Skip to main content
v2026.11,610 entries · CC-BY 4.0

Quality Manual for a Regulated Organisation: Scope, Process Interactions, and ISO 13485 vs. GMP

A regulatory quality manual is an auditable artefact with defined scope, justified exclusions, process interactions, and a document-hierarchy outline — not a marketing statement of intent. Here is what ISO 13485:2016 clause 4.2.2 actually requires, and why GMP frameworks handle the same territory through a different document altogether.

Ask about Quality Manual for a Regulated Organisation: Scope, Process Interactions, and ISO 13485 vs. GMP

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

A quality manual that reads like a mission statement — a page of “we are committed to quality” language with a signature block — fails an audit against ISO 13485:2016 clause 4.2.2 even if every procedure underneath it is sound. The clause does not ask for a statement of intent. It asks for four specific things, and an auditor checking clause 4.2.2 compliance is checking for the presence of each one, not for tone.

What ISO 13485:2016 Clause 4.2.2 Actually Requires

Clause 4.2.2 requires the organization to establish and maintain a quality manual that contains, at minimum:

  • The scope of the quality management system, including detail of and justification for any requirement of the standard the organization has determined does not apply (an exclusion).
  • The documented procedures established for the quality management system, or a reference to where they are held.
  • A description of the interaction between the processes of the quality management system.
  • An outline of the structure of the documentation used in the quality management system.

ISO 9001:2015 dropped the mandatory quality manual entirely when it moved to the Annex SL high-level structure. ISO 13485:2016 deliberately kept it — see CASRAI’s ISO 13485 guide for the fuller structural comparison between the two standards. The practical consequence for device manufacturers: as of the Quality Management System Regulation (QMSR) taking effect February 2, 2026, FDA incorporates ISO 13485:2016 directly into 21 CFR 820 by reference (see CASRAI’s 21 CFR Part 820 subpart map), so clause 4.2.2 is now a binding requirement on US device manufacturers, not just an ISO-certification-scheme expectation.

Scope and Exclusions — the Part Most Manuals Get Wrong

The scope statement is not a company description. It is a precise boundary: which product families, which sites, which processes are inside the QMS, stated in language that maps onto the standard’s own clause structure. Exclusions are the part that trips up manuals written as marketing documents, because an exclusion is only legitimate in narrow circumstances — clause 4.2.2 permits excluding a requirement only where the organization’s product type or activities genuinely make that requirement inapplicable (a contract manufacturer that never performs its own design and development work can reasonably exclude clause 7.3 design controls for that product line; a distributor that never services devices in the field can exclude the servicing requirements). Each exclusion needs its own stated justification in the manual itself. A manual that lists exclusions with no justification attached, or that excludes a requirement because it would be inconvenient to satisfy rather than because it is genuinely inapplicable, is a standing nonconformity waiting to be found during a stage 2 audit or an FDA inspection.

Process Interactions — Not an Org Chart

The interaction requirement asks the manual to show how the QMS processes connect — inputs, outputs, and handoffs — not to reproduce an organizational chart of who reports to whom. A design-and-development process that never states what it hands to purchasing, or a CAPA process with no stated link back into management review, has not satisfied this element even if both processes are individually well documented. Framed against the clause map in CASRAI’s ISO 13485 guide, this is typically where a manual needs to show, at minimum: how design and development (7.3) output feeds purchasing (7.4) and production (7.5); how complaint handling (8.2.2) and nonconforming-product control (8.3) feed corrective and preventive action (8.5.2, 8.5.3); and how CAPA and internal audit (8.2.4) results feed management review (5.6). A single process-interaction diagram with a short narrative for each connection satisfies this more reliably than prose alone, because a reader (including an auditor) can trace a specific handoff without hunting through paragraphs.

Document Hierarchy — What the Manual Points To, Not What It Restates

The fourth 4.2.2 element — an outline of the documentation structure — is where manuals most often over-deliver in the wrong direction. Its job is to describe the hierarchy, not reproduce the content underneath it. A typical regulated-QMS hierarchy runs:

  • Level 1 — the quality manual itself. States scope, exclusions, process interactions, and points to Level 2.
  • Level 2 — procedures (SOPs). Define what happens, who is responsible, and when, for each QMS process named in the manual (design control, purchasing, CAPA, internal audit, and so on).
  • Level 3 — work instructions, forms, and templates. Step-by-step “how,” specific enough that two trained operators produce the same result.
  • Level 4 — records. The evidence that Levels 2 and 3 were actually followed — the artefacts an auditor samples.

A manual that pastes SOP-level content directly into itself creates two sources of truth for the same procedure, and the two drift out of sync the first time either one is revised without the other — a recurring finding in device-manufacturer audits. The manual’s job under 4.2.2 is to name and reference the hierarchy (for example, pointing to a design history file structure like the one in CASRAI’s design history file guide, or to the broader design controls procedure set) rather than to absorb it.

How GMP Handles the Same Territory Differently

This is where a quality manual written for a device company and a “quality system description” written for a drug or biologics manufacturer diverge, and conflating the two is a common source of confusion for organizations that operate under both frameworks.

US drug current Good Manufacturing Practice (21 CFR 211) has no clause that names a “quality manual” or mandates a single document with clause 4.2.2’s specific four-part content list. The operative mechanism instead is the quality control unit: 211.22 establishes that a quality control unit must exist with defined responsibility and authority to approve or reject materials, procedures, and specifications affecting drug identity, strength, quality, and purity, and written procedures are then required subpart by subpart (211.100 and elsewhere) rather than indexed under one governing manual. A drug manufacturer can be fully cGMP-compliant without any document titled “quality manual” existing at all.

ICH Q10 (Pharmaceutical Quality System) is the closest GMP-world analogue, and CASRAI has a dedicated ICH Q10 definition covering its scope and adoption history. Q10 sits above baseline GMP and describes how a firm’s pharmaceutical quality system should function across the product lifecycle, through four management enablers (process performance and product quality monitoring, CAPA, change management, and management review). But Q10 is harmonized guidance, not a binding clause with a mandated document structure the way ISO 13485 §4.2.2 is — it describes an approach to documenting the PQS rather than requiring one specific “quality manual” artefact with a fixed content list.

EU GMP adds a third, genuinely different document into this picture: the Site Master File, described in EudraLex Volume 4 explanatory guidance. A Site Master File describes the manufacturing and quality-control activities actually carried out at a specific site, for use by inspectors and competent authorities assessing that site — it answers “what happens here,” not “how is our QMS scoped and structured,” and it is not a substitute for either a 13485-style quality manual or an ICH Q10 PQS description. See CASRAI’s GCP vs. GLP vs. GMP comparison for how the underlying ICH quality standards differ more broadly.

The practical consequence: an organization operating under both ISO 13485 (as a device manufacturer, or as a combination-product manufacturer with a device component) and GMP frequently maintains a genuine 4.2.2-compliant quality manual because 13485/QMSR requires one, plus separate GMP-facing documentation — a Site Master File if operating in the EU, a documented PQS approach per ICH Q10 — because GMP asks for those instead. These documents are not interchangeable, and an auditor working from one framework will ask for the document their framework actually names, not whichever one the organization happens to have on hand.

ISO 13485 §4.2.2 vs. GMP: Side by Side

Dimension ISO 13485:2016 §4.2.2 GMP (21 CFR 211 / ICH Q10 / EU GMP)
Named document required by the rule itself Yes — “the quality manual,” by name No single named document; 21 CFR 211 has no quality-manual clause
Mandated content list Fixed four elements: scope/exclusions, procedure reference, process interactions, documentation-structure outline Not prescribed; ICH Q10 describes a PQS approach without mandating a document’s contents
Exclusions mechanism Explicit — must be stated and justified in the manual itself No equivalent exclusions clause; scope is set by which cGMP subparts apply to the operation
Site-level operational description Not a 4.2.2 requirement (that’s what the QMS-scope statement is for, at a different level) EU GMP: a separate Site Master File, submitted for inspection/licensing purposes
Enforcement route Certification-body audit; in the US, now also FDA inspection via QMSR incorporation (effective Feb 2, 2026) FDA/EMA inspection against cGMP; ICH Q10 itself is guidance, not binding regulation

Failure Modes an Auditor Will Flag

  • Marketing language instead of a scope statement. “We strive for excellence in everything we do” is not a QMS scope. A scope statement names the product families, sites, and clause boundaries in scope.
  • Exclusions with no justification. Listing “7.3 Design and Development — excluded” with nothing else is not compliant; the justification has to be present in the manual.
  • A process map with no narrative. A diagram of boxes and arrows satisfies the letter of “interaction between processes” only if it is legible enough that an auditor can trace an actual handoff — otherwise it invites a finding anyway.
  • SOP content pasted into the manual. Creates a duplicate source of truth that goes stale the moment either copy is revised without the other.
  • Treating a GMP quality-system description as a 13485 quality manual, or vice versa. The two frameworks name different documents for different purposes; substituting one for the other under audit does not satisfy either clause.

Frequently Asked Questions

Does ISO 9001 still require a quality manual?

No. ISO 9001:2015 removed the mandatory quality manual when it adopted the Annex SL high-level structure shared across modern management-system standards. ISO 13485:2016 deliberately did not follow Annex SL and kept the quality manual requirement at clause 4.2.2. See CASRAI’s ISO 13485 guide for the broader set of requirements ISO 13485 retained after ISO 9001 dropped them.

Is a quality manual required under FDA’s QMSR?

Yes, as of the QMSR’s effective date of February 2, 2026, FDA incorporates ISO 13485:2016 by reference into 21 CFR 820 for device manufacturers, which carries clause 4.2.2’s quality-manual requirement with it. See CASRAI’s 21 CFR Part 820 guide for the current subpart-by-subpart transition status.

Can a small manufacturer combine the quality manual and its top-level procedures into one document?

Clause 4.2.2 does not mandate a specific page count or physical separation between documents, only that the four required elements be present and that procedures be either included or clearly referenced. A small organization can combine documents as long as an auditor can still identify each required element distinctly; combining them does not remove the requirement to state scope, justify exclusions, and describe process interactions.

What happens if an exclusion in the manual isn’t justified?

It is treated as a nonconformity during certification audit or regulatory inspection — an unjustified exclusion is functionally the same as claiming compliance with a requirement the organization has not actually addressed.

Does GMP have a real equivalent to ISO’s quality manual?

Not a direct one. 21 CFR 211 governs the same territory through the quality control unit’s defined authority (211.22) and subpart-specific written procedures rather than one named manual. ICH Q10 describes how a pharmaceutical quality system should function without mandating a specific document’s contents, and EU GMP’s Site Master File serves a different, site-operational purpose rather than the QMS-scope-and-exclusions role clause 4.2.2 assigns to a quality manual.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.