ISO 13485 Internal Audit

ISO 13485 Internal Audit: Step-by-Step Process, Requirements & Checklist

Medical device companies operate in one of the most regulated industries in the world. Maintaining compliance is not only necessary for certification, but also for product quality, patient safety, and market access. One of the most important parts of a compliant Quality Management System (QMS) is the internal audit process under International Organization for Standardization ISO 13485.

An effective ISO 13485 internal audit helps organizations identify gaps, improve processes, prepare for certification audits, and maintain regulatory compliance across global markets.

This guide explains everything you need to know about ISO 13485 internal audits, including requirements, audit planning, audit checklists, common findings, and best practices for medical device manufacturers.

Talk to our experts

What Is an ISO 13485 Internal Audit?

An ISO 13485 internal audit is a systematic and independent evaluation of a company’s Quality Management System to determine whether processes comply with:

  • ISO 13485:2016 requirements
  • Internal procedures and SOPs
  • Applicable regulatory requirements
  • Customer and product quality requirements

The purpose of the audit is not just to “pass certification.” It is designed to improve operational effectiveness and ensure consistent medical device quality and safety.

Internal audits are mandatory under Clause 8.2.4 of ISO 13485.

Why Internal Audits Are Important in ISO 13485

Internal audits provide organizations with a proactive way to identify nonconformities before external auditors or regulatory authorities discover them.

Key Benefits of ISO 13485 Internal Audits

Helps Maintain Certification

Regular audits ensure ongoing compliance with ISO 13485 certification requirements.

Improves Product Quality

Audits help identify process weaknesses that could affect device safety or performance.

Reduces Regulatory Risk

A strong internal audit process helps companies prepare for inspections from authorities like:

  • U.S. Food and Drug Administration FDA
  • European Commission EU regulatory bodies
  • Central Drugs Standard Control Organisation CDSCO
  • Health Canada
Encourages Continuous Improvement

Audits reveal opportunities to improve efficiency, documentation, training, and risk management.

Enhances Employee Awareness

Departments become more aware of compliance responsibilities and quality objectives.

ISO 13485 Internal Audit Requirements

According to ISO 13485:2016, organizations must:

  • Conduct internal audits at planned intervals
  • Determine whether the QMS conforms to ISO 13485 requirements
  • Verify implementation and effectiveness
  • Maintain documented audit procedures
  • Keep audit records and reports
  • Take corrective actions for identified nonconformities

The audit program should consider:

  • Importance of processes
  • Previous audit results
  • Risk levels
  • Regulatory impact

Who Should Perform ISO 13485 Internal Audits?

Internal audits should be conducted by trained and competent auditors who are independent of the area being audited whenever possible.

Auditor Competency Requirements

Auditors should understand:

  • ISO 13485 requirements
  • Medical device regulations
  • Risk management principles
  • CAPA systems
  • Documentation controls
  • Manufacturing and validation processes

     

Many organizations either:

Schedule a Compliance Consultation

Accelerate Market Access with End-to-End Regulatory Guidance

Step-by-Step ISO 13485 Internal Audit Process

1. Develop an Audit Program

Create an annual audit schedule covering all QMS processes.

Typical audit areas include:

  • Document control
  • Risk management
  • Design controls
  • Supplier management
  • Production controls
  • CAPA
  • Complaint handling
  • Training
  • Sterilization validation
  • Cleanroom controls

Risk-based auditing is strongly recommended.

2. Define Audit Scope and Objectives

The audit scope should clearly mention:

  • Department or process
  • Applicable standards
  • Regulatory requirements
  • Audit duration
  • Audit criteria

Example:
“Internal audit of purchasing controls and supplier evaluation processes as per ISO 13485 Clause 7.4.”

3. Prepare an Audit Checklist

An audit checklist helps ensure consistency and complete coverage.

Common ISO 13485 Audit Checklist Areas

Process Area

Key Audit Questions

Document Control

Are SOPs approved and current?

Training

Are competency records maintained?

Risk Management

Is ISO 14971 integrated into processes?

CAPA

Are corrective actions effective?

Supplier Control

Are suppliers evaluated and monitored?

Production

Are process validations documented?

Complaint Handling

Are complaints investigated properly?

Traceability

Can products be traced completely?

4. Conduct the Audit

Auditors gather evidence through:

  • Interviews
  • Document reviews
  • Record verification
  • Process observation
  • Sampling activities

The audit should focus on objective evidence rather than assumptions.

5. Record Audit Findings

Audit findings are generally categorized as:

Major Nonconformity

A serious failure affecting QMS effectiveness or product safety.

Minor Nonconformity

An isolated issue with limited impact.

Observation

An opportunity for improvement without direct noncompliance.

Common ISO 13485 Internal Audit Findings

Medical device companies often encounter findings related to:

  • Incomplete training records
  • Outdated SOPs
  • Missing validation records
  • Ineffective CAPA implementation
  • Supplier qualification gaps
  • Poor risk management linkage
  • Inadequate complaint investigations
  • Calibration record deficiencies

Addressing these issues early helps avoid regulatory action and certification delays.

Corrective Action After Internal Audits

Corrective Action and Preventive Action (CAPA) is critical after identifying nonconformities.

Effective CAPA Process

Root Cause Analysis

Identify the actual reason behind the issue.

Corrective Action Implementation

Fix the issue systematically.

Verification of Effectiveness

Ensure the action resolved the problem permanently.

Documentation

Maintain proper CAPA records and evidence.

Risk-Based Internal Auditing in ISO 13485

Risk-based auditing focuses more attention on high-risk processes such as:

This approach improves audit effectiveness and regulatory readiness.

ISO 13485 Internal Audit Best Practices

Conduct Audits Throughout the Year

Avoid auditing everything just before certification audits.

Use Experienced Auditors

Medical device regulations require technical and regulatory understanding.

Focus on Process Effectiveness

Do not limit audits to document reviews alone.

Review Regulatory Requirements

Ensure alignment with:

Maintain Audit Evidence

Organized records simplify certification and inspection readiness.

Internal Audit vs External Audit

Internal Audit

External Audit

Conducted by organization or consultant

Conducted by certification body

Focuses on improvement

Focuses on certification

Flexible scheduling

Fixed audit schedule

Identifies gaps early

Verifies compliance status

Both are important for maintaining an effective QMS.

How Often Should ISO 13485 Internal Audits Be Conducted?

ISO 13485 does not define a fixed frequency. However, most medical device companies conduct:

  • Full QMS audits annually
  • High-risk process audits quarterly or semi-annually

Audit frequency should be based on:

  • Process risk
  • Regulatory requirements
  • Previous audit findings
  • Organizational changes

ISO 13485 Internal Audit Checklist Example

Management Responsibility

  • Quality policy established
  • Management review conducted
  • Quality objectives monitored

Design and Development

  • Design inputs documented
  • Verification and validation records available
  • Design changes controlled

Production and Process Controls

  • Process validation records maintained
  • Equipment calibration completed
  • Environmental controls monitored

Supplier Management

  • Approved supplier list maintained
  • Supplier evaluations documented
  • Incoming inspection records available

Complaint Handling

  • Complaints logged properly
  • Investigations completed
  • Regulatory reporting assessed

How Operon Strategist Supports ISO 13485 Internal Audits

Operon Strategist provides end-to-end consulting support for medical device companies seeking ISO 13485 compliance, certification readiness, and regulatory approvals.

Our ISO 13485 Services Include

We support:

  • Medical device startups
  • Manufacturers
  • Importers and exporters
  • Contract manufacturers
  • Sterile medical device facilities

     

Our team helps organizations build practical and inspection-ready quality systems aligned with global medical device regulations.

Ensure Seamless Regulatory Compliance for Your Device

Get Your Medical Device Market-Ready with Expert Regulatory Support

FAQ's

An ISO 13485 internal audit is a planned and documented evaluation of an organization’s quality management system to determine whether its processes conform to ISO 13485 requirements and the organization’s own QMS procedures.

Clause 8.2.4 requires organizations to conduct internal audits at planned intervals using a documented audit process. The audit program should consider the status and importance of processes and previous audit results. Auditors should be appropriately selected to maintain objectivity and impartiality, and the organization must address findings and conduct appropriate follow-up.

ISO 13485 requires internal audits at planned intervals rather than prescribing one universal frequency for every organization or process. Audit frequency should consider process importance, previous audit results, changes, and other relevant QMS factors.

An ISO 13485 internal audit checklist should be customized to the audit scope and may cover QMS documentation, management responsibility, training, design and development, purchasing, supplier controls, production, validation, traceability, nonconforming product, complaints, CAPA, internal audits, and management review.