There is a point in almost every medical-device startup when the quality management system stops being something the team can tolerate and becomes something the company must actively control.
In the beginning, paper can work. Shared drives can work. A few spreadsheets can work. Everyone knows where the current procedure lives, who wrote it and who needs to approve it.
It is not elegant, but the team is small and the system is familiar.
Then the company grows. More people need training. More documents need review. Projects create actions. Someone opens a CAPA. Someone else revises a procedure. AI tools begin appearing in everyday work. An auditor asks for evidence from six months ago.
At the same time, regulatory expectations become immediate. The EU MDR is no longer a distant milestone, and FDA’s Quality Management System Regulation (QMSR) has been effective since 2 February 2026.
The problem is not necessarily that the company has a bad QMS. The problem is that the QMS can no longer depend on a few people remembering where everything is and what should happen next.
The all-or-nothing implementation trap
This is where many startups and SMEs make one of two mistakes.
They keep stretching a paper-and-spreadsheet system because replacing it looks expensive and disruptive. Or regulatory pressure finally forces the decision, and they move too far in the opposite direction: buying an enterprise eQMS and trying to digitise everything at once.
Now the company has another problem: a large implementation programme competing with the work the QMS is supposed to support.
qmsWrapper Foundation was designed around a different principle:
Start with what the company can realistically implement today. Put the fundamentals under control. Begin using them. Then build from there.
Foundation is the first of three connected qmsWrapper levels:
Foundation → Lifecycle → Vigilance
Each level builds on the previous one. Work established in Foundation is not discarded when the company adds Lifecycle. Lifecycle is not a replacement system, and Vigilance is not another migration. The capability of the same QMS expands as the organisation’s needs become more complex.
A lower-risk way to begin
For an SME, choosing an eQMS is not only a software purchase. The licence matters, but so do implementation time, training, disruption and the risk of choosing a system that the team cannot realistically adopt.
A company should not have to buy the QMS it may need three years from now before it can solve the problems it has today.
Foundation lowers that barrier by giving the organisation a controlled starting point. The team can implement the essentials, prove that the system works in daily practice and add connected lifecycle capability when the need becomes real.
The principle is simple: start smaller, reduce implementation risk, create value and expand without rebuilding the QMS.
What Foundation is meant to establish
Foundation should not be understood as a collection of modules. Its purpose is to establish the controlled objects and habits that a connected QMS will later depend on.
- A defined QMS structure, including the QMS Manual and organisational responsibilities
- Controlled documents, forms, reviews, approvals and electronic signatures
- Training records connected to people and current information
- Projects and tasks with visible ownership and deadlines
- A controlled CAPA Log and EU AI Compliance Log
- Process Builder and Form Builder for gradual workflow digitisation
- Storage and built-in AI assistance with visible human review
- Controlled MCP connectivity for Storage, Tasks and Projects, subject to permissions and human oversight
The question is therefore not only, ‘Which features are included?’ A more useful implementation question is: ‘What should we put under control first?’
Start with the rules: the QMS Manual
Before automating a process, the organisation must know what the process is supposed to be.
- Who reviews and approves controlled documents?
- How is training assigned and recorded?
- How is a CAPA initiated and controlled?
- Who has authority to approve a change?
- Which procedures apply to each activity?
The QMS Manual provides that structure. For a company moving from paper, Word files or shared folders, the first implementation step does not have to be a complete process redesign.
Bring the current QMS structure into a controlled environment. Confirm responsibilities. Identify current documents, missing records and items that require review. The whole company has not been transformed, but something important has changed: the QMS now has a controlled home.
Make sure people know the rules: training
A controlled procedure has limited value if the people affected by it do not know that it changed. Training is therefore not an advanced capability to add later. It is part of what makes the QMS operational.
Procedure → Person → Training → Evidence

For a small company, this does not require an enterprise learning-management programme. It requires a controlled way to assign and track the training that matters.
A revised procedure should not depend on someone remembering to email three engineers. A new employee should not require Quality to search a spreadsheet to determine which procedures apply. Foundation helps the company establish those habits while the team is still small enough to make them normal.
This also prepares the organisation for Lifecycle. A future quality event or controlled change may result in retraining, but that consequence can only be followed consistently if a controlled training system already exists.
AI governance also begins at the foundation
AI governance can sound like a concern for a mature organisation. In practice, companies are already using AI to improve drafts, search information, prepare content, review documents or support technical work.
The organisation may not think it has an AI programme, but AI may already be part of its operating environment.
The first sensible control is not an enormous governance project. It is knowing:
- Which AI tools are being used
- Where and why they are being used
- Who is responsible for the activity
- What information and records are involved
- What human review and approval apply
That is why the EU AI Compliance Log belongs at the Foundation level. More sophisticated controls can grow as the organisation and its AI use mature, but accountability must begin at the start.
The operating principle remains clear: AI can assist. Humans review, decide and remain accountable.
Turn procedures into controlled work
Moving documents into electronic storage is not the same as implementing an electronic QMS.
The QMS Manual describes how the organisation should operate. Process Builder helps translate that logic into repeatable work. Form Builder helps capture what happened as a structured record.
The company does not have to convert every process at once. Start with one process that causes unnecessary administration: document approval, employee onboarding, CAPA intake or another frequently used quality activity.
- Build the process the team actually needs.
- Create the controlled form or record.
- Run it with real users.
- Improve it based on experience.
- Then move to the next process.
Instead of spending months configuring a perfect future system before anyone receives value, the QMS becomes useful while it is being implemented.
The everyday QMS still has to work
Quality management is not only made up of major lifecycle processes. Documents need updating. CAPAs need recording. Projects need managing. Tasks need owners. Approvals and deadlines need visibility.
Foundation includes these practical capabilities because an electronic QMS cannot sit apart from the work people actually perform.
Document control helps remove the familiar uncertainty of files scattered across laptops, email attachments and folders named ‘FINAL FINAL 3.’ The CAPA Log gives the company a consistent controlled record before the more connected CAPA lifecycle is required. Projects and Tasks give quality actions visible ownership instead of allowing them to disappear into email.
Foundation creates the controlled object. Lifecycle later connects that object to the events, risks, changes, training and evidence around it.
Why Foundation begins with a deliberately bounded MCP
Foundation also introduces controlled interaction through the Model Context Protocol (MCP), but the scope is deliberately bounded to Storage, Tasks and Projects.
These are useful and understandable working environments for a company beginning to use AI-assisted QMS tools. They can support everyday work without immediately opening the deeper lifecycle architecture to an external AI interface.
Broader MCP capability belongs with Lifecycle, when Quality Events, CAPA, risk, supplier quality, technical documentation and traceability begin operating as a connected system.
The principle is the same as the progressive QMS model itself: introduce useful capability, control it, learn how the organisation uses it and expand when the operating need becomes real.
Why the Foundation boundary matters
Foundation is supposed to have a boundary. It has a different job from Lifecycle.
Foundation establishes controlled building blocks. Lifecycle connects quality operations across Quality Events, CAPA, Change Control, supplier quality, risk, traceability and technical documentation. Vigilance extends the system into broader post-market, regulatory, audit and management oversight.
- Foundation establishes control.
- Lifecycle connects quality work and follows consequences.
- Vigilance supports evidence-ready oversight across the QMS.
These are not only feature packages. They reflect different stages in the maturity and operating needs of the QMS.

What the first few weeks can look like
A ten-person medical-device company does not need to wait for a six-month deployment before anyone can use the new QMS.
- Bring in the QMS Manual and confirm users, roles and responsibilities.
- Organise the most important controlled documents and identify what is current or missing.
- Assign training for procedures people already need to follow.
- Record the AI tools already in use and define basic oversight.
- Choose one high-friction process and build it in Process Builder and Form Builder.
- Move active CAPA records, projects and tasks into controlled use.
- Review what worked, then add the next practical process.
The order will differ from one company to another. That is the point. Foundation gives the organisation a controlled place to begin without forcing a small team to behave like a 500-person enterprise.
What Teams Usually Ask Before They Start
What should a medical-device startup control first in an eQMS?
Start with the records and activities the team already depends on: current documents, approvals, training, responsibilities, active tasks and the most frequently used quality forms. The first priority should be the area where missing ownership, outdated information or manual follow-up creates the greatest operational or compliance risk.
Can a medical-device company implement an eQMS gradually?
Yes. A company can establish controlled foundations first, test them in daily work and add connected lifecycle workflows when the need becomes real. A gradual approach still requires a defined plan, clear ownership and controlled records, but it avoids forcing every future QMS process into the first implementation stage.
What is included in qmsWrapper Foundation?
Foundation provides controlled QMS building blocks such as the QMS Manual, document control, forms, approvals, electronic signatures, training records, tasks, projects, storage, CAPA Log, EU AI Compliance Log, Process Builder, Form Builder and built-in AI assistance. Its MCP scope is Storage, Tasks and Projects.
Does Foundation include the full CAPA, Change Control and Risk lifecycle?
No. Foundation includes a controlled CAPA Log and the core records needed to begin. Connected Quality Events, guided CAPA lifecycle, Change Control, Supplier Quality, Risk, Wrapper Mapper, traceability and Technical File capabilities belong to qmsWrapper Lifecycle.
How should AI be used inside a medical-device QMS?
AI can help retrieve information, prepare drafts, identify gaps and suggest next steps. It should not silently approve regulated records or replace accountable decision-makers. Permissions, source records, human review, approval and audit history must remain visible.
What happens when the company needs a more advanced QMS?
The organisation adds Lifecycle for connected regulated workflows and later Vigilance for broader post-market, audit and regulatory oversight. The objective is to expand the same controlled environment without discarding the records, processes and evidence already created in Foundation.
Start where you are. Grow from there.
A growing medical-device company should not have to choose between a QMS that is too fragile for where the business is going and an enterprise implementation that overwhelms the people who must use it.
Foundation offers another path: establish the rules, train the people, control the documents, govern the AI already entering the organisation, turn priority processes into controlled workflows and give actions visible ownership.
When the company needs more, it does not migrate away from Foundation. It adds connected capability through Lifecycle and broader oversight through Vigilance.
The result is a QMS that can become more capable without making the work already completed temporary.
You do not implement qmsWrapper and then start working. You start working in qmsWrapper while you implement it.
Explore how qmsWrapper Foundation supports a practical, progressive start for medical-device quality management, or book a short walkthrough to discuss the first processes your team needs to bring under control.




