ISO 13485 Contract Manufacturer: How to Verify One
What ISO 13485 certification actually buys you
When a contract manufacturer says it is ISO 13485 certified, that tells you the organization runs a quality management system built for medical devices, and that a registrar has audited it against the standard. It does not tell you the certificate covers your product, or that the system works the way you need it to. This guide is about the difference, and how to check it when you’re sourcing from Taiwan.
ISO 13485:2016 is the international quality management standard for organizations involved in the design, production, installation, and servicing of medical devices. Unlike some quality standards, it is built around regulatory requirements: the goal isn’t continual improvement for its own sake, it’s demonstrating a consistent ability to produce devices that meet both customer and regulatory requirements. For a sourcing manager, that reframes what certification is worth. You’re not buying a plaque. You’re buying a documented, auditable, traceable process.
ISO 13485 vs ISO 9001 — why the distinction matters for sourcing
Both are quality management standards, and a factory can hold both. They are not interchangeable.
ISO 9001:2015 is a general quality standard applicable to any industry, and it emphasizes continual improvement and customer satisfaction. ISO 13485:2016 is medical-device specific and emphasizes maintaining an effective, documented, regulation-conformant system. A few differences that change what you can expect from a supplier:
- Regulatory conformance is baked in. ISO 13485 requires the organization to identify and meet applicable regulatory requirements throughout the process. ISO 9001 does not.
- Documentation is heavier and mandatory. ISO 13485 requires documented procedures where ISO 9001 leaves more to the organization’s discretion. For a regulated device, that documentation is what makes the product defensible.
- Risk is tied to safety and efficacy. ISO 13485’s risk-based thinking is oriented to product safety and performance, and it works alongside ISO 14971 for medical-device risk management. ISO 9001’s risk focus is broader and business-oriented.
- Structure. ISO 13485:2016 kept the earlier high-level clause structure rather than adopting the common “Annex SL” layout that ISO 9001:2015 uses, so the two don’t map clause-for-clause. This is why a factory needs both certifications rather than assuming 9001 covers medical work.
Practical takeaway: for a medical device, ISO 9001 alone is not enough. You want a manufacturer certified to ISO 13485, with the scope to match. A dual-certified supplier — ISO 13485 and ISO 9001 — signals a system that handles both regulated devices and general appliance production under one roof.
Traceability: the thing you’re actually paying for
Traceability is the backbone of a 13485 system. It’s the ability to reconstruct, for any finished device, which components went into it, which processes it passed through, who performed them, and what the inspection results were.
ISO 13485 requires the organization to establish records that provide traceability, and for higher-risk devices the requirements tighten. When you audit a supplier, this is the capability to probe hardest, because it’s the one that saves you during a field issue or recall. If a defect surfaces in a batch, traceability is what lets you scope the problem to a lot rather than to every unit you’ve ever shipped.
How to verify it during an audit: pick a finished unit or a recent lot number and ask the supplier to walk it backward. They should be able to produce component lot numbers, the production records for that batch, calibration status of the equipment used, and the inspection results, without a scramble. A supplier who can do this in front of you has a real system. One who promises to “send it later” may be describing a system that doesn’t exist yet.
Device History Record and the medical device file
Two documentation concepts are worth understanding before you audit, because they are where 13485 turns process into evidence.
The Device History Record (DHR) is a term from FDA’s long-standing quality regulation (21 CFR 820 — since harmonized with ISO 13485 under the QMSR) for the production record of a finished device or batch — the documentation proving the device was manufactured in accordance with its master record. ISO 13485 reaches the same outcome through its records of production and its medical device file requirements: for each device type or family, the organization keeps a file containing or referencing the documents that demonstrate conformity. When a manufacturer sells into the US market, you want to see that its production records satisfy DHR expectations even where the ISO term isn’t used.
The medical device file (ISO 13485 clause 4.2.3) is the master reference for a device type: product specifications, manufacturing and inspection procedures, and where relevant, installation and servicing requirements. It’s the “how this device is supposed to be built” document. The production records are the “how this batch was actually built” evidence. During an audit, ask to see a redacted medical device file and a completed batch record for the same product, and check that the second follows the first. Gaps between them are where quality problems live.
Design controls — even if you own the design
Design controls are the disciplined process for taking a device from requirements to a verified, validated, production-ready design: design inputs, outputs, review, verification, validation, transfer, and change control, all documented.
Sourcing managers sometimes assume design controls don’t matter when the brand owns the design and the factory only manufactures. They still do, for two reasons. First, design transfer — moving a design into production — is itself a controlled step, and a factory that handles transfer poorly will introduce defects no incoming design was responsible for. Second, every engineering change you request once production starts flows through change control. A manufacturer with mature design controls handles your change orders with revision control and impact assessment. One without them makes ad-hoc changes that quietly break traceability.
If your contract manufacturer also does design and development work for you, then the full design-control process is in scope, and the ISO 13485 certificate needs to say “design and development” in its scope statement, not just “manufacture.”
CAPA and complaint handling — how a factory learns
A quality system is only as good as its response to failure. ISO 13485 requires corrective and preventive action (CAPA) and complaint-handling processes, and these are where you see whether a manufacturer treats problems as events to close or as data to learn from.
Ask to see a closed CAPA record. A good one states the problem, the root-cause analysis, the correction, the preventive action taken to stop recurrence, and evidence that someone verified the fix worked. A weak one jumps from “problem” to “operator retrained” with nothing in between — that pattern means the same defect will return. For complaint handling, ask how a field complaint from your market reaches the factory floor and how the response is documented. For devices sold in regulated markets, that chain also connects to reporting obligations, so it needs to be real.
Internal audits and management review
Two 13485 requirements tell you whether the system runs on its own or only when a customer is watching. Internal audits are the organization auditing itself against the standard on a schedule. Management review is leadership formally reviewing quality data — audit results, complaints, CAPA status, nonconformances — and acting on it.
During a supplier audit, ask for the internal-audit schedule and a recent internal-audit report, and ask when the last management review happened. A factory that audits itself regularly and whose management reviews produce actions has a self-correcting system. One where these exist only as blank templates has a certificate but not a working QMS, and the difference will show up in your product.
How to verify an ISO 13485 contract manufacturer when sourcing from Taiwan
Taiwan has a deep base of ISO 13485-certified manufacturers, which is exactly why you need a verification routine rather than trust in the logo.
- Confirm the certificate is real and current. Get the certificate number, the certification body, and the accreditation behind it. Check it against the certification body’s registry or a cross-registrar database. Match the legal entity name to your contract.
- Read the scope statement. Confirm it covers your device type and the work you need — manufacture only, or design and development and manufacture.
- Audit traceability live. Pull a lot number and make them walk it backward on the floor.
- Check documentation against reality. Compare a medical device file to an actual batch record for the same product.
- Test change control. Ask how an engineering change order moves through their system and who signs off.
- Confirm regulatory support matches your market. If you sell into the US, verify their production records meet DHR expectations and ask what documentation and testing support they provide for submissions.
For the broader question of choosing a Taiwanese partner — the factory tour checklist, red flags, and IP protection — see our buyer’s guide to medical device contract manufacturers in Taiwan.
How we run it
Gooten Innolife holds ISO 13485:2016 and ISO 9001:2015 certification, and every certificate we hold is verifiable — ask and we’ll give you the numbers to check. We manufacture in Taichung, Taiwan, with production, R&D, and quality assurance co-located, so traceability questions and engineering changes get resolved on the floor.
Quality assurance runs across our five-phase process, with pre-production, in-process, and final inspection plus third-party testing. We have compliance experience with CE, FCC, RoHS, and PSE, and we provide documentation and testing support for FDA submissions. We’ve shipped more than 1,000,000 units to customers in over 50 countries, including a US hair-growth device leader who has built four product generations with us since 2008.
You can review our quality and certifications and OEM/ODM services for the full picture.
Verify us before you commit
If you’re vetting an ISO 13485 contract manufacturer, put us through the checklist above. Contact our engineers, send the technical detail, and check our answers against your own audit standard.
NDA available before any technical discussion.