Contact

What are you looking for?

ISO 9001 vs. ISO 13485: Why Do Companies Struggle When Transitioning to ISO 13485?

SGS North America BlogCertificationAugust 24, 2026

The level of rigor increases substantially.

The first edition of the customer-service standard ISO 9001:1994 was used, in part, to help develop the first edition of the medical device industry-specific standard ISO 13485:1996. Although both standards are quality management system standards that emphasize process control, documentation, corrective action, and continual improvement, ISO 13485 has evolved over the years to serve the unique needs of the medical device industry.

A company that performs well under ISO 9001 may still struggle significantly under ISO 13485 if it lacks:

  1. Regulatory and legal discipline across the jurisdictions in which it plans to sell products
  2. Strategies for identifying, creating, documenting, and updating medical device evidence
  3. Medical device lifecycle controls
  4. A strong documentation integration process

This becomes particularly visible during audits.

How does risk management differ between the two standards?

This is one of the biggest differences. ISO 9001 introduced the concept of "risk-based thinking," but ISO 13485 requires a much deeper and more structured integration of risk management.

Under ISO 13485, risk management shall be applied throughout product realization (commercialization) and is often linked directly to the medical device risk management standard, ISO 14971.

You will not go to jail because you did not say "hello," "thank you," or "How was our customer service?" The risks are significantly higher for medical device manufacturers.

These risks may include:

  1. Design
  2. Suppliers
  3. Production
  4. Usability
  5. Contamination
  6. Labeling
  7. Shipping
  8. Post-market surveillance

Risk management is not optional or conceptual. It becomes operational. This is one of the primary reasons many ISO 9001 organizations initially struggle with medical device industry expectations.

Why is documentation far more important under ISO 13485?

Many ISO 9001 systems are relatively flexible regarding documentation structure. ISO 13485 is different. The medical device industry operates under significant regulatory and legal scrutiny, meaning organizations must demonstrate:

  1. Traceability
  2. Consistency
  3. Validation
  4. Control of records
  5. Documented evidence of conformity

ISO 13485 includes numerous mandatory documented procedures and records, such as:

  1. Complaint handling
  2. CAPA
  3. Internal audits
  4. Supplier controls
  5. Risk management
  6. Clinical evaluations
  7. Document control
  8. Validation activities

This creates a much more structured documentation environment that must align with the jurisdictions where the medical device is marketed and sold.

Why do supplier controls become much stricter under ISO 13485?

Under ISO 9001, supplier evaluation is important for customer satisfaction. Under ISO 13485, supplier failure can directly impact patient safety and regulatory compliance. That changes the expected depth of control.

Organizations may need:

  1. Supplier qualification programs
  2. Risk-based supplier classification
  3. Validation of outsourced processes
  4. Quality agreements
  5. Supplier monitoring
  6. Enhanced traceability

This becomes particularly important for:

  1. Sterilization providers
  2. Contract manufacturers
  3. Software developers
  4. Component suppliers

Many companies underestimate how much supplier oversight expands under ISO 13485.

Can a company be certified to both ISO 9001 and ISO 13485?

Yes. Many organizations implement integrated management systems. However, organizations should not assume that ISO 13485 is simply ISO 9001 with a few additional procedures. The standards operate with different priorities, expectations, and regulatory requirements.

Conclusion: ISO 13485 Is a Regulatory Operating Model for Medical Devices

The transition to ISO 13485 involves far more than adding procedures. It requires organizations to adopt a fundamentally different mindset.

And yes, saying "hello," "please," and "thank you" is always appreciated!

ISO 13485 demands a level of discipline that extends beyond traditional quality management. Organizations must demonstrate robust risk management, stronger documentation controls, comprehensive supplier oversight, and an ongoing commitment to regulatory compliance throughout the product lifecycle.

Learn More with SGS Training

Want to know more? Visit SGS's Training Academy:

USA Training: SGS USA Training

Canada Training: SGS Canada Training

News & Insights

  • SGS - USA - Bloomfield

400 Broadacres Drive,

Suite 200, 2nd Floor,

Bloomfield, New Jersey, 07003,

United States