Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 13485 Internal Audit — ISO 13485:2016 medical device quality management

ISO 13485 Internal Audit: Checklist and Programme Guide

An ISO 13485 internal audit is mandatory under clause 8.2.4, and it is a
prerequisite for certification rather than something you get to afterwards. This guide covers the
programme, a working checklist by clause, and the findings that come up most often.

What clause 8.2.4 requires

Conduct internal audits at planned intervals to determine whether the QMS conforms to planned
arrangements, to the requirements of the standard, and to applicable regulatory requirements, and
whether it is effectively implemented and maintained. A documented procedure is required, covering
planning, conduct, recording and reporting.

Three requirements are easy to miss. The programme must take account of the status and
importance of the processes and areas to be audited, and the results of previous audits

— so a flat annual rota is not compliant. Auditors must not audit their own work.
And the management responsible for the area must ensure corrections and corrective actions are taken
without undue delay.

Building a risk-based ISO 13485 internal audit programme

Weight audit frequency and depth toward the areas that carry the most risk and the worst history.
In practice that usually means design and development, sterilisation and other validated processes,
supplier controls, complaint handling and CAPA get audited more often than, say, document control.

Cover the whole system within the certification cycle, but do not pretend every process deserves
equal attention. Record the reasoning behind the programme — that reasoning is what an external
auditor assesses.

ISO 13485 internal audit checklist by clause

Clause 4 — QMS and documentation. Is the quality manual current and does it
justify any clause 7 exclusions? Does a medical device file exist for each device family? Are
documents controlled, with obsolete versions prevented from unintended use? Are records legible,
retrievable and retained for the defined period?

Clause 5 — Management responsibility. Is the quality policy communicated and
understood? Are quality objectives measurable? Has management review covered every required input,
and are the outputs recorded as decisions? Is the management representative appointed in writing?

Clause 6 — Resource management. Is competence defined and evidenced for roles
affecting product quality? Is training effectiveness evaluated rather than just delivered? Are
infrastructure and work environment controls appropriate, including contamination control where
relevant?

Clause 7 — Product realization. Is risk management running across the
lifecycle and fed by post-production data? Are design inputs, outputs, reviews, verification,
validation and transfer all evidenced, with a design and development file per project? Are suppliers
evaluated, re-evaluated and the records kept? Are processes validated where output cannot be fully
verified? Is traceability demonstrable in both directions, with the extended requirements applied to
implantables?

Clause 8 — Measurement, analysis and improvement. Is feedback collected from
production and post-production and actually analysed? Are complaints investigated, with a
justification recorded where no investigation was performed? Is regulatory reporting happening to the
required timescales? Are nonconforming product controls applied, including rework and advisory
notices? Are corrective and preventive actions distinct, with effectiveness verified?

Audit templates that match the clause structure.

The ISO 13485 Toolkit includes the internal audit procedure, a clause 4 to 8 audit checklist, audit plan and report templates, and a nonconformity and CAPA log with effectiveness review built in.

Explore the ISO 13485 Toolkit →

ISO 13485 internal audit findings that recur

  • Programme not risk-based. Equal attention to every process, no reference to
    previous results.
  • Auditor independence breached in small teams, where the quality manager audits
    processes they run. Use a trained colleague from another function, or an external auditor.
  • Complaints closed without a recorded justification where no investigation was
    carried out — the standard requires that justification.
  • Preventive action indistinguishable from corrective action. If every record in
    the log is reactive, clause 8.5.3 is not being met.
  • Effectiveness never verified. Actions closed on completion rather than on
    evidence they worked.
  • Audit findings raised but corrections not timely, contrary to the “without undue
    delay” requirement.

Getting value rather than just compliance

The audits that improve a business are the ones that follow a product or a complaint end to end
rather than marching through clauses. Pick a device released last quarter and trace it: design
inputs, verification, supplier records, production validation, release, distribution, any complaints.
You will test a dozen clauses at once and see how the system actually behaves.

References

More on ISO 13485

All of these are covered by the ISO 13485 Toolkit, or try the free ISO 13485 templates first.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.