MDSAP Audits: Process Chapters, Grading and How to Prepare

Introduction

The Medical Device Single Audit Program lets one audit of a quality management system satisfy five regulatory authorities: Australia’s TGA, Brazil’s ANVISA, Health Canada, Japan’s MHLW and PMDA, and the US FDA. The audit is performed by an authorised Auditing Organization against ISO 13485 plus the country-specific requirements of each participating jurisdiction. A successful audit produces a certificate valid for three years, with surveillance audits in between.

That is the administrative description, and it is not the reason MDSAP is difficult. The difficulty is structural: MDSAP audits by process, in a fixed sequence of seven chapters, while almost every ISO 13485 quality system is organised by clause. Remapping one onto the other is the single most underestimated piece of preparation, and it is where teams that were confident about their ISO 13485 certification discover that the audit does not follow the shape of their documentation.

This guide covers the seven process chapters and what auditors look for in each, how the points-based grading works and how a finding escalates, the audit cycle and what each stage costs in days, the market access value by country, and a preparation sequence built to run backwards from the audit date. There is a free Excel checklist further down, built on the same audit approach the Auditing Organization uses.

Table of Contents

What MDSAP is, and who it is for

Instead of being audited separately by each authority, a manufacturer is audited once against a unified set of requirements, and the resulting report is accepted by all participating regulators. The audit is performed by an Auditing Organization that has been assessed and authorised by the Regulatory Authorities to conduct MDSAP audits and issue certificates.

The five participating authorities are the TGA in Australia, ANVISA in Brazil, Health Canada, the MHLW and PMDA in Japan, and the FDA in the United States. Observers and affiliate members — the WHO, the European Union, the UK MHRA and South Korea — participate in the programme but do not currently accept an MDSAP certificate in place of their own conformity assessment.

MDSAP is worth considering if any of the following applies:

  • You sell, or plan to sell, in Canada, where MDSAP is mandatory for Class II, III and IV devices under the Medical Devices Regulations. There is no alternative route.
  • You want to reduce the burden of parallel audits across the United States, Brazil, Japan or Australia.
  • You are preparing for FDA oversight and want the MDSAP report accepted in place of a routine surveillance inspection.
  • You operate multiple sites or contract manufacturing and need one defensible quality narrative rather than five variants of it.

✦ Multi-market kit · MDSAP

One audit. Five markets. Ready to submit.

The MDSAP Documentation Kit covers Brazil ANVISA, Japan PMDA, Health Canada, Australia TGA and the FDA — with country-specific reportability worksheets and application checklists, mapped to the seven process chapters the audit actually follows.

✓ 15 SOPs covering 5 MDSAP markets

✓ 18 templates with country worksheets

✓ Brazil · Japan · Canada · Australia · USA

Get the MDSAP Kit → from €399

The structure of the audit, stage by stage

The lifecycle mirrors an ISO 13485 certification cycle: a two-stage initial audit, a three-year certificate, annual surveillance, and a full recertification at the end.

The three-year certification cycle STAGE 1 Readiness review 1–2 days STAGE 2 Full QMS audit all 7 chapters CERTIFICATE valid 3 years YEAR 1 Surveillance critical processes YEAR 2 Surveillance remaining processes YEAR 3 Recertification Unannounced audits sit outside this cycle Triggered by complaints, recalls or risk signals — Health Canada in particular
Figure 1 — The MDSAP certification cycle, and the audit that is not on it

Stage 1 — readiness review

A documentation-focused review confirming that the quality system is mature enough for the full audit. It produces an identification of documentation gaps, confirmation of the audit scope covering sites, product families and exclusions, and a preliminary view of the risk areas. It is normally performed on-site at the main manufacturing facility.

Stage 2 — full QMS audit

The complete on-site audit, structured around the seven process chapters. Auditors sample objective evidence across every relevant process and assess conformity against ISO 13485 and the country-specific requirements. Non-conformities raised here must be addressed with a documented corrective action plan before the certificate can be issued.

Certificate and maintenance

Once corrective actions are accepted, the Auditing Organization issues the certificate for three years.

Audit typeFrequencyScope
Stage 1Once, before Stage 2Documentation review, readiness check
Stage 2 (initial)Once, after Stage 1Full QMS audit across all seven process chapters
Surveillance year 112 months after certificationPartial QMS audit covering all critical processes
Surveillance year 224 months after certificationRemaining processes plus follow-up on prior findings
RecertificationEvery 3 yearsFull QMS re-audit, identical scope to Stage 2
UnannouncedAs requiredTriggered by complaints, recalls or risk signals

Excluding a country from the scope

A manufacturer can include only some of the five jurisdictions. This is a strategic decision and it has to be agreed with the Auditing Organization before the audit plan is finalised.

The usual reasons to exclude a country are no commercial presence and no plan to enter within three years; a device class outside the local regulator’s MDSAP recognition, which affects certain IVDs in some jurisdictions; or a recently passed local inspection that is still valid and not worth duplicating.

Exclusions cut audit days and cost, and they cut the certificate down to match. Adding a country later requires a scope extension audit, which is a chargeable event and not a free amendment. Excluding a market you expect to enter in eighteen months saves money now and costs more within the same certificate cycle.

The seven process chapters

Every MDSAP audit walks the same seven chapters in the same sequence, regardless of manufacturer or Auditing Organization. Understanding that sequence is the most useful preparation a quality team can do, because it is the order in which evidence will be requested.

Ch.ProcessWhat auditors look for
1ManagementManagement review records, quality policy, resource allocation, regulatory reporting decisions
2Device marketing authorization and facility registrationCountry-specific registrations, UDI, listings, licence renewals, change notifications
3Measurement, analysis and improvementInternal audits, CAPA, complaint handling, data analysis, post-market surveillance feedback loops
4Medical device adverse events and advisory notice reportingVigilance procedures per country, MDR and MIR submissions, recall and field safety corrective action records
5Design and developmentDesign controls, design history file, design changes, verification and validation
6Production and service provisionProcess validation, environmental controls, sterilisation, traceability, servicing records
7PurchasingSupplier qualification, supplier monitoring, supplier audits, purchasing controls
The audit sequence, and where the chapters connect 1 · MANAGEMENT 2 · MARKETING AUTHORIZATION 5 · DESIGN AND DEVELOPMENT 7 · PURCHASING suppliers 6 · PRODUCTION AND SERVICE PROVISION 4 · ADVERSE EVENTS AND ADVISORY NOTICES 3 · MEASUREMENT, ANALYSIS AND IMPROVEMENT CAPA and complaint data feed management review
Figure 2 — The seven process chapters, and the loop back into management review

Three chapters carry most of the findings, and each has a guide of its own. Chapter 3 turns on the CAPA system, and the eleven documented requirements it is assessed against are set out in our guide to CAPA under ISO 13485. Chapter 7 turns on purchasing controls, covered in our guide to supplier qualification and the approved supplier list. And the internal audit evidence sampled under chapter 3 is only as good as the programme behind it — our ISO 13485 internal audit checklist covers that.

MDSAP compared with ISO 13485

MDSAP is built on ISO 13485 and is not equivalent to it. The differences are precisely where audit teams find their hardest findings.

DimensionISO 13485:2016MDSAP
ScopeQMS for medical devices, jurisdiction-neutralQMS plus jurisdiction-specific regulatory requirements for five countries
Marketing authorizationNot in scopeExplicitly audited per country: licences, registrations, UDI
Vigilance and adverse eventsGeneric awarenessCountry-specific timelines and submission procedures audited
Non-conformity gradingMajor or minor, with an element of judgementPoints-based 1–5 scale with documented escalation rules
Audit durationSet by the certification bodyCalculated by the MDSAP audit time formula: employees, complexity, sites
Unannounced auditsNot requiredPossible, particularly on Health Canada triggers
Audit organisationTypically by clauseBy process, in a fixed sequence of seven chapters

The last row is the one that costs preparation time. A quality manual and audit programme organised around clauses 4 to 8 of ISO 13485 has to be remapped onto seven processes, and the mapping is not one to one: CAPA appears in chapter 3, design changes in chapter 5, and the regulatory reporting decision that follows a complaint sits in chapter 1 and chapter 4 at once.

The non-conformity grading system

MDSAP’s signature feature is an objective, points-based grading mechanism. It replaces subjective labels with a matrix that produces a numeric grade between 1 and 5, and the calculation is public, which means a manufacturer can grade its own internal audit findings on the same scale before the auditor arrives.

How the grade is calculated STEP 1 Direct or indirect impact on the QMS outcome? STEP 2 First occurrence, or a repeat finding? STEP 3 Read the base grade from the matrix: 1 to 4 STEP 4 Apply escalation, then cap at 5 The two escalation rules, each adding one point +1   no documented procedure exists +1   non-conforming product has been released Why grade 3 is the threshold that matters At grade 3 a corrective action plan becomes mandatory and close-out is tracked; below it, findings are logged
Figure 3 — The grading calculation, and the two rules that push a finding up the scale
GradeMeaningTypical exampleLikely regulator reaction
1Minor, isolated, no QMS impactA single training record missing for a non-critical roleLogged; no follow-up usually required
2Minor with limited QMS impactInconsistent records in a non-critical supplier evaluationTracked at the next surveillance audit
3Direct QMS impact, first occurrenceA design change not formally controlled in the DHFCorrective action plan required; close-out tracked
4Direct QMS impact, recurrent or escalatedRepeat CAPA closure failure across auditsHeightened regulator attention; possible site action
5Severe systemic failure or product safety riskRelease of non-conforming sterile devices without lot reviewMay trigger certificate suspension and regulator notification

The escalation rules are what make grade 3 reachable from a finding that looks minor. A missing training record is a grade 1 — unless there is no documented training procedure behind it, which adds a point, and unless product went out on the strength of that training, which adds another. Two escalations turn an isolated record gap into a finding that requires a corrective action plan.

Market access by country

The business case varies sharply by market, and the table below is the practical question to answer before committing.

CountryMandatory?What MDSAP replaces or enables
CanadaYesRequired to obtain and maintain a Medical Device Licence for Class II to IV. No MDSAP, no Canadian sales.
United StatesNoThe FDA accepts MDSAP reports in place of routine surveillance inspections. Closely aligned with the quality system requirements a 510(k) submission assumes are in place.
BrazilNo, but recommendedReplaces the ANVISA B-GMP inspection for several device categories, which can shorten time to registration substantially. The registration dossier itself is separate — see our guide to ANVISA registration.
JapanNoUsed in MHLW and PMDA QMS conformity assessment; reduces overlap with domestic audits.
AustraliaNoAccepted for TGA conformity assessment on selected certification routes.

The United States case is worth stating precisely, because it is often overstated. MDSAP is not a requirement for market entry and it does not substitute for clearance. What it does is two things: it aligns the quality system with the requirements a 510(k) assumes are already met, and it allows the FDA to accept the audit report in place of a routine surveillance inspection after clearance. Neither is a shortcut through the premarket pathway.

✦ Premium bundle · ISO 13485 + MDSAP

The ultimate global QMS documentation bundle.

Combine ISO 13485 and all five MDSAP markets in one package. A deduplicated structure means you customise each document once, not twice — which matters most for the documents that appear in both, like CAPA, internal audit and management review.

✓ 41 SOPs covering both ISO 13485 and MDSAP

✓ 70+ templates with deduplicated structure

✓ Save €199 vs buying the kits separately

Get the Combined Kit → from €699

The risk-based logic behind the audit

MDSAP is designed so that audit effort concentrates where failure would matter most. Rather than distributing attention evenly across the quality system, it prioritises design controls, production and supplier management on the basis of their influence on product quality and patient safety, and it requires auditors to evaluate not whether procedures exist but whether they are effectively implemented in the areas that carry risk.

The grading system reinforces the same logic from the other end. Assigning severity by impact and by systemic nature means that a finding in a critical process escalates automatically, which lets both the regulator and the manufacturer prioritise remediation without negotiating about it. And the audit draws on complaint data, post-market surveillance and previous audit results to adjust its focus, so the areas sampled most heavily are the ones your own data has already flagged.

The practical consequence is that your risk management file is an audit input, not a separate document. Where ISO 14971 identifies a process as risk-relevant, that process will be sampled more deeply, and the auditor will expect the connection to be visible.

Audit cost and duration

Audit duration is calculated with the MDSAP audit time formula, which accounts for the number of employees, device complexity, number of sites, technology and outsourced processes. The output is a number of audit days, against which the Auditing Organization quotes.

Manufacturer sizeInitial audit daysIndicative initial cost (Stage 1 + Stage 2)
Small — 1 to 25 employees, single site5–7 days€12,000 – €20,000
Medium — 26 to 100 employees, single site8–12 days€20,000 – €35,000
Large — 100+ employees, multi-site13–20+ days€40,000 – €80,000+

These figures are indicative and exclude internal preparation, travel, surveillance audits and remediation. Recurring annual surveillance costs roughly 30 to 40 per cent of the initial audit. Internal preparation cost is usually equal to or greater than the Auditing Organization’s fee, and it is the part that never appears in the quotation.

PhaseDurationKey activities
Preparation3–9 monthsGap analysis, CAPA, internal audit, mock audit, training
AO selection and contract1–2 monthsQuotation, scope definition, Stage 1 booking
Stage 11–2 days on siteDocumentation review, gap close-out plan
Gap remediation1–3 monthsAddress Stage 1 findings before Stage 2
Stage 25–15 days on siteFull QMS audit
Certification1–2 monthsCorrective actions, AO review, certificate issuance

Free MDSAP audit checklist (Excel)

The most efficient way to prepare is to work through a checklist built on the same structure the Auditing Organization will use. This free Excel workbook mirrors the MDSAP Audit Approach: all 90 audit tasks across the seven process chapters.

Each task lists the official task title, the audit objective, the relevant ISO 13485:2016 clause, and the jurisdiction-specific requirements for Australia, Brazil, Canada, Japan and the United States. Use it as a requirements checklist and gap analysis tool: record your evidence, set each task to Conform, Nonconformity, Observation or Not Applicable, and the summary sheet counts your findings automatically, including grades 1 to 5.

✦ Free download · Excel

MDSAP audit checklist — 90 tasks, 7 process chapters

Built on the MDSAP Audit Approach, with ISO 13485:2016 clauses and the requirements of all five jurisdictions. Editable Excel, with an automatic findings summary and grades 1 to 5.

↓ Download the checklist (Excel)

Free · no sign-up required · built by a former Notified Body auditor

The checklist tells you which tasks you have evidence for. The documents behind those tasks — the CAPA, internal audit and management review procedures, the adverse-event reportability worksheets and the country-specific application checklists — are in the MDSAP Documentation Kit, mapped to the same audit model.

Preparation, month by month

MDSAP preparation is not a documentation sprint. It is a six to twelve month operational alignment, and the sequence below mirrors the way Auditing Organizations structure the audit, so working through it in order maximises the return on effort.

Working backwards from the audit date MONTH −12 TO −9 Foundation Gap analysis Remap QMS to 7 chapters Select the AO early MONTH −9 TO −6 Country alignment Vigilance per country Verify all authorizations UDI and labelling MONTH −6 TO −3 Internal validation Internal audit by process Mock audit Close old CAPAs MONTH −3 TO 0 Final readiness Prepare the data room Train front-line staff Open CAPAs older than six months are the single most common source of grade 3 findings
Figure 4 — The preparation sequence, run backwards from the audit date

Months −12 to −9: foundation

Gap analysis against the MDSAP Companion Document and each of the five jurisdictional requirement sets. Map the quality system onto the seven process chapters — most ISO 13485 files are organised by clause, and this remapping is routinely underestimated. Select the Auditing Organization early: lead times for a Stage 1 booking with the larger AOs can exceed six months.

Months −9 to −6: country-specific alignment

Document the vigilance procedures for each jurisdiction — FDA MDR, Health Canada, ANVISA, TGA and PMDA each have their own timelines. Verify that every marketing authorization is current: US registration and listing, the Canadian licence, ANVISA registration, the J-MDN code, the TGA ARTG entry. Map UDI assignments and country-specific labelling.

Months −6 to −3: internal validation

Run a full internal audit using the MDSAP process sequence rather than a clause-based ISO 13485 audit — auditing in the wrong order finds the wrong gaps. Run a mock audit, ideally with someone familiar with MDSAP grading. Close every CAPA older than six months.

Months −3 to 0: final readiness

Prepare the data room: complaint logs, CAPA list, supplier evaluation status, design changes, post-market surveillance summaries. Train front-line staff on how the interviews work, particularly production operators and complaint handlers, who are interviewed directly and whose answers become objective evidence.

The findings that recur

Across published MDSAP audit outcomes the same families of findings appear year after year. Remediating these areas in advance measurably reduces audit risk.

Finding areaTypical issueMitigation
CAPA effectivenessClosed CAPAs reopen because the root cause identified was symptomatic rather than systemicRequire an independent reviewer to sign off the effectiveness check before closure
Design changesChanges implemented in production without a DHF updateLock the change control workflow to a DHF gate
Supplier managementCritical suppliers evaluated once, at qualification, and never againAnnual supplier review against quantitative criteria
Vigilance reportingDomestic reporting in order, country-specific submissions missingA country-by-country decision tree maintained alongside the complaint procedure
Marketing authorizationLicence amendments lagging behind product changesTrigger a licence review at every design change above a defined threshold

Four of these five sit in chapter 3 or chapter 7, which is consistent with where the audit spends its time. The post-market surveillance data that feeds the CAPA system is sampled in chapter 3 as well, so a weak feedback loop surfaces twice in the same audit.

Frequently asked questions

Is MDSAP mandatory?

Only in Canada, where it is required for Class II, III and IV medical device licences. In Australia, Brazil, Japan and the United States it is voluntary but actively recognised, with each authority accepting the audit report for different purposes.

How long does an MDSAP certificate last?

Three years from the date of issue, with mandatory surveillance audits in year 1 and year 2, and a full recertification audit in year 3.

Can I keep my existing ISO 13485 certificate and add MDSAP?

Yes. Most Auditing Organizations offer combined audits in which the ISO 13485 surveillance and the MDSAP surveillance are performed in a single visit, reducing both duration and cost. The certificates remain separate; the audit is integrated.

Does MDSAP replace the FDA quality system requirements?

No. MDSAP audits include the FDA quality system requirements within their scope, so a compliant MDSAP quality system also meets them — but the underlying regulation remains in force independently. Since the QMSR took effect in February 2026, harmonising 21 CFR Part 820 with ISO 13485, the overlap between the two is closer than it was.

What happens if I receive a grade 4 or 5 non-conformity?

The Auditing Organization requires a comprehensive corrective action plan with a tight close-out timeline, and the regulators most affected by the finding are notified through the standardised audit exchange form. In severe cases the certificate can be suspended or withdrawn until remediation is verified.

Which Auditing Organizations are authorised?

The official list is maintained by the MDSAP Regulatory Authority Council and changes over time, so it should be checked directly rather than taken from a secondary source. Selection should be based on geographic coverage, sector experience and lead times rather than on price alone, since Stage 1 booking lead times can exceed six months.

How much does an MDSAP audit cost?

Indicatively, from around €12,000 for a very small single-site manufacturer to €80,000 or more for large multi-site operations, with recurring surveillance at roughly 30 to 40 per cent of the initial audit per year. Internal preparation cost is usually equal to or greater than the Auditing Organization’s fee and does not appear in the quotation.

Why does the MDSAP process order matter so much?

Because MDSAP audits by process while most ISO 13485 quality systems are documented by clause. The audit walks seven chapters in a fixed sequence, and evidence is requested in that order. A manufacturer whose internal audit programme is clause-based will have audited the same content in a different shape, and will find gaps during the audit that its own internal audit did not surface.

Conclusions

MDSAP began as an administrative consolidation — five audits collapsed into one. It has become something more useful than that: a single, defensible account of how a manufacturer controls quality across five of the most demanding regulatory markets in the world.

Two things decide how the audit goes, and both are settled before the auditor arrives. The first is whether the quality system has been remapped onto the seven process chapters, or whether it is still organised by clause and will be searched in real time. The second is the age of the open CAPAs, because effectiveness failures escalate under the grading rules and a CAPA that has been open for a year is a finding waiting to be written.

Start with the free audit checklist above to establish where you stand. If the gaps are in the documents rather than in the evidence, the MDSAP Documentation Kit covers the five markets, and the Combined Kit covers ISO 13485 alongside them with a deduplicated structure.

Related articles