LAW: MDSAP Chapter 5, Design and Development
MDSAP Design and Development: What the
17-Task Audit Chapter Legally Requires
MDSAP Chapter 5 is the most task-dense chapter in the audit programme, with 17 audit tasks covering every stage from design planning through post-market design changes. Updated under MDSAP AU P0002.010 (effective February 6, 2026) to align with the FDA’s Quality Management System Regulation, Chapter 5 now maps design and development obligations directly to ISO 13485:2016 clauses and country-specific requirements for FDA, Health Canada, TGA, ANVISA, and MHLW. This article explains what each cluster of Chapter 5 tasks requires, what auditors look for, what triggers findings, and what every compliance leader at a design-exempt or design-active facility must know before their next MDSAP audit.
17
Audit Tasks in Chapter 5
MDSAP Chapter 5 contains 17 audit tasks, more than any other chapter in the programme. It covers design planning, inputs, outputs, verification, validation, risk management, design transfer, and post-market design changes. Chapter 6 (Production) has 29 tasks and is audited after Chapter 5.
MDSAP AU P0002.010, Feb 2026
2026
MDSAP Audit Approach Updated
MDSAP AU P0002.010, effective February 6, 2026, aligned the audit approach with the FDA’s Quality Management System Regulation (QMSR), effective the same date. References to the legacy QSR were updated; ISO 13485:2016 remains the foundational framework for all Chapter 5 tasks.
NSF: MDSAP Audit Approach Update, Feb 2026
High
Audit Risk if Facility Does Design
Industry guidance consistently rates Chapter 5 as the highest-risk chapter for design-active facilities. Risk management file linkage to design decisions, completeness of design inputs, and design change procedure documentation are the most frequently cited Chapter 5 gaps.
Operon Strategist MDSAP Audit Checklist
MDSAP design and development requirements in Chapter 5 apply to any medical device organisation that designs or develops devices, modifies existing designs, or outsources any part of the design and development process. Facilities that do not perform design activities may have Chapter 5 scoped out of their audit, but only if they can demonstrate through documentation that no design activity occurs within the facility’s scope. Partial design exclusions require careful boundary documentation; auditors will probe the boundary.
The 17 tasks in MDSAP Chapter 5 are logically grouped by the design lifecycle stage they address. Understanding each group’s requirements, and the linkages between them, is essential for audit preparation and for building a design control system that survives scrutiny across all five MDSAP jurisdictions.
Task 1: Design and development procedure and design change procedure
The organisation must maintain a defined and documented procedure for design and development that addresses all stages of the process. Critically, a separate and documented design change procedure must also exist. The design change procedure must include controls and records related to design transfer to production, and must confirm that the production line meets production requirements established during design and development. Auditors verify that both procedures exist, are current, and are actually followed, not simply filed. Source: MDSAP Ch.5 Training Module, Task 1
Task 2: Design and development links to quality problems
Task 2 links Chapter 5 to Chapter 3 (Measurement, Analysis and Improvement). The auditor confirms that quality problems identified through the Chapter 3 process, complaints, non-conformances, CAPA, have been considered as they relate to specific aspects of device design. Facilities that manage quality problems and design decisions in separate silos without a documented linkage mechanism fail this task. The connection between post-market data and design decisions is a legal requirement under ISO 13485:2016 clause 8.2.2. Source: MDSAP Ch.5 Training Module, Task 2
Task 3: Design plan reviewed and controlled
The auditor selects one or more design and development projects and reviews the design plan for each. The plan must document the design and development stages, the review, verification, validation, and design transfer activities appropriate at each stage, and the assignment of responsibilities, authorities, and interfaces between groups involved in design and development. Auditors look for design plans as actual documents, flowcharts, Gantt charts, or PERT charts, not retrospective descriptions of what happened. ISO 13485:2016 clause 7.3.2 governs this task. Source: MDSAP Ch.5 Training Module, Task 3
Task 4: Design and development procedures meet regulatory requirements
Task 4 has an additional US-specific requirement: the auditor verifies that Design and Development procedures address the regulatory requirements for the US market (QMSR / 21 CFR Part 820) and that the organisation maintains defined and documented design change procedures that address those requirements. This task has no linkage to other MDSAP processes, making it a standalone documentation verification. There are additional country-specific requirements for Australia (TGA) and Canada (Health Canada). Source: MDSAP Ch.5 Training Module, Task 4
Task 5: Design and development inputs established
Design inputs must include functional, performance, usability, and safety requirements appropriate to the device’s intended use, as well as applicable statutory and regulatory requirements. They must also address requirements derived from previous similar designs where applicable. The completeness of design inputs is a common audit gap, facilities that treat design inputs as an early-stage formality rather than a maintained, version-controlled document set regularly generate Chapter 5 findings. ISO 13485:2016 clause 7.3.3 governs this task. Source: MDSAP AU P0002.010, Ch.5 Task 5
Task 6: Design inputs complete, coherent, and unambiguous
Task 6 goes further than Task 5: the auditor assesses whether the design inputs are complete, coherent, and unambiguous, not just whether they exist. An input that states “the device shall be safe” is ambiguous. An input that states “the device shall deliver a dose within plus or minus 5% of the programmed volume at all flow rates from 1 to 999 mL/hr under the conditions described in the IEC 60601-2-24 test standard” is specific, measurable, and testable. Ambiguous inputs generate downstream audit failures in Tasks 7 and 9 because the verification and validation evidence cannot be tied to a clear requirement. ISO 13485:2016 clause 7.3.3 governs this task. Source: MDSAP AU P0002.010, Ch.5 Task 6
Task 7: Design outputs and design verification
Design outputs must be traceable to design inputs and must allow evaluation of conformance. The auditor verifies that design verification activities confirm the design output meets the design input requirements. Links to the Purchasing process and Production and Service Controls process apply here, production processes and supplied products essential to proper device functioning must be considered during design and development output and verification. ISO 13485:2016 clause 7.3.4 and 7.3.6 govern this task. Source: MDSAP Ch.5 Training Module, Task 7
Tasks 8-9: Risk management throughout design
Task 8 verifies that risk management is defined and implemented throughout the design and development process, not as a final-stage activity. Risk acceptability criteria must be established and met at every stage. Any residual risk must be evaluated and, where appropriate, communicated to the customer through labelling, service documents, or advisory notices. Task 9 adds a specific requirement to verify that design verification or design validation activities confirm the effectiveness of risk control measures. A risk management file that is completed after the device is designed, rather than as design decisions are made, fails Task 8. ISO 13485:2016 clauses 7.1 and 7.3.3-7.3.4 govern these tasks. Source: MDSAP Ch.5 Training Slides, Tasks 8-9
Task 10: Design validation
Design validation confirms that the device meets the needs of the user and the intended patient population under actual or simulated use conditions. Validation is distinct from verification: verification confirms the design output meets the design input, while validation confirms the design input was the right input for the intended use. Clinical evaluation, usability testing, and simulated use testing are common validation activities. Validation must be completed before commercial distribution and must include all conditions specified in the device’s intended use. ISO 13485:2016 clause 7.3.7 governs this task. Source: MDSAP AU P0002.010, Ch.5 Task 10
Tasks 11-13: Design reviews, clinical evaluation, and design transfer
Task 11 verifies that formal design reviews were conducted at planned intervals, including representatives of all functions relevant to each stage. Records of design reviews must include outcomes and actions. Task 12 addresses clinical evaluation and clinical investigation requirements, which vary by jurisdiction. For devices distributed in Canada or Australia, clinical evidence requirements under Health Canada and TGA may differ from FDA clinical study expectations. Task 13 verifies design transfer to production: that records confirm the production line implemented at the facility meets production requirements established during design and development, and that design transfer controls and records have been determined. ISO 13485:2016 clauses 7.3.5, 7.3.8, and 7.3.7 govern these tasks. Source: MDSAP Ch.5 Training Module, Tasks 11-13
Tasks 14-15: Design changes identified, reviewed, and approved before implementation
Design changes must be identified, documented, reviewed, and approved before implementation. The review of changes must include evaluation of the effect of the change on constituent parts and delivered devices already in production or on the market. For devices distributed in MDSAP markets, design changes that affect device safety, performance, or labelling may require regulatory notification under the applicable jurisdiction’s requirements, this creates a direct link between Chapter 5 Task 14-15 and Chapter 2 Task 3 (advisory notices and design change notification). A change control procedure that does not include a regulatory impact assessment for each applicable market is a Chapter 5 finding. ISO 13485:2016 clause 7.3.9 governs these tasks. Source: MDSAP AU P0002.010, Ch.5 Tasks 14-15
Tasks 16-17: Design history file and design transfer to production verified complete
The Design History File (DHF) must demonstrate that the design was developed in accordance with the approved design plan. It must be complete, traceable, and include all design activities from inputs through transfer. Task 17 addresses the verification that design transfer to production is complete, that the production implementation at the facility meets the production requirements established during design and development. Design transfer records are a frequent Chapter 5 gap in facilities that move through design phases rapidly: records that were not captured contemporaneously cannot be reconstructed later to a level that satisfies audit scrutiny. ISO 13485:2016 clauses 4.2.5, 7.3.2, and 7.3.8 govern these tasks. Source: MDSAP AU P0002.010, Ch.5 Tasks 16-17
Risk management file not linked to design decisions, Tasks 8-9
The most consistently cited Chapter 5 finding across industry guidance. Risk management that runs parallel to design and development rather than integrated into it fails Tasks 8 and 9. The auditor expects to see risk control measures in the risk management file that correspond to specific design decisions, material selections, software architecture choices, physical design features, not a standalone risk document that describes hazards without tracing how design addressed each one. A risk management file completed after device design is finalised fails the “throughout” requirement of Task 8.
Design inputs ambiguous or incomplete, Tasks 5-6
Design inputs that are not specific enough to be verifiable are a Task 6 failure. “Meets applicable standards” without identifying which standards is ambiguous. “Safe for patient use” without measurable safety criteria is ambiguous. Auditors in Chapter 5 trace from design inputs to verification and validation evidence, if the input cannot be tested against an objective criterion, the entire verification record collapses. Incomplete inputs also fail because they omit mandatory categories: usability requirements, applicable statutory and regulatory requirements, and requirements derived from previous similar designs where applicable.
Design changes without formal review before implementation, Tasks 14-15
Design changes implemented through informal channels, an engineering change order approved verbally, a software update pushed without a change control record, a material substitution made without evaluating the effect on the overall device, generate Task 14-15 findings. ISO 13485:2016 clause 7.3.9 requires that design changes be identified, documented, reviewed, and approved before implementation. “Before implementation” is the standard: a change control record opened after a change has already been made is not compliant, even if it documents the change accurately.
Design History File incomplete or not contemporaneous, Tasks 16-17
The DHF must demonstrate that the design was developed in accordance with the approved design plan. Auditors look for design decisions that are traceable, input to output, output to verification, verification to validation, validation to design transfer. Records that were reconstructed or backdated cannot replicate the contemporaneous chain of evidence that demonstrates compliance throughout the design lifecycle. Gaps in the DHF are often discovered when auditors trace a design input through to production and find a missing link between design and manufacturing specifications.
Design change procedure does not include jurisdiction-specific regulatory notification assessment, Tasks 14-15
A design change procedure that evaluates changes for internal QMS impact but does not include a step to assess whether each change requires regulatory notification in each market where the device is distributed is a Chapter 5 finding. This finding also creates a direct Chapter 2 Task 3 finding (advisory notice reporting). A single SOP gap, no regulatory notification assessment in the change control procedure, can generate simultaneous findings in two chapters.
Maintain a documented design and development procedure that meets all 17 tasks
The procedure must address every stage of the design lifecycle covered by Chapter 5 tasks: planning (Tasks 1-4), inputs (Tasks 5-6), outputs and verification (Task 7), risk management (Tasks 8-9), validation (Task 10), reviews and transfer (Tasks 11-13), and design changes (Tasks 14-15). A procedure that addresses some stages but not others is partially compliant at best, and any unaddressed stage can generate a finding.
Integrate risk management into design, not alongside it
Risk management must be an input to design decisions, a driver of design verification activities, and a verification gate before design transfer. Organisations that maintain a risk management file as a parallel document, updated at the end of each phase rather than as decisions are made, will fail Tasks 8 and 9. The risk management file must show how risk control measures drove specific design choices and how verification and validation confirmed those controls are effective.
Update the design and development procedure for the February 2026 MDSAP update
MDSAP AU P0002.010, effective February 6, 2026, aligned the audit approach with the FDA QMSR and updated regulatory references throughout. Organisations whose design and development procedures still reference the legacy QSR (21 CFR 820 as it existed before the QMSR) should review and update those references to confirm continued alignment with the current audit approach and the QMSR. Source: NSF MDSAP Audit Approach Update Analysis, Feb 2026
Document the design exemption boundary if Chapter 5 is excluded from scope
A facility that claims a design exemption must be able to demonstrate, with documentation, that no design activity occurs within the MDSAP audit scope. An undocumented or poorly defined exemption boundary is itself a finding. If design activities occur at a parent company, a sister facility, or a contract design house, those activities must be covered under a different MDSAP certificate or through a formal outsourcing arrangement with an Annex 4 written agreement.
Legal Disclaimer
This article provides educational information about regulations and legal requirements. It does not constitute legal advice. Requirements vary by industry, jurisdiction, and specific workplace conditions. Consult a qualified safety professional or employment attorney for guidance specific to your workplace.
Chapter 5 is the highest-risk chapter for design-active MDSAP facilities
With 17 tasks spanning the full design lifecycle, Chapter 5 leaves no part of the design and development process unexamined. Risk management file linkage, design input completeness, and design change procedure documentation are the most frequently cited gaps. Facilities that perform design activities but have not structured their QMS around the Chapter 5 task sequence should treat their next MDSAP audit as a high-risk event.
The February 2026 MDSAP update requires procedure review for all design-active facilities
MDSAP AU P0002.010 (effective February 6, 2026) updated regulatory references throughout Chapter 5 to align with the FDA QMSR. Facilities whose design and development procedures still reference the legacy QSR should review those documents and confirm alignment with the current audit approach before their next scheduled MDSAP audit cycle.
A design change procedure gap in Chapter 5 creates a simultaneous Chapter 2 finding
The MDSAP audit process is designed around process linkages. A design change procedure that does not include a regulatory notification assessment for each MDSAP market fails Chapter 5 Tasks 14-15 and Chapter 2 Task 3 simultaneously. Both findings appear in the same audit report, both are visible to all five regulatory authorities, and both require CAPA responses. Compliance leaders who treat Chapter 5 design change controls and Chapter 2 advisory notice requirements as separate obligations will consistently generate paired findings. They are two requirements for the same process step.
What does MDSAP Chapter 5 cover?
MDSAP Chapter 5 covers the Design and Development process through 17 audit tasks. It addresses design and development procedures and planning (Tasks 1-4), design inputs and their completeness (Tasks 5-6), design outputs and verification (Task 7), risk management throughout design (Tasks 8-9), design validation (Task 10), design reviews, clinical evaluation, and design transfer (Tasks 11-13), design changes (Tasks 14-15), and the Design History File and design transfer verification (Tasks 16-17). It is the most task-dense chapter in the MDSAP programme. Source: MDSAP AU P0002.010
Can a facility exclude Chapter 5 from its MDSAP audit scope?
Yes, if the facility genuinely does not perform design and development activities within its MDSAP scope. The exclusion must be documented: the facility must be able to demonstrate with records that no design activity occurs within scope. An undocumented exclusion, where the facility claims design exemption but cannot produce evidence of the boundary, is itself a finding. If design is outsourced, a written agreement under MDSAP Annex 4 is required, and the outsourced design activity must be covered under the supplier’s own MDSAP certificate or an equivalent recognised audit. ISO 13485:2016 clause 7.3.1 permits exclusion with justification; the MDSAP audit process requires that justification to be documented and verifiable.
What is the difference between design verification and design validation under Chapter 5?
Design verification (Task 7) confirms that the design output meets the design input requirements. It answers: “Did we build what we designed?” Design validation (Task 10) confirms that the device meets the needs of the user and the intended patient population under actual or simulated conditions of use. It answers: “Did we design the right thing?” Both are required. A device that passes verification but fails validation has been accurately built to incorrect specifications. A device that passes validation but lacks verification documentation has not demonstrated traceability from requirements to performance. MDSAP Chapter 5 requires both, linked to each other and to the risk management file through Tasks 8 and 9.
What changed in MDSAP Chapter 5 under the February 2026 audit approach update?
MDSAP AU P0002.010, effective February 6, 2026, updated regulatory references across the audit approach to align with the FDA’s Quality Management System Regulation (QMSR), which became effective the same date. Within Chapter 5, references to the legacy Quality System Regulation (21 CFR 820 as it existed before QMSR) were updated. ISO 13485:2016 remains the foundational framework for all Chapter 5 tasks. The practical expectation is that ISO 13485 compliance and FDA compliance are now aligned rather than operating as parallel systems, organisations that managed them separately may need to review their procedures for consistency. Source: NSF MDSAP Audit Approach Update Analysis
How does Chapter 5 design change control connect to Chapter 2 advisory notice requirements?
Chapter 5 Tasks 14-15 require that design changes be reviewed before implementation and that the review assess the effect of the change on the device. That assessment must include a regulatory notification evaluation for each market where the device is distributed. Chapter 2 Task 3 requires that advisory notices be submitted to regulatory authorities when changes to marketed devices or the QMS require notification. A design change procedure that does not include a per-jurisdiction regulatory notification assessment fails both Task 14-15 and Chapter 2 Task 3. MDSAP findings cross chapters when processes cross chapters, the audit approach is designed to surface exactly this type of multi-chapter gap.
What does an auditor look for in the Design History File during a Chapter 5 audit?
The auditor looks for a complete, traceable record that demonstrates the device was developed in accordance with the approved design plan. Specifically: design inputs at each stage, design outputs traceable to those inputs, verification evidence linked to design outputs, validation evidence linked to intended use, risk management records showing how design decisions addressed identified risks, design review records with dates and participants, and design transfer records confirming the production implementation meets the design specifications. Gaps in any link of this chain, particularly missing design review records, undated design decisions, or risk management files that were not maintained contemporaneously, are Task 16 findings.
What are the most common Chapter 5 MDSAP findings and how can facilities prevent them?
Industry guidance consistently identifies three Chapter 5 gap clusters: (1) Risk management files not linked to design decisions, prevented by integrating risk management activities into design stage gates, not as a final-stage review; (2) Design inputs that are ambiguous or incomplete, prevented by requiring measurable, testable criteria for every input and reviewing against the Task 6 completeness, coherence, and unambiguity standard before design outputs are started; (3) Design changes implemented without prior formal review, prevented by ensuring the change control procedure explicitly requires review and approval before any implementation, and that the procedure includes a per-jurisdiction regulatory notification assessment. Source: Operon Strategist MDSAP Audit Checklist
Worker Safety
MDSAP Chapter 2: What Every Worker Needs to Know
The worker guide to MDSAP Chapter 2 device marketing authorization and facility registration, covering the three Chapter 2 tasks and how design changes in Chapter 5 trigger Chapter 2 advisory notice obligations.
Situational
MDSAP Chapter 4: What 14 Missed Reports Cost One Facility
A case study in MDSAP Chapter 4 audit failures, showing how design changes without advisory notice notifications create simultaneous Chapter 4 and Chapter 2 findings, directly parallel to Chapter 5 Task 14-15 risks.
Guides
21 CFR Part 803: Medical Device Reporting Requirements
The complete guide to FDA MDR reporting, including the post-market surveillance obligations that feed back into MDSAP Chapter 5 Task 2 (quality problems linked to design) and Chapter 5 Task 8 (risk management informed by post-market data).
MDSAP LAW AND COMPLIANCE LIBRARY
Prepare Your Design Controls for the MDSAP Audit
Explore VelSafe’s MDSAP and medical device regulatory library for law explainers, audit case studies, and compliance guidance covering all seven MDSAP chapters.
Explore All Law Articles