Nonconformity vs Deviation vs OOS Under ISO 13485, 21 CFR 820 and EU MDR 2017/745
- 5 minutes ago
- 9 min read
A failed inspection result, a missed process step, and a temporary change to an approved procedure can look similar on the shop floor. In a medical device quality management system, they are not the same thing.
The words nonconformity, deviation, and OOS are often used together, sometimes even interchangeably. That creates problems. The wrong classification can lead to weak investigations, poor CAPA decisions, delayed batch release, audit findings, or regulatory exposure.
This guide explains what each term means, how ISO 13485, 21 CFR 820, and EU MDR 2017/745 treat them, and how to decide which bucket an event belongs in. This is general regulatory and quality system information, not legal advice.

The three terms mean different things
What is a nonconformity
A nonconformity is the non-fulfilment of a requirement.
That requirement may come from:
A product specification
A drawing
A validated process parameter
A work instruction
A regulatory requirement
A customer requirement
An internal QMS procedure
A risk control requirement
In medical device manufacturing, a nonconformity can relate to product, process, documentation, supplier controls, training, labelling, packaging, sterilisation, or post-market activities.
Examples include:
A device dimension is outside the approved drawing tolerance.
A production record is missing a required verification step.
A supplier provides material without the agreed certificate.
A packaging seal test fails acceptance criteria.
A complaint investigation was not completed as required by procedure.
The key point is simple: a requirement exists, and it was not met.
What is a deviation
A deviation is a departure from an approved requirement, process, instruction, or specification.
In many medical device companies, deviations are managed in two main ways.
A planned deviation is approved before the departure happens. For example, a company may approve the use of an alternative inspection method for one lot because the usual equipment is temporarily unavailable. This needs documented justification, risk assessment, approval, and defined limits.
An unplanned deviation is discovered after something has already gone wrong or gone differently from the approved process. For example, an operator used the wrong curing time by mistake. In practice, an unplanned deviation often becomes, or triggers, a nonconformity investigation.
The important difference is that deviation is about departure from the approved way of working. It does not always mean the product is defective, but it always needs evaluation.
What is OOS
OOS means Out of Specification.
It usually refers to a test, inspection, or measurement result that falls outside a pre-defined acceptance criterion. The term is more common in pharmaceutical and laboratory environments, but medical device companies also use it, especially for testing, incoming inspection, stability studies, biocompatibility support testing, environmental monitoring, packaging validation, and sterilisation-related checks.
Examples include:
Tensile strength is below the approved minimum.
Bioburden result exceeds the internal alert or action limit.
A packaging seal strength result is outside acceptance criteria.
A device output reading fails the approved test limit.
A raw material property result does not meet the purchasing specification.
An OOS result is usually a type of nonconformity because a specification was not met. It may also reveal a deviation if the investigation shows the test method or process was not followed correctly.
The simplest way to separate them
Use this practical logic.
Term | Main question | Typical scope | Usual outcome |
Nonconformity | Was a requirement not met? | Product, process, QMS, supplier, regulatory controls | Correction, segregation, disposition, investigation, possible CAPA |
Deviation | Did we depart from an approved process or instruction? | Process execution, temporary changes, procedural departures | Risk assessment, approval, impact review, possible nonconformance |
OOS | Did a result fall outside an approved specification? | Test, inspection, measurement, lab result | Laboratory or technical investigation, product impact decision, possible nonconformance |
A simple example makes it clearer.
A catheter shaft has an approved outer diameter of 2.00 mm to 2.10 mm. Inspection shows one unit at 2.16 mm.
That is an OOS result because the measurement is outside specification. It is also a nonconformity because the product requirement was not met. If the investigation finds that the extrusion temperature was set outside the approved range, that process departure is a deviation.
One event can carry more than one label. The labels should help the investigation, not replace it.

How ISO 13485 treats nonconformity, deviation, and OOS
ISO 13485 is built around documented controls, risk-based thinking, and evidence that the quality management system works as intended.
The standard directly addresses nonconforming product in clause 8.3. It requires the organisation to identify and control product that does not conform to requirements. The aim is to prevent unintended use or delivery.
Under ISO 13485, controls normally include:
Identification of the nonconforming product
Documentation of the issue
Evaluation of the nonconformity
Segregation or control to prevent unintended use
Defined disposition
Records of the nonconformity and action taken
Re-verification after correction, where needed
Action if nonconforming product is detected after delivery
Disposition may include rework, acceptance under concession where permitted, rejection, scrap, return to supplier, or other justified decisions.
ISO 13485 also connects nonconformities to corrective action. Clause 8.5.2 requires action to eliminate the cause of nonconformities so they do not recur. Not every nonconformity needs a full CAPA, but the organisation must define when escalation is needed.
ISO 13485 does not heavily use the word deviation as a central term. Most companies handle deviations through procedures for production control, process validation, document control, risk management, and nonconforming product control.
The same applies to OOS. ISO 13485 does not set out a detailed OOS investigation model like pharmaceutical guidance often does. In a device QMS, an OOS test result is usually managed through inspection and test controls, nonconforming product procedures, and CAPA when required.
How 21 CFR 820 treats these terms
21 CFR 820 is the US Quality System Regulation for medical devices. The FDA issued a final rule to align Part 820 more closely with ISO 13485 through the Quality Management System Regulation, with the transition set around 2 February 2026. Many device companies still map their procedures to the familiar Part 820 clauses because those clauses shaped QMS practice for years.
Under the traditional 21 CFR 820 structure, 820.90 deals with nonconforming product. It requires manufacturers to establish and maintain procedures to control product that does not conform to specified requirements.
Those procedures must address:
Identification
Documentation
Evaluation
Segregation
Disposition
The evaluation must include a decision on whether an investigation is needed. It must also include notification of the people or functions responsible for the nonconformity.
Disposition must be documented. If product is accepted with a concession, the justification and approval should be clear. If rework is performed, the company must document the rework and re-evaluate the product to confirm it meets requirements.
21 CFR 820 also links these events to other subsystems.
Acceptance activities under 820.80 help detect failures. Production and process controls under 820.70 help prevent them. CAPA under 820.100 requires investigation of causes of nonconforming product and other quality problems. Complaint handling under 820.198 may become relevant if the issue is detected after distribution.
The term deviation is not the main regulatory label in Part 820, but FDA investigators commonly expect firms to control temporary or unplanned departures from approved procedures. A deviation without proper approval, rationale, and product impact assessment can become evidence of poor process control.
The term OOS is also not a core Part 820 heading. Still, if a test result fails the specification, the QMS must treat it as a quality issue. The firm should investigate whether the result is due to product failure, process failure, test method error, equipment issue, sampling issue, or operator error.

How EU MDR 2017/745 treats these terms
EU MDR 2017/745 takes a broader regulatory view. It focuses on conformity with the regulation, General Safety and Performance Requirements, technical documentation, clinical evaluation, post-market surveillance, vigilance, and the manufacturer’s quality management system.
The MDR does not use nonconformity, deviation, and OOS in the same operational way as a factory procedure. Instead, it expects the manufacturer to maintain a QMS capable of ensuring that devices remain in conformity with the regulation.
Article 10 is central for manufacturers. It requires a quality management system covering areas such as regulatory compliance strategy, design, manufacturing, supplier control, risk management, clinical evaluation, post-market surveillance, vigilance, and corrective and preventive actions.
If a manufacturer believes a device placed on the market is not in conformity with the MDR, the manufacturer must take corrective action as needed. This can include bringing the device into conformity, withdrawal, or recall. Where the device presents a serious risk, competent authorities must be informed.
The MDR also places strong emphasis on:
GSPR conformity
The device must meet the applicable General Safety and Performance Requirements in Annex I.
Technical documentation
Records must support conformity. A documentation gap can become a serious issue even when the product appears physically acceptable.
Post-market surveillance
Field data, complaints, trends, and feedback must feed into the QMS.
Vigilance
Serious incidents and field safety corrective actions have specific reporting duties.
In EU MDR practice, an OOS result may be more than a batch release problem. If it affects safety, performance, sterile barrier integrity, labelling, or clinical claims, it can affect MDR conformity. A deviation may also affect conformity if it changes a validated process, a critical supplier control, or a risk control measure.
The key differences across ISO 13485, 21 CFR 820, and EU MDR
The three frameworks overlap, but they do not look at the issue from exactly the same angle.
Framework | Main focus | How it sees nonconformity | How it sees deviation | How it sees OOS |
ISO 13485 | QMS requirements for medical devices | Directly controlled through nonconforming product and CAPA processes | Usually handled through QMS procedures, change control, process control, and risk assessment | Usually treated as evidence of possible nonconforming product or process failure |
21 CFR 820 | US device quality system requirements | Explicit control of nonconforming product, with documentation and disposition | Not a central defined term, but expected to be controlled as part of process and document control | Not a central heading, but failed acceptance results must be investigated and controlled |
EU MDR 2017/745 | Legal conformity of devices in the EU market | Seen in relation to device conformity, QMS, GSPR, PMS, vigilance, and corrective action | Important when it affects validated processes, safety, performance, or regulatory compliance | Important when it affects specifications linked to safety, performance, release, or conformity evidence |
ISO 13485 and 21 CFR 820 are more QMS-operational. EU MDR is more market and regulatory conformity-focused. A well-designed QMS connects all three.
How to classify an event correctly
Start with facts, not labels. Ask these questions in order.
Was there an approved requirement
If there was no approved requirement, specification, instruction, or acceptance criterion, it may not be a nonconformity in the strict sense. It may be a gap in the QMS, which can still need correction.
If a requirement exists and was not met, record a nonconformity.
Was there a test result outside limits
If a measured result is outside an approved limit, open an OOS investigation or record it under the company’s equivalent procedure.
Then decide whether the OOS is valid. Check sample identity, equipment calibration, test method execution, calculation, environmental conditions, and data integrity. If the OOS is confirmed, assess product impact and disposition.
Was the approved process not followed
If the process, instruction, parameter, or sequence was not followed, treat it as a deviation.
For a planned deviation, confirm prior approval, defined scope, risk assessment, and expiry or quantity limit.
For an unplanned deviation, assess whether it caused or could cause nonconforming product.
Is there safety, performance, or regulatory impact
This is where MDR thinking becomes especially important. Ask whether the event affects:
Intended purpose
Essential design outputs
Risk controls
Sterile barrier
Labelling or IFU
Clinical performance claims
Released product
Fielded devices
Complaint or vigilance reporting duties
If the answer is yes, escalation is usually needed.

Common mistakes auditors notice
Auditors and regulators often notice the same weak points.
One common mistake is treating deviation approval as permission to ignore risk. A deviation needs justification, defined limits, and impact assessment. It should not become a routine workaround for a broken process.
Another mistake is closing an OOS investigation as “operator error” without evidence. If the conclusion names people but does not explain the technical cause, the issue may return.
A third mistake is failing to connect repeat nonconformities. Three small events from the same process may point to one larger systemic problem.
Poor disposition records are also common. “Use as is” decisions need authority, rationale, and evidence that safety and performance are not affected. For regulated devices, convenience is not a valid justification.
Companies also get into trouble when post-release issues stay inside production records and never reach complaint, PMS, vigilance, or regulatory assessment processes.
A practical QMS approach that works
A clear procedure can keep the system simple.
Use nonconformity as the broad quality event category when a requirement is not met.
Use deviation for departures from approved procedures, methods, process parameters, or temporary planned changes.
Use OOS for failed test or measurement results against approved specifications.
Then define how these records interact. For example:
An OOS result automatically triggers product impact assessment.
A confirmed OOS becomes a nonconformity unless invalidated with evidence.
An unplanned deviation requires assessment for possible nonconforming product.
A planned deviation must be approved before use.
Repeated deviations or nonconformities are reviewed for CAPA.
Any released product impact is screened for complaint, PMS, vigilance, and field action requirements.
The best systems do not create paperwork for its own sake. They create traceability from event to risk assessment, decision, action, and effectiveness check.
The takeaway
Nonconformity, deviation, and OOS are connected, but each answers a different question.
A nonconformity means a requirement was not met. A deviation means the approved way of working was not followed or was temporarily changed. An OOS means a result failed an approved specification.
Under ISO 13485 and 21 CFR 820, the focus is strong operational control through identification, documentation, evaluation, disposition, and CAPA where needed. Under EU MDR 2017/745, the focus widens to legal device conformity, safety and performance, technical documentation, post-market surveillance, vigilance, and corrective action.
Classify the event correctly, but do not stop there. The real goal is to understand impact, protect users and patients, make a justified product decision, and prevent recurrence where the risk calls for it.




Comments