Document control for medical device QMS, covering numbering, version control, change management, and 21 CFR Part 11 compliance. Use for document control procedures, change control workflows, and electronic signature compliance.
Document control system design and management for ISO 13485-compliant quality management systems, including numbering conventions, approval workflows, change control, and electronic record compliance.
Before setting up document control or validating a document, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Document type — QM, SOP, WI, TF, SPEC, or PLN (sets the required reviewers, approvers, and numbering)
Regulatory scope — ISO 13485 only vs 21 CFR Part 11 electronic records (determines whether audit-trail and e-signature controls are required)
Change classification — administrative, minor, major, or emergency (sets the approval path and impact assessment)
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the document.
Document Control Workflow
Implement document control from creation through obsolescence:
Assign document number per numbering procedure
Create document using controlled template
Route for review to required reviewers
Address review comments and document responses
Obtain required approval signatures
Assign effective date and distribute
Update Document Master List
Validation: Document accessible at point of use; obsolete versions removed
Document Lifecycle Stages
Stage
Definition
Actions Required
Draft
Under creation or revision
Author editing, not for use
Review
Circulated for review
Reviewers provide feedback
Approved
All signatures obtained
Ready for training/distribution
Effective
Training complete, released
Available for use
Superseded
Replaced by newer revision
Remove from active use
Obsolete
No longer applicable
Archive per retention schedule
Document Types and Prefixes
Prefix
Document Type
Typical Content
QM
Quality Manual
QMS overview, scope, policy
SOP
Standard Operating Procedure
Process-level procedures
WI
Work Instruction
Task-level step-by-step
TF
Template/Form
Controlled forms
SPEC
Specification
Product/process specs
PLN
Plan
Quality/project plans
Required Reviewers by Document Type
Document Type
Required Reviewers
Required Approvers
SOP
Process Owner, QA
QA Manager, Process Owner
WI
Area Supervisor, QA
Area Manager
SPEC
Engineering, QA
Engineering Manager, QA
TF
Process Owner
QA
Design Documents
Design Team, QA
Design Control Authority
Document Numbering System
Assign consistent document numbers for identification and retrieval.
Numbering Format
Standard format: PREFIX-CATEGORY-SEQUENCE[-REVISION]
Example: SOP-02-001-A
SOP = Document type (Standard Operating Procedure)
02 = Category code (Document Control)
001 = Sequential number
A = Revision indicator
Category Codes
Code
Functional Area
Description
01
Quality Management
QMS procedures, management review
02
Document Control
This area
03
Human Resources
Training, competency
04
Design & Development
Design control processes
05
Purchasing
Supplier management
06
Production
Manufacturing procedures
07
Quality Control
Inspection, testing
08
CAPA
Corrective/preventive actions
09
Risk Management
ISO 14971 processes
10
Regulatory Affairs
Submissions, compliance
Numbering Workflow
Author requests document number from Document Control
Document Control verifies category assignment
Document Control assigns next available sequence number
Number recorded in Document Master List
Author creates document using assigned number
Validation: Number format matches standard; no duplicates in Master List
Revision Designation
Change Type
Revision Increment
Example
Major revision
Increment number
Rev 01 → Rev 02
Minor revision
Increment sub-revision
Rev 01 → Rev 01.1
Administrative
No change or letter suffix
Rev 01 → Rev 01a
See references/document-control-procedures.md for complete numbering guidance.
Approval and Review Process
Obtain required reviews and approvals before document release.
Review Workflow
Author completes document draft
Author submits for review via routing form or DMS
Reviewers assigned based on document type
Reviewers provide comments within review period (5-10 business days)
Author addresses comments and documents responses
Author resubmits revised document
Approvers sign and date
Validation: All required reviewers completed; all comments addressed with documented disposition
Comment Disposition
Disposition
Action Required
Accept
Incorporate comment as written
Accept with modification
Incorporate with changes, document rationale
Reject
Do not incorporate, document justification
Defer
Address in future revision, document reason
Approval Matrix
Document Level 1 (Policy/QM): CEO or delegate + QA Manager
Document Level 2 (SOP): Department Manager + QA Manager
Document Level 3 (WI/TF): Area Supervisor + QA Representative
Signature Requirements
Element
Requirement
Name
Printed name of signer
Signature
Handwritten or electronic signature
Date
Date signature applied
Role
Function/role of signer
Change Control Process
Manage document changes systematically through review and approval.
Change Control Workflow
Identify need for document change
Complete Change Request Form with justification
Document Control assigns change number and logs request
Route to reviewers for impact assessment
Obtain approvals based on change classification
Author implements approved changes
Update revision number and change history
Validation: Changes match approved scope; change history complete
Change Classification
Class
Definition
Approval Level
Examples
Administrative
No content impact
Document Control
Typos, formatting
Minor
Limited content change
Process Owner + QA
Clarifications
Major
Significant content change
Full review cycle
New requirements
Emergency
Urgent safety/compliance
Expedited + retrospective
Safety issues
Impact Assessment Checklist
Impact Area
Assessment Questions
Training
Does change require retraining?
Equipment
Does change affect equipment or systems?
Validation
Does change require revalidation?
Regulatory
Does change affect regulatory filings?
Other Documents
Which related documents need updating?
Records
What records are affected?
Change History Documentation
Each document must include change history:
| Revision | Date | Description | Author | Approver |
|----------|------|-------------|--------|----------|
| 01 | 2023-01-15 | Initial release | J. Smith | M. Jones |
| 02 | 2024-03-01 | Updated workflow | J. Smith | M. Jones |
21 CFR Part 11 Compliance
Implement electronic record and signature controls for FDA compliance.
Part 11 Scope
Applies To
Does Not Apply To
Records required by FDA regulations
Paper records
Records submitted to FDA
Internal non-regulated documents
Electronic signatures on required records
General email communication
Electronic Record Controls
Validate system for accuracy and reliability
Implement secure audit trail for all changes
Restrict system access to authorized individuals
Generate accurate copies in human-readable format
Protect records throughout retention period
Validation: Audit trail captures who, what, when for all changes
Audit Trail Requirements
Requirement
Implementation
Secure
Cannot be modified by users
Computer-generated
System creates automatically
Time-stamped
Date and time of each action
Original values
Previous values retained
User identity
Who made each change
Electronic Signature Requirements
Requirement
Implementation
Unique to individual
Not shared between persons
At least 2 components
User ID + password minimum
Signature manifestation
Name, date/time, meaning displayed
Linked to record
Cannot be excised or copied
Signature Manifestation
Every electronic signature must display:
Element
Example
Printed name
John Smith
Date and time
2024-03-15 14:32:05 EST
Meaning
Approved for Release
System Controls Checklist
Access Controls:
Unique user ID for each person
Password complexity enforced
Account lockout after failed attempts
Session timeout after inactivity
Audit Trail:
All record creation logged
All modifications logged with old/new values
User identity captured
Date/time stamp on all entries
Security:
Role-based access control
Encryption for data at rest and in transit
Regular backup and tested recovery
See references/21cfr11-compliance-guide.md for detailed compliance requirements.
Document number does not match the PREFIX-CATEGORY-SEQUENCE pattern
Ensure the number follows the format SOP-02-001 (type prefix, 2-digit category code, 3-digit sequence). Check that the prefix matches a recognized document type (QM, SOP, WI, TF, SPEC, PLN).
Validation flags missing approver despite having signatures
approver field is null or empty in the input JSON
Populate the approver field with the name of the approving authority. For SOPs, both Process Owner and QA Manager are required.
Review date validation fails for a current document
review_date is in the past
Update the review date to reflect the next scheduled review. Documents past their review date should be flagged for periodic review and re-approval.
Change history marked incomplete
Not all revisions have entries in the change_history array
Every revision increment must have a corresponding change history entry with revision number, date, description, and author. Fill gaps in the history.
Part 11 controls flagged despite using an eDMS
has_audit_trail or has_electronic_signature set to false
Set both to true and ensure signature_components is at least 2 (user ID + password minimum per Part 11). Verify the eDMS produces computer-generated, timestamped audit trails.
Interactive mode does not display all validation rules
Terminal width too narrow for table output
Widen the terminal window or use --output json for structured output that is not affected by display width.
Obsolete documents still appearing as "Effective"
Status field not updated during revision cycle
When a new revision is released, update the prior revision's status to "Superseded" and ensure it is removed from points of use. Run the validator against the superseded document to confirm.
Success Criteria
Document numbering system enforced with zero duplicate numbers in the Document Master List and 100% format compliance
Document cycle time (draft to effective) averages less than 30 business days across all document types
Review completion rate exceeds 95% (reviews completed on time vs. total reviews initiated)
Overdue periodic review rate below 5% of total effective documents at any point
21 CFR Part 11 compliance verified for all electronic records: audit trails capture who/what/when for every change, electronic signatures include printed name, date/time, and meaning
Change control process handles 100% of document changes through the classification workflow (Administrative/Minor/Major/Emergency) with documented impact assessments
Zero external audit findings related to document control in the most recent certification or surveillance audit
Scope & Limitations
In Scope:
Document numbering convention design and validation
Document lifecycle management (Draft through Obsolete)
Review and approval workflow enforcement
Change control process with classification and impact assessment
21 CFR Part 11 electronic record and electronic signature compliance validation
Periodic review schedule management
Document Master List maintenance
Out of Scope:
eDMS software selection, implementation, or validation (the tool validates metadata, not the DMS platform itself)
EU Annex 11 computerized system validation (complementary to Part 11 but requires separate assessment approach)
Technical file / Design History File content creation (use regulatory-affairs-head for technical documentation)
Record retention schedule creation (the tool validates dates but does not determine regulatory retention periods)
Physical document distribution or archival logistics
Training record management (the tool validates training-related documents but does not manage training programs)
FDA QMSR (effective Feb 2026) incorporates ISO 13485 Clause 4.2 by reference; Part 11 compliance remains a separate FDA requirement for electronic records
CAPA actions frequently require document revisions; the change control process tracks CAPA-driven document changes
Tool Reference
document_validator.py
Validates document metadata, numbering conventions, and regulatory control requirements.
Flag
Required
Description
--doc
Yes (or --interactive or --sample)
Path to document metadata JSON file containing number, title, type, revision, status, dates, approvers, change history, and Part 11 fields
--interactive
No
Launch interactive validation mode for guided document entry
--output
No
Output format: json for structured output with severity-rated findings, omit for human-readable text
--sample
No
Generate a sample document JSON template (pipe to file with > sample_doc.json)
1---2name: quality-documentation-manager3description: Document control for medical device QMS, covering numbering, version control, change management, and 21 CFR Part 11 compliance. Use for document control procedures, change control workflows, and electronic signature compliance.4license: MIT + Commons Clause5---6# Quality Documentation Manager
78Document control system design and management for ISO 13485-compliant quality management systems, including numbering conventions, approval workflows, change control, and electronic record compliance.
910---
1112## Table of Contents
1314- [Document Control Workflow](#document-control-workflow)
15- [Document Numbering System](#document-numbering-system)
16- [Approval and Review Process](#approval-and-review-process)
17- [Change Control Process](#change-control-process)
18- [21 CFR Part 11 Compliance](#21-cfr-part-11-compliance)
19- [Reference Documentation](#reference-documentation)
20- [Tools](#tools)
2122---
2324## Clarify First
2526Before setting up document control or validating a document, confirm these inputs. If any is unknown or vague, ASK — do not assume:
2728- [ ] **Document type** — QM, SOP, WI, TF, SPEC, or PLN (sets the required reviewers, approvers, and numbering)
29- [ ] **Regulatory scope** — ISO 13485 only vs 21 CFR Part 11 electronic records (determines whether audit-trail and e-signature controls are required)
30- [ ] **Change classification** — administrative, minor, major, or emergency (sets the approval path and impact assessment)
3132Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the document.
3334## Document Control Workflow
3536Implement document control from creation through obsolescence:
37381. Assign document number per numbering procedure
392. Create document using controlled template
403. Route for review to required reviewers
414. Address review comments and document responses
425. Obtain required approval signatures
436. Assign effective date and distribute
447. Update Document Master List
458. **Validation:** Document accessible at point of use; obsolete versions removed
4647### Document Lifecycle Stages
4849| Stage | Definition | Actions Required |
50|-------|------------|------------------|
51| Draft | Under creation or revision | Author editing, not for use |
52| Review | Circulated for review | Reviewers provide feedback |
53| Approved | All signatures obtained | Ready for training/distribution |
54| Effective | Training complete, released | Available for use |
55| Superseded | Replaced by newer revision | Remove from active use |
56| Obsolete | No longer applicable | Archive per retention schedule |
5758### Document Types and Prefixes
5960| Prefix | Document Type | Typical Content |
61|--------|---------------|-----------------|
62| QM | Quality Manual | QMS overview, scope, policy |
63| SOP | Standard Operating Procedure | Process-level procedures |
64| WI | Work Instruction | Task-level step-by-step |
65| TF | Template/Form | Controlled forms |
66| SPEC | Specification | Product/process specs |
67| PLN | Plan | Quality/project plans |
6869### Required Reviewers by Document Type
7071| Document Type | Required Reviewers | Required Approvers |
72|---------------|-------------------|-------------------|
73| SOP | Process Owner, QA | QA Manager, Process Owner |
74| WI | Area Supervisor, QA | Area Manager |
75| SPEC | Engineering, QA | Engineering Manager, QA |
76| TF | Process Owner | QA |
77| Design Documents | Design Team, QA | Design Control Authority |
7879---
8081## Document Numbering System
8283Assign consistent document numbers for identification and retrieval.
8485### Numbering Format
8687Standard format: `PREFIX-CATEGORY-SEQUENCE[-REVISION]`
8889```
90Example: SOP-02-001-A
9192SOP = Document type (Standard Operating Procedure)
9302 = Category code (Document Control)
94001 = Sequential number
95A = Revision indicator
96```
9798### Category Codes
99100| Code | Functional Area | Description |
101|------|-----------------|-------------|
102| 01 | Quality Management | QMS procedures, management review |
103| 02 | Document Control | This area |
104| 03 | Human Resources | Training, competency |
105| 04 | Design & Development | Design control processes |
106| 05 | Purchasing | Supplier management |
107| 06 | Production | Manufacturing procedures |
108| 07 | Quality Control | Inspection, testing |
109| 08 | CAPA | Corrective/preventive actions |
110| 09 | Risk Management | ISO 14971 processes |
111| 10 | Regulatory Affairs | Submissions, compliance |
112113### Numbering Workflow
1141151. Author requests document number from Document Control
1162. Document Control verifies category assignment
1173. Document Control assigns next available sequence number
1184. Number recorded in Document Master List
1195. Author creates document using assigned number
1206. **Validation:** Number format matches standard; no duplicates in Master List
121122### Revision Designation
123124| Change Type | Revision Increment | Example |
125|-------------|-------------------|---------|
126| Major revision | Increment number | Rev 01 → Rev 02 |
127| Minor revision | Increment sub-revision | Rev 01 → Rev 01.1 |
128| Administrative | No change or letter suffix | Rev 01 → Rev 01a |
129130See `references/document-control-procedures.md` for complete numbering guidance.
131132---
133134## Approval and Review Process
135136Obtain required reviews and approvals before document release.
137138### Review Workflow
1391401. Author completes document draft
1412. Author submits for review via routing form or DMS
1423. Reviewers assigned based on document type
1434. Reviewers provide comments within review period (5-10 business days)
1445. Author addresses comments and documents responses
1456. Author resubmits revised document
1467. Approvers sign and date
1478. **Validation:** All required reviewers completed; all comments addressed with documented disposition
148149### Comment Disposition
150151| Disposition | Action Required |
152|-------------|-----------------|
153| Accept | Incorporate comment as written |
154| Accept with modification | Incorporate with changes, document rationale |
155| Reject | Do not incorporate, document justification |
156| Defer | Address in future revision, document reason |
157158### Approval Matrix
159160```
161Document Level 1 (Policy/QM): CEO or delegate + QA Manager
162Document Level 2 (SOP): Department Manager + QA Manager
163Document Level 3 (WI/TF): Area Supervisor + QA Representative
164```
165166### Signature Requirements
167168| Element | Requirement |
169|---------|-------------|
170| Name | Printed name of signer |
171| Signature | Handwritten or electronic signature |
172| Date | Date signature applied |
173| Role | Function/role of signer |
174175---
176177## Change Control Process
178179Manage document changes systematically through review and approval.
180181### Change Control Workflow
1821831. Identify need for document change
1842. Complete Change Request Form with justification
1853. Document Control assigns change number and logs request
1864. Route to reviewers for impact assessment
1875. Obtain approvals based on change classification
1886. Author implements approved changes
1897. Update revision number and change history
1908. **Validation:** Changes match approved scope; change history complete
191192### Change Classification
193194| Class | Definition | Approval Level | Examples |
195|-------|------------|----------------|----------|
196| Administrative | No content impact | Document Control | Typos, formatting |
197| Minor | Limited content change | Process Owner + QA | Clarifications |
198| Major | Significant content change | Full review cycle | New requirements |
199| Emergency | Urgent safety/compliance | Expedited + retrospective | Safety issues |
200201### Impact Assessment Checklist
202203| Impact Area | Assessment Questions |
204|-------------|---------------------|
205| Training | Does change require retraining? |
206| Equipment | Does change affect equipment or systems? |
207| Validation | Does change require revalidation? |
208| Regulatory | Does change affect regulatory filings? |
209| Other Documents | Which related documents need updating? |
210| Records | What records are affected? |
211212### Change History Documentation
213214Each document must include change history:
215216```
217| Revision | Date | Description | Author | Approver |
218|----------|------|-------------|--------|----------|
219| 01 | 2023-01-15 | Initial release | J. Smith | M. Jones |
220| 02 | 2024-03-01 | Updated workflow | J. Smith | M. Jones |
221```
222223---
224225## 21 CFR Part 11 Compliance
226227Implement electronic record and signature controls for FDA compliance.
228229### Part 11 Scope
230231| Applies To | Does Not Apply To |
232|------------|-------------------|
233| Records required by FDA regulations | Paper records |
234| Records submitted to FDA | Internal non-regulated documents |
235| Electronic signatures on required records | General email communication |
236237### Electronic Record Controls
2382391. Validate system for accuracy and reliability
2402. Implement secure audit trail for all changes
2413. Restrict system access to authorized individuals
2424. Generate accurate copies in human-readable format
2435. Protect records throughout retention period
2446. **Validation:** Audit trail captures who, what, when for all changes
245246### Audit Trail Requirements
247248| Requirement | Implementation |
249|-------------|----------------|
250| Secure | Cannot be modified by users |
251| Computer-generated | System creates automatically |
252| Time-stamped | Date and time of each action |
253| Original values | Previous values retained |
254| User identity | Who made each change |
255256### Electronic Signature Requirements
257258| Requirement | Implementation |
259|-------------|----------------|
260| Unique to individual | Not shared between persons |
261| At least 2 components | User ID + password minimum |
262| Signature manifestation | Name, date/time, meaning displayed |
263| Linked to record | Cannot be excised or copied |
264265### Signature Manifestation
266267Every electronic signature must display:
268269| Element | Example |
270|---------|---------|
271| Printed name | John Smith |
272| Date and time | 2024-03-15 14:32:05 EST |
273| Meaning | Approved for Release |
274275### System Controls Checklist
276277**Access Controls:**
278- [ ] Unique user ID for each person
279- [ ] Password complexity enforced
280- [ ] Account lockout after failed attempts
281- [ ] Session timeout after inactivity
282283**Audit Trail:**
284- [ ] All record creation logged
285- [ ] All modifications logged with old/new values
286- [ ] User identity captured
287- [ ] Date/time stamp on all entries
288289**Security:**
290- [ ] Role-based access control
291- [ ] Encryption for data at rest and in transit
292- [ ] Regular backup and tested recovery
293294See `references/21cfr11-compliance-guide.md` for detailed compliance requirements.
295296---
297298## Reference Documentation
299300### Document Control Procedures
301302`references/document-control-procedures.md` contains:
303304- Document numbering system and format
305- Document lifecycle stages and transitions
306- Review and approval workflow details
307- Change control process with classification criteria
308- Distribution and access control methods
309- Record retention periods and disposal procedures
310- Document Master List requirements
311312### 21 CFR Part 11 Compliance Guide
313314`references/21cfr11-compliance-guide.md` contains:
315316- Part 11 scope and applicability
317- Electronic record requirements (§11.10)
318- Electronic signature requirements (§11.50, 11.100, 11.200)
319- System control specifications
320- Validation approach and documentation
321- Compliance checklist and gap assessment template
322- Common FDA deficiencies and prevention
323324---
325326## Tools
327328### Document Validator
329330```bash
331# Validate document metadata
332python scripts/document_validator.py --doc document.json
333334# Interactive validation mode
335python scripts/document_validator.py --interactive
336337# JSON output for integration
338python scripts/document_validator.py --doc document.json --output json
339340# Generate sample document JSON
341python scripts/document_validator.py --sample > sample_doc.json
342```
343344Validates:
345- Document numbering convention compliance
346- Title and status requirements
347- Date validation (effective, review due)
348- Approval requirements by document type
349- Change history completeness
350- 21 CFR Part 11 controls (audit trail, signatures)
351352### Sample Document Input
353354```json
355{
356 "number": "SOP-02-001",
357 "title": "Document Control Procedure",
358 "doc_type": "SOP",
359 "revision": "03",
360 "status": "Effective",
361 "effective_date": "2024-01-15",
362 "review_date": "2025-01-15",
363 "author": "J. Smith",
364 "approver": "M. Jones",
365 "change_history": [
366 {"revision": "01", "date": "2022-01-01", "description": "Initial release"},
367 {"revision": "02", "date": "2023-01-15", "description": "Updated workflow"},
368 {"revision": "03", "date": "2024-01-15", "description": "Added e-signature requirements"}
369 ],
370 "has_audit_trail": true,
371 "has_electronic_signature": true,
372 "signature_components": 2
373}
374```
375376---
377378## Document Control Metrics
379380Track document control system performance.
381382### Key Performance Indicators
383384| Metric | Target | Calculation |
385|--------|--------|-------------|
386| Document cycle time | <30 days | Average days from draft to effective |
387| Review completion rate | >95% | Reviews completed on time / Total reviews |
388| Change request backlog | <10 | Open change requests at month end |
389| Overdue review rate | <5% | Documents past review date / Total effective |
390| Audit finding rate | <2 per audit | Document control findings per internal audit |
391392### Periodic Review Schedule
393394| Document Type | Review Frequency |
395|---------------|------------------|
396| Policy | Every 3 years |
397| SOP | Every 2 years |
398| WI | Every 2 years |
399| Specifications | As needed or with product changes |
400| Forms/Templates | Every 3 years |
401402---
403404## Regulatory Requirements
405406### ISO 13485:2016 Clause 4.2
407408| Sub-clause | Requirement |
409|------------|-------------|
410| 4.2.1 | Quality management system documentation |
411| 4.2.2 | Quality manual |
412| 4.2.3 | Medical device file (technical documentation) |
413| 4.2.4 | Control of documents |
414| 4.2.5 | Control of records |
415416### FDA 21 CFR 820
417418| Section | Requirement |
419|---------|-------------|
420| 820.40 | Document controls |
421| 820.180 | General record requirements |
422| 820.181 | Device master record |
423| 820.184 | Device history record |
424| 820.186 | Quality system record |
425426### Common Audit Findings
427428| Finding | Prevention |
429|---------|------------|
430| Obsolete documents in use | Implement distribution control |
431| Missing approval signatures | Enforce workflow before release |
432| Incomplete change history | Require history update with each revision |
433| No periodic review schedule | Establish and enforce review calendar |
434| Inadequate audit trail | Validate DMS for Part 11 compliance |
435436---
437438## Troubleshooting
439440| Problem | Likely Cause | Resolution |
441|---------|-------------|------------|
442| Document validator reports "invalid numbering format" | Document number does not match the `PREFIX-CATEGORY-SEQUENCE` pattern | Ensure the number follows the format `SOP-02-001` (type prefix, 2-digit category code, 3-digit sequence). Check that the prefix matches a recognized document type (QM, SOP, WI, TF, SPEC, PLN). |
443| Validation flags missing approver despite having signatures | `approver` field is null or empty in the input JSON | Populate the `approver` field with the name of the approving authority. For SOPs, both Process Owner and QA Manager are required. |
444| Review date validation fails for a current document | `review_date` is in the past | Update the review date to reflect the next scheduled review. Documents past their review date should be flagged for periodic review and re-approval. |
445| Change history marked incomplete | Not all revisions have entries in the `change_history` array | Every revision increment must have a corresponding change history entry with revision number, date, description, and author. Fill gaps in the history. |
446| Part 11 controls flagged despite using an eDMS | `has_audit_trail` or `has_electronic_signature` set to false | Set both to `true` and ensure `signature_components` is at least 2 (user ID + password minimum per Part 11). Verify the eDMS produces computer-generated, timestamped audit trails. |
447| Interactive mode does not display all validation rules | Terminal width too narrow for table output | Widen the terminal window or use `--output json` for structured output that is not affected by display width. |
448| Obsolete documents still appearing as "Effective" | Status field not updated during revision cycle | When a new revision is released, update the prior revision's status to "Superseded" and ensure it is removed from points of use. Run the validator against the superseded document to confirm. |
449450---
451452## Success Criteria
453454- Document numbering system enforced with zero duplicate numbers in the Document Master List and 100% format compliance
455- Document cycle time (draft to effective) averages less than 30 business days across all document types
456- Review completion rate exceeds 95% (reviews completed on time vs. total reviews initiated)
457- Overdue periodic review rate below 5% of total effective documents at any point
458- 21 CFR Part 11 compliance verified for all electronic records: audit trails capture who/what/when for every change, electronic signatures include printed name, date/time, and meaning
459- Change control process handles 100% of document changes through the classification workflow (Administrative/Minor/Major/Emergency) with documented impact assessments
460- Zero external audit findings related to document control in the most recent certification or surveillance audit
461462---
463464## Scope & Limitations
465466**In Scope:**
467- Document numbering convention design and validation
468- Document lifecycle management (Draft through Obsolete)
469- Review and approval workflow enforcement
470- Change control process with classification and impact assessment
471- 21 CFR Part 11 electronic record and electronic signature compliance validation
472- Periodic review schedule management
473- Document Master List maintenance
474475**Out of Scope:**
476- eDMS software selection, implementation, or validation (the tool validates metadata, not the DMS platform itself)
477- EU Annex 11 computerized system validation (complementary to Part 11 but requires separate assessment approach)
478- Technical file / Design History File content creation (use regulatory-affairs-head for technical documentation)
479- Record retention schedule creation (the tool validates dates but does not determine regulatory retention periods)
480- Physical document distribution or archival logistics
481- Training record management (the tool validates training-related documents but does not manage training programs)
482483---
484485## Integration Points
486487| Skill | Integration |
488|-------|------------|
489| [quality-manager-qms-iso13485](../quality-manager-qms-iso13485/) | Document control (Clause 4.2.3) and record control (Clause 4.2.4) are core QMS processes; the validator enforces ISO 13485 documentation requirements |
490| [qms-audit-expert](../qms-audit-expert/) | Internal audits of Clause 4.2 verify document control effectiveness; audit findings drive document process improvements |
491| [quality-manager-qmr](../quality-manager-qmr/) | Document control metrics (cycle time, overdue reviews, backlog) are reported to management review as QMS performance indicators |
492| [fda-consultant-specialist](../fda-consultant-specialist/) | FDA QMSR (effective Feb 2026) incorporates ISO 13485 Clause 4.2 by reference; Part 11 compliance remains a separate FDA requirement for electronic records |
493| [capa-officer](../capa-officer/) | CAPA actions frequently require document revisions; the change control process tracks CAPA-driven document changes |
494495---
496497## Tool Reference
498499### document_validator.py
500501Validates document metadata, numbering conventions, and regulatory control requirements.
502503| Flag | Required | Description |
504|------|----------|-------------|
505| `--doc` | Yes (or `--interactive` or `--sample`) | Path to document metadata JSON file containing number, title, type, revision, status, dates, approvers, change history, and Part 11 fields |
506| `--interactive` | No | Launch interactive validation mode for guided document entry |
507| `--output` | No | Output format: `json` for structured output with severity-rated findings, omit for human-readable text |
508| `--sample` | No | Generate a sample document JSON template (pipe to file with `> sample_doc.json`) |
Run npx skillmds@latest add borghei/quality-documentation-manager in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Document control for medical device QMS, covering numbering, version control, change management, and 21 CFR Part 11 compliance. Use for document control procedures, change control workflows, and electronic signature compliance. It is listed under Docs & Writing on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free. This skill is licensed under MIT + Commons Clause.
borghei (@borghei) published this skill. Their other Agent Skills are listed on their SkillMD profile.