fda-medtech-compliance-auditor
Assists with regulatory compliance for medical software, specifically focusing on ISO/FDA standards and software lifecycle management.
Install
mkdir -p .claude/skills/fda-medtech-compliance-auditor && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/13740" && unzip -o skill.zip -d .claude/skills/fda-medtech-compliance-auditor && rm skill.zipInstalls to .claude/skills/fda-medtech-compliance-auditor
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Expert AI auditor for Medical Device (SaMD) compliance, IEC 62304, and 21 CFR Part 820. Reviews DHFs, technical files, and software validation.Key capabilities
- →Review Software Validation Protocols for Medical Devices
- →Audit Design History Files (DHF) for software-based tools
- →Ensure IT infrastructure meets 21 CFR Part 11 requirements
- →Prepare CAPA for software defects
- →Identify audit findings with regulatory citations
- →Provide actionable steps for audit readiness
How it works
The skill transforms into a specialized MedTech Compliance Auditor, reviewing provided documents against specified standards. It outputs audit findings with citations and actionable steps for resolution.
Inputs & outputs
When to use fda-medtech-compliance-auditor
- →Audit Design History Files
- →Review software validation protocols
- →Ensure 21 CFR Part 11 compliance
- →Prepare CAPA reports
About this skill
FDA MedTech Compliance Auditor
Overview
This skill transforms your AI assistant into a specialized MedTech Compliance Auditor. It focuses on Software as a Medical Device (SaMD) and traditional medical equipment regulations, including 21 CFR Part 820 (Quality System Regulation), IEC 62304 (Software Lifecycle), ISO 13485, and ISO 14971 (Risk Management).
When to Use This Skill
- Use when reviewing Software Validation Protocols for Medical Devices.
- Use when auditing a Design History File (DHF) for a software-based diagnostic tool.
- Use when ensuring IT infrastructure meets 21 CFR Part 11 requirements for electronic records.
- Use when preparing a CAPA (Corrective and Preventive Action) for a software defect.
How It Works
- Activate the Skill: Mention
@fda-medtech-compliance-auditorand provide the document you wish to review. - Specify the Standard: State whether the focus is on Part 820, Part 11, ISO 13485, ISO 14971, or IEC 62304.
- Receive Findings: The AI outputs specific audit findings categorized by severity (Major, Minor, Opportunity for Improvement) with regulatory citations.
- Correction Guidance: Get actionable steps to resolve each finding and strengthen your audit readiness.
Examples
Example 1: CAPA Root Cause Review
Scenario: A CAPA was opened for a software defect in a Class II device. The documented root cause is “developer error — unclear requirements.” The corrective action is developer retraining.
Finding:
FDA AUDIT FINDING
Severity: Major
Citation: 21 CFR 820.100(a)(2) / IEC 62304 Section 5.1
Analysis:
"Developer error" is a symptom, not a root cause. Retraining alone is
a known red flag for FDA inspectors and will not withstand scrutiny.
The true root cause lies in the software requirements engineering
process itself — not an individual.
Required Actions:
1. Perform a 5-Whys or Fishbone analysis targeting the requirements
gathering and review process.
2. Update the SRS (Software Requirements Specification) and the
corresponding process SOP.
3. Document an effectiveness check with a measurable criterion
(e.g., zero requirements-related defects in next 3 releases).
4. Do not close the CAPA on retraining alone.
Best Practices
- ✅ Do: Provide exact wording from SOPs, risk tables, or validation plans for the most accurate review.
- ✅ Do: Expect strict interpretations — the goal is to find weaknesses before a real inspector does.
- ❌ Don't: Forget to link every software defect to a clinical risk item in your ISO 14971 risk file.
- ❌ Don't: Assume "we tested it and it works" satisfies IEC 62304 software verification requirements.
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
When not to use it
- →When the focus is not on 21 CFR Part 820, IEC 62304, ISO 13485, or ISO 14971
- →When the output is intended as a substitute for environment-specific validation
Limitations
- →The skill requires the user to provide the document for review and specify the standard.
- →The skill expects strict interpretations to find weaknesses before an inspector does.
How it compares
This skill provides specific, citation-backed audit findings and correction guidance, unlike a general document review.
Compared to similar skills
fda-medtech-compliance-auditor side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| fda-medtech-compliance-auditor (this skill) | 0 | 3mo | No flags | Advanced |
| ra-qm-skills | 1 | 2mo | Review | Advanced |
| security-requirement-extraction | 7 | 2mo | No flags | Intermediate |
| gdpr-dsgvo-expert | 8 | 7mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by TJSNDHU
View all by TJSNDHU →You might also like
ra-qm-skills
alirezarezvani
12 production-ready regulatory affairs and quality management skills for HealthTech/MedTech: ISO 13485 QMS, MDR 2017/745, FDA 510(k)/PMA, ISO 27001 ISMS, GDPR/DSGVO compliance, risk management (ISO 14971), CAPA, document control, and internal auditing. Python tools included (all stdlib-only). Works with Claude Code, Codex CLI, and OpenClaw.
security-requirement-extraction
wshobson
Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.
gdpr-dsgvo-expert
davila7
Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance. Provides EU GDPR and German DSGVO expertise, privacy impact assessments, data protection auditing, and compliance verification. Use for GDPR compliance assessments, privacy audits, data protection planning, and regulatory compliance verification.
data-privacy-compliance
davila7
Data privacy and regulatory compliance specialist for GDPR, CCPA, HIPAA, and international data protection laws. Use when implementing privacy controls, conducting data protection impact assessments, ensuring regulatory compliance, or managing data subject rights. Expert in consent management, data minimization, and privacy-by-design principles.
audit-support
anthropics
Support SOX 404 compliance with control testing methodology, sample selection, and documentation standards. Use when generating testing workpapers, selecting audit samples, classifying control deficiencies, or preparing for internal or external audits.
awesome-game-security-overview
gmh5225
Guide for understanding and contributing to the awesome-game-security curated resource list. Use this skill when adding new resources, organizing categories, understanding project structure, or maintaining the README.md format consistency.