The Workbench · Craft
The process that has to be validated, not inspected
A quality system's habit is to catch problems by testing the output — inspect it, measure it, compare it to spec, sign off. ISO 13485:2016 Clause 7.5.6 names a category of process where that habit structurally can't work: production processes whose output cannot be verified by later monitoring or measurement, so a deficiency only becomes visible once the product is already in use. For that category, the standard doesn't ask for stricter inspection. It asks for something different in kind — validating the process itself, in advance, with a documented method that demonstrates it produces the right result every time it runs. A quality file that answers this clause with more inspection, rather than a validation record, has answered a question Clause 7.5.6 didn't ask.
The trigger is a fact about the process, not a risk score
Clause 7.5.6 doesn't scale with how dangerous a bad result would be. It scales with a narrower question: can a later inspection actually catch this process's failures at all? Two situations fail that test, for different reasons. One is destructive verification — checking a unit consumes or destroys it, so inspecting “fully” would leave nothing left to ship. The other is a defect that simply doesn't surface on inspection: concealed inside the finished device, or only manifesting under conditions the inspection bench never reproduces. A process that would be catastrophic if it went wrong but is nonetheless fully checkable afterward, every unit and every time, doesn't trigger this clause on that basis alone. It still owes whatever acceptance and inspection controls its risk otherwise calls for — that's a different clause's job.
Same substance, a different clause number now
Under the old Quality System Regulation, 820.75 said the same thing in FDA's own words: where the results of a process cannot be fully verified by subsequent inspection and test, the process has to be validated with a high degree of assurance and approved according to established procedures. Since QMSR's February 2, 2026 compliance date, that obligation runs through ISO 13485's Clause 7.5.6 instead — the same move this blog has already traced for the DMR, DHF, and DHR's content moving into Clause 4.2 and Clause 7. A validation SOP still citing “820.75” as its authority is citing a paragraph Part 820's own text no longer contains, even though the duty behind it is unchanged.
What the record has to contain, not just conclude
Clause 7.5.6 lists specific elements a documented procedure has to cover: defined criteria for review and approval of the processes, qualification of the equipment and of the personnel running them, specific methods and procedures with defined acceptance criteria, and, where appropriate, statistical techniques with a stated rationale for sample size. That's the industry's IQ/OQ/PQ structure in substance, even though the standard never uses those three letters — installation qualification that the equipment is installed and calibrated as specified, operational qualification that it runs within its parameters, performance qualification that it produces the intended result consistently under real production conditions. A validation report that jumps straight to a performance run, with no documented qualification of the equipment it ran on, has produced evidence for only the last of the three questions the clause structures.
Sterilization is the clause's own worked example
ISO 13485 gives sterilization and sterile-barrier processes their own sub-clause, 7.5.7, precisely because they're the case Clause 7.5.6 is built around. A finished sterile unit can't be opened to confirm it's sterile without destroying the barrier that made it sterile, and any sample large enough to inspect meaningfully would consume the batch it's meant to release. The cycle parameters — temperature, exposure time, gas concentration, whatever the modality specifies — get validated once against a defined method, and every subsequent run gets monitored against those validated parameters rather than re-verified against the finished product. Treating sterilization as just another process that needs extra testing substitutes more inspection for the validation the clause specifically carves this process out to require instead.
Validation doesn't end at signoff
Both the old 820.75 and the current Clause 7.5.6 keep an obligation running after the validation report is approved: monitoring and control of the validated process's own parameters, personnel qualified to run it, and a piece it's easy to let lapse — defined criteria for when the process has to be revalidated. A change in raw material, equipment, or a process parameter outside what the original qualification covered doesn't stay quietly covered by the old report. The record needs a stated trigger for when a change is significant enough to reopen validation, not an assumption that today's process still matches whatever ran during the original qualification.
Where this meets the rest of the file
A validated process that drifts outside its own qualified parameters doesn't get fixed by rerunning the validation quietly — the output it already produced while out of parameter is exactly what a nonconforming-product record exists to disposition, a separate decision from whether the process itself needs requalifying. And a revalidation trigger tied to a recurring parameter drift is often the same signal a CAPA tracker is built to catch before it becomes a pattern rather than an isolated deviation.
A process-validation record built around this structure — the verifiability trigger, the IQ/OQ/PQ documentation elements, and a stated revalidation criterion — is previewed in the launch catalog. If your program draws the validation line differently, the shelf takes that correction directly.
The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.