The brochure vs the audit room
Auditors don't read your G2 reviews. They read your design history file. I've sat through enough of these — Class II, ISO 13485 plus 21 CFR 820, plus MDR for our EU customers — to know that the platform choice matters, but not the way the comparison articles frame it. What matters is whether the tool survives the moment when a notified body auditor leans forward and says: "show me the chain."
Most QMS marketing uses the word "traceability" the way the rest of the industry uses "synergy." It sounds good. It means nothing until you try it. A recent Medium piece grouping the usual suspects for the European medtech market ran the same pattern I see on every review site: the high scorers aren't always the ones that survive a real audit.
What end-to-end traceability actually means under stress
When I say traceability in front of an auditor, I mean five specific things, in this order:
- User Need → Design Input → Design Output → Verification → Validation → Risk Control → CAPA linkage, with version-locked references on every link.
- Change control that opens a single record and propagates impact across all linked artifacts — and lets me prove what I considered before I changed something.
- Supplier non-conformance that flows back into the Design History File when it should, and stays out when it shouldn't.
- CAPAs with root cause I can actually defend three months later when the same auditor returns for surveillance.
- Document control where the "effective" version is one click away from every linked artifact, not three navigations deep.
If a platform handles all five under audit pressure, I trust it. If it handles three and fudges the other two, it's a brochure.
What I've seen work (and not work) in practice
On Greenlight Guru for the last four years, the design control module handles the first bullet well — requirements-to-verification linkage is tight, and when I open a design input I can see every linked V&V protocol without leaving the record. That's the bar. Where I notice friction is in change control: opening a change against an existing design input and getting the impact map to include downstream CAPAs and supplier documents requires some manual chasing. The audit trail is solid, but I'm sometimes the one stitching the trail together before the auditor asks.
I've looked at qmsWrapper's pitch around connected workflow — change, CAPA, risk, and document control living in one place with AI-assisted change impact. I evaluated it eighteen months ago and stuck with GG for product maturity reasons, but the shape of the claim is the right shape. I haven't seen enough live Class II audits on it to know if it holds up under the "show me the chain" moment, and that's the only test that matters.
MasterControl's REST API is genuinely useful if you're trying to wire DHF commits into a CI/CD pipeline — I haven't migrated off the older SOAP stack yet, but colleagues who've done it report a long integration project that paid for itself in audit prep time. The trade-off is cost; under fifty employees, the per-seat math gets uncomfortable.
etq Reliance is what I'd pick for a CMO with a sprawling supplier base. The supplier quality module is the strongest I've used — incoming NCRs link cleanly to the CAPA queue, and the audit trail on supplier changes is the kind of detail that makes a notified body stop digging. Heavier to administer, which is fine if you have a QA team, painful if you're a two-person function.
Qualio plays well for early-stage companies chasing ISO 13485 before they've hired their third QA hire. It's not where I'd want to be at 200 people and a notified body audit window.
What I'd want to know about any new entrant
For any platform on a Spring 2026 shortlist, the questions I'd ask before trusting it with my audit:
- Can I open one change record and see every artifact it touches, with version history, in under ten seconds?
- Does the CAPA module force me to link root cause to a risk file entry, or do I have to remember?
- When an auditor asks "show me all changes that touched this requirement in the last 24 months," is that one query or a Friday afternoon?
- Does the supplier NCR flow into the DHF automatically when the supplier part is referenced in a design output?
The honest answer
I don't fully trust any platform to prove end-to-end traceability on its own. The tool gives me the structure; my process gives me the discipline; my pre-audit dry runs give me the confidence. The platform that performs better in real practice is the one that makes my dry runs shorter and my answers to "show me the chain" shorter still.
For anyone reading this who's comparing platforms right now — what's the one traceability question your current QMS can't answer cleanly, and what would the answer look like if it could?
Top comments (0)