Quality

ISO 13485 Internal Audits, Done For You

ISO 13485 requires you to audit your own quality management system at planned intervals, by people who are independent of the work being audited. For most small and mid-sized device companies that is the hardest clause to satisfy in-house. Taylored runs your internal audit programme for you: clause-by-clause QMS audits, supplier audits and mock certification audits, remote or on-site.

Independent auditors, findings you can act on, and a system that is ready before the certification body arrives.

Client healthcare and skincare products with a stethoscope
Why outsourceWhat we auditAnnual cycleMock auditsChecklistPricingFAQs

Why outsource your ISO 13485 internal audits

Clause 8.2.4 of ISO 13485 asks for internal audits at planned intervals, carried out by auditors who do not audit their own work. In a company of ten or twenty people, where the quality manager also writes the procedures and runs the CAPA system, true independence is close to impossible. Certification bodies know this, and it is one of the most common findings they raise.

Outsourcing the audit solves the independence problem outright, but that is only half the value. An external auditor who has seen dozens of device QMSs brings a benchmark your team does not have: what good looks like, where systems like yours tend to fail, and what your certification body is likely to focus on next.

It also frees your quality team to fix things rather than find them. An internal audit is only useful if the findings are closed, and the people best placed to close them are rarely the ones with time to plan, conduct and write up the audit as well.

We audit against ISO 13485:2016 and the regulations that apply to your devices, including UK MDR, EU MDR and IVDR, and the FDA's Quality Management System Regulation, so one audit programme covers every market you sell into.

What we audit

Full QMS audits

A clause-by-clause audit of your whole quality management system, or a sampled programme that covers every clause across the year. We check that processes exist, are documented and are followed, using your own records as the evidence.

Supplier and subcontractor audits

Critical suppliers, contract manufacturers and sterilisation providers audited against your requirements and ISO 13485, with a report you can file as evidence of supplier control.

Process and product audits

Focused audits of a single process, such as design controls, CAPA, complaint handling or production, where you suspect a weakness or a regulator has asked questions.

Every audit produces a written report with graded findings, objective evidence and a clear owner and due date for each corrective action, in the format certification bodies expect to see.

How the annual audit cycle works

Most clients hand us the whole programme. Here is what a year typically looks like.

Audit plan

We build or refresh your annual audit schedule so that every clause and every critical process is covered at a frequency that matches its risk, and that the plan itself satisfies the standard.

Audits through the year

Audits are carried out to the plan, remotely or on-site, with the people who run each process. Findings are reviewed with you at a closing meeting on the day.

Follow-up and management review

We verify that corrective actions have closed, feed the results into your management review, and adjust next year's plan based on what we found.

If you prefer to keep audits in-house and only need independence for specific areas, we can audit the quality function itself, the one part of the system your quality manager can never audit.

Mock certification audits

Before a Stage 1, Stage 2, surveillance or recertification audit, a mock audit run the way the certification body will run it removes the surprises. We cover:

Mock audits are most valuable four to eight weeks before the real one: close enough that the system is in its final state, far enough away to fix what we find.

ISO 13485 internal audit checklist: what auditors actually look for

Every auditor works from a checklist, but the checklist is not the audit. What separates a pass from a list of findings is whether the records tell the same story as the procedures. Here are the areas where we, and certification bodies, spend most of our time.

Management responsibility and management review with real inputs and decisions. Document and record control that people actually follow. Design and development files that show planning, inputs, outputs, verification, validation and transfer. Risk management under ISO 14971 woven through design and production. Supplier evaluation with evidence. Production controls, including validation of any process whose output cannot be fully verified. Complaint handling, vigilance reporting and CAPA that closes the loop.

If you want a starting point for your own audits, our team can share the checklist structure we use and walk you through how to apply it. What we will not do is hand over a template and call it an audit.

Ask us about the checklist

Not sure whether your QMS is audit-ready?

A fixed-scope gap analysis maps your quality management system against every clause of ISO 13485 and hands you a prioritised plan, so the internal audit finds what you expect it to find.

Start with a gap analysis

How internal audit pricing works

Internal audits are priced per audit day or as an annual programme fee, agreed in writing before the first audit. What moves the price is the scope: the number of clauses and processes in play, how many sites and suppliers are involved, and whether audits are remote or on-site.

We do not publish a rate card, because an annual programme for a single-site software company and quarterly audits across three manufacturing sites are very different jobs. What we can promise is a fixed scope and a fixed fee before any audit starts.

Get a quote for your audit programme

Surveillance and recertification preparation

Certification does not end at the certificate. Surveillance audits follow every year and recertification every three, and the certification body will want to see that internal audits and management reviews have happened on schedule in between. Gaps in that record are an easy finding.

We keep the programme on track between external audits, and run a focused readiness review before each one so that surveillance is a formality rather than a scramble.

Talk to us before your next surveillance audit

Frequently Asked Questions

How often are ISO 13485 internal audits required?

The standard says at planned intervals, and leaves the interval to you, based on the importance and risk of each process and the results of previous audits. In practice most device companies audit every clause at least once a year, with higher-risk processes audited more often. Your certification body will expect to see the plan and the evidence that you followed it.

Can internal audits be done remotely?

Yes. Document review, records sampling and interviews all work well remotely, and certification bodies themselves now audit remotely where it is appropriate. Production, cleanroom and warehouse processes are usually audited on-site, and we agree the mix with you when we scope the programme.

Do you audit our suppliers as well?

Yes. Supplier and subcontractor audits are part of the service, whether that is a critical component supplier, a contract manufacturer or a sterilisation provider. We audit against your supplier requirements and ISO 13485, and give you a report that stands as evidence of supplier control.

Can an outsourced auditor really count as our internal audit?

Yes. ISO 13485 requires auditors to be objective and impartial and not to audit their own work. It does not require them to be employees. An outsourced auditor working to your audit programme is the cleanest way for a small company to meet the independence requirement, and certification bodies accept it routinely.

What happens if you find a major nonconformity?

That is the point of an internal audit: to find it before the certification body does. We grade every finding, explain what would happen if an external auditor saw it, and agree a corrective action and owner with you on the day. We can then verify closure before your next external audit.

Why Taylored for your internal audits

Our auditors are experienced ISO 13485 lead auditors who have audited on behalf of manufacturers and prepared them for certification bodies for years. We know which findings are cosmetic and which will stop your certificate, and we tell you the difference plainly.

Need independent internal audits this year?

Book an audit call