MDSAP certification allows a medical device manufacturer to undergo a single quality management system audit that is accepted by several major regulators. Medfins International helps manufacturers extend an existing ISO 13485 system to meet the country-specific requirements of each participating authority, prepare the MDSAP audit model evidence and respond confidently to findings from a recognised Auditing Organisation.
What is the Medical Device Single Audit Program (MDSAP)?
The Medical Device Single Audit Program lets an MDSAP-recognised Auditing Organisation conduct one regulatory audit of a manufacturer’s QMS that satisfies the relevant requirements of multiple regulatory authorities. The audit is based on ISO 13485:2016 plus the additional national requirements of each participating jurisdiction the manufacturer sells into.
MDSAP is not a product approval. It covers the quality system; product registrations, licences and clearances in each country are still required separately.
Participating regulators
According to the US FDA’s MDSAP information, the regulatory authority members are:
- Therapeutic Goods Administration (TGA), Australia
- Agência Nacional de Vigilância Sanitária (ANVISA), Brazil
- Health Canada
- Ministry of Health, Labour and Welfare (MHLW) and Pharmaceuticals and Medical Devices Agency (PMDA), Japan
- US Food and Drug Administration (FDA)
Official observers include the European Union, Singapore’s HSA, the UK MHRA and the WHO Prequalification of IVDs Programme. Affiliate members currently include regulators in Argentina, Israel, Kenya, the Republic of Korea, Mexico, South Africa and Taiwan. Membership changes over time, so we confirm the current list at the start of each project.
How each regulator uses MDSAP
- Health Canada: an MDSAP certificate is the accepted way to demonstrate QMS compliance for Class II to IV medical device licences.
- US FDA: MDSAP audit reports can be used in place of routine FDA surveillance inspections; for-cause and pre-approval inspections may still take place. Audits address the QMSR in 21 CFR Part 820.
- TGA, ANVISA and MHLW/PMDA: MDSAP reports and certificates are used as evidence of QMS compliance in their conformity assessment and registration processes, reducing the need for separate inspections in many cases.
Who should consider MDSAP?
- Manufacturers selling, or planning to sell, in Canada, where MDSAP is effectively required
- Exporters targeting two or more participating markets who want to reduce the number of regulatory audits
- Indian and overseas manufacturers already certified to ISO 13485 who are expanding to the USA, Brazil, Australia or Japan
Scope of the MDSAP audit
The MDSAP audit model follows a defined sequence of processes:
- Management
- Device marketing authorisation and facility registration
- Measurement, analysis and improvement
- Medical device adverse events and advisory notices reporting
- Design and development
- Production and service controls
- Purchasing
Findings are graded on a 1 to 5 scale, and higher-graded nonconformities must be reported to the regulators within short, fixed timeframes. This makes preparation more important than in a typical ISO 13485 audit.
Documents typically required
- ISO 13485 quality manual and procedures updated for each selected jurisdiction
- Procedures for adverse event reporting, recalls and advisory notices for each country
- Records of market authorisations, establishment registrations and licences held
- Design history, risk management (ISO 14971:2019) and software life-cycle records (IEC 62304) where applicable
- Supplier controls, including critical suppliers and outsourced processes
- Complaint, CAPA, internal audit and management review records
MDSAP certification process
- Market selection: confirm which participating jurisdictions will be in scope.
- Gap analysis: assess your ISO 13485 system against MDSAP audit model tasks and each country’s regulatory requirements.
- QMS update: add the country-specific procedures, reporting routes and records.
- Auditing Organisation selection: choose an MDSAP-recognised Auditing Organisation and agree the audit plan.
- Mock MDSAP audit: an internal audit following the MDSAP audit model and grading approach.
- Initial certification audit: Stage 1 and Stage 2 audits by the Auditing Organisation.
- Nonconformity response: root cause, correction and corrective action plans within the required deadlines.
- Ongoing cycle: annual surveillance audits and recertification on a three-year cycle.
Timelines and what affects them
MDSAP preparation time depends on the maturity of your existing ISO 13485 system, the number of jurisdictions selected, device risk classes, whether design is in scope, and Auditing Organisation availability. Organisations without a functioning ISO 13485 QMS should first build that foundation.
Common reasons for findings
- Adverse event and recall reporting procedures that do not reflect each country’s rules
- Records of market authorisations and registration changes not maintained
- Weak links between complaints, risk management and CAPA
- Insufficient control of critical suppliers and contract manufacturers
Benefits of MDSAP for manufacturers
- Fewer audits: one audit programme can replace several separate regulatory inspections and QMS audits.
- Predictable schedule: audits follow a planned three-year cycle rather than unannounced routine inspections in many cases.
- Market access: it supports licensing in Canada and QMS evidence for registrations in the other member markets.
- Stronger QMS: the structured audit model encourages consistent processes for complaints, reporting and changes across all markets.
MDSAP also has trade-offs. Audits usually take longer than ISO 13485 audits, the requirements of every selected market must be met, and nonconformity responses have strict deadlines. For a company supplying only India and a small number of non-member markets, ISO 13485 certification may be enough.
Keeping MDSAP certification
After certification, the QMS must keep pace with each jurisdiction. New product authorisations, changes to adverse event reporting rules, updates to the FDA QMSR and changes in Health Canada or ANVISA requirements must all be reflected in procedures before the next surveillance audit.
How Medfins International supports you
Led by a CQI and IRCA certified ISO 13485 Lead Auditor, our team maps your QMS against the MDSAP audit model and prepares the country-specific procedures auditors look for. If your QMS needs strengthening first, we start with ISO 13485:2016 certification support. We also connect MDSAP with product submissions such as US FDA 510(k), and offer supplier audit support for critical suppliers. Contact us to plan your MDSAP route.
Frequently asked questions
Does MDSAP replace product registration in each country?
Do I need ISO 13485 certification before MDSAP?
Which countries accept MDSAP?
Can Indian manufacturers get MDSAP certified?
How is MDSAP different from a normal ISO 13485 audit?
Talk to a regulatory expert
Get a free assessment of the pathway, timeline and documents for your device.
Our Services
- India Licensing (CDSCO)
- CDSCO Manufacturing Licence
- CDSCO Import Licence
- Indian Authorised Agent
- CDSCO Test Licence
- Wholesale Registration (MD-42)
- BIS Licence & ISI Mark
- GeM Registration
- Quality & Compliance
- ISO 13485:2016 Certification
- MDSAP Certification
- Internal Audit Support
- Supplier Audit Support
- Training & Workshops
- Annual Maintenance Contract
- Outsourced Regulatory Staff
- Global Market Access
- CE Marking (EU MDR / IVDR)
- US FDA 510(k)
- UAE (MOHAP / EDE)
- Saudi Arabia SFDA
- Egypt EDA
- Sri Lanka NMRA
- Singapore HSA
- Thailand FDA
- Philippines FDA
- Malaysia MDA
