An ISO 13485 internal audit is mandatory under clause 8.2.4, and it is a
prerequisite for certification rather than something you get to afterwards. This guide covers the
programme, a working checklist by clause, and the findings that come up most often.
What clause 8.2.4 requires
Conduct internal audits at planned intervals to determine whether the QMS conforms to planned
arrangements, to the requirements of the standard, and to applicable regulatory requirements, and
whether it is effectively implemented and maintained. A documented procedure is required, covering
planning, conduct, recording and reporting.
Three requirements are easy to miss. The programme must take account of the status and
importance of the processes and areas to be audited, and the results of previous audits
— so a flat annual rota is not compliant. Auditors must not audit their own work.
And the management responsible for the area must ensure corrections and corrective actions are taken
without undue delay.
Building a risk-based ISO 13485 internal audit programme
Weight audit frequency and depth toward the areas that carry the most risk and the worst history.
In practice that usually means design and development, sterilisation and other validated processes,
supplier controls, complaint handling and CAPA get audited more often than, say, document control.
Cover the whole system within the certification cycle, but do not pretend every process deserves
equal attention. Record the reasoning behind the programme — that reasoning is what an external
auditor assesses.
ISO 13485 internal audit checklist by clause
Clause 4 — QMS and documentation. Is the quality manual current and does it
justify any clause 7 exclusions? Does a medical device file exist for each device family? Are
documents controlled, with obsolete versions prevented from unintended use? Are records legible,
retrievable and retained for the defined period?
Clause 5 — Management responsibility. Is the quality policy communicated and
understood? Are quality objectives measurable? Has management review covered every required input,
and are the outputs recorded as decisions? Is the management representative appointed in writing?
Clause 6 — Resource management. Is competence defined and evidenced for roles
affecting product quality? Is training effectiveness evaluated rather than just delivered? Are
infrastructure and work environment controls appropriate, including contamination control where
relevant?
Clause 7 — Product realization. Is risk management running across the
lifecycle and fed by post-production data? Are design inputs, outputs, reviews, verification,
validation and transfer all evidenced, with a design and development file per project? Are suppliers
evaluated, re-evaluated and the records kept? Are processes validated where output cannot be fully
verified? Is traceability demonstrable in both directions, with the extended requirements applied to
implantables?
Clause 8 — Measurement, analysis and improvement. Is feedback collected from
production and post-production and actually analysed? Are complaints investigated, with a
justification recorded where no investigation was performed? Is regulatory reporting happening to the
required timescales? Are nonconforming product controls applied, including rework and advisory
notices? Are corrective and preventive actions distinct, with effectiveness verified?
Audit templates that match the clause structure.
The ISO 13485 Toolkit includes the internal audit procedure, a clause 4 to 8 audit checklist, audit plan and report templates, and a nonconformity and CAPA log with effectiveness review built in.
ISO 13485 internal audit findings that recur
- Programme not risk-based. Equal attention to every process, no reference to
previous results. - Auditor independence breached in small teams, where the quality manager audits
processes they run. Use a trained colleague from another function, or an external auditor. - Complaints closed without a recorded justification where no investigation was
carried out — the standard requires that justification. - Preventive action indistinguishable from corrective action. If every record in
the log is reactive, clause 8.5.3 is not being met. - Effectiveness never verified. Actions closed on completion rather than on
evidence they worked. - Audit findings raised but corrections not timely, contrary to the “without undue
delay” requirement.
Getting value rather than just compliance
The audits that improve a business are the ones that follow a product or a complaint end to end
rather than marching through clauses. Pick a device released last quarter and trace it: design
inputs, verification, supplier records, production validation, release, distribution, any complaints.
You will test a dozen clauses at once and see how the system actually behaves.
References
- ISO 13485:2016 — the standard itself on iso.org.
- FDA Quality Management System Regulation (QMSR) — the rule that incorporated ISO 13485 into 21 CFR Part 820.
More on ISO 13485
- ISO 13485 certification
- ISO 13485 mandatory documents
- ISO 13485 risk management
- ISO 13485 vs ISO 9001
- ISO 13485 internal audit — you are here
- ISO 13485 risk assessment template
All of these are covered by the ISO 13485 Toolkit, or try the free ISO 13485 templates first.