MedQara
Back to blog
Quality system

How to prepare for an ISO 13485 audit in 2026

A complete guide to preparing for an ISO 13485:2016 certification or surveillance audit: documentary checklist, points of attention by chapter, behaviours to adopt, classic mistakes. For medical device quality managers.

7 min readMedQara

The ISO 13485 audit is the rite of passage for medical device manufacturers. Whether for an initial certification, an annual surveillance audit, a renewal audit at the end of the three-year cycle, or a broader MDSAP audit — the mechanics are the same: an accredited auditor scrutinises your quality management system (QMS) and compares what is written with what is actually done.

This guide brings together what ten years of audits teach: what happens on the day, how to prepare in advance, where the traps are, and how to turn an audit into a lever for improvement rather than a source of stress.

Understanding the standard

ISO 13485:2016 is the international standard defining the requirements for a quality management system applicable to medical device manufacturers. It aligns with the requirements of Annex IX of the MDR (QMS audit by the notified body) and is the pivot of the MDSAP programme for five jurisdictions (United States, Canada, Brazil, Australia, Japan).

The structure follows core chapters:

Chapter Area covered
4 Quality management system (QMS) — general
5 Management responsibility
6 Resource management
7 Product realization
8 Measurement, analysis and improvement

No chapter is trivial. Auditors choose their angles depending on the stakes, but overall consistency is always examined.

Four to six months before the audit

Review the scope and the date

Check the precise scope of the certificate (product families, sites concerned) and compare it with the company's current reality. A major change (new site, new class III product) may require an extended audit.

Confirm the date at least four months in advance with the certification body, especially at year-end when calendars are saturated.

Compile the indicator dashboard

Over the past 12 months, gather the key indicators showing that the QMS is alive:

  • Number of internal nonconformities opened / closed
  • Number of CAPAs opened / closed (corrective and preventive actions)
  • Number of customer complaints and average handling time
  • Number of vigilance incidents reported
  • Failure rate by lot, by product
  • Internal audits performed vs planned
  • Personnel training indicators
  • Supplier CAPA summary

These indicators will feed the management review (chapter 5.6) which will be examined first.

Launch an internal pre-audit

Ideally two to three months before the official audit. Involve a trained internal auditor or an external provider who will apply the same methodology as a third-party auditor.

Nonconformities identified internally must be closed before the official audit, or otherwise be the subject of a visible and traced action plan.

Two to four weeks before the audit

Check the master documentation

All versions up to date, signed, dated:

  • Quality manual or equivalent document
  • Main procedures (document control, purchasing, design, production, inspection, maintenance, training, internal audit, management review, nonconformity management, CAPA, vigilance)
  • Process map and responsibility matrix
  • Internal audit plan and reports of internal audits performed
  • Minutes of the last management review
  • Training programme and authorisations

Prepare the evidence of implementation

For each procedure, gather three to five recent examples demonstrating actual application:

  • Traced purchase requests
  • Complete batch records
  • Design review minutes
  • Nonconformity records with investigation
  • Completed CAPAs with evidence of effectiveness

The auditor will "pull the thread" — they pick a product file and ask to see its whole path. If a step is missing, that is a nonconformity.

Prepare the areas

The audit generally includes a shop-floor component: visit to production areas, the inspection laboratory, storage zones. Check:

  • Zone signage (clean, controlled, quarantine)
  • Equipment labelling (metrological status, last calibration)
  • Presence of job sheets, visible work instructions
  • Hygiene, PPE use, compliance with access rules

On the day of the audit

The opening meeting

Presentation of the programme, the audit team, the objectives, the scope. It is also your opportunity to introduce your team — specify who answers on which topic, who takes notes.

Best practice: designate a lead quality contact who accompanies the auditor at all times and a scribe who records questions and answers.

Investigation by chapter

The auditor works through their plan. Here are the most frequent angles of attack:

Chapter 4 — QMS: How does the QMS cover outsourcing? How are regulatory requirements integrated (Article 10 of the MDR, for example)?

Chapter 5 — Management responsibility: What are management's commitments? How is the quality policy deployed and reviewed? When was the last management review? What decisions came out of it?

Chapter 6 — Resources: Is the personnel qualified for their duties? Is there a versatility matrix? How is the work environment controlled (controlled zones, storage conditions)?

Chapter 7 — Realization:

  • 7.1 Planning of product realization
  • 7.2 Customer-related processes (contract review, communications)
  • 7.3 Design and development — often the most scrutinised chapter: reviews, verifications, validations, transfers to production
  • 7.4 Purchasing and supplier control
  • 7.5 Production and service provision
  • 7.6 Control of monitoring and measuring equipment

Chapter 8 — Measurement, analysis, improvement: QMS monitoring and measurement, internal audits, nonconformity management, continual improvement, CAPA.

Handling difficult questions

A few principles:

  • Answer the question asked, without extrapolating
  • When in doubt, say "I will check" rather than invent
  • Never hide a known nonconformity — auditors hate discovering a concealed issue
  • Respect the response times you announce

The closing meeting

The auditor presents their findings: conformities, minor nonconformities, major nonconformities, opportunities for improvement.

Do not contest emotionally. If a nonconformity is misinterpreted, ask for factual clarification — the auditor can amend a finding before the report is sent. But once the report is issued, formalism prevails.

After the audit

Response deadlines

  • Major nonconformities: generally 30 to 60 days to propose an action plan and demonstrate immediate action (containment)
  • Minor nonconformities: generally 60 to 90 days to propose an action plan

These deadlines are set by your certification body and stipulated in the audit report.

Building a robust action plan

For each nonconformity, structure the response into:

  1. Root cause analysis (5 whys, Ishikawa, etc.)
  2. Immediate corrective action (containment)
  3. Fundamental corrective action (QMS correction, training, documentary modification)
  4. Preventive action (extension to similar areas)
  5. Effectiveness verification plan (KPI, follow-up audit)

Careful: an action plan that is only a documentary update without training and without verification is almost always rejected.

Classic mistakes to avoid

  1. Over-promising in the QMS — do not write in a procedure what you do not apply. Better a more pragmatic procedure that is actually followed.
  2. Neglecting recorded training — every employee must have an up-to-date authorisation record for each critical task.
  3. Having CAPAs open for more than six months without justification — a signal of a system that does not close its loops.
  4. Confusing verification and validation — verification confirms that specified requirements are met, validation confirms that end-user needs are met.
  5. Not documenting design reviews — minutes with attendance lists and decisions are essential.
  6. Neglecting risk management (ISO 14971) — the risk management file must be alive, linked to the QMS and to design changes.
  7. Underestimating critical suppliers — initial assessment, periodic requalification, follow-up of supplier nonconformities must be documented.

Typical calendar for 2026

If your next audit is planned for 2026, here is an indicative calendar (to adapt to your cycle):

  • D-6 months: internal pre-audit, action plan
  • D-3 months: official annual management review
  • D-2 months: finalisation of actions, documentary update
  • D-1 month: final documentary review, team briefing
  • D-2 weeks: preparation of areas, verification of signage
  • D-day: audit with a lead quality contact
  • D+30 days: action plan on major nonconformities
  • D+60-90 days: closure of minor nonconformities

Conclusion

A successful ISO 13485 audit is not an isolated event — it is the outcome of rigorous daily operation. The best preparation is a QMS that lives all year: regular internal audits, tracked CAPAs, analyzed indicators, continuing training.

For QA/RA quality managers, the audit is also an opportunity: to have an independent third party validate that improvement efforts are bearing fruit, to identify blind spots, to engage with an external expert.

MedQara continuously follows standards developments (ISO 13485 revisions, new Common Specifications, MDR updates) so that your QMS stays aligned with the state of the art.

Also read: PRRC: responsibilities · Understanding the MDR · QARA glossary

ISO 13485AuditQMSQualityCertification

Keep receiving this kind of content

Once a week, receive analyses of new ANSM, FDA, EMA, MDR and IVDR publications - straight to your inbox.

No spam. Unsubscribe in 1 click. GDPR compliant.