ISO 13485 Internal Audit Checklist: Clause by Clause with Common Findings
Introduction
The internal audit is the most powerful tool a quality team has, and the one most often reduced to a formality. Done well, it finds the weaknesses before a Notified Body or an FDA investigator does. Done badly, it becomes evidence against you: a documented record that the organisation examined its own quality system and failed to find what a regulator later found in a single day.
Since February 2026 the stakes are higher. The FDA QMSR brought internal audit records within the scope of routine inspection — under the previous QSR they were exempt. Reports written on the assumption that no regulator would read them are now inspectable, and the right response is not to write blander audits. It is to make sure every finding has a CAPA record attached to it.
This guide covers what Clause 8.2.4 actually requires, how to build the annual programme, how to run an individual audit, a clause-by-clause checklist you can work from, the eight findings that recur, and how to write a nonconformity that produces a useful corrective action.
Table of Contents
- What Clause 8.2.4 requires
- Building the annual audit programme
- Planning and conducting an individual audit
- Before — preparation
- During — conduct
- After — reporting and follow-up
- The checklist, clause by clause
- The eight findings that recur
- How to write a nonconformity
- The records you must retain
- Frequently asked questions
- Conclusions
What Clause 8.2.4 requires
The requirement is a single clause of ISO 13485:2016, and it carries five distinct obligations. Internal audit is also one of the six documented procedures the standard mandates outright.
| Obligation | What it means | How it is failed |
|---|---|---|
| A documented procedure | Covering responsibilities, planning, conduct, reporting and follow-up. Mandatory, not optional. | Audits performed competently with no procedure behind them |
| A planned programme | Audits scheduled in advance, with frequency reflecting the status and importance of each process and the results of previous audits | An ad hoc or reactive approach; a programme that audits everything at the same frequency regardless of history |
| Auditor independence | Personnel must not audit their own work | The quality manager auditing the processes they own — a structural nonconformity that no caveat in the report resolves |
| Records of results | The plan, the report, and evidence of follow-up, retained per the documented retention period | Findings recorded, follow-up undocumented |
| Timely corrective action | Management of the audited area acts without undue delay to eliminate the nonconformity and its cause, and effectiveness is verified | Actions implemented and closed with no verification that the problem stopped |
✦ Audit-ready kit · ISO 13485
Build your ISO 13485 QMS with confidence.
Internal audit is one of six documented procedures ISO 13485 requires outright. Built on 15+ years of audit experience, every SOP and template references the regulations auditors expect.
✓ 30 SOPs covering the full QMS scope
✓ 56 templates ready to customise
✓ Aligned with EU MDR + FDA QMSR
Building the annual audit programme
The programme is not a single audit. It is a planned series that, taken together, covers the whole quality system within a defined period — normally a year.
Scope covers every process, department and site inside the QMS. For a single-site manufacturer this is straightforward; for multi-site organisations it needs planning so that nothing falls between the sites.
Frequency follows risk. The standard requires frequency to reflect the status and importance of processes and the results of previous audits. Processes with previous nonconformities are audited more often. Design and development, production, CAPA and complaint handling normally warrant at least annual coverage; support processes with a clean history can go longer.
Auditors must be independent of the process and competent to assess it, and competence has to be documented — training records, lead auditor qualification, or evidence of relevant experience.
The programme document maps each QMS process against its planned date, assigned auditor and scope. It is a standard request in Notified Body Stage 1 audits and in FDA pre-inspection information requests, so it should be current rather than reconstructed.
Results feed back. Findings from one cycle move that process to a higher frequency in the next. This step is what turns a schedule into a programme, and it is the one most often missing.
Planning and conducting an individual audit
Before — preparation
Each audit within the programme needs its own plan: scope and objectives, audit criteria (which clauses and procedures apply), dates and location, auditor assignment, and the processes to be covered. The plan goes to the auditee in advance.
Review the previous audit of the same process before starting — both to verify that earlier corrective actions were implemented and to identify where to focus. Then prepare the checklist, based on the relevant clauses, the organisation’s own procedures and any applicable regulatory requirements. A good checklist prompts investigation; a bad one prompts confirmation.
During — conduct
Open with a short meeting confirming scope, objectives and methodology. It is not a formality — it sets the tone.
Evidence comes from three methods: interviews with personnel, observation of activities and conditions, and review of documents and records. No finding is recorded without objective evidence supporting it. Sampling is used rather than full review, and the sample has to be large enough to support the conclusion and representative of the range of activity in the process.
Findings fall into three categories: nonconformities, which are failures to meet a stated requirement; observations or opportunities for improvement, which are weaknesses that do not yet constitute a nonconformity; and positive findings. Close with a meeting presenting the findings, to confirm they are factually accurate and that the auditee understands the evidence behind each one.
After — reporting and follow-up
Issue the report within the timeframe your procedure defines, typically five to ten working days. It covers scope and objectives, criteria, auditor and auditee, dates, a summary of findings and the overall conclusion.
Every nonconformity goes through the CAPA system: immediate correction, root cause analysis, corrective action, implementation timeline, and verification of effectiveness before the finding is closed. A finding closed because the action was implemented, without evidence the problem stopped recurring, fails Clause 8.5.2(f) rather than Clause 8.2.4.
The checklist, clause by clause
Organised by clause, with the evidence to look for in each. It is a working document, not a script.
| Clause | What to ask | Evidence to sample |
|---|---|---|
| Clause 4 — Quality management system | ||
| 4.2.1–4.2.2 | Is there a quality manual defining the QMS scope, with any exclusions and their justification? Are the processes identified, sequenced and their interactions defined? | Quality manual; process map |
| 4.2.3 | Is a medical device file established and maintained for each device type or family? | The medical device file itself — frequently absent, and frequently confused with the design history file |
| 4.2.4 | Is there a documented procedure for control of documents? Are current versions available at points of use, and obsolete documents prevented from unintended use? | Document control procedure; a spot check at a workstation |
| 4.2.5 | Is there a documented procedure for control of records? Are records legible, identifiable, retrievable and retained for the defined period? | Record control procedure; retention schedule |
| 4.1.6 | Has software used in the quality management system been validated for its intended use, proportionate to risk? | Validation records for the eQMS, ERP or document system. See our guide to GAMP 5 |
| Clause 5 — Management responsibility | ||
| 5.3–5.4 | Is there a documented quality policy, communicated and understood? Are quality objectives measurable and monitored? | Policy; objectives with actual measurements against them |
| 5.5.2 | Has a management representative been appointed with defined responsibilities? | Appointment record; job description |
| 5.6 | Are management reviews held at planned intervals? Do records contain all required inputs? Do outputs cover resources, process and product improvements? Are actions from previous reviews tracked to closure? | Minutes; the input pack; the action log |
| Clause 6 — Resource management | ||
| 6.2 | Are competence requirements defined? Are training records current? Is there evidence that effectiveness was evaluated, not just attendance? | Competence matrix; training records; effectiveness assessments |
| 6.3–6.4 | Is infrastructure adequate and maintained? Are work environment conditions defined and controlled, including contamination control where applicable? | Maintenance records; environmental monitoring |
| Clause 7 — Product realization | ||
| 7.1 | Is there a documented quality plan per product or project, with risk management activities planned across realization? | Quality plan; the risk management plan |
| 7.2 | Are product requirements including regulatory ones identified and reviewed before acceptance? Is there a documented complaint handling process? | Contract review records; complaint procedure |
| 7.3 | Is there a design and development plan per device? Are inputs documented and reviewed for adequacy, outputs traceable to inputs? Are reviews, verification and validation complete? Is there a design history file? Are design changes controlled? Was design transfer formally documented? | DHF; change records; transfer record. See our guide to design controls |
| 7.4 | Is there a documented supplier evaluation and selection procedure? Is the approved supplier list current? Do purchasing documents specify product, quality and regulatory requirements? Are suppliers monitored against defined criteria? | ASL; evaluation records; a purchase order traced back to the ASL. See our guide to supplier qualification |
| 7.5 | Are manufacturing processes performed under controlled conditions with documented work instructions? Are in-process inspections recorded? Is identification and traceability maintained? Are processes validated where output cannot be verified by later monitoring? | Batch records; validation reports; a traceability exercise from a serial number |
| 7.6 | Is all measurement equipment identified and calibrated? Do records identify the reference standard used? Is the validity of previous measurements assessed when equipment is found out of tolerance? | Calibration records; an out-of-tolerance case and what was done about it |
| Clause 8 — Measurement, analysis and improvement | ||
| 8.2.1–8.2.2 | Are complaints recorded, investigated and trended? Are regulatory reporting obligations assessed for each one? | Complaint log; reportability decisions with rationale |
| 8.2.4 | Are internal audits planned and conducted per the documented procedure? Is auditor independence maintained? Are results reported to management? | The programme; independence declarations; management review inputs |
| 8.3 | Is there a documented procedure for control of nonconforming product, covering identification, segregation, evaluation and disposition? | NC log; disposition records |
| 8.4 | Is data analysed across feedback, product conformity, process performance and suppliers? | Trend reports feeding management review |
| 8.5.2–8.5.3 | Does the CAPA procedure address all eleven documented requirements? Are CAPAs opened for nonconformities of significance? Is root cause analysis documented and proportionate? Is effectiveness verified before closure? | Three closed CAPAs read end to end |
Clause 4.2.3 — the medical device file — is missing from most internal audit checklists in circulation, including several published ones. It is a distinct requirement from the design history file: the DHF records how the device was developed, the medical device file holds the documentation demonstrating conformity for the device as marketed. Auditing one and calling it the other leaves a gap a Notified Body will find.
✦ Premium bundle · ISO 13485 + MDSAP
Expand globally without rebuilding your QMS five times.
An MDSAP audit samples internal audit evidence in a process-based sequence rather than clause by clause. The Combined Kit gives you one deduplicated documentation set that answers both.
✓ 41 SOPs covering both ISO 13485 and MDSAP
✓ 70+ templates with deduplicated structure
✓ Save €199 vs buying the kits separately
The eight findings that recur
| Finding | What it looks like | What fixes it |
|---|---|---|
| Design and development controls | Incomplete design inputs, missing verification or validation records, undocumented design changes, no formal design transfer | A change control workflow gated on a DHF update |
| CAPA effectiveness | CAPAs opened and closed without adequate root cause analysis, or with no documented evidence that effectiveness was verified | An independent reviewer signs off the effectiveness check before closure |
| Supplier management | Suppliers approved without documented evaluation; the ASL not maintained or not linked to purchasing documents; critical suppliers never re-evaluated | Annual supplier review against quantitative criteria |
| Auditor independence | The quality manager audits processes they are directly responsible for | External auditor, or cross-auditing between functions. A caveat in the report does not resolve it |
| Management review inputs | Reviews held, but with no evidence that all required inputs were reviewed, or with inputs that are superficial rather than data-driven | A standing input pack assembled before the meeting, referenced in the minutes |
| Calibration | Equipment used without current calibration; records that do not identify the reference standard; no process for assessing the impact of out-of-tolerance equipment on released product | An out-of-tolerance procedure with a defined product impact assessment |
| Record retention | Records not retained for the required period, not identifiable or not retrievable; no retention policy aligned with regulatory requirements | A retention schedule per record type, derived from the regulations rather than from habit |
| Training effectiveness | Records demonstrate attendance; nothing demonstrates that personnel can apply the requirements | A defined effectiveness method per training type — observation, assessment or supervised performance |
Six of these eight are the same families that appear in Notified Body findings and FDA inspection observations. That overlap is the argument for the internal audit programme: these are the things that will be found, and the only variable is who finds them first.
How to write a nonconformity
A nonconformity statement has three parts: the objective evidence observed, the requirement not being met, and the clause or procedure reference. Missing any one of them produces a finding that cannot support a root cause analysis.
| Written | Why | |
|---|---|---|
| Poorly | “Supplier management is inadequate.” | No evidence, no requirement, no reference. It states a conclusion, and the corrective action will be equally vague |
| Correctly | “During the audit of the purchasing process it was observed that Supplier X (reference PO-2025-0342) appears on the Approved Supplier List, and no supplier evaluation record was available. This does not meet ISO 13485:2016 clause 7.4.1, which requires suppliers to be evaluated and selected on their ability to meet specified requirements, and records of the evaluation to be maintained.” | Evidence is specific and traceable, the requirement is quoted, the clause is cited. Root cause analysis can start from it |
Write findings as if a regulator will read them, because since February 2026 one can. Under the FDA QMSR, internal audit records fall within the scope of routine inspection — they were exempt under the previous QSR. This is not a reason to soften findings. It is a reason to ensure that every finding has a CAPA record attached showing what was done about it: an honest finding with a closed CAPA reads well, and an honest finding with nothing attached does not.
The records you must retain
Six records per audit, at minimum:
- The annual audit programme
- The audit plan issued in advance for the individual audit
- The completed checklist with evidence notes
- The formal audit report with all findings
- The CAPA record linked to each nonconformity
- The effectiveness verification showing the corrective action worked
Retention follows the period defined in your document control procedure — typically the lifetime of the product plus the applicable regulatory retention period, with a general minimum of five years for most ISO 13485-certified organisations. The sixth record is the one most often absent, and its absence converts an internal audit finding into a CAPA finding.
✦ Complete catalogue
Find the documentation you need — instantly.
Whether you need a complete kit or just one specific SOP, the catalogue has it. Individual process packages and complete bundles, all instantly downloadable and fully editable.
✓ Complete bundles or individual packages
✓ Individual process packages from €69 each
✓ ISO 13485 · MDSAP · EU MDR · EU IVDR
Frequently asked questions
How often must internal audits be conducted under ISO 13485?
The standard requires audits at planned intervals and does not specify a minimum frequency. Industry practice and Notified Body expectation is full QMS coverage at least once per year, with higher-risk processes and those with previous nonconformities audited more frequently. The frequency has to be justified by the status and importance of the process and by previous results, not chosen for convenience.
Can the same person plan and conduct the internal audit?
Yes, provided they are independent of the process being audited. What Clause 8.2.4 prohibits is auditing your own work. Planning and conducting are not in conflict; auditing a process you are responsible for is.
Can we use an external consultant to conduct internal audits?
Yes. It is a legitimate and common approach, particularly for small organisations where independence is otherwise impossible to achieve. The external auditor must have documented competence in ISO 13485 and must be given access to all relevant processes and records.
What happens if we find a major nonconformity during an internal audit?
It goes through the CAPA system with priority, is reported to management immediately, and is addressed before the next certification or surveillance audit. Finding it yourself and correcting it is a materially better position than a Notified Body finding it first — and the record of having done so is evidence that the quality system works.
Are internal audit findings reported to the Notified Body?
Individual findings are not proactively reported. The records — findings and corrective actions — are reviewed during surveillance audits and must be available. Since the FDA QMSR took effect in February 2026, internal audit records are also within the scope of routine FDA inspection, which they were not under the previous QSR.
What is the difference between a nonconformity and an observation?
A nonconformity is a failure to meet a stated requirement of the standard, of a regulation or of the organisation’s own documented procedures. An observation is a weakness that does not yet constitute a failure — a practice that works but is fragile, or a trend heading toward a nonconformity. Observations do not require CAPA, but a pattern of the same observation across audits is itself a finding.
What are the three elements of a well-written nonconformity?
The objective evidence observed, the requirement that is not being met, and the clause or procedure reference. A statement missing any of the three cannot support a meaningful root cause analysis, and will produce a corrective action as vague as the finding.
Does the internal audit have to cover every clause every year?
Every process within the scope of the QMS has to be covered by the programme within the defined period, normally a year. That does not mean every clause is audited at the same depth: frequency and depth follow risk and previous results, which is exactly what Clause 8.2.4 requires. A programme that audits everything identically has not applied the requirement.
Conclusions
A working internal audit programme is the cheapest quality investment available, because every nonconformity found and corrected internally costs a fraction of the same finding raised by a Notified Body, an FDA investigator, or a field event.
Two things separate programmes that work from programmes that exist. Frequency has to move: processes with findings get audited more often, and a schedule that never changes has not applied Clause 8.2.4. And findings have to be written specifically enough to investigate — evidence, requirement, reference — because a vague finding produces a vague corrective action and the same finding next year.
The organisations with clean audit outcomes are not the ones with the most elaborate quality system on paper. They are the ones that audit rigorously, write honest findings, investigate causes properly and verify that their corrective actions actually worked.
If you are building the audit system, the ISO 13485 Documentation Kit includes the internal audit procedure, the annual audit programme template and the audit report and finding forms, alongside the CAPA procedure the findings feed into.
Related articles
- ISO 13485:2016 — The Complete Guide to Medical Device Quality Management
- ISO 13485 CAPA: Clauses 8.5.2 and 8.5.3 Requirements
- ISO 13485 Design Controls and the Design History File
- ISO 13485 Supplier Management and Qualification
- MDSAP Audits: Process Chapters, Grading and Preparation
- ISO 14971 Risk Management for Medical Devices