# Three steps for traceability in medical device software development quality and compliance

Paul Jones

and

Medical Design and Outsourcing

September 7, 2023

[Traceability](https://www.ketryx.com/learn/blog?tag=traceability)

## Table of Contents

[Section link](https://www.ketryx.com/blog/three-steps-for-traceability-in-medical-device-software-development-quality-and-compliance#)

[_This article originally appeared in Medical Design and Outsourcing News on September 7, 2024._](https://www.medicaldesignandoutsourcing.com/traceability-device-software-development-quality-compliance/)

When reviewing the software in software-as-a-medical-device (SaMD), software-in-medical-devices (SiMD) and systems-of-systems-of-medical-devices (SosMD) at the FDA, I was always looking for sufficient evidence to justify the sponsor’s claim that the device performs as intended — safely and effectively.

The arguments to support this claim are derived from the manufacturers’ quality management system (QMS) quality assurance, design controls, and corrective and preventative action (CAPA) process artifacts, which include device distribution, post-market monitoring, and updates.

The concept of traceability between these artifacts was essential to establishing my confidence in a submission’s claimed safety and effectiveness. To understand why this is, you must first understand how a software (or most any product) application is created.

[Read the full article](https://www.medicaldesignandoutsourcing.com/traceability-device-software-development-quality-compliance/)

### Interview transcript

Paul Jones

VP of Regulatory Strategy

Ketryx

Paul is a world-renowned software safety expert who joined Ketryx following 25 years at the Food and Drug Administration (FDA). He helped create the FDA’s approach to safety-critical software and medical devices and founded the FDA’s software engineering lab. While holding committee positions with groups that handled medical software safety standards like ISO 13485, ISO/IEC 62304, and ISO 14971, he reviewed over 300 devices, carried out numerous inspections, and provided training to FDA staff on software quality, risk management, and software engineering. Prior to the FDA, he worked 20 years as a systems/software engineer for companies like Ford Motor, Electronic Data Systems, Honeywell, and SAIC. He holds a Master of Science degree in Computer Engineering from Loyola University, Maryland.

‍

### Explore Our Top Blog Posts

\\
\\
Traceability\\
**Why Change Impact Assessment Is the Hidden Bottleneck in Medical Device Development**\\
\\
Megan Mannino\\
\\
and \\
\\
•  \\
\\
February 19, 2026](https://www.ketryx.com/blog/change-impact-assessment-bottleneck)

.svg).svg)\\
\\
Product Updates\\
**Ketryx’s New Integration with Azure DevOps (ADO): End-to-End Traceability for Regulated Teams**\\
\\
Milan Dzenovljanovic\\
\\
and \\
\\
•  \\
\\
March 20, 2025](https://www.ketryx.com/blog/ado-integration)

\\
\\
Academy\\
**How to Create a Design History File (DHF) for Medical Devices**\\
\\
Lee Chickering\\
\\
and \\
\\
•  \\
\\
January 15, 2025](https://www.ketryx.com/blog/how-to-create-a-design-history-file-dhf-for-medical-devices)
