ISO 13485
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
ISO 13485: Administrative Safeguards
Security management process and risk analysis. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.
- training attendance records
- device master record
- risk management file
- access control policy
- gaps in workforce training records
- insufficient supplier oversight
- incomplete device risk file
- missing access review evidence
Workforce security and clearance procedures. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.
- device master record
- risk management file
- access control policy
- encryption configuration evidence
- weak encryption coverage
- gaps in workforce training records
- insufficient supplier oversight
Information access management. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.
- training attendance records
- device master record
- risk management file
- access control policy
- gaps in workforce training records
- insufficient supplier oversight
- incomplete device risk file
- missing access review evidence
Security awareness and training program. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.
- encryption configuration evidence
- audit log samples
- training attendance records
- device master record
- risk management file
- missing access review evidence
- weak encryption coverage
- gaps in workforce training records
Contingency planning for ePHI. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.
- access control policy
- encryption configuration evidence
- audit log samples
- weak encryption coverage
- gaps in workforce training records
- insufficient supplier oversight
Business associate management. Control from ISO 13485 framework, domain: ISO 13485: Administrative Safeguards.
- training attendance records
- device master record
- risk management file
- access control policy
- encryption configuration evidence
- missing access review evidence
- weak encryption coverage
- gaps in workforce training records
ISO 13485: Organizational Requirements
Security and privacy policies. Control from ISO 13485 framework, domain: ISO 13485: Organizational Requirements.
- training attendance records
- device master record
- risk management file
- access control policy
- insufficient supplier oversight
- incomplete device risk file
- missing access review evidence
- weak encryption coverage
Documentation and record retention. Control from ISO 13485 framework, domain: ISO 13485: Organizational Requirements.
- encryption configuration evidence
- audit log samples
- training attendance records
- device master record
- risk management file
- weak encryption coverage
- gaps in workforce training records
- insufficient supplier oversight
- incomplete device risk file
Compliance evaluation and review. Control from ISO 13485 framework, domain: ISO 13485: Organizational Requirements.
- audit log samples
- training attendance records
- device master record
- risk management file
- missing access review evidence
- weak encryption coverage
- gaps in workforce training records
Incident reporting procedures. Control from ISO 13485 framework, domain: ISO 13485: Organizational Requirements.
- device master record
- risk management file
- access control policy
- encryption configuration evidence
- audit log samples
- gaps in workforce training records
- insufficient supplier oversight
- incomplete device risk file
- missing access review evidence
- weak encryption coverage
ISO 13485: Patient Data Protection
ePHI access controls and authorization. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.
- access control policy
- encryption configuration evidence
- audit log samples
- incomplete device risk file
- missing access review evidence
- weak encryption coverage
ePHI encryption at rest and in transit. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.
- encryption configuration evidence
- audit log samples
- training attendance records
- device master record
- risk management file
- access control policy
- weak encryption coverage
- gaps in workforce training records
- insufficient supplier oversight
- incomplete device risk file
Minimum necessary standard enforcement. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.
- audit log samples
- training attendance records
- device master record
- weak encryption coverage
- gaps in workforce training records
- insufficient supplier oversight
- incomplete device risk file
Patient data de-identification procedures. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.
- training attendance records
- device master record
- risk management file
- access control policy
- insufficient supplier oversight
- incomplete device risk file
- missing access review evidence
- weak encryption coverage
- gaps in workforce training records
Audit trail for ePHI access. Control from ISO 13485 framework, domain: ISO 13485: Patient Data Protection.
- access control policy
- encryption configuration evidence
- audit log samples
- training attendance records
- device master record
- risk management file
- gaps in workforce training records
- insufficient supplier oversight
- incomplete device risk file
- missing access review evidence
- weak encryption coverage
ISO 13485: Physical Safeguards
Facility access controls. Control from ISO 13485 framework, domain: ISO 13485: Physical Safeguards.
- risk management file
- access control policy
- encryption configuration evidence
- audit log samples
- training attendance records
- incomplete device risk file
- missing access review evidence
- weak encryption coverage
Workstation security and use policies. Control from ISO 13485 framework, domain: ISO 13485: Physical Safeguards.
- encryption configuration evidence
- audit log samples
- training attendance records
- missing access review evidence
- weak encryption coverage
- gaps in workforce training records
Device and media controls. Control from ISO 13485 framework, domain: ISO 13485: Physical Safeguards.
- device master record
- risk management file
- access control policy
- encryption configuration evidence
- insufficient supplier oversight
- incomplete device risk file
- missing access review evidence
Disposal and re-use procedures. Control from ISO 13485 framework, domain: ISO 13485: Physical Safeguards.
- access control policy
- encryption configuration evidence
- audit log samples
- training attendance records
- missing access review evidence
- weak encryption coverage
- gaps in workforce training records
- insufficient supplier oversight
ISO 13485: Technical Safeguards
Unique user identification and authentication. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.
- training attendance records
- device master record
- risk management file
- access control policy
- encryption configuration evidence
- incomplete device risk file
- missing access review evidence
- weak encryption coverage
- gaps in workforce training records
- insufficient supplier oversight
Automatic logoff and session management. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.
- device master record
- risk management file
- access control policy
- encryption configuration evidence
- audit log samples
- training attendance records
- gaps in workforce training records
- insufficient supplier oversight
- incomplete device risk file
- missing access review evidence
Audit controls and monitoring. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.
- audit log samples
- training attendance records
- device master record
- risk management file
- incomplete device risk file
- missing access review evidence
- weak encryption coverage
- gaps in workforce training records
- insufficient supplier oversight
Integrity controls for ePHI. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.
- training attendance records
- device master record
- risk management file
- insufficient supplier oversight
- incomplete device risk file
- missing access review evidence
- weak encryption coverage
Transmission security and encryption. Control from ISO 13485 framework, domain: ISO 13485: Technical Safeguards.
- risk management file
- access control policy
- encryption configuration evidence
- audit log samples
- missing access review evidence
- weak encryption coverage
- gaps in workforce training records
- insufficient supplier oversight
- incomplete device risk file
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 13485 framework page.