Medical device supplier audits give manufacturers and importers evidence that critical suppliers and contract manufacturers can consistently deliver conforming products and services. Medfins International plans and conducts on-site and remote supplier audits, supports supplier evaluation and qualification, and helps you put quality agreements in place that meet ISO 13485, CDSCO, EU MDR and US FDA expectations.
What is a medical device supplier audit?
A supplier audit is a systematic assessment of a supplier’s quality system, processes and records to confirm that it can meet your specified requirements. For medical devices, it is one of the main controls used to show that purchased products and outsourced processes do not compromise device safety and performance.
Regulatory basis
- ISO 13485:2016 clause 7.4 (Purchasing): organisations must establish criteria for evaluating and selecting suppliers based on their ability to provide conforming product, their performance and the risk associated with the product. Controls must be proportionate to risk, supplier monitoring and re-evaluation must be planned, and records must be kept.
- ISO 13485 clause 4.1.5: the organisation remains responsible for outsourced processes and must control them, including through written quality agreements.
- India: the Fifth Schedule QMS of the Medical Devices Rules, 2017 carries equivalent purchasing and outsourcing controls, and CDSCO auditors review supplier records during manufacturing licence audits.
- European Union: under the EU MDR and IVDR, notified bodies assess supplier controls and may carry out unannounced audits at critical subcontractors and crucial suppliers.
- United States: the FDA QMSR (21 CFR Part 820), effective 2 February 2026, incorporates ISO 13485 purchasing requirements by reference.
Who needs supplier audit support?
- Manufacturers using contract manufacturers, sterilisation service providers or component suppliers
- Legal manufacturers and brand owners who outsource most or all production
- Importers verifying overseas manufacturers before applying for a CDSCO import licence
- Companies preparing for notified body, MDSAP or CDSCO audits that will review supplier controls
Scope: which suppliers to audit
Not every supplier needs an on-site audit. We help you classify suppliers by risk and choose the right control:
Critical suppliers
Suppliers whose products or services directly affect device safety or performance, such as contract manufacturers, sterilisation, critical components, raw materials in patient contact, software and calibration services. These typically need an audit before approval and periodic re-audits.
Non-critical suppliers
Suppliers of lower-risk items can often be controlled through questionnaires, certificates, incoming inspection and performance monitoring.
Documents typically required
- Supplier evaluation and selection procedure and approved supplier list
- Purchasing specifications and drawings
- Supplier self-assessment questionnaires and certificates, such as ISO 13485
- Quality agreements defining responsibilities, change notification and audit rights
- Supplier audit plans, reports and CAPA records
- Supplier performance data, such as nonconformities, delivery and complaints
Our supplier audit process
- Supplier risk assessment: classify suppliers and define the controls needed for each.
- Pre-audit questionnaire: collect basic information and certificates.
- Audit plan: agree scope, criteria, dates and whether the audit is on-site, remote or hybrid.
- Audit execution: review of the supplier’s QMS, process controls, validation, traceability, change control and nonconformity handling.
- Audit report: findings with objective evidence and a recommendation on approval status.
- Supplier CAPA follow-up: review of the supplier’s corrective actions.
- Quality agreement: draft or review the agreement to reflect audit outcomes.
- Monitoring and re-evaluation: set the re-audit frequency based on risk and performance.
Timelines and what affects them
Supplier audit timelines depend on the supplier’s location and availability, the processes in scope, language needs, whether special processes such as sterilisation or moulding are involved, and how quickly the supplier shares documents and responds to findings.
Common supplier control gaps
- Suppliers approved on the basis of an ISO certificate alone, without risk assessment
- No quality agreement, or one that omits change notification requirements
- Outsourced processes, such as sterilisation, not treated as critical
- Re-evaluation not linked to supplier performance data
- Findings raised with suppliers but never followed up
What a supplier audit covers
A medical device supplier audit is tailored to what the supplier provides, but usually includes:
- QMS structure, certification status and management commitment
- Control of documents, drawings and specifications received from customers
- Incoming material control and the supplier’s own sub-tier suppliers
- Process validation, especially for special processes such as sterilisation, sealing, moulding and welding
- Cleanroom and environmental controls, where applicable
- Calibration, maintenance and equipment qualification
- Traceability, labelling and batch records
- Change control and how customers are notified of changes
- Nonconforming product, complaints and CAPA
Supplier audits and regulatory submissions
Supplier information often ends up in regulatory files. Device Master Files for CDSCO, EU MDR technical documentation and US submissions may reference critical suppliers, sterilisation sites and contract manufacturers. Audit reports and quality agreements help show that these parties are under control.
Remote versus on-site supplier audits
Remote audits reduce travel and can be arranged quickly, which makes them useful for re-audits of well-performing suppliers and for document-heavy reviews. On-site audits remain the better choice for new critical suppliers, special processes and cleanroom operations, where observing the process and the environment gives much stronger evidence. Your supplier procedure should state how the method is chosen, and we help you document that justification.
How Medfins International supports you
Our audits are led by a CQI and IRCA certified ISO 13485 Lead Auditor who understands both the supplier’s process and your regulatory obligations. We audit suppliers in India and overseas, on-site or remotely, and report in a format your certification body or regulator can review.
Supplier audits work well alongside internal audit support, ISO 13485:2016 certification and, for importers, the CDSCO import licence. Contact us to plan your supplier audit programme.
Frequently asked questions
Are supplier audits mandatory under ISO 13485?
Can supplier audits be conducted remotely?
What is a quality agreement?
Can you audit overseas manufacturers for Indian importers?
What happens if a supplier fails the audit?
Talk to a regulatory expert
Get a free assessment of the pathway, timeline and documents for your device.
Our Services
- India Licensing (CDSCO)
- CDSCO Manufacturing Licence
- CDSCO Import Licence
- Indian Authorised Agent
- CDSCO Test Licence
- Wholesale Registration (MD-42)
- BIS Licence & ISI Mark
- GeM Registration
- Quality & Compliance
- ISO 13485:2016 Certification
- MDSAP Certification
- Internal Audit Support
- Supplier Audit Support
- Training & Workshops
- Annual Maintenance Contract
- Outsourced Regulatory Staff
- Global Market Access
- CE Marking (EU MDR / IVDR)
- US FDA 510(k)
- UAE (MOHAP / EDE)
- Saudi Arabia SFDA
- Egypt EDA
- Sri Lanka NMRA
- Singapore HSA
- Thailand FDA
- Philippines FDA
- Malaysia MDA
