Webinar: Building a Culture of Quality: The Leadership Imperative for Operational Excellence
Discover your potential savings with our ROI Calculator
Self-guided Product Tours
Product Demo Videos
Pricing
Recent Analyst Insights
Featured Analyst Insights
2026 Gartner® Magic Quadrant™ for Quality Management System Software
Recent Blogs
Recent Infographics
Recent Case Studies
Featured Case Study
ComplianceQuest Medical Devices QMS Success Stories eBook
Recent Checklists
Featured Checklist
Complaint Handling Process for MedTech and Life Science Companies
Course Offerings
Recent CQ Guides
Datasheets
Brochures
Demo Center
Videos
Podcasts
Recent Webinars
Webinar
Unlocking the Value of Complaints
Recent Whitepapers
Whitepaper
Why You Need to Digitally Transform Your QMS
Compliance
Toolkits
Infographic
Safety Technology Trends to Watch in 2023 (Infographic)
Recent Toolkits
Events and Webinars
Events
Upcoming Webinars
Featured Event
The MedTech Conference 2026
18 Oct, 2026
Boston, MA
About
About ComplianceQuest
ComplianceQuest is the #1 AI-powered Quality, Risk, and Compliance (QRC) platform that connects Product, Quality, Manufacturing, People, Suppliers and Customers in a single system.
Built on Salesforce, the platform delivers end-to-end visibility, AI-driven intelligence, and enterprise-scale execution, enabling organizations to manage risk, ensure regulatory compliance, and turn quality into a driver of growth.
Meet the Leadership Team
Careers
Where Your Career Takes Flight: Join our dynamic team and be part of an innovative, collaborative and rewarding workplace culture.
Corporate Citizenship
Impact Through Action: How the ComplianceQuest team supports social causes and community engagement
Customers & Testimonials
Newsroom
The Pulse of ComplianceQuest: Our newsroom shares stories of innovation, progress, and change
Partners
Stronger Together: How our partnerships drive success and innovation
Upcoming Events
Ensure compliance with ISO 13485 by performing detailed internal audits that focus on compliance, quality, and efficiency.
Please confirm your details
By submitting this form you agree that we can store and process your personal data as per our Privacy Statement. We will never sell your personal information to any third party.
Enter Captcha
A Medical Device Audit Checklist is a structured document used to evaluate compliance with ISO 13485 and other regulatory requirements. It ensures that all relevant quality processes are being reviewed and validated during an internal audit.
An audit checklist allows quality managers to document evidence of compliance based on processes, standard requirements, and process characteristics.
The ISO 13485 audit checklist is a crucial tool for ensuring that all regulatory requirements are met during internal audits. It helps streamline the audit process, ensuring that key areas are thoroughly reviewed, minimizing the risk of errors, and improving overall compliance and efficiency.
With CQ’s AI-enabled EQMS it is possible to drive efficiency into the audit lifecycle by automatically prioritizing audit findings.
Standardized questions and criteria mean every auditor evaluates the same processes the same way, regardless of who conducts the audit.
A ready-made checklist structure means auditors spend less time building the audit from scratch and more time executing it.
A structured checklist prompts auditors to document specific objective evidence rather than general observations.
Checklists can be weighted toward higher-risk processes, aligning audit effort with ISO 13485's risk-based approach.
A common checklist format lets organizations compare audit results and findings consistently across multiple facilities.
The same checklist logic extends to supplier and outsourced process audits, keeping evaluation criteria consistent internally and externally.
Consistent checklist data makes it easier to roll up audit findings and trends for management review.
Recurring checklist use over time surfaces patterns in findings that point to systemic process gaps, not just isolated issues.
A static checklist like a PDF or a spreadsheet only gets an audit team through the audit itself. It doesn't track what happens to findings afterward. ComplianceQuest connects the checklist to the rest of the quality system so findings move through correction, CAPA, and effectiveness verification without manual handoffs.
Build checklists once as controlled templates and reuse them across audit cycles, sites, or supplier audits, with version control so updates propagate consistently.
Schedule audits, assign auditors, and execute the checklist digitally - including on mobile devices in the field - with evidence attached directly to each checklist item.
Findings identified during the audit route automatically to the appropriate process, whether that's a nonconformance record, a CAPA, or a simple corrective note, based on severity and type.
Corrective actions stay linked to the originating finding, so the audit record shows not just what was found but how and when it was resolved.
Dashboards surface recurring findings across audits and sites, helping quality teams identify systemic issues before they become repeat nonconformances or audit citations.
Clause 8 of ISO 13485 focuses on the importance of audits, detailing the need for a manufacturer to plan and conduct internal audits regularly. Essentially, the audit plan must include an ISO 13485 audit checklist that details the required tasks to be performed. The lead auditor creates and maintains the audit checklist. The checklist structure allows the auditor to document compliance evidence based on processes, methods, characteristics, and the audit standard’s requirements. The critical requirements for the internal audit process:
ISO 13485:2016 mandates Stage 1 and Stage 2 audits, which vary in depth, duration, and scope. ISO 13485 audit checklists help prepare for both stages of an internal audit before certification or recertification.
An effective ISO 13485 internal audit checklist must cover every applicable process in the quality management system, not just the areas due for review in a given cycle. Design controls, purchasing, production, and post-market activities all connect to one another, so gaps in one area often surface as findings in another. Auditors must go beyond confirming that a procedure exists, they need to verify it is actually being followed in daily operations, with objective evidence to support that conclusion. A checklist built around this principle produces findings that hold up under scrutiny.
QMS Scope, Documentation, and Record Controls
This area verifies that the documented QMS accurately reflects the organization's actual scope and processes, and that records are controlled, accessible, and retained per procedure. Auditors should confirm document approval workflows are followed, obsolete versions are removed from use, and change history is traceable. Relevant evidence includes document control logs, approval records, and version history for controlled SOPs.
Management Responsibility, Resources, and Competence
This area verifies that leadership is actively driving the QMS through defined responsibilities, adequate resourcing, and periodic review - not simply signing off on it. Auditors should review whether management review meetings occur on schedule, whether quality objectives are tracked, and whether staffing and competence needs are reassessed as the organization changes. Management review minutes and training competency matrices are typical evidence.
Customer and Regulatory Requirements
This area verifies that customer requirements and applicable regulatory obligations are identified, understood, and built into product and process decisions. Auditors should check that customer feedback, contract review records, and regulatory requirement tracking are current and linked to design or process changes where relevant.
Design, Development, and Risk Management
This area verifies that design controls and risk management activities are executed and documented as products move through development. Auditors should review whether design inputs trace to outputs, whether verification and validation activities were completed before design transfer, and whether risk analysis was updated as the design evolved. Design history file (DHF) records and risk management file entries are typical evidence.
Suppliers, Purchasing, and Outsourced Processes
This area verifies that supplier qualification, ongoing performance monitoring, and purchasing controls are functioning as documented. Auditors should confirm approved supplier lists are current, incoming inspection or acceptance criteria are being applied, and outsourced processes are covered by quality agreements. Supplier audit reports and purchasing records are useful evidence here.
Production, Validation, and Product Traceability
This area verifies that manufacturing processes operate within validated parameters and that products can be traced back through production. Auditors should check process validation records, in-process inspection data, and lot or batch traceability records against actual production output.
Complaints, Reporting, and Post-Market Activities
This area verifies that complaint handling, adverse event reporting, and post-market surveillance activities are timely and properly documented. Auditors should review complaint logs for investigation completeness, confirm reportable events were escalated within required timeframes, and check that post-market data feeds back into risk management and CAPA where relevant.
Nonconformance, CAPA, Monitoring, and Improvement
This area verifies that nonconformances are captured, root-caused, and closed with verified effectiveness, not just documented and filed. Auditors should trace a sample of CAPAs from initiation through effectiveness check, and review whether trending of nonconformance data feeds into broader continuous improvement efforts.
We have implemented CQ in a new medical device start-up. The setup and implementation went very smoothly, and the support from the provider has been outstanding. The system fully supports compliance with ISO 13485.
Some of the reasons why I would recommend the software are: 100% cloud-based Allows almost a paperless Quality Management System, Excellent customer support, Simple setup and implementation, User-friendly Efficiency and security, Accessible cost for small companies.
Laura Granados,QMS Systems Development Consultant
A practical medical device audit checklist should do more than confirm conformance - it should help auditors document findings clearly enough that follow-up action is unambiguous. Building one involves a few deliberate steps:
U.S. medical device manufacturers can no longer treat ISO 13485 conformance as automatically sufficient for FDA compliance now that the Quality Management System Regulation (QMSR) incorporates ISO 13485 by reference while retaining certain FDA-specific expectations. An audit checklist built only around ISO 13485 clauses can miss these differences.
Map ISO 13485 Requirements to FDA QMSR
Identify where QMSR incorporates ISO 13485 directly and where it adds or modifies requirements, so the checklist reflects the combined obligation rather than ISO 13485 alone.
Add FDA-Specific Audit Areas
Build in checklist items for areas QMSR addresses distinctly, such as complaint file requirements and specific record-keeping expectations that go beyond the base ISO 13485 text.
Review Audit and Management Records
Confirm that internal audit and management review records meet both the ISO 13485 documentation expectations and any additional FDA record-keeping requirements.
Verify Implementation, Not Just Documentation
Extend the same evidence-based verification approach used elsewhere in the checklist to QMSR-specific areas, since documentation alone won't demonstrate actual compliance during an FDA inspection.
Maintain an FDA QMSR Addendum
Rather than rebuilding the checklist from scratch, maintain a QMSR-specific addendum alongside the core ISO 13485 checklist so both can be updated independently as either standard evolves.
One of our customers is a leading manufacturer of specialty chemicals. To produce these chemicals, the company uses vegetable oils…
The pandemic has accelerated the adoption of remote audits, even in highly regulated industries like manufacturing and medical devices. With…
At ComplianceQuest, we recently published a whitepaper on conducting remote audits for both quality and safety management. The paper focused…
Internal Audit Tool Kit for Medical Device and IVD Manufacturer (Part – 1)
Checklist | June 18th, 2021
Internal Audit Tool Kit for Medical Device and IVD Manufacturer (Part – 2)
Understanding the Medical Device Risk based Approach in a QMS
Checklist | September 27th, 2021
Does your Medical Device Technical File Comply with MDR 2017/745 Requirements?
Checklist | August 24th, 2021
Medical Device Software Lifecycle Processes Checklist (Part 1)
Checklist | August 5th, 2021
Medical Device Software Lifecycle Processes Checklist (Part 2)
Key uses of an ISO 13485 audit checklist:
Simplifies audit planning
Includes corrective action deadlines
Acts as a comprehensive document for third-party evaluation
Helps to identify process gaps
Aids with data consolidation
Reduces audit preparation time
ComplianceQuest has prepared an audit checklist for the ISO 13485 audit that helps quality leaders know the gaps, perform preventive action, and remain compliant with all regulations.
An ISO 13485 audit checklist is a comprehensive tool used to assess compliance with the ISO 13485 standard, which is a quality management system (QMS) standard tailored for medical devices and related products. Originally published in 1996, ISO 13485 was created to harmonize international regulatory requirements for medical devices. Significant revisions to the standard were introduced in 2003 and 2016 to reflect evolving industry needs and regulations.
A medical device audit checklist should include:
Regulatory compliance: Ensures adherence to FDA Quality Management System Regulation (QMSR), ISO 13485, and MDR.
Quality management system (QMS): Covers policies, procedures, and document control.
Design controls: Includes DHF, verification, validation, and risk management.
Supplier and manufacturing controls: Tracks supplier qualification, production processes, and CAPA.
Post-market surveillance – Manages complaints, adverse event reporting, and recalls.
Noncompliance may result in:
Regulatory warnings or penalties (e.g., FDA 483, ISO nonconformance)
Product recalls or holds
Loss of certification or market access
Reputational damage and financial risks
Yes, the ISO 13485 audit checklist can be adapted for supplier audits. It helps evaluate supplier quality systems, documentation, and risk-based performance metrics aligned with the purchasing controls of ISO 13485.
An internal audit should cover the clauses relevant to the scope being audited, typically spanning quality management system requirements, management responsibility, resource management, product realization (including design and production controls), and measurement, analysis, and improvement, since findings in one clause area often connect to others.
ISO 13485 requires internal audits at planned intervals, and most manufacturers run a full audit program annually while auditing higher-risk processes more frequently based on risk level and past findings.
Internal audits must be conducted by personnel who are independent of the process being audited. They don't have direct responsibility for the work under review and who have the training or competence to evaluate it objectively.
Software as a Medical Device (SaMD) companies generally use the same ISO 13485 checklist structure but should extend it to cover software-specific areas such as software lifecycle processes, cybersecurity controls, and software validation, since these fall outside what a hardware-focused checklist typically addresses.
Auditors should review records, data, and documented information that demonstrate a process was actually followed, such as approval records, test results, training records, and CAPA documentation, rather than relying on verbal confirmation that a procedure is being followed.
For more than 25 years, medical device manufacturers prepared for FDA inspections under QSIT (Quality System Inspection Technique). That era…
Medical device manufacturers may outsource components, processes, testing, sterilization, software,…
TL;DR Release delay is usually treated as a quality-review capacity…
A leading industrial manufacturer had seen overall incident rates fall…
Learn about all features of our Product, Quality, Safety, and Supplier suites. Please fill the form below to access our comprehensive demo video.