Verification and Validation (V&V) is the paired process that confirms a medical device is built correctly and that it meets its intended use. Verification checks that design outputs meet design inputs; validation confirms the finished device satisfies user needs and real use conditions. Both are required under ISO 13485 and FDA design controls.
What is Verification and Validation (V&V)?
Verification and Validation (V&V) are two distinct but linked activities inside the design controls process. Verification answers a narrow question: do the design outputs meet the design inputs? Validation answers a broader one: does the resulting device meet the needs of the user and the intended clinical use? A device can pass every dimensional and electrical check (verification) and still fail in use if it was never validated against real conditions (validation).
V&V sits in the middle-to-late phase of the device lifecycle, after design inputs are locked and before design transfer to manufacturing. It produces the objective evidence that regulators and auditors expect to see in the design history file.
Why Verification and Validation (V&V) matters in medical device development
The stakes are patient safety and market access, not just documentation. A design defect that escapes verification can reach production and, in a Class II or III device, cause harm before it is caught. Validation gaps are a frequent root cause in field failures and recalls because a device can be technically correct yet unusable or unsafe in context.
Regulators treat V&V as core evidence. FDA investigators and notified body auditors examine V&V records first, since weak evidence signals a design controls process that is not in control. Rework late in development is also expensive: a requirement that was never verifiable, caught during validation, can force a redesign that costs months. Good V&V front-loads that risk instead of paying for it after design transfer.
How Verification and Validation (V&V) works
V&V runs against a documented set of design inputs and a risk analysis, with every result traceable back to a requirement. The governing clauses are ISO 13485:2016, Section 7.3.6 (design and development verification) and Section 7.3.7 (design and development validation), which are now incorporated by reference into 21 CFR Part 820 following the FDA Quality Management System Regulation that took effect on February 2, 2026. EU MDR 2017/745 requires the same evidence in Annex II technical documentation as in Annex I general safety and performance requirements.
The work typically breaks down like this:
- Plan against requirements. Each design input becomes a verifiable, testable statement with an acceptance criterion. Requirements that cannot be tested are rewritten before any bench work starts.
- Verify design outputs. Confirm outputs meet inputs using inspection, test, analysis, or demonstration. Examples include dimensional inspection, electrical safety testing to IEC 60601-1, electromagnetic compatibility to IEC 60601-1-2, biocompatibility per the ISO 10993 series, and software verification under IEC 62304.
- Validate the finished device. Confirm the device meets user needs under actual or simulated use conditions, including human factors and usability engineering per IEC 62366-1, on production-equivalent units.
- Trace and link to risk. Map every V&V result to its requirement and to the risk controls defined under ISO 14971, so risk mitigations are shown to be effective.
One distinction trips teams up: design validation is not process validation. Process validation (IQ, OQ, PQ) confirms that manufacturing can reliably produce the device, and it belongs to the transfer and production stage rather than to design V&V.
Common challenges and best practices
The most common failure is vague design inputs. If a requirement says a device should be “easy to clean,” verification has nothing objective to test against, and the gap surfaces only during validation when it is costly to fix. Write inputs as measurable statements from the start.
Teams also confuse the two activities. Verification uses bench methods against engineering specs; validation uses production-equivalent units and real users against intended use. Running a validation with an early prototype produces evidence that an auditor will reject.
Weak traceability is the third recurring problem. When results are not linked to requirements and risk controls, reviewers cannot confirm coverage, and one requirement change forces a manual hunt through disconnected reports. A maintained traceability matrix connecting inputs, outputs, V&V evidence, and ISO 14971 risk controls is what good practice looks like, and it shortens audits.
How SJML helps with Verification and Validation (V&V)
SJML runs V&V as part of its end-to-end design and engineering service, carrying programs from concept and feasibility through architecture, design, verification, and design transfer. Risk management to ISO 14971 and usability engineering to IEC 62366-1 are built into the workflow rather than bolted on. In-house labs support electrical safety testing to IEC 60601, EMC, reliability, and environmental and endurance testing, so verification evidence is generated under one roof. Phase-gate program management with structured change control keeps requirements, outputs, and V&V results traceable across the build.
Talk to SJML’s engineering team →
Frequently asked questions
Verification confirms that design outputs meet design inputs, using bench methods like inspection, test, or analysis against engineering specifications. Validation confirms that the finished device meets user needs and intended use, tested on production-equivalent units under real or simulated conditions. Verification asks whether the device was built to spec; validation asks whether it is the right device for its users.
The primary standard is ISO 13485:2016, with design verification in Section 7.3.6 and design validation in Section 7.3.7. These are incorporated by reference into FDA 21 CFR Part 820 under the Quality Management System Regulation effective February 2, 2026. EU MDR 2017/745 requires equivalent evidence, and product standards such as IEC 60601-1, IEC 62304, and IEC 62366-1 define specific test requirements.
No. Design validation confirms the device meets user needs and intended use, and it belongs to the design controls phase. Process validation (IQ, OQ, PQ) confirms that a manufacturing process can consistently produce conforming devices, and it belongs to design transfer and production. Both are required, but they answer different questions at different lifecycle stages.
Verification begins once design inputs are defined, and design outputs exist to test against them. Validation follows, on production-equivalent units, before the device is released to full production. V&V precedes design transfer, so that design defects are caught before manufacturing scales. Results feed the design history file and the technical documentation reviewed by regulators.
Related terms
- Design Verification
- Design Validation
- Design Controls
- Design History File (DHF)
- Process Validation (IQ/OQ/PQ)