MDSAP Audits: Process Chapters, Grading and How to Prepare
Introduction
The Medical Device Single Audit Program lets one audit of a quality management system satisfy five regulatory authorities: Australia’s TGA, Brazil’s ANVISA, Health Canada, Japan’s MHLW and PMDA, and the US FDA. The audit is performed by an authorised Auditing Organization against ISO 13485 plus the country-specific requirements of each participating jurisdiction. A successful audit produces a certificate valid for three years, with surveillance audits in between.
That is the administrative description, and it is not the reason MDSAP is difficult. The difficulty is structural: MDSAP audits by process, in a fixed sequence of seven chapters, while almost every ISO 13485 quality system is organised by clause. Remapping one onto the other is the single most underestimated piece of preparation, and it is where teams that were confident about their ISO 13485 certification discover that the audit does not follow the shape of their documentation.
This guide covers the seven process chapters and what auditors look for in each, how the points-based grading works and how a finding escalates, the audit cycle and what each stage costs in days, the market access value by country, and a preparation sequence built to run backwards from the audit date. There is a free Excel checklist further down, built on the same audit approach the Auditing Organization uses.
Table of Contents
- What MDSAP is, and who it is for
- The structure of the audit, stage by stage
- Excluding a country from the scope
- The seven process chapters
- MDSAP compared with ISO 13485
- The non-conformity grading system
- Market access by country
- The risk-based logic behind the audit
- Audit cost and duration
- Free MDSAP audit checklist (Excel)
- Preparation, month by month
- The findings that recur
- Frequently asked questions
- Conclusions
What MDSAP is, and who it is for
Instead of being audited separately by each authority, a manufacturer is audited once against a unified set of requirements, and the resulting report is accepted by all participating regulators. The audit is performed by an Auditing Organization that has been assessed and authorised by the Regulatory Authorities to conduct MDSAP audits and issue certificates.
The five participating authorities are the TGA in Australia, ANVISA in Brazil, Health Canada, the MHLW and PMDA in Japan, and the FDA in the United States. Observers and affiliate members — the WHO, the European Union, the UK MHRA and South Korea — participate in the programme but do not currently accept an MDSAP certificate in place of their own conformity assessment.
MDSAP is worth considering if any of the following applies:
- You sell, or plan to sell, in Canada, where MDSAP is mandatory for Class II, III and IV devices under the Medical Devices Regulations. There is no alternative route.
- You want to reduce the burden of parallel audits across the United States, Brazil, Japan or Australia.
- You are preparing for FDA oversight and want the MDSAP report accepted in place of a routine surveillance inspection.
- You operate multiple sites or contract manufacturing and need one defensible quality narrative rather than five variants of it.
✦ Multi-market kit · MDSAP
One audit. Five markets. Ready to submit.
The MDSAP Documentation Kit covers Brazil ANVISA, Japan PMDA, Health Canada, Australia TGA and the FDA — with country-specific reportability worksheets and application checklists, mapped to the seven process chapters the audit actually follows.
✓ 15 SOPs covering 5 MDSAP markets
✓ 18 templates with country worksheets
✓ Brazil · Japan · Canada · Australia · USA
The structure of the audit, stage by stage
The lifecycle mirrors an ISO 13485 certification cycle: a two-stage initial audit, a three-year certificate, annual surveillance, and a full recertification at the end.
Stage 1 — readiness review
A documentation-focused review confirming that the quality system is mature enough for the full audit. It produces an identification of documentation gaps, confirmation of the audit scope covering sites, product families and exclusions, and a preliminary view of the risk areas. It is normally performed on-site at the main manufacturing facility.
Stage 2 — full QMS audit
The complete on-site audit, structured around the seven process chapters. Auditors sample objective evidence across every relevant process and assess conformity against ISO 13485 and the country-specific requirements. Non-conformities raised here must be addressed with a documented corrective action plan before the certificate can be issued.
Certificate and maintenance
Once corrective actions are accepted, the Auditing Organization issues the certificate for three years.
| Audit type | Frequency | Scope |
|---|---|---|
| Stage 1 | Once, before Stage 2 | Documentation review, readiness check |
| Stage 2 (initial) | Once, after Stage 1 | Full QMS audit across all seven process chapters |
| Surveillance year 1 | 12 months after certification | Partial QMS audit covering all critical processes |
| Surveillance year 2 | 24 months after certification | Remaining processes plus follow-up on prior findings |
| Recertification | Every 3 years | Full QMS re-audit, identical scope to Stage 2 |
| Unannounced | As required | Triggered by complaints, recalls or risk signals |
Excluding a country from the scope
A manufacturer can include only some of the five jurisdictions. This is a strategic decision and it has to be agreed with the Auditing Organization before the audit plan is finalised.
The usual reasons to exclude a country are no commercial presence and no plan to enter within three years; a device class outside the local regulator’s MDSAP recognition, which affects certain IVDs in some jurisdictions; or a recently passed local inspection that is still valid and not worth duplicating.
Exclusions cut audit days and cost, and they cut the certificate down to match. Adding a country later requires a scope extension audit, which is a chargeable event and not a free amendment. Excluding a market you expect to enter in eighteen months saves money now and costs more within the same certificate cycle.
The seven process chapters
Every MDSAP audit walks the same seven chapters in the same sequence, regardless of manufacturer or Auditing Organization. Understanding that sequence is the most useful preparation a quality team can do, because it is the order in which evidence will be requested.
| Ch. | Process | What auditors look for |
|---|---|---|
| 1 | Management | Management review records, quality policy, resource allocation, regulatory reporting decisions |
| 2 | Device marketing authorization and facility registration | Country-specific registrations, UDI, listings, licence renewals, change notifications |
| 3 | Measurement, analysis and improvement | Internal audits, CAPA, complaint handling, data analysis, post-market surveillance feedback loops |
| 4 | Medical device adverse events and advisory notice reporting | Vigilance procedures per country, MDR and MIR submissions, recall and field safety corrective action records |
| 5 | Design and development | Design controls, design history file, design changes, verification and validation |
| 6 | Production and service provision | Process validation, environmental controls, sterilisation, traceability, servicing records |
| 7 | Purchasing | Supplier qualification, supplier monitoring, supplier audits, purchasing controls |
Three chapters carry most of the findings, and each has a guide of its own. Chapter 3 turns on the CAPA system, and the eleven documented requirements it is assessed against are set out in our guide to CAPA under ISO 13485. Chapter 7 turns on purchasing controls, covered in our guide to supplier qualification and the approved supplier list. And the internal audit evidence sampled under chapter 3 is only as good as the programme behind it — our ISO 13485 internal audit checklist covers that.
MDSAP compared with ISO 13485
MDSAP is built on ISO 13485 and is not equivalent to it. The differences are precisely where audit teams find their hardest findings.
| Dimension | ISO 13485:2016 | MDSAP |
|---|---|---|
| Scope | QMS for medical devices, jurisdiction-neutral | QMS plus jurisdiction-specific regulatory requirements for five countries |
| Marketing authorization | Not in scope | Explicitly audited per country: licences, registrations, UDI |
| Vigilance and adverse events | Generic awareness | Country-specific timelines and submission procedures audited |
| Non-conformity grading | Major or minor, with an element of judgement | Points-based 1–5 scale with documented escalation rules |
| Audit duration | Set by the certification body | Calculated by the MDSAP audit time formula: employees, complexity, sites |
| Unannounced audits | Not required | Possible, particularly on Health Canada triggers |
| Audit organisation | Typically by clause | By process, in a fixed sequence of seven chapters |
The last row is the one that costs preparation time. A quality manual and audit programme organised around clauses 4 to 8 of ISO 13485 has to be remapped onto seven processes, and the mapping is not one to one: CAPA appears in chapter 3, design changes in chapter 5, and the regulatory reporting decision that follows a complaint sits in chapter 1 and chapter 4 at once.
The non-conformity grading system
MDSAP’s signature feature is an objective, points-based grading mechanism. It replaces subjective labels with a matrix that produces a numeric grade between 1 and 5, and the calculation is public, which means a manufacturer can grade its own internal audit findings on the same scale before the auditor arrives.
| Grade | Meaning | Typical example | Likely regulator reaction |
|---|---|---|---|
| 1 | Minor, isolated, no QMS impact | A single training record missing for a non-critical role | Logged; no follow-up usually required |
| 2 | Minor with limited QMS impact | Inconsistent records in a non-critical supplier evaluation | Tracked at the next surveillance audit |
| 3 | Direct QMS impact, first occurrence | A design change not formally controlled in the DHF | Corrective action plan required; close-out tracked |
| 4 | Direct QMS impact, recurrent or escalated | Repeat CAPA closure failure across audits | Heightened regulator attention; possible site action |
| 5 | Severe systemic failure or product safety risk | Release of non-conforming sterile devices without lot review | May trigger certificate suspension and regulator notification |
The escalation rules are what make grade 3 reachable from a finding that looks minor. A missing training record is a grade 1 — unless there is no documented training procedure behind it, which adds a point, and unless product went out on the strength of that training, which adds another. Two escalations turn an isolated record gap into a finding that requires a corrective action plan.
Market access by country
The business case varies sharply by market, and the table below is the practical question to answer before committing.
| Country | Mandatory? | What MDSAP replaces or enables |
|---|---|---|
| Canada | Yes | Required to obtain and maintain a Medical Device Licence for Class II to IV. No MDSAP, no Canadian sales. |
| United States | No | The FDA accepts MDSAP reports in place of routine surveillance inspections. Closely aligned with the quality system requirements a 510(k) submission assumes are in place. |
| Brazil | No, but recommended | Replaces the ANVISA B-GMP inspection for several device categories, which can shorten time to registration substantially. The registration dossier itself is separate — see our guide to ANVISA registration. |
| Japan | No | Used in MHLW and PMDA QMS conformity assessment; reduces overlap with domestic audits. |
| Australia | No | Accepted for TGA conformity assessment on selected certification routes. |
The United States case is worth stating precisely, because it is often overstated. MDSAP is not a requirement for market entry and it does not substitute for clearance. What it does is two things: it aligns the quality system with the requirements a 510(k) assumes are already met, and it allows the FDA to accept the audit report in place of a routine surveillance inspection after clearance. Neither is a shortcut through the premarket pathway.
✦ Premium bundle · ISO 13485 + MDSAP
The ultimate global QMS documentation bundle.
Combine ISO 13485 and all five MDSAP markets in one package. A deduplicated structure means you customise each document once, not twice — which matters most for the documents that appear in both, like CAPA, internal audit and management review.
✓ 41 SOPs covering both ISO 13485 and MDSAP
✓ 70+ templates with deduplicated structure
✓ Save €199 vs buying the kits separately
The risk-based logic behind the audit
MDSAP is designed so that audit effort concentrates where failure would matter most. Rather than distributing attention evenly across the quality system, it prioritises design controls, production and supplier management on the basis of their influence on product quality and patient safety, and it requires auditors to evaluate not whether procedures exist but whether they are effectively implemented in the areas that carry risk.
The grading system reinforces the same logic from the other end. Assigning severity by impact and by systemic nature means that a finding in a critical process escalates automatically, which lets both the regulator and the manufacturer prioritise remediation without negotiating about it. And the audit draws on complaint data, post-market surveillance and previous audit results to adjust its focus, so the areas sampled most heavily are the ones your own data has already flagged.
The practical consequence is that your risk management file is an audit input, not a separate document. Where ISO 14971 identifies a process as risk-relevant, that process will be sampled more deeply, and the auditor will expect the connection to be visible.
Audit cost and duration
Audit duration is calculated with the MDSAP audit time formula, which accounts for the number of employees, device complexity, number of sites, technology and outsourced processes. The output is a number of audit days, against which the Auditing Organization quotes.
| Manufacturer size | Initial audit days | Indicative initial cost (Stage 1 + Stage 2) |
|---|---|---|
| Small — 1 to 25 employees, single site | 5–7 days | €12,000 – €20,000 |
| Medium — 26 to 100 employees, single site | 8–12 days | €20,000 – €35,000 |
| Large — 100+ employees, multi-site | 13–20+ days | €40,000 – €80,000+ |
These figures are indicative and exclude internal preparation, travel, surveillance audits and remediation. Recurring annual surveillance costs roughly 30 to 40 per cent of the initial audit. Internal preparation cost is usually equal to or greater than the Auditing Organization’s fee, and it is the part that never appears in the quotation.
| Phase | Duration | Key activities |
|---|---|---|
| Preparation | 3–9 months | Gap analysis, CAPA, internal audit, mock audit, training |
| AO selection and contract | 1–2 months | Quotation, scope definition, Stage 1 booking |
| Stage 1 | 1–2 days on site | Documentation review, gap close-out plan |
| Gap remediation | 1–3 months | Address Stage 1 findings before Stage 2 |
| Stage 2 | 5–15 days on site | Full QMS audit |
| Certification | 1–2 months | Corrective actions, AO review, certificate issuance |
Free MDSAP audit checklist (Excel)
The most efficient way to prepare is to work through a checklist built on the same structure the Auditing Organization will use. This free Excel workbook mirrors the MDSAP Audit Approach: all 90 audit tasks across the seven process chapters.
Each task lists the official task title, the audit objective, the relevant ISO 13485:2016 clause, and the jurisdiction-specific requirements for Australia, Brazil, Canada, Japan and the United States. Use it as a requirements checklist and gap analysis tool: record your evidence, set each task to Conform, Nonconformity, Observation or Not Applicable, and the summary sheet counts your findings automatically, including grades 1 to 5.
✦ Free download · Excel
MDSAP audit checklist — 90 tasks, 7 process chapters
Built on the MDSAP Audit Approach, with ISO 13485:2016 clauses and the requirements of all five jurisdictions. Editable Excel, with an automatic findings summary and grades 1 to 5.
↓ Download the checklist (Excel)
Free · no sign-up required · built by a former Notified Body auditor
The checklist tells you which tasks you have evidence for. The documents behind those tasks — the CAPA, internal audit and management review procedures, the adverse-event reportability worksheets and the country-specific application checklists — are in the MDSAP Documentation Kit, mapped to the same audit model.
Preparation, month by month
MDSAP preparation is not a documentation sprint. It is a six to twelve month operational alignment, and the sequence below mirrors the way Auditing Organizations structure the audit, so working through it in order maximises the return on effort.
Months −12 to −9: foundation
Gap analysis against the MDSAP Companion Document and each of the five jurisdictional requirement sets. Map the quality system onto the seven process chapters — most ISO 13485 files are organised by clause, and this remapping is routinely underestimated. Select the Auditing Organization early: lead times for a Stage 1 booking with the larger AOs can exceed six months.
Months −9 to −6: country-specific alignment
Document the vigilance procedures for each jurisdiction — FDA MDR, Health Canada, ANVISA, TGA and PMDA each have their own timelines. Verify that every marketing authorization is current: US registration and listing, the Canadian licence, ANVISA registration, the J-MDN code, the TGA ARTG entry. Map UDI assignments and country-specific labelling.
Months −6 to −3: internal validation
Run a full internal audit using the MDSAP process sequence rather than a clause-based ISO 13485 audit — auditing in the wrong order finds the wrong gaps. Run a mock audit, ideally with someone familiar with MDSAP grading. Close every CAPA older than six months.
Months −3 to 0: final readiness
Prepare the data room: complaint logs, CAPA list, supplier evaluation status, design changes, post-market surveillance summaries. Train front-line staff on how the interviews work, particularly production operators and complaint handlers, who are interviewed directly and whose answers become objective evidence.
The findings that recur
Across published MDSAP audit outcomes the same families of findings appear year after year. Remediating these areas in advance measurably reduces audit risk.
| Finding area | Typical issue | Mitigation |
|---|---|---|
| CAPA effectiveness | Closed CAPAs reopen because the root cause identified was symptomatic rather than systemic | Require an independent reviewer to sign off the effectiveness check before closure |
| Design changes | Changes implemented in production without a DHF update | Lock the change control workflow to a DHF gate |
| Supplier management | Critical suppliers evaluated once, at qualification, and never again | Annual supplier review against quantitative criteria |
| Vigilance reporting | Domestic reporting in order, country-specific submissions missing | A country-by-country decision tree maintained alongside the complaint procedure |
| Marketing authorization | Licence amendments lagging behind product changes | Trigger a licence review at every design change above a defined threshold |
Four of these five sit in chapter 3 or chapter 7, which is consistent with where the audit spends its time. The post-market surveillance data that feeds the CAPA system is sampled in chapter 3 as well, so a weak feedback loop surfaces twice in the same audit.
Frequently asked questions
Is MDSAP mandatory?
Only in Canada, where it is required for Class II, III and IV medical device licences. In Australia, Brazil, Japan and the United States it is voluntary but actively recognised, with each authority accepting the audit report for different purposes.
How long does an MDSAP certificate last?
Three years from the date of issue, with mandatory surveillance audits in year 1 and year 2, and a full recertification audit in year 3.
Can I keep my existing ISO 13485 certificate and add MDSAP?
Yes. Most Auditing Organizations offer combined audits in which the ISO 13485 surveillance and the MDSAP surveillance are performed in a single visit, reducing both duration and cost. The certificates remain separate; the audit is integrated.
Does MDSAP replace the FDA quality system requirements?
No. MDSAP audits include the FDA quality system requirements within their scope, so a compliant MDSAP quality system also meets them — but the underlying regulation remains in force independently. Since the QMSR took effect in February 2026, harmonising 21 CFR Part 820 with ISO 13485, the overlap between the two is closer than it was.
What happens if I receive a grade 4 or 5 non-conformity?
The Auditing Organization requires a comprehensive corrective action plan with a tight close-out timeline, and the regulators most affected by the finding are notified through the standardised audit exchange form. In severe cases the certificate can be suspended or withdrawn until remediation is verified.
Which Auditing Organizations are authorised?
The official list is maintained by the MDSAP Regulatory Authority Council and changes over time, so it should be checked directly rather than taken from a secondary source. Selection should be based on geographic coverage, sector experience and lead times rather than on price alone, since Stage 1 booking lead times can exceed six months.
How much does an MDSAP audit cost?
Indicatively, from around €12,000 for a very small single-site manufacturer to €80,000 or more for large multi-site operations, with recurring surveillance at roughly 30 to 40 per cent of the initial audit per year. Internal preparation cost is usually equal to or greater than the Auditing Organization’s fee and does not appear in the quotation.
Why does the MDSAP process order matter so much?
Because MDSAP audits by process while most ISO 13485 quality systems are documented by clause. The audit walks seven chapters in a fixed sequence, and evidence is requested in that order. A manufacturer whose internal audit programme is clause-based will have audited the same content in a different shape, and will find gaps during the audit that its own internal audit did not surface.
Conclusions
MDSAP began as an administrative consolidation — five audits collapsed into one. It has become something more useful than that: a single, defensible account of how a manufacturer controls quality across five of the most demanding regulatory markets in the world.
Two things decide how the audit goes, and both are settled before the auditor arrives. The first is whether the quality system has been remapped onto the seven process chapters, or whether it is still organised by clause and will be searched in real time. The second is the age of the open CAPAs, because effectiveness failures escalate under the grading rules and a CAPA that has been open for a year is a finding waiting to be written.
Start with the free audit checklist above to establish where you stand. If the gaps are in the documents rather than in the evidence, the MDSAP Documentation Kit covers the five markets, and the Combined Kit covers ISO 13485 alongside them with a deduplicated structure.
Related articles
- ISO 13485:2016 — The Complete Guide to Medical Device Quality Management
- ISO 13485 CAPA: Clauses 8.5.2 and 8.5.3 Requirements
- ISO 13485 Internal Audit Checklist
- ISO 13485 Supplier Management and Qualification
- ANVISA Registration: The Complete Guide
- 510(k) Submission: Substantial Equivalence and eSTAR