ISO 13485:2016 Internal Audit

Best Practices For Internal Auditing of ISO 13485:2016 QMS

As a medical device regulatory consulting firm, we’ve seen firsthand the value of thorough, well-executed internal audits of a Quality Management System (QMS). Conducting these audits regularly not only ensures compliance but also identifies and resolves potential nonconformities before they trigger critical failures during external assessments.

This is especially critical for medical device companies, where compliance is directly tied to product safety, regulatory approval, and sustained market access.

In this blog, we’ll explore the key benefits of internal auditing of ISO 13485:2016 QMS, the specific regulatory requirements, and actionable steps to ensure your quality system is robust, compliant, and completely audit-ready.

Contact Operon Strategist today

Why Are Internal Audits Crucial?

Internal audits play a significant role in maintaining the integrity of your QMS. They serve as proactive diagnostics, offering numerous benefits:

  • Ensuring Regulatory Compliance: Internal audits verify that your internal procedures accurately reflect the stringent requirements of ISO 13485 Certification standards.

  • Identifying Gaps in Procedures: Audits help uncover areas of noncompliance or operational inefficiency, enabling you to take corrective action before they escalate into major issues.

  • Continuous Improvement Opportunities: Audits provide valuable insights and objective evidence on how processes can be refined for better performance and sustained compliance.

  • Readiness for External Audits: By identifying and resolving nonconformities internally, you minimize surprises during third-party certification audits, ensuring a smoother approval process.

ISO 13485:2016 and FDA Internal Audit Requirements

Under ISO 13485:2016 (Section 8.2.4), medical device manufacturers are mandated to perform internal audits at planned intervals. The standard requires organizations to:

  • Assess whether the QMS conforms to both ISO 13485:2016 and relevant statutory/regulatory requirements.

  • Confirm that the QMS is implemented effectively and maintained consistently.

  • Establish and maintain documented procedures outlining how audits are planned, executed, and reported, ensuring objectivity and independence (auditors cannot audit their own work).

Furthermore, FDA 21 CFR Part 820.22 outlines parallel requirements for the U.S. market. The FDA emphasizes the need for periodic quality audits, strict documentation of corrective actions, and necessary re-audits to verify that corrective measures were genuinely effective.

🚀 Struggling to align your internal audits with FDA and ISO standards?

Contact our regulatory experts today for comprehensive QMS gap analysis and audit support.

Essential Steps for Effective Internal Auditing of ISO 13485 QMS

1. Audit Planning and Scheduling

A successful internal audit begins with a risk-based, well-structured plan. Under ISO 13485:2016, audit planning must be based on the status and importance of the processes being audited, as well as previous audit results.

  • For established companies, an annual master audit plan typically suffices.

  • For start-ups or companies preparing for an imminent certification audit, conducting audits more frequently will help identify and close early compliance gaps.

2. Forming an Independent Audit Team

Depending on the size and complexity of your operations, you may require a single lead auditor or a cross-functional team. It is essential that auditors are rigorously trained in ISO 13485:2016 and fully understand the company’s QMS. Crucially, auditors must remain objective and cannot audit their own departments.

3. Executing the Audit

Audits should be conducted systematically using clause-referenced checklists. The execution process typically includes:

  • Providing advance notice to the process owners.

  • Conducting an opening meeting to review the scope and objectives.

  • Reviewing objective evidence, key documents, and records (e.g., supplier approvals, process validations, Device History Records, and quality control logs).

  • Summarizing findings in a formal closing meeting, presenting clear action items for any detected nonconformances.

4. Addressing Findings and Corrective Actions (CAPA)

Identifying nonconformances is only the first step. Documenting them through a formal Corrective and Preventive Action (CAPA) system—and ensuring root causes are eliminated through follow-up effectiveness checks—is critical to maintaining compliance. Regular reviews of audit findings by top management ensure accountability and continuous QMS improvement.

Partner with Operon Strategist for Internal Audit Expertise

At Operon Strategist, we provide end-to-end medical device regulatory consulting services to support your internal audit needs. Whether you’re a start-up building your Quality Management System (QMS) from scratch or an established manufacturer preparing for certification or surveillance audits, our expert consultants assist in all aspects of internal auditing—ensuring your quality system is compliant, robust, and completely ready for external audits.

How Operon Strategist Can Help

  • Tailored Internal Audit Procedures: Development and implementation of a complete, customized internal audit procedure aligned with ISO 13485:2016 and FDA requirements.

  • CAPA & Risk Management Support: Hands-on assistance with Corrective and Preventive Actions (CAPA), risk management protocols, and structured Management Reviews.

  • Comprehensive QMS Document Bundle: Access to our turnkey QMS document bundle featuring over 50 standardized procedures covering every requirement under ISO 13485:2016 and FDA 21 CFR Part 820.

  • Audit Readiness & Compliance Assurance: Guidance from experienced regulatory auditors to systematically identify process gaps, eliminate nonconformities, and safeguard your market access.

💡 Don’t leave your medical device compliance to chance

Schedule a consultation with Operon Strategist today to ensure your QMS is robust and ready for certification.

FAQ's

It systematically verifies that a medical device company’s Quality Management System (QMS) meets ISO 13485:2016 standards and internal procedures.

Audits must be conducted at “planned intervals.” Most organizations perform them annually, but frequency should increase for high-risk processes or after significant QMS changes.

No. ISO 13485 requires auditors to be objective and independent; they cannot audit their own work or departments.

Nonconformities must be documented, and root cause analysis must be performed through the Corrective and Preventive Action (CAPA) system to prevent recurrence.

Both require periodic, documented internal quality audits, independent auditors, and strict follow-up on corrective actions, though FDA requirements have specific nuances for U.S. market compliance.