ISO 13485 Internal Audit Checklist

Introduction

ISO 13485:2016 Clause 8.2.4 requires internal audits at planned intervals to verify your quality management system actually works.

For companies selling into the US, 21 CFR 820.22 historically carried the same requirement. The FDA's new Quality Management System Regulation (effective February 2026) now incorporates ISO 13485 directly rather than running a separate audit clause.

Here's the real point of the exercise: a good internal audit catches nonconformities before a registrar or FDA investigator does.

Many quality teams pull a checklist template off the internet and run it against their process. The problem? That template wasn't built around their documented procedures.

It doesn't reference their specific SOPs, their DHF format, or their CAPA numbering system. The gaps hide until a certification auditor finds them and writes a major nonconformity.

This guide gives you a clause-by-clause checklist, the process to run the audit, and how to classify findings correctly once you have them.

TL;DR

  • Map every checklist line to a specific ISO 13485 clause and the internal procedure it verifies
  • Cover six core areas: management responsibility, resources, design controls, production, CAPA, and documentation
  • Follow a repeatable process — plan, prepare, conduct fieldwork, report, and follow up
  • Classify findings by severity using a structured framework so corrective action stays proportionate
  • Treat internal audits as a way to find real process gaps, not an annual checkbox

What You Need Before Starting Your ISO 13485 Internal Audit

Before you schedule anything, gather the right reference materials and confirm your auditor meets the independence requirement in Clause 8.2.4. Skipping this step is how audits turn into unstructured document hunts.

Documents and Records You'll Need

Pull these together before the audit date:

  • The current text of ISO 13485:2016, plus applicable regulatory requirements (for U.S. devices, FDA 21 CFR Part 820)
  • Your quality manual and the specific SOPs governing the process under review
  • Prior internal and external audit reports, plus any open CAPAs tied to that area
  • A representative sample of Design History File (DHF), Device Master Record (DMR), and Device History Record (DHR) records for the process being audited

A document system with revision history and clause-mapped linkages beats folder-by-folder shared-drive searches. When each record is already tagged to its governing clause and related training file, auditors can pull evidence in minutes instead of hours.

Preconditions: Auditor Independence and Scheduling

Clause 8.2.4 of ISO 13485:2016 requires that auditors not audit their own work area. In a five-person quality department, that usually means cross-training a second qualified auditor so nobody reviews a process they own.

Publish the audit schedule in advance. Weight it by:

  • Process risk and criticality
  • Results from the previous audit cycle
  • How much a process has changed since it was last reviewed

Surprise audits erode trust and rarely produce better evidence than an announced one.

The ISO 13485 Internal Audit Checklist: Core Areas to Cover

An effective checklist is organized by clause and cross-references the historical FDA counterpart for US-market companies. Keep it in a maintained spreadsheet, not a static PDF that goes stale after year one.

ISO 13485:2016 Clause Historical 21 CFR Part 820 Counterpart
5.3–5.6 Management responsibility 820.20
6.2–6.4 Resource management 820.25, 820.70
7.3 Design and development 820.30
7.4–7.5 Purchasing and production 820.50, 820.70–820.75
8.2–8.5 Feedback, nonconformity, CAPA 820.100, 820.198
4.2.4–4.2.5 Document and record control 820.40, 820.180

Under the current QMSR, ISO 13485 is incorporated directly, so treat the 820 column as historical context, not a live citation.

Management Responsibility and Quality Policy

  • Quality policy and measurable objectives are documented, communicated, and reviewed at planned management reviews
  • Internal audit program defines criteria, scope, frequency, and methods
  • Findings from the last cycle are closed with evidence, not only logged

Resource Management (Personnel, Infrastructure, Work Environment)

  • Training records show education, skill, and experience match each QMS role
  • Equipment maintenance and calibration schedules are current
  • Work environment controls (for example, cleanliness for sterile processes) are documented and followed on the floor

Design and Development Controls

  • Design History File includes inputs, outputs, verification, validation, and design reviews
  • Risk management file is complete and aligned to ISO 14971
  • Design changes receive documented review and re-verification before implementation

Production and Process Controls

  • Process validation records exist for special processes such as sterilization
  • Device History Records match the Device Master Record line for line
  • Supplier evaluation and ongoing performance monitoring are current and tied to purchasing specifications

CAPA and Nonconforming Product Management

  • Nonconformities are investigated to root cause
  • CAPA effectiveness is verified with objective evidence before closure
  • Complaint data and CAPA trends feed into management review

Documentation and Records Control

  • Document control covers approval, revision, distribution, and removal of obsolete copies at points of use
  • Records are retained per the defined schedule, legible, and retrievable when an auditor requests them

Six core ISO 13485 audit areas mapped to clauses and FDA counterparts

How to Conduct the Internal Audit: A Step-by-Step Process

ISO 13485 doesn't mandate an exact number of steps, but a mature program typically runs through six steps from planning to follow-up.

  1. Plan and announce the schedule — Build an annual plan weighted by process risk and prior findings, then communicate it to process owners in advance. This builds trust rather than triggering "gotcha" defensiveness.
  2. Prepare the individual audit — Define scope, criteria, and checklist items for that specific process. Review the previous audit report and any open CAPAs before you walk in.
  3. Conduct the fieldwork — Hold an opening meeting, then gather objective evidence via document review, record sampling, staff interviews, and direct process observation.
  4. Identify and record findings — Document each finding against a specific clause or procedure, note the objective evidence observed, and assign a preliminary severity rating.
  5. Report and close — Hold a closing meeting to share findings immediately, then issue the written report within your program's defined turnaround time.
  6. Follow up — Verify corrective actions were implemented and actually worked, then feed the results into the next management review.

Skipping step six is the most common gap. Teams close the audit report but never confirm the fix stuck, so the same finding resurfaces next cycle.

Interpreting Audit Findings: From Conformity to Nonconformity

Misclassifying a finding's severity is one of the most common internal audit errors. Rate something a minor nonconformity when it's actually systemic, and the fix never addresses the root cause. Rate a genuine major as minor, and you walk into your certification audit exposed.

A structured framework, commonly summarized as the 5 C's, helps document a finding consistently:

  • Condition: What you actually observed
  • Criteria: The requirement it should have met
  • Cause: Why the gap exists
  • Consequence: What could happen if it's not fixed
  • Corrective Action: What will actually address the root cause

Once the finding is documented, rate its severity so the response matches the risk:

Conformity or Observation: The process meets the requirement. Document it as a strength or improvement opportunity. No mandatory corrective action, but track it for consistency across future audits.

Minor Nonconformity: An isolated lapse in following a documented procedure. Requires correction and a root cause review, but doesn't mean the process itself has failed.

Major Nonconformity: A systemic breakdown, a missing required process, or anything that could affect product safety or regulatory compliance. Requires immediate CAPA and can jeopardize certification if left unresolved.

MDSAP auditors go further and grade findings on a 1-to-5 severity scale rather than a simple minor/major split. That model is useful if your team needs finer-grained escalation criteria.

ISO 13485 audit finding severity levels and 5 Cs documentation framework

Common Mistakes and Best Practices for an Audit-Ready QMS

Watch for these patterns when you harden the QMS for audit:

  • Generic checklist copy-paste: If each line item is not mapped to your documented procedures, clause-specific evidence gaps stay hidden until a registrar finds them.
  • CAPA for every finding: Reserve CAPA for systemic issues. Handle an isolated minor lapse with a documented correction and a monitoring period. One-off CAPAs bury the findings that matter.
  • Uncalibrated severity ratings: Run mock audits and compare how different auditors score the same evidence. If ratings diverge, tighten severity criteria before the next real cycle.

Shared criteria only help if more than one person can apply them. Audit and CAPA competence should not sit with a single senior auditor.

QMS Learning's Medical Device & Life Sciences pathway (pilot cohort Q3 2026) pairs role-specific ISO 13485, FDA 21 CFR Part 820, and ISO 14971 training with an AI Workbench that helps teams pick the right method and export registrar-ready evidence.

Frequently Asked Questions

How do I prepare an ISO 13485 audit checklist?

Start by identifying the applicable clauses, then map each one to your internal procedures and records. Organize them into a scored checklist format, and test and update it after every audit cycle.

What are the 7 steps in the ISO 13485 audit process?

The usual cycle is: plan the program, prepare scope and checklist, open the audit, collect evidence, record findings, report results, and follow up on corrective actions. Your procedure may group a couple of these, but the full loop still covers all seven.

What is an ISO 13485 audit?

An ISO 13485 audit is a structured evaluation of whether your quality management system conforms to the standard and is effectively implemented and maintained. Internal audits are self-conducted; external audits are run by a registrar or regulator.

What are the 5 C's of audit findings?

Condition, Criteria, Cause, Consequence, and Corrective Action. Documenting all five gives a finding enough context that anyone reading the report later understands what happened and why it matters.

How often should ISO 13485 internal audits be conducted?

The standard requires "planned intervals," not a fixed number. Most organizations audit at least annually—FDA guidance has long pointed to no more than 12 months between audits—with higher-risk processes reviewed more often.

Who can perform an ISO 13485 internal audit?

Any trained, objective person who doesn't audit their own work area can serve as an internal auditor. In smaller organizations, this often means cross-training a second staff member to maintain independence.