QMS Nordic
PrivacyTermsSecuritySub-processorsAI ActValidation

← Software validation pack

Regulatory mapping annex — QMS Nordic platform

Regulatory mapping annex — QMS Nordic platform
Document IDQMSN-RMA-001
Applies toQMS Nordic v1.5.0
Generatedfrom the source of truth, not written by hand

Generated from the platform's requirement register, not written by hand, and regenerated on every change. A build check fails if this document falls out of step with the code it describes, so it cannot quietly stop being true — which is what happens to a hand-maintained matrix within two releases.


This annex inverts the traceability matrix. The matrix answers what evidence supports this requirement; this answers what do you claim against this clause, which is the question an auditor actually opens with.

It maps our platform requirements only. It is not a conformity assessment of your device, your quality system, or your use of the platform — a clause appearing here means we hold a requirement against it, not that your obligation under it is discharged. Clauses we make no claim against are absent rather than listed as satisfied.

Requirements with no evidence are marked (no evidence) and are yours to test.

21 CFR Part 11

21 CFR Part 11
ClauseRequirementsRisk
21 CFR Part 11 §11.10(b)URS-AUD-04, URS-RET-02High
21 CFR Part 11 §11.10(c)URS-RET-01High
21 CFR Part 11 §11.10(d)URS-ACC-01, URS-ACC-04 (no evidence)High
21 CFR Part 11 §11.10(e)URS-AUD-01, URS-AUD-02, URS-AUD-03, URS-AUD-04, URS-SIG-04High
21 CFR Part 11 §11.10(g)URS-SIG-01High
21 CFR Part 11 §11.200URS-SIG-01High
21 CFR Part 11 §11.50URS-SIG-02High
21 CFR Part 11 §11.70URS-SIG-03, URS-SIG-04High

EU AI Act Art. 50 (where applicable)

EU AI Act Art. 50 (where applicable)
ClauseRequirementsRisk
EU AI Act Art. 50 (where applicable)URS-AI-01Medium

EU GMP Annex 11

EU GMP Annex 11
ClauseRequirementsRisk
EU GMP Annex 11 §7.2URS-RET-03High

FDA QMSR

FDA QMSR
ClauseRequirementsRisk
FDA QMSR §820.10URS-DOC-01, URS-DOC-02High

GDPR Art. 32

GDPR Art. 32
ClauseRequirementsRisk
GDPR Art. 32URS-ACC-02High

ISO 13485

ISO 13485
ClauseRequirementsRisk
ISO 13485 §4.1.6URS-ACC-01, URS-ACC-04 (no evidence), URS-CHG-01, URS-CHG-02High
ISO 13485 §4.2.4URS-DOC-01, URS-DOC-02, URS-AI-02, URS-AI-03, URS-AI-04High
ISO 13485 §4.2.4(a)URS-ACC-03High
ISO 13485 §4.2.4(b)URS-DOC-05Medium
ISO 13485 §4.2.4(d)URS-DOC-03High
ISO 13485 §4.2.4(f)URS-DOC-04High
ISO 13485 §4.2.5URS-AUD-01, URS-AUD-02, URS-ACC-02, URS-RET-01, URS-RET-02, URS-RET-03, URS-AI-01High
ISO 13485 §5.5.1URS-ACC-03High

What is not mapped here

  • Clauses we hold no requirement against. Their absence is the claim: we do not assert coverage of them. ISO 13485 as a whole is a quality system standard for your organisation; only the clauses touching computer software used in the QMS are in scope for a vendor pack.
  • Your device's own regulatory route. Nothing here speaks to MDR/IVDR classification, conformity assessment, or notified body engagement.
  • Clauses satisfied by process rather than software. Training, management review and supplier control are yours; the platform records them, which is not the same as satisfying them.

Risk is the highest rating among the requirements mapped to that clause, as rated in the traceability matrix. It is our rating of the requirement, not a rating of your risk — template T3 is where you decide that in your context.


QMSN-RMA-001 · v1.5.0 · pack rev. J (2026-09-07)
Published at qmsnordic.com/legal/validation/regulatory-mapping. Cite the version above in your validation record — a pack is evidence, and evidence has to stay retrievable at the version you validated against.

© 2026 Aitech International ApS · Denmark · All rights reserved.QMS Nordic™ is owned, developed, and copyright-protected by Aitech International ApS.
PrivacyTermsSecuritySub-processorsAI ActValidationHome