ISO 13485:2016 Internal Audit Checklist
Objective Evidence
- Quality manual with current approval signatures, showing scope, exclusions, process interactions, and documentation structure -- verify the approval date is within the organization's defined review cycle
- Master document list showing every QMS procedure with document number, title, current revision, effective date, and owner -- cross-check 3 random procedures to confirm the listed revision matches the actual document
- Regulatory requirements matrix mapping each applicable regulation (FDA QMSR, EU MDR, MDSAP, etc.) to specific QMS procedures that address them -- verify at least 2 entries by opening the referenced procedure
- QMS effectiveness metrics dashboard or report (e.g., CAPA closure rate, audit findings trend, complaint rate, on-time delivery) -- confirm data is current within the last quarter
- Most recent internal audit schedule and at least one completed internal audit report covering QMS adequacy -- check that findings were closed with objective evidence
- Training records for at least 2 employees showing they were trained on QMS procedures relevant to their role -- verify training dates are after the most recent procedure revision
Common Nonconformities
- Organization has documented procedures but cannot demonstrate implementation -- a procedure requires periodic quality metric reviews but no meeting minutes, dashboards, or review records exist for the required review period (Major NC).
- Regulatory requirements matrix lists 'FDA 21 CFR 820' but the organization has not updated it to reflect the transition to FDA QMSR incorporating ISO 13485 -- indicates the matrix is not maintained (Minor NC).
- Quality manual has not been approved within the organization's defined review cycle and references organizational roles and processes that no longer exist -- the manual does not reflect the current QMS (Minor NC).
- No documented procedure exists for complaint handling despite the organization receiving a significant volume of complaints annually -- a required procedure per 8.2.2 is completely absent (Major NC).
- Internal audit program covers only production processes; design control, supplier management, and management review have not been audited within the defined audit cycle (Major NC).
Auditor Tips
This clause is the 'is the QMS real?' test. Focus on the gap between documentation and implementation. Ask to see 3 random procedures and then ask the process owner to show you the last time they followed that procedure with dated records. Organizations that bought a template QMS package often have beautiful documents but zero implementation evidence. The word 'maintain' in the standard means ongoing activity -- look for evidence of review, update, and improvement, not just initial creation. FDA 483s frequently cite 'failure to establish and maintain procedures' -- the 'maintain' part is where most organizations fail.
Follow-Up Questions
- Show me the last procedure you updated -- what triggered the change and how did you verify the update was effective?
- How do you identify when a new regulatory requirement applies to your organization, and what is the process to incorporate it into your QMS?
- If I pick a random procedure from your master list, can the process owner show me evidence they followed it in the last 30 days?
What to Sample
Pull 3 procedures from the master list at random. For each, ask the process owner to show you the most recent record proving the procedure was followed. Check that training records exist for personnel performing those activities.
Objective Evidence
- Quality manual section explicitly stating the organization's regulatory role(s) per each market -- verify alignment with actual business activities (e.g., if they claim 'manufacturer' in the EU, confirm they are the entity placing the device on the EU market)
- Regulatory role matrix mapping each role to the applicable regulatory obligations (e.g., EU MDR Article 10 for manufacturers, Article 13 for importers) -- spot-check that obligations listed are accurate
- Legal entity registrations and establishment registrations (FDA establishment registration, EU SRN, EUDAMED actor registration) -- confirm they match the declared roles
- Authorized representative agreements or distribution agreements where applicable -- verify they are current and signed by both parties
- Organizational chart showing where regulatory affairs and quality functions report -- verify alignment with declared roles
Common Nonconformities
- Organization performs contract manufacturing for OEM clients but has documented its role only as 'manufacturer' without acknowledging the OEM relationship or defining responsibilities in quality agreements (Minor NC).
- Quality manual states the organization is the 'legal manufacturer' for the EU market but the EU Authorized Representative agreement has lapsed and has not been renewed -- documented regulatory roles are inconsistent with current contractual arrangements (Major NC).
- Organization distributes devices in multiple markets but the regulatory role documentation only addresses a subset of jurisdictions -- no documented roles exist for some markets where they actively sell (Minor NC).
- No documented role definition exists at all -- the quality manager verbally states they are a manufacturer but this is not captured in any QMS document (Minor NC).
Auditor Tips
This is frequently overlooked because organizations assume their role is obvious. Press on it -- especially for organizations that both manufacture their own devices AND contract manufacture for others, or organizations that import and relabel devices. Each role has different regulatory obligations and the QMS must address all of them. Under EU MDR, getting the role wrong has serious legal consequences. Ask about all markets, not just the primary one. Check that role definitions match actual regulatory registrations.
Follow-Up Questions
- Do you perform any contract manufacturing or private labeling for other companies? If so, how is the regulatory responsibility divided?
- In which markets do you sell, and have you documented your regulatory role for each market?
- If your role changed -- say you started importing devices from a new supplier -- how would that trigger updates to your QMS?
What to Sample
Compare the declared regulatory roles in the quality manual against actual business activities. Check 2 regulatory registrations to confirm they match. If the organization acts as an authorized representative or importer, verify quality agreements are current.
Objective Evidence
- Process inventory or register listing all QMS processes grouped by category (management, core/realization, support, measurement) with named process owners and risk classifications
- Process interaction diagram or matrix showing inputs, outputs, and dependencies between processes -- verify it includes feedback loops (e.g., complaint data feeding back to design)
- Risk-based process control matrix showing how control intensity varies by process risk level -- confirm that higher-risk processes (e.g., sterilization, design control) have more controls than lower-risk ones (e.g., document control)
- Evidence that the process inventory has been reviewed and updated -- look for revision history or management review minutes where process changes were discussed
- Process performance indicators assigned to each process -- verify at least 3 processes have measurable KPIs being tracked
Common Nonconformities
- Process map does not include all processes the organization actually operates -- several distinct processes including calibration, environmental monitoring, and software development are not represented anywhere (Minor NC).
- All processes are assigned identical controls regardless of risk -- the same review frequency, same approval levels, and same monitoring intensity for sterilization validation as for office supply purchasing (Minor NC -- systemic if it masks inadequate controls on high-risk processes).
- Process interactions are described in a flowchart but critical feedback loops are missing -- complaint data does not flow back to design, and CAPA outputs do not feed into management review inputs (Observation).
Auditor Tips
This is a gateway clause. If the organization cannot show you a coherent process map with risk-differentiated controls, every downstream clause will have problems. Look for processes that are missing from the map but clearly exist (tip: check the org chart for departments not represented in the process inventory). The risk-based approach does NOT require formal FMEA on every process -- it means the organization has thought about which processes are high-risk and applied proportionate controls. Ask 'why does this process have this level of control?' and listen for risk-based reasoning versus 'because that is how we always did it.'
Follow-Up Questions
- Which of your processes do you consider highest risk, and how did you arrive at that conclusion?
- When was the last time you added or removed a process from your QMS, and what triggered that change?
- Show me an example where complaint or CAPA data caused you to change a process.
What to Sample
Select 2 processes from the inventory -- one high-risk and one low-risk. Compare the documented controls for each to verify the risk-based approach is applied in practice, not just on paper.
Objective Evidence
- Process determination methodology document or procedure describing how processes were identified -- check it references the organization's regulatory roles as an input
- Complete process list cross-referenced to ISO 13485 clauses showing which processes address which requirements -- spot-check 3 clauses to verify coverage
- Role-specific process requirements analysis showing, for example, additional post-market surveillance processes required for EU MDR manufacturers versus those required for distributors
- Gap analysis or mapping showing that all 'shall' requirements in ISO 13485 are addressed by at least one identified process
- Evidence of periodic review of process adequacy (e.g., management review minutes, internal audit findings related to missing processes)
Common Nonconformities
- Organization recently expanded into a new regulatory market but has not identified market-specific processes for adverse event reporting, registration maintenance, or local labeling requirements (Major NC if devices are already being shipped).
- Process inventory is a direct copy of a consulting template and includes processes the organization does not actually perform (e.g., 'sterilization process' when all products are non-sterile) while missing processes it does perform (e.g., software development, field service) (Minor NC).
- No documented rationale exists for how processes were identified -- the quality manager states 'we just knew what we needed' but cannot show any systematic determination approach (Observation).
- Post-market surveillance process is not identified despite the organization being a Class IIb device manufacturer under EU MDR, where PMS is a mandatory and extensive requirement (Major NC).
Auditor Tips
The key phrase is 'taking into account the roles undertaken by the organization.' A contract sterilizer has different process needs than a design house. Ask what triggered the current process list and whether it has been validated against both the standard's requirements and applicable regulations. Organizations that grow through acquisition often have process gaps where legacy systems were never harmonized. Check for processes that ISO 13485 requires but are easy to miss: post-market surveillance, advisory notice management, and regulatory reporting.
Follow-Up Questions
- Have you entered any new markets in the last 2 years? If so, show me how that triggered a review of your process inventory.
- Walk me through how you verified that your process list covers all applicable regulatory requirements, not just ISO 13485.
- Are there any processes you considered including but decided were not needed? Show me that rationale.
What to Sample
Compare the process inventory against the ISO 13485 table of contents and the organization's declared regulatory roles. Identify at least one process that might be missing and ask about it.
Objective Evidence
- Process risk assessment records showing risk evaluation criteria (likelihood, severity, detectability) applied to QMS processes -- verify assessments are completed for all identified processes, not just production processes
- Risk-based control matrix mapping process risk levels to control requirements (e.g., high-risk = validated process + 100% inspection, medium-risk = periodic sampling, low-risk = self-inspection) -- confirm the matrix is followed in practice
- Process control plans for at least 2 processes at different risk levels -- compare the control points, frequencies, and approval authorities to verify proportionality
- Evidence that process risk assessments are reviewed when changes occur -- look for risk assessment updates linked to CAPA actions or management of change records
- Documentation showing that 'risk' in this context addresses product safety, regulatory compliance, and QMS effectiveness -- not just production risk
Common Nonconformities
- Organization has a risk management file per ISO 14971 for product risk but has not applied any risk-based thinking to QMS process controls -- sterilization validation and label printing have the same quarterly review frequency and same approval level despite dramatically different risk profiles (Minor NC).
- Risk assessment exists but was performed once during initial QMS setup and never updated despite multiple CAPA actions that identified process control weaknesses -- the risk assessment does not reflect current reality (Minor NC).
- Risk-based control matrix assigns the same 'medium' risk to all processes -- no differentiation exists, defeating the purpose of the risk-based approach (Observation).
- Critical process (final device testing) is controlled with the same rigor as a support process (visitor management), while a known-problematic process (supplier receiving inspection) with multiple CAPAs has a 'low risk' rating -- risk ratings do not reflect actual process performance (Major NC if product safety is affected).
Auditor Tips
This is about QMS process risk, not product risk management per ISO 14971 -- though the concepts overlap. Many organizations confuse the two or only address product risk. The standard says 'appropriate processes' -- meaning controls must be proportionate. Red flags: all processes rated the same risk level, risk assessments that have never been updated, or risk ratings that contradict CAPA/complaint data. A process with 5 CAPAs in the last year should not be rated low risk. Ask 'what would happen to patient safety if this process failed?' to test whether risk thinking is real.
Follow-Up Questions
- If a process has had repeated CAPAs or findings, does that trigger a reassessment of its risk level? Show me an example.
- How do you distinguish between product risk (ISO 14971) and QMS process risk in your risk assessments?
- What criteria do you use to decide that a process needs validation versus verification?
What to Sample
Pick the process with the most CAPAs in the last 2 years. Check whether its risk rating reflects that history. Then pick a process with zero CAPAs and compare control intensity.
Objective Evidence
- High-level process interaction diagram (process landscape) showing all QMS processes with directional arrows indicating sequence and data/material flow -- verify it includes feedback loops, not just linear flow
- SIPOC diagrams (Suppliers, Inputs, Process, Outputs, Customers) for at least 3 key processes -- verify that the outputs of one process match the documented inputs of the downstream process
- Process interface definitions or handoff procedures documenting what information or materials transfer between processes, who is responsible, and what acceptance criteria apply at each handoff
- Turtle diagrams for critical processes showing resources, methods, inputs, outputs, KPIs, and risks
- Evidence that process interactions have been validated in practice -- e.g., internal audit reports that tested handoffs between departments, or CAPA records that identified interface failures
Common Nonconformities
- Process map shows a linear flow from design through production to distribution but has no feedback loops from post-market surveillance, complaint handling, or CAPA back to design or production -- this is a systemic gap (Minor NC).
- Process interaction diagram exists in the quality manual but was created during initial QMS setup and has not been updated to reflect a major reorganization that changed the departmental structure (Minor NC).
- SIPOC for the purchasing process lists 'approved supplier' as an output but the supplier qualification process does not list 'purchasing requirements' as an input -- the handoff is undefined (Observation).
- No documentation of process interactions exists at all -- the quality manager explains interactions verbally but cannot show any diagram, matrix, or written description (Minor NC).
Auditor Tips
The most common weakness is linear-only process maps that show no feedback. In a real QMS, data flows backward: complaints feed design improvements, CAPA findings modify production processes, management review decisions reallocate resources. Ask 'if a complaint comes in about a design issue, show me the path that information takes to reach the design team.' If they cannot trace it through their documented interactions, the linkage is broken. Also check that support processes (calibration, training, document control) are shown as enabling the core processes, not floating in isolation.
Follow-Up Questions
- Show me an example where data from a complaint or CAPA resulted in a change to a process upstream -- trace the path through your process interactions.
- When you reorganized your department structure, did you update your process interaction documentation? Show me the before and after.
- How does your management review process receive inputs from all other processes? Show me the linkage.
What to Sample
Trace one real complaint from receipt through investigation, CAPA, and back to a process improvement. Verify each handoff matches the documented process interaction.
Objective Evidence
- Process control plans or process descriptions for at least 3 processes showing all five elements (criteria/methods, resources, actions, monitoring, records) are explicitly addressed
- Process owner documentation showing assigned accountability for each of the five elements per process
- Example of a process that was found deficient in one of the five elements and the corrective action taken to address it
- Internal audit checklist showing these five elements are systematically verified during process audits
- Management review input data that includes process performance against the five elements
Common Nonconformities
- Process descriptions define criteria and methods (element a) but do not address monitoring and measurement (element d) -- a significant proportion of processes have no defined KPIs or monitoring activities (Minor NC).
- Record requirements (element e) are defined in procedures but actual records are not being maintained -- the CAPA process requires effectiveness check records but none have been completed for recent CAPAs (Major NC).
- Resource needs (element b) are not documented for any process -- when a key technician was on leave, no qualified backup existed because resource planning was never formalized (Observation).
Auditor Tips
These five elements form a checklist-within-a-checklist. For any process you audit in detail, verify all five are addressed. The most commonly neglected elements are (c) actions to achieve planned results (organizations monitor but do not act on data) and (d) monitoring and measurement (organizations assume processes work without verifying). Use this clause as a framework when auditing any individual process later in the audit.
Follow-Up Questions
- Pick one of your core processes. Walk me through each of the five elements and show me the evidence for each.
- When monitoring shows a process is not achieving planned results, what triggers corrective action? Show me an example.
- How do you determine what records are needed to demonstrate conformance for each process?
What to Sample
Select 3 processes at random. For each, verify all five elements are documented AND implemented with evidence. Focus on elements (c) and (d) which are most commonly neglected.
Objective Evidence
- Process control plans specifying control parameters, acceptance criteria, control limits, and measurement methods for each critical process step -- verify limits are quantitative where possible, not just 'acceptable'
- Standard operating procedures (SOPs) or work instructions defining the specific methods for process execution -- check that they include decision criteria for pass/fail at key checkpoints
- Process validation records (IQ/OQ/PQ) for processes where output cannot be verified by subsequent inspection -- confirm validation is current and covers the actual operating parameters
- Statistical process control (SPC) charts or equivalent monitoring data showing processes are operating within defined limits
- Training records showing personnel are trained on the specific criteria and methods for processes they operate
- Process flow diagrams showing inspection/decision points with documented acceptance criteria at each point
Common Nonconformities
- SOP for incoming inspection defines the method as 'visual inspection per drawing' but the drawing has no quantitative acceptance criteria -- operators judge acceptability subjectively, leading to inconsistent accept/reject decisions between shifts (Major NC if affecting critical components).
- Process control plan for soldering specifies a temperature range of 350-380C but the actual process parameter monitoring shows the process routinely operates at 390C with no investigation or control plan update (Minor NC).
- Effectiveness criteria for the CAPA process is defined as 'CAPA is effective' with no measurable definition of what constitutes effectiveness -- resulting in 100% of CAPAs being closed as 'effective' despite recurring issues (Minor NC).
- No documented criteria exist for the design review process -- design reviews occur but there are no defined entry criteria, review checklists, or exit criteria to ensure reviews are thorough (Observation).
Auditor Tips
Look for vague criteria like 'acceptable,' 'adequate,' or 'per procedure' without quantitative definitions. These are red flags for subjective decision-making. The best organizations have specific, measurable criteria at every decision point. Ask operators what their acceptance criteria are without the procedure in front of them -- if they cannot state them, the criteria are not effectively communicated. For validated processes, check that actual operating parameters match the validated ranges.
Follow-Up Questions
- Show me how an operator knows whether a process step has passed or failed -- what specific criteria do they use?
- When was the last time you changed acceptance criteria for a process, and what data drove that change?
- For your validated processes, show me that current operating parameters are within the validated ranges.
What to Sample
Select one production process and one quality process. For each, trace from the procedure through to actual records to verify that documented criteria are measurable and are actually being applied consistently.
Objective Evidence
- Resource allocation matrix or staffing plan showing personnel assigned to each QMS process, including backup/cross-trained personnel -- verify at least 2 critical processes have documented backup coverage
- Training matrix showing required competencies per process and current training status of all personnel -- identify any gaps where personnel lack required training
- Equipment and infrastructure lists per process showing what is needed, what is available, and calibration/maintenance status -- spot-check 2 pieces of equipment for current calibration status
- Information systems and data access documentation showing what information each process needs and how it is made available (e.g., document management system access, ERP system, quality data dashboards)
- Budget or resource allocation records showing management commitment to providing resources -- check for evidence of resource requests that were approved and fulfilled
Common Nonconformities
- Single-point-of-failure in quality assurance: only one person is trained to perform final product release, with no documented backup -- when this person was unavailable, product shipments were delayed or released without proper review (Major NC if released without review).
- Personnel requiring training on a recently implemented test method have not all completed the training -- some inspectors are still performing inspections using the old method despite the procedure change (Major NC).
- Calibration laboratory lacks temperature and humidity monitoring despite calibration procedures requiring controlled conditions -- calibration results may not be reliable (Minor NC).
- Production area document stations have outdated versions of work instructions because the document management system was changed and old terminals were never updated to access the new system (Minor NC).
Auditor Tips
Resource adequacy is best assessed by walking the floor, not reading procedures. Look for signs of resource constraints: overtime logs, training backlogs, expired calibrations, unfilled positions. Ask 'what happens when your key quality person is on vacation?' to expose single-point-of-failure risks. Information availability is equally important -- if operators need to look up specifications but the computer system is slow or inaccessible, the information is effectively unavailable. Check that resources match the actual workload, not just the theoretical requirement.
Follow-Up Questions
- What happens when your final inspector is unavailable -- who releases product and how are they qualified?
- Show me your training backlog -- are there any overdue training requirements right now?
- Has a resource constraint ever caused a quality issue? Show me the CAPA or investigation.
What to Sample
Check the training matrix for 2 critical processes to verify all assigned personnel are currently trained. Verify calibration status for 3 pieces of measurement equipment. Ask about backup coverage for single-person roles.
Objective Evidence
- CAPA log showing corrective and preventive actions linked to specific process performance issues -- verify at least 3 CAPAs were triggered by process monitoring data (not just complaints or audit findings)
- Process improvement project records or continuous improvement logs showing data-driven actions to improve process performance -- check for measurable before/after results
- Management review action items related to process effectiveness with evidence of completion and verification of effectiveness
- Trend analysis reports showing process KPIs over time and documented actions taken when trends indicate declining performance
- Preventive action records showing proactive steps taken to prevent process failures before they occur -- distinguish from reactive corrective actions
Common Nonconformities
- Process KPIs have been declining for 3 consecutive quarters (e.g., first-pass yield dropped from 95% to 88%) but no corrective action, investigation, or management escalation occurred -- monitoring exists but there is no action trigger (Major NC).
- CAPA effectiveness verification is performed as a checkbox exercise -- every CAPA is marked 'effective' within the minimum waiting period without actual data analysis or re-measurement of the original problem metric (Minor NC).
- Management review identified multiple action items in the last review but none have been completed or tracked to closure within a reasonable timeframe -- no accountability mechanism exists (Minor NC).
- Organization has no preventive actions in the recent review period -- all quality actions are reactive (complaints, audit findings, deviations) with no evidence of proactive risk mitigation or process improvement (Observation).
Auditor Tips
The difference between a mature and immature QMS is whether data drives action. Many organizations monitor KPIs beautifully but never act on negative trends. Ask 'when this metric went red, what did you do?' If the answer is 'nothing yet,' that is a finding. Also check CAPA effectiveness -- organizations that close 100% of CAPAs as 'effective' are not being honest with themselves. Look for recurrence of the same issue after CAPA closure as evidence of ineffective corrective action. FDA investigators specifically look for 'adequate corrective action' under QMSR.
Follow-Up Questions
- Show me a process KPI that went outside acceptable limits. What action was taken, and did the metric recover?
- When was the last time a CAPA was found to be ineffective? What happened next?
- Give me an example of a preventive action -- something you did proactively before a problem occurred.
What to Sample
Review the CAPA log for the last 12 months. Select 2 CAPAs that were closed as 'effective' and verify the original problem did not recur within 6 months of closure. Check trend data for the related process KPI.
Objective Evidence
- Process monitoring plan identifying what is monitored/measured for each process, measurement methods, frequency, responsibility, and action limits -- verify it covers all identified QMS processes, not just production
- KPI dashboards or metric reports showing actual process performance data with targets and trends -- confirm data is current (within last month) and includes historical trending
- Process performance analysis reports showing data interpretation, trend identification, and conclusions -- verify analysis goes beyond raw data to actionable insights
- Escalation criteria or action triggers defining when process performance requires intervention (e.g., if yield drops below 90%, initiate investigation within 48 hours)
- Records of management review of process performance data with documented decisions and actions
Common Nonconformities
- Organization monitors 6 production KPIs but has zero metrics for support processes (document control, training, calibration, internal audit) -- support process effectiveness is assumed rather than measured (Minor NC).
- KPI dashboard shows data collection is current but no trend analysis, statistical evaluation, or comparison to targets has been performed in an extended period -- data is collected but not analyzed (Minor NC).
- Process monitoring for supplier quality tracks incoming inspection defect rates but the action trigger threshold is set at 25% defect rate -- effectively no action would ever be triggered as the worst supplier is at 8% (Observation).
- Customer complaint rate is tracked monthly but the metric is raw complaint count rather than complaint rate per device shipped, making it useless for trending as sales volume changes (Observation).
Auditor Tips
The standard says 'monitor, measure as appropriate, and analyse' -- all three verbs matter. Organizations that collect data but never analyze it are missing the point. Not every process needs quantitative measurement (some can be monitored through audits, reviews, or observation), but every process needs some form of monitoring. Challenge whether the chosen metrics actually reflect process effectiveness -- vanity metrics that always look good are worthless. Ask 'has this metric ever triggered an action?' If the answer is never, the metric or the threshold may be wrong.
Follow-Up Questions
- Has any of your process metrics ever exceeded the action trigger? Show me what happened.
- How did you decide what to measure for each process -- what was the rationale for choosing these specific KPIs?
- Show me the monitoring data for your document control process. How do you know document control is effective?
What to Sample
Ask to see the monitoring data for 3 processes: one production, one support (e.g., training or document control), and one management (e.g., management review). Verify all three have active monitoring with current data and defined action triggers.
Objective Evidence
- Records matrix or index listing all required record types, mapping each to the ISO 13485 clause and regulatory requirement it satisfies, with defined retention periods and storage locations
- Record retention schedule showing retention periods for each record type, with justification based on device lifetime, regulatory requirements, and the 2-year minimum per 4.2.5
- Three specific records retrieved on request: one design record, one production record, and one quality record -- verify each is complete, legible, properly identified, and stored per procedure
- Electronic records system validation summary showing the system used for record storage is validated per 4.1.6
- Regulatory compliance evidence file or equivalent showing how records demonstrate compliance to each applicable regulation
Common Nonconformities
- Records matrix identifies required record types but the actual retention schedule only covers a subset of them -- the remaining record types have no defined retention period, storage location, or disposition method (Minor NC).
- Design history file (DHF) for the most recent product development project is incomplete -- design review records reference meeting minutes that cannot be located, and several design verification test reports are missing (Major NC).
- Production batch records (DHR) for lot numbers shipped in Q1 are stored in an unlabeled cardboard box in a non-climate-controlled storage room alongside cleaning supplies -- records are at risk of deterioration and are not readily retrievable (Minor NC).
- Electronic quality records are stored on a shared network drive with no access controls, no audit trail, and no backup -- any user can modify or delete records without detection (Major NC).
Auditor Tips
Records are the auditor's primary evidence source. When you request a specific record and it takes more than 15 minutes to retrieve, the retrieval system is ineffective. Test this by requesting a specific batch record from years ago and timing the retrieval. Also check for completeness -- partial records are almost as problematic as missing records. Under FDA QMSR, inadequate record-keeping is one of the most common 483 observations. Pay special attention to electronic records -- if the organization uses spreadsheets or shared drives for quality records, check for data integrity controls (audit trails, access controls, backup, validation).
Follow-Up Questions
- If I give you a specific lot number from 18 months ago, how long would it take you to retrieve the complete batch record? Let us try it.
- How do you ensure electronic records cannot be altered without detection?
- When was the last time you could not locate a required record? What was the outcome?
What to Sample
Request 3 specific records: a DHR from 6+ months ago, a training record for a current employee, and a CAPA record from the last year. Time the retrieval. Verify each is complete, legible, and properly controlled.
Objective Evidence
- Change control procedure for QMS process changes -- verify it requires all three evaluations: QMS impact, product impact, and regulatory compliance
- Change request log showing all process changes in the last 12 months with status, approvals, and completion dates
- A specific completed change record showing the three required evaluations were performed with documented rationale and conclusions
- Evidence of change communication -- training records, notifications, or meeting minutes showing affected personnel were informed of the change
- Post-change effectiveness review records showing the change achieved its intended outcome without unintended consequences
Common Nonconformities
- Organization moved final inspection from one building to another but did not evaluate the impact on the QMS (different environmental controls, different equipment calibration status, different document access points) or on product quality (temperature-sensitive testing in an unconditioned space) (Major NC).
- Change control log shows multiple process changes in the last year but only a minority have completed impact assessments -- the remainder were implemented with 'assessment to follow' and were never completed (Minor NC).
- A manufacturing process parameter was changed based on an operator suggestion without going through change control -- the change was discovered during a subsequent internal audit (Major NC if affecting a validated process).
- Process changes are evaluated for product impact but QMS impact is never assessed -- a change to the purchasing process eliminated a verification step, which degraded supplier control but was not identified because only product impact was considered (Minor NC).
Auditor Tips
Process changes are a top finding area because organizations often change processes informally without going through change control. Ask 'has anything changed in the last 6 months?' and then check whether those changes went through the formal process. Look especially at changes driven by cost reduction, efficiency, or customer requests -- these are most likely to bypass quality evaluation. The three required evaluations (QMS impact, product impact, regulatory control) must all be performed for every change. Missing any one is a finding. Post-change effectiveness review is implied by 4.1.3(c) and is a best practice to verify.
Follow-Up Questions
- What was the most recent change to a manufacturing process, and can you walk me through the complete change record?
- Have you ever had to reverse a process change because it had unintended consequences? Show me that record.
- How do you capture informal changes -- for example, if an operator starts doing something differently?
What to Sample
Review the change log for the last 12 months. Select 2 changes and verify all three evaluations were performed. Ask floor personnel about any changes not in the log.
Objective Evidence
- QMS impact assessment form or record for the specific change showing all affected processes, documents, training, and system elements were identified and evaluated
- Cross-functional review records showing that departments beyond the originating department were consulted on QMS impact (e.g., quality, regulatory, operations, training)
- Document change requests triggered by the process change -- showing that related procedures, work instructions, and forms were updated
- Training impact assessment showing whether personnel need retraining as a result of the process change
- Internal audit plan updates reflecting the process change as a priority area for the next audit cycle
Common Nonconformities
- QMS impact assessment is a single-line entry stating 'no impact on QMS' for a change that moved all document control from paper to electronic -- clearly this affects document control procedures, training, record retention, and infrastructure requirements (Major NC).
- Impact assessment was performed by the process owner alone with no cross-functional input -- quality, regulatory, and training were not consulted on a change to the sterilization process that requires procedure updates, revalidation, and operator retraining (Minor NC).
- Process change triggered updates to 3 SOPs but the training matrix was not updated to reflect new training requirements -- personnel continue to operate under old training records that do not cover the revised procedures (Minor NC).
Auditor Tips
A genuine QMS impact assessment should identify ripple effects: does the change affect procedures that need updating? Training that needs refreshing? Metrics that need adjusting? Audit plans that need revising? If the impact assessment consistently says 'no impact,' either the changes are truly trivial or the assessment is not being done seriously. Cross-functional review is critical -- the process owner often cannot see impacts to other departments. Ask who participated in the impact assessment and whether they signed off.
Follow-Up Questions
- Who participated in this QMS impact assessment? Was it cross-functional or done by one person?
- Show me that all documents affected by this change were identified and updated.
- How did you verify that all affected personnel were retrained after this change?
What to Sample
Take one recent process change. Trace the QMS impact assessment to verify all affected documents were updated, all affected personnel were retrained, and cross-functional input was obtained.
Objective Evidence
- Product impact assessment record showing evaluation of how the process change affects device quality, safety, efficacy, and performance -- look for specific, documented rationale, not generic statements
- Risk management file updates (ISO 14971) triggered by the process change -- verify whether the process change introduces new hazards or changes residual risk levels
- Verification or validation plans triggered by the change -- if the change affects a validated process, confirmation that revalidation was performed or a justified rationale for why it was not needed
- Regulatory impact assessment showing whether the change requires notification to regulatory bodies (e.g., FDA letter-to-file, NBOG change notification, supplement submission)
- Post-change product testing or inspection data confirming product continues to meet specifications after the change
Common Nonconformities
- Manufacturing process change (new adhesive supplier for device assembly) was evaluated only for cost and delivery impact but not for biocompatibility, bond strength, or aging performance -- product impact assessment does not exist (Major NC).
- Risk management file was not updated after a process change that altered the sterilization cycle parameters -- the existing risk assessment references the old parameters and does not reflect current processing conditions (Major NC).
- Product impact assessment states 'no impact on product' for a change to final inspection sampling plan from 100% to AQL-based sampling -- this directly affects the probability of nonconforming product reaching the market and was not evaluated for product safety impact (Minor NC).
- Process change required revalidation per the organization's own procedure but revalidation was deferred indefinitely due to cost -- product continues to be manufactured under the changed process without validation evidence (Major NC).
Auditor Tips
This is the patient safety question. Every process change must be evaluated for whether it could affect the device that patients or healthcare providers use. The evaluation should be specific and technical, not a rubber stamp. Red flags: assessments that always conclude 'no impact,' assessments performed without engineering or clinical input, and changes to validated processes without revalidation consideration. Under EU MDR, significant changes may require notified body notification. Under FDA QMSR, certain changes require premarket submissions. If the organization does not assess regulatory impact, they risk unauthorized changes.
Follow-Up Questions
- For this change, did you update the risk management file? If not, why not?
- Was revalidation required for this change? Show me the rationale for your decision.
- Did you notify any regulatory body about this change? How did you determine whether notification was required?
What to Sample
Select 2 process changes from the last year. Verify each has a product impact assessment with technical rationale. Check whether risk files and validation records were updated as needed.
Objective Evidence
- Completed change control form with all required approvals (originator, quality, regulatory, management as applicable) dated before the change was implemented
- Validation or verification records generated as a result of the change -- confirm they were completed before the change was put into production use
- Training records showing all affected personnel were trained on the change before they were required to work under the new process
- Communication records (emails, meeting minutes, notifications) showing the change was communicated to all affected parties including, where applicable, suppliers, customers, and regulatory bodies
- Regulatory submission or letter-to-file documentation if the change requires regulatory notification -- or a documented rationale for why notification was not required
Common Nonconformities
- Change was implemented before the change control form was approved -- the change ran for several weeks without formal authorization, and multiple production lots were manufactured under the unapproved change (Major NC).
- Change control form shows quality approval but not regulatory approval, despite the change affecting a 510(k)-cleared manufacturing process -- regulatory impact was never formally assessed or approved (Minor NC).
- Personnel training on the process change was not completed until well after implementation -- operators were working under the new process without training during the gap period (Minor NC).
- Supplier providing a critical component was not notified of a change to incoming inspection acceptance criteria that affects their quality agreement obligations (Observation).
Auditor Tips
The key audit point is timing: was the change formally approved before implementation, or was it retroactively documented? Check dates carefully. The approval date must precede the implementation date. Also verify that all required approvals were obtained -- many organizations have a change control procedure that requires regulatory approval but it is routinely skipped. Ask for the change control log and check for any entries that are still 'open' or 'pending' but already implemented. These are unauthorized changes.
Follow-Up Questions
- Show me the dates: when was this change approved, and when was it first implemented? Do those dates align with your procedure?
- Are there any currently open change requests where the change has already been implemented but approvals are pending?
- How do you ensure that no process change is implemented without completing the required approvals first?
What to Sample
Review the change control log for any entries where implementation date precedes approval date. Select 2 changes and verify the complete approval chain was obtained before implementation.
Objective Evidence
- Outsourced process register listing all processes that affect product conformity with the external party name, process description, risk classification, and quality agreement reference number -- verify completeness by cross-referencing the process map
- Signed quality agreements for at least 2 outsourced processes -- verify they define quality requirements, acceptance criteria, right to audit, communication protocols, change notification, nonconformance reporting, and record retention obligations
- Risk assessments for outsourced processes showing risk level and corresponding control strategy -- verify higher-risk processes have more stringent controls
- Supplier monitoring records for outsourced processes (performance scorecards, audit reports, incoming inspection data, nonconformance logs) -- verify monitoring is active and current
- Evidence that the organization retains ultimate responsibility for outsourced process conformity -- e.g., CAPA records for supplier-related issues, management review of supplier performance
Common Nonconformities
- Organization outsources sterilization (ethylene oxide) to a contract sterilizer but has no written quality agreement -- the relationship is governed only by a commercial purchase order that does not address quality requirements, change notification, or right to audit (Major NC).
- Quality agreement with a subcontractor references a superseded revision of the applicable acceptance standard -- the quality requirements in the agreement are outdated and do not reflect current industry acceptance criteria (Minor NC).
- All outsourced processes are subject to identical annual audit controls regardless of risk -- the company that performs critical biocompatibility testing receives the same level of oversight as the company that provides courier services (Observation).
- Organization outsources software development but does not include it on the outsourced process register because 'software is not manufacturing' -- software directly affects device safety and performance and must be controlled as an outsourced process (Major NC for SaMD or software-controlled devices).
- Supplier monitoring data shows an outsourced process has an elevated defect rate over a sustained period but no corrective action has been initiated and the supplier's performance rating was not downgraded (Minor NC).
Auditor Tips
Outsourced process control is a top-5 audit finding area globally. Organizations frequently fail to identify all outsourced processes (missing software development, design services, regulatory consulting, calibration, testing laboratories). Written quality agreements are mandatory -- a purchase order is not a quality agreement. The organization cannot delegate responsibility by outsourcing; they remain accountable as if they performed the work in-house. FDA and notified bodies specifically look at whether the organization can demonstrate they control their outsourced processes effectively. Ask 'what would you do if this supplier shut down tomorrow?' to test contingency planning.
Follow-Up Questions
- Are there any outsourced processes not on this list? What about calibration, testing, design services, software, regulatory consulting, or distribution?
- Show me the quality agreement for your highest-risk outsourced process. Does it include right to audit, change notification, and nonconformance reporting?
- When was the last time you audited this outsourced process provider? What did you find?
What to Sample
Select the 2 highest-risk outsourced processes. Review quality agreements for completeness. Check monitoring data for the last 12 months. Verify at least one has been audited within the defined audit cycle.
Objective Evidence
- Outsourced process monitoring schedule defining monitoring methods (audit, incoming inspection, performance review, certificate review), frequency, and responsibility for each outsourced process
- Supplier performance scorecards or dashboards showing objective metrics (defect rate, on-time delivery, audit scores, complaint rate) for outsourced processes -- verify data is current and trended over time
- Supplier audit reports for outsourced process providers completed within the defined audit cycle -- verify findings were tracked to closure
- Incoming inspection or verification records for outsourced process outputs -- check for objective evidence that the outsourced work is verified against defined acceptance criteria
- Nonconformance or CAPA records related to outsourced process failures -- verify the organization took ownership and drove resolution
Common Nonconformities
- Monitoring plan calls for periodic supplier audits but the highest-risk outsourced process (e.g., contract sterilization) has not been audited within the required cycle due to 'scheduling difficulties' -- no alternative monitoring was put in place during the gap (Major NC).
- Incoming inspection of outsourced assemblies is 'certificate of conformance review only' with no physical verification -- when multiple lots were subsequently found defective at final test, the certificates had all been accepted as conforming (Minor NC).
- Supplier scorecard shows an outsourced process conformance has trended downward over multiple review periods but no escalation, CAPA, or management review discussion has occurred (Minor NC).
- Organization monitors production outsourcing but has no monitoring mechanism for the outsourced regulatory consulting firm that prepares their 510(k) submissions and EU technical files (Observation).
Auditor Tips
Monitoring must be active, not passive. Accepting certificates of conformance without any physical verification is passive -- and risky. Look for evidence that the organization actually verifies outsourced work through a combination of methods: audits, incoming inspection, performance trending, and qualification testing. The frequency and intensity of monitoring should be risk-based. Challenge organizations that have never found a problem with an outsourced process -- either they are not looking hard enough, or they are not monitoring effectively. Ask to see the worst-performing outsourced process and what was done about it.
Follow-Up Questions
- Show me the monitoring data for your worst-performing outsourced process. What actions have you taken?
- Have you ever had to disqualify or escalate a supplier providing an outsourced process? Walk me through that situation.
- Beyond certificate review, what physical verification do you perform on outsourced process outputs?
What to Sample
Review monitoring records for 2 outsourced processes. Verify that the defined monitoring frequency is being met and that performance data is being reviewed. Check for at least one instance where unsatisfactory performance triggered action.
Objective Evidence
- Quality policy or quality manual statement explicitly acknowledging retained responsibility for outsourced processes
- CAPA records where the organization took ownership of nonconformities originating from outsourced processes -- verify the organization drove root cause analysis and corrective action, not just passed it to the supplier
- Management review records showing outsourced process performance is reviewed at the management level with documented decisions and accountability
- Regulatory submission records where the organization (not the supplier) signed off on data generated by outsourced processes
- Customer complaint records related to outsourced process issues showing the organization handled the complaint and resolved it -- not redirected the customer to the supplier
Common Nonconformities
- Customer complaint about a labeling error was forwarded directly to the contract labeling company with no CAPA opened by the organization -- the organization treated the complaint as the supplier's problem rather than its own (Major NC).
- Three consecutive nonconforming lots from an outsourced assembly process were returned to the supplier but the organization opened no CAPA, performed no root cause analysis, and did not assess whether previously shipped product was affected (Major NC).
- Management review records do not include outsourced process performance as an input -- supplier quality data is managed at the operational level with no executive visibility or accountability (Minor NC).
- When asked about a regulatory nonconformance related to outsourced testing, the quality manager stated 'that is the test lab's responsibility, not ours' -- demonstrating a fundamental misunderstanding of retained accountability (Major NC in mindset, translates to Minor NC for documentation gap).
Auditor Tips
This requirement tests organizational culture. The standard is clear: outsourcing does not transfer responsibility. The organization is as accountable for outsourced work as for in-house work. Look for blame-shifting language: 'the supplier did it,' 'that is their problem,' 'we trusted their certificate.' These indicate a delegation mindset rather than a retained-responsibility mindset. Also check whether complaints and CAPAs related to outsourced processes are handled with the same rigor as internal issues. Under FDA QMSR, the establishment registration holder is responsible regardless of who performs the work.
Follow-Up Questions
- When a complaint comes in about a product aspect that was outsourced, who owns the investigation -- you or the supplier?
- Show me a CAPA related to an outsourced process failure. Did your organization drive the root cause analysis?
- If a regulatory authority contacted you about a quality issue with an outsourced process, how would you respond?
What to Sample
Find 2 nonconformances or complaints related to outsourced processes in the last 12 months. Verify the organization (not the supplier) owned the investigation, root cause analysis, and corrective action.
Objective Evidence
- Outsourced process risk classification matrix showing risk level assigned to each outsourced process based on product impact, patient risk, and regulatory significance
- Tiered control strategy document defining different control levels (e.g., Tier 1: annual audit + incoming inspection + quarterly review; Tier 2: biennial audit + certificate review; Tier 3: certificate review only) mapped to risk levels
- Supplier capability assessments showing evaluation of the external party's quality system maturity, certifications, track record, and capacity -- and how capability influences control level
- Evidence that control levels have been adjusted based on supplier performance -- e.g., a supplier that was moved from Tier 2 to Tier 1 after quality issues
- Records showing risk reassessment was triggered by supplier performance changes, product changes, or regulatory changes
Common Nonconformities
- All outsourced processes are subject to identical annual audit and quarterly performance review regardless of risk -- the courier service receives the same oversight as the contract sterilizer (Observation but systemic).
- Supplier capability assessment does not exist for the outsourced electropolishing process, which is classified as critical and performed by a small job shop with no ISO 13485 certification and no previous medical device experience (Major NC).
- Risk classification was performed once during initial supplier qualification and has never been updated -- a supplier that has had significant nonconformances still carries a 'low risk' rating from years ago (Minor NC).
- High-risk outsourced process (contract sterilization) is controlled identically to a low-risk outsourced process (administrative translation services) -- proportionate control is not demonstrated (Minor NC).
Auditor Tips
Proportionality is the key word. Organizations must be able to articulate why different outsourced processes get different levels of control. The two factors are risk (how much damage could result from failure) and capability (how likely is the external party to deliver conforming output). A highly capable, ISO 13485-certified, long-track-record supplier performing a low-risk process may need less oversight than a new, uncertified supplier performing a high-risk process. If all suppliers are controlled identically, either low-risk suppliers are over-controlled (wasteful) or high-risk suppliers are under-controlled (dangerous). Ask for the decision logic.
Follow-Up Questions
- Show me your highest-risk and lowest-risk outsourced processes side by side. How do the controls differ?
- Has a supplier's control level ever been escalated or de-escalated based on performance? Show me the record.
- How do you evaluate a new outsourced process provider's capability before you start using them?
What to Sample
Compare the control strategies for the highest-risk and lowest-risk outsourced processes. Verify that the difference in control intensity is documented and justified by risk and capability assessments.
Objective Evidence
- Signed quality agreements for all outsourced processes -- verify they are separate from commercial/purchase agreements and specifically address quality obligations
- Quality agreement register or log showing all agreements with version, effective date, signatory, and review date -- verify no agreements are expired or unsigned
- Quality agreement template or checklist defining minimum required content -- verify it includes all mandatory elements (quality requirements, change notification, right to audit, NC handling, record retention, regulatory access)
- Evidence of quality agreement review and update -- look for revision history, periodic review records, or amendments triggered by changes
- Compliance verification records showing the organization has confirmed the supplier is meeting quality agreement obligations -- not just signing and filing
Common Nonconformities
- No written quality agreement exists for the outsourced software testing laboratory -- the relationship is governed only by purchase orders with no quality provisions (Major NC).
- Quality agreement with the contract manufacturer references a superseded version of ISO 13485 -- the agreement has not been reviewed or updated since initial signing (Minor NC).
- Quality agreement requires advance notification of process changes, but the contract sterilizer changed cycle parameters without notification and the organization was unaware until discovered during an audit (Major NC -- agreement exists but is not effective).
- Quality agreement is embedded within the commercial supply agreement and does not clearly distinguish quality obligations from commercial terms -- quality requirements are vague (e.g., 'supplier shall maintain quality') rather than specific (Observation).
- Quality agreements for a significant proportion of outsourced processes do not include a right-to-audit clause, meaning the organization has no contractual basis to audit these suppliers (Minor NC).
Auditor Tips
Written quality agreements are explicitly required by the standard -- verbal agreements or reliance on purchase orders is insufficient. The quality agreement should be a standalone document (or clearly separated section) that specifically addresses quality obligations. Key elements to check: (1) specific quality requirements and acceptance criteria, (2) change notification obligations -- both directions, (3) right to audit, (4) nonconformance reporting and handling, (5) record retention and access, (6) regulatory authority access. If the agreement exists but is not being followed (e.g., changes made without notification), the agreement is ineffective. Ask to see evidence the agreement is actively managed, not just signed and forgotten.
Follow-Up Questions
- When was the last time a supplier notified you of a change per the quality agreement? Show me the notification and your response.
- Has your organization ever exercised the right to audit per a quality agreement? Show me the audit report.
- Show me a quality agreement that was updated or amended. What triggered the change?
What to Sample
Review quality agreements for the 2 highest-risk outsourced processes. Check for all mandatory elements. Verify at least one change notification was received and processed per the agreement terms.
Objective Evidence
- QMS software inventory listing all software applications used in the QMS with name, version, purpose, risk classification, validation status, and last validation date -- verify it includes spreadsheets, databases, ERP modules, document management systems, and LIMS, not just custom software
- Computer software validation procedure defining the approach, risk classification methodology, validation activities per risk level, acceptance criteria, and revalidation triggers
- Completed validation packages for at least 2 software applications including validation plan, test protocols (IQ/OQ/PQ or equivalent), test results, deviation handling, and approval records
- Revalidation records showing at least one example of software that was revalidated after a change (update, patch, configuration change, new module)
- Risk assessment for each software application showing how validation effort is proportionate to risk -- verify higher-risk applications (e.g., automated inspection systems) have more rigorous validation than lower-risk ones (e.g., visitor log)
Common Nonconformities
- Organization uses multiple Excel spreadsheets for quality-critical calculations (statistical sampling, process capability, complaint trending, CAPA effectiveness) but none are validated -- formulas have not been verified, version control does not exist, and any user can modify formulas without detection (Major NC).
- ERP system was upgraded to a new version but no revalidation was performed -- the organization assumed the vendor's release notes constituted validation (Minor NC).
- Software validation inventory lists only a few custom applications but does not include the document management system, calibration tracking database, complaint database, or spreadsheets used for quality calculations -- the inventory is incomplete (Minor NC).
- Validation procedure exists but defines only one level of validation regardless of risk -- a production scheduling tool and the automated vision inspection system that performs 100% dimensional inspection receive the same validation treatment (Observation).
- Software validation records show testing was performed by the software developer with no independent verification or user acceptance testing -- the same person who created the formulas tested them (Minor NC).
Auditor Tips
Computer software validation under 4.1.6 is one of the most common findings globally and a perennial FDA 483 observation. The biggest gap is always spreadsheets -- organizations that meticulously validate their ERP completely ignore the Excel spreadsheets that make quality decisions. Ask specifically about spreadsheets used for calculations, trending, or acceptance decisions. Risk-proportionate means a critical inspection system needs full IQ/OQ/PQ while a simple visitor log might need only basic functional testing. Revalidation after updates is frequently missed -- organizations apply automatic updates without considering validation impact. Check for IT-initiated patches that bypassed quality assessment.
Follow-Up Questions
- How many Excel spreadsheets do you use for quality-related calculations or decisions? Are they on your validation inventory?
- When your ERP or document management system received its last update, did that trigger a revalidation assessment? Show me the record.
- Who performs the validation testing -- is it independent from the person who developed or configured the software?
What to Sample
Request the software validation inventory. Cross-check it against what you observe during the audit (spreadsheets open on screens, databases referenced in procedures, software mentioned in work instructions). Select 2 items: one validated application to review the package, and one that may be missing from the inventory.
Objective Evidence
- Computer software validation SOP or procedure document -- verify it is a controlled, approved, current document (not a draft or template)
- Software risk classification methodology within the procedure defining how software applications are categorized by risk level (e.g., based on impact to product quality, patient safety, data integrity)
- Validation planning templates or requirements showing what activities are required at each risk level (e.g., high-risk: full IQ/OQ/PQ; medium-risk: OQ/PQ; low-risk: functional verification)
- Acceptance criteria framework defining what constitutes successful validation (e.g., all critical test cases pass, no critical defects open, deviation resolution complete)
- Revalidation trigger criteria defining what changes require revalidation (e.g., version upgrades, configuration changes, OS updates, infrastructure changes, new modules)
Common Nonconformities
- No documented procedure exists for computer software validation -- the quality manager states 'we use industry best practice' but there is no written procedure defining the organization's approach (Major NC for missing mandatory procedure).
- Procedure exists but does not define risk-based validation requirements -- all software receives the same level of validation regardless of risk, which is neither proportionate nor practical (Minor NC).
- Procedure does not address revalidation after changes -- only initial validation is covered, leaving no guidance for when updates, patches, or configuration changes require revalidation assessment (Minor NC).
- Procedure is a downloaded template that references 'GAMP 5' and 'FDA General Principles of Software Validation' but does not customize the approach to the organization's specific software landscape or risk tolerance (Observation).
Auditor Tips
The procedure must be documented -- this is explicitly stated in the standard. A common evasion is referencing industry guidance (GAMP 5, FDA guidance) as the procedure. Industry guidance informs the procedure, but the organization must have its own documented procedure that defines its specific approach. The procedure should be practical and implementable, not an academic exercise. Check that the procedure matches what is actually done -- if the procedure describes full lifecycle validation but records only show basic functional testing, there is a disconnect.
Follow-Up Questions
- Walk me through how you would validate a new piece of QMS software using this procedure. What are the specific steps?
- How does your procedure differentiate between high-risk and low-risk software validation activities?
- When was this procedure last reviewed, and was it updated based on lessons learned from recent validations?
What to Sample
Review the procedure against one completed validation package to verify the procedure was actually followed. Check that risk classification, planning, testing, and acceptance criteria match what the procedure requires.
Objective Evidence
- Validation completion records with approval dates for at least 2 software applications -- compare these dates against the go-live or first-use dates to confirm validation preceded use
- Go-live authorization records showing formal approval to put validated software into production use -- verify the authorization references the completed validation
- User acceptance testing (UAT) records showing end users verified the software meets their operational needs before go-live
- Data migration validation records if the software replaced a previous system -- verify data integrity was confirmed during migration
- Parallel operation records if applicable -- showing the new system ran alongside the old system to verify consistent results before cutover
Common Nonconformities
- QMS software was deployed before the validation report was completed -- the software was used for quality decisions for weeks without validation, and multiple quality records were managed using the unvalidated system (Major NC).
- Validation was completed for one version of the software but the actually installed version is a later release -- the validated version was never deployed and the deployed version was never validated (Major NC).
- Go-live approval does not exist -- the IT department deployed the software and notified quality after the fact, with no formal authorization to use it for QMS purposes (Minor NC).
- Organization acquired a company and integrated their ERP system but the integrated system was never validated as a whole -- only the individual components were validated separately before integration (Minor NC).
Auditor Tips
The requirement is unambiguous: validated 'prior to initial use.' Any software used for QMS purposes before validation is complete is a finding. This is one of the easiest things to verify -- just compare dates. Common evasion: 'we were still validating while we used it' -- this is non-compliant. Also check that the validated version matches the installed version. IT departments sometimes update software versions between validation completion and deployment. Always verify the version number on the validation record matches what is actually running on the system.
Follow-Up Questions
- For the last QMS software you deployed, show me the validation completion date and the first date it was used for quality purposes.
- Has there ever been a case where software was deployed before validation was complete? What happened?
- How do you prevent IT from updating QMS software without validation sign-off?
What to Sample
Select the 2 most recently deployed QMS software applications. Verify the validation completion date precedes the go-live date. Confirm the validated version matches the currently installed version.
Objective Evidence
- Software change log for at least one QMS application showing all updates, patches, configuration changes, and version upgrades applied since initial validation -- verify each change has a documented revalidation assessment
- Revalidation impact assessments showing how each change was evaluated for its effect on validated functionality -- verify the assessment is specific to the change, not a generic statement
- Revalidation test records where the impact assessment determined revalidation was needed -- verify testing scope is proportionate to the change (full revalidation for major version upgrades, targeted regression testing for minor patches)
- Risk-based rationale documents where revalidation was determined not to be needed -- verify the rationale is specific and defensible, not a rubber stamp
- IT change management records showing coordination between IT and quality for QMS software changes
Common Nonconformities
- ERP system has received numerous patches and version updates since initial validation, but no revalidation assessment was performed for any of them -- IT applied updates following the vendor's release schedule without quality involvement (Major NC).
- Revalidation was performed after a major version upgrade but the scope only tested a subset of validated functions -- no rationale exists for excluding the remaining functions from regression testing (Minor NC).
- Impact assessment for a database configuration change states 'no impact on validated functionality' but the change modified the user access permissions, which were specifically validated as a security control during initial validation (Minor NC).
- Automatic operating system updates are applied to the server hosting the QMS document management system with no assessment of impact on the validated application -- the quality department is not aware when updates occur (Observation).
Auditor Tips
Revalidation is where most organizations fall down. Initial validation might be well done but ongoing change management is poor. The biggest risk is IT-initiated changes (patches, OS updates, infrastructure changes) that bypass quality. Ask IT when the last update was applied and then check whether quality was involved. Proportionality is important: a major version upgrade needs more rigorous revalidation than a cosmetic UI patch. But the assessment must happen for every change -- the question is the depth of revalidation, not whether to assess. Look for automatic updates that are applied without human review.
Follow-Up Questions
- How does your quality department learn about IT changes to QMS software? Is there a formal notification process?
- Show me the last software update that was assessed and determined NOT to require revalidation. What was the rationale?
- Are automatic updates enabled for any QMS software or the infrastructure it runs on?
What to Sample
Pick one QMS software application. Request the change log for the last 2 years. Select 3 changes and verify each has a documented revalidation assessment. For changes requiring revalidation, review the test records.
Objective Evidence
- Validation record repository showing where all software validation records are stored, how they are organized, and who has access -- verify the repository is controlled and backed up
- Complete validation packages for at least 2 software applications including: validation plan, risk assessment, test protocols, test results with pass/fail, deviation reports, summary report, and approval signatures
- Traceability matrix within the validation package showing requirements traced to test cases traced to test results -- verify complete coverage
- Record retention schedule for software validation records showing retention periods meet 4.2.5 requirements (device lifetime, regulatory requirements, minimum 2 years)
- Evidence that validation records have been maintained through system changes -- if the original validation was for an older version, show how records for all versions are preserved and accessible
Common Nonconformities
- Validation records for the calibration tracking database consist only of a single-page summary stating 'validation passed' with no test protocols, test data, or traceability -- records are insufficient to demonstrate what was tested and how (Major NC).
- Original validation records for the ERP system were stored on a shared drive that was decommissioned during an IT infrastructure upgrade -- records cannot be located and may have been lost (Major NC).
- Validation package is incomplete: test protocols exist but test results were recorded on scratch paper that was discarded after the summary was written -- original test data is not available (Minor NC).
- Spreadsheet validation records exist but are stored in the spreadsheet file itself (a 'validation' tab) -- the validation record is within the object being validated, creating a circular integrity problem (Observation).
Auditor Tips
Validation without records is the same as no validation. The records must tell the complete story: what was planned, what was tested, what the results were, what deviations occurred, and who approved. Requesting 'show me your validation records' is one of the most revealing audit questions because it exposes both the quality of validation and the quality of record-keeping. Look for completeness: a validation plan without test results, or test results without a plan, are both incomplete. Check that records for superseded software versions are still accessible -- you may need them for post-market investigations. Records stored within the validated system itself (e.g., validation documents in the document management system being validated) create a circular dependency that should be addressed.
Follow-Up Questions
- If I needed to see the validation evidence for a specific software function, could you trace from the requirement to the test result? Let us try it.
- Where are validation records for software that has been replaced or decommissioned? Can you still access them?
- How do you ensure that validation records themselves are protected from unauthorized modification?
What to Sample
Request the complete validation package for 2 software applications. Verify each package contains all required elements (plan, risk assessment, protocols, results, approvals). Trace one requirement through the traceability matrix to verify coverage.
Objective Evidence
- Documentation hierarchy diagram (documentation pyramid) showing the relationship between quality manual, procedures, work instructions, forms, and records -- verify it reflects actual practice
- Master document list showing total document count by category, with current revision status summary -- look for documents with overdue reviews as an indicator of system health
- Documentation requirements matrix mapping ISO 13485 'shall document' requirements and applicable regulatory documentation requirements to specific organizational documents
- Document numbering and classification scheme documentation showing how documents are categorized, numbered, and identified
- Document management system overview showing how documents are created, reviewed, approved, distributed, and retired -- whether electronic, paper, or hybrid
Common Nonconformities
- Documentation hierarchy diagram in the quality manual shows a 4-level pyramid but the actual document management system has documents that do not fit any level -- engineering drawings, specifications, and validation protocols are not categorized in the hierarchy (Observation).
- Master document list shows a significant number of procedures have review dates overdue -- indicating systemic neglect of the documentation system (Minor NC).
- No documentation requirements matrix exists -- the organization cannot demonstrate which specific documents address which ISO 13485 or regulatory requirements (Minor NC).
- Organization operates a hybrid paper-electronic system but has no procedure governing how the two systems interact, which is the system of record, or how conflicts are resolved (Minor NC).
Auditor Tips
Start with the big picture before diving into details. The health of the documentation system is a leading indicator for the health of the entire QMS. If the master document list shows dozens of overdue reviews, expect findings throughout the audit. Ask for the master document list sorted by last review date -- the oldest entries reveal systemic neglect. Count the mandatory ISO 13485 documented procedures (approximately 18) and verify all exist. The documentation hierarchy should make sense for the organization's size and complexity -- a 10-person startup does not need 500 documents, and a 1,000-person manufacturer should not have only 30.
Follow-Up Questions
- How many documents are currently overdue for periodic review? Show me the report.
- Can you show me every ISO 13485-required documented procedure and confirm each one exists and is current?
- What document management system do you use, and has it been validated per 4.1.6?
What to Sample
Request the master document list sorted by review date. Count overdue reviews. Verify all mandatory ISO 13485 procedures exist. Spot-check 3 random documents for current approval and alignment with the hierarchy.
Objective Evidence
- Documented quality policy (signed by top management, displayed or accessible to all employees) and quality objectives (measurable, time-bound, tracked) -- verify both are current and aligned
- Quality manual meeting all 4.2.2 requirements (scope, procedures/references, process interactions, documentation structure)
- Compliance matrix listing every ISO 13485 'shall document a procedure' and 'shall maintain records' requirement mapped to the specific organizational document that addresses it -- spot-check 5 entries
- List of organization-determined documents (beyond ISO minimums) with rationale for why each is needed -- typically includes work instructions, engineering specifications, forms, and technical references
- Regulatory documentation index showing all documentation required by applicable regulations (FDA DHF/DMR/DHR, EU MDR Technical Documentation, MDSAP requirements) with document references and status
Common Nonconformities
- Quality objectives for the current year are identical to the previous 3 years ('maintain customer satisfaction above 90%', 'reduce complaints by 10%') -- objectives are not challenging, specific, or updated based on actual performance data (Observation).
- Compliance matrix shows all ISO 13485 procedures are addressed but 3 entries reference the same generic 'Quality System Procedure QSP-001' for document control, record control, AND internal audit -- one procedure cannot adequately address all three distinct requirements (Minor NC if the procedure actually covers all three; Major NC if it does not).
- No regulatory documentation index exists for EU MDR Technical Documentation requirements despite the organization holding CE marking -- they cannot demonstrate which documents satisfy Annex II/III requirements (Major NC).
- Organization-determined documents do not include work instructions for complex assembly operations performed by production operators -- procedures exist but are too high-level for operator use (Observation if operators are experienced; Minor NC if errors are occurring).
Auditor Tips
This is the checklist of checklists. All five categories are mandatory, and missing any one is a finding. Category (e) -- regulatory documentation -- is where most gaps exist because organizations focus on ISO 13485 and forget market-specific requirements. Ask 'in which markets do you sell?' and then verify documentation exists for each market's requirements. Category (d) is the organization's opportunity to tailor documentation to their needs, but many organizations either over-document (creating unmanageable systems) or under-document (leaving critical processes to tribal knowledge). The test is: can a qualified replacement person do this job using only the available documentation?
Follow-Up Questions
- For which regulatory markets do you have devices registered, and can you show me the documentation required for each?
- Show me an organization-determined document that you created because you identified a need beyond ISO 13485 requirements. What drove that decision?
- How do you verify that your documentation system remains complete as new requirements emerge?
What to Sample
Verify all 5 categories are addressed. Spot-check 5 ISO 13485 required procedures from the compliance matrix. Check regulatory documentation completeness for the primary market. Ask about documentation for the most complex production process.
Objective Evidence
- Quality manual document -- current, approved revision with signatures and date, revision history showing when it was last reviewed and what changed
- Scope section including products, sites, regulatory roles, and applicable standards -- with any exclusions explicitly identified and justified with documented rationale
- Procedure listing or reference section showing all QMS procedures either contained in or referenced by the manual -- cross-check against the master document list for completeness
- Process interaction section with visual diagrams showing how QMS processes connect, sequence, and exchange inputs/outputs
- Documentation structure section explaining the documentation hierarchy, numbering convention, document types, and how to navigate the documentation system
Common Nonconformities
- Quality manual scope excludes Section 7.3 (Design and Development) with the justification 'we do not perform design' but the organization modifies device labeling for different markets and makes configuration changes based on customer requirements -- these constitute design activities under ISO 13485 (Major NC).
- Quality manual references procedures that have been consolidated into other procedures and no longer exist under the referenced document numbers -- the manual has not been updated to reflect the consolidation (Minor NC).
- Process interaction section shows a simplistic linear flow with no feedback loops, no support process connections, and no measurement/analysis linkages -- it does not reflect actual process interactions (Minor NC).
- Quality manual has not been approved within its defined review cycle and references the organization's former name, a relocated facility address, a discontinued product line, and an outdated organizational structure (Minor NC).
- No documentation structure outline exists in the manual -- the hierarchy is not explained, and new employees have no roadmap for navigating the QMS documentation (Minor NC).
Auditor Tips
The quality manual is typically the first document requested in any audit. It should function as a roadmap to the entire QMS. All four elements are mandatory. The most common finding is inadequate exclusion justification -- organizations exclude design (7.3) when they should not, or exclude servicing (7.5.4) for devices that clearly need servicing. Challenge every exclusion: ask 'why is this excluded?' and verify the justification holds up under scrutiny. If the manual looks like a generic template (identical language to other organizations, no company-specific content), it was likely purchased rather than developed, and implementation may be equally superficial.
Follow-Up Questions
- Walk me through your justification for each exclusion. How did you determine these clauses do not apply?
- If I am a new quality engineer starting today, how would I use this manual to understand your QMS?
- When was the last change to the manual, and what triggered it?
What to Sample
Read the scope and exclusion section carefully. Verify each exclusion is justified. Cross-check 5 procedure references against the master document list. Verify the process interaction diagram matches the actual process inventory.
Objective Evidence
- Medical device file index or table of contents for at least one device family showing all six required elements: (a) device description/intended use/labeling, (b) product specifications, (c) manufacturing/packaging/storage/handling/distribution, (d) measuring and monitoring procedures, (e) installation requirements, (f) servicing procedures
- Device description and intended use statement that is specific, accurate, and aligned with regulatory clearances/approvals -- compare against current labeling for consistency
- Product specifications package including performance specifications, material specifications, dimensional drawings, and acceptance criteria
- Manufacturing procedure references with current revision status -- verify at least 2 are current and accessible
- Evidence the file is actively maintained -- look for recent additions, updates linked to design changes or CAPAs, and a revision log
Common Nonconformities
- Medical device file for the flagship product does not exist as a coherent, organized collection -- the quality manager states 'all the documents exist but they are in different systems and folders' with no index, no cross-referencing, and no way to confirm completeness (Major NC).
- Device description states 'intended for general laboratory use' but the regulatory clearance specifies 'for in-vitro diagnostic use with human serum samples only' -- the device file does not match the regulatory clearance (Major NC).
- Medical device file contains manufacturing procedures from 2018 but the manufacturing process was significantly changed in 2022 -- the file has not been updated to reflect current manufacturing methods (Major NC if procedures used in production differ from those in the file).
- File is organized for the organization's primary device family but no file exists for separately classified and registered accessory devices -- each classified device needs its own file (Minor NC).
- Installation requirements (element e) and servicing procedures (element f) are marked 'N/A' without justification for a capital equipment device that requires professional installation and annual calibration (Minor NC).
Auditor Tips
The medical device file (also called technical file or technical documentation) is the single most important documentation deliverable for regulatory compliance. Under EU MDR, this is the Annex II/III Technical Documentation. Under FDA, elements overlap with the DHF, DMR, and premarket submissions. The file must be a cohesive, navigable collection -- not scattered documents that theoretically exist somewhere. Test retrievability: ask for a specific element and time how long it takes. If it takes more than 5 minutes to locate a key element, the file is not adequately organized. Each device family needs its own file. 'As appropriate' for elements (e) and (f) means you must justify N/A, not just skip them.
Follow-Up Questions
- How many distinct device files do you maintain, and does each registered device have its own file?
- Show me the most recently updated element of this device file. What triggered the update?
- If a regulatory authority requested your technical documentation tomorrow, how long would it take to compile and submit it?
What to Sample
Select one device file. Verify all 6 elements are present. Open 2 referenced procedures to confirm they are current. Compare the device description against regulatory clearance. Check the revision log for evidence of active maintenance.
Objective Evidence
- Document control procedure (SOP) addressing all eight control elements (a through h) -- verify it is a controlled, approved, current document itself
- Master document list or register showing every controlled document with document number, title, current revision, effective date, approval authority, and distribution status -- verify the list is current by cross-checking 5 random entries
- Document approval records for 3 recently issued or revised documents showing the review and approval workflow was followed -- verify approvers are authorized per the approval matrix
- External document register identifying standards, regulations, customer specifications, and supplier documents incorporated into the QMS with current version verification records
- Obsolete document controls -- either physical demonstration (stamps, segregation) or electronic demonstration (access controls, archive status) showing how obsolete documents are prevented from unintended use
- Document change records for 2 recent changes showing change identification, reason for change, review, approval, and communication to affected parties
Common Nonconformities
- Obsolete document revision found in active use at a point-of-use location -- the document is multiple revision levels behind the current version, indicating distribution recall process failed to retrieve the superseded copy (Major NC).
- Document control procedure requires periodic review of all controlled documents but a significant percentage have not been reviewed within the required cycle -- the review procedure is not being followed systemically (Minor NC).
- External document register does not include ISO 13485:2016 itself, nor does it include harmonized standards (e.g., ISO 14971, IEC 62304, IEC 62366) referenced in regulatory submissions -- external documents are not adequately controlled (Minor NC).
- Electronic document management system allows any user to modify document metadata (effective date, revision number) without approval or audit trail -- system integrity controls are inadequate (Major NC).
- No document control procedure exists for engineering drawings -- drawings are controlled by the engineering department under a separate system with different revision practices, creating parallel uncontrolled documentation (Minor NC).
Auditor Tips
Document control is bread-and-butter auditing but consistently yields findings. The floor walk is essential -- ask to see the document at the point of use and compare it to the master list. Check workstations, inspection areas, labs, and receiving docks. Electronic systems create a false sense of security; check that access controls actually work by asking 'can you edit this document right now?' If the answer is yes for a non-author, that is a finding. The eight control elements (a-h) must ALL be addressed. External documents are frequently forgotten. The single most common document control finding across industries is obsolete documents in use -- always check for this.
Follow-Up Questions
- Can I walk the production floor and check the documents at 3 workstations against your master list?
- Show me how a document moves from draft through review, approval, distribution, and eventual obsolescence in your system.
- When was the last time someone found an obsolete document in use? What corrective action was taken?
What to Sample
Check documents at 3 different points of use against the master list. Verify 2 recent document changes followed the full control procedure. Confirm 2 external documents are at current published versions.
Objective Evidence
- Records control procedure addressing all six control elements: identification, storage, security/integrity, retrieval, retention time, and disposition -- verify the procedure covers both paper and electronic records
- Records matrix listing all QMS record types with identification scheme, storage location, retention period, responsible person, and disposition method -- verify retention periods meet 4.2.5 requirements
- Three specific records retrieved on request to test retrievability: (1) a production batch record from 12+ months ago, (2) a training record for a current employee, (3) a CAPA or complaint record -- time the retrieval
- Record integrity controls: for paper records, check storage conditions, environmental protection, and ink permanence; for electronic records, check access controls, audit trails, backup procedures, and system validation
- Record disposition evidence: a record that was dispositioned (destroyed or archived) per the retention schedule, with evidence that disposition was authorized and documented
Common Nonconformities
- Records control procedure addresses paper records comprehensively but does not address electronic records -- the organization migrated to an electronic QMS but the procedure was never updated (Minor NC).
- Production batch records (DHR) for recently manufactured lots took an extended time to retrieve from off-site storage because the indexing system has not been maintained -- records are not readily retrievable (Minor NC).
- Electronic quality records are stored on individual employee laptops rather than a central controlled system -- when an employee left the company, inspection records on their laptop could not be accessed due to encryption (Major NC).
- Retention schedule defines a blanket '10 years' for all records without considering device lifetime, regulatory requirements, or record type -- some records should be retained longer (implantable devices), and the minimum retention analysis has not been performed (Minor NC).
- Handwritten production records use pencil rather than indelible ink, and multiple records show erasures with no traceability of the original entry (Major NC for data integrity).
Auditor Tips
Record control findings are among the most common FDA 483 observations. The six control elements are all mandatory. Test retrievability practically: give a specific record identifier and start timing. If it takes more than 10-15 minutes, the system is inadequate for a regulatory inspection. Data integrity is a critical focus area -- look for pencil entries, white-out, missing dates/signatures, and electronic records without audit trails. Retention is complex: the standard requires the LONGEST of device lifetime, regulatory requirements, or 2-year minimum. For implantable devices, this could be 15-25 years. Ask about backup and disaster recovery -- if a fire destroyed the records room, what would be lost? Electronic records on unvalidated systems (spreadsheets, email, shared drives) are a growing concern.
Follow-Up Questions
- What is your device lifetime definition, and how does that drive your record retention periods?
- Show me your backup and disaster recovery procedure for quality records. When was it last tested?
- Have you ever been unable to locate a required record? What happened?
What to Sample
Request 3 specific records by identifier and time the retrieval. Inspect 2 paper records for data integrity (indelible ink, no erasures, complete entries). Check 2 electronic record systems for access controls and audit trails.
Objective Evidence
- Quality policy document -- signed by current top management (CEO, President, or equivalent), displayed or accessible to all employees, and reviewed within the organization's defined cycle (typically annually or during management review)
- Quality objectives document with specific, measurable, achievable, relevant, and time-bound (SMART) targets for the current period -- verify objectives include both product quality and regulatory compliance dimensions
- Quality objectives tracking report or dashboard showing current performance against each objective with trend data -- verify data is current within the last reporting period
- Traceability matrix or narrative linking each policy commitment (e.g., 'committed to product safety') to a specific measurable objective (e.g., 'reduce safety-related complaints by 15% by Q4')
- Department-level or process-level objectives that cascade from organizational objectives -- verify at least 2 departments have specific objectives aligned to the organization's quality objectives
Common Nonconformities
- Quality policy is signed by a former executive who is no longer with the organization -- the current top management has not reviewed or reaffirmed the policy (Minor NC).
- Quality objectives state 'improve customer satisfaction' and 'reduce defects' but have no quantitative targets, timelines, or measurement methods -- they are aspirations, not measurable objectives (Minor NC).
- Quality objectives tracking shows the same targets have been missed for multiple consecutive years with no management action to adjust either the targets or the improvement plans -- the objectives system is not driving improvement (Observation).
- Quality policy commits to 'meeting all applicable regulatory requirements' but quality objectives contain no regulatory compliance metrics -- there is no linkage between the policy commitment and measurable objectives (Minor NC).
- Quality objectives exist at the organizational level but do not cascade to departments -- production, design, and purchasing have no department-level quality objectives tied to the organization's objectives (Observation).
Auditor Tips
The quality policy should reflect genuine organizational commitment, not generic boilerplate. Read it and ask: could this policy apply to any organization, or is it specific to this company? Generic policies indicate superficial commitment. Quality objectives must be SMART -- vague objectives like 'improve quality' are not compliant. The real test is whether objectives drive action: ask what happened when an objective was missed. If the answer is 'nothing,' the system is not effective. The policy-to-objectives linkage should be traceable. Each policy commitment should have at least one corresponding measurable objective.
Follow-Up Questions
- Which quality objective was hardest to achieve last year, and what actions did you take?
- Show me how department-level objectives roll up to organizational quality objectives.
- If I asked a production operator what the quality objectives are, what would they say?
What to Sample
Review the quality policy for management signature currency. Check 3 quality objectives for SMART criteria. Verify tracking data is current. Ask 2 floor personnel if they know the quality policy or objectives.
Objective Evidence
- QMS scope statement clearly defining which products, product families, or device groups are covered -- verify alignment with regulatory registrations and certifications
- Site listing showing all locations included in the QMS scope with their activities (manufacturing, design, warehousing, service) -- compare against actual operational sites
- Exclusion listing with detailed justification for each excluded requirement showing why it does not apply based on the organization's activities, products, and regulatory roles -- not just 'not applicable'
- Certification scope from the most recent ISO 13485 certificate -- verify alignment between the certificate scope and the quality manual scope statement
- Risk assessment or justification document for exclusions showing the analysis that determined exclusion does not affect product quality or regulatory compliance
Common Nonconformities
- Quality manual excludes Section 7.3 (Design and Development) with the justification 'the organization does not perform design' but the organization makes custom modifications to standard devices based on surgeon preferences, develops new software features, and creates new labeling -- all of which constitute design activities (Major NC).
- Scope statement lists the headquarters address but the organization operates an additional manufacturing facility where a significant portion of production occurs -- the additional site is not in scope and has never been audited (Major NC).
- Exclusion of Section 7.5.1.2.2 (Particular requirements for sterile medical devices) is justified as 'we do not manufacture sterile devices' but the organization's product catalog includes a sterile wound care kit that is terminally sterilized by a contract sterilizer (Major NC).
- Scope statement has not been updated since initial certification and still references a product line that was discontinued years ago while excluding 2 new product lines added since then (Minor NC).
- Certificate scope says 'design, manufacture, and distribution of Class II cardiovascular devices' but the quality manual scope says 'manufacture and distribution' -- design is missing from the manual scope despite being on the certificate (Minor NC).
Auditor Tips
Scope review is where experienced auditors find high-impact findings. Challenge every exclusion relentlessly. The most abused exclusion is Section 7.3 (Design) -- organizations that make any modification, customization, or adaptation of devices are performing design and cannot exclude it. Under EU MDR, private labelers and system/procedure pack producers are considered manufacturers and must have design controls. Under FDA QMSR, any device modification requires design controls. If an organization excludes installation (7.5.3) or servicing (7.5.4), verify their devices truly require neither. Compare scope to the certification body's certificate -- misalignment is a finding for both the organization and the certification body.
Follow-Up Questions
- Do you make any modifications, customizations, or configurations to your devices based on customer requirements? If so, how is that not design?
- Are all your operational sites included in the scope? Have you opened, closed, or relocated any sites since the scope was last updated?
- Has your certification body accepted all your exclusions? Can I see their assessment?
What to Sample
Compare the quality manual scope to the ISO 13485 certificate scope and to actual business operations. Challenge each exclusion with specific questions about activities that might require the excluded clause.
Objective Evidence
- Device description document covering physical characteristics, principles of operation, materials of construction, accessories, variants, and key performance parameters -- verify it is specific enough to distinguish this device from similar devices
- Intended use/intended purpose statement -- compare word-for-word against the intended use in regulatory clearances (510(k), CE Technical Documentation, etc.) to verify exact alignment
- All current labeling: device label, packaging label, shipping label, Instructions for Use (IFU), package insert, quick start guide -- verify all are controlled documents at current revision
- Contraindications, warnings, and precautions documentation -- verify these are included in labeling and are based on risk analysis
- Evidence that marketing materials (website, brochures, trade show materials) are consistent with the cleared/approved intended use and do not make off-label claims
Common Nonconformities
- Device intended use in the medical device file states 'for diagnostic use' but the 510(k) clearance states 'for use as an adjunct to clinical evaluation' -- the intended use has been broadened beyond the cleared indication without regulatory authorization (Major NC).
- Instructions for Use have not been updated to reflect a hardware revision that changed the user interface and added new menu options -- users are following outdated instructions (Minor NC).
- Marketing brochure claims the device 'prevents infections' but the cleared intended use is 'aids in reducing bacterial contamination' -- marketing claims exceed the regulatory clearance (Major NC for potential off-label promotion).
- Device label is missing the unique device identifier (UDI) required under FDA and EU MDR regulations -- the labeling does not meet current regulatory requirements (Major NC).
- Translated IFUs for some language markets were translated by a non-medical translator and have not been verified for accuracy of medical terminology (Minor NC).
Auditor Tips
Intended use alignment is a critical finding area. The intended use in the device file, labeling, and marketing materials must match the regulatory clearance exactly. Any broadening of intended use without regulatory authorization is a serious finding. Check labeling for regulatory completeness: UDI (mandatory under FDA and EU MDR), symbols per ISO 15223, manufacturer contact information, lot/serial number, expiration date (if applicable), and storage conditions. IFU should cover all foreseeable use scenarios including misuse warnings. Compare the marketing website against the cleared intended use -- off-label promotion is a compliance risk that quality should monitor.
Follow-Up Questions
- Read me the intended use from your regulatory clearance, and now from your product labeling. Are they identical?
- Who reviews marketing materials for consistency with the regulatory clearance before publication?
- Show me your labeling change control process. How do you ensure labeling is updated when the device or its clearance changes?
What to Sample
Compare intended use across 3 sources: regulatory clearance, device file, and current labeling. Verify UDI compliance. Check one translated IFU against the source language version for completeness. Review the marketing website for one product.
Objective Evidence
- Document approval authority matrix defining who can review and approve each document type based on competency and organizational authority -- verify it covers all document types (procedures, work instructions, specifications, forms, labels)
- Document review checklist or criteria used during review to assess technical accuracy, completeness, clarity, regulatory compliance, and consistency with other documents
- Three recently issued or revised documents showing complete review and approval records -- check for reviewer and approver signatures/electronic approvals, dates, and evidence of the review itself (comments, redlines, review meeting minutes)
- Competency records for current document reviewers and approvers showing they have the technical knowledge and authority to assess the documents they approve
- Electronic document management system workflow demonstrating the review-approve-release sequence with controls preventing documents from being issued without all required approvals
Common Nonconformities
- A procedure for a critical process was reviewed and approved only by the quality manager -- no technical review by engineering, process specialists, or production personnel who have relevant domain expertise (Minor NC).
- Documents show approval signatures where all signatures were obtained on the same date as the document creation date -- indicating no time was allowed for meaningful review (Observation -- may indicate rubber-stamping).
- Document management system allows documents to be made 'effective' before all required electronic approvals are completed -- documents were found to have been distributed with incomplete approvals (Major NC).
- No approval authority matrix exists -- approvals are based on 'whoever is available' rather than defined competency and authority requirements (Minor NC).
- Form templates (blank forms used for records) are issued without review or approval -- they are treated as 'just forms' despite containing acceptance criteria, test parameters, and calculation fields that affect quality decisions (Minor NC).
Auditor Tips
Review and approval are distinct activities. Review assesses technical content; approval authorizes use. Both must happen before issuance. The key question is: are the right people reviewing? A quality procedure reviewed only by quality misses operational input. A design document reviewed only by design misses manufacturing and quality input. Cross-functional review is best practice for procedures that affect multiple departments. Watch for signs of rubber-stamping: all approvals on the same day, no evidence of review comments or redlines, or a single approver for all documents regardless of subject matter. Forms and templates are often overlooked but should be controlled and approved because they can contain embedded criteria.
Follow-Up Questions
- Show me the review comments or redline markup for the last document revision. What was changed based on the review?
- When was the last time a document was sent back for revision during the review process? What was the issue?
- How do you ensure that approvers have the technical competency to assess the documents they approve?
What to Sample
Pull 3 recently approved documents. Verify approvers are authorized per the matrix. Look for evidence of substantive review (comments, changes between draft and final). Check that approval dates precede effective dates.
Objective Evidence
- Records control procedure (SOP) -- verified as a controlled, current, approved document -- addressing all six elements with specific, implementable requirements for each
- Record identification scheme showing how records are named, numbered, or coded to make them uniquely identifiable -- verify the scheme is consistently applied by checking 5 random records
- Record storage specifications for both paper (location, environmental conditions, access controls) and electronic (server location, backup schedule, access permissions) records
- Record security and integrity controls: for paper (locked storage, restricted access, indelible ink requirements); for electronic (user authentication, role-based access, audit trails, encryption)
- Record retrieval demonstration -- request 3 specific records and verify they can be located and accessed within a reasonable time
- Record retention schedule with retention periods justified per device lifetime, regulatory requirements, and 2-year minimum -- with disposition procedures (authorized destruction or transfer to archive)
Common Nonconformities
- Records control procedure was written for a paper-based system and has not been updated despite the organization migrating the majority of records to electronic systems -- the procedure does not address electronic record identification, storage, security, or integrity (Major NC for missing mandatory procedure elements).
- Procedure requires records to be stored in a 'secure, climate-controlled environment' but batch records for the current year are stored in cardboard boxes stacked in an unheated warehouse where temperature and humidity are not controlled (Minor NC).
- Procedure addresses five of six required elements but does not address disposition -- there is no defined process for what happens when records reach the end of their retention period (Minor NC).
- Record identification scheme is not consistently applied -- some records use the lot number, some use a date-based code, some have no identification at all, and the same record type uses different identification methods in different departments (Minor NC).
- Security and integrity controls for electronic records rely on shared login credentials -- multiple quality inspectors share a single login to the inspection data system, making it impossible to attribute individual records to specific inspectors (Major NC for data integrity).
Auditor Tips
This is one of the mandatory documented procedures in ISO 13485. All six elements must be explicitly addressed -- missing any one is a finding. The most commonly neglected elements are security/integrity and disposition. Test the procedure's effectiveness by requesting records and observing how they are managed in practice. The gap between the documented procedure and actual practice is where findings live. Electronic records require specific controls that paper-based procedures do not address: audit trails, electronic signatures (if applicable), backup/recovery, and platform validation. Shared credentials destroy data integrity and individual accountability. Ask each department how they manage their records and compare to the procedure.
Follow-Up Questions
- How does your procedure address electronic records specifically -- not just paper records?
- Show me the last record that was dispositioned. How was the disposition authorized and documented?
- Do any personnel share login credentials for systems that contain quality records?
What to Sample
Review the procedure for all 6 elements. Test retrieval with 3 specific records. Check storage conditions for paper records. Verify electronic systems have individual credentials and audit trails.
Objective Evidence
- Quality manual -- physical or electronic document -- confirmed to exist, to be controlled (in the master document list), and to be at the current approved revision
- Approval page showing management authorization with date -- verify the approver is current top management
- Revision history showing the manual has been reviewed and updated as needed -- verify at least one review has occurred within the organization's defined review cycle
- Evidence the manual is accessible to all personnel who need it -- distribution list, intranet location, posted copies, or electronic access log
- Verification that the manual meets all 4.2.2 requirements (scope with exclusion justifications, procedure references, process interactions, documentation structure)
Common Nonconformities
- Quality manual exists in draft form but has never been formally approved -- it has been 'in review' for an extended period while being used as the operational manual (Minor NC).
- Quality manual is maintained by a consultant who updates it periodically but the document is not in the organization's document management system and is not subject to the organization's document control procedure (Minor NC).
- The quality manual exists but no one in the organization can locate a controlled copy -- after an extended search, the quality manager finds an old printed version that is multiple revisions behind current (Minor NC).
- Organization has two quality manuals -- one for FDA audits and one for notified body audits -- with conflicting content about scope and exclusions (Major NC).
Auditor Tips
The quality manual is mandatory. Some organizations try to argue that a collection of procedures constitutes a manual, but the standard requires a specific document (or collection of documents) that functions as a manual. The manual should be treated as the top-level controlled document. Check that it is subject to the same document control as any other controlled document. An uncontrolled manual is an oxymoron. If the organization uses a consultant to maintain the manual, verify that internal personnel understand its content and can explain their QMS using it.
Follow-Up Questions
- Who is responsible for maintaining the quality manual, and when was it last updated?
- If a regulatory inspector asked to see your quality manual right now, how quickly could you produce the current controlled copy?
- Does the content of the manual accurately reflect how your QMS actually operates today?
What to Sample
Verify the manual is in the master document list at the current revision. Confirm the approver is authorized. Check that it is accessible to personnel. Spot-check one section for accuracy against actual practice.
Objective Evidence
- Section of the quality manual listing or referencing all QMS documented procedures -- by document number and title, organized by clause or process area
- Master document list filtered to show all procedures -- to be cross-referenced against the manual's procedure list for completeness
- Procedure numbering system documentation showing how procedures are identified and organized
- Verification that all ISO 13485 mandatory documented procedures are included in the reference list
- Evidence that the procedure reference list is updated when procedures are added, removed, or consolidated
Common Nonconformities
- Quality manual references a set of procedures but the master document list contains additional procedures -- procedures created since the manual was last updated are not referenced (Minor NC).
- Manual references a procedure that has been superseded -- the replacement procedure exists under a different document number but the manual was never updated, resulting in broken references (Minor NC).
- Procedure references in the manual use only generic descriptions ('a document control procedure exists') rather than specific document numbers and titles, making it impossible to verify the reference points to an actual document (Observation).
- Manual references are organized alphabetically rather than by clause or process area, making it difficult to verify that all required procedures are addressed (Observation).
Auditor Tips
The manual must either contain the procedures (rare for larger organizations) or reference them by document number and title. References must be maintained -- this is a common gap because the manual is updated less frequently than individual procedures. A quick cross-check: count the procedures referenced in the manual and count the procedures on the master list. If the numbers do not match, investigate. Also verify that all ISO 13485 mandatory procedures are referenced. There are approximately 18 mandatory documented procedures in the standard.
Follow-Up Questions
- Have any procedures been added or removed since the manual was last updated? Are those changes reflected in the manual?
- Show me where the manual references your CAPA procedure, your internal audit procedure, and your management review procedure.
- How do you ensure the manual's procedure references stay current when procedures are revised or consolidated?
What to Sample
Cross-check 10 procedure references from the manual against the master document list. Verify document numbers and titles match. Identify any procedures on the master list not referenced in the manual.
Objective Evidence
- Product performance specifications defining the functional, mechanical, electrical, optical, or biological performance requirements the device must meet -- with quantitative acceptance criteria and test methods for each
- Material specifications for all materials in contact with the patient or critical to device performance -- including material grade, purity, biocompatibility classification, and supplier qualification requirements
- Dimensional drawings or CAD models with toleranced dimensions, GD&T callouts where appropriate, and clear indication of critical dimensions
- Software specifications if applicable (functional requirements, performance requirements, cybersecurity requirements, interoperability requirements) per IEC 62304
- Traceability from specifications to design outputs (showing specifications were derived from design outputs) and to verification/validation test protocols (showing how specifications are verified)
Common Nonconformities
- Product specifications for a Class II implantable device do not include biocompatibility requirements for patient-contacting materials -- material is specified only by part number without biocompatibility classification or test requirements (Major NC).
- Performance specification states 'device shall withstand normal use conditions' without defining what 'normal use' means in measurable terms -- no quantitative durability, fatigue, or mechanical performance criteria exist (Minor NC).
- Dimensional drawing tolerance for a critical mating dimension is +/- 0.5mm but incoming inspection records show the actual measurement capability is +/- 0.3mm -- the specification tolerance exceeds the measurement system's discrimination capability (Observation).
- Software requirements specification has not been updated since the initial release but the software has undergone significant revisions with added functionality -- the specification does not describe the current product (Major NC).
- Specifications exist but are not traceable to design outputs -- no matrix or cross-reference connects the specifications to the design output documents that established them (Minor NC).
Auditor Tips
Specifications define what the device must be and do. They must be specific, measurable, and verifiable. Vague specifications like 'suitable for intended use' or 'meets industry standards' are inadequate. Every specification should have an acceptance criterion and a defined test method. Check that specifications cover all critical attributes including safety-critical dimensions, biocompatibility-critical materials, and performance-critical parameters. Under FDA QMSR, the Device Master Record must contain device specifications. Under EU MDR, Technical Documentation must include design specifications per Annex II. Verify specifications are current and match the device actually being manufactured.
Follow-Up Questions
- For this critical specification, show me the test method and the most recent test result. Does the device meet the spec?
- How do you determine which specifications are safety-critical versus non-critical?
- When a specification changes, how do you ensure all downstream documents (test procedures, acceptance criteria, labeling) are updated?
What to Sample
Review the specifications for one device family. Verify 3 specifications have quantitative acceptance criteria and defined test methods. Check one specification against actual test data to verify the device meets the spec. Trace one specification to its design output source.
Objective Evidence
- Document review schedule or calendar showing planned review dates for all controlled documents -- verify it covers all document types, not just procedures
- Completed periodic review records for at least 3 documents showing the review was performed, by whom, the conclusion (adequate as-is, needs revision, or to be obsoleted), and the date -- verify reviews were substantive, not just a signature
- A specific example of a document that was revised based on a periodic review finding -- show the review record identifying the needed change, the change request, and the updated document
- Re-approval records for documents that were revised after review -- verify re-approval follows the same authority matrix as initial approval
- Report or dashboard showing the current status of periodic reviews: how many are current, how many are overdue, and trend data
Common Nonconformities
- Document control procedure requires all documents to be reviewed periodically but a significant proportion have not been reviewed within the required cycle -- no escalation or management notification mechanism exists for overdue reviews (Minor NC).
- Periodic review records consist of a single signature and date with no evidence that the document content was actually read or assessed for continued adequacy -- the review is a formality, not a substantive evaluation (Observation).
- Documents that have been reviewed are re-approved with a new effective date even when no changes were made -- this creates unnecessary version control confusion and makes it impossible to distinguish between reviewed-no-change and revised documents (Observation).
- Work instructions for production processes have not been updated despite process validation changes, CAPA-driven modifications, and equipment replacements -- the review process did not capture these needed updates (Minor NC).
Auditor Tips
Periodic review is one of the most gamed aspects of document control. Organizations stamp documents as 'reviewed' without reading them. To test this, open a document with the process owner and ask them to identify something that has changed since the last review -- if they cannot, the review may not have been substantive. Look for documents where the review cycle has been met on paper but content has not been updated despite known changes (CAPAs, process changes, organizational changes). Also check whether re-approval after revision follows the proper authority -- documents should not be re-approved by someone without the technical competency to assess the changes.
Follow-Up Questions
- When was the last time a periodic review resulted in a document being revised? Show me the record.
- How do you ensure that periodic reviews are substantive and not just a signature exercise?
- What triggers a document update outside of the periodic review schedule -- for example, a CAPA or a process change?
What to Sample
Check the review status for 5 random documents against the defined schedule. For 2 documents marked as 'reviewed -- no changes needed,' verify nothing has changed in the process since the review.
Objective Evidence
- Physical record security controls: locked storage cabinets or rooms, restricted access lists, key or access card logs -- verify physical controls are actually used (not unlocked doors or propped-open cabinets)
- Electronic record security controls: user authentication (individual credentials, not shared), role-based access permissions, session timeout, and password complexity requirements -- verify by reviewing system configuration
- Audit trail demonstration for at least one electronic records system showing who accessed or modified a record, when, and what was changed -- verify the audit trail cannot be modified or disabled by standard users
- Data integrity controls: for paper records, indelible ink policy, correction procedures (single-line strikethrough, initials, date, reason); for electronic records, electronic signature requirements, field-level audit trails, and data validation rules
- Backup and disaster recovery procedures for electronic records with evidence of backup testing -- verify backup frequency is appropriate for the data criticality
Common Nonconformities
- Quality records room has an electronic access control system but the door was found propped open during the audit, and the access log shows the door has been propped open for most of the last month -- physical security controls are defeated (Minor NC).
- Three quality inspectors share a single user account in the inspection data management system because 'there are not enough licenses' -- individual accountability for record entries is impossible (Major NC for data integrity).
- Electronic document management system has no audit trail -- documents can be modified by any authorized user with no record of who made the change or what was changed (Major NC).
- Paper production records show multiple instances of white-out or overwriting corrections without single-line strikethrough, date, initials, or reason for correction -- record integrity is compromised (Major NC for data integrity).
- Backup of the electronic quality system is performed weekly but has never been tested for recoverability -- the organization cannot confirm that backups are usable (Minor NC).
Auditor Tips
Data integrity is the hottest topic in regulatory compliance today. FDA, EU notified bodies, and MDSAP auditors all focus heavily on it. The ALCOA+ principles (Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available) provide the framework. Shared credentials are a red flag for data integrity -- if you cannot attribute a record entry to a specific individual, the entire record is questionable. For electronic records, ask to see the audit trail for a specific record modification. If there is no audit trail, every electronic record in the system is potentially unreliable. For paper records, walk through production and check for whiteout, erasures, or overwritten entries. These are classic data integrity failures.
Follow-Up Questions
- Show me the audit trail for a specific record that was modified. Who made the change, when, and what was the original entry?
- Are there any shared credentials in your quality record systems? How do you attribute entries to individuals?
- When was the last time you tested restoring from backup? Show me the test record.
What to Sample
Check physical access controls for the records room (actually try the door). Review user access permissions for 2 electronic records systems. Request an audit trail printout for one modified record. Inspect 5 paper records for correction compliance.
Objective Evidence
- ISO 13485 compliance matrix listing every clause that requires a documented procedure or record, mapped to the specific organizational document that addresses it -- verify all entries have a valid, current document reference
- Master list of all ISO 13485 mandatory documented procedures (approximately 18) with document numbers, titles, and current revision dates -- confirm each procedure exists and is current
- Master list of all ISO 13485 mandatory record types with retention requirements -- confirm the records control procedure addresses each type
- Gap analysis report from the most recent review showing whether any required procedures or records are missing or outdated
- Internal audit records showing the compliance matrix is verified during internal audits
Common Nonconformities
- Compliance matrix does not exist -- the organization relies on the quality manual to demonstrate coverage but the manual does not systematically address every 'shall' requirement (Minor NC).
- Matrix identifies all required procedures but some reference procedures that are 'in development' and have been in development for an extended period (Major NC for missing mandatory procedures).
- Matrix maps 4.2.5 records requirements to a single generic 'records control procedure' but does not identify the specific record types that must be maintained per each clause -- the mapping is too general to verify compliance (Observation).
- Procedures listed in the compliance matrix have been superseded or consolidated but the matrix has not been updated -- it references non-existent documents (Minor NC).
Auditor Tips
This is your tool for verifying systemic documentation completeness. Count the mandatory procedures: document control (4.2.4), record control (4.2.5), software validation (4.1.6), management review (5.6), training/competence (6.2), risk management (7.1), customer communication (7.2.3), design and development (7.3 if applicable), purchasing (7.4.1), production control (7.5.1), monitoring and measurement (8.2.4), internal audit (8.2.2), nonconforming product (8.3), CAPA (8.5.2/8.5.3), and advisory notices (8.2.3). If any are missing, it is a major finding. The compliance matrix should be a living document updated whenever procedures change.
Follow-Up Questions
- Walk me through how you verified that every mandatory procedure in ISO 13485 has been addressed.
- When was this compliance matrix last updated, and what triggered the update?
- Are there any mandatory procedures that are currently under revision or pending approval?
What to Sample
Verify the compliance matrix against a list of ISO 13485 mandatory documented procedures. Spot-check 5 entries by opening the referenced document to confirm it exists and is current. Check for any matrix entries that reference non-existent documents.
Objective Evidence
- Process interaction diagram or map in the quality manual showing all QMS processes with directional flow indicators -- verify it includes management processes, core/realization processes, support processes, and measurement/improvement processes
- Input/output definitions for at least 3 key process interactions showing what data, materials, or information transfers between processes and who is responsible for the handoff
- Feedback loops documented in the diagram showing how post-market data (complaints, CAPAs, audits) flows back to upstream processes (design, production, purchasing)
- Support process connections showing how training, calibration, document control, and infrastructure maintenance enable the core processes
- Evidence that the documented interactions reflect reality -- cross-reference with actual process records showing the described interactions occur in practice
Common Nonconformities
- Process interaction diagram shows only forward-flow (design to production to distribution) with no feedback from post-market surveillance, complaints, CAPAs, or management review back to design or production (Minor NC).
- Diagram shows fewer processes than the organization actually operates -- support processes (calibration, environmental monitoring, document control, IT, training, facility maintenance) are not depicted (Minor NC).
- Process interactions are described in text only with no visual representation -- a new employee or auditor cannot quickly understand how the QMS processes connect (Observation).
- The process interaction diagram was created during initial certification and has not been updated despite the addition of a post-market surveillance process, a supplier audit process, and the elimination of a separate receiving inspection process (Minor NC).
Auditor Tips
A good process interaction diagram tells the story of how the organization works. It should be understandable to someone unfamiliar with the company. The most common weakness is missing feedback loops -- data must flow backward from post-market activities to design and production. Check that support processes are shown as enabling the core processes, not floating independently. Ask the quality manager to trace a specific scenario through the diagram: 'If a customer complaint identified a design issue, show me the path information takes through your processes.' If they cannot trace it, the interaction documentation is inadequate or the interactions are not working.
Follow-Up Questions
- Trace a customer complaint through your process interaction diagram from receipt to resolution. Does the diagram show this path?
- When you added a new process to your QMS, was the process interaction diagram updated? Show me the before and after.
- How do support processes like training and calibration connect to your core processes in this diagram?
What to Sample
Compare the process interaction diagram against the process inventory for completeness. Trace one real-world scenario (complaint to CAPA to design change) through the diagram. Verify feedback loops exist for at least complaints, CAPAs, and management review.
Objective Evidence
- Manufacturing procedures or work instructions with sufficient detail for a trained operator to consistently produce the device -- including process parameters, equipment, tooling, environmental requirements, and in-process checkpoints
- Process flow diagram showing the complete manufacturing sequence from incoming materials through finished goods with inspection points, hold points, and decision points identified
- Packaging specifications including materials, configuration, labeling placement, seal parameters, and sterile barrier system validation references if applicable
- Storage condition specifications for raw materials, work-in-process, and finished goods -- including temperature, humidity, shelf life, and FIFO/FEFO requirements
- Distribution procedures covering shipping methods, cold chain requirements if applicable, handling restrictions, and distribution records for traceability
- Process validation records (IQ/OQ/PQ) for validated processes -- verify validations are current and cover actual operating conditions
Common Nonconformities
- Manufacturing work instructions for the molding process specify a temperature range of 180-200C and a pressure range of 80-100 bar, but the process validation was performed only at the center point (190C/90 bar) -- the validated window does not cover the full operating range specified in the work instructions (Major NC).
- Packaging specification for a sterile device references a packaging validation that was performed with the previous packaging material and has not been repeated since the material supplier was changed (Major NC).
- Storage conditions for the finished device specify 'store at room temperature' without defining the acceptable temperature range -- the warehouse has no temperature monitoring and experiences summer temperatures exceeding 40C (Minor NC).
- Distribution procedure does not address cold chain requirements for a temperature-sensitive in-vitro diagnostic reagent -- product is shipped via standard ground freight with no temperature indicators (Major NC if product is temperature-sensitive).
- Manufacturing procedure lacks sufficient detail for a critical assembly step -- the instruction says 'apply adhesive and cure per specification' without specifying adhesive quantity, application method, cure time, or cure temperature (Minor NC).
Auditor Tips
This is the Device Master Record (DMR) content in FDA terminology. It must be detailed enough that a qualified person could reproduce the device from these documents alone. Walk through the manufacturing procedure with a production operator and check whether they follow it step by step or deviate from it. Common gaps: packaging procedures that do not address sterile barrier integrity, storage conditions that are vague or unmonitored, and distribution procedures that ignore environmental requirements. Validated processes must be operated within the validated ranges -- check that work instruction parameters match validation ranges. If process validation has not been updated after changes, the device may be manufactured outside validated conditions.
Follow-Up Questions
- Walk me through this manufacturing procedure with the operator. Do they follow it exactly as written?
- Show me your process validation for this manufacturing step. Do the current operating parameters fall within the validated range?
- How do you verify that storage conditions are maintained throughout the supply chain to the end customer?
What to Sample
Select one manufacturing procedure and observe it in practice. Compare actual parameters to the procedure and to the validation. Check packaging specifications against the validated configuration. Verify storage conditions are monitored.
Objective Evidence
- Document revision numbering convention (e.g., Rev A/B/C, Rev 1.0/1.1/2.0) documented in the document control procedure -- verify it is consistently applied across all document types
- Revision history or change log within 3 documents showing what was changed in each revision -- verify changes are described with enough specificity to understand what changed and why
- Change identification methods such as revision bars, highlighted text, track changes summary, or change tables -- demonstrate that users can identify what changed between revisions
- Master document list with current revision status for all controlled documents -- verify this is the single source of truth and is kept current
- User-facing mechanism for confirming current version (e.g., banner on electronic documents showing 'current controlled version,' footer showing effective date and revision, or watermark system)
Common Nonconformities
- Revision history in a controlled document states 'various updates throughout' for a revision -- the specific changes are not identified, making it impossible to understand what changed and whether training is needed (Minor NC).
- Organization uses revision letters (A, B, C) for SOPs and revision numbers (1, 2, 3) for work instructions with no documented convention -- the inconsistency creates confusion about which is the latest version (Observation).
- Master document list shows a procedure at one revision level but the document available in the electronic system is at a different (older) revision -- the list and the system are out of sync, and personnel may be working from an obsolete version (Major NC).
- No change identification method is used -- users must compare entire documents revision-by-revision to identify changes, which is impractical for long procedures (Minor NC).
- Printed copies at workstations have no mechanism to indicate whether they are the current version -- there is no footer date, no revision status, and no comparison reference to the master list (Minor NC).
Auditor Tips
The purpose of this requirement is to prevent confusion about which version is current and what changed. Check three things: (1) can a user determine the current revision from the document itself, (2) can a user determine what changed from the previous revision, and (3) does the master list agree with what is actually available? A quick audit technique: pick up a document at a workstation and ask the user 'how do you know this is the current version?' If they cannot answer confidently, the identification system is inadequate. Electronic document management systems should enforce version control, but check that the system is configured correctly.
Follow-Up Questions
- How does an operator at a workstation know they are looking at the current version of a document?
- Show me the revision history for a document that has been revised at least 3 times. Can I understand what changed at each revision?
- What prevents someone from printing a document and using the printed copy after a new revision is issued?
What to Sample
Pick up 3 documents at points of use. Verify each shows the current revision matching the master list. Check revision histories in 2 documents for specificity of change descriptions.
Objective Evidence
- Record retention schedule showing each record type with its assigned retention period and the basis for that period (device lifetime, regulatory requirement, or 2-year minimum) -- verify the schedule uses the longest applicable period
- Device lifetime definitions for each device family showing how the organization determined expected device lifetime -- verify the methodology is rational (e.g., based on design life, wear-out data, clinical evidence, or industry norms)
- Regulatory retention requirements analysis for each applicable market showing the specific retention periods required by each regulation (e.g., FDA requires DHR for device lifetime; EU MDR Article 10(8) requires technical documentation for at least 10 years after last device is placed on market)
- Evidence of retention schedule review -- verify it is updated when new products are introduced, device lifetimes change, or new regulatory requirements emerge
- Disposition records for records that have been destroyed at end of retention period -- verify retention period had been fully satisfied before destruction
Common Nonconformities
- Retention schedule specifies '10 years' for all records without considering device lifetime or regulatory requirements -- for implantable devices with an expected lifetime of 15-20 years, records would be destroyed prematurely (Major NC).
- Device lifetime has not been formally defined for any device family -- when asked, the quality manager estimates '5-7 years' but this is not documented or justified with data (Minor NC).
- Retention schedule does not account for EU MDR Article 10(8) requirement to retain technical documentation for multiple years after the last device in the series is placed on the market -- the schedule was developed before EU MDR and only considers FDA requirements (Minor NC).
- Records for production lots were destroyed before the retention period should have ended -- the devices have an expected in-service life exceeding the retention period applied, meaning production records were destroyed while devices are still in active use (Major NC).
- Retention schedule addresses only quality records -- human resources records, calibration records, and facility maintenance records are not included despite being QMS records (Minor NC).
Auditor Tips
The retention calculation is: take the LONGEST of (device lifetime, regulatory requirement, 2-year minimum). For implantable devices, this can be 15-25+ years. For disposable devices, it might be 5-7 years. The 2-year minimum is a floor, not a target. Challenge organizations that use a single blanket retention period for all records -- different record types for different device types may require different retention. Device lifetime is the most commonly undocumented element. Ask how they determined it and look for documented rationale. Under FDA, the DMR must be retained for the lifetime of the device. Under EU MDR, 10 years after last device placed on market plus the device lifetime. Many organizations underestimate their retention obligations.
Follow-Up Questions
- How did you determine the expected lifetime for each of your device families? Show me the documented rationale.
- For your longest-lived device, what is the required retention period and are all associated records being retained that long?
- Have you ever had to retrieve a record that was close to or past its retention period? What was the situation?
What to Sample
Review the retention schedule for 3 device families. Verify device lifetime is documented. Check that the longest applicable period is used. Verify no records have been destroyed prematurely.
Objective Evidence
- List of organization-determined documents (beyond ISO 13485 mandatory documents) with rationale for each -- e.g., work instructions for complex assembly, visual inspection standards with reference photos, equipment operation manuals, troubleshooting guides
- Risk-based justification for documentation decisions -- evidence that the organization assessed which processes need additional documentation based on complexity, risk, and personnel experience
- Work instructions for critical or complex manufacturing steps -- verify these provide sufficient detail beyond what is in the higher-level procedure
- Visual standards, reference samples, or limit samples for subjective inspections -- verify these exist where visual judgment is required
- Technical references, equipment manuals, and calculation aids that support process execution -- verify these are controlled if they contain quality-critical information
Common Nonconformities
- Complex multi-step manufacturing process relies entirely on operator experience with no work instruction -- the procedure mentions the process but provides no step-by-step detail, and operators perform the process differently between shifts (Minor NC if no quality issues; Major NC if defects are occurring).
- Visual inspection for cosmetic defects has no reference standards, limit samples, or acceptance photographs -- inspectors shown the same defect made different accept/reject decisions during the audit (Minor NC).
- Organization determined that 'no additional documents are needed beyond ISO requirements' but has a complex, multi-step sterilization loading process that is performed entirely from memory -- new operators learn the process informally from experienced operators over an extended period (Observation).
- Equipment operation manual from the manufacturer is used on the shop floor but is not controlled within the document management system -- it is an uncontrolled external document that contains quality-critical setup parameters (Minor NC).
Auditor Tips
This clause gives the organization discretion to determine what additional documentation they need. The audit question is whether that determination is rational and adequate. A 3-person workshop might genuinely need fewer documents than a 300-person factory, but the decision should be risk-based, not arbitrary. Red flags: complex processes with no work instructions, subjective inspections with no visual standards, and new employees who 'learn from watching' rather than from documents. The test is: if your most experienced operator left tomorrow, could a qualified replacement person do the job from the available documentation? If not, more documentation is needed.
Follow-Up Questions
- Is there any process where a new employee would struggle to learn from documentation alone? What supplemental documents would help?
- For your most complex manufacturing step, show me the documentation available to the operator. Is it sufficient?
- How do you decide when a process needs a work instruction versus just a procedure?
What to Sample
Identify the most complex manufacturing process and verify adequate documentation exists. Check whether visual inspections have reference standards. Ask 2 operators if they feel they have enough documentation to do their job correctly.
Objective Evidence
- Documentation hierarchy section of the quality manual showing the relationship between document levels (e.g., manual, procedures, work instructions, forms/records) with descriptions of what each level contains
- Document numbering and classification system explanation showing how documents are categorized, numbered, and identified -- verify the system is logical and enables easy navigation
- Documentation roadmap or guide for users explaining how to find, access, and navigate QMS documents -- particularly important for new employees or auditors
- Visual diagram (documentation pyramid, tree structure, or matrix) illustrating the documentation architecture
- Example showing how the structure works in practice: starting from the quality manual, navigating to a procedure, then to a work instruction, then to a form or record
Common Nonconformities
- Quality manual does not contain any description of the documentation structure -- the hierarchy is 'understood' by long-term employees but is not documented anywhere (Minor NC).
- Documentation structure diagram shows 4 levels but the actual document management system has 6 document types that do not map to any level in the hierarchy -- specifications, engineering drawings, and validation protocols are not categorized (Minor NC).
- Document numbering system has evolved organically over many years with multiple numbering schemes in use simultaneously -- there is no unified classification system and users cannot determine a document's type or category from its number (Observation).
- Documentation structure outline exists but is so complex (excessive levels and categories) that users report they cannot find documents and resort to asking colleagues rather than navigating the system (Observation).
Auditor Tips
The documentation structure outline is the 'map' of the QMS documentation. It should help users understand what types of documents exist, how they relate to each other, and how to find what they need. The classic four-level pyramid (manual, procedures, work instructions, forms/records) works for many organizations but is not the only valid approach. Whatever structure is chosen, it must be clearly described and consistently applied. A good test: give a new employee the quality manual and ask them to find a specific work instruction using only the documentation structure information in the manual. If they cannot navigate to it, the structure is inadequate.
Follow-Up Questions
- Using the documentation structure in the manual, show me how a new employee would find the work instruction for a specific production step.
- Has your documentation structure ever been revised to improve usability? What changed?
- Do all document types in your system fit within the documented hierarchy, or are there orphan categories?
What to Sample
Read the documentation structure section of the quality manual. Verify it covers all document types actually used. Test navigability by trying to find one specific document using only the structure description.
Objective Evidence
- Incoming inspection procedures for critical materials and components with specific test methods, acceptance criteria, and sampling plans (including AQL levels and statistical rationale for sample sizes)
- In-process inspection and test procedures at each quality checkpoint in the manufacturing process -- with control charts, SPC data, or equivalent monitoring data showing processes are in control
- Final inspection and testing procedures (final release testing) with complete acceptance criteria covering all specification parameters -- verify the test procedure covers every product specification
- Test equipment and measurement tools specified for each inspection -- with calibration status and measurement system analysis (GR&R) evidence showing the measurement system is capable
- Sampling plans with statistical justification (e.g., ANSI/ASQ Z1.4 for attributes, ANSI/ASQ Z1.9 for variables) showing the AQL, inspection level, and switching rules
Common Nonconformities
- Incoming inspection sampling plan uses AQL 4.0 (4% acceptable defect level) for a critical biocompatibility-tested material without justification for why 4% nonconforming is acceptable for a patient-contacting component (Minor NC).
- Final test procedure does not test all product specification parameters -- some specifications including safety-critical parameters have no test procedure and are not verified before release (Major NC).
- In-process inspection for dimensional measurements uses a caliper with 0.01mm resolution to measure a tolerance of +/-0.02mm -- the measurement system has inadequate discrimination (10:1 rule not met) and GR&R has never been performed (Minor NC).
- Sampling plan for final release testing is 'per inspector judgment' with no defined sample size, AQL, or statistical rationale -- different inspectors test different sample sizes for the same lot (Minor NC).
- No in-process inspection points exist for a multi-step manufacturing process -- all inspection occurs at final test, meaning nonconforming product progresses through the entire manufacturing process before detection (Observation).
Auditor Tips
Measuring and monitoring procedures are the organization's evidence that the device meets specifications. Every product specification should have a corresponding test or inspection that verifies it. Look for gaps where specifications exist but no test procedure covers them -- this is a common finding. Sampling plans must be statistically justified, not arbitrary. AQL levels must be appropriate for the risk level of the attribute being tested -- safety-critical attributes may require 100% testing or tightened inspection. Measurement system capability (GR&R) is often overlooked but is critical: if the measurement system cannot reliably distinguish conforming from nonconforming product, the inspection is meaningless.
Follow-Up Questions
- Show me the traceability between product specifications and test procedures. Is every specification verified by a test?
- What is the statistical rationale for your sampling plans? How did you determine the AQL levels?
- Have you performed measurement system analysis (GR&R) for your critical measurements? Show me the results.
What to Sample
Compare the product specification list against the test procedure list to identify untested specifications. Review sampling plans for statistical rationale. Check measurement system capability for one critical measurement. Verify calibration status for 2 pieces of test equipment.
Objective Evidence
- Document distribution matrix showing which documents are required at which locations/workstations -- verify it is current and reflects actual operational needs
- Point-of-use document verification at 3 locations (production workstation, inspection area, and laboratory or warehouse) -- compare document revisions against the master document list
- Electronic access capability at points of use -- verify personnel can access current documents from their workstation (terminals, tablets, or printed controlled copies)
- Controlled copy management procedure (if paper copies are used) showing how controlled copies are issued, tracked, and recalled when revisions occur
- Access log or usage data from the electronic document management system showing that operators actually access and view documents -- not just that they theoretically can
Common Nonconformities
- Printed work instruction found at a workstation that does not match the current revision on the master document list -- the distribution control process failed to recall and replace the obsolete copy (Major NC).
- Electronic document management system is available on only a few terminals for a production area with many workstations -- operators report they rarely access procedures because the terminals are not conveniently located (Observation leading to risk of operators working from memory).
- Document distribution matrix requires specific documents at a workstation but not all are present -- required test procedures or acceptance criteria specifications are missing (Minor NC).
- Controlled paper copies at workstations are laminated and mounted on the wall but the lamination is yellowed and cracked, making portions of the text difficult to read -- documents are available but not legible (Minor NC).
- Night shift operators do not have access to the electronic document management system because the system undergoes nightly maintenance from 11 PM to 3 AM -- during this window, operators work from memory (Minor NC).
Auditor Tips
This is a floor-walk finding -- you must physically go to points of use and check. Do not rely on the document controller's assurance that 'all copies are current.' Pick up the document at the workstation, note the revision, and compare it to the master list. Check multiple locations including areas that are less visible (storage rooms, shipping docks, remote production cells). For electronic systems, verify that operators actually know how to access documents and do so regularly -- an electronic system that nobody uses is as ineffective as missing paper copies. Ask an operator to show you how they would access a specific procedure right now.
Follow-Up Questions
- Show me the procedure for recalling and replacing documents when a new revision is issued. How long does the replacement take?
- Can you access the current version of your work instruction from this workstation right now? Show me.
- When was the last time a discrepancy was found between a point-of-use document and the master list? What corrective action was taken?
What to Sample
Walk to 3 different work areas. At each, check 2 documents against the master list for current revision. Ask one operator to demonstrate accessing a document. Check a less-visited area (warehouse, shipping) for document availability.
Objective Evidence
- Procedure or policy for protecting confidential health information (CHI/PHI/PII) in quality records -- identifying what types of health information exist in QMS records and how they are protected
- Privacy regulation compliance analysis identifying which privacy regulations apply (HIPAA, GDPR, Health Canada PIPEDA, etc.) and how the organization meets each applicable requirement
- Access control implementation for records containing health information -- restricted access lists, encryption for electronic records, locked storage for paper records, with regular access reviews
- Training records showing personnel who handle health information have been trained on privacy requirements and protection methods
- Breach notification procedure and any incident records -- showing the organization is prepared to respond if health information is compromised
Common Nonconformities
- Clinical investigation records containing patient names, dates of birth, and medical history are stored in an unlocked filing cabinet accessible to all production floor personnel -- no access restrictions exist for records containing protected health information (Major NC).
- Complaint records include patient identifiers (name, hospital, treating physician) but the organization has no PHI protection procedure and no HIPAA or GDPR compliance program despite operating in both US and EU markets (Major NC).
- Electronic complaint database contains patient health information but access is not role-restricted -- all employees with system access can view patient details regardless of job function or need-to-know (Minor NC).
- Organization ships devices to EU hospitals and receives adverse event reports containing patient data but has not identified GDPR applicability or designated a Data Protection Officer as required (Minor NC).
- Privacy training has not been conducted -- personnel who handle complaint records and clinical data have never received training on confidential health information protection requirements (Minor NC).
Auditor Tips
This requirement is often overlooked because organizations do not think of themselves as 'handling health information.' But any organization that receives complaint reports, adverse event reports, clinical investigation data, or customer feedback involving patient cases likely has protected health information in their records. Ask where patient information might appear in quality records: complaints, CAPA investigations, post-market surveillance reports, clinical evaluation reports, and vigilance reports. Under GDPR, even de-identified health data may still be considered personal data if re-identification is possible. The requirement says 'in accordance with applicable regulatory requirements,' so determine which privacy regulations apply before assessing compliance.
Follow-Up Questions
- Where in your quality records might patient health information appear? Have you performed an inventory?
- Which privacy regulations apply to your organization, and how have you determined that?
- Show me the access controls for records that contain patient health information. Who can access them and why?
What to Sample
Check access controls for complaint records and clinical investigation records. Verify that records containing health information have restricted access. Ask whether a privacy impact assessment or data inventory has been performed.
Objective Evidence
- Regulatory documentation index listing all applicable regulations by market (FDA, EU MDR, Health Canada MDR, MDSAP, TGA, PMDA, ANVISA, etc.) and the specific documentation each requires
- FDA-specific documentation: Design History File (DHF), Device Master Record (DMR), Device History Record (DHR), Medical Device Reporting records -- verify they exist and are maintained
- EU MDR-specific documentation: Technical Documentation per Annex II, Clinical Evaluation Report per Annex XIV, Post-Market Surveillance plan and report, PSUR -- verify they exist and are current
- Regulatory submission files (510(k), CE Technical File, De Novo, PMA) with current status and any conditions or commitments
- Regulatory intelligence process showing how the organization identifies new or changing regulatory requirements and updates documentation accordingly
Common Nonconformities
- Organization sells devices in multiple markets but regulatory documentation index only addresses a subset of jurisdictions -- documentation requirements for some markets where devices are sold have not been identified (Minor NC).
- EU MDR Technical Documentation was prepared for initial certification but has not been updated to reflect design changes, labeling changes, and a new clinical evaluation completed since certification -- documentation does not reflect the current device (Major NC).
- FDA Design History File (DHF) does not exist as a coherent file -- design documents are scattered across engineering, quality, and regulatory departments with no index, no cross-referencing, and no completeness verification (Minor NC -- Major NC if FDA inspection is imminent).
- Organization has no regulatory intelligence process -- when EU MDR replaced the Medical Device Directive, the organization was caught unprepared because they had no mechanism to track regulatory changes (Observation).
- Clinical Evaluation Report required by EU MDR Article 61 is outdated and has not been updated with post-market clinical data collected since the original report -- the clinical evidence base does not reflect current experience (Minor NC).
Auditor Tips
Organizations that sell in multiple markets must maintain documentation for each market's regulatory requirements. The documentation burden compounds quickly. FDA requires DHF/DMR/DHR structure. EU MDR requires Annex II/III Technical Documentation. MDSAP adds country-specific requirements for Canada, Brazil, Japan, and Australia. Ask 'in which countries are your devices registered?' and then check documentation for each. Under EU MDR, Technical Documentation must be a living document updated with post-market data. Under FDA QMSR (effective 2026), the emphasis shifts to ISO 13485 alignment but the DHF/DMR/DHR structure remains fundamental. Organizations transitioning to QMSR should be updating their documentation structure.
Follow-Up Questions
- In which countries are your devices registered or marketed? Show me the documentation required for each.
- Has your EU MDR Technical Documentation been updated since initial certification? When and what triggered the updates?
- How do you monitor for new or changing regulatory requirements that affect your documentation obligations?
What to Sample
Verify the regulatory documentation index covers all markets where devices are sold. Check one market's documentation for completeness (e.g., EU MDR Annex II checklist). Verify the most recent regulatory change has been reflected in documentation.
Objective Evidence
- Installation procedure or installation manual covering step-by-step installation instructions, site requirements, environmental requirements, utility requirements, and safety precautions -- verify completeness for all device configurations
- Installation qualification (IQ) protocol or checklist used to verify the device is correctly installed -- including acceptance criteria for installation verification
- Installer qualification requirements defining who is authorized to install the device (manufacturer, authorized service provider, customer with training) and what training or certification they need
- Installation record or certificate template used to document completed installations with verification results
- N/A justification document (if installation is not required) showing the rationale -- verify the device truly does not need any form of installation, setup, or commissioning
Common Nonconformities
- Capital equipment medical device (laboratory analyzer) requires professional installation including plumbing connections, electrical wiring, and software configuration, but the device file contains no installation procedure -- field service engineers install from experience without documented procedures (Major NC).
- Installation procedure exists but does not address software setup and configuration, which is performed separately by IT personnel at the customer site without documented instructions or acceptance criteria (Minor NC).
- Installation is marked 'N/A' for a patient monitoring system that requires wall mounting, electrical connection, network configuration, and alarm threshold setup -- all of which constitute installation activities (Major NC for inappropriate exclusion).
- Installation records show no failed installation verifications -- a 100% first-time pass rate suggests either the verification is not rigorous or installations are genuinely simple, which contradicts the complexity of the installation manual (Observation).
- Third-party installation service providers are used but no quality agreement governs the installation activity and no installer qualification requirements are defined (Minor NC).
Auditor Tips
'As appropriate' means the organization must determine whether installation applies and document that determination. Anything requiring setup, configuration, connection, calibration, or commissioning at the use site constitutes installation. Software-configurable devices always have installation requirements even if the hardware is simple. If the organization uses third-party installers, those are outsourced processes requiring quality agreements per 4.1.5. Installation IQ/OQ protocols are standard practice for capital equipment. Check installation records for completeness and whether installation verification actually tests the installed device. A blank installation checklist signed 'complete' without specific measurements or observations is inadequate evidence.
Follow-Up Questions
- If a third party installs your device, how do you verify the installation was done correctly?
- Show me the last 3 installation records. Were any installation verifications failed or remediated?
- Does your device have any software configuration during installation? How is that addressed in the installation procedure?
What to Sample
Review the installation procedure for completeness. Check 2 installation records for proper completion. Verify installer qualification records if third parties perform installation. If marked N/A, challenge the justification.
Objective Evidence
- Document identification standards defining what must appear on every controlled document (title, document number, revision, effective date, page numbering, approval authority) -- check 5 random documents for compliance
- Physical protection measures for paper documents at points of use (lamination, protective sleeves, climate-controlled storage) -- verify by inspection at workstations
- Electronic format standards defining acceptable file formats for long-term readability (e.g., PDF/A for archival, controlled access to proprietary formats) and migration procedures when formats become obsolete
- Backup and disaster recovery procedures for electronic documents with evidence of testing -- verify recovery time objectives and recovery point objectives are defined
- Legibility verification for aged documents -- pull a document from archival storage and verify it is still readable
Common Nonconformities
- Paper work instructions at 3 production workstations are faded, stained, and partially torn -- the text is difficult to read in sections and operators confirm they 'know the process by heart' rather than relying on the degraded documents (Minor NC).
- Document identification is inconsistent: SOPs include document number, revision, and date; work instructions include only a title; forms include a form number but no revision; engineering drawings use a completely separate numbering system -- identification is not standardized (Minor NC).
- Electronic documents are stored exclusively in a proprietary format that requires specific software to open -- no contingency plan exists for the scenario where the software vendor discontinues the product or the file format becomes obsolete (Observation).
- Electronic backup is performed nightly to an off-site server but the backup has never been tested for recoverability -- the organization cannot confirm that backed-up documents are actually recoverable and legible (Minor NC).
- Archived paper documents stored in a basement are exposed to moisture and some show signs of mold growth -- legibility is being compromised by inadequate storage conditions (Minor NC).
Auditor Tips
Legibility and identifiability are practical requirements that are best assessed through observation. During your floor walk, look at documents physically -- are they readable? Check for fading, staining, tearing, or smudging. For electronic documents, the concern is long-term accessibility: will the format still be readable in 10-15 years? PDF/A is the gold standard for archival. Identification should be consistent -- if an uncontrolled page is separated from its parent document, can someone identify what it is? Every page should have enough identification to be traceable. Check archived documents too, not just active ones.
Follow-Up Questions
- Pull a document from your archives that is at least 5 years old. Is it still legible?
- What file format do you use for long-term storage of electronic documents, and have you verified it will remain accessible?
- If a single page falls out of a printed procedure, can someone identify which document it belongs to from the page alone?
What to Sample
Physically inspect documents at 3 workstations for legibility. Check identification consistency across 5 document types. Retrieve one archived document and verify legibility. Verify electronic backup recoverability evidence.
Objective Evidence
- Indelible ink policy or requirement for paper records -- verify production areas use approved pens and that records do not show pencil entries, erasures, or fading ink
- Environmental controls for paper record storage including temperature, humidity, light exposure, and pest control -- verify storage areas meet defined conditions
- Electronic record system validated per 4.1.6 with controls for long-term data integrity -- including format migration plans, media refresh schedules, and system obsolescence planning
- Record identification scheme showing how records are uniquely identified for retrieval -- verify 3 records can be located using the identification system within 5 minutes each
- Periodic legibility verification or record condition assessment -- evidence that archived records are periodically checked for degradation
Common Nonconformities
- Production batch records use thermal printer receipts for label verification -- thermal paper fades over time and records are already becoming illegible while the retention requirement extends far beyond the expected legibility period (Major NC).
- Records are retrievable by lot number but not by date range, product type, or customer -- when a field corrective action required identifying all devices shipped to a specific customer within a time window, records could not be retrieved by that criterion (Minor NC for retrieval capability).
- Electronic records in a legacy database are at risk because the database software (MS Access 2010) is no longer supported and the IT department has flagged potential migration issues -- no plan exists to migrate records to a supported platform (Observation -- becomes Minor NC if records become inaccessible).
- Paper records stored in off-site archive use a numbering system that was changed during a prior system update -- records stored before the change use the old system and records after the change use the new system, with no concordance table -- archivists cannot reliably locate older records (Minor NC).
- Handwritten inspection records from the second shift are frequently illegible due to rushed entries and poor handwriting -- specific dimensional values cannot be read with certainty (Minor NC for data integrity).
Auditor Tips
Records have a longer critical lifespan than documents because they are evidence that activities occurred. A record that becomes illegible is the same as a missing record -- you cannot prove the activity happened. Thermal paper is the single biggest legibility risk for paper records: it fades rapidly and is used in many label printers, receipt printers, and test equipment printouts. If you see thermal paper, it is almost certainly a finding. For electronic records, the risk is format obsolescence and media degradation. Ask about records from 5+ years ago and verify they are still accessible and readable. Retrievability must be practical: if it takes 2 hours to find a specific record, it is not 'readily retrievable.' Test this by requesting a specific record and timing the response.
Follow-Up Questions
- Do any of your records or record attachments use thermal paper? How do you prevent fading?
- Show me a record from 5 years ago. Is it still legible, identifiable, and was it retrievable in a reasonable time?
- What is your plan for records stored in legacy electronic systems that may become unsupported?
What to Sample
Request 3 records from different time periods (recent, 2 years ago, 5+ years ago). Verify each is legible, identifiable, and was retrievable in under 10 minutes. Inspect paper records for thermal paper usage. Check electronic system for media refresh evidence.
Objective Evidence
- Service manual or servicing procedures covering preventive maintenance schedules, diagnostic procedures, repair instructions, and calibration procedures -- verify completeness for all serviceable device configurations
- Spare parts list with part numbers, specifications, and approved suppliers -- verify parts are identified for all serviceable components
- Field service technician qualification requirements defining training, certification, and competency requirements for personnel authorized to service the device
- Service record templates showing what must be documented during each service event -- including device identification, work performed, parts replaced, calibration results, and verification of proper function after service
- Service feedback loop to design and quality -- procedures or records showing how service data (failure modes, parts consumption, customer feedback) is collected, analyzed, and fed back to product improvement
- N/A justification if servicing is not applicable -- verify the device truly requires no maintenance, repair, or calibration during its intended lifecycle
Common Nonconformities
- Medical device (patient monitor) requires annual calibration and preventive maintenance but the device file contains no servicing procedures -- field service engineers use an informal checklist that has never been reviewed, approved, or controlled (Major NC).
- Spare parts list has not been updated since the device was first released -- some components have been redesigned and some obsoleted, but the spare parts list still references the original part numbers (Minor NC).
- Third-party service providers perform maintenance on the organization's devices in the field but no service training program exists and no qualification requirements are defined for third-party technicians (Minor NC).
- Service records are collected but not analyzed -- the organization has accumulated field service data showing a recurring failure mode in a specific component but no corrective action has been taken because service data is not reviewed by engineering (Minor NC).
- Servicing is marked 'N/A' for a surgical instrument that has a defined reprocessing cycle, recommended replacement of wear components, and a calibration requirement for the force-sensing feature -- all of which constitute servicing (Major NC for inappropriate exclusion).
Auditor Tips
'As appropriate' means the organization must assess whether servicing applies and justify the determination. Devices with moving parts, electronic components, software, batteries, sensors, consumable elements, or calibration needs require servicing. Even disposable devices may need cleaning or reprocessing instructions if they are reusable. The servicing procedures in the device file must be sufficient for qualified personnel to maintain the device safely. Check for a feedback loop: service data is a gold mine for design improvement, and organizations that do not analyze it miss opportunities to improve reliability and safety. Under EU MDR, Article 2(3) defines servicing activities that must be controlled. FDA has cited organizations for inadequate service procedures when field failures resulted from improper servicing.
Follow-Up Questions
- How do you collect and analyze field service data? Show me the most recent analysis.
- Show me the qualification records for your field service technicians. What training do they receive?
- Has field service data ever led to a design change or product improvement? Show me an example.
What to Sample
Review the servicing procedures for completeness. Check the spare parts list against current design. Verify service technician training records. Review 3 service records for completeness. Check whether service data analysis has been performed.
Objective Evidence
- External document register listing all external documents incorporated into the QMS -- with document name, source, version/edition, date verified current, location within QMS, and responsible person for monitoring updates
- Currency verification records showing when each external document was last checked for updates -- verify a systematic process exists (subscriptions, periodic checks, industry alerts)
- Distribution control for external documents showing how authorized copies are made available and how obsolete versions are withdrawn when updates are published
- Subscription or alert services for key standards and regulations -- evidence that the organization proactively monitors for changes rather than discovering updates reactively
- Process for incorporating external document changes into the QMS -- showing how a new edition of a standard triggers review of affected internal procedures
Common Nonconformities
- External document register lists ISO 13485:2016 and ISO 14971 but does not include many other external documents referenced in internal procedures: harmonized standards (e.g., IEC 60601, IEC 62304, ISO 10993 series), customer specifications, industry guidelines, and regulatory guidance documents (Minor NC).
- Organization references a superseded edition of a key harmonized standard in their risk management procedure but the current edition has been published -- the obsolete standard has been in use for an extended period without detection (Minor NC or Major NC depending on whether the procedural requirements differ meaningfully).
- A customer specification referenced in the manufacturing procedure has been superseded by the customer with changed acceptance criteria, but the organization is still manufacturing to the outdated version (Major NC).
- No external document register exists -- the organization has not identified which external documents are incorporated into their QMS (Minor NC).
- External standards are controlled through the organization's subscription to an online standards service, but the subscription has expired and the organization is using cached copies that may not be current (Minor NC).
Auditor Tips
External document control is one of the most frequently overlooked requirements. Organizations focus on internal documents and forget that standards, regulations, customer specifications, and supplier documents are equally subject to control. The most common finding is using superseded editions of standards -- ask to see the edition referenced in procedures and compare against the current published edition. Customer specifications are another gap area: changes issued by customers may not be captured in the organization's change management system. For regulations, ask how the organization monitors for regulatory changes in each market. If the answer is 'we check when the auditor tells us,' the process is reactive and inadequate.
Follow-Up Questions
- How do you learn when a standard you reference has been updated? Show me the process.
- When was the last time an external document update triggered changes to your internal procedures? Walk me through that example.
- Do you reference any customer-provided specifications? How do you ensure you always have the current version?
What to Sample
Review the external document register for completeness. Verify currency of 3 external standards referenced in internal procedures. Check one customer specification for current version. Verify the organization has a process for monitoring regulatory changes.
Objective Evidence
- Record correction procedure defining how corrections are made to both paper records (single-line strikethrough, initials, date, reason) and electronic records (audit trail requirements, correction fields, reason for change)
- Paper record examples showing compliant corrections -- single-line strikethrough with original data visible, corrector's initials, date, and reason for change (if not obvious)
- Electronic audit trail printout showing a specific record change with who made the change, when, what was changed (old value and new value), and the reason
- Training records showing personnel who create records have been trained on correction procedures
- Inspection of 10 random paper records for correction compliance -- looking for any use of whiteout, erasure, overwriting, or corrections without proper attribution
Common Nonconformities
- Multiple production batch records show corrections made with white correction fluid (whiteout) covering original entries -- the original data has been permanently obscured and the corrections are not attributed to any individual (Major NC for data integrity).
- Electronic inspection records in the QMS database can be overwritten by any user with no audit trail, no capture of original values, and no attribution of who made the change -- data integrity controls are absent (Major NC).
- Paper records show corrections with single-line strikethrough and initials, but dates are not included on any corrections -- it is impossible to determine when the corrections were made relative to the original entries (Minor NC).
- Record correction procedure requires a 'reason for change' on every correction but the majority of corrections on sampled records have no reason documented -- the procedure is not being followed (Minor NC).
- Operator logbook shows entries that appear to have been erased and re-written in different ink -- the original entries are not recoverable and the changes are not traceable (Major NC for data integrity).
Auditor Tips
Record correction compliance is a direct indicator of data integrity culture. Go through actual records with a fine-tooth comb. Look for whiteout (feel the page surface for bumps), erasures (look for smudged or lighter areas), overwritten entries (look for two layers of writing), and undated or uninitialed corrections. For electronic records, the audit trail is the key control -- if the system has no audit trail, every record in that system is suspect. Ask to see a demonstration: have someone make a correction to a test record and verify the audit trail captures everything required. The FDA's data integrity guidance is clear: original data must be preserved, changes must be traceable, and attributable. ALCOA+ principles apply to corrections.
Follow-Up Questions
- Show me how a correction is made in your electronic quality system. Is the original value preserved?
- Make a correction to a test record in front of me. Now show me the audit trail for that correction.
- When was the last time someone was coached on proper record correction practices?
What to Sample
Inspect 10 paper records for correction compliance (strikethrough, initials, date, reason). Check the audit trail capability of 2 electronic systems. Make a test correction and verify the audit trail captures it. Look specifically for whiteout or erasures.
Objective Evidence
- Document protection procedure or section within the document control procedure addressing physical protection (environmental controls, fire suppression, water damage prevention, pest control) and electronic protection (backup, redundancy, cybersecurity, disaster recovery)
- Backup schedule and backup verification records for electronic document systems -- verify backups occur at the defined frequency and have been tested for recoverability within the last 12 months
- Disaster recovery plan covering both paper and electronic documents with defined recovery time objectives, recovery point objectives, and roles/responsibilities -- verify the plan has been tested or exercised
- Environmental monitoring records for physical document storage areas -- temperature, humidity, and any incidents of environmental excursion
- Business continuity plan addressing document access during system outages, facility damage, or other disruptions
Common Nonconformities
- Electronic document management system is backed up nightly but the backup has never been tested for recoverability -- the organization cannot confirm that documents could be restored from backup in a disaster scenario (Minor NC).
- Paper document archive is located in a basement that has experienced water intrusion -- despite a known risk, no document relocation, waterproofing, or protection measures have been implemented (Minor NC).
- No disaster recovery plan exists for the electronic QMS system -- if the server hosting the document management system failed, the organization has no documented plan for restoring access to controlled documents (Minor NC).
- Server room housing the electronic document system has no fire suppression system and no uninterruptible power supply -- a fire or power surge could result in total loss of all electronic QMS documents (Observation or Minor NC depending on risk).
- Organization migrated from paper to electronic documents but the original paper documents were destroyed after scanning without verifying scan quality -- some scanned documents are partially illegible (Minor NC).
Auditor Tips
This requirement is about proactive protection, not reactive recovery. Ask 'what would happen to your documents if there was a fire tonight?' The answer reveals the maturity of protection measures. Key checks: backup testing (untested backups are unreliable), off-site backup storage (on-site only is vulnerable to local disasters), environmental controls for paper storage, and cybersecurity for electronic systems. Ransomware is an emerging threat that can encrypt all electronic documents simultaneously -- ask about cybersecurity controls and whether the backup is isolated from the primary network. For paper documents, the biggest risks are fire, water, and pest damage. Organizations that have migrated to electronic often neglect the remaining paper documents.
Follow-Up Questions
- When was the last time you tested restoring documents from backup? Show me the test record.
- If your main server was destroyed tonight, how long would it take to restore access to controlled documents?
- Do you have off-site backup or redundancy for your electronic documents?
What to Sample
Verify backup schedule and latest backup test record. Inspect physical document storage for environmental risks. Check whether disaster recovery plan exists and has been tested. Verify cybersecurity controls for the document management system.
Objective Evidence
- Obsolete document control procedure defining the process for withdrawing, marking, and archiving or destroying obsolete documents -- covering both paper and electronic documents
- A recent example of a document made obsolete: show the change notice, the recall from points of use, the marking/stamping applied, and the archive record
- Obsolete document identification method for retained copies: stamps ('OBSOLETE'), watermarks, electronic flags, restricted access -- verify the method is consistently applied
- Verification records showing that obsolete copies were recalled from all distribution points -- a confirmation process that all known copies were accounted for
- Electronic document management system configuration showing how obsolete documents are handled: moved to archive section, access restricted, clearly labeled, removed from active search results
Common Nonconformities
- Obsolete revision of a controlled procedure found in active use at a workstation while the master document list shows a newer current revision -- indicating distribution control failure for a document that has been superseded (Major NC).
- Obsolete paper documents are retained in the same filing cabinet as current documents with no distinguishing marks -- only the filing date differentiates current from obsolete copies, creating a high risk of unintended use (Minor NC).
- Electronic document management system retains obsolete versions alongside current versions in the same folder with no visual indicator of obsolete status -- users must check the revision number against the master list to determine currency (Minor NC).
- Organization destroys all obsolete documents immediately upon supersession but the document control procedure requires retention of one archive copy -- the procedure is not being followed and historical document versions are being lost (Minor NC).
- Controlled copy recall process relies on email notification to copy holders but there is no confirmation or verification step -- when a procedure was revised, several printed controlled copies were not returned or replaced (Minor NC).
Auditor Tips
Finding an obsolete document in active use is one of the most straightforward and common findings in QMS auditing. It is also one of the most impactful because it means an operator, inspector, or engineer is working to outdated instructions. Always check documents at points of use during floor walks. The electronic environment creates a new challenge: obsolete electronic documents that remain accessible in shared folders, email attachments, or personal downloads. Organizations with electronic systems sometimes have better version control in the DMS but worse control in practice because users download documents locally and never update them. Ask operators where they get their documents -- if they say 'I have a copy on my desktop,' that copy may be obsolete. Retained obsolete copies must be clearly marked -- 'OBSOLETE' stamp, watermark, or electronic flag.
Follow-Up Questions
- Show me where you keep retained obsolete copies. How are they marked and can someone accidentally use them?
- When you issue a new revision of a document, how do you verify that all old copies are recalled or replaced?
- Do any operators keep personal copies of documents on their computer desktops or in local folders?
What to Sample
Check documents at 3 points of use for current revision. Ask to see the obsolete document archive and verify marking. Check one recent obsolescence for evidence that all distributed copies were recalled. Ask 2 operators where they access their documents.
Objective Evidence
- Document change approval authority matrix defining who can approve changes to each document type -- showing both primary and alternate approvers with required competencies
- Change approval records for 3 recent document changes showing the approver's identity, competence basis, and access to background information (e.g., the change request, related CAPA, customer feedback, or regulatory requirement that drove the change)
- Delegation procedure for cases where the original approving function is unavailable -- showing how alternate approvers are qualified and provided with necessary background information
- Evidence of cross-functional review for document changes affecting multiple departments -- meeting minutes, review comments, or electronic workflow showing input from affected parties
- Competency records for current document change approvers showing relevant technical qualifications
Common Nonconformities
- Manufacturing work instruction changes are approved exclusively by the quality department without review by manufacturing engineering or production supervisors who have technical knowledge of the process -- the approver may not understand the practical implications of the changes (Minor NC).
- When the primary approver (engineering manager) is unavailable, changes are approved by the quality coordinator who has no engineering background and no access to the technical rationale for the changes -- the delegate lacks 'pertinent background information' (Minor NC).
- Change approval records show only signatures and dates with no evidence that the approver reviewed the actual changes, understood the rationale, or assessed the impact -- approvals appear to be rubber stamps (Observation).
- Document changes driven by CAPA actions were approved by the CAPA owner without providing the approver with the original CAPA investigation, root cause analysis, or effectiveness criteria -- the approver did not have access to the pertinent background (Minor NC).
Auditor Tips
The key phrase is 'pertinent background information.' The approver must understand WHY the change is being made, not just WHAT changed. If a change is driven by a CAPA, the approver should have access to the CAPA record. If driven by a customer requirement, the approver should see the customer communication. Ask the approver: 'why was this change made?' If they cannot explain the rationale, they did not have pertinent background information when they approved it. The standard allows alternate approvers ('another designated function') but they must be competent and informed. A rotating duty approver who signs everything without reading is not compliant.
Follow-Up Questions
- For this specific change, what background information did the approver have access to when they approved it?
- If the original approver is on leave, who approves changes and how are they brought up to speed on the technical context?
- Show me a change that was rejected during the review process. What was the reason for rejection?
What to Sample
Select 3 recent document changes. Verify the approver is authorized per the matrix. Ask the approver (or check the record) what background information was available. Check for at least one cross-functional review for a change affecting multiple departments.
Objective Evidence
- Obsolete document retention procedure or schedule defining how long obsolete documents must be retained, with the basis for each retention period
- Retention period analysis showing the three criteria considered: (1) at least the lifetime of the medical device, (2) not less than the retention period of any resulting record per 4.2.5, and (3) as specified by applicable regulatory requirements -- with the longest period applied
- Obsolete document archive (physical or electronic) showing retained obsolete copies with dates, identification, and expected retention end dates
- Evidence that obsolete documents are accessible when needed -- for example, a recent retrieval of an obsolete document for a complaint investigation, field action, or regulatory inquiry
- Process for destroying obsolete documents after the retention period expires -- with authorization and documentation requirements
Common Nonconformities
- Obsolete documents are destroyed immediately upon supersession with no retention -- the organization cannot retrieve the manufacturing procedure used to produce devices currently in the field because it was destroyed when the new revision was issued (Major NC).
- Retention period for obsolete documents does not consider that the devices manufactured under those documents have an expected in-service life exceeding the retention period -- documents could be destroyed while devices are still in active use (Minor NC).
- Obsolete document archive exists but requested documents could not be located for a complaint investigation -- the archive indexing system is inadequate (Minor NC).
- No defined retention period exists for obsolete documents -- some departments retain all historical versions indefinitely while others destroy them immediately, with no organizational policy (Minor NC).
- Related records per 4.2.5 have a longer retention period than obsolete documents -- documents to which devices were manufactured would be destroyed while the related production records are still required to be retained (Minor NC).
Auditor Tips
This requirement often catches organizations off guard because they focus on current document control and forget about obsolete document retention. The retention analysis is similar to record retention under 4.2.5 but applies to documents. The critical question is: if a field corrective action is needed 10 years from now, can you retrieve the exact version of the manufacturing procedure used to produce those devices? If the answer is no because obsolete documents were destroyed, that is a finding. The standard explicitly says retention must be at least the device lifetime AND not less than record retention periods AND must meet regulatory requirements. Always use the longest of these three criteria. Check that the obsolete document archive is organized and retrievable.
Follow-Up Questions
- If a complaint was received about a device manufactured 8 years ago, could you retrieve the exact manufacturing procedure revision that was in effect when that device was produced?
- How does your obsolete document retention period compare to your record retention period under 4.2.5? Is it at least as long?
- Show me the last time an obsolete document was retrieved for an investigation. How long did it take?
What to Sample
Verify the obsolete document retention period analysis against device lifetime and record retention. Request one specific obsolete document version and verify it can be retrieved. Check that the archive is organized and indexed.
Objective Evidence
- Quality manual or QMS overview document -- verify it names specific top management roles and their QMS accountabilities, not just generic org chart references
- Board or executive meeting minutes from the last 12 months -- look for quality/compliance as a standing agenda item, not a one-off mention
- Management commitment statement or signed quality policy -- confirm the signatory is current top management, not a predecessor who left 2 years ago
- Resource allocation records -- check that management approved budget line items specifically for QMS activities (audits, training, CAPA, equipment qualification)
- Organizational chart showing reporting lines -- verify the quality function has a direct line to top management, not buried 3 levels below operations
- Evidence of management participation in quality events -- look for attendance at CAPA reviews, design reviews, or supplier audits beyond just management review meetings
Common Nonconformities
- Top management cannot articulate the quality policy or name the current quality objectives when interviewed -- indicates the QMS operates as a quality department exercise rather than a leadership-driven system (Major NC)
- Quality function reports to operations or manufacturing VP with no independent access to top management -- creates inherent conflict of interest when quality decisions impact production schedules (Major NC)
- Management commitment is limited to signing the quality policy annually with no other documented involvement in QMS activities throughout the year (Minor NC)
- No evidence that top management reviews or approves resource requests for QMS improvements -- quality budget decisions are made at middle management level only (Minor NC)
Auditor Tips
Start the audit here by interviewing the CEO or site general manager. Ask them to describe the QMS in their own words without referencing documents. Their fluency -- or lack thereof -- tells you more about real management commitment than any signed policy statement. If top management defers all questions to the quality manager, that is itself a finding. Cross-reference what management says with what operators on the floor believe about management's priorities.
Follow-Up Questions
- When was the last time you personally intervened in a production decision because of a quality concern?
- How do you ensure quality considerations are factored into strategic business decisions such as new product launches or facility changes?
- Can you give me an example of a resource request from the quality team that you approved in the last 12 months?
What to Sample
Interview at least 2 members of top management and 3 shop-floor personnel. Compare their descriptions of management's involvement in quality to identify perception gaps.
Objective Evidence
- Management review meeting minutes -- verify top management attendance (not just their delegate), look for specific decisions with assigned owners and deadlines, not just 'noted' or 'acknowledged'
- Budget approval records for quality initiatives -- cross-check that approved amounts were actually disbursed, not just approved on paper
- Executive communications referencing quality and compliance -- verify these go beyond boilerplate; look for specific references to company performance data, incidents, or improvement initiatives
- Strategic planning documents -- confirm quality objectives are integrated into the business strategy, not appended as an afterthought
- Training records showing management participated in quality/regulatory training -- check if management completed GMP awareness, MDR transition, or similar regulatory training
- Capital expenditure approvals for quality-related equipment or infrastructure -- verify management signed off on IQ/OQ/PQ-related investments
Common Nonconformities
- Management review records show the quality manager presented all data and top management only signed the minutes without documented discussion, questions, or decisions -- this is passive attendance, not commitment (Minor NC)
- Top management approved a quality policy years ago but has no record of reviewing, questioning, or updating it since, despite significant changes in product portfolio and regulatory landscape (Minor NC)
- Quality objectives exist only at the quality department level with no cascade to operations, R&D, or supply chain -- management has not ensured objectives are established at relevant functions and levels (Major NC)
- Management allocated zero dedicated budget for CAPA implementation or corrective action verification activities -- corrective actions are expected to be absorbed within existing operational budgets (Minor NC)
- No evidence that management conducts or participates in management reviews -- reviews are conducted entirely by quality manager and results are emailed to management for 'review and approval' (Major NC)
Auditor Tips
The five sub-clauses (a through e) are all mandatory demonstrations of commitment. Do not accept a single signed quality policy as evidence for all five. Ask management to walk you through a recent quality problem and describe their personal involvement. Strong organizations will show you real decisions -- stopped shipments, approved unbudgeted CAPA resources, or personally communicated regulatory changes. Weak organizations produce only signatures and attendance lists. Cross-reference 5.1 evidence with 5.6 management review outputs to check consistency.
Follow-Up Questions
- Describe a situation in the last year where you personally had to make a difficult decision between production schedule and quality requirements.
- How do you stay informed about changes in medical device regulations that affect this organization?
- What quality metrics do you monitor personally, and how often?
What to Sample
Review management review records from the last 2 cycles. For each, verify top management attendance, specific decisions made, and follow-up completion rates.
Objective Evidence
- Regulatory requirements matrix or register -- verify it covers all markets where devices are sold (FDA, EU MDR, MDSAP countries), check the last update date, and confirm it includes recent regulatory changes like EUDAMED milestones or FDA QMSR transition
- Customer requirement capture process -- look for a systematic method (VOC program, contract review, design input process) rather than ad-hoc collection of customer emails
- Customer satisfaction measurement results with trend analysis -- check for meaningful metrics (complaint rates per unit shipped, NPS scores, on-time delivery) rather than generic satisfaction surveys with 95%+ satisfaction claims
- Post-market surveillance data analysis -- verify feedback from the field is systematically collected, analyzed for trends, and fed back into design and manufacturing
- Management review inputs showing customer and regulatory data -- confirm management actually reviews this data and makes decisions based on it
- Contract review records for recent orders -- check that customer-specific requirements (labeling, packaging, testing, documentation) are identified before acceptance
Common Nonconformities
- Organization sells devices in 5 EU member states but the regulatory matrix only references the Medical Devices Directive 93/42/EEC with no evidence of EU MDR 2017/745 transition planning or gap analysis (Major NC)
- Customer satisfaction is measured only by absence of complaints -- no proactive satisfaction measurement exists, and management interprets 'no news is good news' as meeting customer requirements (Minor NC)
- Post-market surveillance data is collected but not analyzed for trends or fed back to design or manufacturing -- the data sits in a database with no periodic review or action trigger thresholds (Minor NC)
- Contract review process exists but does not include verification of customer-specific regulatory requirements for different jurisdictions -- same labeling is shipped to all markets regardless of local requirements (Major NC)
- Management review does not include any customer feedback data or regulatory compliance status -- Section 5.6.2 inputs (a) through (c) are missing entirely (Major NC)
Auditor Tips
This clause has teeth because it requires management to ensure requirements are both 'determined AND met' -- not just listed. Ask to see a specific product and trace its regulatory requirements from identification through implementation to verification. The gap between 'we know the requirements' and 'we can prove we meet them' is where most findings live. Pay special attention to organizations that recently entered new markets or launched new device classifications -- the regulatory requirement identification process is stress-tested during those transitions.
Follow-Up Questions
- How quickly after a new FDA guidance document is published does your organization assess its applicability and impact?
- Show me how a customer complaint from the last 6 months was traced back to a requirement gap and resulted in a process change.
- Who is responsible for monitoring regulatory changes in each jurisdiction where you sell devices?
What to Sample
Select 2 products sold in different regulatory jurisdictions. Trace the regulatory requirement identification through to objective evidence of compliance for each.
Frequently Asked Questions
Get the Full 334-Item Checklist
Download the complete ISO 13485:2016 internal audit checklist with all 334 expert items, objective evidence requirements, common nonconformities, auditor tips, and a professional scoring rubric.
This checklist is an educational resource for audit preparation. It does not constitute professional regulatory advice. Always consult qualified auditors for certification decisions.