QAtrial v3.0 is the largest release since the project’s initial launch. It adds Design Control with a Kanban workflow, ISO 13485:2016 gap assessment, a Workflow Engine, Notification Center, Custom Fields, AI Requirements Extraction, improved LLM provider settings, and QMSR-specific gap analysis. This article covers what shipped, why each feature matters, and what is coming next.
Get business pricing on monitors, keyboards and dev gear
- Business-only prices and quantity discounts
- Tax-exempt purchasing
- Multiple users, one account, clear invoices
Version 3.0
| Preset | Default Model | Temperature | Max Tokens | API Key | Data |
|---|---|---|---|---|---|
| 🟠 Anthropic | claude-sonnet-4-20250514 | 0.2 | 4096 | Required | Cloud |
| 🟢 OpenAI | gpt-4.1 | 0.2 | 4096 | Required | Cloud |
| 🔵 OpenRouter | anthropic/claude-sonnet-4 | 0.2 | 4096 | Required | Cloud |
| 🦙 Ollama (Local) | llama3.1:8b | 0.3 | 2048 | Not required | Local |
| 🖥️ LM Studio (Local) | local-model | 0.3 | 2048 | Not required | Local |
Context: Why These Features, Why Now
Three regulatory developments shaped the v3.0 feature set:
FDA QMSR (effective February 2, 2026). The FDA’s Quality Management System Regulation replaces the decades-old 21 CFR 820 (Quality System Regulation) with a new framework that incorporates ISO 13485:2016 by reference. Every FDA-regulated medical device manufacturer must transition their quality system. This creates urgent demand for tools that support ISO 13485 gap assessment and design control workflows.
EU AI Act (high-risk devices deadline August 2, 2027). AI used in medical devices classified as high-risk must meet transparency, data governance, and bias documentation requirements. Quality tools themselves are not directly affected, but the AI capabilities within quality tools must be documented and transparent.
ICH E6(R3) (adopted 2025). The updated Good Clinical Practice guideline enables decentralized trials and risk-based quality management, changing how CROs and sponsors manage clinical quality.
QAtrial v3.0 focuses on the most immediate of these: the QMSR transition. Medical device companies need ISO 13485 gap assessment, design control workflows, and configurable approval processes now, not in two years.
As an affiliate, we earn on qualifying purchases.
Design Control Kanban
What It Is
A new Design Control tab in the main navigation presents a Kanban board with seven phases:
- User Needs — what the user requires from the device
- Design Input — specific, measurable requirements derived from user needs
- Design Output — the design documents, specifications, and drawings that fulfill design inputs
- Verification — confirmation that design outputs meet design inputs
- Validation — confirmation that the device meets user needs under actual use conditions
- Transfer — handoff to manufacturing with production specifications
- Released — the design is complete and under change control
Each phase displays cards showing the design item’s title, status badge (draft, in_review, approved, rejected), linked requirement count, and linked test count.
Gated Advancement
The critical feature is gated phase advancement. A design item can only move to the next phase when its current phase status is “approved.” This prevents the common failure mode where design items advance through phases without formal review, creating compliance gaps that surface during audits.
The gate enforcement is structural, not procedural. The “Advance to Next Phase” button is only available for approved items. You cannot work around it by editing status fields directly.
DHF, DMR, and DHR
Design Control includes document record containers:
- Design History File (DHF): Contains the complete design history for a device, including all records generated during the design process
- Device Master Record (DMR): Contains the procedures and specifications for a finished device
- Device History Record (DHR): Contains the production record for each unit or batch
Each container supports version control, section management, and linking to design items and requirements. Status lifecycle: draft, active, superseded, obsolete.
Why It Matters
ISO 13485 Section 7.3 and the FDA QMSR require formal design controls for medical devices. Design control findings are among the most common FDA audit observations. Having the design control workflow integrated with requirements, tests, and the audit trail in the same tool means the traceability chain from user need to released design is continuous and documented.
medical device design control workflow tool
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
ISO 13485:2016 Gap Assessment
Two Modes
The ISO 13485 gap assessment evaluates your project against all 27 clauses of ISO 13485:2016 (Sections 4.1 through 8.5).
Keyword Match mode works without any AI provider. It matches your requirement titles and descriptions against curated keyword lists for each clause. Scoring: two or more matched requirements equals “covered,” one match equals “partial,” zero matches equals “gap.” This mode is deterministic and always available.
AI Analysis mode sends your requirements to the configured LLM for semantic analysis against clause intent. It returns evidence (which requirements address each clause) and recommendations (what is missing). This mode catches requirements that address a clause without using the specific keywords.
The Assessment View
The assessment displays:
- Readiness score: 0-100% with a stacked progress bar (green for covered, yellow for partial, red for gaps)
- Summary statistics: counts of covered, partial, and gap clauses
- Section accordions: clauses organized by ISO 13485 major sections (Quality Management System, Management Responsibility, Resource Management, Product Realization, Measurement and Improvement)
- Per-clause detail: status icon, clause number and title, description, criticality badge (critical, high, medium, low), matched requirement IDs as clickable tags
- Gap remediation: a “+ Req” button on each gap or partial clause that auto-generates a requirement with the correct ISO 13485 regulatory reference, appropriate risk level, and relevant tags
The Clause Registry
The foundation is a curated registry of 27 ISO 13485:2016 clauses (src/lib/iso13485Clauses.ts), each with clause number, title, section grouping, description, keywords for static matching, and criticality level. Critical clauses include 4.1 (QMS General Requirements), 4.2.3 (Medical Device File), 7.3 (Design and Development), 7.5 (Production and Service Provision), 8.2 (Monitoring and Measurement), 8.3 (Control of Nonconforming Product), and 8.5 (Improvement/CAPA).
QMSR Context
The FDA QMSR incorporates ISO 13485:2016 by reference, meaning US medical device manufacturers must now comply with ISO 13485 where they previously complied with 21 CFR 820. The gap assessment tool directly supports this transition by showing which ISO 13485 clauses your existing quality system covers and where gaps exist.
QMSR compliance management software
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Workflow Engine
Configurable Approval Workflows
The workflow engine supports multi-step approval routing with:
- Workflow definitions: name, trigger type (on_status_change, on_create, on_edit, manual), entity type, and ordered steps
- Step configuration: type (approval, review, sign, notify, auto_check), assignee role, required number of approvers, SLA hours, and escalation rules
- Workflow instances: track current step, approvals received, and status (active, completed, cancelled, escalated)
Default Workflows
Two workflows ship out of the box:
- Requirement Approval: Three steps — Review (one approver) then Approve (one approver) then Sign (one signer)
- Design Gate Review: Three steps — Review (one reviewer) then Approve (two approvers required) then Sign (one signer)
The two-approver design gate review reflects the regulatory expectation that design phase transitions require multiple independent approvals, particularly in pharmaceutical and medical device contexts.
Multi-Approver Logic
Steps can require multiple approvers. The workflow automatically advances to the next step when the required number of approvals is reached. If any approver rejects, the workflow is cancelled. This logic handles the common regulated-industry requirement for consensus-based quality decisions.
AI requirements extraction for medical devices
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Notification Center
A bell icon in the header toolbar shows an unread count badge. Clicking it opens a dropdown with up to 20 recent notifications.
Notification types include: approval_needed, task_overdue, capa_deadline, workflow_escalation, audit_reminder, status_change, and mention. Each notification displays a type-specific icon, title, message, timestamp, and read/unread indicator.
A “Mark all read” button clears the unread state. Notifications integrate with the workflow engine: when a workflow step requires your approval, you receive a notification.
Custom Fields
Users can define custom metadata fields on requirements, tests, CAPA records, and design items. Supported field types: text, number, date, select, multi_select, boolean, and URL. Fields can be marked as required or optional, with default values and select options.
This addresses one of the most frequent requests in quality management tools: the ability to add organization-specific metadata without modifying the core schema. A device company might add a “Product Family” select field to requirements. A pharmaceutical company might add a “Batch Number” text field to test records.
AI Requirements Extraction
A new AI prompt allows you to paste regulatory text (a QMSR paragraph, an MDR Annex I clause, a section of ISO 14971) and have the AI extract individual, testable requirements. Each extracted requirement includes a title, description, regulatory reference, and risk level.
This feature targets the labor-intensive process of decomposing regulations into actionable requirements. A single paragraph of regulatory text might contain three or four distinct requirements that need to be tracked and tested separately. The AI handles the decomposition; you review and accept the results.
LLM Provider Settings
Five Presets
Provider configuration now uses one-click presets:
| Preset | Default Model | Temperature | API Key |
|---|---|---|---|
| Anthropic | claude-sonnet-4-20250514 | 0.2 | Required |
| OpenAI | gpt-4.1 | 0.2 | Required |
| OpenRouter | anthropic/claude-sonnet-4 | 0.2 | Required |
| Ollama (Local) | llama3.1:8b | 0.3 | Not required |
| LM Studio (Local) | local-model | 0.3 | Not required |
Model Dropdowns
Each preset provides a dropdown of available models instead of requiring you to type model names. Anthropic shows Claude Sonnet, Opus, and Haiku variants. OpenAI shows GPT-4.1, GPT-4o, and o3-mini variants. OpenRouter shows models from Anthropic, OpenAI, Google, Meta, DeepSeek, and Qwen. Ollama shows common local models.
Smart Defaults
Cloud providers default to lower temperature (0.2) and higher token limits (4096) for regulatory precision. Local providers default to slightly higher temperature (0.3) and lower token limits (2048) to accommodate smaller models. The API Key field shows “Not required” for Ollama and LM Studio.
What Is Coming Next
The roadmap has three planned releases after v3.0:
v3.1 — Enterprise Collaboration. Real-time collaboration (WebSocket-based live editing), multi-site dashboard, supplier quality portal, electronic batch records, REST/GraphQL API, and webhook/event streaming. This release targets multi-site pharmaceutical and biotech operations.
v3.2 — Clinical and AI Intelligence. Electronic Trial Master File (eTMF), eConsent workflow, AI audit preparation assistant, predictive quality analytics, change impact predictor, and regulatory change monitor. This release targets CROs and organizations wanting deeper AI capabilities.
v3.3 — Global Expansion. Country-specific features for Brazil, Australia, Saudi Arabia, Switzerland, Singapore, Israel, India, and UAE/GCC. New verticals: IVD (IVDR), combination products, ATMP (advanced therapy), digital health/SaMD, automotive safety (ISO 26262), and food safety (FSMA/HACCP). Plus eCTD submission builder, data residency for multi-region deployment, and offline PWA mode.
Upgrading to v3.0
If you are running an earlier version of QAtrial:
cd QAtrial
git pull origin main
npm install
npm run dev
Existing project data in localStorage is compatible with v3.0. New features (Design Control, Custom Fields, Workflows, Notifications) initialize with empty stores and become available immediately.
The new ISO 13485 assessment and QMSR gap analysis tools work with your existing requirements. Run a keyword-mode assessment first to see your baseline coverage, then configure an AI provider for deeper analysis.
The Bigger Picture
QAtrial v3.0 is specifically shaped by the QMSR transition. Medical device companies have a concrete deadline (February 2026) and a concrete need (demonstrate ISO 13485 compliance where they previously demonstrated 21 CFR 820 compliance). The design control Kanban, ISO 13485 gap assessment, workflow engine, and AI-assisted requirement extraction address that need directly.
But the features are not device-specific. The workflow engine serves pharmaceutical approval processes. The custom fields serve any organization with unique metadata needs. The notification center serves any team that needs to stay aware of pending quality actions. The LLM presets serve anyone who wants to use AI for quality work, whether in the cloud or entirely on their own hardware.
Version 3.0 marks the point where QAtrial moves from a capable requirements and test management tool to a regulated quality workspace that addresses the full scope of what quality teams actually need to manage.
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
