An ISO 13485 audit is more than a review of documents. It is an opportunity to confirm that a medical device quality management system (QMS) is properly implemented, maintained, and supported by objective evidence. For quality managers, using an ISO 13485 audit checklist can make audit preparation more organized and help ensure important processes are not overlooked.
A well-prepared checklist should reflect the organization's actual activities, risks, responsibilities, and documented processes. It should also help auditors record evidence, identify gaps, and follow up on audit findings.
1. Review QMS Documentation and Document Control
Start by checking whether required QMS documents are available, approved, current, and properly controlled. Review the quality manual, procedures, work instructions, forms, and records relevant to the organization's processes.
A practical document control audit checklist should verify document approval, revision status, availability at points of use, and control of obsolete documents. Records should also be identifiable, legible, retrievable, and protected from unintended changes.
2. Check Management Responsibility and Resources
An ISO 13485 internal audit should examine whether management responsibilities and authorities are clearly defined. Quality objectives, management review activities, communication, and resource availability should be reviewed to determine whether the QMS is being effectively supported.
Auditors can also review training and competency records to confirm that personnel performing quality-related activities have the appropriate knowledge and skills.
3. Examine Risk Management and Product Realization
Risk management is an important area of medical device quality management. The audit should consider whether applicable risks are identified, evaluated, controlled, and reviewed throughout relevant product realization activities.
Using a risk management audit checklist can help quality managers review connections between risk management activities, design and development, production controls, and post-production information.
4. Review Design, Purchasing, and Production Controls
The ISO 13485 internal audit checklist should cover design and development controls where applicable, including planning, inputs, outputs, verification, validation, changes, and design records.
Supplier and purchasing controls also deserve attention. A supplier audit checklist can help assess supplier evaluation, selection, monitoring, purchasing information, and verification of purchased products or services.
For production and service activities, review process controls, equipment, work environments, identification and traceability, product preservation, and monitoring records as applicable.
5. Check CAPA, Complaints, and Nonconformities
Audit preparation should include a review of how the organization handles nonconforming outputs, corrective actions, complaints, and related investigations. Check whether problems are documented, causes are appropriately investigated, actions are implemented, and effectiveness is evaluated.
These records can provide valuable internal audit evidence and may reveal recurring issues that require further attention.
6. Prepare Audit Questions and Evidence
Good ISO 13485 audit questions should encourage auditors to verify how processes actually operate rather than simply asking whether a procedure exists. Interview employees, observe activities, and sample relevant records to establish objective evidence. An ISO 13485 clause-by-clause audit guide can also help auditors systematically review applicable areas and avoid missing important points during the audit.
A useful audit preparation checklist should therefore include documents to review, personnel to interview, processes to sample, and records to verify.
7. Record Findings and Follow Up
During the ISO 13485 audit, document evidence clearly and relate findings to the applicable requirement or established process. Findings should be communicated consistently, investigated where necessary, and followed through with corrective action and effectiveness review.
For organizations preparing for an ISO 13485 certification audit, having structured, editable QMS documentation can simplify preparation and help teams organize their evidence. An ISO 13485 audit checklist can be supported by ready-to-customize manuals, procedures, forms, and related documents that can be adapted to actual processes.
Overall, an effective checklist should be practical rather than simply a long list of questions. It should help quality managers evaluate implementation, collect meaningful evidence, identify gaps, and improve audit readiness.