Audit — medical devices is a systematic, independent, documented process to obtain evidence and evaluate it against defined criteria to confirm the extent of conformity. In devices, audits verify QMS, product, and process compliance with regulations and standards (e.g., ISO 13485, MDR/IVDR, 21 CFR 820/QMSR) and drive continual improvement (ISO 19011; ISO 13485:2016 §8.2.4).

Scope: scope/market focusJurisdictions: US/EU/CA/JP/AUContexts: QMS • Suppliers • Conformity assessment

Regulatory framework

  • US (FDA): Quality System Regulation inspections under FD&C Act §704 and 21 CFR 820 (until QMSR transition); Quality Management System Regulation final rule aligning with ISO 13485 (21 CFR Part 820, amended 2024; compliance date 2026); supplier controls 21 CFR 820.50; records 21 CFR 820.180.
  • EU (MDR/IVDR): Manufacturer QMS obligations (MDR Art. 10(9); IVDR Art. 10(8)); NB conformity assessment and audits (MDR Annex IX/XI; IVDR Annex IX/XI), including surveillance and unannounced audits (MDR Annex IX §3.3–3.4; IVDR Annex IX §3.3–3.4).
  • Canada (Health Canada): MDSAP audits recognized for licensing; CMDR SOR/98-282 Part 1 (e.g., §§32–43) and ISO 13485 certification via MDSAP for Class II–IV.
  • Japan (PMDA/MHLW): QMS conformity audits under PMD Act and QMS Ordinance (MHLW Ministerial Ordinance No. 169/2004); supplier controls and records per QMS Ordinance.
  • Australia (TGA): Conformity assessment audits under Therapeutic Goods (Medical Devices) Regulations 2002, including surveillance; QMS based on ISO 13485 (Regs r. 5.7–5.8; Sch. 3).
  • Standards & guidance: ISO 13485:2016 §8.2.4 (internal audits); ISO 19011:2018 (auditing guidelines).

Key elements / What it covers

  • Planned, risk-based program covering all QMS processes within a defined cycle (ISO 13485 §8.2.4).
  • Independence and competence of auditors; defined scope, criteria, and methods (ISO 19011).
  • Objective evidence via sampling of documents, records, interviews, and observation.
  • Findings classification (nonconformity/observation/opportunity), with requirement traceability.
  • Outputs integrated into CAPA, PMS, and management review.

Process / How it works

  • Plan: Establish risk-based audit program and schedule considering changes, complaints, and prior findings (ISO 13485 §8.2.4).
  • Define: Set scope, criteria (procedures, ISO 13485, MDR/IVDR, 21 CFR 820), team, and sampling strategy.
  • Prepare: Review documents/records; create checklists and interview guides.
  • Execute: Conduct opening meeting, collect evidence on-site/remote, record objective evidence.
  • Report: Classify findings with requirement→evidence→impact; agree containment where needed.
  • Follow-up: Ensure CAPA, verify effectiveness, and feed into management review (ISO 13485 §8.5, §5.6).

Common pitfalls

  • Auditors not independent/competent for the processes audited (violates ISO 13485 §8.2.4 and ISO 19011).
  • Program not risk-based; high-risk or changed processes skipped.
  • Weak evidence trails (missing UDI/traceability, training, DHR/DMR linkages).
  • Poor finding statements (no requirement citation or impact) leading to weak CAPA.
  • Supplier audits not scaled to risk for critical items/services (21 CFR 820.50; MDR Art. 10(9)).

Quick checks / Tips

  • Confirm annual/defined-cycle coverage of all QMS processes with risk-based prioritization.
  • Verify auditor independence, competence, and documented plans/checklists.
  • Trace each finding to a requirement and objective evidence; set due dates and owners.
  • Link audit outputs to CAPA, change control, PMS/PSUR, and management review actions.

FAQ

Is an internal audit mandatory?

Yes. ISO 13485:2016 §8.2.4 requires internal audits at planned intervals; EU MDR/IVDR require an effective QMS (MDR Art. 10(9); IVDR Art. 10(8)) that includes internal audits.

How do audits differ from FDA inspections?

Internal/supplier/NB audits assess against defined criteria; FDA inspections are regulatory examinations under FD&C Act §704 and 21 CFR 820 (transitioning to QMSR).

Are unannounced audits required in the EU?

Yes, Notified Bodies may perform unannounced on-site audits during surveillance (MDR Annex IX §3.4; IVDR Annex IX §3.4).

Do we need to audit all suppliers?

Use risk-based supplier controls. Critical suppliers/CMs typically require qualification and periodic audits commensurate with risk (21 CFR 820.50; MDR Art. 10(9)).

What must an audit report include?

Scope, criteria, team, methods, evidence summary, classified findings, conclusion, and required corrections/CAPA with timelines (ISO 19011; ISO 13485 §8.2.4/§8.5).