The Workbench · The Shelf

How a template goes stale, and how we watch for it

On February 2 of this year, a citation a generation of quality engineers knew by heart — 21 CFR 820.100, the corrective-and-preventive-action requirement — stopped existing as free-standing regulatory text. FDA's Quality Management System Regulation took effect that day, replacing most of Part 820 with a pointer to ISO 13485:2016. Any document-control SOP or CAPA tracker that cited “820.100” by name went stale the moment the rule changed, whether or not anyone told the team that built it.

That's the risk a static template carries and a live one doesn't: the source it maps to can move without asking permission. A regulation gets amended, a guidance gets superseded, a standard gets revised. The document sitting in a shared drive doesn't know, and neither does the person who pulls it out eighteen months later.

A template outlives the person who built it

Most working documents in a quality system are written once, under deadline, by whoever drew the task that quarter. They then get reused for years by people who weren't in the room when the citations were chosen. That's fine as long as the citations still hold. It stops being fine silently — nobody circles back to re-check a document's legal footing unless an audit forces the question, and by then the gap has usually been load-bearing for a while.

The QMSR transition is this year's clearest case, but it isn't unusual in kind. FDA finalized new Q-Submission Program guidance in May 2025, superseding the version from June 2023 — two years is not a long shelf life for a document that shapes how sponsors ask for feedback. Standards move on their own clock too: ISO periodically reviews and revises its catalog, and a clause number that was current at publication can be renumbered or withdrawn at the next revision. None of this is exotic. It's just the normal rate at which regulatory ground shifts, and most templates aren't built to notice it.

What we map, concretely

The discipline we're building the shelf around is narrow but specific: every resource states the exact source it implements — the regulation citation, the guidance title and date, the standard and clause — and the revision of that source it was built against, printed on the resource itself, not buried in an internal changelog only we can see. A CAPA tracker that references “ISO 13485:2016, clause 8.5.2” is a falsifiable claim. You can check it. A tracker that just says “per your quality system requirements” is not, and its staleness is undetectable until someone gets burned by it.

Watching for movement

Stating the source is necessary but not sufficient — someone still has to watch it. Our practice is to treat a source's movement the way a working CAPA tracker treats a trigger event: not a vague obligation to “stay current,” but a dated event that starts a bounded review, the same logic our checklist piece argued for a version-dated row. A Federal Register notice, a guidance finalization, a standard's revision cycle — each one is a fact with a date, and a resource mapped to that source should get reviewed against the new version within a set window, not whenever someone happens to notice during audit prep.

The honest version of “always up to date”

No small team can watch every source continuously, and we won't claim otherwise. The promise a commons can actually keep isn't perpetual currency — it's a visible last-checked date on every resource, and a fast, public correction when a gap is reported instead of a quiet one. If you spot a citation in the launch catalog that's drifted from its source, that's not an edge case for us — that's the exact failure mode this whole practice exists to catch, and we want the report. Tell us where it broke, or get notified when the shelf opens and you can check the rest yourself.

The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.

All Workbench notes