Skip to content

Evidence request lists

ISO 13485

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

ISO 13485: Administrative Safeguards

ISO13485-06
Security management process and risk analysis

Security management process and risk analysis. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.

Artefacts an auditor will ask for
  • training attendance records
  • device master record
  • risk management file
  • access control policy
Where this commonly fails
  • gaps in workforce training records
  • insufficient supplier oversight
  • incomplete device risk file
  • missing access review evidence
ISO13485-07
Workforce security and clearance procedures

Workforce security and clearance procedures. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.

Artefacts an auditor will ask for
  • device master record
  • risk management file
  • access control policy
  • encryption configuration evidence
Where this commonly fails
  • weak encryption coverage
  • gaps in workforce training records
  • insufficient supplier oversight
ISO13485-08
Information access management

Information access management. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.

Artefacts an auditor will ask for
  • training attendance records
  • device master record
  • risk management file
  • access control policy
Where this commonly fails
  • gaps in workforce training records
  • insufficient supplier oversight
  • incomplete device risk file
  • missing access review evidence
ISO13485-09
Security awareness and training program

Security awareness and training program. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.

Artefacts an auditor will ask for
  • encryption configuration evidence
  • audit log samples
  • training attendance records
  • device master record
  • risk management file
Where this commonly fails
  • missing access review evidence
  • weak encryption coverage
  • gaps in workforce training records
ISO13485-10
Contingency planning for ePHI

Contingency planning for ePHI. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.

Artefacts an auditor will ask for
  • access control policy
  • encryption configuration evidence
  • audit log samples
Where this commonly fails
  • weak encryption coverage
  • gaps in workforce training records
  • insufficient supplier oversight
ISO13485-11
Business associate management

Business associate management. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.

Artefacts an auditor will ask for
  • training attendance records
  • device master record
  • risk management file
  • access control policy
  • encryption configuration evidence
Where this commonly fails
  • missing access review evidence
  • weak encryption coverage
  • gaps in workforce training records

ISO 13485: Organizational Requirements

ISO13485-21
Security and privacy policies

Security and privacy policies. Control from ISO 13485 framework, domain: ISO 13485: Organizational Requirements.

Artefacts an auditor will ask for
  • training attendance records
  • device master record
  • risk management file
  • access control policy
Where this commonly fails
  • insufficient supplier oversight
  • incomplete device risk file
  • missing access review evidence
  • weak encryption coverage
ISO13485-22
Documentation and record retention

Documentation and record retention. Control from ISO 13485 framework, domain: ISO 13485: Organizational Requirements.

Artefacts an auditor will ask for
  • encryption configuration evidence
  • audit log samples
  • training attendance records
  • device master record
  • risk management file
Where this commonly fails
  • weak encryption coverage
  • gaps in workforce training records
  • insufficient supplier oversight
  • incomplete device risk file
ISO13485-23
Compliance evaluation and review

Compliance evaluation and review. Control from ISO 13485 framework, domain: ISO 13485: Organizational Requirements.

Artefacts an auditor will ask for
  • audit log samples
  • training attendance records
  • device master record
  • risk management file
Where this commonly fails
  • missing access review evidence
  • weak encryption coverage
  • gaps in workforce training records
ISO13485-24
Incident reporting procedures

Incident reporting procedures. Control from ISO 13485 framework, domain: ISO 13485: Organizational Requirements.

Artefacts an auditor will ask for
  • device master record
  • risk management file
  • access control policy
  • encryption configuration evidence
  • audit log samples
Where this commonly fails
  • gaps in workforce training records
  • insufficient supplier oversight
  • incomplete device risk file
  • missing access review evidence
  • weak encryption coverage

ISO 13485: Patient Data Protection

ISO13485-01
ePHI access controls and authorization

ePHI access controls and authorization. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.

Artefacts an auditor will ask for
  • access control policy
  • encryption configuration evidence
  • audit log samples
Where this commonly fails
  • incomplete device risk file
  • missing access review evidence
  • weak encryption coverage
ISO13485-02
ePHI encryption at rest and in transit

ePHI encryption at rest and in transit. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.

Artefacts an auditor will ask for
  • encryption configuration evidence
  • audit log samples
  • training attendance records
  • device master record
  • risk management file
  • access control policy
Where this commonly fails
  • weak encryption coverage
  • gaps in workforce training records
  • insufficient supplier oversight
  • incomplete device risk file
ISO13485-03
Minimum necessary standard enforcement

Minimum necessary standard enforcement. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.

Artefacts an auditor will ask for
  • audit log samples
  • training attendance records
  • device master record
Where this commonly fails
  • weak encryption coverage
  • gaps in workforce training records
  • insufficient supplier oversight
  • incomplete device risk file
ISO13485-04
Patient data de-identification procedures

Patient data de-identification procedures. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.

Artefacts an auditor will ask for
  • training attendance records
  • device master record
  • risk management file
  • access control policy
Where this commonly fails
  • insufficient supplier oversight
  • incomplete device risk file
  • missing access review evidence
  • weak encryption coverage
  • gaps in workforce training records
ISO13485-05
Audit trail for ePHI access

Audit trail for ePHI access. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.

Artefacts an auditor will ask for
  • access control policy
  • encryption configuration evidence
  • audit log samples
  • training attendance records
  • device master record
  • risk management file
Where this commonly fails
  • gaps in workforce training records
  • insufficient supplier oversight
  • incomplete device risk file
  • missing access review evidence
  • weak encryption coverage

ISO 13485: Physical Safeguards

ISO13485-17
Facility access controls

Facility access controls. Control from ISO 13485 framework, domain: ISO 13485: Physical Safeguards.

Artefacts an auditor will ask for
  • risk management file
  • access control policy
  • encryption configuration evidence
  • audit log samples
  • training attendance records
Where this commonly fails
  • incomplete device risk file
  • missing access review evidence
  • weak encryption coverage
ISO13485-18
Workstation security and use policies

Workstation security and use policies. Control from ISO 13485 framework, domain: ISO 13485: Physical Safeguards.

Artefacts an auditor will ask for
  • encryption configuration evidence
  • audit log samples
  • training attendance records
Where this commonly fails
  • missing access review evidence
  • weak encryption coverage
  • gaps in workforce training records
ISO13485-19
Device and media controls

Device and media controls. Control from ISO 13485 framework, domain: ISO 13485: Physical Safeguards.

Artefacts an auditor will ask for
  • device master record
  • risk management file
  • access control policy
  • encryption configuration evidence
Where this commonly fails
  • insufficient supplier oversight
  • incomplete device risk file
  • missing access review evidence
ISO13485-20
Disposal and re-use procedures

Disposal and re-use procedures. Control from ISO 13485 framework, domain: ISO 13485: Physical Safeguards.

Artefacts an auditor will ask for
  • access control policy
  • encryption configuration evidence
  • audit log samples
  • training attendance records
Where this commonly fails
  • missing access review evidence
  • weak encryption coverage
  • gaps in workforce training records
  • insufficient supplier oversight

ISO 13485: Technical Safeguards

ISO13485-12
Unique user identification and authentication

Unique user identification and authentication. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.

Artefacts an auditor will ask for
  • training attendance records
  • device master record
  • risk management file
  • access control policy
  • encryption configuration evidence
Where this commonly fails
  • incomplete device risk file
  • missing access review evidence
  • weak encryption coverage
  • gaps in workforce training records
  • insufficient supplier oversight
ISO13485-13
Automatic logoff and session management

Automatic logoff and session management. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.

Artefacts an auditor will ask for
  • device master record
  • risk management file
  • access control policy
  • encryption configuration evidence
  • audit log samples
  • training attendance records
Where this commonly fails
  • gaps in workforce training records
  • insufficient supplier oversight
  • incomplete device risk file
  • missing access review evidence
ISO13485-14
Audit controls and monitoring

Audit controls and monitoring. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.

Artefacts an auditor will ask for
  • audit log samples
  • training attendance records
  • device master record
  • risk management file
Where this commonly fails
  • incomplete device risk file
  • missing access review evidence
  • weak encryption coverage
  • gaps in workforce training records
  • insufficient supplier oversight
ISO13485-15
Integrity controls for ePHI

Integrity controls for ePHI. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.

Artefacts an auditor will ask for
  • training attendance records
  • device master record
  • risk management file
Where this commonly fails
  • insufficient supplier oversight
  • incomplete device risk file
  • missing access review evidence
  • weak encryption coverage
ISO13485-16
Transmission security and encryption

Transmission security and encryption. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.

Artefacts an auditor will ask for
  • risk management file
  • access control policy
  • encryption configuration evidence
  • audit log samples
Where this commonly fails
  • missing access review evidence
  • weak encryption coverage
  • gaps in workforce training records
  • insufficient supplier oversight
  • incomplete device risk file
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 13485 framework page.