Skip to main content
HomeChecklists › ISO 13485:2016 Internal Audit Checklist

ISO 13485:2016 Internal Audit Checklist

334 items Last updated: 2026-06-22
0% complete — 0 of 334 items
Status:
Section 4.1 — General Requirements 0/26
4.1.1
Is the QMS formally documented, implemented, and maintained in accordance with ISO 13485? Does the documentation address all applicable requirements of ISO 13485 and relevant regulatory requirements through defined procedures or arrangements?
Quality manual with current approval signatures, showing scope, exclusions, process interactions, and documentation structure -- verify the approval date is within the organization's defined review cycle

Objective Evidence

  • Quality manual with current approval signatures, showing scope, exclusions, process interactions, and documentation structure -- verify the approval date is within the organization's defined review cycle
  • Master document list showing every QMS procedure with document number, title, current revision, effective date, and owner -- cross-check 3 random procedures to confirm the listed revision matches the actual document
  • Regulatory requirements matrix mapping each applicable regulation (FDA QMSR, EU MDR, MDSAP, etc.) to specific QMS procedures that address them -- verify at least 2 entries by opening the referenced procedure
  • QMS effectiveness metrics dashboard or report (e.g., CAPA closure rate, audit findings trend, complaint rate, on-time delivery) -- confirm data is current within the last quarter
  • Most recent internal audit schedule and at least one completed internal audit report covering QMS adequacy -- check that findings were closed with objective evidence
  • Training records for at least 2 employees showing they were trained on QMS procedures relevant to their role -- verify training dates are after the most recent procedure revision

Common Nonconformities

  • Organization has documented procedures but cannot demonstrate implementation -- a procedure requires periodic quality metric reviews but no meeting minutes, dashboards, or review records exist for the required review period (Major NC).
  • Regulatory requirements matrix lists 'FDA 21 CFR 820' but the organization has not updated it to reflect the transition to FDA QMSR incorporating ISO 13485 -- indicates the matrix is not maintained (Minor NC).
  • Quality manual has not been approved within the organization's defined review cycle and references organizational roles and processes that no longer exist -- the manual does not reflect the current QMS (Minor NC).
  • No documented procedure exists for complaint handling despite the organization receiving a significant volume of complaints annually -- a required procedure per 8.2.2 is completely absent (Major NC).
  • Internal audit program covers only production processes; design control, supplier management, and management review have not been audited within the defined audit cycle (Major NC).

Auditor Tips

This clause is the 'is the QMS real?' test. Focus on the gap between documentation and implementation. Ask to see 3 random procedures and then ask the process owner to show you the last time they followed that procedure with dated records. Organizations that bought a template QMS package often have beautiful documents but zero implementation evidence. The word 'maintain' in the standard means ongoing activity -- look for evidence of review, update, and improvement, not just initial creation. FDA 483s frequently cite 'failure to establish and maintain procedures' -- the 'maintain' part is where most organizations fail.

Follow-Up Questions

  • Show me the last procedure you updated -- what triggered the change and how did you verify the update was effective?
  • How do you identify when a new regulatory requirement applies to your organization, and what is the process to incorporate it into your QMS?
  • If I pick a random procedure from your master list, can the process owner show me evidence they followed it in the last 30 days?

What to Sample

Pull 3 procedures from the master list at random. For each, ask the process owner to show you the most recent record proving the procedure was followed. Check that training records exist for personnel performing those activities.

Preview complete — 3 of 27 sections shown
Section 5.1 — Management Commitment 5 items Download to access
Section 5.3 — Quality Policy 6 items Download to access
Section 5.4 — Planning 4 items Download to access
Section 5.5 — Responsibility, Authority and Communication 6 items Download to access
Section 5.6 — Management Review 19 items Download to access
Section 6.1 — Provision of Resources 3 items Download to access
Section 6.2 — Human Resources 7 items Download to access
Section 6.3 — Infrastructure 6 items Download to access
Section 6.4 — Work Environment and Contamination Control 11 items Download to access
Section 7.1 — Planning of Product Realization 7 items Download to access
Section 7.2 — Customer-Related Processes 18 items Download to access
Section 7.3 — Design and Development 32 items Download to access
Section 7.4 — Purchasing 19 items Download to access
Section 7.5 — Production and Service Provision 46 items Download to access
Section 7.6 — Control of Monitoring and Measuring Equipment 11 items Download to access
Section 8.1 — General (Measurement, Analysis, Improvement) 5 items Download to access
Section 8.2 — Monitoring and Measurement 20 items Download to access
Section 8.3 — Control of Nonconforming Product 12 items Download to access
Section 8.4 — Analysis of Data 10 items Download to access
Section 8.5 — Improvement 17 items Download to access

Frequently Asked Questions

What is ISO 13485?
ISO 13485:2016 is the international standard for quality management systems in the medical device industry. It specifies requirements for a QMS where an organization needs to demonstrate its ability to provide medical devices and related services that consistently meet customer and applicable regulatory requirements.
How many clauses does ISO 13485 have?
ISO 13485:2016 has 8 main sections (Clauses 1-8), with Clauses 4 through 8 containing the auditable requirements. Clause 4 covers the QMS, Clause 5 covers management responsibility, Clause 6 covers resource management, Clause 7 covers product realization, and Clause 8 covers measurement, analysis, and improvement.
What is the difference between ISO 13485 and ISO 9001?
ISO 13485 is specific to medical devices and includes requirements for risk management, regulatory compliance, design controls, process validation, and traceability that are not in ISO 9001. ISO 9001 focuses on continual improvement while ISO 13485 emphasizes maintaining the effectiveness of the QMS. ISO 13485 also requires documented procedures in more areas than ISO 9001.
How often should ISO 13485 internal audits be conducted?
ISO 13485 requires internal audits at planned intervals, typically annually. The audit program should consider the status and importance of processes and areas, as well as results of previous audits. High-risk areas or areas with previous findings may need more frequent auditing. Most organizations audit all clauses at least once per year.

Get the Full 334-Item Checklist

Download the complete ISO 13485:2016 internal audit checklist with all 334 expert items, objective evidence requirements, common nonconformities, auditor tips, and a professional scoring rubric.

Free download. No credit card required.

This checklist is an educational resource for audit preparation. It does not constitute professional regulatory advice. Always consult qualified auditors for certification decisions.