ISO 13485 Audits: Definition, Types, Process, and How to Prepare

ISO 13485 Audits: Definition, Types, Process, and How to Prepare

Published: June 16, 2025

Updated: January 30, 2026

ISO 13485 is an internationally recognized standard that defines the quality management system (QMS) requirements for medical device manufacturers. The purpose of ISO 13485 is to provide medical devices and related services that consistently meet customer and regulatory requirements throughout the product lifecycle.

An ISO 13485 audit is a formal evaluation of an organization’s QMS to determine its conformity with ISO 13485:2016 and internal procedures.

ISO 13485:2016 requires internal audits per Clause 8.2.4 to evaluate QMS conformity, and supplier audits per Clause 7.4.1 to evaluate external providers. External audits may also be conducted by notified bodies or regulatory agencies to assess ISO 13485 certification or compliance.

The ISO 13485 audit process involves documented planning, auditor preparation, execution using clause-referenced checklists, supporting documentation, post-audit CAPA management, and integration into Management Review activities.

Effective audit preparation includes understanding the audit scope, verifying controlled documentation and training records, auditing high-risk QMS processes, for example, CAPA, change control, and organizing audit evidence by clause using audit checklists. To support these activities, a validated QMS software centralizes quality processes such as document control, audit management, training, CAPA, and change control. This ensures real-time traceability, version control, and ISO 13485 audit readiness.

What Is an ISO 13485 Audit?

An ISO 13485 audit is a systematic, independent, and documented assessment to determine whether a medical device organization’s Quality Management System (QMS) meets ISO 13485:2016 requirements.

The purpose of an ISO 13485 audit is to verify QMS compliance, and effectiveness, and ensure that QMS processes consistently meet ISO 13485 requirements to support product quality and regulatory compliance.

ISO 13485 audits apply to manufacturers, suppliers, and service providers involved in the design, production, installation, or servicing of medical devices. These audits are conducted by accredited third-party certification bodies such as BSI or TÜV SÜD as part of initial certification, surveillance, and recertification.

What Are the Types of ISO 13485 Audits for Medical Devices?

The different types of audits for medical devices under ISO 13485 are listed below.

ISO 13485 Internal Audits

An ISO 13485 internal audit is a systematic, independent, and documented process for evaluating whether the Quality Management System (QMS) meets ISO 13485:2016, internal procedures, and applicable regulatory requirements. Internal audits are required per ISO13485, Clause 8.2.4.

The purpose of an ISO 13485 internal audit is to verify the implementation and effectiveness of QMS processes, identify nonconformities, and ensure early detection of QMS deficiencies that could impact product safety, performance, or regulatory compliance.

ISO 13485 Internal Audits must assess the conformity of critical processes such as design and development per Clause 7.3, Corrective Action per Clause 8.5.2 and Preventive Action per Clause 8.5.3, production per Clause 7.5, and document control per Clause 4.2, using objective evidence to assess compliance. Examples of objective evidence include Device History Records (DHRs), audit trails, and validation records.

These audits are performed by trained, qualified personnel who are independent of the area being audited, with auditor competence documented per Clause 6.2.

Internal audit frequency must be risk-based and documented in an internal audit schedule that ensures full QMS coverage, prioritizing high-risk processes or processes where most nonconformities have occurred.

Internal audit results should be used as input into Management Review per Clause 5.6, and subsequent internal audits.

ISO 13485 Supplier Audits

An ISO 13485 supplier audit is a risk-based, documented evaluation of an external supplier’s Quality Management System. The purpose of ISO 13485 supplier audits is to verify compliance with Purchasing per Clause 7.4 and the supplier’s ability to meet quality, safety, and regulatory requirements.

A supplier audit applies to entities providing products or services that may impact device safety, performance, or conformity. It assesses compliance with approved specifications, quality agreements, and documented supplier procedures using objective evidence.

Unlike internal audits per Clause 8.2.4, which assess in-house QMS effectiveness, supplier audits extend QMS oversight to third parties. They are conducted by qualified QA personnel with expertise in procurement, quality, and regulatory compliance.

Supplier audits are essential for maintaining control over outsourced processes, ensuring suppliers consistently meet relevant specifications and regulatory requirements.

Key elements of ISO 13485 supplier audits include review of the supplier’s QMS documentation, certifications, DHRs, process validation, change control, complaint handling, and Corrective and Preventive Action (CAPA) systems.

Supplier audit results must be documented and used to update risk ratings, supplier scorecards, and the Approved Supplier List (ASL) as part of the supplier management cycle.

ISO 13485 Certification Audits

An ISO 13485 certification audit is a formal, third-party assessment of a medical device manufacturer’s Quality Management System to verify conformity with the ISO 13485:2016 standard.

The purpose of the certification audit is to confirm that the QMS is implemented, maintained, and capable of consistently meeting regulatory and product quality requirements supporting market access and regulatory compliance.

Certification audits are conducted by accredited registrars or Notified Bodies and involve a clause-by-clause evaluation of the QMS, supported by objective evidence such as records, SOPs, and validation reports.

These three phases in an ISO 13485 audit are:

Certification audit findings are classified, and nonconformities must be addressed within defined timelines to achieve or maintain certification.

Audit outcomes are documented in a controlled audit report and stored in the QMS.

What is the ISO 13485 Audit Process?

The following process steps reflect the ISO 13485 internal audit process and are applicable to supplier and certification audits with some modifications to audit scope, responsibility, and applicable ISO 13485 requirements based on audit type. The differences are briefly explained in the relevant sections below.

  1. Audit Planning and Scheduling: Define the audit scope, criteria, frequency, and responsible personnel based on process criticality, previous nonconformities, and regulatory priorities. The audit plan must ensure coverage of all applicable ISO 13485 clauses over the audit cycle and be documented within the QMS.
  2. Audit Team Preparation: Assign competent, independent auditors per Clause 6.2, and equip them with clause-referenced checklists, prior audit results, and relevant QMS documentation.
  3. Opening Meeting: Formally initiate the audit by presenting the scope, ISO 13485 clause coverage, audit criteria, and nonconformity classification. Confirm access to controlled records, electronic systems, and physical areas, and clearly define responsibilities.
  4. Conducting the Audit (On-Site or Remote): Evaluate QMS implementation and effectiveness using interviews, direct observation of activities, and review of objective evidence such as DHRs, CAPA records, and referencing applicable clauses.
  5. Documenting Audit Findings: Record each finding with clause reference, evidence ID, and severity classification (major or minor nonconformity), where applicable in the audit findings log.
  6. Closing Meeting: Present clause-referenced findings, confirm classification per internal criteria, assign responsible owners, and document required follow-up actions, including CAPA initiation if applicable.
  7. Audit Report Issuance: A clause-referenced and controlled audit report detailing the scope, findings categorized by severity, and audit conclusion summarizing overall QMS conformity.
  8. Corrective Actions and Follow-Up: Initiate and document CAPAs for applicable nonconformities, including root cause analysis, action implementation, and effectiveness verification.
  9. Management Review and Continuous Improvement: Present audit outcomes and CAPA status during Management Review to assess QMS performance, assign actions, and drive continuous improvement.

1. Audit Planning and Scheduling

Audit planning defines the scope, frequency, methods, and responsibilities of internal audits. The purpose of audit planning and scheduling is to ensure coverage of all applicable ISO 13485 clauses based on risk, CAPA history, and process criticality, among others.

The QA representative or the Audit Program Owner uses tools like the Nonconformity (NC) log, CAPA tracker, and product master files to generate a documented schedule. The schedule must cover all major QMS areas and be updated after significant changes in the QMS or regulatory environment. Maintaining an updated, risk-based audit schedule is essential to ensure compliance and ongoing audit program effectiveness. The approved audit schedule is maintained as a controlled document and is used to execute the audit.

2. Audit Team Preparation

Audit team preparation ensures auditors are competent, independent, and assigned per audit scope. The purpose of audit team preparation is to establish a team capable of executing an objective and compliant audit.

The QA representative verifies auditor training records and assigns roles based on auditor expertise. Tools to support audit team preparation include training matrices, process-specific checklists, and audit history. Auditor assignments should align with process complexity, and designated auditors should be familiar with previous findings relevant to their areas. The assembled audit team must be documented and meet the qualification requirements defined in Clause 6.2.

3. Opening Meeting

The opening meeting is a formal session to communicate the audit scope, ISO 13485 clauses covered, audit schedule, and access requirements such as availability of records, facilities, and personnel. The purpose of the opening meeting is to align process owners with audit objectives and confirm the availability of key records and personnel.

The Lead Auditor presents the agenda, and highlights focus areas, for example, CAPAs, and validation records. The Lead Auditor also documents any exclusions or constraints, such as QMS areas not in scope.

4. Conducting the Audit (On-Site or Remote)

Conducting the audit involves a systematic, clause-referenced review of controlled records and process activities to evaluate the implementation and effectiveness of QMS processes. The purpose of conducting the audit is to verify that the organization meets ISO 13485 requirements using verifiable documentation, interviews, and direct observations.

5. Documenting Audit Findings

Documenting audit findings involves recording nonconformities, observations, and Opportunities for Improvement (OFIs) with references to relevant clauses and supporting objective evidence. The purpose of documenting audit findings is to establish clear, traceable, factual findings for corrective action and compliance verification.

6. Closing Meeting

The closing meeting is a formal review session where all audit findings are presented to process owners, their classifications are confirmed, and responsibility for follow-up actions is assigned. The purpose of the closing meeting is to ensure that each finding is fully understood, acknowledged by the responsible function, and documented in accordance with applicable procedures or work instructions.

7. Audit Report Issuance

The audit report is a version-controlled summary of the audit scope, methods, findings, and conclusions. The purpose of an audit report is to create a record of audit execution and outcomes, traceable to applicable ISO 13485 clauses.

8. Corrective Actions and Follow-Up

Corrective actions and follow-up involve the formal initiation, implementation, and closure of CAPAs linked to audit-identified nonconformities. The purpose of implementing corrective actions and follow-up is to address the determined root cause, restore compliance with applicable requirements, and prevent recurrence through risk-based follow-up actions.

9. Management Review and Continuous Improvement

Management Review is a structured evaluation of QMS performance conducted in accordance with ISO 13485:2016 Clause 5.6. The purpose of Management Review is to evaluate QMS performance against defined objectives. Management Review also identifies recurring or cross-functional risks that could compromise QMS effectiveness and drive strategic actions for improvement.

What Are the Post-Audit Activities After an ISO 13485 Internal Audit?

Post-audit activities following an ISO 13485 internal audit are outlined below.

  1. Receive and Review the Audit Report: The designated QA representative, for example, the Quality Manager receives the final audit report and verifies the clause references, and classification of findings before initiating formal follow-up activities.
  2. Communicate Audit Results Internally: Audit findings and classifications are communicated to relevant process owners. Timelines and responsibilities for addressing audit findings are clearly defined and documented.
  3. Perform Root Cause Analysis: For applicable nonconformities, process owners conduct documented root cause analysis using approved methodologies.
  4. Initiate Corrective Actions (CAPA): CAPAs are formally initiated for audit findings that require systemic correction.
  5. Implement Corrective Actions: Corrective actions are executed, including updates to controlled documents, retraining, process modifications, or system changes, with all changes recorded in the CAPA log.
  6. Verify Effectiveness of Actions: The designated QA performs effectiveness checks using measurable criteria.
  7. Close Out Non-Conformities: Each nonconformity is formally closed in the audit tracking system with traceability to evidence, root causes, and associated corrective or preventive actions.
  8. Conduct Management Review: Management Review needs to be conducted as per clause 5.6.
  9. Update the Audit Program: The audit schedule is revised based on audit outcomes.
  10. Promote Continuous Improvement: Data from audit findings, OFIs, and CAPA trends are analyzed for QMS improvements.

How to Prepare for an ISO 13485 Audit?

The following steps outline how to prepare for an ISO 13485 audit:

  1. Understand the Audit Scope and Requirements: Confirm which ISO 13485 clauses, processes, and locations are in scope.
  2. Assign Audit Roles and Responsibilities: Designate the audit program owner, area owner(s), and QA representatives, where necessary.
  3. Ensure Documentation Is Current and Controlled: Verify that all SOPs, work instructions, forms, and records are approved, up-to-date, and version-controlled.
  4. Review Previous Audits and CAPA Records: Assess closure status and effectiveness of prior CAPAs linked to audit findings.
  5. Conduct a Mock Audit or Gap Assessment: Use a clause-referenced internal audit checklist to simulate audit conditions.
  6. Verify Training and Competency Records: Ensure training matrices and individual records demonstrate current training and competency.
  7. Audit the CAPA, Change Control, and Risk Management Processes: Confirm these core systems are functioning effectively.
  8. Prepare Quality and Regulatory Reports: Ensure Management Review outputs and other reports are up to date and accurate.
  9. Organize Audit Evidence and Files: Ensure that audit evidence is accessible per audit checklist requirements.
  10. Brief and Train Staff on Audit Conduct: Train staff on how to respond to auditor questions factually.
  11. Schedule a Pre-Audit Walkthrough: Conduct a final readiness review of the facility, personnel, and documentation.

What Are the Common ISO 13485 Audit Findings?

The common ISO 13485 audit findings are listed below.

What Are the Best Practices to Ensure ISO 13485 Compliance and Audit Readiness?

The best practices to ensure ISO 13485 compliance are listed below.

  1. Establish a Robust Document Control System: All SOPs and forms must be revision-controlled.
  2. Automate and Track Employee Training: Use training management tools that link training requirements to current SOP versions.
  3. Implement a Closed-Loop CAPA Process: Each CAPA must document the root cause.
  4. Use Integrated QMS Software: Validated platforms provide real-time control of documents.
  5. Maintain a Proactive Internal Audit Program: Audit schedules must be risk-based.
  6. Conduct Regular Management Reviews: Reviews must evaluate QMS effectiveness.
  7. Ensure Comprehensive Supplier Management: Maintain an up-to-date Approved Supplier List supported by documented selection activities.
  8. Keep Risk Management Files Current: Risk files must reflect current product configurations.
  9. Validate and Maintain Equipment and Software: All software must be validated with documented protocols.
  10. Prepare and Organize Audit Evidence Continuously: Maintain readily accessible evidence such as DHRs, CAPA files, and validation reports.