Requirements Traceability Matrix (RTM)

A Requirements Traceability Matrix, or equivalenttraceability mechanism, connects requirements with related risks, design orconfiguration elements, assurance activities, results, and unresolved issues.

Traceability helps demonstrate that applicable requirementshave been addressed and that assurance activities are linked to defined needsand risks.

·        User and functionalrequirements

·        Design or configurationreferences

·        Risk assessments andcontrols

·        Test cases or otherassurance activities

·        Execution results

·        Deviations or issues

·        Approval or release status

·        Change references

The structure should reflect the organization’s methodology.During implementation, traceability helps identify missing, duplicated, orinadequately verified requirements. During operation, it supports impactassessment by showing which requirements, risks, controls, and records may beaffected by a change.

Frequently Asked Questions

Is an RTM required by the FDA?

FDA regulations and guidance do not generally require adocument specifically titled Requirements Traceability Matrix. An RTM is onecommonly used method for presenting traceability evidence.

What should an RTM include?

At a minimum, the traceability mechanism should identify theapplicable requirement and the evidence demonstrating how it was addressed.Where relevant, it should also link requirements to risks, controls, design orconfiguration, results, deviations, and changes.

Is a spreadsheet suitable for an RTM?

A controlled spreadsheet can be suitable when itscomplexity, access, review, approval, and maintenance are appropriatelymanaged. Managed tooling may reduce manual reconciliation for complex orfrequently changing systems.

When should the RTM be updated?

Traceability should be maintained throughout the life cycleand updated whenever applicable requirements, risks, configurations, assuranceactivities, results, or related changes are approved or modified.

‍