Stage 1Gap assessment — know what you owe

Before any software or SOP, write down three things: which regulations apply to you (for a US-market device company that usually starts with FDA QMSR / 21 CFR 820 and ISO 13485, with ISO 14971 for risk), which of their requirements you already satisfy informally, and which you satisfy not at all. At 30 people the honest answer is usually "we do most of this in email, spreadsheets, and one senior engineer's memory" — which is a gap, because a QMS requirement you can't evidence is a requirement you don't meet.

Turn the gap list into an owned plan: every gap gets an owner, a target date, and a definition of done that names the evidence an auditor would ask for. Resist the urge to write forty SOPs in a weekend — sequence them in the order the rest of this playbook follows, because each stage depends on the one before it.

  • Map each applicable clause to: evidence exists / evidence is informal / no evidence.
  • Decide your regulatory strategy now (US only? MDSAP jurisdictions later?) — it changes the scope of Stages 5 and 6.
  • Set a management-review cadence from day one, even while the QMS is a skeleton.
Where Azora does the workThe gap plan itself lives as owned, dated work in Project Management (tasks, owners, due dates, dependencies), with the emerging risk picture in the QMS Risk Register. Management Review in the QMS records the governance cadence, and the Traceability module will later prove requirement-to-evidence coverage instead of a hand-maintained spreadsheet.

Stage 2Document control + e-sign — the foundation

Everything else in a QMS is written down somewhere, so the document system comes first. You need controlled documents with versions, an approval workflow, a way to know who has read what, and a periodic-review cadence — and, if you intend to keep records electronically for FDA purposes, signatures designed around 21 CFR Part 11: re-authentication at the moment of signing, a rendered manifestation of who signed, when, and why, and an append-only history behind the record.

Start with a small, real document set: a quality manual, the document-control SOP itself, and the SOPs for the processes in Stages 3–5. Every SOP you approve through the controlled workflow is simultaneously content and evidence — it demonstrates the document system works.

  • Approve the document-control SOP through the document-control workflow. Auditors notice.
  • Decide signature meanings (author / reviewer / approver) before the first signature, not after.
  • Keep obsolete revisions retrievable but unmistakably superseded.
Where Azora does the workDocuments in Wiki & Docs and the QMS document-control workflow: versioned documents, approval routing, read receipts, periodic review. Change Control in QMS carries the Part 11-designed e-signature ceremony — re-authentication, adopted signature manifestation, server-owned timestamps — over a tamper-evident, append-only audit trail. The Trust center describes exactly how those controls behave.

Stage 3CAPA, NCR, and complaints — the correction loop

The heart of an FDA-ready QMS is the loop that notices problems, contains them, fixes root causes, and proves the fix worked. That is three linked record types, and the links are the point: a complaint from the field, the nonconformance report that confirms and contains it, and the CAPA that carries root-cause analysis, corrective actions, and an effectiveness check. When these live in disconnected tools, the audit question "show me the CAPA this complaint led to" becomes a scavenger hunt.

Write the SOPs so that thresholds are explicit — not every NCR deserves a CAPA, and a CAPA system flooded with trivia is as non-functional as no CAPA system. Define what escalates, who decides, and what evidence closes each record.

  • Every CAPA should point at the record that triggered it — complaint, NCR, audit finding, or internal signal.
  • Effectiveness checks get a due date and an owner at CAPA creation, not at closure.
  • Complaint intake needs a path from support conversations into the quality system, or signals will die in an inbox.
Where Azora does the workCAPA, NCR, and Complaints are first-class linked records in QMS — CAPAs auto-link to their source NCRs, complaints, and audit findings, and carry effectiveness checks. Field signals arrive through Support tickets linked to bugs and serialized units, and corrective work is executed as owned tasks in Project Management, so the regulated record and the engineering work stay attached.

Stage 4Training & competence — prove people are ready

A QMS the team hasn't been trained on is a liability with a table of contents. Regulators expect you to define competence requirements per role, train people on the procedures that apply to them, keep records of that training, and re-train when documents change. At 30 people this is genuinely manageable — if it's wired to the document system, so that a revised SOP automatically raises the question "who needs re-training?"

  • Define a role-to-procedure matrix: which roles must be trained on which SOPs.
  • Record training with a date, a trainee, the document version trained on, and an attestation.
  • Treat read-receipts as awareness, not competence — some procedures need demonstrated proficiency.
Where Azora does the workTraining records in QMS Training track per-person training against document versions; HR & People holds the roles, onboarding checklists, and employee records the matrix hangs off; document read-receipt tracking closes the loop when a controlled document revs.

Stage 5Audits & supplier controls — inspect yourself first

Internal audits are how you find your gaps before an auditor does; supplier controls are how you extend the QMS beyond your own walls. Build an internal-audit program that covers the whole QMS on a defined cycle, feed findings into the CAPA loop from Stage 3, and qualify your critical suppliers: risk-tier them, define what qualification requires per tier, and keep the evaluations current.

  • Auditor independence matters even in a small company — no one audits their own process.
  • Findings without CAPA linkage are observations, not a functioning audit program.
  • Purchasing controls only work if the approved-supplier list is enforced where POs are actually raised.
Where Azora does the workAudit management in QMS runs internal, supplier, and external audits with finding tracking that feeds CAPA. Supplier records in ERP / Operations carry risk tiers and qualification status beside purchasing — the approved-supplier list and the PO workflow share one database, so the control is enforced where the spend happens. Supplier findings link back into the quality record.

Stage 6MDSAP readiness — one audit, five jurisdictions

If your market strategy includes Canada, Brazil, Japan, or Australia alongside the US, MDSAP lets one audit cycle cover multiple regulators — but it audits your QMS as a set of linked processes, following chains across management, measurement, design, production, and purchasing. A QMS built as the previous five stages describe is largely MDSAP-shaped already; readiness work is mostly about rehearsing the linkages and closing the residual gaps for each jurisdiction in scope.

  • Run a mock audit against the MDSAP companion-document structure before the real cycle.
  • Rehearse process linkages: pick a complaint and walk it to a CAPA, a design change, training, and a release, on demand.
  • Track jurisdiction-specific requirements (registrations, reporting clocks) explicitly rather than assuming ISO 13485 coverage is enough.
Where Azora does the workThe MDSAP cycle tracker in QMS supports mock external-audit prep across the MDSAP structure; Vigilance handles reporting-clock timelines; Regulatory Authorization records track per-jurisdiction status; and because complaints, NCRs, CAPAs, changes, training, and releases are one linked chain, the "walk me through it" rehearsal is a click-through in Traceability, not a week of assembly.

After stage 6Keep it boring

An FDA-ready QMS is not a project you finish; it's an operating rhythm. Management review on cadence, internal audits on cycle, CAPAs closed with effectiveness evidence, training current against document versions. The goal of all six stages is that the next audit — internal, FDA, or MDSAP — is boring, because the evidence was accumulating as the work happened rather than being reconstructed for the occasion.

Want to see the modules in this playbook with realistic seeded data? Explore the live demo, browse the organized QMS hub, or email us — we'll walk your own gap list through the platform with you.

Put the playbook to work

Bring us your gap list.

We'll map it stage by stage against the platform — with the engineers who built it, not a script.