Quality
ISO 13485 is the international standard for medical device quality management systems - and the backbone of compliance in almost every market. UK MDR, EU MDR and IVDR, the FDA's Quality Management System Regulation (QMSR), Australia's TGA and UAE registration all expect a QMS built to ISO 13485.
At Taylored Consultancy Ltd, we make ISO 13485 clear and practical. We build, audit and improve device quality systems with support from experienced lead auditors, so you're certification-ready and inspection-ready - never scrambling.
Clearing the path to market -
regulatory and quality expertise that gets your medical device quality systems certified, compliant, and trusted.

We develop and implement a complete ISO 13485 quality management system tailored to your device, your processes and the markets you sell into.
Already certified, or part-way there? We run a full gap analysis or pre-audit health check to find and fix weaknesses before they become findings.
We help you put compliant design control, risk and technical documentation in place - the records auditors and Notified Bodies scrutinise most.
We weave ISO 14971 risk management through your QMS so risk isn't a bolt-on, but part of how you work.
We conduct internal audits against ISO 13485 and your applicable regulations, preparing you for external inspections and audits.
We help you build effective corrective and preventive action processes that satisfy auditors and genuinely improve your operations.
We carry out supplier and sub-contractor audits so you have confidence in your supply chain and the evidence to prove it.
We map your ISO 13485 system against EU MDR/IVDR, the FDA QMSR and MDSAP, so one well-built system satisfies multiple regulators at once.
Facing a certification body, Notified Body or FDA inspection? We provide hands-on support to help you prepare, respond and stay compliant.
A quality system shouldn't just sit in a drawer gathering dust. We build practical systems your team actually uses, so you're covered, certified, and audit-ready - without unnecessary delays or surprises.
ISO 13485 - Medical devices quality management systems
ISO 14971 - Risk management for medical devices
EN 62304 / IEC 62304 - Medical device software lifecycle
ISO 19011 - Auditing management systems
ISO/IEC 17021 - Requirements for certification bodies
EU MDR (2017/745) / IVDR (2017/746) - QMS obligations
FDA QMSR (21 CFR 820) - US device quality system regulation
MDSAP - Medical Device Single Audit Programme
ISO 9001 - General quality management
IEC 62366 - Usability Engineering
Yes. If you want to place a medical device on the UK or EU market, you'll need a quality management system that meets ISO 13485, either directly or through an equivalent recognised by your Notified Body or Approved Body. It underpins CE and UKCA marking by demonstrating your design, risk management and production controls are robust enough for regulators and auditors alike. Without it, most conformity assessment routes simply aren't open to you.
ISO 13485 is built specifically for medical devices, while ISO 9001 is a generic quality standard used across any industry. ISO 13485 drops ISO 9001's emphasis on continual improvement and instead sharpens the focus on risk management, design controls, traceability and regulatory compliance, because in this sector patient safety matters more than process optimisation. Many device manufacturers hold both, but 13485 is the one regulators actually require.
Most organisations take between six and twelve months to move from a standing start to certification, depending on how mature your existing processes are and how complex your device range is. Building a compliant QMS from scratch, embedding design controls and risk management, and preparing for a certification body audit all take time to do properly. We help clients plan a realistic timeline from day one, so there are no last-minute surprises.
ISO 13485 aligns closely with the FDA's Quality System Regulation (QMSR), which has now adopted ISO 13485 as its basis, but certification alone doesn't automatically satisfy every FDA expectation. You'll still need to map your QMS against QMSR specifics and any additional US requirements. Holding ISO 13485 puts you in a strong position for FDA readiness, but the two shouldn't be treated as identical.
MDSAP (Medical Device Single Audit Program) is a single audit that lets you demonstrate compliance across multiple markets, including Australia, Canada, Japan, the US and Brazil, instead of facing separate national audits. It's built on ISO 13485 as its foundation, so if you're already certified you're most of the way there. It's not mandatory everywhere, but it's a smart route if you're targeting several of those markets at once.
Costs vary widely depending on the size of your organisation, the complexity of your device portfolio, and how developed your existing quality processes already are. Expect to budget for certification body audit fees, any consultancy support to build or close gaps in your QMS, and internal time for documentation and training. Smaller manufacturers with simple, low-risk devices typically spend less than those running multiple product lines across several markets.
In practice, yes. ISO 13485 requires a risk management process, and ISO 14971 is the recognised standard for delivering it. The two are designed to work together: ISO 13485 sets out your quality management system, while ISO 14971 governs how you identify, evaluate and control risk throughout a device's lifecycle. Auditors expect to see risk management woven into your QMS, not treated as a bolt-on exercise.
Yes, and it's actually easier to build it right from the start than to retrofit one later. Without legacy processes to unpick, a new company can design a QMS around its actual product and market strategy from day one. We work with early-stage medical device businesses to build practical, audit-ready systems that scale as the company grows, rather than over-engineering documentation nobody will use.
Switching consultancy support is usually straightforward, since your QMS documentation and certificate stay with you regardless of who's advising you, and a new consultant simply picks up where the last one left off after a review of your current system. Switching certification body is a little more involved, as it typically means a transfer audit rather than starting certification from scratch, but it doesn't mean losing your existing certificate while the move is arranged. We can support with either.
Still have questions? Contact us and we'll be happy to help.