ISO 13485 Audit Finding on Regulatory Issues - Internal Audits

kansascitysteve

Starting to get Involved
#1
We are currently going through ISO 13485 certification and completed stage 1. The auditor reviewed all of our internal audit records and noted that we have not performed regulatory internal audits.

He tols us we had to complete a full internal audit to verify compliance with applicable regulations. We are also going for CMDCAS, TGA, and MDD with this audit.

Can someone please point me in the right direction with how to perform an internal regulatory audit? We have verified compliance with 13485, but am not sure where to begin for the various regulations.

Any help or guidance is greatly appreciated...!
Thanks
 
Elsmar Forum Sponsor
C

cclee

#2
Re: 13485 Audit finding - Internal Audits

Hi, one approach you could use is to reference the applicable clause/section/article/Annex in your internal audit documents or records ( audit plan, checklist, matrix, ..etc) when assessing the audit evidence against the audit criteria.

For example, if your quality manual claims conformance to ISO13485, CMDCAS, MDD & PAL you should reference the apppropriate elements under assessment:

Audit topic: Control of records
ISO13485 - 4.2.4
CMDRs - sec. 9 (2), se. 34, sec. 43, sec 52-56
MDD - Annex II, 3.2
Article 9

Hope this helps.
 
Last edited by a moderator:
#3
Re: 13485 Audit finding - Internal Audits

Have you been doing process based audits? If so, researching the various regulatory requirements affecting each process, from those requirements (CMDCAS etc) these can be added into whatever planning tool/checklist you use. If you've been doing just compliance to ISO 13485, you might have narrowly dodged another NC for not auditing processes, too...:notme:
 

Sidney Vianna

Post Responsibly
Leader
Admin
#5
Re: ISO 13485 Audit Finding - Internal Audits

He tols us we had to complete a full internal audit to verify compliance with applicable regulations. We are also going for CMDCAS, TGA, and MDD with this audit.

Any help or guidance is greatly appreciated...!
Thanks
While compliance with regulations is critical, ISO 13485 does not specifically mandate you perform an internal audit against regulatory requirements. If you can demonstrate that your organization has the knowledge & awareness of the requirements and compliance is assured via adherence to the business processes that embed the means to comply with regulations, an "internal regulatory compliance audit" would be redundant.
 
R

Roland Cooke

#6
Re: ISO 13485 Audit Finding - Internal Audits

I basically agree with Sidney.

That said, I would perform an documentation audit against the various regulations to ensure that all applicable requirements have been built into the overall system.

In addition, you may find there is benefit in doing sub-audits that focus on specific regulatory elements (vigilance handling, technical files, etc).
 

Jen Kirley

Quality and Auditing Expert
Leader
Admin
#7
Re: ISO 13485 Audit Finding - Internal Audits

While compliance with regulations is critical, ISO 13485 does not specifically mandate you perform an internal audit against regulatory requirements. If you can demonstrate that your organization has the knowledge & awareness of the requirements and compliance is assured via adherence to the business processes that embed the means to comply with regulations, an "internal regulatory compliance audit" would be redundant.
I am feeling too hot to believe I am as sharp as I otherwise hope to be, but I believe Sidney is saying the standard asks us to understand what regulations require of us, to build our systems in a way to clearly meet those requirements, and to audit against that system. Did I get that right, Sidney?

The thing is, in order to convince people we're doing this there should be evidence. There should be something that shows what regulations your organization recognizes it must meet, how your planning methods ensure that's getting done (including updates), and practical examples of procedures and actual activities supporting it's happened.

Typically auditors list an element number alongside evidence of compliance. In order to lay anyone's concerns to rest, when auditing heavily regulated systems like Process Safety Management I cite actual codes along with the standard elements I'm auditing against. Maybe this isn't the best method, but it's worked for my people and me.
 
#8
Re: ISO 13485 Audit Finding - Internal Audits

Going from the Title of ISO 13485 (Requirements for regulatory purpose), your internal audit scope must be specific to what you are auditing, based on the regulations to which you claim alignment of your QMS.
Ex.: ISO13485 + MDD + CMDR
The requirements for regulatory purpose once gets into the audit scope, will encompass the audit of specific requirements. Note that many of your procedures (documented or otherwise) for your various processes will be aligned to one or more regulatory requirements as well, and you may also have specific procedures for specific regulatory requirements.
Typically when an internal audit of design and development is planned, dwelling into the design inputs from the regulatory requirements points will be a good example, and from this all other design route could be audited.
CMDR requires certain annual renewals and if CMDR is in your internal audit scope, you could audit both the process of how this is complied with and look for records of evidence. Similarly MDD requires specific tasks for a manufacturer who is out of europe. These could also be audited for compliance when MDD is in your internal audit scope. So it depends on how you have integrated the regulatory inputs and tasks into your QMS, and how they are performed, including internal audits...
 
Last edited:

Sidney Vianna

Post Responsibly
Leader
Admin
#9
Re: ISO 13485 Audit Finding - Internal Audits

Did I get that right, Sidney?
Hi Jennifer.
Yes, you got the essence of my post. But let me add: Assuring regulatory compliance via internal audits is like driving a car forward by looking at the rear view mirrors (pardon the cliche'). Internal audits are just one component of the check step in the PDCA cycle.

Compliance with regulatory regulations, just like focus on customer satisfaction and product conformity CAN ONLY be sustainably achieved if the tasks and activities necessary are EMBEDDED in the business processes of the organization. Some of the regulatory requirements any organization has to comply with are part of the QMS; So, if I internally audit my QMS thoroughly, I am ALSO checking if my organization has a system to ensure regulatory compliance or not, thus no need for a separate internal regulatory compliance audit.
 
Thread starter Similar threads Forum Replies Date
kys123 Implications of failing an Anvisa Audit for ISO 13485 Certification ISO 13485:2016 - Medical Device Quality Management Systems 4
D Audit Report details when ISO 13485:2016 and cGMP 21 CFR 820 are applicable ISO 13485:2016 - Medical Device Quality Management Systems 6
R Looking for ISO 13485 Internal Audit Checklist ISO 13485:2016 - Medical Device Quality Management Systems 8
D Question on using audit checklist ISO 13485:2016 ISO 13485:2016 - Medical Device Quality Management Systems 20
D Lead time to schedule an ISO 13485 audit General Auditing Discussions 2
S Does anyone have a checklist to prepare for ISO 13485, Stage I audit? ISO 13485:2016 - Medical Device Quality Management Systems 3
M ISO 13485:2016 internal audit checklist Medical Device and FDA Regulations and Standards News 8
F ISO 13485 - EU countries that could request another audit ISO 13485:2016 - Medical Device Quality Management Systems 2
L How to deal with an ISO 13485 Supplier Audit nonconformance ISO 13485:2016 - Medical Device Quality Management Systems 17
A What if Contract Manufacturers does not have an ISO 13485 certificate? Where will the NB audit take place, at legal mfg. site or contract mfg. site? Other Medical Device Regulations World-Wide 3
B Using external FDA and ISO 13485 audit as internal audit Internal Auditing 6
L ISO 13485:2016 Clause 8.4 - Analysis of Audit Observations ISO 13485:2016 - Medical Device Quality Management Systems 8
M Internal audit consultant ISO 13485 Needed in France (English speaker) Consultants and Consulting 4
P Dropping ISO 9001 limits the scope of the ISO 13485 audit? ISO 13485:2016 - Medical Device Quality Management Systems 6
E MDSAP Audit - Our QMS conforms to ISO 13485:2016 and FDA GMP Canada Medical Device Regulations 9
J ISO 13485 Audit Nonconformance written against 6.3 Infrastructure ISO 13485:2016 - Medical Device Quality Management Systems 25
J Training documentation - ISO 13485 audit and the auditor had questions General Auditing Discussions 7
J EU ISO 13485:2016 Recertification Audit - Effect of 10 Minor Nonconformances EU Medical Device Regulations 2
J ISO 13485 Recertification audit extension ISO 13485:2016 - Medical Device Quality Management Systems 1
M Internal Audit Assessment Criteria - ISO 13485:2016 Internal Auditing 21
A ISO-13485 7.1 - Preparing for our MDSAP audit ISO 13485:2016 - Medical Device Quality Management Systems 5
T ISO 13485: 2016 Internal Audit - Is sampling on projects allowed? ISO 13485:2016 - Medical Device Quality Management Systems 6
D Where I can find an ISO 13485:2016 Audit Schedule example? ISO 13485:2016 - Medical Device Quality Management Systems 4
L Need HELP with Internal Audit Program ISO 13485.2003 Quality Management System (QMS) Manuals 3
J Internal Audits - Closing Audit Deficiency Reports (ISO 13485) Internal Auditing 4
S EN ISO 13485:2016 vs. ISO 13485:2016 - Unannounced MDD Audit yesterday ISO 13485:2016 - Medical Device Quality Management Systems 4
V Under what circumstances will a Registrar Audit a Company? (ISO 13485 - Canada) Canada Medical Device Regulations 5
A Audit Checklist for ISO 13485:2016 ISO 13485:2016 - Medical Device Quality Management Systems 21
S Audit checklist for "Design Controls" per ISO 13485 wanted Internal Auditing 3
somashekar ISO 13485 plus ISO 9001:2015 will now attract a minimum 2 day upgrade audit ISO 13485:2016 - Medical Device Quality Management Systems 9
M ISO 13485 Audit Questions - Internal Auditor Training and other Requirements ISO 13485:2016 - Medical Device Quality Management Systems 10
J Can I conduct Internal Audit for combined ISO 9001, ISO 13485 and ISO 14001? Internal Auditing 37
Q Writing appropriate ISO 13485 Audit Report Findings Internal Auditing 15
S How is the NB ISO 13485 audit for CE Marking different from regular ISO audit ? EU Medical Device Regulations 5
K Including ISO 13485 Audit JPAL Registration Japan Medical Device Regulations 3
M ISO 13485 Certification - Internal Audit Program Required ISO 13485:2016 - Medical Device Quality Management Systems 12
J Pre-Revenue Medical Device Company ISO 13485 Audit ISO 13485:2016 - Medical Device Quality Management Systems 1
F Response to ISO 13485 Audit Minor Nonconformances ISO 13485:2016 - Medical Device Quality Management Systems 6
L Mock Audit by External Consultant (ISO 13485) 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 8
Q Class I Technical File reviewed during ISO 13485 Certification Audit by NB CE Marking (Conformité Européene) / CB Scheme 10
A Quality Objectives 5.4.1 - KPI SOP - ISO 13485 Audit Observations EU Medical Device Regulations 6
M IAF-MD9 Audit Man-Days Requirements for ISO 13485 Quality Manager and Management Related Issues 30
R How much "harder" is an ISO 13485 Registration Audit compared to ISO 9001 ISO 13485:2016 - Medical Device Quality Management Systems 6
Q Post Market Surveillance SOP - ISO 13485 Audit Nonconformance ISO 13485:2016 - Medical Device Quality Management Systems 3
L ISO 13485 Internal Audit Schedule example needed Internal Auditing 9
T One Supplier Audit Checklist to cover ISO 9001:2008 and 13485:2003 Supplier Quality Assurance and other Supplier Issues 1
T I'm seeking ISO 13485:2003 Supplier Audit Checklist Supplier Quality Assurance and other Supplier Issues 1
C Lapse between ISO 13485 certificate expiring and new audit ISO 13485:2016 - Medical Device Quality Management Systems 9
J General ISO 13485 Certification Assessment Audit Question ISO 13485:2016 - Medical Device Quality Management Systems 1
C Contract Manufacturer and Stage 2 Audit for ISO 13485 ISO 13485:2016 - Medical Device Quality Management Systems 5

Similar threads

Top Bottom