MDSAP audit checklist
Practising auditors wrote these 62 audit questions, covering the full standard. Each item names the objective evidence to request, the nonconformities most often raised against it, and what to sample. It is free to read, with no sign-up required.
Download the PDF
Includes all 62 items, formatted for a clipboard.
You will get one email with the file. We will not send anything else.
What each item gives you
This is what an auditor needs at each item. You already hold the standard itself.
Phrases it the way you would ask it in the room.
Names the specific artefacts that satisfy the item, and how to tell a real one from a placeholder.
Lists the findings most often raised here, in the words they get written up in.
Shows where the item usually goes wrong, and what a mature answer sounds like against a rehearsed one.
Explains how many to take, how to choose them, and what to cross-reference them against.
Gives the second and third questions to ask when the first answer is too smooth.
All 62 items on this page
Questions below are grouped by section, and you can check items off as you go — this browser remembers your progress. Open any row for its evidence, common nonconformities and auditor tips.
§chapter.1 Management
1.1 Has the organization planned, implemented, and documented a quality management system that meets both ISO 13485:2016 requirements and the regulatory requirements of all jurisdictions in which it markets devices? Does a quality manual or equivalent documentation exist that defines QMS scope, process interactions, and exclusion justifications?
- Quality manual or equivalent documentation showing QMS scope, applicable regulatory jurisdictions, product scope, and site coverage -- verify alignment with actual marketing authorizations held
- QMS process map or interaction diagram showing how management, realization, support, and measurement processes interconnect -- confirm process owners are current employees
- Master document list filtered to management system procedures -- verify at least 3 randomly selected procedures have current revision dates within the organization's defined review cycle
- QMS change management records from the past 12 months -- verify that changes were risk-assessed and validated before implementation
- Regulatory requirements matrix mapping each MDSAP jurisdiction's requirements to specific QMS procedures -- cross-check at least 2 entries against the referenced procedures
- Quality manual scope does not include all jurisdictions for which the organization holds marketing authorizations -- devices are sold in Brazil but QMS scope only references FDA and Health Canada (Grade 3 -- direct QMS impact).
- No documented QMS change management process exists -- recent organizational changes (new production line, site move) were implemented without assessing impact on the QMS (Grade 3).
- Process interaction diagram is a generic template that does not reflect the organization's actual process flow -- names and departments on the diagram do not match the current organizational chart (Grade 1).
- Quality manual has not been reviewed or updated within the organization's defined review cycle and references obsolete regulatory requirements (Grade 1).
This is your calibration question. Use it to gauge whether the QMS is a living system or shelf documentation. Ask the quality manager to walk through the process map without referring to notes -- hesitation or misalignment with reality signals a paper QMS. Verify that the scope explicitly names every jurisdiction where the organization holds marketing authorizations, not just the 'primary' markets. Check that exclusions (e.g., design control exclusion) are justified and not used to avoid applicable requirements. Per MDSAP companion document QMS P0015, verify that the quality manual addresses multi-jurisdiction applicability.
Request the quality manual, process map, and regulatory requirements matrix. Cross-reference the scope against actual marketing authorizations. Pull 3 random procedures from the master list and verify they are current.
- When was the last structural change to your QMS, and what triggered it?
- How do you ensure your QMS addresses the regulatory requirements of all five MDSAP jurisdictions, not just the ones you audit against most frequently?
- If a new jurisdiction-specific requirement was published tomorrow, what is your process for incorporating it?
1.2 Has top management appointed a management representative with defined authority and responsibility for ensuring the QMS is established, implemented, and maintained? Does this person have unrestricted access to report QMS performance directly to top management?
- Documented appointment letter or organizational chart showing the management representative with reporting line to top management
- Job description or role definition specifying QMS responsibilities, authority to stop production for quality reasons, and access to top management
- Meeting minutes or communication records showing the management representative reporting QMS status to top management within the past 12 months
- Evidence that the management representative has authority over resources needed to maintain the QMS
- Management representative role is assigned to a mid-level quality engineer who reports through two layers of management before reaching top management -- no direct access for escalation of quality issues (Grade 1).
- No formal appointment exists -- the quality manager performs the role by default but has no documented authority to halt production or escalate systemic issues (Grade 1).
- Management representative changed 6 months ago but the quality manual and regulatory submissions still reference the previous appointee (Grade 1).
Verify this is not a checkbox exercise. The management representative must have real authority, not just a title. Ask for a specific example of when they escalated a quality concern to top management and what happened. In organizations where the management representative is also the quality manager, verify they have sufficient independence to raise concerns about cost-driven decisions that compromise quality. Per FDA requirements, verify this role has authority over quality system activities.
Review the appointment letter or job description. Check the last 2 management review meeting attendee lists to confirm the management representative was present and actively participated.
- Can you describe a recent situation where you escalated a quality concern to top management? What was the outcome?
- If you needed to stop a production line due to a quality issue, do you have the authority to do that without additional approval?
1.3 Has the organization established a quality policy that includes a commitment to compliance with regulatory requirements and to maintaining the effectiveness of the QMS? Has the policy been communicated to and understood by personnel at all levels?
- Documented quality policy signed by top management with a date within the organization's defined review cycle
- Evidence of communication to all levels -- posted in work areas, included in onboarding, referenced in training materials
- Interview 2--3 employees at different levels (floor operator, supervisor, engineer) to verify they can describe the quality policy in their own words
- Records showing the quality policy was reviewed during management review -- confirm review date and any resulting changes
- Quality policy is posted in the conference room but floor operators cannot articulate what it means or how it applies to their work -- communication is one-directional with no evidence of understanding (Grade 1).
- Policy does not reference regulatory compliance -- it focuses on customer satisfaction and continuous improvement but omits the organization's commitment to meeting applicable regulatory requirements (Grade 1).
- Quality policy was last reviewed more than 5 years ago and references an organizational mission statement that has since changed (Grade 1).
The quality policy test is simple: can a floor operator explain it in their own words? If they can only recite it from a poster, it is not understood. Look for evidence that the policy drives actual behavior -- for example, does the CAPA procedure reference the quality policy commitment to continuous improvement? Health Canada and ANVISA place particular emphasis on regulatory compliance commitment in the policy statement.
Read the quality policy. Interview 2 employees at different levels. Check that the most recent management review agenda included quality policy review.
- How do you verify that personnel understand the quality policy -- not just that they have been told about it?
- When was the quality policy last changed, and what drove the change?
1.4 Has the organization established a risk management process that addresses the entire product lifecycle, from design through post-market surveillance? Are risk management plans and risk management files maintained for each device or device family?
- Risk management procedure referencing ISO 14971 and addressing all lifecycle phases -- verify it covers risk analysis, risk evaluation, risk control, and residual risk evaluation
- Risk management plan for at least one device showing scope, responsibilities, risk acceptability criteria, and planned verification activities
- Risk management file for the same device showing risk analysis records, risk control measures, and residual risk assessment -- verify it is current and includes post-market data
- Evidence that production and post-production information is fed back into the risk management process -- link to complaint data, CAPA records, or post-market surveillance reports
- Risk management file was completed at design transfer and has not been updated with post-market data -- no evidence that complaint trends, CAPA outcomes, or field performance data have been evaluated for risk impact (Grade 3 -- direct QMS impact).
- Risk acceptability criteria are not defined or are defined so broadly that no risk is ever deemed unacceptable -- the risk management process cannot demonstrate it would reject a design with unacceptable risk (Grade 3).
- Risk management process addresses only product risks and does not cover process risks (e.g., sterilization failure, packaging breach) as required by the MDSAP audit model (Grade 2).
- No linkage between risk management and design inputs -- design input requirements do not reference the risk analysis, and risk controls are not traced to design outputs (Grade 3).
Risk management is a thread that runs through every MDSAP chapter. Use this task to establish the baseline and then verify linkages in Chapters 3--7. The most common failure is a static risk management file that was created during design and never updated. Ask for the last update date and what triggered it. MDSAP companion document QMS P0015 specifically requires verification of lifecycle risk management, not just design-phase risk analysis. All five jurisdictions require ISO 14971 application -- verify the organization references the current edition.
Select the highest-risk device. Review the risk management plan and file. Verify the file includes post-market data updates within the past 12 months. Check linkage to at least one CAPA record.
- When was the risk management file for your highest-risk device last updated, and what triggered the update?
- How does post-market information -- complaints, CAPAs, literature reviews -- feed back into your risk management files?
- What criteria do you use to determine if a risk is acceptable, and can you show me an example where a risk was initially deemed unacceptable?
1.5 Has the organization established controls over outsourced processes that affect product conformity? Are outsourced process providers evaluated, monitored, and subject to quality agreements that define responsibilities and quality requirements?
- List of outsourced processes with risk classification and rationale for outsourcing -- verify it includes all outsourced activities (sterilization, testing, calibration, design, manufacturing)
- Quality agreements or technical agreements for each critical outsourced process -- verify they define responsibilities, quality requirements, acceptance criteria, and right of audit
- Supplier audit or evaluation records for outsourced process providers -- verify frequency is risk-based and evaluations are current
- Monitoring data for outsourced processes -- incoming inspection results, performance metrics, or periodic review records
- Sterilization is outsourced but no quality agreement exists with the contract sterilizer -- the organization relies on the sterilizer's ISO certificate without defining specific requirements or monitoring performance (Grade 3).
- Outsourced processes are not included in the organization's process map or QMS scope -- they are managed as simple 'purchases' without the controls required for outsourced QMS processes (Grade 2).
- Quality agreements exist but have not been reviewed since initial execution -- the outsourced provider has changed processes, moved facilities, or been acquired without triggering a review of the agreement (Grade 1).
Outsourced process control is a frequent finding area because organizations often treat outsourced processes as simple purchases. The key distinction is control and responsibility: if the process is part of the organization's QMS but performed externally, it requires more than purchase order controls. Verify quality agreements are specific (not generic templates) and include right-of-audit clauses. Health Canada and FDA place particular emphasis on outsourced sterilization and testing. Cross-reference with Chapter 6 (Purchasing) to avoid duplicate findings.
Review the outsourced process list. Select the most critical outsourced process and verify the quality agreement, most recent audit or evaluation, and monitoring data.
- How do you distinguish between an outsourced process and a purchased product or service?
- When was the last time you audited your contract sterilizer or other critical outsourced process provider?
- If your outsourced process provider changed a key process parameter, how would you know?
1.6 Has the organization established and maintained communication processes with regulatory authorities for each jurisdiction where it markets devices? Are regulatory notifications, change notifications, and authority communications documented and tracked?
- Procedure or process description for regulatory authority communication covering all applicable jurisdictions
- Log or tracking system for regulatory correspondence -- submissions, notifications, queries, and responses
- Records of regulatory notifications submitted in the past 12 months (e.g., change notifications, annual reports, periodic safety reports)
- Evidence that regulatory authority communications are reviewed for QMS impact and routed to appropriate personnel
- Organization has no centralized tracking of regulatory authority correspondence -- communications are managed by individual regulatory affairs staff with no oversight or handoff process (Grade 1).
- Regulatory notifications required by Health Canada (Significant Change notifications) or ANVISA (post-registration changes) were not submitted or were submitted late (Grade 3 -- jurisdiction-specific requirement violation).
- No process exists to monitor regulatory authority communications for changes that may affect the QMS -- the organization is unaware of a published guidance document that impacts its device classification (Grade 2).
Each jurisdiction has different notification requirements. FDA requires Annual Reports (PMA) and 510(k) for changes. Health Canada requires Significant Change applications. ANVISA requires post-registration change notifications. PMDA requires partial change approvals. TGA requires change notifications for ARTG entries. Verify the organization tracks obligations per jurisdiction, not just its primary market. This task links to Chapter 2 (Marketing Authorization) -- verify consistency.
Review the regulatory correspondence log. Select one recent device change and verify that all required regulatory notifications were submitted to applicable jurisdictions within required timeframes.
- How do you track regulatory notification obligations across all five MDSAP jurisdictions?
- Can you show me the last regulatory notification you submitted? Which jurisdictions required it, and was it submitted within the required timeframe?
1.7 Does management review input include data from all required sources, including QMS performance, feedback, process performance, product conformity, audit results, complaint and CAPA trends, regulatory changes, and risk management updates? Does the review cover multi-jurisdiction regulatory performance?
- Management review procedure defining required inputs, frequency, and participants -- verify it lists all inputs required by ISO 13485:2016 clause 5.6.2
- Most recent management review minutes or report showing each required input was addressed with data -- not just agenda items, but actual metrics, trends, and analysis
- Evidence that complaint trends, CAPA effectiveness data, audit findings, and post-market surveillance data were presented with quantitative analysis
- Records showing management review covered jurisdiction-specific regulatory performance -- adverse event reporting timeliness, regulatory submissions status, and authority communications
- Management review minutes show topics were discussed but no quantitative data was presented -- 'CAPA status was reviewed' with no trend data, closure rates, or effectiveness metrics (Grade 2).
- Required inputs were omitted -- no review of post-market surveillance data, no review of regulatory changes, or no review of risk management updates (Grade 2).
- Management review does not address multi-jurisdiction regulatory performance -- adverse event reporting compliance, regulatory submission status, and authority communications are not covered per MDSAP requirements (Grade 2).
- Management review frequency does not meet the defined schedule -- the most recent review was 18 months ago despite a documented annual requirement (Grade 1).
Management review is the most commonly cited finding area in MDSAP audits because it is the integration point for data from all other chapters. Verify actual data was presented, not just agenda items. MDSAP specifically requires that management review address multi-jurisdiction regulatory performance -- this goes beyond the ISO 13485 minimum. Ask to see the slide deck or data package, not just the minutes. Cross-reference complaint data shown in management review against actual complaint records from Chapter 3.
Review the last 2 management review records. Verify all required inputs per ISO 13485 clause 5.6.2 were addressed with data. Verify management review outputs include action items with assigned owners and completion dates.
- Can you show me the data package that was presented at the last management review -- not just the minutes, but the actual charts and metrics?
- How do you ensure management review covers regulatory performance for all five MDSAP jurisdictions?
- What specific actions resulted from the last management review, and can you show me evidence they were completed?
1.8 Do management review outputs include decisions and actions related to resource needs, QMS improvements, regulatory compliance improvements, and product improvements? Are action items tracked to completion with evidence of effectiveness?
- Management review output records showing specific decisions, action items, responsible parties, and target dates
- Action item tracking log or system showing status of management review actions -- verify closure evidence for completed items
- Evidence that management review outputs addressed resource allocation decisions (personnel, equipment, infrastructure)
- Evidence that at least one improvement action from management review was implemented and its effectiveness verified
- Management review minutes conclude with vague action items ('improve CAPA process') with no specific owner, target date, or measurable success criteria (Grade 1).
- Action items from previous management reviews are carried forward indefinitely without escalation or re-prioritization -- the same items appear on 3 consecutive reviews without progress (Grade 2).
- No evidence that management review outputs led to actual resource allocation decisions -- the organization identifies resource needs but management does not approve or fund them (Grade 2).
The value of management review is in the outputs, not the meeting. Look for specific, measurable actions with assigned owners. If the same action items recur across multiple reviews without resolution, this indicates the management review process is ineffective as a driver of improvement. Verify at least one action was closed with evidence of effectiveness -- not just completion. MDSAP expects management review to drive multi-jurisdiction regulatory improvements, not just QMS process changes.
Review action items from the last 2 management reviews. Track at least 3 items to closure with effectiveness evidence. Check for overdue or recurring items.
- Show me an action item from the last management review that has been completed. What evidence do you have that it was effective?
- Are there any management review action items that have been open for more than 6 months? Why?
1.9 Has the organization determined and provided the resources, infrastructure, and work environment needed to achieve product conformity and regulatory compliance? Is infrastructure qualification and maintenance documented?
- Resource planning records or budget allocations for quality system resources -- personnel, equipment, facilities, and training
- Infrastructure qualification records for critical production and testing equipment -- IQ/OQ/PQ or equivalent
- Preventive maintenance schedules and records for critical infrastructure -- verify maintenance is current
- Work environment monitoring records where environmental conditions affect product quality -- temperature, humidity, particulate counts, ESD controls
- Cleanroom environmental monitoring records show out-of-specification particulate counts on multiple occasions with no investigation or corrective action taken (Grade 3).
- No preventive maintenance program exists for production equipment -- maintenance is performed only when equipment fails (Grade 2).
- Organization has added a second production shift but has not assessed whether infrastructure (equipment capacity, environmental controls, utilities) is adequate for increased throughput (Grade 1).
Infrastructure and work environment are often treated as facilities management issues rather than QMS requirements. Verify that environmental monitoring where required (cleanrooms, ESD areas, temperature-controlled storage) produces documented records that are reviewed for trends. If the organization performs sterilization or uses controlled environments, cross-reference with Chapter 5. FDA 21 CFR 820.70 and ANVISA GMP requirements (RDC ANVISA 665/2022) include specific environmental controls.
Review infrastructure maintenance records for 3 critical production or testing assets. Check environmental monitoring data for one controlled area. Verify out-of-specification events were investigated.
- How do you determine what infrastructure and environmental controls are needed for your products?
- Can you show me environmental monitoring data for your most critical production area over the past 6 months?
1.10 Has the organization established document control and record control processes that meet the requirements of all applicable MDSAP jurisdictions? Are documents approved, distributed, and controlled to prevent use of obsolete versions? Are records retained for the periods required by each jurisdiction?
- Document control procedure addressing approval, review, distribution, revision control, and obsolete document management -- verify it references jurisdiction-specific retention requirements
- Master document list or electronic document management system showing current revisions, effective dates, and approval status for all QMS documents
- Record retention schedule that addresses the retention requirements of all five MDSAP jurisdictions -- verify it identifies the longest applicable retention period for each record type
- Evidence of controlled document distribution -- verify that at least 3 work areas have current revision documents available (not obsolete versions)
- Record retention schedule only addresses FDA requirements (2 years or device lifetime) and does not account for longer retention periods required by other jurisdictions -- Health Canada requires retention for the life of the device plus one year, ANVISA requires specific periods per record type (Grade 2).
- Obsolete documents are still accessible in production areas without clear identification as superseded -- operators could inadvertently follow an outdated procedure (Grade 3).
- Electronic document management system does not enforce approval workflows -- documents can be posted without formal review and approval (Grade 2).
Document and record control is foundational and often audited early. For MDSAP, the key differentiator is multi-jurisdiction retention requirements. Each jurisdiction has different retention periods, and the organization must apply the most stringent. FDA requires device lifetime plus 2 years for certain records. Health Canada requires device lifetime plus 1 year. ANVISA and PMDA have their own schedules. Verify the organization has identified the longest period and applies it consistently. Cross-reference with Chapter 2 for technical documentation retention.
Check the record retention schedule against jurisdiction-specific requirements. Verify 3 random documents on the production floor are current revision. Confirm at least one obsolete document was properly retired.
- How do you determine the record retention period when multiple jurisdictions have different requirements?
- Can you show me how you prevent use of obsolete documents in production areas?
§chapter.2 Device marketing authorization and facility registration
2.1 Does the organization hold valid marketing authorizations for each device in each jurisdiction where it is marketed? Are regulatory submissions prepared, submitted, and maintained according to documented procedures?
- List of all devices marketed by jurisdiction, showing the marketing authorization type, number, and status (active, pending, expired) for each device-jurisdiction combination
- Regulatory submission procedure covering submission types, review workflows, and tracking mechanisms for each jurisdiction
- Sample marketing authorizations -- at least one per jurisdiction -- verified as current and matching the device currently being manufactured
- Tracking system for regulatory submission status, approval conditions, and renewal dates
- Devices are being marketed in a jurisdiction without a valid marketing authorization -- the organization assumed mutual recognition where none exists (Grade 4 -- direct impact, regulatory violation).
- Marketing authorization references an older device specification that no longer matches the current manufactured device -- design changes were implemented without updating the submission (Grade 3).
- No systematic tracking of marketing authorization renewal dates -- an authorization expired without the organization being aware (Grade 3).
This is where you verify the legal right to market. Cross-reference the device list against actual marketing authorizations for each jurisdiction. Common gaps: devices sold through distributors in jurisdictions where the manufacturer has not obtained or maintained authorization, or devices that have undergone design changes without corresponding regulatory updates. Each jurisdiction has different change notification thresholds -- verify the organization knows them. FDA requires new 510(k) for certain changes. Health Canada requires Significant Change applications. ANVISA and TGA have post-market change notification processes.
Select 3 devices. For each, verify the marketing authorization is current in every jurisdiction where the device is sold. Cross-reference the authorized device description against the current design output specifications.
- Can you show me a complete list of every device you sell, by jurisdiction, with the corresponding marketing authorization number?
- How do you determine whether a design change requires a new regulatory submission versus a change notification?
2.2 Is the organization's establishment or facility registered with each applicable regulatory authority? Are device listings current and accurate for each jurisdiction?
- Establishment registration records for each applicable jurisdiction -- FDA establishment registration, Health Canada establishment licence, ANVISA company registration, PMDA marketing authorization holder registration, TGA sponsor registration
- Device listing records showing all marketed devices are listed with the correct classification, product codes, and proprietor information per jurisdiction
- Evidence of annual registration renewals where required -- FDA annual registration, Health Canada annual licence fee
- Records showing device listing updates when devices are added, modified, or discontinued
- FDA establishment registration has lapsed because the annual renewal was missed -- the organization is technically operating without current registration (Grade 4).
- Device listing does not include all devices currently marketed -- recently launched devices were not added to the listing within the required timeframe (Grade 3).
- Device classification in the listing does not match the actual classification determination -- product codes or device class designations are incorrect (Grade 2).
Establishment registration and device listing are separate from marketing authorization but equally critical. FDA requires annual establishment registration and device listing updates. Health Canada requires an establishment licence that must be renewed annually. ANVISA requires company registration (Cadastro). Verify each is current. A common gap is that the organization registered years ago but has not updated its listing when new devices were added or existing devices were modified. Cross-reference the device listing against the marketing authorization list from Task 2.1.
Verify establishment registrations are current for each jurisdiction. Cross-reference device listings against the actual product catalog. Check that at least one recently launched device was added to listings within the required timeframe.
- When was your most recent establishment registration renewal for each jurisdiction?
- How do you ensure device listings are updated when you launch a new device or discontinue an existing one?
2.3 Does device labeling meet the requirements of each jurisdiction where the device is marketed? Are labeling controls in place to prevent mix-ups, ensure accuracy, and manage translations?
- Labeling control procedure covering label design, approval, storage, issuance, and reconciliation
- Labeling review records showing verification against jurisdiction-specific requirements -- FDA 21 CFR 801, Health Canada CMDR labeling requirements, ANVISA labeling rules, PMDA labeling standards, TGA labeling requirements
- Sample labels for at least one device -- verify they include all required elements per applicable jurisdiction (device name, manufacturer, UDI/GTIN, lot/serial, expiry, IFU reference, regulatory symbols)
- Translation management records for multi-language labeling -- verification that translations are accurate and cover all required jurisdictions
- Labels do not include Unique Device Identification (UDI) information as required by the applicable jurisdiction's UDI implementation timeline (Grade 3).
- Instructions for Use are only available in English and the primary market language but not in languages required by other jurisdictions where the device is sold (Grade 2).
- Labeling review checklist does not address jurisdiction-specific requirements -- it only covers ISO 15223 symbols without verifying country-specific text and content requirements (Grade 2).
Labeling is a high-variation area across jurisdictions. FDA has extensive labeling requirements under 21 CFR 801 and UDI requirements. Health Canada requires bilingual (English/French) labeling. ANVISA requires Portuguese labeling. PMDA requires Japanese labeling with specific content requirements. TGA has its own labeling requirements. Verify the organization has a labeling matrix that identifies requirements per jurisdiction. Pay special attention to UDI compliance timelines, which vary by device class and jurisdiction.
Select one device sold in at least 3 jurisdictions. Verify the label includes all required elements per each jurisdiction. Check that IFU translations exist for required languages. Verify UDI status.
- How do you ensure labeling compliance when a device is sold in multiple jurisdictions with different language and content requirements?
- What is your current UDI compliance status for each applicable jurisdiction?
2.4 Does the organization maintain technical documentation or design dossiers that support marketing authorization submissions for each jurisdiction? Are these documents updated when design changes occur?
- Technical documentation or design dossier for at least one device -- verify it contains the elements required by each applicable jurisdiction's submission format
- Change management records showing technical documentation updates aligned with design changes
- Traceability matrix linking design outputs to technical documentation sections -- verify consistency
- Evidence that technical documentation supports currently marketed device versions, not obsolete configurations
- Technical documentation has not been updated to reflect design changes made after initial marketing authorization -- the dossier describes a configuration that no longer matches the manufactured device (Grade 3).
- No traceability between design history file and technical documentation -- engineers cannot demonstrate which technical documentation sections are affected by a given design change (Grade 2).
- Technical documentation exists only for the primary jurisdiction submission format (e.g., FDA 510(k)) with no equivalent documentation structured for other jurisdictions' requirements (Grade 1).
Technical documentation is the regulatory record of the device. Each jurisdiction has different expectations for format and content -- FDA Summary (510(k)), EU Technical Documentation (MDR Annex II/III), Health Canada STED format. Verify the organization can produce jurisdiction-specific documentation on request. The most common gap is documentation that was created for initial submission and never updated as the device evolved. Cross-reference with Chapter 4 (Design Changes) to verify consistency.
Select one device with a recent design change. Verify the technical documentation reflects the current design. Cross-reference at least 2 design outputs against the technical documentation content.
- If a regulatory authority requested your current technical documentation for a specific device, how quickly could you produce it?
- How do you ensure technical documentation stays synchronized with design changes?
2.5 Has the organization identified and implemented all applicable regulatory requirements for each jurisdiction, including jurisdiction-specific requirements that go beyond ISO 13485? Is there a systematic process for monitoring regulatory changes?
- Regulatory requirements matrix mapping each jurisdiction's specific requirements to QMS procedures -- verify completeness for all five MDSAP jurisdictions
- Regulatory intelligence process -- documented method for monitoring regulatory changes, guidance updates, and enforcement actions in each jurisdiction
- Records showing regulatory change assessments performed in the past 12 months -- at least one change per jurisdiction identified, assessed, and actioned or dismissed with rationale
- Training records showing regulatory affairs personnel are trained on jurisdiction-specific requirements
- Regulatory requirements matrix only covers FDA and Health Canada -- no systematic identification of ANVISA, PMDA, or TGA-specific requirements despite marketing devices in those jurisdictions (Grade 2).
- No formal regulatory intelligence process exists -- the organization relies on trade publications and informal networks rather than systematic monitoring of regulatory authority publications (Grade 1).
- Regulatory change was published 6 months ago but the organization has not assessed its impact -- no evidence that new guidance or regulation was reviewed for QMS impact (Grade 2).
This task verifies that the organization proactively manages regulatory compliance rather than reacting to audit findings. Each MDSAP jurisdiction publishes regulatory changes at different frequencies and through different channels. Verify the organization monitors FDA Federal Register, Health Canada Gazette, ANVISA Diario Oficial, PMDA notifications, and TGA regulatory updates. A mature organization will have a regulatory change management procedure that routes changes to affected process owners with defined timelines for assessment.
Review the regulatory requirements matrix for completeness. Verify the regulatory intelligence process has produced at least 2 change assessments in the past 12 months. Spot-check one jurisdiction-specific requirement against the organization's actual implementation.
- How do you monitor regulatory changes across all five MDSAP jurisdictions?
- Can you show me the last regulatory change you assessed and what action resulted?
2.6 Has the organization appointed authorized representatives, local agents, or Person Responsible for Regulatory Compliance where required by each jurisdiction? Are agreements current and responsibilities clearly defined?
- List of appointed representatives per jurisdiction -- authorized representative (EU/Health Canada), local agent (ANVISA), marketing authorization holder (PMDA), sponsor (TGA)
- Written agreements with each representative defining responsibilities, authority, and communication protocols -- verify agreements are current and signed
- Evidence of communication between the organization and its representatives in the past 12 months
- Verification that representative contact information provided to regulatory authorities is accurate and current
- Authorized representative agreement has expired or the representative has changed without notifying the regulatory authority (Grade 3).
- No formal agreement exists with the local agent in Brazil -- the organization uses a distributor as its ANVISA representative without a written agreement defining regulatory responsibilities (Grade 2).
- Representative contact information on file with the regulatory authority does not match the current representative -- the previous representative's details are still registered (Grade 2).
Each jurisdiction has specific requirements for local representation. Health Canada requires a Canadian representative for foreign manufacturers. ANVISA requires a legal representative in Brazil. PMDA requires a marketing authorization holder in Japan. TGA requires an Australian sponsor. Verify that agreements are not just commercial distribution agreements but specifically address regulatory responsibilities. A common gap is that the organization changed its representative but did not update the registration with the regulatory authority.
Review representative agreements for at least 2 jurisdictions. Verify the representative information registered with the regulatory authority matches the current agreement. Check for recent communication records.
- How do you verify that your authorized representatives are fulfilling their regulatory obligations?
- When was the last time you reviewed and updated your representative agreements?
2.7 Does the organization participate in any voluntary standards, industry programs, or consensus standards relevant to its devices? Are these referenced in the QMS and kept current?
- List of voluntary or consensus standards applied to devices (e.g., IEC 60601 for electrical safety, ISO 10993 for biocompatibility, IEC 62304 for software)
- Evidence that referenced standards are current editions -- verify the organization is aware of and planning for standard transitions
- Verification that standard requirements are incorporated into design inputs and testing protocols
- Organization references an obsolete edition of a consensus standard in its marketing authorization submission and has not assessed the impact of transitioning to the current edition (Grade 1).
- Voluntary standards are referenced in design documentation but the organization cannot demonstrate compliance testing against the referenced edition (Grade 1).
This is a lower-risk task but can reveal gaps in the organization's awareness of evolving standards. If the organization references consensus standards in its marketing authorization submissions, verify those standards are current. Standard transitions (e.g., IEC 60601-1 Edition 3.2, ISO 10993 revisions) often trigger design changes that require regulatory notification.
Review the standards reference list. Verify at least 2 referenced standards are current editions. Check one standard transition for QMS impact assessment.
- Which consensus standards do you reference in your marketing authorization submissions, and are they current editions?
§chapter.3 Measurement, analysis, and improvement
3.1 Has the organization established and maintained documented procedures for complaint handling that cover receiving, reviewing, evaluating, investigating, and closing complaints? Does the procedure include criteria for determining when a complaint requires investigation and when it must be reported to regulatory authorities?
- Complaint handling procedure covering intake, evaluation, investigation, trending, and closure -- verify it includes reportability assessment criteria for all five MDSAP jurisdictions
- Complaint log or database showing all complaints received in the past 12 months -- verify completeness by cross-referencing against customer communication records and returned product logs
- Sample of 5 complaint records -- verify each was evaluated for investigation need, reportability was assessed per jurisdiction, investigation (where required) was completed, and the record was closed with documented rationale
- Complaint trending reports showing analysis by product, complaint type, severity, and time -- verify trends are reviewed and actioned
- Complaint procedure does not include jurisdiction-specific reportability criteria -- the organization uses a single set of reporting criteria that does not address differences between FDA MDR, Health Canada Mandatory Problem Reporting, ANVISA Tecnovigilancia, PMDA adverse event reporting, and TGA reporting (Grade 3).
- Complaints received through non-standard channels (social media, distributor verbal reports, sales team feedback) are not captured in the complaint system (Grade 3).
- Complaint investigations do not address root cause -- records show the complaint was evaluated but the investigation consists only of reviewing the complaint description without product examination, process review, or causal analysis (Grade 2).
- Complaint trending is performed but trends are not linked to the CAPA system -- recurring complaint types are identified but no corrective action is initiated (Grade 3).
Complaint handling is the single most commonly cited chapter in MDSAP audits and is a top-5 FDA 483 observation. Start by verifying the procedure includes multi-jurisdiction reportability criteria. Then sample at least 5 complaints -- include at least one that was reported to a regulatory authority and at least one that was evaluated and determined not reportable. Verify the rationale for non-reportability is documented and defensible. Cross-reference with Chapter 7 (Adverse Events) to verify all reportable events identified in complaints were actually reported. FDA 21 CFR 803 and 820.198 set the baseline; Health Canada CMDR s.57--58, ANVISA RDC 67/2009, PMDA adverse event reporting, and TGA adverse event reporting add jurisdiction-specific layers.
Pull 5 complaint records: 2 investigated, 1 reported to a regulatory authority, 1 determined not reportable, 1 closed without investigation (verify rationale). Verify trending data is current and linked to CAPA.
- How do you ensure complaints from all sources -- including distributors, social media, and sales teams -- are captured in your complaint system?
- Can you walk me through the reportability assessment for a specific complaint and show me how you determined it was or was not reportable?
- How do complaint trends feed into your CAPA system?
3.2 Has the organization established a CAPA system that identifies, investigates, and eliminates causes of existing and potential nonconformities? Does the system include root cause analysis methodology, effectiveness verification, and prevention of recurrence?
- CAPA procedure defining triggers, investigation methodology, root cause analysis tools, corrective action planning, implementation tracking, and effectiveness verification criteria
- Sample of 3 CAPA records -- at least one triggered by a complaint, one by an audit finding, and one by a process trend -- verify each includes root cause analysis, corrective action plan, implementation evidence, and effectiveness verification
- CAPA metrics showing timeliness of closure, effectiveness rates, and trending of CAPA sources -- verify metrics are reported in management review
- Evidence that preventive actions are also initiated -- not just corrective actions in response to problems
- Root cause analysis consists of a single 'why' statement without systematic methodology -- no evidence of 5-Why analysis, fishbone diagram, fault tree, or other structured root cause tool (Grade 2).
- CAPA effectiveness verification is performed immediately after corrective action implementation without allowing sufficient time for the action to demonstrate sustained effectiveness -- verification is a 'check-the-box' exercise (Grade 3).
- CAPA system is exclusively corrective -- no evidence of preventive actions based on trend analysis, risk assessment, or proactive identification of potential problems (Grade 2).
- CAPA records show the same root cause identified repeatedly across multiple CAPAs without recognizing the systemic nature of the problem -- each instance is treated as an isolated event (Grade 3).
CAPA is the engine of continuous improvement and is scrutinized heavily by all five MDSAP jurisdictions. The most common failures are shallow root cause analysis and ineffective verification. When reviewing CAPA records, look for evidence that the root cause is a systemic cause (not a symptom), that the corrective action addresses that systemic cause, and that effectiveness was verified with objective evidence after sufficient time elapsed. FDA expects CAPA to be one of the most robust processes in the QMS. Ask for CAPAs that failed effectiveness verification -- a mature system will have examples.
Review 3 CAPA records end-to-end. Verify root cause analysis methodology, corrective action appropriateness, implementation evidence, and effectiveness verification. Check at least one preventive action record. Verify CAPA metrics are reported in management review.
- Can you show me a CAPA where the first corrective action did not work and you had to revise your approach? What did you learn?
- How long do you wait between implementing a corrective action and verifying its effectiveness?
- How do you distinguish between a corrective action and a preventive action in your system?
3.3 Does the organization conduct internal audits at planned intervals to verify the QMS conforms to planned arrangements, ISO 13485 requirements, and applicable regulatory requirements? Is the audit program risk-based and does it cover all QMS processes within the defined audit cycle?
- Internal audit procedure defining audit planning, auditor qualification and independence, audit conduct, reporting, and follow-up requirements
- Internal audit schedule or program showing all QMS processes are covered within the defined cycle -- verify risk-based frequency and that no processes are excluded
- Completed internal audit reports from the past 12 months -- verify audits were conducted by qualified, independent auditors and findings were clearly documented
- Internal audit finding follow-up records -- verify findings were addressed with corrective actions and effectiveness was verified
- Internal audit program does not cover all QMS processes -- design controls, risk management, or regulatory affairs have not been audited within the defined audit cycle (Grade 2).
- Internal auditors audit their own areas of responsibility -- no evidence of independence between auditor and audited activity (Grade 2).
- Internal audit findings are documented but no corrective action follow-up is performed -- findings are recorded and then forgotten (Grade 2).
- Internal audit program does not address MDSAP jurisdiction-specific requirements -- audits cover ISO 13485 clauses but not FDA, Health Canada, ANVISA, PMDA, or TGA regulatory requirements (Grade 1).
Internal audits are the organization's self-assessment mechanism. If the internal audit program is weak, problems will go undetected. Verify the audit program is risk-based (higher-risk processes audited more frequently), covers all QMS processes, and that auditors are qualified and independent. A common gap is that internal audits focus on documentation compliance without assessing process effectiveness. Ask to see an internal audit report where the auditor identified a process effectiveness issue, not just a documentation gap. Cross-reference internal audit findings against your own audit findings -- significant gaps indicate the internal audit program is not effective.
Review the audit schedule for completeness. Read 2 internal audit reports. Verify at least 3 findings were followed up with corrective actions. Check auditor qualification records for at least 2 auditors.
- How do you determine the frequency and scope of internal audits?
- Can you show me an internal audit finding where the auditor identified a systemic process issue rather than a documentation gap?
- How do you qualify internal auditors and maintain their competency?
3.4 Does the organization monitor and measure processes and product to verify that requirements are met? Are monitoring results analyzed for trends and used as input to the CAPA system and management review?
- List of monitored processes with defined metrics, targets, and monitoring frequency -- verify critical processes (production, sterilization, complaint handling, CAPA) have measurable objectives
- Process monitoring data for at least 2 critical processes -- verify data is current, targets are defined, and out-of-specification results trigger investigation
- Product monitoring records (inspection, testing) showing product conforms to acceptance criteria -- verify records include the identity of the inspector and the acceptance criteria used
- Trend analysis reports showing process and product monitoring data analyzed over time -- verify adverse trends trigger investigation or CAPA
- Process monitoring metrics are defined but not analyzed for trends -- data is collected but never reviewed in aggregate to identify deteriorating performance (Grade 2).
- Product acceptance records do not identify the acceptance criteria used -- inspectors record 'pass' or 'fail' without documenting against which specification or drawing revision the product was inspected (Grade 2).
- Out-of-specification results are addressed individually but not trended -- recurring out-of-specification events for the same parameter are not identified as a pattern requiring CAPA (Grade 3).
Monitoring and measurement is where you verify the organization knows its processes are performing as intended. Look for defined metrics with targets, not just data collection. The most common gap is that data is collected but never analyzed for trends. Ask to see a trend chart for a critical process parameter and verify the organization has defined action limits (not just specification limits). Cross-reference monitoring results with CAPA records -- adverse trends should trigger CAPA.
Review process monitoring data for 2 critical processes. Verify trend analysis is performed. Check one product inspection record for completeness (acceptance criteria, inspector identity, instrument used).
- Can you show me a trend chart for a key process parameter? What are your action limits versus specification limits?
- When was the last time monitoring data triggered a CAPA or process investigation?
3.5 Does the organization have documented procedures for controlling nonconforming product at all stages -- incoming, in-process, finished, and returned? Are dispositions (accept, rework, reject, concession) documented with rationale, and are concessions authorized by the appropriate function?
- Nonconforming product control procedure covering identification, segregation, disposition, and documentation requirements for all product stages
- Nonconforming product records from the past 12 months -- sample at least 3, including at least one concession/use-as-is disposition
- For concession dispositions, verify approval authority is appropriate (not the same person who discovered the nonconformity) and rationale addresses impact on safety, performance, and regulatory compliance
- Records showing nonconforming product was segregated to prevent unintended use
- Nonconforming product is dispositioned as 'use-as-is' or 'accept with concession' without documented rationale assessing impact on device safety, performance, and regulatory compliance (Grade 3).
- No physical segregation of nonconforming product -- nonconforming material is stored alongside conforming material with only a label or tag to differentiate (Grade 2).
- Reworked product is released without re-inspection or re-testing against the original acceptance criteria (Grade 3).
- Concession dispositions are approved by quality staff without involvement of design engineering or regulatory affairs for devices with critical safety requirements (Grade 2).
Nonconforming product control is a direct patient safety concern. Focus on concession dispositions -- these are the highest risk because nonconforming product is being released to market with an accepted deviation. Verify the rationale is documented, technically sound, and approved by someone with the authority and competence to assess safety impact. FDA places significant emphasis on this area. Per MDSAP companion document QMS P0015, verify that nonconforming product disposition considers regulatory impact, not just product specification compliance. Cross-reference with Chapter 5 (Production) for in-process nonconformities and Chapter 7 for returned product.
Review 3 nonconforming product records. Verify at least one concession disposition has documented rationale and appropriate approval. Check segregation practices on the production floor. Verify reworked product was re-inspected.
- Show me a nonconforming product record where the disposition was 'use-as-is.' How was the safety and regulatory impact assessed?
- How do you track the cumulative effect of concessions on a product line over time?
3.6 Does the organization analyze data from quality system sources -- complaints, CAPA, audits, process monitoring, product quality, supplier performance -- to identify opportunities for improvement? Are analysis results documented and fed into management review?
- Data analysis procedure or practice defining sources, methods, frequency, and outputs
- Data analysis reports or dashboards covering at least complaints, CAPA, audit findings, process monitoring, and supplier performance -- verify reports are current (within past 6 months)
- Evidence that data analysis identified at least one trend or pattern that triggered a corrective or preventive action
- Management review records showing data analysis results were presented and discussed
- Data from different quality system sources is analyzed in isolation -- complaint trends, audit findings, and process monitoring data are never correlated to identify systemic issues (Grade 2).
- Data analysis consists of summary statistics (counts, averages) without trend analysis or statistical process control -- the organization cannot detect deteriorating performance before it becomes a nonconformity (Grade 1).
- Data analysis reports are produced but not reviewed by management or used as input to decision-making (Grade 1).
This task verifies the organization connects data from disparate sources to identify systemic patterns. The most mature organizations correlate complaint data with production data, CAPA with audit findings, and supplier performance with product quality. Ask for an example where data analysis led to a proactive improvement action. If the organization only uses data analysis reactively (after a problem occurs), the system is not functioning as intended by the standard.
Review the most recent data analysis output. Verify it covers all required sources. Check that at least one trend or pattern was identified and actioned. Confirm the analysis was presented at management review.
- Can you show me an example where data analysis from multiple sources identified a systemic issue that would not have been visible from any single source alone?
- What statistical tools or methods do you use for data analysis?
3.7 Are regulatory reporting requirements for each MDSAP jurisdiction documented and implemented? When a complaint or adverse event meets reportability criteria, is the report submitted to the applicable regulatory authority within the required timeframe?
- Reportability assessment procedure with jurisdiction-specific criteria -- FDA MDR (21 CFR 803), Health Canada Mandatory Problem Reporting (CMDR s.59--61), ANVISA Tecnovigilancia (RDC 67/2009), PMDA adverse event reporting (PMD Act Art. 68-10), TGA adverse event reporting (TG(MD)R Part 4 Div 2)
- Regulatory reporting timeline matrix showing required timeframes per jurisdiction and event type -- FDA 30-day/5-day, Health Canada 10-day/48-hour, ANVISA 72-hour/24-hour, PMDA 15-day/immediate, TGA 10-day/48-hour
- Records of regulatory reports submitted in the past 24 months -- verify reports were submitted within required timeframes
- Records of events evaluated and determined not reportable -- verify rationale is documented per jurisdiction
- Reports were submitted to FDA but not to other applicable jurisdictions -- the organization reported to its primary regulatory authority but did not assess reportability for Health Canada, ANVISA, PMDA, or TGA (Grade 4 -- direct regulatory impact).
- Reports were submitted but outside the required timeframe -- jurisdiction-specific timelines were not met (Grade 3).
- Reportability assessment criteria are generic and do not account for differences between jurisdictions -- the same threshold is applied regardless of the jurisdiction's specific definition of a reportable event (Grade 3).
- No records exist for events determined not reportable -- the organization cannot demonstrate it performed a reportability assessment (Grade 2).
This is one of the highest-risk tasks in the MDSAP audit because late or missed reporting is a Grade 4--5 nonconformity that can trigger a 5-Day Notice. Each jurisdiction has different reportability criteria and timelines. FDA uses 'death or serious injury' and 'malfunction that could cause death or serious injury.' Health Canada uses 'incident' with a broader definition. ANVISA, PMDA, and TGA each have their own definitions. Verify the organization has a jurisdiction-by-jurisdiction decision matrix and can demonstrate compliance for each report submitted. Cross-reference with Chapter 7 for detailed adverse event review.
Review 3 regulatory reports and verify submission timeliness. Review 2 events determined not reportable and verify rationale per jurisdiction. Cross-reference complaint records from Task 3.1 with reporting records.
- Walk me through a recent reportability decision. How did you determine which jurisdictions required a report?
- Can you show me an event that was reportable in one jurisdiction but not another, and explain the difference?
3.8 Has the organization established processes for collecting and analyzing post-market surveillance data? Is post-market surveillance planned, documented, and proportionate to the risk class of each device?
- Post-market surveillance plan for at least one device -- verify it defines data sources, collection methods, analysis frequency, and actions based on findings
- Post-market surveillance data and analysis records -- verify data collection is active, not just planned
- Evidence that post-market surveillance findings feed into risk management, CAPA, and design processes
- Records showing post-market surveillance data was reported to applicable regulatory authorities where required (periodic safety reports, PSUR equivalents)
- No post-market surveillance plan exists -- the organization relies on complaint handling as its only source of post-market information without proactive data collection (Grade 2).
- Post-market surveillance plan exists but is generic across all devices regardless of risk class -- no risk-proportionate approach to data collection and analysis frequency (Grade 1).
- Post-market surveillance data is collected but not analyzed or fed back into the risk management file -- the process is disconnected from the rest of the QMS (Grade 2).
Post-market surveillance is increasingly emphasized by all MDSAP jurisdictions. The plan must be proportionate to device risk -- higher-risk devices require more active and frequent surveillance. Verify the organization collects data from multiple sources (complaints, literature, registries, clinical follow-up, competitive intelligence) rather than relying solely on complaints. PMDA and Health Canada have specific post-market surveillance reporting requirements. Cross-reference with risk management (Task 1.4) and CAPA (Task 3.2).
Review the post-market surveillance plan for the highest-risk device. Verify data was collected and analyzed within the defined timeframe. Check that at least one finding was routed to risk management or CAPA.
- Beyond complaints, what other data sources do you use for post-market surveillance?
- How do post-market surveillance findings trigger updates to your risk management files?
3.9 Has the organization validated computer software used in the QMS, including quality system software (e.g., EQMS, complaint databases, ERP modules for quality) and software used in production and inspection? Is revalidation performed when software changes?
- Software validation procedure covering scope (which software requires validation), validation approach (IQ/OQ/PQ or equivalent), roles, and revalidation triggers
- Inventory of software used in the QMS with validation status -- verify critical software (complaint database, CAPA system, document management, production control, inspection systems) is validated
- Validation records for at least one critical QMS software system -- verify validation included requirements definition, test protocols, test results, and approval
- Revalidation records for software that has been updated or upgraded -- verify revalidation was performed within a defined timeframe after the change
- No inventory of QMS-related software exists -- the organization cannot identify which software systems require validation (Grade 2).
- Excel spreadsheets used for critical calculations (acceptance criteria, statistical analysis, label generation) are not validated -- the organization does not consider spreadsheets as software requiring validation (Grade 3).
- Software was validated at initial installation but has undergone multiple updates without revalidation -- current software version does not match the validated version (Grade 2).
- Validation records consist only of 'installation verified' without functional testing, edge case testing, or data integrity verification (Grade 2).
Software validation is a perennial finding area. ISO 13485 clause 4.1.6 and FDA 21 CFR 820.70(i) require validation of computer software used in the QMS. The most commonly missed items are Excel spreadsheets, Access databases, and software used in measuring and test equipment. Ask the organization to show you their software inventory and then walk the production floor -- you will almost always find software in use that is not on the inventory. Revalidation after updates is also frequently missed, especially for cloud-based QMS systems that update automatically.
Review the software inventory. Walk the production floor and identify software not on the inventory. Review validation records for one critical system. Verify revalidation was performed after the most recent update.
- How do you determine which software systems require validation?
- Are there any Excel spreadsheets or databases used for quality-critical calculations? Are they validated?
- How do you manage revalidation when your cloud-based QMS software provider releases an update?
§chapter.4 Medical device adverse events and advisory notices
4.1 Does the organization have a documented process for identifying potential adverse events from all information sources, including complaints, service records, returned product, literature, post-market surveillance, and third-party reports? Does the process ensure no potential adverse event goes unevaluated?
- Adverse event identification procedure listing all information sources that must be monitored -- complaints, service reports, returned product analysis, literature, registries, social media, distributor reports, clinical studies
- Evidence that each information source is actively monitored -- not just documented, but demonstrate actual monitoring activities with records
- Records showing potential adverse events identified from sources other than direct complaints -- at least one example from literature, post-market surveillance, or service data
- Cross-referencing between complaint records and adverse event evaluation records -- verify no complaints that could involve harm were excluded from adverse event evaluation
- Adverse event identification relies solely on the complaint handling process -- service reports, returned product analysis, and literature monitoring are not evaluated for potential adverse events (Grade 3).
- Distributor and sales force reports are not systematically captured and evaluated for adverse event information -- the organization has no mechanism to collect safety information from the distribution channel (Grade 3).
- Literature monitoring for adverse events is not performed, or is performed for clinical literature only without monitoring regulatory authority databases, recall databases, or competitor field actions for similar devices (Grade 2).
Adverse event identification must cast a wide net. The most common gap is relying solely on formal complaints. Service records, field actions by competitors with similar devices, and post-market surveillance data can all identify potential adverse events. Verify the organization monitors regulatory authority databases (FDA MAUDE, Health Canada recall database, etc.) for events involving similar devices from other manufacturers. Each jurisdiction has a different definition of what constitutes an adverse event -- verify the organization applies the broadest applicable definition when screening sources.
Review the adverse event identification procedure. Verify at least 3 information sources are actively monitored with records. Cross-reference 5 complaint records against adverse event evaluation records to verify none were missed.
- Show me an example of an adverse event that was identified from a source other than a customer complaint.
- Do you monitor regulatory databases for events involving similar devices from other manufacturers?
- How do you ensure service records and returned product data are evaluated for potential adverse events?
4.2 Does the organization have a documented reportability determination process with jurisdiction-specific criteria? Are reportability decisions made by qualified personnel within timeframes that allow timely regulatory reporting?
- Reportability determination procedure with decision criteria for each MDSAP jurisdiction -- verify criteria match current regulatory requirements (not outdated references)
- Decision flowcharts or matrices showing how events are assessed against each jurisdiction's reportability criteria
- Records of reportability determinations for at least 5 events -- verify qualified personnel made the determination, rationale is documented, and the determination was made within the required timeframe
- Training records showing personnel involved in reportability determination are trained on jurisdiction-specific criteria and updated when requirements change
- Reportability criteria reference outdated regulatory requirements -- FDA MDR criteria reference superseded guidance or Health Canada criteria do not reflect current CMDR amendments (Grade 3).
- Reportability determinations are made by personnel without training on jurisdiction-specific criteria -- a single person makes all determinations using only FDA criteria regardless of the jurisdiction (Grade 3).
- Time from event awareness to reportability determination exceeds the reporting window for at least one jurisdiction -- the determination process itself consumes the available reporting time (Grade 4).
The reportability determination is the most critical step in adverse event management. Each jurisdiction has different criteria. FDA uses 'death, serious injury, or malfunction that could cause either.' Health Canada uses a broader 'incident' definition. ANVISA, PMDA, and TGA each have their own definitions. The organization must evaluate each event against all applicable jurisdictions independently. A common finding is applying only FDA criteria to all jurisdictions. Verify determinations are documented with rationale per jurisdiction, not just a single yes/no determination.
Review 5 reportability determinations. Verify each addresses all applicable jurisdictions independently. Check the elapsed time from event awareness to determination. Verify at least one 'not reportable' determination has documented rationale per jurisdiction.
- Walk me through a recent reportability determination. How did you apply each jurisdiction's criteria independently?
- What happens if your regulatory affairs staff disagree on reportability? Is there an escalation process?
4.3 When events are determined reportable, are reports prepared and submitted to the applicable regulatory authority within the required timeframes? Does the organization track reporting deadlines per jurisdiction and event type?
- Regulatory reporting timeline matrix per jurisdiction and event severity -- FDA 5-day/30-day, Health Canada 10-day/48-hour, ANVISA 72-hour/24-hour, PMDA 15-day/immediate, TGA 10-day/48-hour
- Report submission records for events reported in the past 24 months -- verify each report was submitted within the required timeframe per jurisdiction
- Tracking system showing reporting deadlines, submission dates, and follow-up report due dates
- Copies of submitted reports or submission confirmations from each regulatory authority
- Adverse event reports were submitted to FDA within the required 30 days but not to Health Canada within the required 10 days, or not to ANVISA within 72 hours -- the organization applied the longest deadline to all jurisdictions (Grade 4).
- Follow-up reports required by the regulatory authority were not submitted or were submitted late (Grade 3).
- No tracking system for reporting deadlines -- the organization relies on individual regulatory affairs staff to remember deadlines without systematic tracking (Grade 2).
This is a Grade 4/5 nonconformity area. Late reporting or failure to report is one of the fastest paths to a 5-Day Notice in an MDSAP audit. Verify every report submitted in the past 24 months was within the applicable timeline for each jurisdiction. Pay particular attention to multi-jurisdiction events where different jurisdictions have different timelines -- the organization must meet the earliest deadline. Also verify follow-up report obligations are tracked and met. If the organization has never reported an adverse event, verify this is reasonable given their device risk profile and complaint volume -- zero reports from a manufacturer of Class III devices with a high complaint volume is a red flag.
Review all adverse event reports from the past 24 months. Calculate elapsed time from event awareness to report submission for each. Verify compliance with each jurisdiction's timeline. Check follow-up report status.
- How do you track reporting deadlines when an event is reportable in multiple jurisdictions with different timelines?
- Have you ever submitted a report late? If so, what corrective action did you take?
4.4 Does the organization have documented procedures for initiating and managing recalls, advisory notices, and field safety corrective actions? Are procedures aligned with the requirements of each applicable jurisdiction?
- Recall and advisory notice procedure covering initiation criteria, risk assessment, scope determination, notification content, effectiveness checks, and regulatory authority notification requirements per jurisdiction
- Recall or advisory notice records from the past 3 years -- verify regulatory notifications were submitted to all applicable jurisdictions within required timeframes
- If no recalls have occurred, review the recall procedure for adequacy and verify recall readiness through a mock recall exercise record
- Recall effectiveness check records -- verify the organization assessed whether the recall achieved its intended objective
- Recall procedure does not address jurisdiction-specific notification requirements -- some jurisdictions require pre-notification before initiating a recall, while others require notification within a defined timeframe (Grade 3).
- A field corrective action was performed as a voluntary quality improvement without recognizing it met the regulatory definition of a recall -- the action was not reported to regulatory authorities (Grade 4).
- No evidence of recall readiness -- no mock recall exercises, no recall team identified, no communication templates prepared, and recall procedure has never been tested (Grade 2).
- Recall effectiveness was not assessed -- the organization performed a recall but did not measure the percentage of product returned or corrected (Grade 2).
Recalls and field safety corrective actions are high-regulatory-risk activities. Each jurisdiction has different definitions of what constitutes a recall and different notification requirements. FDA has specific recall classification (Class I, II, III) and effectiveness check requirements. Health Canada requires recall reports and may require a public advisory. ANVISA, PMDA, and TGA each have their own processes. If the organization has not had a recall, verify recall readiness through mock recall records and procedure adequacy. A common finding is that organizations perform field corrections without recognizing them as recalls under the regulatory definition.
If recalls have occurred, review at least one recall record end-to-end. If not, review the procedure and mock recall exercise records. Verify regulatory notification compliance for each jurisdiction.
- When was your last recall or field safety corrective action? Walk me through the process from decision to effectiveness check.
- If you have never had a recall, when was your last mock recall exercise? What did you learn from it?
- How do you determine whether a voluntary field action meets the regulatory definition of a recall?
4.5 Does the organization investigate adverse events with a depth proportionate to the severity and risk? Are investigation records complete, including root cause analysis, device evaluation, and corrective action determination?
- Adverse event investigation procedure defining investigation depth based on event severity, required investigation elements, and timelines
- Investigation records for at least 3 adverse events -- verify investigations include device examination (where possible), failure analysis, root cause determination, and corrective action assessment
- Evidence that investigation findings feed back into risk management files, CAPA, and design processes
- Records showing trends in adverse events are analyzed and systemic corrective actions are taken when patterns emerge
- Adverse event investigations are superficial -- records show the complaint was reviewed and a report was filed, but no technical investigation (device examination, failure analysis, process review) was performed (Grade 3).
- Investigation timelines are not defined or not adhered to -- some investigations remain open for extended periods without explanation or interim regulatory notification (Grade 2).
- Investigation findings do not feed back into the risk management file -- new hazards or hazardous situations identified through adverse event investigation are not incorporated into the risk analysis (Grade 3).
Investigation depth should be proportionate to risk. A death or serious injury requires thorough root cause analysis, device examination, and process review. A malfunction with no patient harm may require less extensive investigation. Verify the organization has defined criteria for investigation depth. The most common gap is investigations that consist of re-reading the complaint letter without any technical analysis. Also verify that investigation findings update the risk management file -- this closes the loop between post-market experience and pre-market risk assessment.
Review 3 adverse event investigation records with varying severity levels. Verify investigation depth is proportionate. Check that at least one investigation resulted in a risk management file update or CAPA initiation.
- How do you determine the appropriate depth of investigation for an adverse event?
- Can you show me an adverse event investigation that resulted in a change to a risk management file?
4.6 Does the organization trend adverse event and complaint data to identify emerging safety signals? Are trend reports submitted to regulatory authorities where required?
- Adverse event trending procedure defining data sources, analysis methods, signal detection criteria, and reporting triggers
- Trend analysis reports showing adverse event and complaint data analyzed over time by device, event type, severity, and root cause category
- Records of any trend reports submitted to regulatory authorities -- FDA requires MDR trend reporting under certain conditions, other jurisdictions have periodic safety reporting requirements
- Evidence that trend analysis results are reviewed in management review and fed into post-market surveillance and risk management processes
- No systematic trending of adverse events -- individual events are investigated but cumulative data is not analyzed for emerging patterns or safety signals (Grade 2).
- Trend analysis frequency is insufficient for the complaint volume -- high-volume devices require more frequent trending than quarterly (Grade 1).
- Trend reports identify increasing event rates but no action is taken -- the trend is documented but not evaluated for regulatory reporting obligations or risk management impact (Grade 3).
Trending is the bridge between individual event management and systemic safety surveillance. FDA may require MDR trend reporting if the manufacturer identifies a meaningful increase in event frequency. Health Canada and other jurisdictions have periodic safety update reporting requirements. Verify the organization has defined signal detection criteria -- how many events of the same type, in what timeframe, before it is considered a signal? Cross-reference with post-market surveillance (Task 3.8) and data analysis (Task 3.6).
Review the most recent adverse event trend analysis. Verify signal detection criteria are defined. Check that trend results were presented at management review and any required trend reports were submitted to regulatory authorities.
- How do you define a safety signal in your adverse event data?
- Can you show me a trend analysis that identified an emerging pattern and what action was taken?
§chapter.5 Design and development
5.1 Has the organization established and documented design and development plans for each design project? Do plans define stages, activities, responsibilities, review points, and resource needs? Are plans updated as the design evolves?
- Design and development procedure defining the organization's standard design control process -- stages, gate reviews, deliverables, and approval requirements at each stage
- Design plan for a current or recent design project -- verify it defines scope, stages, activities, responsibilities, design review schedule, and interfaces with other functions (regulatory, manufacturing, quality, risk management)
- Evidence that the design plan was updated during the project -- verify at least one plan revision reflecting a scope change, schedule change, or new information discovered during design
- Records showing resources were allocated as defined in the plan -- personnel, equipment, test facilities
- Design plan is a static document created at project initiation and never updated -- actual design activities deviated significantly from the plan without documented rationale (Grade 2).
- Design plan does not define design review stages or review responsibilities -- reviews occurred ad hoc without a planned schedule (Grade 2).
- No design plan exists for a design project that resulted in a marketed device -- the organization performed design activities without the planning required by ISO 13485 clause 7.3.2 (Grade 3).
Select the most recent completed design project or an ongoing project. The design plan is the roadmap -- verify it was a living document that evolved with the project. A common failure is a plan that was created to satisfy the requirement but never used to manage the project. Ask the design team leader to walk through the plan and show where it was updated during the project. Cross-reference the plan stages with actual design review records. If the organization claims a design control exclusion, verify the exclusion is justified per ISO 13485 clause 4.2.2.
Select one design project. Review the design plan, verify at least one plan update, and cross-reference plan stages against design review records. If the organization excludes design controls, verify the justification.
- Can you walk me through how the design plan was updated during this project?
- How do you determine which design projects require formal design controls versus informal development processes?
5.2 Are design inputs documented, reviewed, and approved? Do they include functional and performance requirements, safety requirements, applicable regulatory requirements, risk management outputs, and user needs? Are design inputs complete, unambiguous, and verifiable?
- Design input document or requirements specification for the selected design project -- verify it includes all required input categories (functional, performance, safety, regulatory, risk, human factors, usability, biocompatibility where applicable)
- Approval records showing design inputs were formally reviewed and approved before design activities commenced
- Traceability matrix linking each design input to its source (user need, regulatory requirement, risk analysis output, standard requirement)
- Evidence that design inputs were evaluated for completeness, non-contradiction, and verifiability -- records of design input review meeting or checklist
- Design inputs do not include applicable regulatory requirements for all jurisdictions where the device will be marketed -- inputs reference FDA requirements but omit Health Canada, ANVISA, PMDA, or TGA-specific requirements (Grade 2).
- Design inputs are not traceable to user needs or intended use -- requirements exist but the organization cannot demonstrate why each requirement was defined (Grade 2).
- Design inputs include subjective requirements ('easy to use,' 'lightweight') that are not verifiable against measurable acceptance criteria (Grade 1).
- Risk management outputs are not included as design inputs -- the risk analysis identifies hazards and required risk controls, but these are not captured in the design input specification (Grade 3).
Design inputs are the foundation of design controls. If inputs are incomplete, everything downstream (outputs, verification, validation) is compromised. Focus on three areas: (1) Are risk management outputs included as design inputs? (2) Are regulatory requirements for all applicable jurisdictions included? (3) Can every design input be verified with a measurable acceptance criterion? The traceability matrix is the key document -- if it does not exist or has gaps, design controls are incomplete. FDA places particular emphasis on design input documentation and often cites 820.30(c) as a 483 observation.
Review the design input specification for the selected project. Verify completeness against the required input categories. Check the traceability matrix for at least 5 design inputs -- verify each has a source and a verification method.
- How do you ensure risk management outputs are captured as design inputs?
- Can you show me the traceability matrix and demonstrate that every design input has a corresponding verification activity?
- How were regulatory requirements for each target jurisdiction incorporated into design inputs?
5.3 Are design outputs documented in a form that allows verification against design inputs? Do they include or reference acceptance criteria, essential performance characteristics, and information needed for production, servicing, and installation?
- Design output documentation for the selected project -- specifications, drawings, software requirements, manufacturing instructions, labeling artwork -- verify they are in a form that allows comparison against design inputs
- Evidence that each design output can be traced to a design input and that the output satisfies the input requirement
- Verification that design outputs include essential safety and performance characteristics identified in the risk analysis
- Evidence that design outputs include information needed for production (manufacturing specifications, process parameters) and purchasing (component specifications)
- Design outputs do not reference acceptance criteria -- drawings and specifications define nominal dimensions or performance values but do not include tolerances or acceptance ranges needed for verification (Grade 2).
- No traceability between design outputs and design inputs -- the output documents exist but cannot be mapped to specific input requirements (Grade 2).
- Design outputs do not include essential performance characteristics identified in the risk analysis as requiring post-market monitoring (Grade 3).
- Design outputs are incomplete for design transfer -- manufacturing instructions reference 'see engineering team' for critical process parameters instead of documented, controlled specifications (Grade 3).
Design outputs are the deliverables of the design process. Verify they are in a controlled, approved form (not draft documents or engineer's notes). The critical test is traceability: can each design input be traced to a design output, and vice versa? Gaps in traceability indicate either missing inputs or incomplete design outputs. Focus on essential performance characteristics -- these must be identified in outputs because they drive post-market monitoring. Cross-reference design outputs with production documentation in Chapter 5 to verify design transfer completeness.
For the selected project, trace 5 design inputs to their corresponding design outputs. Verify acceptance criteria are defined. Check that essential performance characteristics from the risk analysis are included in design outputs.
- Can you show me how a specific design input requirement was addressed in the design output documentation?
- How do you ensure design outputs include all information needed for manufacturing without requiring informal knowledge from the design team?
5.4 Were design reviews conducted at suitable stages as defined in the design plan? Did reviews include representatives of all functions concerned with the design stage under review, plus independent reviewers? Are review records complete?
- Design review records for each planned review stage -- verify attendees, topics discussed, issues identified, and actions assigned
- Attendee lists showing participation of all required functions -- at minimum, design engineering, quality, regulatory, manufacturing, and risk management, plus at least one independent reviewer not directly involved in the design
- Action item tracking showing design review actions were completed and verified before proceeding to the next stage
- Evidence that design review considered risk management status, regulatory compliance, and manufacturing feasibility -- not just design engineering topics
- Design reviews were conducted but attendee records show only design engineering participants -- no representation from quality, regulatory, manufacturing, or independent reviewers (Grade 2).
- Design review action items were assigned but not tracked to closure -- the review identified issues but the design proceeded without verifying resolution (Grade 3).
- Design reviews were not conducted at all planned stages -- one or more stages were skipped or combined without documented justification (Grade 2).
Design reviews are governance checkpoints, not technical discussions between engineers. Verify that cross-functional representation occurred at each review and that an independent reviewer (someone not on the design team) participated. The most common gap is reviews that are engineer-only meetings without quality, regulatory, or manufacturing input. Action items from design reviews must be tracked and closed before the gate is passed. Cross-reference the design plan review schedule against actual review records to verify all planned reviews occurred.
Review design review records for at least 2 stages. Verify cross-functional attendance and independent reviewer participation. Track at least 3 action items to closure.
- How do you ensure independent review at each design review stage?
- Can you show me a design review action item that was tracked to closure before the design proceeded?
5.5 Was design verification performed to confirm that design outputs meet design input requirements? Were verification activities planned, documented with pass/fail criteria, and conducted using appropriate methods (inspection, test, analysis, comparison)?
- Verification plan or protocol defining verification activities, methods, acceptance criteria, and responsible personnel for each design input requirement
- Verification test records or reports showing test results against acceptance criteria -- verify traceability to specific design input requirements
- Evidence that verification was completed before design validation or design transfer -- verify sequence
- Records of any verification failures, the disposition of failures, and retesting after design modifications
- Design verification does not cover all design inputs -- a traceability gap exists where some requirements have no corresponding verification activity (Grade 3).
- Verification acceptance criteria are not defined before testing -- pass/fail criteria were determined after the test results were known, making the verification biased (Grade 3).
- Verification testing was performed using uncalibrated instruments or unvalidated test methods -- the verification results are not reliable (Grade 3).
- Verification failures were not documented -- design changes were made and retesting occurred, but the failed results and failure analysis were not recorded (Grade 2).
Verification answers the question 'did we build the device right?' Every design input must have a corresponding verification activity with pre-defined acceptance criteria. The traceability matrix should show complete coverage -- no input without a verification method. Common gaps: software requirements not verified, biocompatibility requirements verified only by reference to material data sheets without testing, and electrical safety requirements verified only against a subset of applicable test clauses. Verify that acceptance criteria were defined before testing, not reverse-engineered from results.
For the selected project, verify the verification plan covers all design inputs. Review verification test records for at least 5 requirements. Check calibration records for instruments used in verification. Verify any failures were documented with retesting.
- Can you show me the traceability from a design input through verification to the test result?
- Were any verification tests failed? If so, show me the failure record and the subsequent design change and retest.
5.6 Was design validation performed under defined conditions, including simulated or actual conditions of use, to confirm the device meets user needs and intended use? Was validation performed on representative production units, not prototype or bench-top samples?
- Validation plan or protocol defining validation activities, user scenarios, acceptance criteria, and the rationale for any simulated (versus actual) use conditions
- Evidence that validation was performed on production-representative units (or justified rationale for using non-production units)
- Validation test records or reports showing results against acceptance criteria -- verify testing addressed intended use, user needs, and applicable clinical requirements
- Software validation records where the device includes software -- verify software validation followed IEC 62304 and included testing of intended use scenarios
- Design validation was performed on prototype units that differ from production units in material, manufacturing process, or configuration -- validation results may not be representative of the marketed device (Grade 3).
- Validation did not include testing under the conditions of actual or simulated use -- bench testing was performed but no human factors or usability testing was conducted for a user-operated device (Grade 3).
- Clinical evaluation or clinical data supporting validation is insufficient -- the organization references published literature for a predicate device without establishing equivalence (Grade 3).
- Software validation was not performed or was limited to unit testing without system-level validation of intended use scenarios (Grade 3).
Validation answers 'did we build the right device?' It must demonstrate the device meets user needs under conditions of actual or simulated use. Key verification: (1) Units used for validation were production-representative. (2) Use conditions in the validation protocol match the intended use in the labeling. (3) Human factors/usability was addressed for user-operated devices. (4) Clinical evidence is adequate for the device risk class and intended use claims. FDA places heavy emphasis on validation and frequently cites 820.30(g). Cross-reference with risk management to verify risk controls were validated.
Review the validation plan and protocol. Verify units used were production-representative. Check that use conditions match intended use. Review at least 3 validation test results. Verify clinical evidence adequacy for at least one intended use claim.
- How did you determine the validation units were representative of production?
- Was any human factors or usability testing included in design validation? Why or why not?
- How does your clinical evidence support the intended use claims in your labeling?
5.7 Was design transfer executed in a controlled manner, ensuring all design outputs, manufacturing specifications, and process parameters were formally transferred to production? Were design transfer activities planned and verified?
- Design transfer plan or procedure defining what is transferred, who receives it, and how completeness is verified
- Design transfer records showing each design output (specifications, drawings, procedures, test methods) was formally transferred to production documentation
- Verification records confirming production can consistently produce the device to specification using transferred documentation -- process validation results, initial production runs, first article inspections
- Evidence that production personnel were trained on transferred documentation before production commenced
- Design transfer was not formally executed -- production uses engineering drawings and documents that were never formally controlled or approved as production documentation (Grade 3).
- Not all design outputs were transferred -- critical process parameters remain as informal knowledge within the design team and are not documented in production procedures (Grade 3).
- Production training was not completed before the start of production -- operators received on-the-job training after production had already begun (Grade 2).
Design transfer is where design outputs become production documentation. The most common failure is informal transfer where engineers verbally communicate critical parameters to production. Verify that production documents are formally issued, revision-controlled, and traceable to approved design outputs. Check for 'tribal knowledge' -- ask a production operator if there are any process steps or parameters that are not in the written procedure. Cross-reference with Chapter 5 (Production Controls) to verify production documentation matches design outputs.
For the selected project, compare at least 3 design output documents against corresponding production documents. Verify they match. Check training records for production personnel. Review first article inspection or initial production run results.
- How do you verify that all design outputs were successfully transferred to production?
- Are there any process parameters or assembly steps that production knows through experience but are not in the documented procedures?
5.8 Are design changes identified, documented, reviewed, verified, validated (where appropriate), and approved before implementation? Does the change process assess the impact of changes on existing marketed devices, including regulatory notification requirements?
- Design change procedure defining how changes are initiated, evaluated, approved, implemented, and documented
- Design change records for at least 2 changes -- verify each includes impact assessment, verification and validation (where needed), regulatory notification assessment per jurisdiction, and approval before implementation
- Evidence that the change impact assessment covers previously validated devices, marketed product, and labeling -- not just the component being changed
- Records showing regulatory notification assessment was performed for design changes -- did the change require a new 510(k), Health Canada Significant Change, ANVISA change notification, PMDA partial change, or TGA change notification?
- Design changes were implemented in production before completing verification and validation -- the change order shows implementation date before verification completion date (Grade 3).
- Impact assessment for design changes does not address regulatory notification requirements -- the organization changed a critical component without assessing whether a new regulatory submission was required in any jurisdiction (Grade 3).
- Design change verification is limited to testing the changed element without assessing system-level impact -- a material change was verified for biocompatibility but its effect on device performance, sterilization, and shelf life was not evaluated (Grade 3).
- Design change records are incomplete -- some changes were implemented through informal engineering updates without formal change documentation (Grade 3).
Design changes are a high-risk area because incomplete change assessment can result in unanticipated impacts on device safety and performance. Every change must be assessed for impact on existing designs, currently manufactured product, and regulatory status. The most common gap is implementing a change without assessing whether it triggers a regulatory notification in any of the five MDSAP jurisdictions. Cross-reference with Chapter 2 (Marketing Authorization) to verify regulatory notification compliance for design changes. Ask for a design change that required regulatory notification and verify it was submitted.
Review 2 design change records. Verify impact assessment, verification/validation records, regulatory notification assessment, and approval before implementation. Cross-reference with Chapter 2 regulatory submissions.
- Can you show me a recent design change and walk through the impact assessment?
- How do you determine whether a design change requires regulatory notification in each jurisdiction?
- Have you ever implemented a design change and later discovered it required a regulatory submission you did not make?
5.9 Does the organization maintain a design history file or technical file for each device type that provides a complete record of the design and development process? Is the file accessible, current, and complete?
- Design history file (DHF) or technical file for the selected device -- verify it contains or references all required design control records (plan, inputs, outputs, reviews, verification, validation, transfer, changes)
- DHF index or table of contents showing the file is organized and complete -- cross-reference against the design plan to verify all planned deliverables are present
- Evidence that the DHF is maintained as a living document -- verify recent design changes are reflected in the file, not just the original design records
- Accessibility verification -- the file can be located, retrieved, and presented within a reasonable timeframe (not scattered across multiple unlinked locations)
- Design history file is incomplete -- design review records, verification test reports, or risk management file references are missing from the DHF (Grade 2).
- DHF has not been updated to reflect design changes made after initial market release -- the file documents the original design but not the current marketed configuration (Grade 2).
- DHF content is scattered across multiple locations (network drives, physical binders, different electronic systems) with no unified index or table of contents -- the complete design history cannot be efficiently reviewed (Grade 1).
The DHF tells the complete story of the design. Verify it is organized, complete, and current. A common gap is a DHF that documents the original design but was never updated as the device evolved through design changes. Compare the DHF table of contents against the design plan deliverables to identify missing records. If the organization uses electronic systems for design records, verify the file structure allows efficient retrieval -- scattered records across multiple systems without a unified index are equivalent to a disorganized physical file. FDA expects the DHF to be readily retrievable during inspections.
Review the DHF for the selected device. Verify completeness against the design plan. Check that at least one post-market design change is reflected in the file. Verify the file can be retrieved and navigated within 10 minutes.
- Can you show me the DHF for your most recently designed device and walk through its organization?
- Is the DHF updated when design changes are made to a marketed device, or does it only document the original design?
§chapter.6 Production and service controls
6.1 Is production carried out under controlled conditions including documented procedures, suitable equipment, defined process parameters, and monitoring at specified stages? Are work instructions available at the point of use?
- Manufacturing procedures or work instructions for at least 2 production processes -- verify they define process parameters, equipment settings, in-process controls, and acceptance criteria
- Production floor observation -- verify operators follow documented procedures, equipment is identified and maintained, and work instructions are accessible at the workstation
- Production records (batch records, device history records) for at least 2 recent production runs -- verify process parameters were recorded and compared against defined limits
- Equipment qualification records (IQ/OQ/PQ) for at least one critical production machine
- Work instructions at the production station are an outdated revision -- operators are following a superseded procedure while the current revision is available only in the document management system (Grade 3).
- Process parameters are not defined in the work instruction -- operators set equipment parameters based on experience rather than documented specifications (Grade 3).
- In-process monitoring or inspection is not performed at the stages required by the device history record template -- operators skip monitoring steps that are defined but not enforced (Grade 3).
- Production equipment is not identified with a calibration or maintenance status -- the organization cannot demonstrate the equipment was in a qualified state during production (Grade 2).
This task requires production floor observation. Walk the production line and compare what you observe against what the procedures specify. Look for: (1) Work instruction revision matches master document list. (2) Operators actually refer to work instructions (not just have them nearby). (3) Process parameters displayed on equipment match the documented ranges. (4) In-process checks are being performed and recorded. The most common finding is a mismatch between documented procedures and actual practice. Per FDA 21 CFR 820.70, production must be controlled by documented procedures.
Observe at least 2 production operations. Compare observed practice against documented procedures. Review batch records for at least 2 recent production runs. Check calibration status of at least one critical production machine.
- Can you show me the work instruction for this operation and verify it matches what the operator is doing?
- How do you ensure operators are aware when a procedure revision is issued?
6.2 Are processes whose output cannot be fully verified by subsequent monitoring or measurement (special processes) validated? Is validation documented with defined protocols, acceptance criteria, and revalidation triggers?
- List of validated processes (sterilization, welding, sealing, soldering, software, cleaning, surface treatment) with validation status and revalidation dates
- Validation protocol and report for at least one validated process -- verify IQ, OQ, PQ were performed with pre-defined acceptance criteria
- Evidence that process parameters established during validation are maintained in production -- compare validated parameters against current production settings
- Revalidation records -- verify revalidation was performed when required triggers occurred (equipment change, material change, process change, prolonged downtime)
- A special process is performed in production but has not been validated -- the organization relies on final product testing to verify the process output, which by definition cannot fully verify a special process (Grade 4).
- Process validation was performed but the validated parameters do not match current production parameters -- the process was changed after validation without revalidation (Grade 3).
- Revalidation triggers are not defined -- the organization has no criteria for when revalidation is required after changes to equipment, materials, or process parameters (Grade 2).
- Validation was performed on equipment that has since been replaced -- the new equipment was not qualified or validated (Grade 3).
Process validation is a critical area, especially for sterilization, sealing, welding, and software processes. The key question is: if I cannot verify the output of this process through subsequent testing, has it been validated? Common gaps: heat sealing of packaging validated but revalidation not performed after changing the sealing machine; cleaning processes not validated; software manufacturing processes not validated. Verify validation was performed on the actual production equipment using production materials, not engineering prototypes on test equipment. Cross-reference with Chapter 5 to verify design transfer of validated process parameters.
Review the validated process list. Select one process and review the validation protocol, report, and current production parameters. Verify parameters match. Check for revalidation triggers and recent revalidation records.
- How do you identify which processes are special processes requiring validation?
- Can you show me the revalidation criteria for your most critical validated process?
- What was the last trigger that caused a process revalidation?
6.3 Is device identification and traceability maintained throughout production, distribution, and post-market? Can the organization trace a finished device back to the components, materials, and production records used in its manufacture?
- Identification and traceability procedure defining how devices are identified at each production stage and how traceability is maintained from raw materials through distribution
- Traceability records for at least one finished device -- trace from finished device (lot/serial number) back to raw material lot numbers, production records, inspection records, and sterilization records
- Forward traceability records -- given a raw material lot number, can the organization identify all finished devices that contain it?
- UDI compliance records -- verify devices subject to UDI requirements have compliant identifiers per applicable jurisdiction timelines
- Traceability cannot be demonstrated from finished device to component lot numbers -- the batch record does not capture all component lot numbers used during production (Grade 3).
- Forward traceability is not possible -- given a component recall, the organization cannot identify which finished devices contain the affected component (Grade 4 -- direct patient safety impact).
- Implantable devices do not have unit-level traceability -- lot-level traceability is maintained but individual device serial numbers are not linked to specific component lots (Grade 3 for implantables).
- UDI requirements have not been implemented for devices subject to current UDI compliance deadlines (Grade 3).
Traceability is a patient safety requirement. The acid test is a simulated recall scenario: pick a component lot number and ask the organization to identify all finished devices containing that component and where they were distributed. If they cannot do this efficiently, the traceability system is inadequate. For implantable devices, traceability must be at the unit level (not just lot level). Verify UDI compliance for devices subject to current jurisdiction-specific implementation timelines. Cross-reference with Chapter 6 (Purchasing) for incoming component identification.
Select one finished device lot. Trace backward to component lots, production records, and inspection records. Select one component lot and trace forward to all finished devices containing it. Verify UDI compliance for at least one device.
- If a component supplier notified you of a defective lot, how quickly could you identify all affected finished devices and their distribution?
- Show me the traceability chain for a specific finished device -- from finished product back to raw materials.
6.4 Does the organization control product preservation -- handling, storage, packaging, and shipping -- to maintain product conformity throughout the supply chain? Are environmental conditions monitored and controlled where they affect product quality?
- Preservation procedure covering handling, storage, packaging, and shipping requirements -- including environmental controls (temperature, humidity, cleanliness) where applicable
- Storage area inspection records showing environmental monitoring data, expiration date management, and stock rotation (FIFO or equivalent)
- Packaging validation records for sterile barrier systems or other critical packaging -- verify validation covers seal integrity, transit simulation, and shelf life
- Shipping records showing controlled conditions are maintained during transit where required (cold chain, shock indicators, humidity indicators)
- Temperature-sensitive products are stored without environmental monitoring -- no temperature logs or alarm systems for controlled storage areas (Grade 3).
- Sterile barrier system packaging has not been validated for the actual distribution conditions -- shelf life and transit studies do not reflect real-world shipping conditions (Grade 3).
- Expired raw materials or finished goods are found in storage without proper segregation or disposition -- the organization does not have an effective expiration date management process (Grade 2).
- No evidence of first-expired-first-out stock rotation -- older product remains in storage while newer product is shipped (Grade 1).
Product preservation is a production floor and warehouse audit task. Walk the storage areas and check: (1) Environmental conditions are controlled and monitored. (2) Expired materials are identified and segregated. (3) Stock rotation is practiced. (4) Packaging is appropriate for the intended distribution conditions. For sterile devices, verify sterile barrier system packaging validation includes accelerated aging and transit simulation. For temperature-sensitive products, verify cold chain controls are defined and monitored.
Walk the storage area. Check environmental monitoring records. Verify expiration date management. Review packaging validation records for at least one product. Check 3 items in storage for proper identification and condition.
- How do you manage expiration dates for raw materials and finished goods in storage?
- Has your packaging been validated for the most extreme shipping conditions in your distribution network?
6.5 Are monitoring and measuring devices calibrated or verified at defined intervals against traceable standards? Are calibration records maintained and is the validity of previous measurements assessed when equipment is found out of calibration?
- Calibration procedure defining equipment inventory, calibration intervals, methods, acceptance criteria, and actions when equipment is found out of calibration
- Calibration records for at least 3 pieces of measuring equipment -- verify calibration is current, traceable to national or international standards, and within acceptance criteria
- Evidence that calibration status is identifiable on the equipment -- labels, tags, or electronic system showing calibration date, due date, and status
- Records showing impact assessment when equipment was found out of calibration -- verification of the validity of previous measurements and product disposition decisions
- Calibration for critical measuring equipment has lapsed -- equipment was used for product acceptance beyond the calibration due date without recalibration (Grade 3).
- Equipment was found out of calibration but no impact assessment was performed -- the organization recalibrated the equipment without evaluating whether product accepted using the out-of-calibration equipment conforms to specifications (Grade 3).
- Calibration intervals are not risk-based -- all equipment is calibrated annually regardless of criticality, historical drift data, or frequency of use (Grade 1).
- Calibration is not traceable to national or international standards -- the organization calibrates equipment using in-house references that are not themselves traceable (Grade 2).
Calibration directly affects product quality measurement reliability. The most impactful finding is equipment found out of calibration without a subsequent impact assessment. Per ISO 13485 clause 7.6, the organization must assess the validity of previous measurements when equipment is found not conforming to requirements. This may require product retest, notification to customers, or recall. Verify at least 3 pieces of equipment are calibrated, current, and labeled. Check the calibration status of equipment you observe in use during production floor observation.
Check calibration status for at least 3 pieces of equipment observed in use. Review calibration records for currency and traceability. Verify at least one out-of-calibration impact assessment record.
- Can you show me a case where equipment was found out of calibration and describe what impact assessment was performed?
- How do you determine calibration intervals for your measuring equipment?
6.6 Are final product inspection and testing activities performed before release? Are acceptance activities documented with pass/fail results, acceptance criteria, and the identity of personnel performing acceptance? Is the device history record complete before product release?
- Final inspection and testing procedure defining required tests, acceptance criteria, sampling plans, and release authority
- Final inspection records for at least 2 recent production lots -- verify all required tests were performed, results meet acceptance criteria, and the record is signed by authorized personnel
- Device history record (DHR) for at least one production lot -- verify it contains all required elements: production records, inspection records, component traceability, labeling records, and release authorization
- Evidence that product is not released until all required acceptance activities are complete -- verify the release process prevents shipment of uninspected product
- Product was released before all final acceptance activities were complete -- the DHR shows the release date before the date of the final inspection (Grade 4 -- nonconforming product may have been distributed).
- Final inspection acceptance criteria do not match the design output specification -- the inspection procedure uses different (often wider) tolerances than the approved design specification (Grade 3).
- DHR is incomplete at the time of product release -- required elements (sterilization records, labeling verification, calibration status) are missing or added after release (Grade 3).
- Identity of the person performing final acceptance is not recorded -- inspection records show pass/fail results but not who performed the inspection (Grade 2).
Final acceptance is the last quality gate before product reaches patients. Verify the DHR tells a complete story from raw material receipt through final inspection and release. Cross-reference final inspection acceptance criteria against design output specifications -- they must match. A common finding is discrepancy between what the design team specified and what the quality team inspects against. Also verify the release authority has the appropriate qualification and independence. Per FDA 21 CFR 820.80 and 820.184, the DHR must be complete before release.
Review 2 DHRs for completeness. Verify final inspection records, release authorization, and that release did not occur before inspection completion. Cross-reference acceptance criteria against design specifications for at least 3 parameters.
- Can you show me a complete DHR and walk through each element?
- How do you prevent product from being shipped before the DHR is complete and released?
6.7 If the organization provides installation or servicing for its devices, are installation and servicing activities performed according to documented procedures? Are installation and service records maintained?
- Installation procedure defining installation requirements, acceptance criteria, and documentation requirements (if applicable)
- Installation records for at least 2 installations -- verify acceptance criteria were met and records are complete
- Servicing procedure defining service activities, parts management, training requirements, and record-keeping
- Service records showing service activities performed, parts used, and post-service verification
- Installation records do not demonstrate that acceptance activities were performed after installation -- the device was installed but not functionally verified in its installed environment (Grade 2).
- Service records are incomplete -- service activities are tracked in a CRM system but do not capture the technical details needed for trend analysis and post-market surveillance (Grade 1).
- Service personnel training records are not maintained -- the organization cannot demonstrate that service technicians were trained on the devices they service (Grade 2).
This task is applicable only if the organization performs installation or servicing. If not applicable, document the exclusion and move on. If applicable, verify installation and service records feed into the complaint and adverse event processes (Chapter 3 and 4). Service records are a valuable source of post-market surveillance data -- verify they are analyzed. FDA has specific requirements for installation under 21 CFR 820.170 and servicing under the QMSR supplemental requirements.
If applicable, review 2 installation records and 2 service records. Verify completeness and linkage to complaint/adverse event processes. If not applicable, verify the exclusion justification.
- How do service reports feed into your complaint handling and post-market surveillance processes?
- Are third-party service organizations subject to the same documentation requirements as internal service teams?
6.8 If the organization uses sterilization processes, are sterilization processes validated, routinely monitored, and revalidated per applicable standards? Are sterilization records maintained as part of the device history record?
- Sterilization validation records per applicable standard -- ISO 11135 (EtO), ISO 17665 (steam), ISO 11137 (radiation), or equivalent
- Routine sterilization monitoring records -- biological indicators, chemical indicators, physical parameters, and parametric release data where used
- Sterilization revalidation records -- verify revalidation frequency and triggers are defined and current
- Sterility assurance level (SAL) documentation -- verify SAL of 10^-6 is demonstrated for terminally sterilized devices
- If sterilization is outsourced, review the quality agreement and verification records per Task 1.5 (outsourced process controls)
- Sterilization process is not validated per the applicable standard -- the organization uses sterilization but has not performed a formal validation per ISO 11135, ISO 17665, or ISO 11137 (Grade 4).
- Sterilization monitoring parameters show excursions from validated ranges but no investigation or corrective action was taken (Grade 4).
- Revalidation has not been performed within the defined interval or after process changes (Grade 3).
- Outsourced sterilization provider changed a key process parameter without notifying the manufacturer -- no quality agreement clause requires such notification (Grade 3).
Sterilization validation is the highest-risk process validation because failure can result in nonsterile devices reaching patients. Verify the validation was performed per the applicable standard (not a generic protocol), routine monitoring is consistent with validated parameters, and revalidation is current. If sterilization is outsourced, cross-reference with Task 1.5 for outsourced process controls. All five MDSAP jurisdictions consider sterilization validation failures as high-grade nonconformities. This is a frequent Grade 4--5 finding area.
Review sterilization validation records for at least one method. Check routine monitoring records for the last 3 months. Verify revalidation currency. If outsourced, review the quality agreement.
- Can you show me the current sterilization validation summary report and the most recent routine monitoring records?
- When was sterilization last revalidated, and what triggered the revalidation?
§chapter.7 Purchasing and supplier management
7.1 Does the organization have documented purchasing procedures that ensure purchased product conforms to specified requirements? Are purchasing controls proportionate to the effect of the purchased product on subsequent production or the final device?
- Purchasing procedure defining the purchasing process, supplier qualification requirements, and purchasing document requirements
- Evidence that purchasing controls are risk-based -- critical components, raw materials, and outsourced processes receive more stringent controls than non-critical supplies
- Approved supplier list (ASL) or equivalent showing all suppliers of critical components and services with their qualification status
- Purchasing documents (purchase orders) for at least 2 critical components -- verify they include complete specifications, quality requirements, and reference to applicable standards
- Purchasing controls are uniform across all suppliers regardless of risk -- the same level of evaluation and monitoring is applied to a critical component supplier and an office supply vendor (Grade 1).
- Purchase orders for critical components do not include quality requirements, specifications, or reference to applicable standards -- the organization relies on verbal agreements or catalog descriptions (Grade 3).
- Components are purchased from suppliers not on the approved supplier list -- unapproved suppliers are used for convenience without the required evaluation (Grade 3).
Purchasing controls must be proportionate to risk. The organization should classify suppliers and purchased products by their impact on the final device. Critical components (raw materials that contact patients, software components, sterilization services) require more rigorous controls than indirect materials. Verify that purchase orders for critical components include complete specifications -- if the purchase order says only 'order per catalog,' the organization has not communicated its quality requirements. Cross-reference with Chapter 1 (outsourced processes) and Chapter 6 (incoming inspection).
Review the purchasing procedure. Check the ASL for completeness. Review purchase orders for at least 2 critical components. Verify risk-based purchasing controls are implemented.
- How do you classify suppliers and purchased products by risk?
- Can you show me a purchase order for a critical component and verify it includes complete quality requirements?
7.2 Does the organization evaluate and select suppliers based on their ability to meet specified requirements? Are supplier evaluations documented with defined criteria, and are records maintained?
- Supplier evaluation procedure defining evaluation criteria, methods (questionnaire, audit, performance review, certification review), and approval authority
- Supplier evaluation records for at least 3 suppliers -- including at least one critical component supplier and one service provider -- verify evaluations are documented with objective criteria and approval decisions
- Evidence that evaluation criteria include quality system capability, regulatory compliance, and ability to meet specification requirements -- not just price and delivery
- Records showing re-evaluation or ongoing assessment of existing suppliers -- verify supplier evaluations are not one-time events
- Supplier evaluations are based solely on ISO certificate review without verifying the certificate scope covers the products or services being purchased -- the supplier's ISO certification may not cover the relevant manufacturing processes (Grade 2).
- Supplier evaluation records consist only of a self-assessment questionnaire returned by the supplier without independent verification -- the organization accepts supplier self-reported capabilities at face value (Grade 1).
- Critical component suppliers have not been re-evaluated since initial approval -- some suppliers have been on the ASL for years without any reassessment of their continued capability (Grade 2).
- No supplier evaluation was performed -- a new supplier was added to the ASL based on a single successful purchase order without formal evaluation (Grade 3).
Supplier evaluation must be proportionate to the criticality of the purchased product. Critical component suppliers should be evaluated more rigorously (on-site audit, detailed questionnaire, sample testing) than non-critical suppliers (certificate review, self-assessment). Verify that evaluations include quality system capability, not just commercial factors. The most common gap is relying solely on ISO certificates without verifying the certificate scope. A supplier may be ISO 13485 certified for one product line but not for the product they supply to this organization. Cross-reference with supplier monitoring (Task 7.3).
Review evaluation records for at least 3 suppliers with varying criticality levels. Verify evaluation criteria are objective and documented. Check at least one re-evaluation record for a long-standing supplier.
- How do you verify that a supplier's ISO certificate covers the specific products or services you purchase from them?
- How often do you re-evaluate existing suppliers, and what triggers a re-evaluation outside the scheduled cycle?
7.3 Does the organization monitor supplier performance on an ongoing basis? Are supplier performance metrics defined, tracked, and used as input to supplier re-evaluation and CAPA decisions?
- Supplier monitoring procedure or practice defining metrics, data collection, review frequency, and actions for underperformance
- Supplier scorecard or performance reports for at least 2 critical suppliers -- verify metrics include quality (reject rate, nonconformance rate), delivery, and responsiveness
- Evidence that supplier performance data is reviewed periodically and discussed in management review or supplier review meetings
- Records showing action taken when a supplier's performance deteriorated -- corrective action requests, supplier audits, conditional approval, or disqualification
- No ongoing supplier performance monitoring exists -- the organization evaluates suppliers at initial qualification but does not track their performance over time (Grade 2).
- Supplier performance metrics are collected but not analyzed for trends -- individual reject events are addressed but deteriorating performance patterns are not identified (Grade 1).
- A supplier with consistently poor quality performance remains on the ASL without corrective action, conditional approval, or disqualification decision -- the organization continues to purchase from underperforming suppliers (Grade 2).
Supplier monitoring closes the feedback loop on supplier quality. Verify the organization tracks incoming reject rates, delivery performance, and response to quality issues. The most valuable check is asking: 'Which supplier has the worst quality performance, and what have you done about it?' If the organization cannot answer this question, monitoring is either not performed or not analyzed. Cross-reference with incoming inspection data from Chapter 6 and nonconforming product records from Chapter 3.
Review supplier performance data for at least 2 critical suppliers over the past 12 months. Verify action was taken for any performance issues. Check that supplier performance is reported in management review.
- Which supplier currently has the highest reject rate, and what action have you taken?
- How does supplier performance data feed into your supplier re-evaluation and CAPA processes?
7.4 Does the organization verify purchased product meets specified requirements through incoming inspection, testing, or other verification activities? Are acceptance criteria defined and records maintained?
- Incoming inspection procedure defining inspection requirements, acceptance criteria, sampling plans, and disposition authorities for different product categories
- Incoming inspection records for at least 3 received lots of critical components -- verify acceptance criteria, test results, disposition, and inspector identity are documented
- Evidence that incoming inspection acceptance criteria match the purchase specification -- verify consistency between what was ordered and what was inspected against
- Records showing disposition of received material that failed incoming inspection -- reject, return, concession decision with rationale
- Incoming inspection acceptance criteria do not match the purchase specification or design specification -- the inspection checks different parameters or uses different tolerances than what was specified (Grade 3).
- No incoming inspection is performed for critical components -- the organization relies entirely on the supplier's certificate of conformance without any independent verification (Grade 3).
- Sampling plans for incoming inspection are not based on a recognized statistical method (ANSI/ASQ Z1.4, ISO 2859) and are not justified by risk assessment (Grade 1).
- Material that failed incoming inspection was accepted by concession without documented rationale or appropriate approval authority (Grade 3).
Verification of purchased product is the supply chain quality gate. The most common finding is reliance on supplier certificates of conformance (C of C) without any independent verification. While a C of C can supplement incoming inspection, it should not replace it entirely for critical components. Verify that inspection criteria match the purchase specification and the design specification. If skip-lot inspection is used, verify the qualification criteria for skip-lot status and the conditions for returning to full inspection. Cross-reference with Task 7.1 (purchasing documents) and Chapter 6 production records.
Review incoming inspection records for at least 3 critical component lots. Verify acceptance criteria match specifications. Check at least one failure/rejection record. Verify sampling plan basis.
- For which components do you accept product based solely on the supplier's certificate of conformance?
- Can you show me an incoming inspection failure and the resulting disposition?
7.5 Does the organization have agreements with suppliers that include notification of changes to products, processes, or quality systems? Are supplier change notifications evaluated for impact on the medical device?
- Quality agreements or supply agreements for critical suppliers that include change notification clauses -- verify the clause requires advance notification of changes to materials, processes, specifications, or quality system status
- Records of supplier change notifications received and the organization's impact assessment for each
- Evidence that supplier changes triggered appropriate actions -- incoming inspection adjustment, revalidation, regulatory assessment, design change evaluation
- Records showing the organization verifies supplier change notification compliance -- periodic checks that suppliers are honoring notification commitments
- Quality agreements with critical suppliers do not include change notification clauses -- the organization has no contractual mechanism to require advance notice of supplier changes (Grade 2).
- Supplier change notifications were received but no impact assessment was performed -- the organization acknowledged receipt without evaluating the effect on the medical device (Grade 3).
- A supplier changed a material or process without notification and the change was discovered during incoming inspection or product failure investigation -- the quality agreement did not require notification or was not enforced (Grade 3).
Supplier change notification is a critical control because unnotified supplier changes are a frequent root cause of product quality issues. Verify quality agreements require advance notification and that the organization has a process to evaluate the impact of notified changes. The most common gap is that agreements require notification but the organization does not systematically track or evaluate notifications received. Ask for an example of a supplier change notification and verify the impact assessment considered regulatory implications (does the change require a design change? a regulatory notification?). Cross-reference with Task 5.8 (design changes) and Chapter 2 (regulatory notifications).
Review quality agreements for 2 critical suppliers for change notification clauses. Check at least one supplier change notification and the resulting impact assessment. If no notifications have been received, assess whether this is reasonable given the supplier base size and timeframe.
- Can you show me a recent supplier change notification and the impact assessment you performed?
- How do you verify that suppliers are honoring their change notification commitments?
§chapter.8 Cross-jurisdictional gap analysis
8.1 Has the organization performed a systematic gap analysis comparing regulatory requirements across all MDSAP jurisdictions where it markets devices? Does the analysis identify where requirements differ and how each difference is addressed in the QMS?
- Cross-jurisdictional regulatory requirements gap analysis document -- a matrix or comparison showing where requirements of FDA, Health Canada, ANVISA, PMDA, and TGA differ from each other and from ISO 13485
- Evidence that the gap analysis covers all major QMS process areas -- adverse event reporting, complaint handling, labeling, design changes, marketing authorization, record retention, and post-market surveillance
- Records showing the gap analysis is maintained -- updated when new regulatory requirements are published or when the organization enters new jurisdictions
- Mapping of each identified gap to the QMS procedure or process that addresses it
- No systematic cross-jurisdictional gap analysis has been performed -- the organization assumes ISO 13485 compliance satisfies all jurisdictions without verifying jurisdiction-specific requirements (Grade 3).
- Gap analysis was performed at MDSAP initial certification but has not been updated to reflect regulatory changes in any jurisdiction (Grade 2).
- Gap analysis identifies differences but does not map each difference to a specific QMS procedure or process -- gaps are identified but not demonstrably closed (Grade 2).
This is the foundational task for cross-jurisdictional verification. Without a gap analysis, the organization is operating on assumptions. The gap analysis should be a living document, not a one-time exercise. Common areas where jurisdictions diverge significantly: adverse event reporting definitions and timelines, labeling requirements, marketing authorization change thresholds, record retention periods, and establishment registration requirements. Verify the organization has staff or consultants with expertise in each jurisdiction's requirements -- a gap analysis performed by someone who does not understand the requirements of a given jurisdiction will miss gaps.
Review the gap analysis document. Verify it covers all 5 jurisdictions and all major QMS process areas. Select 3 identified gaps and verify the QMS procedure that addresses each. Check the gap analysis revision history for currency.
- When was this gap analysis last updated, and what triggered the update?
- Who performed the gap analysis, and what jurisdiction-specific expertise did they bring?
- Can you show me a specific requirement that differs between jurisdictions and how your QMS addresses both?
8.2 Do adverse event reporting procedures address the specific reportability definitions, reporting timelines, report formats, and follow-up requirements for each MDSAP jurisdiction independently? Can the organization demonstrate it has submitted timely reports to all applicable jurisdictions, not just the primary market?
- Adverse event reporting procedure with a jurisdiction-specific section or appendix for each MDSAP jurisdiction -- verify definitions of reportable events, reporting timelines, report format requirements, and follow-up obligations are specified per jurisdiction
- Comparison of reporting timelines by jurisdiction and event type showing the organization has identified the earliest deadline for multi-jurisdiction events
- Records of adverse event reports submitted in the past 24 months -- verify each reportable event was reported to ALL applicable jurisdictions, not just the primary market
- Records of events determined not reportable in a specific jurisdiction with documented rationale addressing that jurisdiction's specific criteria
- Adverse event was reported to FDA but not to Health Canada, ANVISA, PMDA, or TGA -- the organization applied only one jurisdiction's reporting criteria to a multi-jurisdiction event (Grade 4).
- Reporting procedure uses generic criteria that do not account for jurisdiction-specific differences in reportable event definitions -- Health Canada's 'incident' definition is broader than FDA's 'death/serious injury/malfunction' definition, but the procedure only uses the FDA definition (Grade 3).
- Reports to secondary jurisdictions (ANVISA, PMDA, TGA) are consistently submitted later than reports to FDA or Health Canada -- secondary jurisdictions are treated as lower priority despite having their own timeline requirements (Grade 3).
This is the most common cross-jurisdictional gap in MDSAP audits. Organizations that are FDA-centric tend to apply FDA MDR criteria globally and miss events that are reportable in other jurisdictions under broader definitions. Health Canada, in particular, uses a broader definition of 'incident' than FDA uses for 'reportable event.' ANVISA has unique reporting categories. PMDA has specific timelines that differ from FDA. Verify the organization evaluates each event against each jurisdiction independently. Sample at least 2 events and verify multi-jurisdiction reporting compliance.
Review 3 adverse event reports. For each, verify all applicable jurisdictions received timely reports. Review 2 non-reportable determinations and verify rationale addresses each jurisdiction's criteria independently.
- Show me an event that was reportable in all 5 jurisdictions. Were all 5 reports submitted within their respective timelines?
- Have you ever had an event that was reportable in one jurisdiction but not another? Explain the difference.
8.3 Does the record retention schedule address the requirements of all MDSAP jurisdictions and apply the most stringent retention period for each record type? Can the organization demonstrate it retains records for at least the longest applicable period?
- Record retention schedule showing retention periods per record type with jurisdiction-specific requirements identified -- FDA (expected lifetime + 2 years for certain records), Health Canada (device life + 1 year), ANVISA, PMDA, and TGA-specific periods
- Evidence that the organization applies the most stringent retention period -- verify the schedule selects the longest applicable period for each record type
- Records management system or archive demonstrating records are retrievable for the defined retention periods
- Evidence that electronic records are backed up and accessible for the full retention period -- data migration records for system changes
- Record retention schedule only addresses FDA requirements and does not identify or apply longer retention periods required by other jurisdictions (Grade 2).
- Records were destroyed before the retention period expired because the organization applied a shorter jurisdiction's retention period instead of the longest applicable period (Grade 3).
- Electronic records from a previous quality system or document management system are no longer accessible after system migration -- records within the retention period cannot be retrieved (Grade 3).
Record retention is a quiet but serious compliance area. Each jurisdiction has different requirements, and the organization must apply the most stringent. Common gaps: FDA requires some records for the expected lifetime of the device plus 2 years. Health Canada requires device life plus 1 year. If the device has an indefinite expected lifetime (e.g., permanent implant), records must be retained indefinitely in practice. Verify the organization has thought through this for each device type. Also verify electronic record accessibility -- system migrations often result in orphaned records that are technically retained but practically inaccessible.
Review the retention schedule for completeness across jurisdictions. Verify at least 2 record types apply the most stringent period. Request retrieval of one record near the end of its retention period to verify accessibility.
- How do you determine the 'expected lifetime' of your devices for record retention purposes?
- When you last migrated your quality system software, how did you ensure all records remained accessible?
8.4 Does the organization maintain valid marketing authorizations, establishment registrations, and device listings in all jurisdictions where it markets devices? Are these tracked centrally and renewed before expiration?
- Centralized tracking system or spreadsheet showing all marketing authorizations, establishment registrations, and device listings per jurisdiction with status, expiration dates, and renewal due dates
- Evidence of current status for each entry -- authorization letters, registration confirmations, or database screenshots from each jurisdiction's regulatory system
- Records of timely renewals or re-registrations -- verify no gaps in authorization or registration status
- Process for adding new jurisdictions or removing discontinued devices from tracking
- No centralized tracking exists -- marketing authorizations and registrations are managed by different individuals for different jurisdictions with no single view of compliance status (Grade 2).
- A marketing authorization or establishment registration has expired without the organization being aware -- the tracking system did not generate alerts before expiration (Grade 4).
- Devices are marketed in a jurisdiction where the marketing authorization has lapsed or was never obtained -- particularly common in secondary markets managed by distributors (Grade 4).
This task verifies the organization has the legal right to market in every jurisdiction where it actually sells devices. The most critical check is comparing the actual distribution records against the marketing authorization list -- if devices are shipped to a jurisdiction where no authorization exists, this is a Grade 4+ nonconformity. Common gaps: organizations that rely on distributors to maintain local registrations without verifying registration status, or organizations that enter new markets through distributor agreements without obtaining the necessary marketing authorization. Cross-reference with Chapter 2 tasks.
Review the centralized tracking system. Verify status is current for at least 3 authorizations/registrations across different jurisdictions. Cross-reference with distribution records to verify no devices are shipped to unregistered markets.
- Can you show me a single view of all your marketing authorizations across all jurisdictions with their current status?
- How do you verify that distributors in secondary markets are maintaining the required local registrations?
8.5 Does the organization apply the MDSAP nonconformity grading system (Grades 1--5) consistently? Does the organization understand the implications of each grade, including the 5-Day Notice trigger for Grades 4 and 5?
- Procedure or training materials showing the organization understands the MDSAP nonconformity grading system per GHTF/SG3/N19:2012
- Records of previous MDSAP audit nonconformities showing how grades were assigned, corrective actions planned, and evidence submitted within the required timeframes
- Evidence that the organization tracks remediation deadlines -- 15 days for corrective action plan, 30 days for evidence of implementation
- Training records showing quality and management personnel understand the 5-Day Notice process and its regulatory implications
- Organization does not understand the MDSAP grading system and cannot explain the difference between Grade 3 and Grade 4 nonconformities or the 5-Day Notice implications (Grade 1 -- informational).
- Previous MDSAP audit corrective actions were not completed within the required timeframes -- corrective action plans were submitted late or evidence of implementation was not provided within 30 days (Grade 2).
- No process exists for managing MDSAP audit nonconformity remediation -- the organization treats MDSAP NCs the same as internal audit findings without tracking the specific MDSAP remediation timelines (Grade 1).
This is an organizational readiness task. The MDSAP grading system is unique and has serious regulatory consequences. A 5-Day Notice (triggered by two or more Grade 4 NCs or any Grade 5 NC) notifies all five regulatory authorities and can result in coordinated regulatory action. Verify the organization understands this system and has a process for managing MDSAP audit findings with the specific MDSAP remediation timelines. Review previous MDSAP audit reports (if available) and verify all NCs were closed within the required timeframes.
Review previous MDSAP audit reports. Verify NC remediation timelines were met. Check that the organization has documented the grading system and 5-Day Notice process in its quality procedures or training materials.
- What is your process for responding to an MDSAP audit nonconformity, and how do you ensure you meet the 15-day and 30-day deadlines?
- Have you ever received a Grade 4 or 5 nonconformity? If so, describe the 5-Day Notice process and your response.
8.6 Does the organization have personnel with regulatory expertise for each MDSAP jurisdiction? Are jurisdiction-specific regulatory requirements assigned to qualified personnel who maintain current knowledge?
- Organizational chart or role assignments showing regulatory responsibility assignments per jurisdiction
- Qualifications and training records for regulatory affairs personnel covering jurisdiction-specific requirements -- verify personnel are trained on the regulatory frameworks of the jurisdictions they are responsible for
- Evidence of continuing education or regulatory intelligence activities -- conference attendance, regulatory association memberships, training on regulatory changes
- Records showing jurisdiction-specific regulatory expertise was applied in decision-making -- regulatory submission reviews, reportability determinations, change notification assessments
- All regulatory activities for all 5 jurisdictions are managed by a single person with deep expertise in only one jurisdiction -- the organization lacks backup capability and jurisdiction-specific depth for 4 of 5 jurisdictions (Grade 2).
- Regulatory personnel have not received training on recent regulatory changes in jurisdictions they manage -- they are applying outdated requirements (Grade 2).
- No regulatory expertise exists in-house for ANVISA, PMDA, or TGA -- the organization relies entirely on external consultants with no internal understanding of those jurisdictions' requirements (Grade 1).
MDSAP compliance requires jurisdiction-specific expertise. Verify the organization has access to regulatory knowledge for each jurisdiction -- either in-house or through qualified external resources. If relying on external consultants, verify the consultant's qualifications and that the organization retains enough internal understanding to oversee the consultant's work. Common gap: organizations with strong FDA and Health Canada expertise but minimal knowledge of ANVISA, PMDA, or TGA requirements, leading to compliance gaps in secondary jurisdictions.
Verify regulatory responsibility assignments for each jurisdiction. Review qualifications and training records for at least 2 regulatory personnel. Check continuing education or regulatory update records from the past 12 months.
- Who is responsible for regulatory compliance in each MDSAP jurisdiction?
- How do you ensure your regulatory staff stays current on changes in all five jurisdictions?
8.7 Are labeling, packaging, and instructions for use compliant with the requirements of each jurisdiction where the device is marketed? Has the organization verified that language, content, and format requirements are met per jurisdiction?
- Labeling compliance matrix showing requirements per jurisdiction -- language requirements (bilingual for Canada, Portuguese for Brazil, Japanese for Japan), UDI requirements, regulatory symbols, and content requirements
- Verification records showing labels and IFU were reviewed against each jurisdiction's requirements before market release
- Sample labels for at least one device -- verify compliance with language, UDI, and content requirements for each applicable jurisdiction
- Translation verification records for multi-language labeling -- back-translation or native speaker review
- Labels for the Canadian market do not include bilingual (English/French) text as required by Health Canada (Grade 3).
- Instructions for Use are not available in the local language for all jurisdictions where the device is marketed (Grade 2).
- UDI compliance has not been achieved for devices subject to current implementation deadlines in one or more jurisdictions (Grade 3).
- Regulatory symbols used on labels do not meet the specific requirements of all jurisdictions -- some jurisdictions require text in addition to or instead of certain symbols (Grade 1).
Labeling is a high-variation area across jurisdictions. Each has specific language, content, and format requirements. Verify the organization has a jurisdiction-by-jurisdiction labeling checklist and applies it before releasing labeling for each market. Common gaps: missing French in Canadian labeling, missing Portuguese in Brazilian labeling, missing Japanese in Japanese labeling, and non-compliant UDI formatting. Cross-reference with Chapter 2, Task 2.3.
Select one device sold in at least 3 jurisdictions. Verify the label and IFU meet each jurisdiction's requirements. Check UDI compliance status. Verify translation quality records.
- How do you ensure labeling compliance is verified for each jurisdiction before market release?
- What is your process for managing labeling changes when a jurisdiction updates its requirements?
8.8 Does the organization's management review process specifically address multi-jurisdiction compliance status, cross-jurisdictional regulatory performance, and harmonization gaps? Are jurisdiction-specific issues escalated to management?
- Management review agenda and minutes showing jurisdiction-specific compliance was addressed -- not just overall QMS performance, but performance per jurisdiction (regulatory submissions, reporting compliance, marketing authorization status, labeling compliance)
- Jurisdiction-specific compliance metrics presented at management review -- adverse event reporting timeliness per jurisdiction, marketing authorization renewal status per jurisdiction, and regulatory query response timeliness
- Records of management decisions addressing cross-jurisdictional compliance gaps -- resource allocation for under-served jurisdictions, process improvements for multi-jurisdiction requirements
- Evidence that management review output includes actions specific to cross-jurisdictional compliance improvement
- Management review does not address jurisdiction-specific compliance -- QMS performance is reviewed at a global level without distinguishing between regulatory performance in each MDSAP jurisdiction (Grade 2).
- Compliance metrics are reported for FDA only -- no data is presented on adverse event reporting timeliness, marketing authorization status, or regulatory correspondence for Health Canada, ANVISA, PMDA, or TGA (Grade 2).
- Cross-jurisdictional compliance gaps were identified but not escalated to management or addressed in management review output actions (Grade 1).
Management review is the capstone of the MDSAP audit. Verify that it explicitly addresses multi-jurisdiction compliance, not just overall QMS performance. A mature MDSAP-compliant organization presents jurisdiction-specific data: How many adverse events were reported to each jurisdiction and were they on time? What is the marketing authorization status per jurisdiction? Were any regulatory queries received and how quickly were they answered? If management review only presents aggregate data without jurisdiction breakdowns, the organization is not managing multi-jurisdiction compliance at the management level.
Review the last management review minutes for jurisdiction-specific content. Verify compliance metrics were presented per jurisdiction. Check that at least one management review output action addresses cross-jurisdictional compliance.
- Can you show me the jurisdiction-specific compliance data that was presented at the last management review?
- Has management ever made a resource allocation decision specifically to address a cross-jurisdictional compliance gap?
Each item shows its evidence, common nonconformities and auditor tips. The PDF holds the same content, formatted for a clipboard.