DEV Community

Priya Nair
Priya Nair

Posted on

I spent five years turning QMS into paperwork. This video reminded me what it was for.

The conversation that was never in the QMS

Last week I watched a short video on the difference between "managing quality" and "managing through quality." I expected the usual vendor pitch. Instead I got something I have been trying to articulate for about three years.

The core idea, in my own words: a QMS is not a library of approved documents. It is the running record of the conversations that produced a quality decision. When the conversation lives in email, in hallway chats, in someone's head, and only the output lands in the system, you do not have a quality management system. You have a paperwork archive that audits well and protects no one.

I have built that archive. More than once.

What the theatre looks like in MDR work

To be fair, the theatre builds itself. MDR 2017/745, Annex II, Section 6.1 wants your post-market surveillance data. Article 10(9) wants you to keep Technical Documentation up to date. Annex IX wants your QMS documented. None of those articles say "produce a PDF every quarter." But in practice this is what happens:

  • A PSUR gets generated as a 40-page document that nobody re-reads after sign-off.
  • A CAPA is opened, root cause is "human error," corrective action is "retrain," and the closure date is set for 90 days out.
  • A change request gets approved in one module; the linked risk file gets updated in a separate one, three weeks later, by a different person.
  • The audit trail says everything was done on time. The actual decision happened in a Teams chat.

I am not picking on any one company. I have been inside that exact pattern. So has every QA colleague I trust.

What "managing through quality" means, in my day

The phrase that stuck with me from the video was simple: quality decisions happen through conversations, so bring the conversation into the QMS. In practice this means the artefact (the CAPA record, the change ticket, the risk assessment) is not the start of the work. It is the residue of the work. The work is the discussion that produced it.

When I read the Peek Vision team's writeup of their CE-marking journey, the part that struck me was not the regulatory strategy. It was the description of how their clinical, regulatory, and engineering leads made decisions together, with the evidence on the table, and only then wrote the document. The document was downstream of the decision. In most places I have worked, the document was the decision.

That is the gap. And the gap is where notified body findings come from. A finding is rarely "your procedure is wrong." It is "you cannot show me how you decided this."

Where the conversation actually breaks down

Three places, in my experience:

  1. Between functions. Regulatory, clinical, quality, and engineering each have their own swim lane. The decision needs all four. The system only stores each lane's output.
  2. Between the live work and the record. Engineers discuss a design change in a meeting. The change record captures the outcome, not the reasoning. A year later, in a PSUR or a clinical evaluation update, the why is gone.
  3. Between humans and the tools that are supposed to help. An eQMS that requires fourteen fields to log a deviation will get bypassed. The deviation happens in a Notion doc, a Slack thread, or a verbal "I will fix it." The QMS never sees it.

This is where the AI conversation gets interesting, and where it gets dangerous.

What controlled assistance actually looks like

Granted, "AI for QMS" is mostly noise in vendor decks right now. But there is a real category underneath the noise: AI-assisted or AI-guided help for the people who are already doing the work.

Concretely:

  • A CAPA owner drafts a root cause, and the system flags missing elements against your procedure. Reviewable, not authoritative.
  • A change request gets opened, and the impact mapping pulls the linked risks, suppliers, and design history items automatically. Connected workflow, not a new module bolted on the side.
  • A supplier-quality engineer chases a non-conformance, and the system summarises the last eighteen months of similar NCRs for that supplier. Traceable, sourced, dismissible.

The key word is reviewable. The QMS manager and the engineer stay in the loop. The AI is a controlled assistant. It does not sign anything. It does not close the CAPA. It does not make the call. It surfaces what is already in the system, and it lets a human decide.

What I took from the video

Two things.

First, the audit trail of the decision matters more than the audit trail of the document. If you can show the conversation that produced your equivalence claim under MDR Article 61, your literature search strategy, your PMCF methodology choice, that is the evidence the notified body is actually asking for, even when they phrase it as "show me your procedure."

Second, the tools that bring the conversation into the system, not just the output, are the ones that change behaviour. A system that lets a CAPA owner, a quality manager, and a design engineer argue in writing, in one place, with the linked risk and the linked change visible, will outperform a system that lets them each file a separate report. Connected workflow is not a feature. It is the point.

The video is worth twenty minutes if any of this resonates. The link is in the opener.

Over to you

Where in your QMS does the conversation happen outside the system, and what is the cost when the auditor asks "show me how you decided this" and the only answer is a signed PDF?

Top comments (0)