ISO 13485 Gap Assessment: A Step-by-Step Guide for Medical Device Manufacturers (2026)

Learn how to run an ISO 13485 gap assessment step by step — from scoping and clause mapping to grading findings and building a remediation timeline before your certification audit.

How to run an ISO 13485 gap assessment before your certification body ever sees your QMS.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Gap Assessment Is the Step Most Manufacturers Skip

Many manufacturers don’t discover their biggest ISO 13485 gaps until they systematically compare their QMS against the standard.

An ISO 13485 gap assessment gives you a structured way to find those gaps before your certification body does. It’s a clause-by-clause comparison of your current quality management system against what ISO 13485:2016 actually requires — and it’s one of the highest-leverage steps between “we think we’re ready” and “we’re ready for Stage 1.”

This guide walks through the gap assessment process step by step: how to scope it, how to run it, how to grade what you find, and how to turn the results into a remediation plan your team can actually execute before your audit window opens.

From the Floor: As a certified ISO 9001 Internal Auditor, the pattern I see most often in gap assessments — regardless of which standard is on the cover — is a QMS that has real documentation but no clause map. Procedures exist. Records exist. But nobody has walked the standard clause by clause and confirmed each requirement actually has evidence behind it. That’s exactly what a gap assessment is designed to expose, and finding it internally gives your team more control over the remediation timeline than discovering it during certification.

Before you build a remediation plan, you need to know where the gaps actually are. Run the free ISO 13485 Gap Assessment Checklist and get a clause-by-clause starting point for your own QMS.


In This Guide

  • What an ISO 13485 gap assessment actually is, and how it differs from an internal audit
  • The eight-step process, from scoping to remediation
  • How to grade findings so your team knows what to fix first
  • A readiness checklist for what “gap-assessed” should actually mean
  • Answers to the questions manufacturers ask most before their first assessment


👉 Start Here (Top Resources)

  • Own the standard you’re assessing against: ISO 13485:2016 — ANSI Webstore — you can’t run an accurate gap assessment without the current clause text in front of you. Use code CC2026 for 5% off through December 31, 2026.
  • Close the gaps once you find them: 9001Simplified — documentation kits built for manufacturers who need to build or rebuild QMS documentation without hiring a full-time consultant.
  • Get your team trained on the requirements before they run the assessment: ISO 13485 Training — BSI Group — a team that understands the clause structure finds gaps faster and more accurately than one working from intuition.

What an ISO 13485 Gap Assessment Actually Is

A gap assessment is not an audit. It’s not a certification activity, and no external party has to be involved. It’s an internal, structured comparison: for every requirement in ISO 13485:2016, does your QMS have documented evidence that requirement is met — and if not, how far off is it?

That distinction matters because it changes the tone of the exercise. An internal audit (covered in our guide on how to audit a medical device QMS) assumes a QMS is largely built and tests whether it’s being followed. A gap assessment assumes nothing — it’s asking “does this exist at all, and if it does, is it complete.”

Gap Assessment vs. Internal Audit

Gap AssessmentInternal Audit
Primary questionDoes the requirement and supporting evidence exist?Is the QMS being followed and operating effectively?
Typical timingOften performed during QMS development or transitionPerformed as part of the established audit program
Main outputGap list and remediation planAudit findings and corrective action
Evidence examinedDocuments, records, and implementation evidenceProcess implementation, records, and objective evidence
PurposeIdentify what needs to be built, changed, or strengthenedEvaluate conformity and implementation of the established QMS

Quick Answer

QuestionQuick Answer
Is a gap assessment required for ISO 13485 certification?No. It’s not a formal requirement of the standard, but it’s a practical risk-reduction step manufacturers can use to identify gaps before a certification audit.
How long does a gap assessment take?As a planning estimate, a single-site manufacturer with an existing QMS might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability.
Can I do a gap assessment myself, or do I need a consultant?You can do it yourself with a structured checklist and a working knowledge of the standard. Consultants add value for complex or first-time QMS builds, but the assessment itself doesn’t require outside certification.
What’s the difference between a gap assessment and an internal audit?A gap assessment checks whether documentation and evidence exist against each clause. An internal audit checks whether an existing, documented QMS is actually being followed in practice.

The Eight-Step Gap Assessment Process

Step 1: Define Scope and Assemble Your Team

Before you open the standard, decide what’s actually in scope. Which sites? Which product lines? Which regulatory markets — because that determines which country-specific requirements layer on top of the ISO 13485 baseline. If you’re weighing whether MDSAP applies to your assessment scope, our MDSAP vs ISO 13485 guide walks through that decision separately.

Assemble a small cross-functional team — quality, at minimum, plus whoever owns design, production, and supplier management. A gap assessment run entirely by one person in the quality department tends to miss operational gaps that only show up on the floor.

Step 2: Gather Current QMS Documentation

Pull everything: your quality manual, procedures, work instructions, forms, records, and any prior audit findings — internal or external. If your document control system is disorganized, this step alone often reveals your first gap. See our guide on ISO 13485 documentation requirements for what a complete document set should include.

Step 3: Build Your Clause Map

At a high level, ISO 13485:2016 organizes its requirements across five main clause groups: Quality Management System (Clause 4), Management Responsibility (Clause 5), Resource Management (Clause 6), Product Realization (Clause 7), and Measurement, Analysis and Improvement (Clause 8). Build a simple matrix — clause number down one side, your corresponding procedure or record down the other. Anywhere that cell is blank is your first visible gap, before you’ve even started evaluating quality.

ISO 13485 gap assessment clause map connecting requirements to procedures, records, and objective evidence
An ISO 13485 gap assessment clause map connects each requirement to the corresponding QMS procedure, work instruction, records, and objective evidence.

Step 4: Walk Each Clause Against the Evidence

This is the core of the assessment. For each clause, ask three questions: Does a documented procedure exist? Does it match what the standard actually requires — not just what sounds similar? And is there objective evidence (records, forms, logs) that the procedure is being followed, not just written?

CAPA is worth flagging specifically here because it requires the team to connect nonconformance, root cause, corrective action, and effectiveness verification across the QMS. Our breakdown of CAPA requirements under ISO 13485 covers what auditors expect to see connected — traceable within the QMS rather than reconciled manually across separate systems.

This is often where gap assessments slow down because the work is tedious, not because it’s conceptually difficult. If your team needs a structured starting point instead of building the clause matrix from scratch → Run the free ISO 13485 Gap Assessment Checklist.

ISO 13485 gap assessment showing how procedures, records, and objective evidence demonstrate QMS conformity
An ISO 13485 gap assessment should verify not only that procedures exist, but that records provide objective evidence the QMS is being followed.

Step 5: Grade Each Finding

Not every gap carries the same weight. A missing signature on a training record is not the same category of problem as a design control process that doesn’t exist. Grade findings on a simple scale:

  • Critical — the requirement is effectively absent. No procedure, no evidence, no compensating control.
  • Major — a procedure exists but has a significant gap against the clause requirement, or evidence of following it is inconsistent.
  • Minor — the procedure and evidence both exist, but execution has small, correctable inconsistencies.

Grading matters because it drives sequencing. These labels are an internal prioritization framework, not ISO 13485-defined finding classifications — the exact grading terminology and criteria used by a certification body or regulatory program can vary. For an internal assessment, the important thing is to apply your criteria consistently so the team knows which gaps require immediate attention.

Step 6: Prioritize Remediation

Start with the gaps that present the greatest risk to QMS conformity or product and regulatory compliance. In most cases, that means addressing foundational gaps such as a missing design-control process or nonexistent CAPA system before working through lower-risk administrative issues. Major findings come next, typically grouped by clause area so one person or team can work through related gaps together rather than jumping between unrelated processes.

If you are rebuilding documentation from a critical or major finding → start with the clause itself, not a generic template. A procedure written to satisfy a checklist item without matching your actual process creates a new gap the moment an auditor asks a follow-up question.

If you are working through a backlog of minor findings → batch them by owner and set a single close-out date rather than tracking dozens of individual deadlines. Minor findings left open individually tend to get lost; batched with a deadline, they get closed.

Step 7: Build a Remediation Timeline

Attach real dates to every finding, not target quarters. Critical findings should have the shortest timeline your team can realistically execute — these are the gaps most likely to create significant problems during a certification assessment if they remain unresolved. Build in a buffer before your target certification audit date; remediation almost always takes longer than the first estimate, especially where a new procedure requires training staff to actually follow it.

Step 8: Re-Assess Before You Schedule Your Audit

A gap assessment isn’t a one-time snapshot. Once remediation work closes out your critical and major findings, re-walk those specific clauses to confirm the fix actually holds — not just that a document was updated, but that the evidence trail behind it exists. This is also the point where many manufacturers benefit from a full internal audit as a final check before scheduling Stage 1.


Common Mistakes That Undermine a Gap Assessment

Treating the assessment as a documentation review only. Confirming a procedure exists isn’t the same as confirming it’s followed. A gap assessment that never looks at records — training logs, CAPA files, supplier evaluations — will miss exactly the kind of gap an auditor finds first, because auditors ask for objective evidence, not just the procedure. Our guide on common mistakes in ISO 13485 QMS implementation covers this pattern in more depth.

Assessing against an old edition of the standard. ISO 13485:2016 is the current edition, but manufacturers working from a QMS built years ago sometimes have procedures written against superseded clause numbering. Confirm you’re assessing against the current published text before you start building your clause matrix.

Skipping the connection to FDA’s QMSR. If you sell into the United States, consider whether your gap assessment also needs to address FDA’s QMSR requirements and inspection expectations — FDA’s QMSR, effective February 2, 2026 and incorporating ISO 13485:2016 by reference, expanded what FDA can review during an inspection. Records that were previously exempt from routine inspection under the legacy QSR — management review, internal quality audit, and supplier audit records — are not exempt under QMSR. That’s worth building into your assessment scope rather than assuming an ISO 13485-only assessment automatically covers it.


Gap Assessment Readiness Checklist

✅ Scope defined — sites, product lines, and regulatory markets confirmed
✅ Cross-functional team assembled, not just quality department staff
✅ Full current QMS documentation set gathered and organized
✅ Clause matrix built against ISO 13485:2016, Clauses 4 through 8
✅ Each clause walked against both procedure and objective evidence, not procedure alone
✅ Findings graded — critical, major, minor — using consistent criteria
✅ Remediation timeline built with real dates, prioritized by severity
✅ Critical and major findings re-assessed after remediation, before scheduling your audit

ISO 13485 gap assessment process showing how manufacturers find, prioritize, remediate, and re-assess QMS gaps before certification
An ISO 13485 gap assessment turns identified QMS gaps into a prioritized remediation plan, followed by verification and re-assessment before the certification audit.

Frequently Asked Questions

Is a gap assessment required before ISO 13485 certification?

No. It’s not a formal requirement in the standard itself. It’s a risk-reduction step manufacturers use to avoid discovering major or critical nonconformities for the first time during an actual certification audit, where findings can delay certification.

How is a gap assessment different from an internal audit?

A gap assessment asks whether documentation and evidence exist at all against each clause — it’s typically run once, early, often before a QMS is fully built out. An internal audit assumes a documented QMS exists and tests whether it’s actually being followed in day-to-day operation. A common approach is to run the gap assessment first, then use internal audits on a recurring schedule once the QMS is established.

Who should be involved in a gap assessment?

At minimum, someone from quality who knows the standard well enough to interpret clause intent, plus representation from any function the clauses touch directly — design, production, supplier management. A single-person assessment tends to miss operational gaps that only surface when someone from outside quality reviews the finding.

How long does a gap assessment typically take?

As a planning estimate, a manufacturer with an existing QMS and a single site in scope might spread the assessment across roughly 2–4 weeks of part-time effort. Actual duration varies significantly with QMS maturity, scope, number of sites, product lines, and team availability — manufacturers building a QMS from scratch, or with multiple sites in scope, should expect it to take longer.

Can I use the same gap assessment for MDSAP readiness?

Largely, yes — MDSAP audits use ISO 13485:2016 requirements alongside applicable regulatory requirements from participating authorities, so a thorough ISO 13485 gap assessment covers most of the same ground. MDSAP layers those country-specific regulatory requirements on top of the ISO 13485 baseline, so if MDSAP is in scope, your assessment should also map those additional requirements. See our MDSAP vs ISO 13485 guide for how the two relate.

What happens if I find a critical gap close to my planned audit date?

Push the audit date. Scheduling a certification audit around a known critical gap doesn’t make the gap disappear — it moves the risk of discovering that gap into the certification audit, where the certification body will determine whether the issue constitutes a nonconformity and how it should be classified, instead of remaining an internal finding you controlled the timeline on.

Do I need a consultant to run a gap assessment?

Not necessarily. A structured checklist and a working knowledge of the standard’s clause structure is enough for most single-site manufacturers with an existing QMS. Consultants add the most value for first-time QMS builds, multi-site assessments, or situations where the internal team lacks bandwidth to run the assessment alongside daily operations.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still figuring out where your QMS stands? Start with the ISO 13485 Gap Assessment Checklist — it’s the fastest way to see your clause-by-clause starting point before you build a full remediation plan.

🔹 Ready to close documentation gaps you’ve already identified? 9001Simplified’s documentation kits are built for manufacturers assembling or rebuilding QMS documentation without a full-time consultant.

🔹 Need to confirm your clause matrix against the current standard? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through December 31, 2026.

🔹 Want your team trained before they run the assessment? BSI Group’s ISO 13485 training builds the clause knowledge that makes a gap assessment faster and more accurate.

Treating a gap assessment as a formality can leave significant gaps undiscovered until the certification audit. A properly executed assessment gives your team an opportunity to find those gaps internally, assign ownership, and control the remediation timeline before the certification audit begins. The Standards Navigator will keep this guide current as ISO 13485 and its related regulatory frameworks continue to evolve.


Stay Ahead of Your Next Audit Cycle

Skipping the gap assessment step doesn’t remove the risk of undiscovered gaps — it increases the chance that a gap will first be identified during the certification process, in front of an auditor, where the certification body determines whether it constitutes a nonconformity. Running it properly moves that discovery earlier, onto your own timeline, with your team in control of the fix.

The Standards Navigator tracks how ISO 13485, MDSAP, and FDA’s QMSR continue to shift so your QMS doesn’t fall behind a requirement you didn’t know had changed.

👉 Get updates on ISO 13485 requirements and medical device compliance as they happen
👉 Be first to access new gap assessment tools and documentation resources as we build them

Subscribe

* indicates required

Industrial Compliance. Clearly Explained.

How to Audit a Medical Device QMS: The ISO 13485 Internal Audit Process (2026 Guide)

This guide walks medical device manufacturers through the ISO 13485 Clause 8.2.4 internal audit requirement — including audit program design, the six-step audit process, and the five most common findings auditors cite. It also covers what changed under the FDA QMSR and the new ISO 19011:2026 audit guidance.

A clause-by-clause guide to planning, conducting, and closing out ISO 13485 internal audits under the new FDA QMSR

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


The Internal Audit That Used to Be Private Isn’t Anymore

For years, medical device manufacturers treated the internal audit report as an internal document — useful for finding problems, but shielded from FDA inspectors under the confidentiality provision in the old 21 CFR 820.180(c). That protection is gone.

Since February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) has been in effect, and it incorporates ISO 13485:2016 by reference rather than running a parallel U.S.-specific standard alongside it. FDA’s own Final Rule FAQ is direct about what that means for audits: “The QMSR gives the FDA the authority to inspect management review, quality audits, and supplier audit reports. The exceptions that existed in the QS regulation at § 820.180(c) are not maintained in the QMSR.” That’s not a third-party interpretation — it’s FDA’s own published position.

So this isn’t limited to internal audit reports. Management review minutes and supplier audit reports lost the same protection. A checklist you run through once a year to satisfy Clause 8.2.4 on paper is no longer a low-risk approach — it’s now a document an inspector may read line by line, and so are the meetings where leadership reviewed it.

From the Floor: I’ve built and run internal audit programs at facilities with 500-plus employees, and the finding that costs organizations the most isn’t a missing procedure — it’s a corrective action that gets closed on paper before the root cause is actually fixed. As a certified ISO 9001 Internal Auditor, I’ve sat across the table from auditors who catch that in about ninety seconds. Whether you’re auditing to ISO 9001 or ISO 13485, the internal audit only works if it’s harder on you than the external one will be.

Before your next surveillance audit, most quality teams don’t fail because they misunderstand Clause 8.2.4 — they fail because their audit program looks complete on paper but hasn’t been stress-tested against real objective evidence. Run your QMS through the free ISO 13485 Gap Assessment Checklist before an inspector or a Notified Body does it for you.


In This Guide

  • What ISO 13485 Clause 8.2.4 actually requires
  • How internal audits differ from supplier and certification audits
  • What Clause 6.2 actually requires of your auditors — and what “competent” really means
  • Building a risk-based annual audit program
  • The audit process: planning, evidence, reporting, and CAPA follow-up
  • A real finding-to-CAPA example, start to finish
  • The five most common internal audit findings — and how to avoid them
  • What changes if you’re audited under MDSAP
  • What changed under the FDA QMSR and ISO 19011:2026
  • Whether you need outside help or can run this internally


👉 Start Here (Top Resources)


What Clause 8.2.4 Actually Requires

ISO 13485 requires internal audits under Clause 8.2.4 to verify that QMS processes are implemented and effective, catch nonconformities, and surface QMS deficiencies early enough that they don’t become product-safety or regulatory problems. That sounds close to ISO 9001’s internal audit clause, and it is — but ISO 13485 asks for more.

Clause 8.2.4 requires that internal audits determine conformity to planned arrangements, the requirements of the standard, the organization’s own QMS requirements, and applicable regulatory requirements — and unlike ISO 9001, ISO 13485 explicitly requires the audit program to account for regulatory requirements such as FDA 21 CFR Part 820, EU MDR, or MDSAP alongside the standard itself. Teams that build their audit program purely off the ISO 13485 clause structure, without folding in the regulatory layer, are the ones who get flagged.

Most common finding: auditors treat Clause 8.2.4 as a documentation-review exercise and skip the regulatory cross-reference entirely. If your audit checklist doesn’t ask “does this also satisfy 21 CFR Part 820 or MDR Article 10?” it isn’t finished.

Audits must assess conformity across critical processes — design and development under Clause 7.3, corrective action under Clause 8.5.2, preventive action under Clause 8.5.3, production under Clause 7.5, and document control under Clause 4.2 — using objective evidence like device history records, audit trails, and validation records. Auditors must be trained, qualified, and independent of the area they’re auditing, with that competence documented under Clause 6.2.

If you are already ISO 9001 certified → your internal audit infrastructure transfers directly, but your checklist needs a regulatory column added for every process area, not just a conformity column.


Internal Audits vs. Supplier Audits vs. Certification Audits

Comparison infographic showing internal audits, supplier audits, and certification audits under ISO 13485.
Understanding the differences between internal, supplier, and certification audits improves audit planning and regulatory compliance.

Manufacturers frequently conflate these three, and an auditor will notice immediately if your procedure does too.

Audit TypeGoverning ClausePerformed ByPrimary Purpose
Internal AuditClause 8.2.4Trained internal personnel, independent of the area auditedVerify your own QMS conforms to the standard and your own procedures
Supplier AuditClause 7.4.1Quality or supplier quality personnelVerify external providers meet quality and regulatory requirements
Certification AuditISO/IEC 17021-1Accredited third-party Notified Body or registrarDetermine whether the full QMS meets ISO 13485 for certification

ISO 13485 requires internal audits, just as its sister standard ISO 9001 does, and they exist for two reasons: to confirm the QMS meets the standard’s requirements, and to confirm the organization actually follows its own rules. A strong internal audit program is what makes a certification audit uneventful instead of a fire drill.


Auditor Competence: What Clause 6.2 Actually Requires

This is the section most audit programs get thin on, and it’s where a surprising number of otherwise solid internal audit programs fall apart under scrutiny.

Clause 6.2 requires that anyone doing work affecting product quality — and that includes auditors — be competent based on appropriate education, training, skills, and experience. ISO 13485 doesn’t spell out a fixed list of required knowledge areas the way a checklist would, but three areas consistently show up when a Notified Body reviews auditor files:

  • The standard itself. A working knowledge of ISO 13485:2016 clause structure, not just the SOPs written to satisfy it.
  • Audit methodology. Understanding of the audit cycle — planning, evidence gathering, reporting, follow-up — along with the difference between a minor observation and a major nonconformity. ISO 13485’s own note under Clause 8.2.4 points auditors toward ISO 19011 for this.
  • Applicable regulatory context. Basic familiarity with the regulations that apply to your product and markets — 21 CFR Part 820, EU MDR, MDSAP — not full legal mastery, but enough to recognize when a finding also touches a regulatory requirement.

Competence is not the same thing as certification. ISO 13485 does not require a certified internal auditor credential, and ISO 19011 doesn’t mandate formal training either — the standard’s actual requirement is that the audit process ensure objectivity and impartiality, and that competence be evaluated and documented. In practice, though, “read and understand the internal procedure” is not evidence Notified Bodies accept as sufficient. An auditor who can’t produce a training record, a completed course certificate, or documented on-the-job evaluation showing how their competence was assessed is a finding waiting to happen — even if that person is, in fact, good at the job.

What acceptable training records look like in practice:

  • A certificate of completion from an ISO 13485 internal auditor course (typically covering the standard itself plus ISO 19011 audit methodology) — see BSI vs. ISOQAR if you’re deciding where to send your team for that training
  • Internal on-the-job qualification records — a documented mentored audit or two, signed off by a qualified lead auditor
  • A training matrix that ties each auditor to the specific processes and clauses they’re qualified to audit, refreshed when the QMS or the standard changes

Auditor independence gets checked alongside competence. The most frequent failure here isn’t a skills gap — it’s a quality manager who owns a process auditing that same process, or an auditor rotation that never actually rotates the highest-risk areas like design controls.

If you are not confident your auditor files would hold up to this list → that’s a fifteen-minute file review, not a project, and it’s worth doing before your next Notified Body visit rather than during it.


Building a Risk-Based Audit Program

The audit program must cover every process, department, and site within your QMS scope, with audit frequency determined by the status and importance of each process along with the results of prior audits. High-risk processes — design and development, production, CAPA, and complaint handling — typically need at least annual coverage, while lower-risk support functions can be audited less frequently if previous results were consistently clean.

Most manufacturers get the frequency question backwards. They audit everything on a flat annual calendar instead of weighting toward where the last audit found something. If your CAPA process had a finding last year, auditing it again on the same twelve-month clock as your HR training records is a scheduling decision an inspector will question.

If you are preparing for your first surveillance audit under the new QMSR → build your program around the regulatory cross-reference first, then layer the standard’s clause structure on top of it — not the other way around.


The Internal Audit Process, Step by Step

Infographic illustrating the ISO 13485 internal audit process from planning through CAPA verification for medical device quality management systems.
The six-step ISO 13485 internal audit process helps medical device manufacturers identify nonconformities and verify corrective actions.

Prepare a checklist based on the relevant clauses of ISO 13485, your documented procedures, and applicable regulatory requirements — a good checklist prompts investigation rather than simply confirming what’s already assumed to be true.

1. Scope and schedule. Define which processes, sites, and clauses are in scope for this audit cycle.

2. Documentation review. Analyze the quality manual, procedures, and prior audit reports before setting foot on the floor — this is where checklists get mapped to specific clauses.

3. Opening meeting. Confirm scope, objectives, and methodology with the auditee before evidence-gathering begins — this sets the tone for the entire audit.

4. Evidence gathering. Collect objective evidence through interviews, direct observation, and document/record review — no finding should be written down without evidence behind it.

5. Reporting. Findings get written up, classified by severity, and routed to the process owner and management.

6. CAPA follow-up. Every corrective action needs documented root cause analysis appropriate to the significance of the nonconformity, with effectiveness verified before the CAPA is closed.

Most teams execute steps 1 through 5 competently. Step 6 is where programs fall apart — a CAPA gets marked closed the day the immediate fix is implemented, with no verification that the fix actually held.

Trigger: If your last three internal audits found the same category of nonconformity in different words each time, that’s not three separate findings — that’s one root cause your CAPA process never actually reached.

Before your next audit cycle, check your CAPA closure process against what auditors actually verify — most teams don’t realize how thin their effectiveness checks are until someone else reviews them.


A Real Finding, Start to Finish

Steps on a page are easy to nod along with. Here’s what a properly closed finding actually looks like end to end, using one of the most common design-control gaps auditors find.

StageWhat It Looked Like
FindingDuring a design and development audit, three of twelve design verification records sampled were missing the reviewer’s signature. Work was completed and dated, but sign-off wasn’t captured.
Objective EvidenceDesign History File records DHF-114, DHF-119, and DHF-122, cross-referenced against the design review meeting minutes showing the reviews occurred.
Nonconformity Statement“Design verification records DHF-114, DHF-119, and DHF-122 lack the required reviewer signature per QMS-SOP-014, Section 6.2. Design and development control per ISO 13485:2016 Clause 7.3.6 requires verification results, including necessary actions, to be recorded.”
Root CauseInvestigation traced it to a recent SOP revision that moved the sign-off step later in the workflow. Staff hadn’t been retrained on the updated sequence — the procedure changed, but the training that should have accompanied it under Clause 6.2 didn’t happen.
CorrectionThe three records were completed retroactively with the reviewer’s signature and a note explaining the delay, reviewed and accepted by the quality manager.
Corrective Action (CAPA)Retrain design team on the revised sign-off sequence; add a mandatory signature field to the design review template so records can’t be filed incomplete.
Effectiveness CheckSample the next ten design verification records over the following quarter. Zero missing signatures required to close the CAPA as effective.

Notice what makes this closeable rather than cosmetic: the root cause isn’t “people forgot” — it’s a training gap tied to a specific procedure change, and the corrective action addresses the system, not just the three records. That’s the difference between a finding that stays closed and one that reappears with different reference numbers next year.


The Five Most Common Findings

Infographic highlighting the five most common ISO 13485 internal audit findings in medical device quality management systems.
The most common ISO 13485 internal audit findings often involve documentation, CAPA effectiveness, auditor competence, and risk-based planning.

Incomplete audit records — missing reports, plans, or linked CAPAs — is one of the most frequently cited internal audit issues. A close second is failing to apply a risk-based approach to audit planning, or simply not maintaining the internal audit schedule at all. Beyond that, auditors regularly find no timely follow-up on actions from internal audits, no records showing auditor competence against the applicable regulations, and auditors who weren’t actually impartial — reviewing work they had a hand in.

Design and development controls remain the single most frequently cited nonconformity area globally — incomplete design inputs, missing verification or validation records, undocumented design changes, or no formal design transfer procedure. See Validation & Verification Requirements for how this plays out in practice.

⚠️ If your auditor rotation lets the same person audit design controls year after year without ever being audited themselves on that same process, that’s an impartiality gap that a Notified Body will flag before you do.

If you are not confident your last internal audit would hold up under this list → that’s exactly what a structured gap assessment is for, not a guess.

Check your program against these five findings before your next audit — most gaps take under 45 minutes to identify →


MDSAP: What Changes for Multi-Market Audits

If your devices sell into more than one of the five MDSAP markets — the U.S., Canada, Australia, Brazil, or Japan — your internal audit program needs to account for a different audit model, not just an extra regulatory reference.

The Medical Device Single Audit Program lets one audit by an accredited Auditing Organization satisfy the requirements of all five participating regulators at once, in place of separate national audits. It’s built on ISO 13485:2016, but it isn’t a straight overlay — MDSAP uses a process-based audit model with a defined sequence, rather than working straight down the ISO clause list, and it maps every audit task to both the relevant ISO 13485 clause and each country’s specific regulatory requirement.

The grading system is the biggest practical difference. Where an ISO 13485 certification audit typically classifies findings as minor or major, MDSAP uses a points-based Grade 1–5 scale: nonconformities affecting clauses with indirect QMS impact start lower, direct-impact clauses start higher, and points are added for repeat findings or for a nonconforming product that was actually released. Grade 4 and 5 findings must be resolved before a certificate is issued or maintained — there’s no ambiguity about severity once the math is run.

What this means for your internal audit program: if you’re pursuing or maintaining MDSAP, your internal audits should follow the MDSAP process sequence — not just walk through ISO 13485 clauses in order — so that gaps surface in the same structure an Auditing Organization will use. The recurring findings across published MDSAP audits track closely with the same weak points internal audits should already be hunting for: open CAPAs left unclosed past a reasonable window, supplier and purchasing controls that don’t demonstrate follow-through, and root cause analysis that’s thin enough to not survive a second look.

One benefit worth knowing about: MDSAP audit reports can substitute for the FDA’s routine biennial device inspections. A well-run MDSAP program isn’t just multi-market efficiency — it can reduce how often FDA shows up separately.


What Changed: QMSR and ISO 19011:2026

Two regulatory shifts affect how internal audits get run in 2026, and both are recent enough that older internal procedures may not reflect them.

Since February 2, 2026, the FDA’s QMSR has incorporated ISO 13485:2016 by reference, replacing the former Quality System Regulation, and FDA inspections now run under Compliance Program 7382.850 rather than the old QSR framework. As covered above, the practical effect for internal audits is direct: the confidentiality safe harbor that used to apply to internal audit reports, management review records, and supplier audit reports under the old 21 CFR 820.180(c) has been removed, and FDA’s own FAQ confirms it in plain language.

Separately, ISO published the fourth edition of ISO 19011 — Guidelines for auditing management systems — on May 27, 2026, replacing the 2018 edition that had guided audit programs for nearly eight years. ISO 13485 doesn’t mandate ISO 19011 compliance directly — Clause 8.2.4 references audit principles in its own language — but Notified Bodies and experienced auditors widely treat ISO 19011 as the authoritative reference for structuring an audit program, so if your internal audit SOPs still cite the 2018 edition, expect your Notified Body to ask why.

Neither change requires rebuilding your program from scratch. Both are reasons to review your internal audit SOP this year rather than next.


Quick Audit-Readiness Checklist

✅ Audit program covers every process, site, and department in your QMS scope ✅ Audit frequency is risk-weighted, not a flat annual calendar
✅ Every checklist item maps to a specific ISO 13485 clause and the applicable regulatory requirement
✅ Auditors are independent of the area they’re reviewing, with Clause 6.2 competence records on file — not just “read and understand” sign-offs
✅ Findings are backed by objective evidence — interviews, observation, or documented records
✅ CAPA effectiveness is verified before closure, not assumed
✅ If pursuing MDSAP, internal audits follow the MDSAP process sequence, not just the ISO clause order
✅ Internal audit SOP references ISO 19011:2026, not the 2018 edition
✅ Design and development records are current — this is the single most-cited finding category


FAQ

How often does ISO 13485 require internal audits?

The standard doesn’t specify a fixed interval — it requires audits “at planned intervals” based on process risk and prior audit history. Most manufacturers audit high-risk processes like design controls and CAPA annually at minimum, with lower-risk support functions audited less frequently if history is clean.

Can the same person who performs a process also audit it?

No. Clause 8.2.4 requires auditors to be independent of the area being audited. A quality manager who owns the CAPA process, for example, shouldn’t be the one auditing CAPA compliance.

Do internal auditors need a formal certification?

No. ISO 13485 requires documented competence — education, training, skills, and experience — but doesn’t mandate a specific certification. In practice, most Notified Bodies expect more than an internal read-and-understand sign-off, so a course certificate or documented mentored-audit record is the safer standard to work toward.

Does the FDA QMSR require a separate internal audit program from ISO 13485?

No. Since the QMSR incorporates ISO 13485:2016 by reference, there isn’t a separate U.S.-specific internal audit requirement layered on top — your Clause 8.2.4 program is the audit program the FDA now expects, with the regulatory cross-reference built in.

Are internal audit reports confidential from FDA inspectors?

Not anymore. FDA’s own QMSR Final Rule FAQ confirms the confidentiality exceptions under the old 21 CFR 820.180(c) — covering internal audits, management review, and supplier audits — are not maintained under the QMSR.

What’s the difference between an internal audit and a supplier audit under ISO 13485?

Internal audits (Clause 8.2.4) evaluate your own QMS. Supplier audits (Clause 7.4.1) evaluate external providers’ ability to meet your quality and regulatory requirements. Both are required, but they’re separate programs with separate scopes.

Does MDSAP replace our ISO 13485 internal audit requirement?

No, but it changes the structure. MDSAP is built on ISO 13485 and layers in country-specific regulatory requirements from up to five markets, using a process-based sequence and a points-based Grade 1–5 nonconformity system rather than the minor/major classification used in standard certification audits.

What’s the most common reason internal audit programs fail a certification audit?

Incomplete records — missing audit reports, plans, or linked CAPAs — combined with no evidence of a risk-based approach to scheduling. Both are findings a Notified Body catches quickly because they’re procedural gaps, not technical ones.

Should we hire a consultant to run our internal audits, or can we do it ourselves?

Either can work if the auditor is properly trained and genuinely independent of the process. Many manufacturers use in-house auditors for most cycles and bring in an outside auditor periodically to test whether their internal program is actually rigorous or just familiar with its own blind spots.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching your audit obligations? Start with ISO 13485 Documentation Requirements to understand what your QMS needs on paper before you audit it.

🔹 Ready to build or strengthen your audit program? 9001Simplified’s documentation templates can shortcut the SOP-writing process without a consultant retainer.

🔹 Need the standard itself to build your checklist against? Get ISO 13485:2016 from ANSI Webstore — code CC2026 takes 5% off through the end of 2026.


An internal audit program that only exists to satisfy Clause 8.2.4 on paper was already a risk before the QMSR removed the confidentiality safe harbor. Now it’s a document an inspector can read directly. The Standards Navigator will keep tracking what QMSR enforcement and ISO 19011:2026 mean for how medical device manufacturers actually run their audit programs — not just what the clause says.


Subscribe for Medical Device Compliance Updates

Most manufacturers don’t lose a certification over one bad audit finding — they lose it over a pattern of findings their own internal audit program should have caught first. Organizations that treat Clause 8.2.4 as a paperwork requirement get surprised at surveillance. Organizations that treat it as their first line of defense rarely do.

The Standards Navigator tracks how ISO 13485, the FDA QMSR, and the standards that govern medical device audits actually work in practice — not just what the clause text says.

👉 Get updates on ISO 13485 audit requirements and QMSR enforcement changes 👉 Be first to access new medical device compliance checklists and gap assessment tools

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.