Ten governance pillars · one regulated stack.
Quick-reference grid of the ten frameworks that shape regulated quality systems · then the cross-stack drilldown for each. ISO 9001 · ISO 13485 · ICH Q10 · Q9(R1) · Q12 · 21 CFR Part 820 / QMSR · 21 CFR Part 11 · EU Annex 11 · ISO/IEC 42001 · GAMP 5. The flagship chapter for governance.
The governance stack: ten frameworks.
Layered · load-bearing · audit-testedNo regulated organisation runs on a single quality framework. The governance spine is built by layering ten standards — some written by industry (ISO), some by harmonised regulators (ICH), some by single-jurisdiction regulators (FDA, EMA), and the newest tier by horizontal AI bodies (ISO/IEC 42001, EU AI Act). Each framework owns a different surface. Each has its own audit grammar. Inspections and notified-body assessments read this stack as a single document — gaps between layers are where 483s and major non-conformances cluster.
10 frameworks · one comparison · one audit lens.
Pick a framework. Read its scope, its trigger, what it requires, its audit-readiness implications. Designed for the QA director, the validation lead, the regulatory affairs team, the clinical operations sponsor, and the AI/ML governance owner asked to bridge ISO/IEC 42001 onto the existing PQS.
The ten governance pillars.
The regulated-life-sciences spineBelow: a quick-reference grid of the ten frameworks · then the comparison drilldown for each. QMSR (★) is where 2026 implementation friction runs deepest; ISO/IEC 42001 (★) is where the AI-governance retrofit work sits.
Quick reference · the ten frameworks.
ISO 9001:2015.
Generic QMS foundation. Plan-Do-Check-Act, customer focus, risk-based thinking, leadership, continual improvement. The non-regulated baseline that every other QMS layers on.
ISO 13485:2016.
Medical-device QMS. Notified-body baseline for EU MDR / IVDR. Now the foundation FDA's QMSR harmonises against, effective 2 February 2026.
ICH Q10 · PQS.
Pharmaceutical Quality System (2008). Adds product lifecycle, management responsibility, knowledge management to the ISO 9001 baseline. The standard a pharma sponsor's PQS is graded against.
ICH Q9(R1) 2023.★
Quality Risk Management. R1 (Jan 2023) added subjectivity-management, knowledge-base risk, and digitalisation. The most-cited ICH document in 2024-2026 inspections.
ICH Q12 · lifecycle.
Lifecycle management for established conditions and post-approval changes. Step 4 in November 2019. Implementation uneven across regions through 2026.
21 CFR 820 / QMSR.★
FDA medical-device QMS rule. Final rule Feb 2024; effective 2 February 2026. Harmonises with ISO 13485:2016 by reference, retains FDA-specific overlays.
21 CFR Part 11.
Electronic records, electronic signatures (1997). Audit trail, attribution, identification, validation. The data-integrity floor — ALCOA+ derives from §11 read across regulators.
EU Annex 11.
Computerised systems · EU GMP Volume 4. Companion to Part 11 in EU jurisdictions. Annex 22 (AI-specific) currently in finalisation alongside the Annex 11 revision.
ISO/IEC 42001:2023.★
AI management system (Dec 2023). The first international standard for governance of AI. The AI-equivalent of ISO 9001. Layers onto the existing QMS, not a replacement.
GAMP 5 2nd ed.
Validation lifecycle for computerised systems. ISPE GAMP 5 (2nd edition 2022) added critical-thinking, agile, AI/ML appendices. Industry-best-practice anchor for Part 11 / Annex 11 implementation.