ISO 13485 Contract Manufacturer: How to Verify One
What ISO 13485 certification actually buys you
When a contract manufacturer tells you it’s ISO 13485 certified, you’ve learned exactly one thing: the organization runs a quality management system built for medical devices, and a registrar has audited it against the standard. You haven’t learned whether the certificate covers your product, or whether the system works the way you need it to. This guide is about that gap, and how to check it when you’re sourcing from Taiwan.
ISO 13485:2016 is the international quality management standard for organizations that design, produce, install, and service medical devices. Unlike some quality standards, it’s built around regulatory requirements. The goal isn’t continual improvement for its own sake; it’s proving the factory can consistently produce devices that meet both customer and regulatory requirements. For a sourcing manager, that changes what the certification is worth. You’re not buying a plaque for the lobby. You’re buying a documented, auditable, traceable process.
ISO 13485 vs ISO 9001: why the distinction matters for sourcing
Both are quality management standards, and a factory can hold both. One doesn’t substitute for the other.
ISO 9001:2015 is a general standard that works for any industry; the emphasis is continual improvement and customer satisfaction. ISO 13485:2016 is specific to medical devices, and the emphasis is keeping an effective, documented, regulation-conformant system running. A few differences change what you can expect from a supplier:
- Regulatory conformance is baked in. ISO 13485 requires the organization to identify and meet applicable regulatory requirements throughout the process. ISO 9001 doesn’t.
- Documentation is heavier and mandatory. ISO 13485 requires documented procedures where ISO 9001 leaves more to the organization’s discretion. For a regulated device, that documentation is what makes the product defensible when questions come up.
- Risk is tied to safety and efficacy. ISO 13485’s risk-based thinking points at product safety and performance, and it works alongside ISO 14971 for medical-device risk management. ISO 9001’s risk focus is broader and more business-oriented.
- Structure. ISO 13485:2016 kept the earlier high-level clause structure instead of adopting the “Annex SL” layout ISO 9001:2015 uses, so the two don’t map clause for clause. That’s why a factory needs both certifications, and why you can’t assume 9001 covers medical work.
The practical takeaway: for a medical device, ISO 9001 alone isn’t enough. You want a manufacturer certified to ISO 13485, with a scope that matches your product. A supplier holding both tells you the same roof handles regulated devices and general appliance production.
Traceability: the thing you’re actually paying for
Traceability is the backbone of a 13485 system. For any finished device, the factory should be able to reconstruct which components went into it, which processes it passed through, who performed them, and what the inspection results were.
ISO 13485 requires records that provide traceability, and for higher-risk devices the requirements tighten. When you audit a supplier, this is the capability to probe hardest, because it’s the one that saves you during a field issue or recall. If a defect surfaces in a batch, traceability lets you scope the problem to one lot instead of every unit you’ve ever shipped.
How to verify it during an audit: pick a finished unit or a recent lot number and ask the supplier to walk it backward. They should produce component lot numbers, the production records for that batch, calibration status on the equipment used, and the inspection results, without a scramble. A supplier who can do that in front of you has a real system. One who promises to “send it later” may be describing a system that doesn’t exist yet.
Device History Record and the medical device file
Two documentation concepts are worth understanding before you audit, because they’re where 13485 turns process into evidence.
The Device History Record (DHR) is a term from FDA’s long-standing quality regulation (21 CFR 820, since harmonized with ISO 13485 under the QMSR). It’s the production record of a finished device or batch: the paperwork proving the device was built in accordance with its master record. ISO 13485 gets to the same outcome through its production records and its medical device file requirements: for each device type or family, the organization keeps a file containing or referencing the documents that demonstrate conformity. If the manufacturer sells into the US market, what you want to see is production records that satisfy DHR expectations, even where the FDA term isn’t used.
The medical device file (ISO 13485 clause 4.2.3) is the master reference for a device type: product specifications, manufacturing and inspection procedures, and where relevant, installation and servicing requirements. It answers “how this device is supposed to be built.” The production records answer “how this batch was actually built.” During an audit, ask to see a redacted medical device file and a completed batch record for the same product, then check that the second follows the first. The gaps between them are where quality problems live.
Design controls, even if you own the design
Design controls are the disciplined process for taking a device from requirements to a verified, validated, production-ready design: design inputs, outputs, review, verification, validation, transfer, and change control, all documented.
Sourcing managers sometimes figure design controls don’t matter when the brand owns the design and the factory only builds it. They still do, for two reasons. First, design transfer (moving a design into production) is itself a controlled step, and a factory that handles transfer poorly will introduce defects the incoming design never had. Second, once production starts, every engineering change you request flows through change control. A manufacturer with mature design controls handles your change orders with revision control and impact assessment. One without them makes ad-hoc changes that quietly break traceability.
If your contract manufacturer also does design and development work for you, the full design-control process is in scope, and the ISO 13485 certificate needs to say “design and development” in its scope statement, not just “manufacture.”
CAPA and complaint handling: how a factory learns
A quality system shows its worth in how it responds to failure. ISO 13485 requires corrective and preventive action (CAPA) and complaint-handling processes, and this is where you find out whether a manufacturer treats problems as events to close or as data to learn from.
Ask to see a closed CAPA record. A good one states the problem, the root-cause analysis, the correction, the preventive action taken to stop recurrence, and evidence that someone verified the fix worked. A weak one jumps from “problem” to “operator retrained” with nothing in between. That pattern means the same defect will come back. For complaint handling, ask how a field complaint from your market reaches the factory floor and how the response gets documented. For devices sold in regulated markets, that chain also connects to reporting obligations, so it has to be real.
Internal audits and management review
Two 13485 requirements tell you whether the system runs on its own or only when a customer is watching. Internal audits: the organization audits itself against the standard on a schedule. Management review: leadership formally reviews the quality data (audit results, complaints, CAPA status, nonconformances) and acts on it.
During a supplier audit, ask for the internal-audit schedule and a recent internal-audit report, and ask when the last management review happened. A factory that audits itself regularly, and whose management reviews produce actions, has a self-correcting system. One where these exist only as blank templates has a certificate but not a working QMS. That difference will show up in your product.
How to verify an ISO 13485 contract manufacturer when sourcing from Taiwan
Taiwan has a deep base of ISO 13485-certified manufacturers. That’s exactly why you need a verification routine instead of trust in the logo.
- Confirm the certificate is real and current. Get the certificate number, the certification body, and the accreditation behind it. Check it against the certification body’s registry or a cross-registrar database, and match the legal entity name to your contract.
- Read the scope statement. Confirm it covers your device type and the work you need: manufacture only, or design and development plus manufacture.
- Audit traceability live. Pull a lot number and have them walk it backward on the floor.
- Check documentation against reality. Compare a medical device file to an actual batch record for the same product.
- Test change control. Ask how an engineering change order moves through their system and who signs off.
- Confirm regulatory support matches your market. If you sell into the US, verify their production records meet DHR expectations, and ask what documentation and testing support they provide for submissions.
For the broader question of choosing a Taiwanese partner (the factory tour checklist, red flags, and IP protection), see our buyer’s guide to medical device contract manufacturers in Taiwan.
How we run it
Gooten Innolife holds ISO 13485:2016 and ISO 9001:2015 certification, and every certificate we hold is verifiable. Ask, and we’ll give you the numbers to check. We manufacture in Taichung, Taiwan, with production, R&D, and quality assurance on one site, so traceability questions and engineering changes get resolved on the floor.
Quality assurance runs across our five-phase process, with pre-production, in-process, and final inspection plus third-party testing. We have compliance experience with CE, FCC, RoHS, and PSE, and we provide documentation and testing support for FDA submissions. We’ve shipped more than 1,000,000 units to customers in over 50 countries, including a US hair-growth device leader who’s built four product generations with us since 2008.
You can review our quality and certifications and OEM/ODM services for the full picture.
Verify us before you commit
If you’re vetting an ISO 13485 contract manufacturer, put us through the checklist above. Contact our engineers, send the technical detail, and check our answers against your own audit standard.
NDA available before any technical discussion.