ISO 13485 – Controlling forms
One of the controversial issues with interpretation of ISO 13485:2003 Standard and other standards is control of forms. Many companies, by some reason, treat forms differently than documents, leaving them not controlled. Per ISO 13485:2003, clause 4.2.3, “Documents required by the quality management system shall be controlled. Let’s see if a form qualifies to be a “document” that “shall” be controlled.
Forms and tables are frequently used as lower-level documents. Very often, it is not necessary to write a traditional instruction with the purpose, scope and instructions if a simple table is sufficient to provide these instructions. One of the typical non-conformities that companies get during audits of their ISO 13485 quality management systems is against forms that are not part of the documentation system.
When questioning the validity of a form without a number, I often hear: “This is just a form.” It always escapes me, why should a form be different from any other instruction? How would we know that we need a form if it is not referenced in our documentation system? After all, if you are not managing forms by assigning document or part number and decide to modify them, how can you be sure that the latest revision is being revised? At best it would be difficult. In practice it would be impossible.
Anyway, what is a form? A short review will help answering this question. If we have a list of directions telling us to:
– make a table with two columns
– write down your business name into the 1-st column
– put your business’s URL into the 2-nd column
I would bet that most of us would call this three-line direction an instruction. So, if this is an instruction, it shall be controlled.
Now, what if we were given a two-column table where the first column was titled “You company name” and the second column “Company’s URL”. We were asked to complete the form. Easy to imagine, we would enter our company’s name and our URL in the table. It means that we interpreted this table as an “instruction”.
If we agree that our first three-line instruction in English was a “real” instruction, that needs to be controlled, the second, completed form, resulting in the same output, must also be an instruction!
I think that the confusion regarding forms used in ISO 13485 quality management systems is based on the fact that forms serve two purposes. Empty forms are brief instructions written in tabular language. After forms are filled out, they become records. Records are managed in a different manner than procedures. Let’s remember this and treat our blank forms as instructions letting the documentation management process govern them. There are a couple of simple tests you may take when you are tempted to use a form that has not been assigned a part number:
– Let’s say that somebody changed your favorite form. Would you want to know why?
– If you revised your form, would you like your assemblers to use the latest revision?
– If you were absent, would you like folks to find your form just by finding a reference to it in your ISO 13485:2003 quality management system?
Just one “Yes” to the above questions indicates that your form is definitely a candidate for Documentation Control practices.
Filed under: Business