This repository publishes the open-source baseline behind qms.dearauditor.ch. It exists to provide a GitHub-native, reusable QMS baseline for remote-first medical device teams and to expose the controlled documents, templates, and workflows that make up the published example system.
This repository is not, by itself, an adopting company's operational QMS. It is the public upstream baseline that a company can select, mirror into a controlled private repository, tailor for its organization, validate for intended QMS use, train against, and approve before use. Product, study, supplier, validation, release, and operational evidence belongs in the adopter's designated controlled repositories, not in this public upstream baseline.
If you are here to use or read the baseline, start with the end-user links below. If you need repository/adoption background, use the landing page, the open-source adoption model, and CONTRIBUTING.md.
If you are reading this page on a QMS-YYYY-MM-DD-RNNN tag, this README is the release landing page for that published QMS baseline.
| I need to... | Open |
|---|---|
| Understand what this baseline is for | Landing page |
| Read the top-level baseline explanation | QM-001 Quality Manual |
| Adopt the baseline into a company QMS | Open-source adoption model |
| Tailor the baseline to what I am building | Adoption profiles |
| Jump straight to the current published document set | Published library |
| Open the formal QMS release for this baseline | QMS-2026-07-09-R005 |
| Find a specific SOP by topic | SOP library by topic |
| Open the work instructions | Work instructions |
| See my training work as a logged-in GitHub user | My open training issues |
| See role-based training requirements | Training matrix |
| See recorded training status | Training status report |
| Browse record families and templates | Records index |
| Understand workflows, automations, and trust boundaries | System architecture |
| Open the end-to-end automation diagram | Workflow automation map |
| Check published GitHub releases | Releases |
| Ask about adoption, support, or pilot use | Commercial support and adoption help |
- Published upstream baseline example entity:
ACME GmbH - Registered office:
Paradeplatz 8, 8001 Zurich, Switzerland - Operating model:
Remote-first - Current baseline shown in this README:
1published Quality Manual,23published SOPs, and2published WIs - Formal QMS release for this baseline:
QMS-2026-07-09-R005 - Formal QMS releases use
QMS-YYYY-MM-DD-RNNN, whereRNNNis the global sequential upstream baseline release number - This repository also publishes record-specific releases, so the newest overall release is not always the newest QMS baseline. In GitHub Releases, use the newest
QMS-...entry when you need the latest published QMS version.
The public upstream baseline provides reusable controlled content, templates, workflow automation, validators, and bootstrap tooling. The detailed adoption sequence is maintained in the open-source adoption model. Optional adoption profiles map common product types and use cases to the baseline areas that typically apply, without changing the product-independent default baseline.
The gap-analysis files in this repository show how the upstream baseline content maps to the current product-independent standards preparation set, including ISO 9001, ISO 13485, ISO 14971, IEC 62304, IEC 62366-1, IEC 82304-1, ISO/IEC 27001, and ISO/IEC 42001. They do not approve a downstream company, product, study, hosted service, or tool configuration by themselves.
- My open training issues for the logged-in user
- Training matrix for GitHub user-to-role mappings plus required versus awareness training scope
- Training status report for auditor-friendly current completion state
- SOP-011 Competence, Training, and Awareness for the governing procedure
- System architecture and workflow automation map for the workflow model
Use the grouped links below for navigation. The raw machine-readable published controlled-document index remains further down for automation compatibility.
- QM-001 Quality Manual -
R09
- SOP-001 Document and Record Control -
R15 - SOP-002 Corrective and Preventive Action (CAPA) -
R06 - SOP-003 Internal Audit -
R07 - SOP-004 Management Review -
R09 - SOP-005 QMS Governance -
R23 - SOP-011 Competence, Training, and Awareness -
R12 - SOP-016 Quality Metrics and Data Analysis -
R07 - SOP-017 Infrastructure and Maintenance Control -
R06 - SOP-021 Information Security Management (ISO/IEC 27001) -
R02 - SOP-022 AI Management System (ISO/IEC 42001) -
R02 - SOP-023 Data Protection and Privacy Management (GDPR and Swiss nFADP) -
R00
- SOP-006 Software Validation (QMS Tools) -
R05 - SOP-007 Medical Device File Control -
R10 - SOP-008 Design and Development Control -
R11 - SOP-009 Change Management -
R11 - SOP-018 Risk Management (ISO 14971) -
R10 - SOP-019 Usability Engineering (IEC 62366-1) -
R13 - SOP-020 Software Lifecycle, Configuration, and Release Management (IEC 62304) -
R13
- SOP-010 Supplier and Purchasing Control -
R05 - SOP-012 Feedback and Complaint Handling -
R08 - SOP-013 Regulatory Incident Reporting -
R07 - SOP-014 Post-Market Surveillance -
R07 - SOP-015 Nonconforming Product Control -
R06
- WI-001 Verification and Validation Execution -
R09 - WI-002 Configuration and Release Management Execution -
R10
Machine-readable published controlled document index (used by release and training automation)
| Document ID | Title | File | Revision Date | Published Revision | Status |
|---|---|---|---|---|---|
| QM-001 | Quality Manual | qm/QM-001-QualityManual.md | 2026-05-26 | R09 | Published |
| SOP-001 | Document and Record Control | sops/SOP-001-DocControl.md | 2026-05-04 | R15 | Published |
| SOP-002 | Corrective and Preventive Action (CAPA) | sops/SOP-002-CAPA.md | 2026-05-04 | R06 | Published |
| SOP-003 | Internal Audit | sops/SOP-003-InternalAudit.md | 2026-05-04 | R07 | Published |
| SOP-004 | Management Review | sops/SOP-004-ManagementReview.md | 2026-05-26 | R09 | Published |
| SOP-005 | QMS Governance | sops/SOP-005-QMSGovernance.md | 2026-05-26 | R23 | Published |
| SOP-006 | Software Validation (QMS Tools) | sops/SOP-006-SoftwareValidation.md | 2026-05-04 | R05 | Published |
| SOP-007 | Medical Device File Control | sops/SOP-007-MedicalDeviceFileControl.md | 2026-05-04 | R10 | Published |
| SOP-008 | Design and Development Control | sops/SOP-008-DesignAndDevelopmentControl.md | 2026-05-04 | R11 | Published |
| SOP-009 | Change Management | sops/SOP-009-ChangeManagement.md | 2026-05-04 | R11 | Published |
| SOP-010 | Supplier and Purchasing Control | sops/SOP-010-SupplierAndPurchasingControl.md | 2026-05-04 | R05 | Published |
| SOP-011 | Competence, Training, and Awareness | sops/SOP-011-CompetenceTrainingAndAwareness.md | 2026-05-26 | R12 | Published |
| SOP-012 | Feedback and Complaint Handling | sops/SOP-012-FeedbackAndComplaintHandling.md | 2026-05-26 | R08 | Published |
| SOP-013 | Regulatory Incident Reporting | sops/SOP-013-RegulatoryIncidentReporting.md | 2026-05-04 | R07 | Published |
| SOP-014 | Post-Market Surveillance | sops/SOP-014-PostMarketSurveillance.md | 2026-05-04 | R07 | Published |
| SOP-015 | Nonconforming Product Control | sops/SOP-015-NonconformingProductControl.md | 2026-05-04 | R06 | Published |
| SOP-016 | Quality Metrics and Data Analysis | sops/SOP-016-QualityMetricsAndDataAnalysis.md | 2026-05-26 | R07 | Published |
| SOP-017 | Infrastructure and Maintenance Control | sops/SOP-017-InfrastructureAndMaintenanceControl.md | 2026-05-04 | R06 | Published |
| SOP-018 | Risk Management (ISO 14971) | sops/SOP-018-RiskManagement.md | 2026-05-04 | R10 | Published |
| SOP-019 | Usability Engineering (IEC 62366-1) | sops/SOP-019-UsabilityEngineering.md | 2026-05-04 | R13 | Published |
| SOP-020 | Software Lifecycle, Configuration, and Release Management (IEC 62304) | sops/SOP-020-SoftwareLifecycleConfigurationAndReleaseManagement.md | 2026-05-04 | R13 | Published |
| SOP-021 | Information Security Management (ISO/IEC 27001) | sops/SOP-021-InformationSecurityManagement.md | 2026-05-04 | R02 | Published |
| SOP-022 | AI Management System (ISO/IEC 42001) | sops/SOP-022-AIManagementSystem.md | 2026-05-04 | R02 | Published |
| SOP-023 | Data Protection and Privacy Management (GDPR and Swiss nFADP) | sops/SOP-023-DataProtectionAndPrivacyManagement.md | 2026-05-14 | R00 | Published |
| WI-001 | Verification and Validation Execution | wis/WI-001-VerificationAndValidationExecution.md | 2026-04-27 | R09 | Published |
| WI-002 | Configuration and Release Management Execution | wis/WI-002-ConfigurationAndReleaseManagementExecution.md | 2026-04-27 | R10 | Published |
- Records index for reusable record templates and record families
- Company profile baseline
- Regulatory market scope baseline
- Quality manual traceability matrix
- QMS tooling inventory and validation baseline
- Signer registry
- Gap analyses: ISO 9001, ISO 13485, ISO 14971, IEC 62304, IEC 62366-1, IEC 82304-1, ISO/IEC 27001, ISO/IEC 42001
This baseline is maintained by DearAuditor. If you want hands-on help adopting it - mirroring it into your controlled repository, tailoring, training, validating it for intended use, or producing IQ/OQ/PQ validation documentation - contact the maintainers directly:
- Aliaksei Tsitovich - Management Representative, maintainer - LinkedIn - aliaksei@dearauditor.ch
- Søren Thorup - Quality Assurance Lead - LinkedIn - soren@dearauditor.ch
An introductory conversation costs nothing and does not commit you to anything.
- Landing page for the higher-level explanation of why this project exists
- Open-source adoption model for public-upstream versus private-adopter repo boundaries
- examples/bootstrap for downstream bootstrap seeds
- CONTRIBUTING.md for contribution and validation expectations