FD

fda-medtech-compliance-auditor

Assists with regulatory compliance for medical software, specifically focusing on ISO/FDA standards and software lifecycle management.

Install

mkdir -p .claude/skills/fda-medtech-compliance-auditor && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/13740" && unzip -o skill.zip -d .claude/skills/fda-medtech-compliance-auditor && rm skill.zip

Installs to .claude/skills/fda-medtech-compliance-auditor

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Expert AI auditor for Medical Device (SaMD) compliance, IEC 62304, and 21 CFR Part 820. Reviews DHFs, technical files, and software validation.
143 charsno explicit “when” trigger
Advanced

Key capabilities

  • Review Software Validation Protocols for Medical Devices
  • Audit Design History Files (DHF) for software-based tools
  • Ensure IT infrastructure meets 21 CFR Part 11 requirements
  • Prepare CAPA for software defects
  • Identify audit findings with regulatory citations
  • Provide actionable steps for audit readiness

How it works

The skill transforms into a specialized MedTech Compliance Auditor, reviewing provided documents against specified standards. It outputs audit findings with citations and actionable steps for resolution.

Inputs & outputs

You give it
Document to review (e.g., Software Validation Protocol, DHF, CAPA), specified standard (e.g., Part 820, IEC 62304)
You get back
Audit findings categorized by severity with regulatory citations, correction guidance

When to use fda-medtech-compliance-auditor

  • Audit Design History Files
  • Review software validation protocols
  • Ensure 21 CFR Part 11 compliance
  • Prepare CAPA reports

About this skill

FDA MedTech Compliance Auditor

Overview

This skill transforms your AI assistant into a specialized MedTech Compliance Auditor. It focuses on Software as a Medical Device (SaMD) and traditional medical equipment regulations, including 21 CFR Part 820 (Quality System Regulation), IEC 62304 (Software Lifecycle), ISO 13485, and ISO 14971 (Risk Management).

When to Use This Skill

  • Use when reviewing Software Validation Protocols for Medical Devices.
  • Use when auditing a Design History File (DHF) for a software-based diagnostic tool.
  • Use when ensuring IT infrastructure meets 21 CFR Part 11 requirements for electronic records.
  • Use when preparing a CAPA (Corrective and Preventive Action) for a software defect.

How It Works

  1. Activate the Skill: Mention @fda-medtech-compliance-auditor and provide the document you wish to review.
  2. Specify the Standard: State whether the focus is on Part 820, Part 11, ISO 13485, ISO 14971, or IEC 62304.
  3. Receive Findings: The AI outputs specific audit findings categorized by severity (Major, Minor, Opportunity for Improvement) with regulatory citations.
  4. Correction Guidance: Get actionable steps to resolve each finding and strengthen your audit readiness.

Examples

Example 1: CAPA Root Cause Review

Scenario: A CAPA was opened for a software defect in a Class II device. The documented root cause is “developer error — unclear requirements.” The corrective action is developer retraining.

Finding:

FDA AUDIT FINDING
Severity: Major
Citation: 21 CFR 820.100(a)(2) / IEC 62304 Section 5.1

Analysis:
"Developer error" is a symptom, not a root cause. Retraining alone is
a known red flag for FDA inspectors and will not withstand scrutiny.
The true root cause lies in the software requirements engineering
process itself — not an individual.

Required Actions:
1. Perform a 5-Whys or Fishbone analysis targeting the requirements
   gathering and review process.
2. Update the SRS (Software Requirements Specification) and the
   corresponding process SOP.
3. Document an effectiveness check with a measurable criterion
   (e.g., zero requirements-related defects in next 3 releases).
4. Do not close the CAPA on retraining alone.

Best Practices

  • Do: Provide exact wording from SOPs, risk tables, or validation plans for the most accurate review.
  • Do: Expect strict interpretations — the goal is to find weaknesses before a real inspector does.
  • Don't: Forget to link every software defect to a clinical risk item in your ISO 14971 risk file.
  • Don't: Assume "we tested it and it works" satisfies IEC 62304 software verification requirements.

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

When not to use it

  • When the focus is not on 21 CFR Part 820, IEC 62304, ISO 13485, or ISO 14971
  • When the output is intended as a substitute for environment-specific validation

Limitations

  • The skill requires the user to provide the document for review and specify the standard.
  • The skill expects strict interpretations to find weaknesses before an inspector does.

How it compares

This skill provides specific, citation-backed audit findings and correction guidance, unlike a general document review.

Compared to similar skills

fda-medtech-compliance-auditor side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
fda-medtech-compliance-auditor (this skill)03moNo flagsAdvanced
ra-qm-skills12moReviewAdvanced
security-requirement-extraction72moNo flagsIntermediate
gdpr-dsgvo-expert87moReviewAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

ra-qm-skills

alirezarezvani

12 production-ready regulatory affairs and quality management skills for HealthTech/MedTech: ISO 13485 QMS, MDR 2017/745, FDA 510(k)/PMA, ISO 27001 ISMS, GDPR/DSGVO compliance, risk management (ISO 14971), CAPA, document control, and internal auditing. Python tools included (all stdlib-only). Works with Claude Code, Codex CLI, and OpenClaw.

13

security-requirement-extraction

wshobson

Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.

759

gdpr-dsgvo-expert

davila7

Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance. Provides EU GDPR and German DSGVO expertise, privacy impact assessments, data protection auditing, and compliance verification. Use for GDPR compliance assessments, privacy audits, data protection planning, and regulatory compliance verification.

831

data-privacy-compliance

davila7

Data privacy and regulatory compliance specialist for GDPR, CCPA, HIPAA, and international data protection laws. Use when implementing privacy controls, conducting data protection impact assessments, ensuring regulatory compliance, or managing data subject rights. Expert in consent management, data minimization, and privacy-by-design principles.

418

audit-support

anthropics

Support SOX 404 compliance with control testing methodology, sample selection, and documentation standards. Use when generating testing workpapers, selecting audit samples, classifying control deficiencies, or preparing for internal or external audits.

412

awesome-game-security-overview

gmh5225

Guide for understanding and contributing to the awesome-game-security curated resource list. Use this skill when adding new resources, organizing categories, understanding project structure, or maintaining the README.md format consistency.

49

Search skills

Search the agent skills registry