Regulatory Audit

Regulatory audit is a formal, evidence-based examination of a medical device organization’s quality management system, records, and processes against a defined regulation or standard such as ISO 13485:2016, EU MDR 2017/745, or FDA 21 CFR Part 820. Auditors sample objective evidence and record findings as nonconformities or observations.


What is a regulatory audit?

A regulatory audit tests whether a manufacturer does what its procedures say, and whether those procedures satisfy the law of its markets. The auditor gathers objective evidence: signed records, test data, training files, complaint investigations, supplier agreements. Conformity is a conclusion drawn from evidence, not from assertions.

Audits fall into three categories. First-party audits are internal, run under ISO 13485:2016 Clause 8.2.4. Second-party audits are conducted by a customer on a supplier, which is what an OEM does when it qualifies a contract manufacturer. Third-party audits come from an independent body: a Notified Body, an MDSAP Auditing Organization, or a regulator acting under statutory inspection authority. ISO 19011:2026 (fourth edition, May 2026) is the reference guidance for first-party and second-party audits, while ISO/IEC 17021-1 governs certification bodies.


Why a regulatory audit matters in medical device development

Audit outcomes gate market access. A Notified Body cannot issue an EU MDR certificate without a successful quality management system assessment, and no CE Marking follows without that certificate. In the United States, an FDA inspection closed as Official Action Indicated (OAI) can lead to a warning letter, import alert, or consent decree.

The commercial cost is rarely the regulatory penalty itself. It is the launch slipping by months while a Design History File (DHF) is remediated, or supplier requalification that delays manufacturing. Regulatory audits exist to protect patient safety. Identifying weaknesses in complaint handling, CAPA, risk management, or production controls before devices reach patients is the primary objective.


How a regulatory audit works

Most regulatory audits follow a structured process regardless of who performs them.

A typical workflow includes:

  • Planning and scope. Define the audit criteria, scope, objectives, locations, products, and applicable regulations. Risk determines the audit depth.
  • Opening meeting. Review the audit plan, schedule, confidentiality, escorts, and communication process.
  • Evidence collection. Interview personnel, observe activities, review procedures, and trace objective evidence through the quality system. Auditors may follow a single device from design records through manufacturing, testing, release, and distribution.
  • Findings classification. Record departures from requirements as major nonconformities, minor nonconformities, or observations, depending on the applicable audit scheme.
  • Closing meeting. Present findings with supporting evidence and discuss timelines for corrective actions.
  • Response and closure. The manufacturer performs root cause analysis, implements Corrective and Preventive Actions (CAPA), submits objective evidence, and demonstrates effectiveness before findings are closed.

Audit frequency depends on the regulatory framework.

Under EU MDR 2017/745 Annex IX, Notified Bodies perform surveillance audits at least once every 12 months, with at least one unannounced audit every five years at either the manufacturer or a critical supplier.

The Medical Device Single Audit Program (MDSAP) allows a single audit to satisfy regulatory quality system requirements for Australia, Brazil, Canada, Japan, and the United States, using a three-year audit cycle.

The FDA follows a different approach. The Quality Management System Regulation (QMSR) became effective on February 2, 2026, incorporating ISO 13485:2016 into 21 CFR Part 820. On the same date, the Quality System Inspection Technique (QSIT) was retired and replaced by Compliance Program 7382.850, which organizes inspections around six quality management system areas and four additional FDA requirements, using risk management as the inspection entry point.


Common challenges and best practices

One of the most common findings is the gap between documented procedures and actual practice. Procedures may be approved and trained, yet daily operations follow different processes. Auditors quickly identify these inconsistencies through interviews and record sampling.

Another frequent weakness is ineffective internal auditing. Internal audits that consistently report no meaningful findings often indicate that the audit program itself lacks effectiveness. Since the legacy protection under 21 CFR 820.180© was removed with the implementation of the QMSR, FDA investigators may now review internal audit reports, supplier audit reports, and management review records during inspections.

Successful organizations typically:

  • Maintain complete traceability from design requirements through risk controls, verification, validation, manufacturing, and post-market surveillance.
  • Practice rapid retrieval of controlled records before audits.
  • Close CAPAs only after demonstrating objective evidence of effectiveness.
  • Perform supplier qualification through on-site audits where appropriate, not questionnaires alone.
  • Train subject matter experts to answer audit questions accurately and concisely without expanding audit scope unnecessarily.

How SJML helps with regulatory audits

SJML supports regulatory audit readiness through its Compliance-as-a-Service offering. Its QARA specialists prepare organizations for FDA inspections, EU MDR Notified Body audits, MDSAP assessments, supplier audits, and customer quality audits.

SJML assists with Design History File (DHF) remediation, technical documentation preparation, ISO 14971 risk management, ISO 13485 quality systems, CAPA implementation, supplier qualification, and audit response planning. Because manufacturing, engineering, quality, and regulatory functions operate within the same organization, audit evidence remains consistent, traceable, and readily available throughout the product lifecycle.

Talk to SJML’s QARA team →


Frequently asked questions

What is the difference between a regulatory audit and an inspection?

A regulatory audit evaluates conformity against a certification standard or regulatory quality system and is typically performed by a Notified Body, certification body, MDSAP Auditing Organization, or the organization itself.
An inspection is performed by a government regulatory authority, such as the FDA, exercising legal enforcement powers. Inspections may directly result in warning letters, import alerts, injunctions, or other enforcement actions, whereas audits generally result in nonconformities, certificate suspension, or certificate withdrawal.

How often will a Notified Body audit a manufacturer?

Under EU MDR 2017/745 Annex IX, surveillance audits occur at least once every 12 months throughout the certification cycle.
In addition, Notified Bodies must perform at least one unannounced audit during each five-year certification cycle, with additional audits performed whenever risk indicators justify increased oversight.

Can the FDA review internal audit reports?

Yes.
The exemption previously contained in 21 CFR 820.180© was removed when the FDA Quality Management System Regulation (QMSR) became effective on February 2, 2026. FDA investigators may now request internal audit reports, supplier audit reports, and management review records during inspections.
Organizations should therefore maintain complete documentation showing that audit findings were investigated, corrected, and effectively closed.

Does an ISO 13485 certificate satisfy FDA requirements?

No.
Although ISO 13485:2016 is incorporated by reference into the FDA QMSR, FDA regulations include additional requirements covering records, labeling and packaging controls, complaint handling, and other FDA-specific provisions.
Holding an ISO 13485 certificate or completing an MDSAP audit does not replace an FDA inspection. Manufacturers remain subject to FDA inspection against the complete QMSR requirements.


Related terms

  • Corrective and Preventive Action (CAPA)
  • Quality Management System (QMS)
  • MDSAP
  • Nonconformance Report (NCR)
  • Supplier Qualification

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

Ask Sygma AI

AI-Powered Assistant

SJ Assistant