Ten governance pillars · one regulated stack.
Quick-reference grid of the ten frameworks that shape regulated quality systems · then the cross-stack drilldown for each. ISO 9001 · ISO 13485 · ICH Q10 · Q9(R1) · Q12 · 21 CFR Part 820 / QMSR · 21 CFR Part 11 · EU Annex 11 · ISO/IEC 42001 · GAMP 5. The flagship chapter for governance.
The governance stack: ten frameworks.
Layered · load-bearing · audit-testedNo regulated organisation runs on a single quality framework. The governance spine can be understood by layering ten standards — some written by industry (ISO), some by harmonised regulators (ICH), some by single-jurisdiction regulators (FDA, EMA), and the newest tier by horizontal AI bodies (ISO/IEC 42001, EU AI Act). Each framework owns a different surface. Each has its own audit grammar. Inspections and notified-body assessments often look across this stack in practice; gaps between layers are where evidence-readiness questions tend to appear.
10 frameworks · one comparison · one audit lens.
Pick a framework. Read its scope, its trigger, what it requires, its audit-readiness implications. Designed for the QA director, the validation lead, the regulatory affairs team, the clinical operations sponsor, and the AI/ML governance owner asked to bridge ISO/IEC 42001 onto the existing PQS.
The ten governance pillars.
The regulated-life-sciences spineBelow: a quick-reference grid of the ten frameworks · then the comparison drilldown for each. QMSR (★) is where 2026 implementation friction runs deepest; ISO/IEC 42001 (★) is where the AI-governance retrofit work sits.
Quick reference · the ten frameworks.
ISO 9001:2015.
Generic QMS foundation. Plan-Do-Check-Act, customer focus, risk-based thinking, leadership, continual improvement. The non-regulated baseline that every other QMS layers on.
ISO 13485:2016.
Medical-device QMS. Notified-body baseline for EU MDR / IVDR. Now the foundation FDA's QMSR harmonises against, effective 2 February 2026.
ICH Q10 · PQS.
Pharmaceutical Quality System (2008). Adds product lifecycle, management responsibility, knowledge management to the ISO 9001 baseline. The standard a pharma sponsor's PQS is graded against.
ICH Q9(R1) 2023.★
Quality Risk Management. R1 (Jan 2023) added subjectivity-management, knowledge-base risk, and digitalisation. A central quality-risk reference for modern audit and inspection thinking.
ICH Q12 · lifecycle.
Lifecycle management for established conditions and post-approval changes. Step 4 in November 2019. Implementation uneven across regions through 2026.
21 CFR 820 / QMSR.★
FDA medical-device QMS rule. Final rule Feb 2024; effective 2 February 2026. Harmonises with ISO 13485:2016 by reference, retains FDA-specific overlays.
21 CFR Part 11.
Electronic records, electronic signatures (1997). Audit trail, attribution, identification, validation. The data-integrity floor — ALCOA+ derives from §11 read across regulators.
EU Annex 11.
Computerised systems · EU GMP Volume 4. Companion to Part 11 in EU jurisdictions. AI-related EU GMP expectations under watch through official EudraLex updates.
ISO/IEC 42001:2023.★
AI management system (Dec 2023). The first international standard for governance of AI. The AI management-system anchor. Layers onto the existing QMS, not a replacement.
GAMP 5 2nd ed.
Validation lifecycle for computerised systems. ISPE GAMP 5 (2nd edition 2022) added critical-thinking, agile, AI/ML appendices. Industry-best-practice anchor for Part 11 / Annex 11 implementation.
Cross-stack comparison · scope, trigger, requirements, audit lens.
/ 01 ISO 9001:2015.Generic QMS · the non-regulated baseline every regulated stack layers on. +
/ 02 ISO 13485:2016.Medical-device QMS · notified-body baseline · QMSR foundation. +
/ 03 ICH Q10 · Pharmaceutical Quality System.2008 · the pharma PQS standard layered on ISO 9001. +
/ 04 ICH Q9(R1) · Quality Risk Management.★2005 / R1 January 2023 · a central quality-risk reference for modern audit and inspection thinking. +
/ 05 ICH Q12 · lifecycle management.Step 4 November 2019 · established conditions, post-approval changes. +
/ 06 21 CFR Part 820 / QMSR.★FDA medical-device QMS · effective 2 February 2026. +
/ 07 21 CFR Part 11.Electronic records · electronic signatures · the data-integrity floor. +
/ 08 EU Annex 11.Computerised systems · EU GMP Volume 4 · AI-related GMP expectations under official-source watch. +
/ 09 ISO/IEC 42001:2023.★December 2023 · an international AI management-system standard. +
/ 10 GAMP 5 2nd edition.Validation lifecycle for computerised systems · ISPE 2nd ed. 2022. +
Source register.
official anchors · interpretation separatedQMSR final rule.
Federal Register final rule amending the Quality System Regulation; effective date and FDA-specific overlays should be read from the rule text.
21 CFR Part 820.
Current legal text for FDA device quality-system requirements; use this as the live clause anchor for QMSR references.
Q9(R1) quality risk management.
Step 4 guideline for quality-risk-management concepts, subjectivity, formality, and knowledge management.
Q10 pharmaceutical quality system.
Pharmaceutical quality-system reference for management responsibility, lifecycle quality, CAPA, and continual improvement.
Q12 lifecycle management.
Step 4 guideline for established conditions, post-approval change management, and product lifecycle management.
21 CFR Part 11.
Electronic records and electronic signatures rule; use with predicate-rule context and FDA scope guidance.
Data integrity Q&A.
FDA questions-and-answers guidance on data integrity and CGMP; useful for ALCOA+ and audit-trail interpretation.
EudraLex Volume 4.
Official EU GMP page for Annex 11 and related GMP annexes; AI-specific GMP claims should be checked here before publication.
EU AI Act.
Regulation (EU) 2024/1689 official text; used for AI Act timing, high-risk system references, and governance boundaries.
ISO/IEC 42001.
AI management-system standard landing page. Full standard text is paid; public iFeed content should not quote unavailable clauses.
Computer Software Assurance.
FDA guidance PDF for production and quality-system software; useful for CSA and CSV evidence-readiness discussion.
GAMP 5, second edition.
Industry guidance landing page. Treat as implementation guidance, not a regulation; full guide access is controlled by ISPE.