Regulatory mapping annex — QMS Nordic platform| Document ID | QMSN-RMA-001 |
| Applies to | QMS Nordic v1.5.0 |
| Generated | from the source of truth, not written by hand |
Generated from the platform's requirement register, not written by hand, and regenerated on every change. A build check fails if this document falls out of step with the code it describes, so it cannot quietly stop being true — which is what happens to a hand-maintained matrix within two releases.
This annex inverts the traceability matrix. The matrix answers what evidence supports this requirement; this answers what do you claim against this clause, which is the question an auditor actually opens with.
It maps our platform requirements only. It is not a conformity assessment of your device, your quality system, or your use of the platform — a clause appearing here means we hold a requirement against it, not that your obligation under it is discharged. Clauses we make no claim against are absent rather than listed as satisfied.
Requirements with no evidence are marked (no evidence) and are yours to test.
21 CFR Part 11
21 CFR Part 11| Clause | Requirements | Risk |
|---|
| 21 CFR Part 11 §11.10(b) | URS-AUD-04, URS-RET-02 | High |
| 21 CFR Part 11 §11.10(c) | URS-RET-01 | High |
| 21 CFR Part 11 §11.10(d) | URS-ACC-01, URS-ACC-04 (no evidence) | High |
| 21 CFR Part 11 §11.10(e) | URS-AUD-01, URS-AUD-02, URS-AUD-03, URS-AUD-04, URS-SIG-04 | High |
| 21 CFR Part 11 §11.10(g) | URS-SIG-01 | High |
| 21 CFR Part 11 §11.200 | URS-SIG-01 | High |
| 21 CFR Part 11 §11.50 | URS-SIG-02 | High |
| 21 CFR Part 11 §11.70 | URS-SIG-03, URS-SIG-04 | High |
EU AI Act Art. 50 (where applicable)
EU AI Act Art. 50 (where applicable)| Clause | Requirements | Risk |
|---|
| EU AI Act Art. 50 (where applicable) | URS-AI-01 | Medium |
EU GMP Annex 11
EU GMP Annex 11| Clause | Requirements | Risk |
|---|
| EU GMP Annex 11 §7.2 | URS-RET-03 | High |
FDA QMSR
FDA QMSR| Clause | Requirements | Risk |
|---|
| FDA QMSR §820.10 | URS-DOC-01, URS-DOC-02 | High |
GDPR Art. 32
GDPR Art. 32| Clause | Requirements | Risk |
|---|
| GDPR Art. 32 | URS-ACC-02 | High |
ISO 13485
ISO 13485| Clause | Requirements | Risk |
|---|
| ISO 13485 §4.1.6 | URS-ACC-01, URS-ACC-04 (no evidence), URS-CHG-01, URS-CHG-02 | High |
| ISO 13485 §4.2.4 | URS-DOC-01, URS-DOC-02, URS-AI-02, URS-AI-03, URS-AI-04 | High |
| ISO 13485 §4.2.4(a) | URS-ACC-03 | High |
| ISO 13485 §4.2.4(b) | URS-DOC-05 | Medium |
| ISO 13485 §4.2.4(d) | URS-DOC-03 | High |
| ISO 13485 §4.2.4(f) | URS-DOC-04 | High |
| ISO 13485 §4.2.5 | URS-AUD-01, URS-AUD-02, URS-ACC-02, URS-RET-01, URS-RET-02, URS-RET-03, URS-AI-01 | High |
| ISO 13485 §5.5.1 | URS-ACC-03 | High |
What is not mapped here
- Clauses we hold no requirement against. Their absence is the claim: we do not assert coverage of them. ISO 13485 as a whole is a quality system standard for your organisation; only the clauses touching computer software used in the QMS are in scope for a vendor pack.
- Your device's own regulatory route. Nothing here speaks to MDR/IVDR classification, conformity assessment, or notified body engagement.
- Clauses satisfied by process rather than software. Training, management review and supplier control are yours; the platform records them, which is not the same as satisfying them.
Risk is the highest rating among the requirements mapped to that clause, as rated in the traceability matrix. It is our rating of the requirement, not a rating of your risk — template T3 is where you decide that in your context.