ISO 13485 internal audit: how to prepare

Two people reviewing printed quality records at a table during an ISO 13485 internal audit

Internal audits are one of those QMS activities that tend to get left until the certification body visit is looming, at which point they get done in a hurry, mostly to generate a record. That’s a missed opportunity, because a well-run internal audit is one of the more useful tools you have for finding problems while they’re still cheap to fix, and most of the value comes from the preparation. So this post covers what ISO 13485 actually asks for, how to plan an audit programme that goes beyond clause-ticking, and a few UK-specific items (the post-market surveillance requirements in particular) that belong on any audit checklist in 2026.

What ISO 13485 actually requires

The requirement sits in clause 8.2.4 of ISO 13485:2016, and it’s fairly short. You need a documented procedure for internal audits, audits conducted at planned intervals, and for each audit you need to define the criteria, scope, frequency and methods. Auditors have to be objective and impartial, which in practice means nobody audits their own work, and you need records of the audits and their results. Where nonconformities turn up, the standard expects correction and corrective action to be taken without undue delay, which is a phrase worth taking seriously, as a certification body auditor will absolutely check the dates.

The clause also points you at ISO 19011 for guidance on how to actually conduct audits, and it’s worth knowing that ISO 19011 was revised in May 2026, replacing the 2018 edition. It’s a technical revision, not a rethink, with more on remote auditing and the use of digital tools, and because it’s guidance rather than requirements there’s no transition period to worry about. If your internal audit procedure references the 2018 version, updating the reference is a five minute job that saves an awkward conversation later.

Plan the programme around risk, not the clause list

The most common weakness I see in internal audit programmes is that they’re built as a tour of the standard, clause by clause, once a year, regardless of what’s actually going on in the business. It satisfies the letter of 8.2.4, but it means your highest-risk processes get the same attention as your lowest-risk ones, and the standard itself tells you to take into account the status and importance of the processes being audited. So plan the programme around your processes and weight it by risk.

In practice that means looking at where the problems have actually been. If your last certification audit raised findings in purchasing, or your complaint log points at one product family, those areas earn a deeper look and possibly a second visit within the cycle. The same goes for anything that has changed this year, whether that’s a critical supplier, new people or a new product. Quieter processes still get covered, because the certification body will want to see the full QMS audited over the cycle, but they don’t need the same depth. A simple schedule showing which processes are audited when, with a sentence on why, is quite a bit more defensible than a calendar entry saying “annual audit”.

Gather the inputs before you write the checklist

Preparation is mostly about arriving with the right questions, and the right questions come from your own records rather than from the standard. Before each audit, pull together the previous audit reports for that process (were the actions actually closed, and did they work?), the open CAPAs and any nonconformity trends, the relevant complaint records, and the minutes of the last management review. Then build your checklist from your own procedures, since the audit is checking whether you do what your documents say you do, and the standard sits behind that. A checklist copied from a generic template will get you generic findings.

It’s also worth deciding the methods up front, which is where the revised ISO 19011 is useful. Reviewing records is fine, but the findings that matter usually come from watching the work being done and talking to the people doing it, so plan the audit around a real order or a real design change and follow it through the process end to end.

The UK angle: put PMS on the checklist

If you sell devices in Great Britain, the strengthened post-market surveillance requirements have applied since 16 June 2025, and they belong on every internal audit checklist now because they’re exactly the sort of thing a busy manufacturer sets up once and then lets drift. The audit should confirm there’s a PMS plan in place for each device, that the PMS reports or periodic safety update reports required for your device class are actually being produced on schedule, and that the shortened vigilance timescales are reflected in your procedures. A serious incident reporting clock that starts on time is the kind of detail that’s easy to check internally and painful to have MHRA check for you.

Beyond PMS, the GB rules are moving. MHRA published draft regulations in spring 2026 covering international reliance, reclassification, UDI and implant cards, and while none of that is law yet, an internal audit is a reasonable place to record a watching brief so nobody can say it went unnoticed. CE marked devices also remain accepted in GB for now (to 30 June 2028 for directive certificates and 30 June 2030 for EU MDR devices), so if you rely on that route it’s worth the audit confirming someone owns the plan for what happens as those dates approach. None of these are blockers to keeping devices on the market, but they’re the questions a good audit asks a year before they become urgent.

If the audit takes you into design and development records, it’s worth checking the technical documentation against what a reviewer would expect to find, and I’ve written separately about what actually goes in a medical device technical file.

The small company problem: who audits the auditor?

In a small manufacturer, and quite a few of MDIN’s clients are exactly this, one person often runs the whole QMS, which creates an obvious problem with 8.2.4, because that person can’t objectively audit the processes they operate. There are reasonable ways round it. You can train a second person from elsewhere in the business to audit the quality processes, or set up a reciprocal arrangement with another small manufacturer. The other option is to bring in an external auditor to conduct the internal audit on your behalf, which is entirely acceptable to certification bodies, as the audit is still internal in the sense that it’s yours, done against your system, for your benefit. The external route also brings fresh eyes, which tends to surface the things everyone inside the business has stopped seeing. This is something we do for clients alongside ISO 13485 QMS setup, so I’m reasonably biased, but the pattern of one person marking their own homework is the finding I’d least like to receive from a certification body.

On the day, and afterwards

During the audit itself, work from objective evidence and sample real records rather than the ones offered to you. Write findings specific enough that someone could act on them, quoting the record and the gap against the requirement. An audit that finds nothing is usually a sign it wasn’t looking very hard, so treat a modest crop of findings as the system working. Afterwards, the standard’s “without undue delay” wording applies, so get corrections and corrective actions logged with owners and dates, verify they were effective rather than just done, and feed the results into management review, which is where the audit programme for the next cycle gets adjusted. Done that way, the internal audit stops being a chore before the certification visit and becomes the mechanism that keeps the certificate safe.

If you’re setting up a QMS from scratch or facing your first certification audit, or you need an independent pair of hands for the internal audit itself, I’d be happy to have a call to talk it through. There’s no charge for an initial chat, and you can book one here.

Frequently asked questions

Who can carry out an ISO 13485 internal audit?

Anyone with the competence to audit and enough independence from the work being audited, so auditors mustn’t audit their own processes. That can be a trained person from another part of the business or an external contractor conducting the audit on your behalf, which certification bodies accept as normal practice.

How often do internal audits need to be done?

ISO 13485 says planned intervals rather than a fixed frequency. Most manufacturers cover the full QMS over a twelve month cycle, with higher-risk or recently changed processes audited more often. The interval should be justified in your audit programme, ideally with reference to risk.

What should an ISO 13485 internal audit checklist include?

Build it from your own procedures rather than a generic template, so each item checks whether you do what your documents say. Add the open CAPAs, complaint trends and previous audit actions for that process, and for GB devices include the post-market surveillance plan, PMS reporting schedule and vigilance timescales in force since June 2025.

Can I outsource my internal audit?

Yes. An external auditor can plan and conduct the internal audit for you, and it remains an internal audit because it’s performed against your system on your behalf. You keep responsibility for acting on the findings, so the corrective actions still need your ownership and your dates.