MDSAP Audit Checklist
Objective Evidence
- Quality manual or equivalent documentation showing QMS scope, applicable regulatory jurisdictions, product scope, and site coverage -- verify alignment with actual marketing authorizations held
- QMS process map or interaction diagram showing how management, realization, support, and measurement processes interconnect -- confirm process owners are current employees
- Master document list filtered to management system procedures -- verify at least 3 randomly selected procedures have current revision dates within the organization's defined review cycle
- QMS change management records from the past 12 months -- verify that changes were risk-assessed and validated before implementation
- Regulatory requirements matrix mapping each MDSAP jurisdiction's requirements to specific QMS procedures -- cross-check at least 2 entries against the referenced procedures
Common Nonconformities
- Quality manual scope does not include all jurisdictions for which the organization holds marketing authorizations -- devices are sold in Brazil but QMS scope only references FDA and Health Canada (Grade 3 -- direct QMS impact).
- No documented QMS change management process exists -- recent organizational changes (new production line, site move) were implemented without assessing impact on the QMS (Grade 3).
- Process interaction diagram is a generic template that does not reflect the organization's actual process flow -- names and departments on the diagram do not match the current organizational chart (Grade 1).
- Quality manual has not been reviewed or updated within the organization's defined review cycle and references obsolete regulatory requirements (Grade 1).
Auditor Tips
This is your calibration question. Use it to gauge whether the QMS is a living system or shelf documentation. Ask the quality manager to walk through the process map without referring to notes -- hesitation or misalignment with reality signals a paper QMS. Verify that the scope explicitly names every jurisdiction where the organization holds marketing authorizations, not just the 'primary' markets. Check that exclusions (e.g., design control exclusion) are justified and not used to avoid applicable requirements. Per MDSAP companion document QMS P0015, verify that the quality manual addresses multi-jurisdiction applicability.
Follow-Up Questions
- When was the last structural change to your QMS, and what triggered it?
- How do you ensure your QMS addresses the regulatory requirements of all five MDSAP jurisdictions, not just the ones you audit against most frequently?
- If a new jurisdiction-specific requirement was published tomorrow, what is your process for incorporating it?
What to Sample
Request the quality manual, process map, and regulatory requirements matrix. Cross-reference the scope against actual marketing authorizations. Pull 3 random procedures from the master list and verify they are current.
Objective Evidence
- Documented appointment letter or organizational chart showing the management representative with reporting line to top management
- Job description or role definition specifying QMS responsibilities, authority to stop production for quality reasons, and access to top management
- Meeting minutes or communication records showing the management representative reporting QMS status to top management within the past 12 months
- Evidence that the management representative has authority over resources needed to maintain the QMS
Common Nonconformities
- Management representative role is assigned to a mid-level quality engineer who reports through two layers of management before reaching top management -- no direct access for escalation of quality issues (Grade 1).
- No formal appointment exists -- the quality manager performs the role by default but has no documented authority to halt production or escalate systemic issues (Grade 1).
- Management representative changed 6 months ago but the quality manual and regulatory submissions still reference the previous appointee (Grade 1).
Auditor Tips
Verify this is not a checkbox exercise. The management representative must have real authority, not just a title. Ask for a specific example of when they escalated a quality concern to top management and what happened. In organizations where the management representative is also the quality manager, verify they have sufficient independence to raise concerns about cost-driven decisions that compromise quality. Per FDA requirements, verify this role has authority over quality system activities.
Follow-Up Questions
- Can you describe a recent situation where you escalated a quality concern to top management? What was the outcome?
- If you needed to stop a production line due to a quality issue, do you have the authority to do that without additional approval?
What to Sample
Review the appointment letter or job description. Check the last 2 management review meeting attendee lists to confirm the management representative was present and actively participated.
Objective Evidence
- Documented quality policy signed by top management with a date within the organization's defined review cycle
- Evidence of communication to all levels -- posted in work areas, included in onboarding, referenced in training materials
- Interview 2--3 employees at different levels (floor operator, supervisor, engineer) to verify they can describe the quality policy in their own words
- Records showing the quality policy was reviewed during management review -- confirm review date and any resulting changes
Common Nonconformities
- Quality policy is posted in the conference room but floor operators cannot articulate what it means or how it applies to their work -- communication is one-directional with no evidence of understanding (Grade 1).
- Policy does not reference regulatory compliance -- it focuses on customer satisfaction and continuous improvement but omits the organization's commitment to meeting applicable regulatory requirements (Grade 1).
- Quality policy was last reviewed more than 5 years ago and references an organizational mission statement that has since changed (Grade 1).
Auditor Tips
The quality policy test is simple: can a floor operator explain it in their own words? If they can only recite it from a poster, it is not understood. Look for evidence that the policy drives actual behavior -- for example, does the CAPA procedure reference the quality policy commitment to continuous improvement? Health Canada and ANVISA place particular emphasis on regulatory compliance commitment in the policy statement.
Follow-Up Questions
- How do you verify that personnel understand the quality policy -- not just that they have been told about it?
- When was the quality policy last changed, and what drove the change?
What to Sample
Read the quality policy. Interview 2 employees at different levels. Check that the most recent management review agenda included quality policy review.
Objective Evidence
- Risk management procedure referencing ISO 14971 and addressing all lifecycle phases -- verify it covers risk analysis, risk evaluation, risk control, and residual risk evaluation
- Risk management plan for at least one device showing scope, responsibilities, risk acceptability criteria, and planned verification activities
- Risk management file for the same device showing risk analysis records, risk control measures, and residual risk assessment -- verify it is current and includes post-market data
- Evidence that production and post-production information is fed back into the risk management process -- link to complaint data, CAPA records, or post-market surveillance reports
Common Nonconformities
- Risk management file was completed at design transfer and has not been updated with post-market data -- no evidence that complaint trends, CAPA outcomes, or field performance data have been evaluated for risk impact (Grade 3 -- direct QMS impact).
- Risk acceptability criteria are not defined or are defined so broadly that no risk is ever deemed unacceptable -- the risk management process cannot demonstrate it would reject a design with unacceptable risk (Grade 3).
- Risk management process addresses only product risks and does not cover process risks (e.g., sterilization failure, packaging breach) as required by the MDSAP audit model (Grade 2).
- No linkage between risk management and design inputs -- design input requirements do not reference the risk analysis, and risk controls are not traced to design outputs (Grade 3).
Auditor Tips
Risk management is a thread that runs through every MDSAP chapter. Use this task to establish the baseline and then verify linkages in Chapters 3--7. The most common failure is a static risk management file that was created during design and never updated. Ask for the last update date and what triggered it. MDSAP companion document QMS P0015 specifically requires verification of lifecycle risk management, not just design-phase risk analysis. All five jurisdictions require ISO 14971 application -- verify the organization references the current edition.
Follow-Up Questions
- When was the risk management file for your highest-risk device last updated, and what triggered the update?
- How does post-market information -- complaints, CAPAs, literature reviews -- feed back into your risk management files?
- What criteria do you use to determine if a risk is acceptable, and can you show me an example where a risk was initially deemed unacceptable?
What to Sample
Select the highest-risk device. Review the risk management plan and file. Verify the file includes post-market data updates within the past 12 months. Check linkage to at least one CAPA record.
Objective Evidence
- List of outsourced processes with risk classification and rationale for outsourcing -- verify it includes all outsourced activities (sterilization, testing, calibration, design, manufacturing)
- Quality agreements or technical agreements for each critical outsourced process -- verify they define responsibilities, quality requirements, acceptance criteria, and right of audit
- Supplier audit or evaluation records for outsourced process providers -- verify frequency is risk-based and evaluations are current
- Monitoring data for outsourced processes -- incoming inspection results, performance metrics, or periodic review records
Common Nonconformities
- Sterilization is outsourced but no quality agreement exists with the contract sterilizer -- the organization relies on the sterilizer's ISO certificate without defining specific requirements or monitoring performance (Grade 3).
- Outsourced processes are not included in the organization's process map or QMS scope -- they are managed as simple 'purchases' without the controls required for outsourced QMS processes (Grade 2).
- Quality agreements exist but have not been reviewed since initial execution -- the outsourced provider has changed processes, moved facilities, or been acquired without triggering a review of the agreement (Grade 1).
Auditor Tips
Outsourced process control is a frequent finding area because organizations often treat outsourced processes as simple purchases. The key distinction is control and responsibility: if the process is part of the organization's QMS but performed externally, it requires more than purchase order controls. Verify quality agreements are specific (not generic templates) and include right-of-audit clauses. Health Canada and FDA place particular emphasis on outsourced sterilization and testing. Cross-reference with Chapter 6 (Purchasing) to avoid duplicate findings.
Follow-Up Questions
- How do you distinguish between an outsourced process and a purchased product or service?
- When was the last time you audited your contract sterilizer or other critical outsourced process provider?
- If your outsourced process provider changed a key process parameter, how would you know?
What to Sample
Review the outsourced process list. Select the most critical outsourced process and verify the quality agreement, most recent audit or evaluation, and monitoring data.
Objective Evidence
- Procedure or process description for regulatory authority communication covering all applicable jurisdictions
- Log or tracking system for regulatory correspondence -- submissions, notifications, queries, and responses
- Records of regulatory notifications submitted in the past 12 months (e.g., change notifications, annual reports, periodic safety reports)
- Evidence that regulatory authority communications are reviewed for QMS impact and routed to appropriate personnel
Common Nonconformities
- Organization has no centralized tracking of regulatory authority correspondence -- communications are managed by individual regulatory affairs staff with no oversight or handoff process (Grade 1).
- Regulatory notifications required by Health Canada (Significant Change notifications) or ANVISA (post-registration changes) were not submitted or were submitted late (Grade 3 -- jurisdiction-specific requirement violation).
- No process exists to monitor regulatory authority communications for changes that may affect the QMS -- the organization is unaware of a published guidance document that impacts its device classification (Grade 2).
Auditor Tips
Each jurisdiction has different notification requirements. FDA requires Annual Reports (PMA) and 510(k) for changes. Health Canada requires Significant Change applications. ANVISA requires post-registration change notifications. PMDA requires partial change approvals. TGA requires change notifications for ARTG entries. Verify the organization tracks obligations per jurisdiction, not just its primary market. This task links to Chapter 2 (Marketing Authorization) -- verify consistency.
Follow-Up Questions
- How do you track regulatory notification obligations across all five MDSAP jurisdictions?
- Can you show me the last regulatory notification you submitted? Which jurisdictions required it, and was it submitted within the required timeframe?
What to Sample
Review the regulatory correspondence log. Select one recent device change and verify that all required regulatory notifications were submitted to applicable jurisdictions within required timeframes.
Objective Evidence
- Management review procedure defining required inputs, frequency, and participants -- verify it lists all inputs required by ISO 13485:2016 clause 5.6.2
- Most recent management review minutes or report showing each required input was addressed with data -- not just agenda items, but actual metrics, trends, and analysis
- Evidence that complaint trends, CAPA effectiveness data, audit findings, and post-market surveillance data were presented with quantitative analysis
- Records showing management review covered jurisdiction-specific regulatory performance -- adverse event reporting timeliness, regulatory submissions status, and authority communications
Common Nonconformities
- Management review minutes show topics were discussed but no quantitative data was presented -- 'CAPA status was reviewed' with no trend data, closure rates, or effectiveness metrics (Grade 2).
- Required inputs were omitted -- no review of post-market surveillance data, no review of regulatory changes, or no review of risk management updates (Grade 2).
- Management review does not address multi-jurisdiction regulatory performance -- adverse event reporting compliance, regulatory submission status, and authority communications are not covered per MDSAP requirements (Grade 2).
- Management review frequency does not meet the defined schedule -- the most recent review was 18 months ago despite a documented annual requirement (Grade 1).
Auditor Tips
Management review is the most commonly cited finding area in MDSAP audits because it is the integration point for data from all other chapters. Verify actual data was presented, not just agenda items. MDSAP specifically requires that management review address multi-jurisdiction regulatory performance -- this goes beyond the ISO 13485 minimum. Ask to see the slide deck or data package, not just the minutes. Cross-reference complaint data shown in management review against actual complaint records from Chapter 3.
Follow-Up Questions
- Can you show me the data package that was presented at the last management review -- not just the minutes, but the actual charts and metrics?
- How do you ensure management review covers regulatory performance for all five MDSAP jurisdictions?
- What specific actions resulted from the last management review, and can you show me evidence they were completed?
What to Sample
Review the last 2 management review records. Verify all required inputs per ISO 13485 clause 5.6.2 were addressed with data. Verify management review outputs include action items with assigned owners and completion dates.
Objective Evidence
- Management review output records showing specific decisions, action items, responsible parties, and target dates
- Action item tracking log or system showing status of management review actions -- verify closure evidence for completed items
- Evidence that management review outputs addressed resource allocation decisions (personnel, equipment, infrastructure)
- Evidence that at least one improvement action from management review was implemented and its effectiveness verified
Common Nonconformities
- Management review minutes conclude with vague action items ('improve CAPA process') with no specific owner, target date, or measurable success criteria (Grade 1).
- Action items from previous management reviews are carried forward indefinitely without escalation or re-prioritization -- the same items appear on 3 consecutive reviews without progress (Grade 2).
- No evidence that management review outputs led to actual resource allocation decisions -- the organization identifies resource needs but management does not approve or fund them (Grade 2).
Auditor Tips
The value of management review is in the outputs, not the meeting. Look for specific, measurable actions with assigned owners. If the same action items recur across multiple reviews without resolution, this indicates the management review process is ineffective as a driver of improvement. Verify at least one action was closed with evidence of effectiveness -- not just completion. MDSAP expects management review to drive multi-jurisdiction regulatory improvements, not just QMS process changes.
Follow-Up Questions
- Show me an action item from the last management review that has been completed. What evidence do you have that it was effective?
- Are there any management review action items that have been open for more than 6 months? Why?
What to Sample
Review action items from the last 2 management reviews. Track at least 3 items to closure with effectiveness evidence. Check for overdue or recurring items.
Objective Evidence
- Resource planning records or budget allocations for quality system resources -- personnel, equipment, facilities, and training
- Infrastructure qualification records for critical production and testing equipment -- IQ/OQ/PQ or equivalent
- Preventive maintenance schedules and records for critical infrastructure -- verify maintenance is current
- Work environment monitoring records where environmental conditions affect product quality -- temperature, humidity, particulate counts, ESD controls
Common Nonconformities
- Cleanroom environmental monitoring records show out-of-specification particulate counts on multiple occasions with no investigation or corrective action taken (Grade 3).
- No preventive maintenance program exists for production equipment -- maintenance is performed only when equipment fails (Grade 2).
- Organization has added a second production shift but has not assessed whether infrastructure (equipment capacity, environmental controls, utilities) is adequate for increased throughput (Grade 1).
Auditor Tips
Infrastructure and work environment are often treated as facilities management issues rather than QMS requirements. Verify that environmental monitoring where required (cleanrooms, ESD areas, temperature-controlled storage) produces documented records that are reviewed for trends. If the organization performs sterilization or uses controlled environments, cross-reference with Chapter 5. FDA 21 CFR 820.70 and ANVISA RDC 16/2013 have specific environmental control requirements.
Follow-Up Questions
- How do you determine what infrastructure and environmental controls are needed for your products?
- Can you show me environmental monitoring data for your most critical production area over the past 6 months?
What to Sample
Review infrastructure maintenance records for 3 critical production or testing assets. Check environmental monitoring data for one controlled area. Verify out-of-specification events were investigated.
Objective Evidence
- Document control procedure addressing approval, review, distribution, revision control, and obsolete document management -- verify it references jurisdiction-specific retention requirements
- Master document list or electronic document management system showing current revisions, effective dates, and approval status for all QMS documents
- Record retention schedule that addresses the retention requirements of all five MDSAP jurisdictions -- verify it identifies the longest applicable retention period for each record type
- Evidence of controlled document distribution -- verify that at least 3 work areas have current revision documents available (not obsolete versions)
Common Nonconformities
- Record retention schedule only addresses FDA requirements (2 years or device lifetime) and does not account for longer retention periods required by other jurisdictions -- Health Canada requires retention for the life of the device plus one year, ANVISA requires specific periods per record type (Grade 2).
- Obsolete documents are still accessible in production areas without clear identification as superseded -- operators could inadvertently follow an outdated procedure (Grade 3).
- Electronic document management system does not enforce approval workflows -- documents can be posted without formal review and approval (Grade 2).
Auditor Tips
Document and record control is foundational and often audited early. For MDSAP, the key differentiator is multi-jurisdiction retention requirements. Each jurisdiction has different retention periods, and the organization must apply the most stringent. FDA requires device lifetime plus 2 years for certain records. Health Canada requires device lifetime plus 1 year. ANVISA and PMDA have their own schedules. Verify the organization has identified the longest period and applies it consistently. Cross-reference with Chapter 2 for technical documentation retention.
Follow-Up Questions
- How do you determine the record retention period when multiple jurisdictions have different requirements?
- Can you show me how you prevent use of obsolete documents in production areas?
What to Sample
Check the record retention schedule against jurisdiction-specific requirements. Verify 3 random documents on the production floor are current revision. Confirm at least one obsolete document was properly retired.
Objective Evidence
- List of all devices marketed by jurisdiction, showing the marketing authorization type, number, and status (active, pending, expired) for each device-jurisdiction combination
- Regulatory submission procedure covering submission types, review workflows, and tracking mechanisms for each jurisdiction
- Sample marketing authorizations -- at least one per jurisdiction -- verified as current and matching the device currently being manufactured
- Tracking system for regulatory submission status, approval conditions, and renewal dates
Common Nonconformities
- Devices are being marketed in a jurisdiction without a valid marketing authorization -- the organization assumed mutual recognition where none exists (Grade 4 -- direct impact, regulatory violation).
- Marketing authorization references an older device specification that no longer matches the current manufactured device -- design changes were implemented without updating the submission (Grade 3).
- No systematic tracking of marketing authorization renewal dates -- an authorization expired without the organization being aware (Grade 3).
Auditor Tips
This is where you verify the legal right to market. Cross-reference the device list against actual marketing authorizations for each jurisdiction. Common gaps: devices sold through distributors in jurisdictions where the manufacturer has not obtained or maintained authorization, or devices that have undergone design changes without corresponding regulatory updates. Each jurisdiction has different change notification thresholds -- verify the organization knows them. FDA requires new 510(k) for certain changes. Health Canada requires Significant Change applications. ANVISA and TGA have post-market change notification processes.
Follow-Up Questions
- Can you show me a complete list of every device you sell, by jurisdiction, with the corresponding marketing authorization number?
- How do you determine whether a design change requires a new regulatory submission versus a change notification?
What to Sample
Select 3 devices. For each, verify the marketing authorization is current in every jurisdiction where the device is sold. Cross-reference the authorized device description against the current design output specifications.
Objective Evidence
- Establishment registration records for each applicable jurisdiction -- FDA establishment registration, Health Canada establishment licence, ANVISA company registration, PMDA marketing authorization holder registration, TGA sponsor registration
- Device listing records showing all marketed devices are listed with the correct classification, product codes, and proprietor information per jurisdiction
- Evidence of annual registration renewals where required -- FDA annual registration, Health Canada annual licence fee
- Records showing device listing updates when devices are added, modified, or discontinued
Common Nonconformities
- FDA establishment registration has lapsed because the annual renewal was missed -- the organization is technically operating without current registration (Grade 4).
- Device listing does not include all devices currently marketed -- recently launched devices were not added to the listing within the required timeframe (Grade 3).
- Device classification in the listing does not match the actual classification determination -- product codes or device class designations are incorrect (Grade 2).
Auditor Tips
Establishment registration and device listing are separate from marketing authorization but equally critical. FDA requires annual establishment registration and device listing updates. Health Canada requires an establishment licence that must be renewed annually. ANVISA requires company registration (Cadastro). Verify each is current. A common gap is that the organization registered years ago but has not updated its listing when new devices were added or existing devices were modified. Cross-reference the device listing against the marketing authorization list from Task 2.1.
Follow-Up Questions
- When was your most recent establishment registration renewal for each jurisdiction?
- How do you ensure device listings are updated when you launch a new device or discontinue an existing one?
What to Sample
Verify establishment registrations are current for each jurisdiction. Cross-reference device listings against the actual product catalog. Check that at least one recently launched device was added to listings within the required timeframe.
Objective Evidence
- Labeling control procedure covering label design, approval, storage, issuance, and reconciliation
- Labeling review records showing verification against jurisdiction-specific requirements -- FDA 21 CFR 801, Health Canada CMDR labeling requirements, ANVISA labeling rules, PMDA labeling standards, TGA labeling requirements
- Sample labels for at least one device -- verify they include all required elements per applicable jurisdiction (device name, manufacturer, UDI/GTIN, lot/serial, expiry, IFU reference, regulatory symbols)
- Translation management records for multi-language labeling -- verification that translations are accurate and cover all required jurisdictions
Common Nonconformities
- Labels do not include Unique Device Identification (UDI) information as required by the applicable jurisdiction's UDI implementation timeline (Grade 3).
- Instructions for Use are only available in English and the primary market language but not in languages required by other jurisdictions where the device is sold (Grade 2).
- Labeling review checklist does not address jurisdiction-specific requirements -- it only covers ISO 15223 symbols without verifying country-specific text and content requirements (Grade 2).
Auditor Tips
Labeling is a high-variation area across jurisdictions. FDA has extensive labeling requirements under 21 CFR 801 and UDI requirements. Health Canada requires bilingual (English/French) labeling. ANVISA requires Portuguese labeling. PMDA requires Japanese labeling with specific content requirements. TGA has its own labeling requirements. Verify the organization has a labeling matrix that identifies requirements per jurisdiction. Pay special attention to UDI compliance timelines, which vary by device class and jurisdiction.
Follow-Up Questions
- How do you ensure labeling compliance when a device is sold in multiple jurisdictions with different language and content requirements?
- What is your current UDI compliance status for each applicable jurisdiction?
What to Sample
Select one device sold in at least 3 jurisdictions. Verify the label includes all required elements per each jurisdiction. Check that IFU translations exist for required languages. Verify UDI status.
Objective Evidence
- Technical documentation or design dossier for at least one device -- verify it contains the elements required by each applicable jurisdiction's submission format
- Change management records showing technical documentation updates aligned with design changes
- Traceability matrix linking design outputs to technical documentation sections -- verify consistency
- Evidence that technical documentation supports currently marketed device versions, not obsolete configurations
Common Nonconformities
- Technical documentation has not been updated to reflect design changes made after initial marketing authorization -- the dossier describes a configuration that no longer matches the manufactured device (Grade 3).
- No traceability between design history file and technical documentation -- engineers cannot demonstrate which technical documentation sections are affected by a given design change (Grade 2).
- Technical documentation exists only for the primary jurisdiction submission format (e.g., FDA 510(k)) with no equivalent documentation structured for other jurisdictions' requirements (Grade 1).
Auditor Tips
Technical documentation is the regulatory record of the device. Each jurisdiction has different expectations for format and content -- FDA Summary (510(k)), EU Technical Documentation (MDR Annex II/III), Health Canada STED format. Verify the organization can produce jurisdiction-specific documentation on request. The most common gap is documentation that was created for initial submission and never updated as the device evolved. Cross-reference with Chapter 4 (Design Changes) to verify consistency.
Follow-Up Questions
- If a regulatory authority requested your current technical documentation for a specific device, how quickly could you produce it?
- How do you ensure technical documentation stays synchronized with design changes?
What to Sample
Select one device with a recent design change. Verify the technical documentation reflects the current design. Cross-reference at least 2 design outputs against the technical documentation content.
Objective Evidence
- Regulatory requirements matrix mapping each jurisdiction's specific requirements to QMS procedures -- verify completeness for all five MDSAP jurisdictions
- Regulatory intelligence process -- documented method for monitoring regulatory changes, guidance updates, and enforcement actions in each jurisdiction
- Records showing regulatory change assessments performed in the past 12 months -- at least one change per jurisdiction identified, assessed, and actioned or dismissed with rationale
- Training records showing regulatory affairs personnel are trained on jurisdiction-specific requirements
Common Nonconformities
- Regulatory requirements matrix only covers FDA and Health Canada -- no systematic identification of ANVISA, PMDA, or TGA-specific requirements despite marketing devices in those jurisdictions (Grade 2).
- No formal regulatory intelligence process exists -- the organization relies on trade publications and informal networks rather than systematic monitoring of regulatory authority publications (Grade 1).
- Regulatory change was published 6 months ago but the organization has not assessed its impact -- no evidence that new guidance or regulation was reviewed for QMS impact (Grade 2).
Auditor Tips
This task verifies that the organization proactively manages regulatory compliance rather than reacting to audit findings. Each MDSAP jurisdiction publishes regulatory changes at different frequencies and through different channels. Verify the organization monitors FDA Federal Register, Health Canada Gazette, ANVISA Diario Oficial, PMDA notifications, and TGA regulatory updates. A mature organization will have a regulatory change management procedure that routes changes to affected process owners with defined timelines for assessment.
Follow-Up Questions
- How do you monitor regulatory changes across all five MDSAP jurisdictions?
- Can you show me the last regulatory change you assessed and what action resulted?
What to Sample
Review the regulatory requirements matrix for completeness. Verify the regulatory intelligence process has produced at least 2 change assessments in the past 12 months. Spot-check one jurisdiction-specific requirement against the organization's actual implementation.
Objective Evidence
- List of appointed representatives per jurisdiction -- authorized representative (EU/Health Canada), local agent (ANVISA), marketing authorization holder (PMDA), sponsor (TGA)
- Written agreements with each representative defining responsibilities, authority, and communication protocols -- verify agreements are current and signed
- Evidence of communication between the organization and its representatives in the past 12 months
- Verification that representative contact information provided to regulatory authorities is accurate and current
Common Nonconformities
- Authorized representative agreement has expired or the representative has changed without notifying the regulatory authority (Grade 3).
- No formal agreement exists with the local agent in Brazil -- the organization uses a distributor as its ANVISA representative without a written agreement defining regulatory responsibilities (Grade 2).
- Representative contact information on file with the regulatory authority does not match the current representative -- the previous representative's details are still registered (Grade 2).
Auditor Tips
Each jurisdiction has specific requirements for local representation. Health Canada requires a Canadian representative for foreign manufacturers. ANVISA requires a legal representative in Brazil. PMDA requires a marketing authorization holder in Japan. TGA requires an Australian sponsor. Verify that agreements are not just commercial distribution agreements but specifically address regulatory responsibilities. A common gap is that the organization changed its representative but did not update the registration with the regulatory authority.
Follow-Up Questions
- How do you verify that your authorized representatives are fulfilling their regulatory obligations?
- When was the last time you reviewed and updated your representative agreements?
What to Sample
Review representative agreements for at least 2 jurisdictions. Verify the representative information registered with the regulatory authority matches the current agreement. Check for recent communication records.
Objective Evidence
- List of voluntary or consensus standards applied to devices (e.g., IEC 60601 for electrical safety, ISO 10993 for biocompatibility, IEC 62304 for software)
- Evidence that referenced standards are current editions -- verify the organization is aware of and planning for standard transitions
- Verification that standard requirements are incorporated into design inputs and testing protocols
Common Nonconformities
- Organization references an obsolete edition of a consensus standard in its marketing authorization submission and has not assessed the impact of transitioning to the current edition (Grade 1).
- Voluntary standards are referenced in design documentation but the organization cannot demonstrate compliance testing against the referenced edition (Grade 1).
Auditor Tips
This is a lower-risk task but can reveal gaps in the organization's awareness of evolving standards. If the organization references consensus standards in its marketing authorization submissions, verify those standards are current. Standard transitions (e.g., IEC 60601-1 Edition 3.2, ISO 10993 revisions) often trigger design changes that require regulatory notification.
Follow-Up Questions
- Which consensus standards do you reference in your marketing authorization submissions, and are they current editions?
What to Sample
Review the standards reference list. Verify at least 2 referenced standards are current editions. Check one standard transition for QMS impact assessment.
Objective Evidence
- Complaint handling procedure covering intake, evaluation, investigation, trending, and closure -- verify it includes reportability assessment criteria for all five MDSAP jurisdictions
- Complaint log or database showing all complaints received in the past 12 months -- verify completeness by cross-referencing against customer communication records and returned product logs
- Sample of 5 complaint records -- verify each was evaluated for investigation need, reportability was assessed per jurisdiction, investigation (where required) was completed, and the record was closed with documented rationale
- Complaint trending reports showing analysis by product, complaint type, severity, and time -- verify trends are reviewed and actioned
Common Nonconformities
- Complaint procedure does not include jurisdiction-specific reportability criteria -- the organization uses a single set of reporting criteria that does not address differences between FDA MDR, Health Canada Mandatory Problem Reporting, ANVISA Tecnovigilancia, PMDA adverse event reporting, and TGA reporting (Grade 3).
- Complaints received through non-standard channels (social media, distributor verbal reports, sales team feedback) are not captured in the complaint system (Grade 3).
- Complaint investigations do not address root cause -- records show the complaint was evaluated but the investigation consists only of reviewing the complaint description without product examination, process review, or causal analysis (Grade 2).
- Complaint trending is performed but trends are not linked to the CAPA system -- recurring complaint types are identified but no corrective action is initiated (Grade 3).
Auditor Tips
Complaint handling is the single most commonly cited chapter in MDSAP audits and is a top-5 FDA 483 observation. Start by verifying the procedure includes multi-jurisdiction reportability criteria. Then sample at least 5 complaints -- include at least one that was reported to a regulatory authority and at least one that was evaluated and determined not reportable. Verify the rationale for non-reportability is documented and defensible. Cross-reference with Chapter 7 (Adverse Events) to verify all reportable events identified in complaints were actually reported. FDA 21 CFR 803 and 820.198 set the baseline; Health Canada CMDR s.57--58, ANVISA RDC 67/2009, PMDA adverse event reporting, and TGA adverse event reporting add jurisdiction-specific layers.
Follow-Up Questions
- How do you ensure complaints from all sources -- including distributors, social media, and sales teams -- are captured in your complaint system?
- Can you walk me through the reportability assessment for a specific complaint and show me how you determined it was or was not reportable?
- How do complaint trends feed into your CAPA system?
What to Sample
Pull 5 complaint records: 2 investigated, 1 reported to a regulatory authority, 1 determined not reportable, 1 closed without investigation (verify rationale). Verify trending data is current and linked to CAPA.
Objective Evidence
- CAPA procedure defining triggers, investigation methodology, root cause analysis tools, corrective action planning, implementation tracking, and effectiveness verification criteria
- Sample of 3 CAPA records -- at least one triggered by a complaint, one by an audit finding, and one by a process trend -- verify each includes root cause analysis, corrective action plan, implementation evidence, and effectiveness verification
- CAPA metrics showing timeliness of closure, effectiveness rates, and trending of CAPA sources -- verify metrics are reported in management review
- Evidence that preventive actions are also initiated -- not just corrective actions in response to problems
Common Nonconformities
- Root cause analysis consists of a single 'why' statement without systematic methodology -- no evidence of 5-Why analysis, fishbone diagram, fault tree, or other structured root cause tool (Grade 2).
- CAPA effectiveness verification is performed immediately after corrective action implementation without allowing sufficient time for the action to demonstrate sustained effectiveness -- verification is a 'check-the-box' exercise (Grade 3).
- CAPA system is exclusively corrective -- no evidence of preventive actions based on trend analysis, risk assessment, or proactive identification of potential problems (Grade 2).
- CAPA records show the same root cause identified repeatedly across multiple CAPAs without recognizing the systemic nature of the problem -- each instance is treated as an isolated event (Grade 3).
Auditor Tips
CAPA is the engine of continuous improvement and is scrutinized heavily by all five MDSAP jurisdictions. The most common failures are shallow root cause analysis and ineffective verification. When reviewing CAPA records, look for evidence that the root cause is a systemic cause (not a symptom), that the corrective action addresses that systemic cause, and that effectiveness was verified with objective evidence after sufficient time elapsed. FDA expects CAPA to be one of the most robust processes in the QMS. Ask for CAPAs that failed effectiveness verification -- a mature system will have examples.
Follow-Up Questions
- Can you show me a CAPA where the first corrective action did not work and you had to revise your approach? What did you learn?
- How long do you wait between implementing a corrective action and verifying its effectiveness?
- How do you distinguish between a corrective action and a preventive action in your system?
What to Sample
Review 3 CAPA records end-to-end. Verify root cause analysis methodology, corrective action appropriateness, implementation evidence, and effectiveness verification. Check at least one preventive action record. Verify CAPA metrics are reported in management review.
Objective Evidence
- Internal audit procedure defining audit planning, auditor qualification and independence, audit conduct, reporting, and follow-up requirements
- Internal audit schedule or program showing all QMS processes are covered within the defined cycle -- verify risk-based frequency and that no processes are excluded
- Completed internal audit reports from the past 12 months -- verify audits were conducted by qualified, independent auditors and findings were clearly documented
- Internal audit finding follow-up records -- verify findings were addressed with corrective actions and effectiveness was verified
Common Nonconformities
- Internal audit program does not cover all QMS processes -- design controls, risk management, or regulatory affairs have not been audited within the defined audit cycle (Grade 2).
- Internal auditors audit their own areas of responsibility -- no evidence of independence between auditor and audited activity (Grade 2).
- Internal audit findings are documented but no corrective action follow-up is performed -- findings are recorded and then forgotten (Grade 2).
- Internal audit program does not address MDSAP jurisdiction-specific requirements -- audits cover ISO 13485 clauses but not FDA, Health Canada, ANVISA, PMDA, or TGA regulatory requirements (Grade 1).
Auditor Tips
Internal audits are the organization's self-assessment mechanism. If the internal audit program is weak, problems will go undetected. Verify the audit program is risk-based (higher-risk processes audited more frequently), covers all QMS processes, and that auditors are qualified and independent. A common gap is that internal audits focus on documentation compliance without assessing process effectiveness. Ask to see an internal audit report where the auditor identified a process effectiveness issue, not just a documentation gap. Cross-reference internal audit findings against your own audit findings -- significant gaps indicate the internal audit program is not effective.
Follow-Up Questions
- How do you determine the frequency and scope of internal audits?
- Can you show me an internal audit finding where the auditor identified a systemic process issue rather than a documentation gap?
- How do you qualify internal auditors and maintain their competency?
What to Sample
Review the audit schedule for completeness. Read 2 internal audit reports. Verify at least 3 findings were followed up with corrective actions. Check auditor qualification records for at least 2 auditors.
Objective Evidence
- List of monitored processes with defined metrics, targets, and monitoring frequency -- verify critical processes (production, sterilization, complaint handling, CAPA) have measurable objectives
- Process monitoring data for at least 2 critical processes -- verify data is current, targets are defined, and out-of-specification results trigger investigation
- Product monitoring records (inspection, testing) showing product conforms to acceptance criteria -- verify records include the identity of the inspector and the acceptance criteria used
- Trend analysis reports showing process and product monitoring data analyzed over time -- verify adverse trends trigger investigation or CAPA
Common Nonconformities
- Process monitoring metrics are defined but not analyzed for trends -- data is collected but never reviewed in aggregate to identify deteriorating performance (Grade 2).
- Product acceptance records do not identify the acceptance criteria used -- inspectors record 'pass' or 'fail' without documenting against which specification or drawing revision the product was inspected (Grade 2).
- Out-of-specification results are addressed individually but not trended -- recurring out-of-specification events for the same parameter are not identified as a pattern requiring CAPA (Grade 3).
Auditor Tips
Monitoring and measurement is where you verify the organization knows its processes are performing as intended. Look for defined metrics with targets, not just data collection. The most common gap is that data is collected but never analyzed for trends. Ask to see a trend chart for a critical process parameter and verify the organization has defined action limits (not just specification limits). Cross-reference monitoring results with CAPA records -- adverse trends should trigger CAPA.
Follow-Up Questions
- Can you show me a trend chart for a key process parameter? What are your action limits versus specification limits?
- When was the last time monitoring data triggered a CAPA or process investigation?
What to Sample
Review process monitoring data for 2 critical processes. Verify trend analysis is performed. Check one product inspection record for completeness (acceptance criteria, inspector identity, instrument used).
Objective Evidence
- Nonconforming product control procedure covering identification, segregation, disposition, and documentation requirements for all product stages
- Nonconforming product records from the past 12 months -- sample at least 3, including at least one concession/use-as-is disposition
- For concession dispositions, verify approval authority is appropriate (not the same person who discovered the nonconformity) and rationale addresses impact on safety, performance, and regulatory compliance
- Records showing nonconforming product was segregated to prevent unintended use
Common Nonconformities
- Nonconforming product is dispositioned as 'use-as-is' or 'accept with concession' without documented rationale assessing impact on device safety, performance, and regulatory compliance (Grade 3).
- No physical segregation of nonconforming product -- nonconforming material is stored alongside conforming material with only a label or tag to differentiate (Grade 2).
- Reworked product is released without re-inspection or re-testing against the original acceptance criteria (Grade 3).
- Concession dispositions are approved by quality staff without involvement of design engineering or regulatory affairs for devices with critical safety requirements (Grade 2).
Auditor Tips
Nonconforming product control is a direct patient safety concern. Focus on concession dispositions -- these are the highest risk because nonconforming product is being released to market with an accepted deviation. Verify the rationale is documented, technically sound, and approved by someone with the authority and competence to assess safety impact. FDA places significant emphasis on this area. Per MDSAP companion document QMS P0015, verify that nonconforming product disposition considers regulatory impact, not just product specification compliance. Cross-reference with Chapter 5 (Production) for in-process nonconformities and Chapter 7 for returned product.
Follow-Up Questions
- Show me a nonconforming product record where the disposition was 'use-as-is.' How was the safety and regulatory impact assessed?
- How do you track the cumulative effect of concessions on a product line over time?
What to Sample
Review 3 nonconforming product records. Verify at least one concession disposition has documented rationale and appropriate approval. Check segregation practices on the production floor. Verify reworked product was re-inspected.
Objective Evidence
- Data analysis procedure or practice defining sources, methods, frequency, and outputs
- Data analysis reports or dashboards covering at least complaints, CAPA, audit findings, process monitoring, and supplier performance -- verify reports are current (within past 6 months)
- Evidence that data analysis identified at least one trend or pattern that triggered a corrective or preventive action
- Management review records showing data analysis results were presented and discussed
Common Nonconformities
- Data from different quality system sources is analyzed in isolation -- complaint trends, audit findings, and process monitoring data are never correlated to identify systemic issues (Grade 2).
- Data analysis consists of summary statistics (counts, averages) without trend analysis or statistical process control -- the organization cannot detect deteriorating performance before it becomes a nonconformity (Grade 1).
- Data analysis reports are produced but not reviewed by management or used as input to decision-making (Grade 1).
Auditor Tips
This task verifies the organization connects data from disparate sources to identify systemic patterns. The most mature organizations correlate complaint data with production data, CAPA with audit findings, and supplier performance with product quality. Ask for an example where data analysis led to a proactive improvement action. If the organization only uses data analysis reactively (after a problem occurs), the system is not functioning as intended by the standard.
Follow-Up Questions
- Can you show me an example where data analysis from multiple sources identified a systemic issue that would not have been visible from any single source alone?
- What statistical tools or methods do you use for data analysis?
What to Sample
Review the most recent data analysis output. Verify it covers all required sources. Check that at least one trend or pattern was identified and actioned. Confirm the analysis was presented at management review.
Objective Evidence
- Reportability assessment procedure with jurisdiction-specific criteria -- FDA MDR (21 CFR 803), Health Canada Mandatory Problem Reporting (CMDR s.59--61), ANVISA Tecnovigilancia (RDC 67/2009), PMDA adverse event reporting (PMD Act Art. 68-10), TGA adverse event reporting (TG(MD)R Part 4 Div 2)
- Regulatory reporting timeline matrix showing required timeframes per jurisdiction and event type -- FDA 30-day/5-day, Health Canada 10-day/48-hour, ANVISA 72-hour/24-hour, PMDA 15-day/immediate, TGA 10-day/48-hour
- Records of regulatory reports submitted in the past 24 months -- verify reports were submitted within required timeframes
- Records of events evaluated and determined not reportable -- verify rationale is documented per jurisdiction
Common Nonconformities
- Reports were submitted to FDA but not to other applicable jurisdictions -- the organization reported to its primary regulatory authority but did not assess reportability for Health Canada, ANVISA, PMDA, or TGA (Grade 4 -- direct regulatory impact).
- Reports were submitted but outside the required timeframe -- jurisdiction-specific timelines were not met (Grade 3).
- Reportability assessment criteria are generic and do not account for differences between jurisdictions -- the same threshold is applied regardless of the jurisdiction's specific definition of a reportable event (Grade 3).
- No records exist for events determined not reportable -- the organization cannot demonstrate it performed a reportability assessment (Grade 2).
Auditor Tips
This is one of the highest-risk tasks in the MDSAP audit because late or missed reporting is a Grade 4--5 nonconformity that can trigger a 5-Day Notice. Each jurisdiction has different reportability criteria and timelines. FDA uses 'death or serious injury' and 'malfunction that could cause death or serious injury.' Health Canada uses 'incident' with a broader definition. ANVISA, PMDA, and TGA each have their own definitions. Verify the organization has a jurisdiction-by-jurisdiction decision matrix and can demonstrate compliance for each report submitted. Cross-reference with Chapter 7 for detailed adverse event review.
Follow-Up Questions
- Walk me through a recent reportability decision. How did you determine which jurisdictions required a report?
- Can you show me an event that was reportable in one jurisdiction but not another, and explain the difference?
What to Sample
Review 3 regulatory reports and verify submission timeliness. Review 2 events determined not reportable and verify rationale per jurisdiction. Cross-reference complaint records from Task 3.1 with reporting records.
Objective Evidence
- Post-market surveillance plan for at least one device -- verify it defines data sources, collection methods, analysis frequency, and actions based on findings
- Post-market surveillance data and analysis records -- verify data collection is active, not just planned
- Evidence that post-market surveillance findings feed into risk management, CAPA, and design processes
- Records showing post-market surveillance data was reported to applicable regulatory authorities where required (periodic safety reports, PSUR equivalents)
Common Nonconformities
- No post-market surveillance plan exists -- the organization relies on complaint handling as its only source of post-market information without proactive data collection (Grade 2).
- Post-market surveillance plan exists but is generic across all devices regardless of risk class -- no risk-proportionate approach to data collection and analysis frequency (Grade 1).
- Post-market surveillance data is collected but not analyzed or fed back into the risk management file -- the process is disconnected from the rest of the QMS (Grade 2).
Auditor Tips
Post-market surveillance is increasingly emphasized by all MDSAP jurisdictions. The plan must be proportionate to device risk -- higher-risk devices require more active and frequent surveillance. Verify the organization collects data from multiple sources (complaints, literature, registries, clinical follow-up, competitive intelligence) rather than relying solely on complaints. PMDA and Health Canada have specific post-market surveillance reporting requirements. Cross-reference with risk management (Task 1.4) and CAPA (Task 3.2).
Follow-Up Questions
- Beyond complaints, what other data sources do you use for post-market surveillance?
- How do post-market surveillance findings trigger updates to your risk management files?
What to Sample
Review the post-market surveillance plan for the highest-risk device. Verify data was collected and analyzed within the defined timeframe. Check that at least one finding was routed to risk management or CAPA.
Objective Evidence
- Software validation procedure covering scope (which software requires validation), validation approach (IQ/OQ/PQ or equivalent), roles, and revalidation triggers
- Inventory of software used in the QMS with validation status -- verify critical software (complaint database, CAPA system, document management, production control, inspection systems) is validated
- Validation records for at least one critical QMS software system -- verify validation included requirements definition, test protocols, test results, and approval
- Revalidation records for software that has been updated or upgraded -- verify revalidation was performed within a defined timeframe after the change
Common Nonconformities
- No inventory of QMS-related software exists -- the organization cannot identify which software systems require validation (Grade 2).
- Excel spreadsheets used for critical calculations (acceptance criteria, statistical analysis, label generation) are not validated -- the organization does not consider spreadsheets as software requiring validation (Grade 3).
- Software was validated at initial installation but has undergone multiple updates without revalidation -- current software version does not match the validated version (Grade 2).
- Validation records consist only of 'installation verified' without functional testing, edge case testing, or data integrity verification (Grade 2).
Auditor Tips
Software validation is a perennial finding area. ISO 13485 clause 4.1.6 and FDA 21 CFR 820.70(i) require validation of computer software used in the QMS. The most commonly missed items are Excel spreadsheets, Access databases, and software used in measuring and test equipment. Ask the organization to show you their software inventory and then walk the production floor -- you will almost always find software in use that is not on the inventory. Revalidation after updates is also frequently missed, especially for cloud-based QMS systems that update automatically.
Follow-Up Questions
- How do you determine which software systems require validation?
- Are there any Excel spreadsheets or databases used for quality-critical calculations? Are they validated?
- How do you manage revalidation when your cloud-based QMS software provider releases an update?
What to Sample
Review the software inventory. Walk the production floor and identify software not on the inventory. Review validation records for one critical system. Verify revalidation was performed after the most recent update.
Frequently Asked Questions
Get the Full 62-Item Checklist
Download the complete MDSAP audit checklist with all 62 expert items, objective evidence requirements, common nonconformities, auditor tips, and a professional scoring rubric.
This checklist is an educational resource for audit preparation. It does not constitute professional regulatory advice. Always consult qualified auditors for certification decisions.