The Workbench · Craft

What makes a checklist worth trusting

There are two kinds of checklists in regulatory work: the kind that catches the missing bench-test report before FDA's intake reviewer does, and the kind that exists so an SOP can say a checklist exists. They look identical. The difference is structural, and it is checkable.

Checklists have a good reputation borrowed from aviation and surgery, where they demonstrably save lives. The borrowed reputation is a problem: it lets a column of checkboxes feel rigorous regardless of what the boxes say. In a quality system, an untrustworthy checklist is worse than none — it converts "we didn't verify this" into "we verified this," on paper, with a signature.

Four rules separate the working kind from the ceremonial kind.

1. Every item traces to a primary source

A checklist item that can't cite its origin is folklore. Maybe it entered the list because of a real finding in 2019; maybe someone copied it from a slide. You can't tell, so you can't prune it, and un-prunable lists grow until people skim them. The working version puts the citation on the item — the RTA checklist row, the ISO 13485 clause, the guidance section — so every box answers says who? before it asks for a tick.

2. One item, one verifiable claim

"Labeling reviewed and device description consistent with predicate comparison" is three claims wearing one checkbox. When it's ticked, which of the three happened? Compound items are how gaps hide inside completed checklists. The discipline is a verb, an object, and nothing else — if you need the word "and," you need another row.

3. Ask for evidence, not agreement

A checkbox asks "do you agree this is fine?" — and under deadline, everyone agrees. An evidence prompt asks "where is it?" — a document number, a test-report ID, a page reference. The empty evidence cell is the entire safety mechanism: agreement can be reflexive, but a citation has to exist to be written down. This is why our checklists ship as spreadsheets with an objective-evidence column, not as printable tick-sheets.

4. A checklist without a version date is a rumor

The sources move. FDA revises the RTA policy; standards get amended; guidance finalizes. A checklist copied in 2023 and still circulating in 2026 is a snapshot of a document that no longer exists — and its users are the last to know. The working version states which revision of the source it was built against, visibly, so staleness is a fact you can check rather than a surprise an auditor delivers.

The test

Take any checklist your team relies on and ask of one row: where did this item come from, what single claim does it make, what evidence does it demand, and against which revision of the source was it written? A trustworthy checklist answers all four from the page. Everything on the Toolkit's shelf is built to pass that test — and when one of ours can't, that's a defect, and we'd like to hear about it.

The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.

All Workbench notes