Webinar: Building a Culture of Quality: The Leadership Imperative for Operational Excellence

Discover your potential savings with our ROI Calculator

  Medical Device  >  ISO 13485 audit checklist

ISO 13485 Audit Checklist for Medical Devices

Ensure compliance with ISO 13485 by performing detailed internal audits that focus on compliance, quality, and efficiency.

Request Demo Guided Product Tour
Medical Device Audit Checklist

What is a Medical Device Audit Checklist?

A Medical Device Audit Checklist is a structured document used to evaluate compliance with ISO 13485 and other regulatory requirements. It ensures that all relevant quality processes are being reviewed and validated during an internal audit.

An audit checklist allows quality managers to document evidence of compliance based on processes, standard requirements, and process characteristics.

  • Medical device manufacturers adhere to ISO 13485 and are mandated to perform internal audits to ensure that safety and effectiveness objectives are established and maintained.
  • These audits focus on improving processes and ensuring that manufacturing, development, and other related controls meet current good manufacturing practices (GMP) and the requirements of ISO 13485.
  • These audits help determine the current status and health of the QMS and processes. The standard emphasizes that manufacturers must use a risk-based approach to all quality processes, which reiterates the value of an ISO 13485 checklist.

Why Medical Device Audit Checklists are necessary for Internal Audits

The ISO 13485 audit checklist is a crucial tool for ensuring that all regulatory requirements are met during internal audits. It helps streamline the audit process, ensuring that key areas are thoroughly reviewed, minimizing the risk of errors, and improving overall compliance and efficiency.

  • The checklist documents the questions that ensure that the process outputs meet the planned arrangements for the process.
  • The ISO 13485 internal audit checklist is a time-saving tool to help prevent mistakes and implement a lean but useful QMS.
  • Upon completion, the audit checklist helps the auditor review to reconfirm if any aspect of the evaluation process was uncovered.

Importance of Medical Device Audit Checklists

Are you a quality leader looking to streamline your internal audit workflow?

With CQ’s AI-enabled EQMS it is possible to drive efficiency into the audit lifecycle by automatically prioritizing audit findings.

Watch the demo today!
ai-based-audit-checklist-personalized-demo

Benefits of Using a Medical Device ISO 13485 Audit Checklist

Improves Audit Consistency

Standardized questions and criteria mean every auditor evaluates the same processes the same way, regardless of who conducts the audit.

Reduces Audit Preparation Time

A ready-made checklist structure means auditors spend less time building the audit from scratch and more time executing it.

Strengthens Evidence Collection

A structured checklist prompts auditors to document specific objective evidence rather than general observations.

Supports Risk-Based Auditing

Checklists can be weighted toward higher-risk processes, aligning audit effort with ISO 13485's risk-based approach.

Improves Multi-Site Standardization

A common checklist format lets organizations compare audit results and findings consistently across multiple facilities.

Strengthens Supplier Oversight

The same checklist logic extends to supplier and outsourced process audits, keeping evaluation criteria consistent internally and externally.

Improves Management Visibility

Consistent checklist data makes it easier to roll up audit findings and trends for management review.

Supports Continuous Improvement

Recurring checklist use over time surfaces patterns in findings that point to systemic process gaps, not just isolated issues.

How does ComplianceQuest Turn the Checklist into a Closed-Loop Audit Workflow?

A static checklist like a PDF or a spreadsheet only gets an audit team through the audit itself. It doesn't track what happens to findings afterward. ComplianceQuest connects the checklist to the rest of the quality system so findings move through correction, CAPA, and effectiveness verification without manual handoffs.

01

Create and Reuse Controlled Audit Checklists

Build checklists once as controlled templates and reuse them across audit cycles, sites, or supplier audits, with version control so updates propagate consistently.

02

Plan and Conduct the Audit

Schedule audits, assign auditors, and execute the checklist digitally - including on mobile devices in the field - with evidence attached directly to each checklist item.

03

Route Findings to the Right Workflow

Findings identified during the audit route automatically to the appropriate process, whether that's a nonconformance record, a CAPA, or a simple corrective note, based on severity and type.

04

Track Actions Through Closure

Corrective actions stay linked to the originating finding, so the audit record shows not just what was found but how and when it was resolved.

05

Monitor Trends and Recurring Findings

Dashboards surface recurring findings across audits and sites, helping quality teams identify systemic issues before they become repeat nonconformances or audit citations.


Request a Demo
Rental Equipment Companies
Whitepaper

Regulatory Auditing of Quality Systems of Medical Device Manufacturers

Rental Equipment Companies
Whitepaper

Guidelines for Regulatory Auditing of Quality Systems of Medical Device Manufacturers

Audit Stages of ISO 13485 Audit Checklists

Understanding Audit Stages of ISO 13485

Clause 8 of ISO 13485 focuses on the importance of audits, detailing the need for a manufacturer to plan and conduct internal audits regularly. Essentially, the audit plan must include an ISO 13485 audit checklist that details the required tasks to be performed. The lead auditor creates and maintains the audit checklist. The checklist structure allows the auditor to document compliance evidence based on processes, methods, characteristics, and the audit standard’s requirements. The critical requirements for the internal audit process:

  • Quality audits should be performed to ensure compliance of the quality system with the applicable regulatory requirements
  • The independence of the auditors shall be demonstrated consistently
  • The link between internal audits and the CAPA process shall be shown appropriately and documented
  • Internal audit plans and reports shall be documented.

ISO 13485:2016 mandates Stage 1 and Stage 2 audits, which vary in depth, duration, and scope. ISO 13485 audit checklists help prepare for both stages of an internal audit before certification or recertification.

  • Stage 1 audits can be performed in a day. An ISO auditor from the certifying body will provide a positive and negative findings report to determine whether the company is ready to proceed to stage 2.
  • A comprehensive evaluation of the organization’s compliance, stage 2 audits can last several days. The auditor will review documentation, internal audits, management reviews, controls, and all relevant processes. The auditor will produce a list of non-conformances to be corrected before certification or recertification.


What should an ISO 13485 Internal Audit Checklist cover?

An effective ISO 13485 internal audit checklist must cover every applicable process in the quality management system, not just the areas due for review in a given cycle. Design controls, purchasing, production, and post-market activities all connect to one another, so gaps in one area often surface as findings in another. Auditors must go beyond confirming that a procedure exists, they need to verify it is actually being followed in daily operations, with objective evidence to support that conclusion. A checklist built around this principle produces findings that hold up under scrutiny.

Eight Key ISO 13485 Internal Audit Areas

  • QMS Scope, Documentation, and Record Controls

    This area verifies that the documented QMS accurately reflects the organization's actual scope and processes, and that records are controlled, accessible, and retained per procedure. Auditors should confirm document approval workflows are followed, obsolete versions are removed from use, and change history is traceable. Relevant evidence includes document control logs, approval records, and version history for controlled SOPs.

  • Management Responsibility, Resources, and Competence

    This area verifies that leadership is actively driving the QMS through defined responsibilities, adequate resourcing, and periodic review - not simply signing off on it. Auditors should review whether management review meetings occur on schedule, whether quality objectives are tracked, and whether staffing and competence needs are reassessed as the organization changes. Management review minutes and training competency matrices are typical evidence.

  • Customer and Regulatory Requirements

    This area verifies that customer requirements and applicable regulatory obligations are identified, understood, and built into product and process decisions. Auditors should check that customer feedback, contract review records, and regulatory requirement tracking are current and linked to design or process changes where relevant.

  • Design, Development, and Risk Management

    This area verifies that design controls and risk management activities are executed and documented as products move through development. Auditors should review whether design inputs trace to outputs, whether verification and validation activities were completed before design transfer, and whether risk analysis was updated as the design evolved. Design history file (DHF) records and risk management file entries are typical evidence.

  • Suppliers, Purchasing, and Outsourced Processes

    This area verifies that supplier qualification, ongoing performance monitoring, and purchasing controls are functioning as documented. Auditors should confirm approved supplier lists are current, incoming inspection or acceptance criteria are being applied, and outsourced processes are covered by quality agreements. Supplier audit reports and purchasing records are useful evidence here.

  • Production, Validation, and Product Traceability

    This area verifies that manufacturing processes operate within validated parameters and that products can be traced back through production. Auditors should check process validation records, in-process inspection data, and lot or batch traceability records against actual production output.

  • Complaints, Reporting, and Post-Market Activities

    This area verifies that complaint handling, adverse event reporting, and post-market surveillance activities are timely and properly documented. Auditors should review complaint logs for investigation completeness, confirm reportable events were escalated within required timeframes, and check that post-market data feeds back into risk management and CAPA where relevant.

  • Nonconformance, CAPA, Monitoring, and Improvement

    This area verifies that nonconformances are captured, root-caused, and closed with verified effectiveness, not just documented and filed. Auditors should trace a sample of CAPAs from initiation through effectiveness check, and review whether trending of nonconformance data feeds into broader continuous improvement efforts.

All the QMS processes in one software, excellent choice.

We have implemented CQ in a new medical device start-up. The setup and implementation went very smoothly, and the support from the provider has been outstanding. The system fully supports compliance with ISO 13485.

Some of the reasons why I would recommend the software are: 100% cloud-based Allows almost a paperless Quality Management System, Excellent customer support, Simple setup and implementation, User-friendly Efficiency and security, Accessible cost for small companies.

Laura Granados,
QMS Systems Development Consultant

Itek logo
Itek logo
How to Create an Audit Checklist

How do you create an Audit Checklist that produces Actionable Findings?

A practical medical device audit checklist should do more than confirm conformance - it should help auditors document findings clearly enough that follow-up action is unambiguous. Building one involves a few deliberate steps:

  • Define the Audit Scope and Criteria - Decide which processes, sites, or product lines the audit will cover, and confirm which standard, regulation, or internal procedure each checklist item is being evaluated against.
  • Review Risks and Previous Quality Issues - Look at prior audit findings, CAPA history, and known risk areas before finalizing the checklist so higher-risk processes get proportionate attention.
  • Convert Requirements Into Evidence-Based Questions - Rephrase each requirement as a specific question that points the auditor toward the objective evidence needed to answer it, rather than a yes/no restatement of the clause.
  • Define the Evidence the Auditor Should Review - For each checklist item, note the type of record, observation, or artifact that would support a conformance determination.
  • Add Finding and Follow-Up Fields - Build in structured fields for recording the finding, its severity or classification, and the owner responsible for follow-up, so nothing depends on auditor memory after the fact.
  • Review and Update the Checklist - Revisit the checklist periodically to reflect process changes, regulatory updates, or lessons learned from previous audits, so it doesn't go stale.

Schedule a Consultation

How should an ISO 13485 Audit Checklist Address FDA QMSR Requirements?

U.S. medical device manufacturers can no longer treat ISO 13485 conformance as automatically sufficient for FDA compliance now that the Quality Management System Regulation (QMSR) incorporates ISO 13485 by reference while retaining certain FDA-specific expectations. An audit checklist built only around ISO 13485 clauses can miss these differences.

Map ISO 13485 Requirements to FDA QMSR

Identify where QMSR incorporates ISO 13485 directly and where it adds or modifies requirements, so the checklist reflects the combined obligation rather than ISO 13485 alone.

Add FDA-Specific Audit Areas

Build in checklist items for areas QMSR addresses distinctly, such as complaint file requirements and specific record-keeping expectations that go beyond the base ISO 13485 text.

Review Audit and Management Records

Confirm that internal audit and management review records meet both the ISO 13485 documentation expectations and any additional FDA record-keeping requirements.

Verify Implementation, Not Just Documentation

Extend the same evidence-based verification approach used elsewhere in the checklist to QMSR-specific areas, since documentation alone won't demonstrate actual compliance during an FDA inspection.

Maintain an FDA QMSR Addendum

Rather than rebuilding the checklist from scratch, maintain a QMSR-specific addendum alongside the core ISO 13485 checklist so both can be updated independently as either standard evolves.

Elevate Your Medical Device Audit Process With ComplianceQuest’s Medical Device Audit Checklist, Designed to Drive Accuracy, Compliance, and Efficiency Across Every Audit Stage With Flexible, Scalable Workflows.

Request an Online Demo



Quality-centric Companies Rely on CQ QMS

  • Flex
  • continental
  • 3m logo
  • YKK
  • Qorvo
  • Canon
  • Stryker
  • Lam Research
  • Just Evotech

Frequently Asked Questions

  • Key uses of an ISO 13485 audit checklist:

    • Simplifies audit planning

    • Includes corrective action deadlines

    • Acts as a comprehensive document for third-party evaluation

    • Helps to identify process gaps

    • Aids with data consolidation

    • Reduces audit preparation time


    ComplianceQuest has prepared an audit checklist for the ISO 13485 audit that helps quality leaders know the gaps, perform preventive action, and remain compliant with all regulations.

  • An ISO 13485 audit checklist is a comprehensive tool used to assess compliance with the ISO 13485 standard, which is a quality management system (QMS) standard tailored for medical devices and related products. Originally published in 1996, ISO 13485 was created to harmonize international regulatory requirements for medical devices. Significant revisions to the standard were introduced in 2003 and 2016 to reflect evolving industry needs and regulations.

  • A medical device audit checklist should include:

    • Regulatory compliance: Ensures adherence to FDA Quality Management System Regulation (QMSR), ISO 13485, and MDR.

    • Quality management system (QMS): Covers policies, procedures, and document control.

    • Design controls: Includes DHF, verification, validation, and risk management.

    • Supplier and manufacturing controls: Tracks supplier qualification, production processes, and CAPA.

    • Post-market surveillance – Manages complaints, adverse event reporting, and recalls.

  • Noncompliance may result in:

    • Regulatory warnings or penalties (e.g., FDA 483, ISO nonconformance)

    • Product recalls or holds

    • Loss of certification or market access

    • Reputational damage and financial risks

  • Yes, the ISO 13485 audit checklist can be adapted for supplier audits. It helps evaluate supplier quality systems, documentation, and risk-based performance metrics aligned with the purchasing controls of ISO 13485.

  • An internal audit should cover the clauses relevant to the scope being audited, typically spanning quality management system requirements, management responsibility, resource management, product realization (including design and production controls), and measurement, analysis, and improvement, since findings in one clause area often connect to others.

  • ISO 13485 requires internal audits at planned intervals, and most manufacturers run a full audit program annually while auditing higher-risk processes more frequently based on risk level and past findings.

  • Internal audits must be conducted by personnel who are independent of the process being audited. They don't have direct responsibility for the work under review and who have the training or competence to evaluate it objectively.

  • Software as a Medical Device (SaMD) companies generally use the same ISO 13485 checklist structure but should extend it to cover software-specific areas such as software lifecycle processes, cybersecurity controls, and software validation, since these fall outside what a hardware-focused checklist typically addresses.

  • Auditors should review records, data, and documented information that demonstrate a process was actually followed, such as approval records, test results, training records, and CAPA documentation, rather than relying on verbal confirmation that a procedure is being followed.

Mascot Astronut

Related Insights

Connect with a CQ Expert

Learn about all features of our Product, Quality, Safety, and Supplier suites. Please fill the form below to access our comprehensive demo video.

Mascot

Please confirm your details

×
spinner
Consult Now

Comments