requests waste the mechanism by asking the wrong kind of question.
23 July 2026
Why every regulatory team rebuilds the same documents
The Shelf
The industry's working documents live in private stashes — so every team pays the tuition again. The case for a shared shelf.
23 July 2026
What makes a checklist worth trusting
Craft
Most checklists produce ceremony, not safety. Four rules separate the ones that catch errors from the ones that decorate them.
23 July 2026
The launch catalog: what makes the cut
The Shelf
A toolkit's first job is choosing what not to ship. The four criteria behind the launch shelf — and the documents we refuse to template.