ISO 13485 Internal Audit Checklist (Downloadable)
By the IgeraIndustria Quality & Compliance Team · September 2026 · 10 min read
A thorough ISO 13485:2016 internal audit checklist walks through all five mandatory clauses of the standard — Quality Management System (Clause 4), Management Responsibility (Clause 5), Resource Management (Clause 6), Product Realization (Clause 7), and Measurement, Analysis and Improvement (Clause 8) — verifying that each requirement has documented evidence, is being followed in practice, and is traceable back to a specific procedure or record. Use it to self-assess readiness before a certification or surveillance audit, not as a substitute for the standard's own text.
"The organization shall establish, document, implement and maintain a quality management system and maintain its effectiveness in accordance with the requirements of this International Standard."
— Paraphrased core intent of ISO 13485:2016, Clause 4.1
Why a structured checklist matters more than a generic one
ISO 13485:2016 is the quality management standard for medical device manufacturers and their suppliers, and it is built on five clause groups that mirror how a device actually moves from design to market: how the QMS itself is governed, how leadership steers it, what resources back it, how the product is realized, and how performance is measured and improved. A useful internal audit checklist follows that same structure, because an assessor's findings almost always map back to one of those five clauses — and because gaps in one clause tend to cascade into the next (a weak document control process under Clause 4, for example, will surface again as inconsistent records under Clause 7 and Clause 8).
Rather than treating internal audit as a once-a-year compliance exercise, the most audit-ready QA teams use a checklist like this one continuously, spot-checking one or two clause areas a month so that nothing is discovered for the first time when a notified body auditor is standing in the room.
The checklist: 5 clauses, self-assessment by area
Clause 4 — Quality Management System
- Is the scope of the QMS clearly defined, including any exclusions and their justification?
- Is there a current, controlled Quality Manual referencing all mandatory procedures?
- Does document control ensure only the current approved version of each procedure is in use at the point of work?
- Are records retained, legible, identifiable and retrievable, with a defined retention approach appropriate to the device's lifetime?
- Where processes are outsourced, is there evidence of control over the outsourced process and its supplier?
Clause 5 — Management Responsibility
- Is there a documented quality policy that is communicated and understood at relevant levels of the organization?
- Are quality objectives set, measurable, and reviewed against actual performance?
- Does top management conduct management review at planned intervals, with the required inputs and outputs?
- Is a management representative formally appointed with defined authority over the QMS?
- Is there evidence that management review outputs actually drive corrective action or resource decisions?
Clause 6 — Resource Management
- Are competence requirements defined for roles affecting product quality, with evidence of training or qualification?
- Is training effectiveness evaluated, not just attendance recorded?
- Is the work environment controlled where it affects product conformity (e.g. cleanroom, ESD, contamination control)?
- Are infrastructure elements (equipment, facilities, IT systems) maintained and their maintenance documented?
Clause 7 — Product Realization
- Is planning for product realization documented, covering the full lifecycle from design input to delivery?
- Are customer and regulatory requirements reviewed and confirmed before order acceptance?
- Is design and development controlled with defined inputs, outputs, reviews, verification and validation, and is the design history file complete and traceable?
- Are suppliers evaluated and re-evaluated, with purchasing controls proportionate to the risk of the purchased product?
- Is production carried out under controlled conditions, with process validation evidence where output cannot be fully verified by subsequent monitoring?
- Is there a robust process for identification and traceability, including UDI where applicable, through to servicing and complaint handling?
- Are monitoring and measuring equipment calibrated, with calibration status identifiable and records maintained?
Clause 8 — Measurement, Analysis and Improvement
- Is customer feedback, including complaints, systematically collected and fed back into the QMS?
- Are internal audits planned, conducted against a documented programme, and are findings tracked to closure?
- Is nonconforming product controlled, with clear criteria for rework, use-as-is, scrap or return?
- Is data analysis used to identify trends, not just to close individual nonconformances?
- Are CAPAs (corrective and preventive actions) investigated for root cause, and is their effectiveness verified after implementation?
- Is there a documented process for advisory notices and, where relevant, reporting to regulatory authorities?
Practical impact: what auditors actually probe
Certification and surveillance auditors rarely stop at "does the procedure exist?" They trace a sample — a specific batch record, a specific complaint, a specific design change — end to end, checking that what the procedure says should happen is what the records show actually happened. That means the most valuable preparation is not rereading the standard, but pulling your own records and asking whether they would survive that kind of trace: does the CAPA reference the nonconformance that triggered it, does the training record predate the date the employee started performing that task, does the design history file show verification evidence for every input it lists.
Cross-clause consistency is another common probe point. An auditor who spots a supplier change under Clause 7 will often go looking for the corresponding supplier re-evaluation under Clause 6, and a CAPA closed under Clause 8 should be visible in the next management review under Clause 5. Internal audits that only check each clause in isolation tend to miss exactly these links — which is often where real findings live.
Common mistakes that surface in audits
- Procedures that exist but aren't followed as written: a document control procedure that requires a specific approval sequence, but records show approvals happening out of order or after the fact.
- Training records without effectiveness checks: attendance is logged, but there is no evidence the person demonstrated competence afterward.
- CAPAs closed without verified effectiveness: the corrective action was implemented, but nobody checked afterwards whether the nonconformance actually stopped recurring.
- Design history files with gaps: a design change is documented, but the corresponding verification or validation evidence is missing or filed elsewhere and hard to retrieve.
- Internal audits that don't reach every clause within the audit cycle: some areas get audited every year while others are quietly skipped, leaving blind spots exactly where an external auditor is likely to look.
- Supplier files that lag behind actual supplier changes: a new supplier is already shipping product before their evaluation record is complete.
Turning the checklist into an audit-ready habit
A checklist is only as useful as the evidence behind each line item, and the slowest part of most internal audits is not deciding what to check — it's finding the record that proves it. Searching through shared drives and version histories for the right procedure revision, the right training record, or the right supplier evaluation eats into the time that should go to actually evaluating whether the process worked.
This is the gap IgeraIndustria is built to close: it lets your QA team ask a direct question — such as "what does our design change procedure say about re-verification?" or "when was this supplier last re-evaluated?" — and get an answer sourced directly from your own QMS documents, internal procedures and audit history, with the exact source cited. Instead of an auditor (internal or external) waiting while someone searches for the right file, the answer and its citation are available on the spot, which is exactly the kind of traceability an ISO 13485 audit is designed to test.
Make your QMS instantly searchable before your next audit
IgeraIndustria connects your procedures, records and audit history so any question about your quality system gets an answer with an exact source — no more digging through shared drives the night before the auditor arrives.
Discover IgeraIndustriaFrequently asked questions
How often should an ISO 13485 internal audit be conducted?
The standard requires that internal audits be conducted at planned intervals to determine whether the QMS conforms to requirements and is effectively implemented — it does not prescribe a fixed frequency. Most organizations run a documented annual audit programme designed to cover every clause and relevant process at least once within the cycle, with higher-risk areas audited more frequently. Your own audit programme and risk assessment should define the exact interval for your organization.
Can this checklist be used to prepare for a notified body or certification body audit?
Yes, that is its intended use — as a practical self-assessment tool to identify gaps before an external assessor does. It is not, however, a substitute for the full text of ISO 13485:2016 or for the specific audit checklist your certification body or notified body may use, which can include additional interpretive guidance.
Does this checklist apply to both manufacturers and suppliers to the medical device industry?
ISO 13485 applies to any organization involved in one or more stages of the life cycle of a medical device, including design, production, storage, distribution, installation or servicing, as well as suppliers providing product or QMS-related services. The five clauses covered here apply broadly, though the specific requirements that are relevant to a given organization depend on its role and any documented exclusions.
What is the difference between a nonconformance and a CAPA?
A nonconformance is the identification of a specific instance where a requirement was not met. A CAPA (corrective and preventive action) is the broader process of investigating the root cause behind one or more nonconformances and implementing action intended to prevent recurrence or occurrence. Not every nonconformance requires a full CAPA — that judgement should follow your own documented criteria.
How long should QMS records be retained?
ISO 13485 requires that record retention be defined by the organization and be at least as long as the lifetime of the device as defined by the organization, but not less than two years from release of the product by the organization, unless national or regional regulation specifies a longer period. Because applicable retention periods can vary by record type, device class and jurisdiction, confirm the exact periods that apply to your products with a qualified regulatory or quality consultant rather than relying on a general rule.
Who should carry out an internal audit — can the QA manager audit their own department?
ISO 13485 requires that auditors not audit their own work, to maintain objectivity and impartiality. This is usually addressed through cross-functional internal auditors, a rotation of auditing responsibilities, or in smaller organizations, external or contracted auditors for areas where independence cannot otherwise be achieved.
What happens if an internal audit finds a major nonconformance?
It should be handled through your CAPA process like any other significant finding: root cause investigation, corrective action, and verification that the action was effective. Findings from internal audits, including their status and closure, are also expected to be reviewed as part of management review under Clause 5.
Important notice
This article is a practical self-assessment aid and does not constitute certification, legal or regulatory advice, and it is not a substitute for the full text of ISO 13485:2016 or for your certification body's own audit criteria. Clause references and requirements are summarized for readability; always verify the exact wording against the current standard. For guidance specific to your organization, product classification or applicable jurisdiction, consult a qualified quality management consultant or your notified body / certification body directly.
Summary
- An effective ISO 13485 internal audit checklist covers all five mandatory clauses: QMS (4), Management Responsibility (5), Resource Management (6), Product Realization (7), and Measurement, Analysis & Improvement (8).
- Auditors trace specific records end to end and check consistency across clauses — self-assessment should do the same, not just confirm procedures exist.
- Most findings trace back to evidence gaps: training without effectiveness checks, CAPAs closed without verification, or design history files with missing verification records.
- Making your procedures, records and audit history instantly searchable — with exact source citation — turns audit preparation from a scramble into a routine check.
Last updated: September 2026 | Reference: ISO 13485:2016 — Medical devices — Quality management systems — Requirements for regulatory purposes | Author: IgeraIndustria Quality & Compliance Team | IgeraIndustria. This checklist is a summary aid; where it differs from the current published standard or your certification body's requirements, those sources take precedence.