Medical Device Single Audit Program (MDSAP)

Medical Device Single Audit Program (MDSAP) is an international program that lets one audit of a manufacturer’s quality management system satisfy the regulatory requirements of five participating authorities: the US FDA, Health Canada, Brazil’s ANVISA, Australia’s TGA, and Japan’s MHLW/PMDA. Audits follow ISO 13485:2016 plus jurisdiction-specific rules and are performed by recognized Auditing Organizations.


What is the Medical Device Single Audit Program (MDSAP)?

MDSAP grew out of the International Medical Device Regulators Forum (IMDRF), which ran a three-year pilot before the program moved into full operation. The idea is simple: instead of five regulators sending five separate inspection teams to the same factory, one recognized third party audits the quality management system (QMS) once, against a shared audit model, and shares the report with every participating authority.

The audit sits at the QMS level, not the product. It does not approve a device, grant CE marking, or replace a 510(k). What it does is evidence that the systems producing the device (design controls, production controls, complaint handling, CAPA) meet the quality requirements of each jurisdiction the manufacturer sells into.


Why the Medical Device Single Audit Program (MDSAP) matters in medical device development

For manufacturers with multi-market ambitions, audit load is a real operating cost. Each inspection consumes weeks of QA and RA time and carries its own findings and remediation cycle. MDSAP collapses that into one annual event on a three-year certification cycle.

Health Canada makes the calculation easy: an MDSAP certificate is required to hold a Medical Device License. Without it, the Canadian market is closed. For the other four authorities, participation is voluntary but carries weight. FDA will accept an MDSAP audit report in place of a routine surveillance inspection, though for-cause inspections, pre-approval inspections, and compliance follow-ups still happen. ANVISA uses audit outputs as input to its own pre-market and post-market decisions, which can shorten Brazilian timelines considerably.

The stakes cut the other way too. Because one report reaches five regulators, a significant nonconformity is visible to all of them at once. There is no quiet remediation in a single jurisdiction.


How the Medical Device Single Audit Program (MDSAP) audit works

The audit criteria are ISO 13485:2016 in full, plus the country-specific requirements each authority layers on top: 21 CFR Part 820 (renamed the Quality Management System Regulation, effective February 2, 2026, and now incorporating ISO 13485:2016 by reference), 21 CFR Parts 803 and 806 for reporting and corrections, Canada’s Medical Devices Regulations, Brazil’s RDC ANVISA 16/2013 good manufacturing practices, and the Australian and Japanese equivalents.

Auditors work through a published Audit Approach document that splits the QMS into seven process areas and hundreds of tasks. Four are primary processes:

  • Management
  • Measurement, Analysis, and Improvement
  • Design and Development
  • Production and Service Controls

There are three supporting processes:

  • Purchasing
  • Device Marketing Authorization and Facility Registration
  • Medical Device Adverse Events and Advisory Notices Reporting

The last two exist purely to capture jurisdiction-specific regulatory obligations that ISO 13485 does not address.

The sequence is fixed and risk-weighted. Auditors begin with Management, then trace linkages between processes, checking that the output of one becomes a controlled input to the next. Design and development are skipped if the manufacturer does not perform them, though outsourcing design does not remove the obligation.

Nonconformities are graded numerically rather than described qualitatively. A base score derives from the task involved, with escalations for missing processes and repeat findings. Scores above a defined threshold trigger a notification to the regulatory authorities.


Common challenges and best practices

The most frequent failure is treating MDSAP as an ISO 13485 audit with extra paperwork. It is not. ISO 13485 auditors sample; MDSAP auditors follow a script. If a task exists in the Audit Approach, it will be asked, and the answer needs a record behind it.

A second problem is scope selection. Manufacturers list the participating countries they market in, and only those requirements apply. Listing a country speculatively adds audit burden with no benefit.

Preparation that works looks like this. Map every procedure and record to the seven process areas and the specific tasks under each. Run a gap assessment against the Audit Approach itself, not against a summary of it. Rehearse evidence retrieval, because auditors are timeboxed per task and slow retrieval reads as poor control. Make sure post-market data actually feeds CAPA and management review with traceable links, since the interaction between processes is what auditors probe hardest.

Teams also underestimate the supporting processes. Facility registration status, license numbers, and adverse event reporting timelines are checked against public regulatory databases. Discrepancies are easy to find and hard to explain.


How SJML helps with the Medical Device Single Audit Program (MDSAP)

Syrma Johari MedTech is an end-to-end medical device CDMO operating a quality management system certified to ISO 13485 and aligned to FDA, EU MDR/IVDR, MDSAP, Health Canada, and CDSCO frameworks. Our QARA practice supports manufacturers with QMS build-out and remediation, DHF and technical file preparation, supplier qualification and audits, complaint handling with root cause analysis and CAPA, and post-market surveillance and vigilance planning. Manufacturing sites run process validation, traceability through an integrated MES, and cleanroom and PCBA operations under the same quality system.

Talk to SJML’s QARA team →


Frequently asked questions

Is MDSAP mandatory?

Only in Canada. Health Canada requires a valid MDSAP certificate from a recognized Auditing Organization before it will issue or maintain a Medical Device License. The FDA, ANVISA, TGA, and MHLW/PMDA treat participation as voluntary, though each accepts or uses MDSAP audit reports within its own oversight process to varying degrees.

Does MDSAP replace ISO 13485 certification?

No, but the two combine. MDSAP audits assess conformity to ISO 13485:2016 as their base standard, so most Auditing Organizations issue an ISO 13485 certificate alongside the MDSAP certificate and run both within one audit cycle. The MDSAP certificate adds the jurisdiction-specific regulatory requirements that ISO 13485 alone does not cover.

Does an MDSAP certificate get me CE marking?

No. The European Union holds observer status in MDSAP and does not accept MDSAP audits for conformity assessment. CE marking under EU MDR 2017/745 or IVDR 2017/746 requires a separate notified body assessment of both the QMS and the technical documentation.

How long is the MDSAP audit cycle?

Three years. An initial certification audit covers the full quality management system, followed by surveillance audits in years one and two that sample process areas, then a recertification audit in year three. Audit duration depends on site count, headcount, device risk class, and how many participating jurisdictions are in scope.


Related terms

  • ISO 13485
  • Quality Management System Regulation (QMSR)
  • CAPA
  • Design Controls
  • Post-Market Surveillance

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

Ask Sygma AI

AI-Powered Assistant

SJ Assistant