ISO 13485 with AI — the device file, alive and traceable from the part to post-market.

ISO 13485 + UDI + MDR demand multi-dimensional traceability: from design (DHF) to production (DMR), to the UDI of every single unit, to post-market. iLEAN covers the four axes with continuous capture and a living dossier — with no need to rebuild the file every time the notified body knocks on the door.

← See all Lean methods

Medical device packaging line under GMP conditions with an Edge camera reading the UDI code on a sterile pack while a quality lead reviews the DHF dossier on an iLEAN tablet — ISO 13485 with AI
The problem

Four files that always have to add up — and almost never live in the same place.

The quality system of a medical device manufacturer has to keep four files alive and consistent — and most plants have them scattered across as many systems as they have departments:

  1. DHF (Design History File) — the design history. It usually sits in a PLM/eQMS, but the real changes (scale-up to production, supplier changes) end up in another system or in an R&D spreadsheet.
  2. DMR (Device Master Record) — the master recipe of the product in production. It lives close to the ERP/MES, but the approved deviations that modify it are not always updated at the pace of the plant.
  3. UDI — the unique identifier of every unit, traceable to its batch and to its DMR and DHF. It is printed or marked on the line, but bidirectional traceability (from the unit to the batch, from the batch to its DHF) requires cross-checking three systems.
  4. Post-market monitoring (PMS) — the complaints, incidents and reports that arrive through heterogeneous channels (distributor email, hospital call, web form). They almost never reach the system that cross-checks them against the batch and the DHF in time, and reverse traceability stays incomplete.

When the notified body audits, or when a post-market event forces a field corrective action, the cross-check of all four has to be rebuilt by hand. The honest sentence from the quality manager: "my DHF is frozen at the launch version, my DMR changes with every deviation, my UDI is run by production, and complaints are handled by the RA team — and all four have to add up in the dossier".

How it fits the IRIS system

iLEAN does not replace your eQMS — it seals the crack between the four files and reality.

A medical device quality system does not fail at documentation — it fails at the synchronization between what happens on the floor and the live files. iLEAN acts as the filler that closes that gap. It does not ask you to change your eQMS, your PLM, your ERP or your complaint system. It sits on top and guarantees that evidence arrives complete, linked to the right UDI/batch/DHF, and signed.

Edge reads the UDI and the integrity of the pack. Tracer captures every deviation, every complaint, every supplier certificate. Writer keeps DHF, DMR and PSUR alive. The person — from RA — signs.

The iLEAN pieces applied to ISO 13485 with UDI and MDR:

  • iLEAN Edge — terminals with computer vision (CNN) over the medical device line: OCR of the printed or marked UDI, integrity of the sterile pack seal, labelling control, batch number and expiry date reading. If anything does not match what is expected, it holds the unit in milliseconds before release. It works with no network: medical device safety cannot depend on connectivity.
  • iLEAN Tracer (Connect + integrations) — captures everything the eQMS cannot see on its own: every deviation an operator opens, every change request from the R&D team, every supplier certificate that arrives by email, every complaint that comes in through the web form or from the distributor by WhatsApp. It links each one to the batch, to the UDI and to the DHF/DMR element it touches.
  • iLEAN Writer + RA Agent — Writer builds living dossiers for DHF, DMR, PSUR and MDR/QMSR. The agent cross-checks consistency across the four files and raises a flag when an approved deviation has not been reflected in the current DMR, when a PSUR needs updating because of the frequency of a complaint, or when a UDI registered in EUDAMED/GUDID does not match the batch produced. The RA person decides and signs — the line does not go to the field on its own.

See the full IRIS architecture →

Before and after

eQMS + regulatory sprints vs. living files with iLEAN

AspectClassic eQMS + sprintsWith iLEAN Edge + Tracer + Writer
DHF between launch and annual reviewFrozen — real changes never arriveAlive — every change request updates the DHF
DMR vs. plant realityOut of date whenever deviations are approvedSynchronized in real time with MES/ERP
UDI: bidirectional traceabilityManual — three systems cross-checked by handEdge reads + Tracer links + automatic dossier
Post-market monitoringScattered channels, late arrivalUnified capture at second zero
PSUR generation3-5 weeks rebuilding evidencePre-built dossier — review and sign
Notified body auditPre-auditor sprint by the quality teamFile ready every day of the year
Impact estimate

Impact estimate for your plant — to be validated with your numbers.

The block below is an estimate to be validated with the data from your plant and your regulatory portfolio. We lay it out so the committee has an order of magnitude; we refine it during the diagnostic.

  • Class IIa/IIb medical device manufacturer with ISO 13485 + MDR + UDI, 1-3 production lines, an RA/QA team of 4-10 people.
  • First value expected within a few weeks: Edge pilot on one line with UDI reading + pack integrity + unified capture of post-market complaints for one product family.
  • Indicative payback between 4 and 9 months, depending on the monthly volume of deviations, change requests and complaints, and on the cost of regulatory sprints (PSUR, MDR Technical File update, notified body audits).
  • Expected reduction in time spent on administrative evidence work: ≥30% (estimate to be validated). The hard lever is not the hours saved — it is the regulatory risk avoided: one major notified body finding or one FDA Form 483 costs far more than the entire pilot.

And the RA lead's reasonable objection

"What if the AI gets it wrong when linking a complaint to a batch or reading a UDI?" — hallucination is a problem of free generation, not of anchored tasks. In tasks where AI merely recontextualizes a data point (reading a UDI and comparing it with the expected batch, normalizing a complaint that arrived by email), the best models brought error below 1.5% [1]. And even so, nothing critical is decided alone: iLEAN holds the unit or proposes the cross-check, and the RA person signs. The European AI Act and medical device regulation agree in requiring human oversight for high-risk AI — iLEAN's three rings are designed precisely to support that requirement without giving up the power.

[1] OpenAI paper "Why Language Models Hallucinate", 2025 — on the reliability of AI in anchored tasks.

Frequently asked

What people ask about ISO 13485 medical devices with AI

What is the difference between ISO 13485 and 21 CFR 820?

ISO 13485 is the international quality management system standard for medical devices. 21 CFR Part 820 is the US FDA regulation (QSR — Quality System Regulation). The FDA is harmonizing it with ISO 13485:2016 through the QMSR rule (Quality Management System Regulation), which will bring both far closer together. iLEAN treats ISO 13485 as the common substrate and maps records so they cover both requirements without duplicating work on the plant floor.

And EU MDR (Regulation 2017/745)?

MDR demands a live technical file (Annex II/III), UDI, systematic post-market monitoring (PMS Plan + PMCF + PSUR) and reinforced traceability. ISO 13485 is the QMS foundation MDR requires; iLEAN adds what MDR asked for on top of it — continuous capture of post-market incidents from multiple channels (distributor email, transcribed hospital call, web form), PSUR generation with the evidence already collected, and traceability from every UDI to its batch and to its DHF.

How do you keep the DHF (Design History File) alive?

The DHF documents the design history of the medical device — requirements, verification and validation plans, design decisions, risk management (ISO 14971). The classic problem is that the DHF freezes at launch while the product keeps changing (scale-up to the plant, supplier changes, process improvements). iLEAN captures every change request, every corrective action and every deviation, and links each one to the DHF element it touches, so the file evolves with the product instead of ageing in a folder.

Does it integrate with UDI (Unique Device Identification)?

Yes. UDI requires every device to carry a unique identifier traceable to its production batch, its DMR and its DHF. iLEAN Edge reads the UDI printed or marked on the packaging line (vision plus OCR), links it to the batch produced, and connects that traceability with the ERP/MES and with the UDI databases (FDA GUDID, EU EUDAMED). If the UDI is not legible or does not match the expected batch, it holds the unit before release.

What about post-market monitoring (PMS)?

Post-market monitoring is the most underrated axis of MDR and ISO 13485:2016 — and the hardest one to sustain, because the information arrives through heterogeneous channels (distributor email, hospital complaint, clinician report, web form). iLEAN Connect captures all of those channels at second zero, normalizes them and routes them to the complaint/PSUR management system. The agent cross-checks the event with the batch, the UDI, the DHF and the current risk analysis, and prepares the dossier that the Regulatory Affairs lead signs.

Let's talk

Tell us about your case and within 48h we will send the estimated ROI of this AI project for your ISO 13485 system.

We work on your plant's real data and your regulatory portfolio, not on ours. Diagnostic with no strings attached.

Request the 48h ROI estimate See Lean Manufacturing