The systematic process (21 CFR 820.30; ISO 13485) for controlling medical-device design — inputs, outputs, review, verification, validation, transfer, and changes — captured in a traceable design history file.
Design controls impose a traceable structure on device development. Design inputs capture the user needs and intended use as requirements that are complete, unambiguous, and verifiable. Design outputs are what development produces — specifications, drawings, code, labelling — and must be expressed so they can be checked against the inputs. Between them sit formal design reviews at defined stages, with an independent reviewer who has no direct responsibility for the stage under review.
Verification and validation are distinct and are frequently confused. Verification asks whether the design outputs meet the design inputs — did we build the device right? Validation asks whether the device meets user needs and intended uses under actual or simulated use conditions — did we build the right device? Validation therefore involves initial production units and, where relevant, clinical evaluation; passing verification tells you nothing about whether the device is fit for its purpose.
Design transfer translates the design into production specifications, and design changes remain controlled after launch — a change post-market re-enters the same verification, validation, and review discipline. Everything is captured in the Design History File, the traceable record from user need through to released design. Design control deficiencies are among the most frequently cited device findings, usually as broken traceability or validation performed on prototypes rather than production-equivalent units.
- —Inputs (requirements) → outputs (specifications) with traceability throughout.
- —Formal design reviews at defined stages, with an independent reviewer present.
- —Verification: outputs meet inputs. Validation: device meets user needs in actual or simulated use.
- —Validation uses initial production units — not prototypes.
- —Design transfer converts the design into production specifications; changes stay controlled after launch.
- —The Design History File is the traceable record; broken traceability is a common finding.
21 CFR 820.30 (Design Controls), transitioning under the FDA QMSR effective February 2026; ISO 13485:2016 §7.3; risk management integrated per ISO 14971; usability engineering per IEC 62366-1.
Frequently asked questions
What is Design Controls?
The systematic process (21 CFR 820.30; ISO 13485) for controlling medical-device design — inputs, outputs, review, verification, validation, transfer, and changes — captured in a traceable design history file.
Which regulations cover Design Controls?
21 CFR 820.30 (Design Controls), transitioning under the FDA QMSR effective February 2026; ISO 13485:2016 §7.3; risk management integrated per ISO 14971; usability engineering per IEC 62366-1.
SPEQ decodes published regulatory concepts in plain language. Definitions are a practitioner reference, not legal or regulatory advice.
Get the Weekly GxP Briefing
Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.