The audit nobody wants to repeat
A reviewer asked for the 2019 risk management report. Forty minutes later, three of us had failed to find it. The document existed. It was signed off. It was filed under a folder whose naming logic was obvious in 2020 and inscrutable to all subsequent versions of the team.
Per ISO 13485:2016 clause 4.2.5, we are supposed to control those records. In practice what we controlled was the file itself. Not the finding of it.
This is the thing nobody admits in the run-up to a notified body audit: the documentation is usually fine. The findability is not. And findability is what your reviewer is actually testing when they ask for something slightly obscure. The document control quality you can talk about. The folder hierarchy you have to demonstrate in front of them, while they wait.
What "where is it stored" actually costs
Every minute a reviewer spends hunting is a minute your subject matter expert is not answering the question that was actually asked. It pulls the QA lead off the walkthrough. It pulls the CAPA owner off the substantive part of the interview. The audit extends by half a day. You start losing answers you had ready, because everyone is busy being a filing clerk.
The reviewer does not care that your eQMS has a search box. They will use the search box once. After that they will ask a human. If the human's answer starts with "let me check," you have already spent more than you should have.
How I lay out qmsWrapper storage before an audit
I work in qmsWrapper. The principles below are universal, but I will describe how I actually use them.
1. Mirror the standard, not the team.
Top-level folders follow ISO 13485 clauses and MDR Annex II / III sections. Not "Marketing" or "Engineering" or, god forbid, "Misc." When a reviewer asks for "your post-market surveillance system per Article 10(9)(h)," the path is something like MDR / Art10_PMS / and the next click gets them the PSUR template, the PMCF plan, the vigilance procedure, and the periodic trend report. No translation needed. The reviewer navigates the same map you do.
2. Date in the name, year first.
2021-03-14_RiskManagementReport_v3.0_SIGNED.pdf, not RMR_final_FINAL_v2.pdf. ISO 8601 sorts. Sorting works in isolation, but it also means the version history is visually obvious, and your auditor can ask "show me the version in force before the post-market design change" without anyone opening a file to check.
3. One current, one archive.
For every live document there is exactly one active version in the live folder and one archive folder per year. Anything superseded moves immediately. No Final_Final_v3_use_this_one.docx ever lives in the live tree. When the reviewer asks "what was in force in Q2 last year," you click one folder. Done.
4. Cross-link to the clause, not just the title.
Every document name carries the clause or annex it satisfies — through tags, metadata, or simply a suffix in the filename. When the reviewer is sampling, they pull the document and the clause lives next to it. The traceability link is in the file itself. No separate traceability matrix to walk them through.
5. A 00_README at the root of each domain.
Two paragraphs. What lives here, what does not, who owns it, last reviewed date. The reviewer opens the README before they open anything else. If they ask you a question, you point at it.
What this changes on the day
When the storage is laid out this way, the audit shifts. The reviewer navigates. You answer. The CAPA owner is not pulled into a hunt. The QA lead is not pulled into a translation. The substantive findings get more substantive. The trivial ones — "your folder structure is confusing" — simply do not exist.
It also changes the run-up. A reviewer will email a document request list two weeks ahead. In a well-organised system you answer it in an hour, not a day. That hour is the difference between the QA lead being able to keep doing their job and the QA lead spending the week pulling files. The controlled, reviewable nature of how everything is filed is what makes the difference between a smooth audit week and a triage exercise.
The honest concession
This takes discipline. The first time you do it, you will resent it. The second time, it is a habit. The third time, it is the reason your audit finishes on Friday afternoon instead of dragging through Saturday morning.
It is also not the whole answer. Storage is one piece. Your change control has to actually close, your CAPAs have to actually have root causes, your training records have to actually be current. Storage does not save you from a bad QMS. It just stops the audit from finding out about the bad parts because of the wrong folder. The documents still have to be good. You just give the reviewer a fair chance to read them.
Does your team have a shared convention, or does each function still file its own way? I am curious whether anyone has cracked this for the genuinely awkward documents — the ones that cross functions, where the obvious owner is genuinely unclear and "MDR - Annex II section 6.1" is not enough on its own to tell the reviewer which version is the right one.
Disclosure: I work on qmsWrapper.
Top comments (0)