ISO 13485: Why Traceability Matters Long After a Medical Device Leaves Your Hands

A customer reports a fault with a medical device you supplied eighteen months ago.
They need answers. Your team starts searching.
The sales record shows the model, but not the serial number. A production file lists the parts used, but nobody can link it to that particular device. The employee who managed the order has left.
Meanwhile, similar devices may still be in use.
You cannot yet tell which ones might share the problem or who needs to hear from you.
This is where poor traceability becomes more than a paperwork issue.
It can slow an investigation, delay a safety response and leave people making important decisions with missing facts.
A completed delivery does not mean the device’s story is over. It may be installed, moved, serviced, repaired or updated. A concern may appear long after the original order has been closed.
ISO 13485 medical device traceability helps businesses maintain the links needed to understand that story.
The key question is simple:
If a problem arose tomorrow, could your team find reliable answers about a device supplied years ago?
What traceability means in everyday work
Traceability means being able to follow the relevant history of a device through connected records.
You need to identify the device and link it to the information your business is required to keep.
Depending on the product, your role and the rules that apply, this may include materials, production details, checks, distribution and later service work.
A batch number identifies a group of products. A serial number identifies an individual unit.
These details are useful when they connect to trustworthy records.
A number printed on a label offers limited help if it cannot be linked to the right production or delivery information.
Think of traceability as a chain.
Each record provides a link to another part of the device’s history. If a link is missing, the team may struggle to follow that history when it matters.
The aim is to retrieve clear evidence rather than rely on somebody remembering what happened.
Why ISO 13485 reaches beyond production
ISO 13485 sets out requirements for a quality management system for the medical device sector.
Its use extends to organisations involved in activities such as design, production, installation and servicing, along with related services. Quality therefore needs attention beyond the point where a device is made. ISO 13485 — Medical devices
Traceability arrangements should reflect the device, the organisation’s activities and applicable regulatory requirements.
Businesses should not assume that every product needs exactly the same records.
Implantable devices, for example, have particular traceability requirements under ISO 13485. The Medical Device Single Audit Program’s guidance includes checks on relevant component and material records, distribution records and shipping recipients. mdsap.global
The practical starting point is understanding which requirements apply to your work.
From there, define what must be recorded, who records it and how the information stays connected.
Certification to ISO 13485 does not, by itself, give a product legal approval for sale. The standard and the relevant market rules need to be considered together.
Delivery starts another part of the story
Once a device leaves your premises, several things may happen.
It may pass through a distributor. A hospital may move it between departments. An engineer may replace a part. Software may be updated.
Months later, the information captured at dispatch may no longer explain the full picture.
That is why your arrangements should consider relevant activities after supply, including how information comes back to the business.
You will not control every movement or event.
However, you can define responsibilities, agree information-sharing arrangements and keep the records within your control accurate.
Ask where the next link in the chain will come from.
If a distributor sells the product onward, who keeps that record? If your team services it, how is the work linked to the correct unit?
Planning these links before supply is easier than trying to rebuild them during an urgent investigation.
A label alone cannot answer an investigation
A clear label is an important starting point.
It helps staff and users identify a device. It does not explain everything that happened to it.
Imagine receiving a serial number from a customer.
Can you use it to locate the relevant build record? Can you identify the approved product version? Where applicable, can you see which parts were fitted and which checks were completed?
Can you then find the supply and service history?
These links need to work in practice.
Different departments may use different references. Sales might search by customer name, production by batch and engineers by equipment number.
Without a shared way to connect those references, each team may hold a useful piece of information that others cannot find.
Review how your identifiers work across departments.
A strong system allows people to follow the record without guessing whether two similar entries refer to the same device.
Missing records make the scope of a problem harder to judge
Consider a fictional example.
A supplier reports a possible issue with one batch of a component. Your business has used that component in several production runs.
You now need to understand which finished devices contain it.
If the records connect clearly, your team can identify potentially affected products and investigate further.
If they do not, uncertainty grows.
You may have to consider a wider group of devices because you cannot confidently separate those containing the component from those that do not.
That can increase disruption for customers and your own team.
Reliable records help define the group that needs attention. They do not replace a proper assessment of the problem or prove that devices outside the group are safe.
The evidence still needs careful review.
But a clear connection between components and finished products gives the investigation a much stronger starting point than an incomplete folder of unrelated documents.
Traceability supports a clearer safety response
When a device-related risk needs action after supply, the response may involve more than collecting products.
Depending on the issue, it could include a repair, a software update or revised instructions.
The right response must be assessed against the risk and applicable rules.
Traceability helps answer practical questions: which devices are affected, who received them and how can the right people be reached?
MHRA guidance recommends records that help identify distributed devices and emphasises onward traceability arrangements with distributors. It also explains that manufacturers remain responsible for ensuring safety communications reach end users. GOV.UK
Knowing the invoice address may be insufficient.
A device could sit in a different department, building or organisation by the time action is needed.
Your arrangements should help you find the appropriate route to the people responsible for it.
Incomplete contact details can turn an otherwise clear safety message into a difficult search.
Connect complaints to the device history
A complaint is easier to investigate when it can be linked to the right product record.
“The unit stopped working” describes a concern. It does not identify which unit, version or batch is involved.
Your complaint process should help staff collect the relevant details available to them.
These may include the product name, identifying number, description of the issue and information about when it occurred.
Link the complaint to the device’s history where possible.
That connection can help your team compare reports, review earlier repairs and identify patterns.
Do not let missing details become a reason to ignore a concern or delay required reporting. Some information may need to be gathered during the investigation.
The purpose is to improve understanding while responding appropriately.
A good complaint record helps the next person continue the work without having to start the same conversation again.
Service and repair records need to remain connected
A repair may change what you need to know about a device.
A part could be replaced. Settings may be adjusted. Software may move to a different version.
If the service record sits separately from the product history, an investigation may miss that change.
For example, the original build record could show one component while the device now contains another.
Where servicing forms part of your work, define which details need recording and how they connect to the unit.
Record the actual work performed, supported by the checks and approvals relevant to the task.
Avoid vague entries such as “sorted” or “working now”.
Those phrases tell a future reader very little.
A clear service history can help explain whether an issue relates to the original product, later work or another factor.
It also supports the engineer who next works on the device.
Changes need a history people can follow
Devices and their supporting information may change over time.
A design may be revised. A supplier may change. Instructions may be updated.
Years later, your team may need to establish which version applied to a particular device when it was made or supplied.
Using today’s information to explain yesterday’s product can lead to errors.
Keep relevant earlier records accessible and clearly identified.
Make sure the team can distinguish current instructions from historical information retained for reference.
For devices involving software, a useful review question is whether the applicable version and relevant update history can be linked to the device or installation.
The method will depend on the product and your responsibilities.
The important point is to maintain a clear connection.
A change should not leave earlier products with a history that can no longer be understood.
Keep records for the right period
Closing an order is not a sound reason to delete its supporting records.
Medical devices may remain in use for years. Questions about their history may arise long after the commercial transaction ends.
Your retention arrangements need to reflect ISO 13485, applicable regulatory requirements and the relevant device lifetime.
Avoid applying one general office rule to every medical device record.
The period appropriate to a routine administrative document may be unsuitable for evidence needed to support a device investigation.
Define which records must be retained, the retention period and the basis for that decision.
Consider how records will remain readable when systems change.
An old file is of little use if the business no longer has a way to open it.
Retention also needs ownership. Someone should know which records may be removed, which must remain and how that decision is controlled.
Protect the records and test access
Records need protection from loss, damage and unauthorised changes.
They also need to be available to authorised people when required.
A spreadsheet saved on one employee’s laptop creates an obvious weakness. So does a paper archive that nobody else understands.
Review where information is held, who can access it and how it is backed up.
Test whether a backup can actually be restored.
Consider the information itself, too.
Traceability does not automatically mean every organisation should collect patient details. The need for such information depends on the device, the role and applicable requirements.
Where personal information is involved, appropriate privacy and security controls matter.
Collect and share what is needed for a defined purpose, through suitable arrangements.
A useful system gives the right people access to relevant evidence while protecting information from unnecessary exposure.
Software cannot repair a broken process by itself
Digital tools can make records easier to link and retrieve.
Scanning identifiers may reduce typing errors. Searchable records can help an investigation move faster.
However, a new system cannot correct unclear responsibilities on its own.
If nobody checks the number entered at dispatch, the wrong number can still be stored. If a service team does not update the record, the history remains incomplete.
Start with the process.
Define what information is needed, when it is captured and who checks it. Then assess whether the tool supports those tasks.
Where software is used in the quality management system, its suitability and required validation also need attention under ISO 13485.
Train people to use it correctly and monitor common errors.
The technology should support reliable work. It should not create the impression that every record is accurate simply because it appears on a screen.
Give people a clear role in the chain
Traceability rarely belongs to one department.
Purchasing may record supplier details. Production may create build records. Dispatch may capture recipients. Engineers may document service work.
The quality team cannot create all those links after the event.
Each person needs to understand what they record, why it matters and what to do if something is missing.
Explain the practical effect of errors.
A wrong batch number could send an investigation towards the wrong group of products. An incomplete service note may hide a part change.
Use examples relevant to the role.
Then check understanding through actual tasks rather than attendance at training alone.
People should also feel able to pause work or raise a concern through the agreed route when a required record is unclear.
A gap noticed early is easier to address while the facts are still available.
Test the chain before an urgent problem does
A written procedure can look complete while the working system contains gaps.
Test it with a realistic exercise.
Select a supplied device and ask an authorised team member to retrieve its relevant history.
Then try the reverse direction: start with a component batch or production record and identify the finished products linked to it.
Use examples that reflect your activities and obligations.
Include older records, serviced products or items supplied through a distributor where appropriate.
Record where the search becomes difficult.
Does it rely on one person? Are references inconsistent? Is part of the history held somewhere the team cannot access?
The exercise should produce useful actions.
It is a chance to improve the chain before an incident places the same weaknesses under pressure.
The benefits of an ISO consultant’s support
One of the benefits of an ISO consultant’s support is an independent review of how your traceability arrangements work across teams.
A consultant can help you compare documented methods with real records, identify missing links and plan practical improvements.
They can support internal audits, staff guidance and exercises that test whether information can be retrieved.
For example, they may help reveal that production and dispatch use identifiers that are not reliably connected.
Useful support should build your team’s understanding rather than simply add more forms.
Choose support suited to your device activities and the markets involved. Specialist regulatory questions need appropriate expertise.
The organisation remains responsible for its decisions, records and required actions.
A consultant cannot guarantee product safety or replace a regulatory authority. Their contribution is helping the business recognise weaknesses and manage its system with greater confidence.
Follow one device from start to finish
At your next quality review, choose one medical device your business has supplied.
Ask the team to show its relevant history using the records available today.
Can you identify it clearly? Can you connect it to the required production, supply and service information? If a concern arose, do you know how to reach the appropriate people?
Note every point where the answer depends on memory, an unclear reference or a missing file.
Assign each gap to someone and agree when it will be reviewed.
Then repeat the exercise with another device after the changes have been made.
Traceability has value when records remain connected and usable long after delivery.
The most useful question to take into your next review is:
Could someone who was not involved in the original job follow this device’s history without guessing?
Use the answer to decide which link needs attention first.





