MDSAP Audit Preparation: The Seven Processes, Grading and What It Costs

Most manufacturers approach MDSAP as a certificate to be obtained. It is more useful to treat it as an audit to be survived, because the audit model is what makes MDSAP different from anything else in your quality calendar. This article covers what the auditors actually examine, how findings are scored, what it costs and how long it takes.

One audit, five regulators

The Medical Device Single Audit Program lets a recognised third-party Auditing Organisation conduct a single audit of your quality management system that is accepted by the regulatory authorities of Australia, Brazil, Canada, Japan and the United States. Health Canada requires it. The other four accept it in place of their own routine inspection.

The European Union is not a participant. A manufacturer holding MDSAP certification still needs a notified body for CE marking, and still needs a CDSCO licence for India. MDSAP replaces inspections in the five member markets, not everywhere.

The seven processes the audit follows

An MDSAP audit is not organised by clause number. It follows a process model, and the auditor moves through the organisation in a fixed sequence, tracing real records rather than reading procedures. The seven processes are:

  1. Management — management review, quality policy and objectives, resource decisions, and how the organisation acts on data.
  2. Device marketing authorisation and facility registration — the licences and registrations you hold in each participating market, and whether they match what you actually make and ship.
  3. Measurement, analysis and improvement — complaint handling, nonconformity, CAPA, internal audit and data analysis.
  4. Medical device adverse events and advisory notices reporting — whether reportable events were identified, decided and filed inside each regulator’s clock.
  5. Design and development — design controls, design transfer and design changes, where the manufacturer performs design.
  6. Production and service controls — process validation, monitoring, traceability, servicing and installation.
  7. Purchasing — supplier evaluation, purchasing data and verification of purchased product.

Two of these are where most organisations lose ground. The marketing authorisation process catches licence scope that has drifted from the product range. The adverse event process catches reporting decisions that were made informally and never documented, which is the commonest finding of all.

How findings are graded

MDSAP does not record findings as major or minor. Every nonconformity is scored numerically, starting from a base grade of 4 or 5 depending on which clause was breached, and then escalated by two rules: add one point if the nonconformity is an absence of a documented process, and add one more if it has already resulted in a product that does not conform.

A grade of 4 or above triggers notification to the regulatory authorities. That is the practical consequence worth understanding before the audit: the grading is arithmetic, not negotiation, and a missing procedure scores higher than a procedure that exists but was followed imperfectly.

What it costs and how long it takes

Fees are set by the Auditing Organisation, not by the regulators, so they vary. The cost drivers are the number of sites, the number of employees, whether you perform design, and whether sterilisation is in scope. Budget for the initial certification audit to run over two stages, followed by surveillance audits in years one and two and a recertification audit in year three.

The realistic timeline from a standing start is nine to fifteen months: gap assessment, remediation, one full internal audit cycle and one management review against the process model, then the stage one and stage two audits. Organisations already certified to ISO 13485:2016 shorten the front half considerably, because the management system exists and only the regulatory-specific processes need building.

Preparing properly

  • Map your evidence to the process model, not to the standard. Your procedures are probably numbered by ISO 13485 clause. The auditor will not follow that order. Build an index that answers “where is the evidence for process 4?” before someone asks it in the room.
  • Reconcile licences against products. Pull every marketing authorisation you hold in the five markets and check it against the current catalogue. Discontinued products still licensed, and shipped products not licensed, are both findings.
  • Reconstruct your reporting decisions. For every complaint in the last two years that could have been reportable, there should be a written decision explaining why it was or was not reported, against each market’s criteria. Where that record does not exist, create the decision log now and say so openly rather than leaving the gap.
  • Run a full internal audit against the process model. Not a clause-by-clause internal audit. The same sequence the Auditing Organisation will use, by someone who did not write the procedures.
  • Close CAPAs before the audit, or explain them. An open CAPA is not a finding. An open CAPA with no evidence of progress is.

Choosing an Auditing Organisation

Only recognised Auditing Organisations may conduct MDSAP audits, and the list is published and maintained by the regulatory authorities. When choosing, weigh three things: whether they are accredited for your device technology, their availability against your target date, and whether the same body also serves as your EU notified body. Using one organisation for both can simplify scheduling, but it is not always the cheapest or the fastest.

Frequently asked questions

Is MDSAP mandatory?
In Canada, yes. Health Canada accepts only MDSAP certification for medical device licensing. In Australia, Brazil, Japan and the United States it is voluntary and accepted in place of routine inspection.

Does MDSAP replace ISO 13485 certification?
No. MDSAP is built on ISO 13485:2016 plus each participating market’s own regulatory requirements. Most manufacturers hold both certificates. The audits can often be combined.

Do we need MDSAP if we only sell in India and Europe?
No. Neither India nor the EU participates. India requires a CDSCO licence; the EU requires a notified body certificate under the MDR or IVDR.

What happens if we get a grade 4 or 5 finding?
The Auditing Organisation notifies the relevant regulatory authorities. Certification is not automatically lost, but the finding must be addressed, and the authority may act on it independently.

How long is an MDSAP certificate valid?
Three years, subject to surveillance audits in the intervening years, in the same pattern as ISO 13485.

Medfins International prepares manufacturers for MDSAP through gap assessment against the process model, remediation of the regulatory-specific processes, and a full mock audit before the certification audit. See our MDSAP certification support, or the full list on our services page.

Similar Posts