ISO 13485 Internal Audit Support for Medical Device Companies

ISO 13485 internal audit services give medical device and IVD organisations an independent, objective view of how well their quality management system works in practice. Medfins International plans and conducts internal audits, pre-certification and mock regulatory audits, and supports your team through CAPA follow-up, so issues are found and fixed before a certification body or regulator finds them.

What is an ISO 13485 internal audit?

Clause 8.2.4 of ISO 13485:2016 requires organisations to conduct internal audits at planned intervals to determine whether the QMS conforms to planned arrangements, the standard, the organisation’s own requirements and applicable regulatory requirements, and whether it is effectively implemented and maintained.

The standard requires a documented procedure, an audit programme that considers the status and importance of processes and results of previous audits, auditors who do not audit their own work, and follow-up actions taken without undue delay to eliminate detected nonconformities and their causes.

Why outsource internal audits?

Small and growing companies often find it hard to meet the independence requirement, or lack trained auditors with regulatory knowledge. Even larger organisations benefit from an external view before key events. An independent internal audit helps you:

  • Meet the independence requirement of ISO 13485 clause 8.2.4
  • Test readiness for certification, surveillance, MDSAP or regulatory inspections
  • Check that regulatory requirements, such as CDSCO licence conditions, vigilance and FDA QMSR obligations, are built into daily work
  • Give management reliable inputs for management review

Who needs internal audit support?

  • Manufacturers preparing for a CDSCO or State Licensing Authority audit under the Medical Devices Rules, 2017
  • Organisations preparing for initial ISO 13485 certification or MDSAP audits
  • Companies with recurring nonconformities or overdue CAPAs
  • Importers and distributors running an ISO 13485 system for storage, distribution or servicing
  • Businesses that have lost their internal auditor or management representative

Scope of our internal audits

Audit types

  • Full system audits covering all applicable ISO 13485 clauses
  • Process audits of areas such as design, production, sterilisation, purchasing or complaint handling
  • Pre-certification and mock audits simulating a certification body, MDSAP Auditing Organisation or CDSCO inspection
  • Follow-up audits to verify CAPA implementation and effectiveness

Reference criteria

  • ISO 13485:2016 and, where relevant, ISO 14971:2019 risk management
  • Fifth Schedule of the Medical Devices Rules, 2017 for Indian manufacturers
  • US FDA QMSR (21 CFR Part 820), EU MDR 2017/745 or IVDR 2017/746 requirements for exporters
  • Your own procedures, licence conditions and customer requirements

Our audits follow the guidance in ISO 19011:2018, Guidelines for auditing management systems, on audit programme management, planning, evidence collection and reporting.

What we need from you

  • Quality manual, procedures and organisation chart
  • List of products, licences, registrations and certificates
  • Previous internal and external audit reports and open CAPAs
  • Access to records and to personnel during the audit, on-site or remote

Our internal audit process

  1. Audit programme: we build or review a risk-based annual audit programme covering all QMS processes.
  2. Audit plan: scope, criteria, schedule and auditees are agreed in advance.
  3. Document review: procedures and records are checked against the standard and regulations.
  4. Audit execution: interviews, observation and record sampling, on-site or remote.
  5. Closing meeting: findings are presented and clarified with your team.
  6. Audit report: nonconformities graded with objective evidence, plus observations and improvement opportunities.
  7. CAPA support: we help with root cause analysis and corrective action plans.
  8. Verification: follow-up review of closure evidence and effectiveness.

Timelines and what affects them

Audit duration depends on the number of employees and sites, the processes in scope, whether design and development is included, the number of products and markets, and whether the audit is remote or on-site. We agree the number of audit days after reviewing your scope.

Common weaknesses found during internal audits

  • Audit programmes that do not reflect process risk or previous results
  • Findings closed with corrections only, without root cause analysis
  • No verification of CAPA effectiveness
  • Training records that do not demonstrate competence
  • Regulatory changes, such as new CDSCO notifications or the FDA QMSR transition, not assessed

Internal audits and management review

Internal audit results are a required input to management review under ISO 13485 clause 5.6. A good audit report gives top management a clear picture of QMS performance, recurring issues, resource needs and regulatory risks, so decisions are based on evidence rather than assumptions.

We present findings in a way that supports this review, grouping issues by process and risk and highlighting trends across audit cycles.

Mock regulatory audits

Before a CDSCO or State Licensing Authority inspection under the Medical Devices Rules, 2017, a notified body audit or an MDSAP audit, a mock audit can make a real difference. We follow the approach used by the external auditor, check that key records can be retrieved quickly, and prepare staff for interviews.

  • Checks that licence conditions and approved product lists match what is manufactured or imported
  • Review of Device Master File and Plant Master File consistency with actual practice
  • Traceability exercises from a finished device back to raw materials and suppliers
  • Walk-through of complaint, vigilance and recall procedures

How Medfins International supports you

Internal audits are led by Mr. Arunkumar Chokkalingam, a CQI and IRCA certified ISO 13485 Lead Auditor, together with our regulatory team. We write findings that are specific and traceable, so your team knows exactly what to fix.

Internal audit support fits naturally with ISO 13485:2016 certification, supplier audit support and internal auditor training, and can be included in a regulatory annual maintenance contract. Contact us to schedule your audit.

Frequently asked questions

How often should ISO 13485 internal audits be done?
ISO 13485 requires audits at planned intervals, without fixing a frequency. Most organisations cover every QMS process at least once a year, auditing higher-risk or problem areas more often. The audit programme should reflect process importance and previous audit results, and certification bodies expect to see a complete cycle before initial certification.
Can an external consultant perform our internal audit?
Yes. ISO 13485 allows internal audits to be carried out by competent external auditors acting on behalf of the organisation. This is a common way for smaller companies to meet the requirement that auditors do not audit their own work. The organisation remains responsible for the audit programme and for acting on findings.
What is a mock audit?
A mock audit simulates an external audit, such as an ISO 13485 certification audit, MDSAP audit or CDSCO inspection, using the same criteria, style and time pressure. It helps staff get used to being audited and identifies gaps before the real audit, when there is still time to correct them.
Can internal audits be done remotely?
Many parts of an internal audit, such as document and record review and interviews, can be done remotely using video calls and shared files. Production, warehousing and cleanroom areas are better assessed on-site. We often combine remote document review with a shorter on-site visit.
Do you help close audit findings?
Yes. After the audit we support root cause analysis, correction and corrective action planning, and we can verify closure evidence and CAPA effectiveness in a follow-up review. The decisions and implementation remain with your organisation, as ISO 13485 requires, but we make sure actions address causes rather than symptoms.