Supplier Audit Support for Medical Device Manufacturers

Medical device supplier audits give manufacturers and importers evidence that critical suppliers and contract manufacturers can consistently deliver conforming products and services. Medfins International plans and conducts on-site and remote supplier audits, supports supplier evaluation and qualification, and helps you put quality agreements in place that meet ISO 13485, CDSCO, EU MDR and US FDA expectations.

What is a medical device supplier audit?

A supplier audit is a systematic assessment of a supplier’s quality system, processes and records to confirm that it can meet your specified requirements. For medical devices, it is one of the main controls used to show that purchased products and outsourced processes do not compromise device safety and performance.

Regulatory basis

  • ISO 13485:2016 clause 7.4 (Purchasing): organisations must establish criteria for evaluating and selecting suppliers based on their ability to provide conforming product, their performance and the risk associated with the product. Controls must be proportionate to risk, supplier monitoring and re-evaluation must be planned, and records must be kept.
  • ISO 13485 clause 4.1.5: the organisation remains responsible for outsourced processes and must control them, including through written quality agreements.
  • India: the Fifth Schedule QMS of the Medical Devices Rules, 2017 carries equivalent purchasing and outsourcing controls, and CDSCO auditors review supplier records during manufacturing licence audits.
  • European Union: under the EU MDR and IVDR, notified bodies assess supplier controls and may carry out unannounced audits at critical subcontractors and crucial suppliers.
  • United States: the FDA QMSR (21 CFR Part 820), effective 2 February 2026, incorporates ISO 13485 purchasing requirements by reference.

Who needs supplier audit support?

  • Manufacturers using contract manufacturers, sterilisation service providers or component suppliers
  • Legal manufacturers and brand owners who outsource most or all production
  • Importers verifying overseas manufacturers before applying for a CDSCO import licence
  • Companies preparing for notified body, MDSAP or CDSCO audits that will review supplier controls

Scope: which suppliers to audit

Not every supplier needs an on-site audit. We help you classify suppliers by risk and choose the right control:

Critical suppliers

Suppliers whose products or services directly affect device safety or performance, such as contract manufacturers, sterilisation, critical components, raw materials in patient contact, software and calibration services. These typically need an audit before approval and periodic re-audits.

Non-critical suppliers

Suppliers of lower-risk items can often be controlled through questionnaires, certificates, incoming inspection and performance monitoring.

Documents typically required

  • Supplier evaluation and selection procedure and approved supplier list
  • Purchasing specifications and drawings
  • Supplier self-assessment questionnaires and certificates, such as ISO 13485
  • Quality agreements defining responsibilities, change notification and audit rights
  • Supplier audit plans, reports and CAPA records
  • Supplier performance data, such as nonconformities, delivery and complaints

Our supplier audit process

  1. Supplier risk assessment: classify suppliers and define the controls needed for each.
  2. Pre-audit questionnaire: collect basic information and certificates.
  3. Audit plan: agree scope, criteria, dates and whether the audit is on-site, remote or hybrid.
  4. Audit execution: review of the supplier’s QMS, process controls, validation, traceability, change control and nonconformity handling.
  5. Audit report: findings with objective evidence and a recommendation on approval status.
  6. Supplier CAPA follow-up: review of the supplier’s corrective actions.
  7. Quality agreement: draft or review the agreement to reflect audit outcomes.
  8. Monitoring and re-evaluation: set the re-audit frequency based on risk and performance.

Timelines and what affects them

Supplier audit timelines depend on the supplier’s location and availability, the processes in scope, language needs, whether special processes such as sterilisation or moulding are involved, and how quickly the supplier shares documents and responds to findings.

Common supplier control gaps

  • Suppliers approved on the basis of an ISO certificate alone, without risk assessment
  • No quality agreement, or one that omits change notification requirements
  • Outsourced processes, such as sterilisation, not treated as critical
  • Re-evaluation not linked to supplier performance data
  • Findings raised with suppliers but never followed up

What a supplier audit covers

A medical device supplier audit is tailored to what the supplier provides, but usually includes:

  • QMS structure, certification status and management commitment
  • Control of documents, drawings and specifications received from customers
  • Incoming material control and the supplier’s own sub-tier suppliers
  • Process validation, especially for special processes such as sterilisation, sealing, moulding and welding
  • Cleanroom and environmental controls, where applicable
  • Calibration, maintenance and equipment qualification
  • Traceability, labelling and batch records
  • Change control and how customers are notified of changes
  • Nonconforming product, complaints and CAPA

Supplier audits and regulatory submissions

Supplier information often ends up in regulatory files. Device Master Files for CDSCO, EU MDR technical documentation and US submissions may reference critical suppliers, sterilisation sites and contract manufacturers. Audit reports and quality agreements help show that these parties are under control.

Remote versus on-site supplier audits

Remote audits reduce travel and can be arranged quickly, which makes them useful for re-audits of well-performing suppliers and for document-heavy reviews. On-site audits remain the better choice for new critical suppliers, special processes and cleanroom operations, where observing the process and the environment gives much stronger evidence. Your supplier procedure should state how the method is chosen, and we help you document that justification.

How Medfins International supports you

Our audits are led by a CQI and IRCA certified ISO 13485 Lead Auditor who understands both the supplier’s process and your regulatory obligations. We audit suppliers in India and overseas, on-site or remotely, and report in a format your certification body or regulator can review.

Supplier audits work well alongside internal audit support, ISO 13485:2016 certification and, for importers, the CDSCO import licence. Contact us to plan your supplier audit programme.

Frequently asked questions

Are supplier audits mandatory under ISO 13485?
ISO 13485 does not require an audit for every supplier. It requires risk-based evaluation, selection, monitoring and re-evaluation of suppliers. For critical suppliers and outsourced processes, an audit is usually the most convincing way to show adequate control, and certification bodies and regulators generally expect one.
Can supplier audits be conducted remotely?
Yes, for many suppliers a remote audit using document sharing and live video is acceptable, particularly for re-audits of well-performing suppliers. For special processes such as sterilisation, moulding or cleanroom manufacturing, an on-site audit gives stronger evidence. The choice should be justified by risk.
What is a quality agreement?
A quality agreement is a written document between you and a supplier that defines quality responsibilities, such as specifications, change notification, nonconformity handling, records, audit rights and regulatory support. ISO 13485 requires quality agreements for outsourced processes, and they are strongly recommended for all critical suppliers.
Can you audit overseas manufacturers for Indian importers?
Yes. Importers often want assurance about a foreign manufacturer before registering products with CDSCO. We can assess the manufacturer’s QMS, documentation and regulatory status on-site or remotely and report the results, helping you decide on the partnership and prepare the import licence application.
What happens if a supplier fails the audit?
The supplier is usually asked to submit a corrective action plan. Depending on risk, you may approve the supplier conditionally with added controls, such as increased incoming inspection, or withhold approval until actions are verified. We help you document the decision and follow-up in line with your purchasing procedure.