QSIT-Based ISO 13485 Internal Audit Schedule

M

MyronW

Our internal audit schedule had become an unwieldy nightmare for me. I am the only auditor, and the schedule was not process based, it was not logic based, it was not anything based. It was just a mess that I inherited, so I took it upon myself to make some sense of it.

Fortunately, I had just completed an audit cycle, and our system is in pretty good shape, so I didn't have any huge messes to clean up. I started looking at different ways to schedule the audits according to the standard: status, importance, results of previous audits, etc., and found that none of these criteria are useful for setting up a baseline schedule. That's why new folks stand around with that deer-in-the headlights look when they try to set up their first schedule. It doesn't make sense to set up a results-based schedule when you don't have any results to work with!

After much thought and work, I developed an annual internal audit schedule that is based on the FDA's QSIT Manual. I was careful to keep it as process-based as I could, although there is room for improvement. All of the ISO 13485:2003 elements are covered, but they are not sequential, nor are they intended to be.

Have a look, and let me know what you think. So far it's worked out quite well!

Myron
 

Attachments

  • QSIT-Based Internal Audit Schedule.xlsx
    25.5 KB · Views: 1,529
M

MIREGMGR

You say that things are in pretty good shape regarding preceding internal audits...is that also true of your CB's last couple of audits, and of any recent FDA inspections?
 
G

Gert Sorensen

That looks very interesting. I will dig into it immediately!

Thank you for sharing it.
:bigwave:
 
M

MyronW

You say that things are in pretty good shape regarding preceding internal audits...is that also true of your CB's last couple of audits, and of any recent FDA inspections?

FDA came through here in September. No troubles.:D
We had our recertifying audit 2 weeks ago. We passed, although there were 3 minor NCs. One for an obsolete sterilization standard (we don't make sterile products), one for references to obsolete revisions of standards in a couple of SOPs and a job description, and one for a missing audit checklist.:bonk:

Each of these NCs falls on my shoulders as the internal auditor to detect prior to an outside audit. I inherited this system in May of last year, and I'm the Chief Cook and Bottlewasher when it comes to doing audits both internal and external. I take this stuff both seriously and personally, and when it becomes apparent that I have not performed to the same standard I hold others to, I am mortified.

That's why I developed this new QSIT-based schedule. I created it prior to the recent audits, but the cycle had just started. I am confident that as the audits progress, there will be more that comes to light, and more that needs to be fixed.
 

Weiner Dog

Med Device Consultant
Glad that you have developed a QSIT-based audit approach.

My understanding is that internal audits typically should be quality system based. When required (such as through risk analysis), mini process audits should occur. This is how FDA does it. Why shouldn't US companies do the same? Why do some US companies base their internal audits against EU notified body requirements first?
 
M

MIREGMGR

Why do some US companies base their internal audits against EU notified body requirements first?

One reason might be that a US company certified to ISO 13485 and CE Mark is audited ~annually for those certifications, and much less frequently by FDA. We talk with FDA regularly, but they haven't been in to see us in almost eight years.

In addition, the Voluntary Audit Report Submission program is expected to get off the ground sometime soon, and it'll formally replace the QSIT1 process with US FDA recognition of the ISO 13485 audit process.
 
J

jinggu

That's how I find it to be. My current audit plan developed around FDA requirements were berated by ISO certification body. I figure a plan fulfilling EU or ISO requirements put you in a better position in face of FDA's inspections.
 
S

SpeedRacer24

This audit schedule looks quite good and very well thought out . Thanks MyronW for sharing this.

As a Quality Engineer one of my many responsibilities is to manage the Internal Audit program. My Manager has requested that we move to a QSIT style audit approach in 2014. I'm going to see if your schedule could be of help to me in this regards.

Now I just need a really good QSIT style internal audit checklist as a starting point for the auditors to go on. Can anyone here suggest where I might be able to find one? Please let me know, thanks. :)
 

love02eat

Involved In Discussions
Our internal audit schedule had become an unwieldy nightmare for me. I am the only auditor, and the schedule was not process based, it was not logic based, it was not anything based. It was just a mess that I inherited, so I took it upon myself to make some sense of it.

Fortunately, I had just completed an audit cycle, and our system is in pretty good shape, so I didn't have any huge messes to clean up. I started looking at different ways to schedule the audits according to the standard: status, importance, results of previous audits, etc., and found that none of these criteria are useful for setting up a baseline schedule. That's why new folks stand around with that deer-in-the headlights look when they try to set up their first schedule. It doesn't make sense to set up a results-based schedule when you don't have any results to work with!

After much thought and work, I developed an annual internal audit schedule that is based on the FDA's QSIT Manual. I was careful to keep it as process-based as I could, although there is room for improvement. All of the ISO 13485:2003 elements are covered, but they are not sequential, nor are they intended to be.

Have a look, and let me know what you think. So far it's worked out quite well!

Myron


Love the the QSIT. How is this working for you since 2010. I was thinking of using this. But if you also have a updated version would love to see it. my story is similar like yours. we are also ISO13485:2003.


Many thanks :applause:
Rachel
 
Thread starter Similar threads Forum Replies Date
B Looking for recommendation for QSIT Training Training - Internal, External, Online and Distance Learning 4
M Audit of Goods In as part of the QSIT "Production & Process Controls" Schedule 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 4
T What do "OAI" "VAI" and "NAI" used in FDA QSIT manual mean in inspections? ISO 13485:2016 - Medical Device Quality Management Systems 3
J US based company no longer selling in the EU: Clinical Evaluation Report and PMS requirements EU Medical Device Regulations 1
D Risk Based Sample Size and Standards Compliance ISO 14971 - Medical Device Risk Management 2
P Increase in audit days for multi-site companies based on the new AS9104-1 2022 AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 0
C VOCs as extractable in substance based medical device EU Medical Device Regulations 0
M Risk-based approach to Test Method Validation for Design Verification? US Medical Device Regulations 5
T Use errors identification - based on primary operating functions or use scenarios ? IEC 62366 - Medical Device Usability Engineering 3
T AS9100D Risk-Based Internal Audit Schedule AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 10
J0anne How to find Certifying Bodies for US based & sold Medical Devices? US Medical Device Regulations 11
T Risk based CA AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 5
A CE-Mark regulatory advice - US based Organization CE Marking (Conformité Européene) / CB Scheme 6
A ISO 9001- any advise please with transitioning from a paper based system to eQMS and multi site scope ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 1
L Do non-EU based manufacturers require an importer/distributor? EU Medical Device Regulations 23
D Integrated Management System (IMS) - Process Vs Clause Based Audits ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 19
C Need help in determining applicable clause for an audit finding (based on AS9120B) ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 4
A Information on Process-based Internal Auditing Needed Internal Auditing 6
M ADME data- substances based MD EU Medical Device Regulations 0
E Which regulatory framework for an app-based study for research purposes? EU Medical Device Regulations 1
J Cloud Based System Qualification and Validation (including 21 CFR Part 11) 7
R Does anyone use iQMS for their ISO based document control? Manufacturing and Related Processes 5
C What Theory is MIL-STD-105E Sample Size Code Letters Based on? Quality Tools, Improvement and Analysis 3
N QMS standard for a research based Organisation Quality Manager and Management Related Issues 1
R Cloud-based SaMD Validation IEC 62304 - Medical Device Software Life Cycle Processes 8
S How many tester quantity we need on the line based on the cycle time and peak volume Manufacturing and Related Processes 3
S Alcohol based cleaner for Food Contact Surface? Food Safety - ISO 22000, HACCP (21 CFR 120) 0
I Excel based Gage R&R VS Minitab calculation Gage R&R (GR&R) and MSA (Measurement Systems Analysis) 5
P Scenario based risk assessment IEC 27001 - Information Security Management Systems (ISMS) 1
C CBD based products registration in EU and UK EU Medical Device Regulations 4
L Economic Operator based in UK EU Medical Device Regulations 10
C Biologic Evaluation based on ISO 10993-1 EU Medical Device Regulations 2
R Select the 1 Supplier based on the Parts Durability from 6 Supplier Samples using Minitab Using Minitab Software 11
H Existing cloud based medical device - questions regarding improving the processes IEC 62304 - Medical Device Software Life Cycle Processes 6
A % of defects on the whole batch based on result from inspection under AQL Level II Inspection, Prints (Drawings), Testing, Sampling and Related Topics 6
Ed Panek Does this FDA Requirement Apply to international (not USA) distributors for USA based manufacturing companies? 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 0
R X-RAY Based Diagnostic Veterinary medical Devices Medical Device and FDA Regulations and Standards News 2
T Controlling Expandable Forms in Paper-Based Document Control System Document Control Systems, Procedures, Forms and Templates 10
M Reduce occurrence rating based on the PMS data and customer complaint data ISO 14971 - Medical Device Risk Management 2
K Interesting Discussion "World Class Product" based QM. I need advice. Quality Management System (QMS) Manuals 14
S DHF/DMR/MDF for a software-only, cloud-based, single-instance device Medical Information Technology, Medical Software and Health Informatics 2
Sidney Vianna IATF 16949 News Risked Based Audit Day Calculation IATF 16949 - Automotive Quality Systems Standard 2
S Annual Inspection Layout - Based on Customer print ? IATF 16949 - Automotive Quality Systems Standard 8
F IVD registration in EU - Northern Ireland based company EU Medical Device Regulations 0
M Medical device substance based-leachables Other Medical Device Related Standards 2
A API Spec Q1 Purchasing Process - Supplier Reevaluation based on Supplier Risks 5.6.1.4 Oil and Gas Industry Standards and Regulations 19
P Testing cloud-based backups IT (Information Technology) Service Management 8
silentmonkey Rationalising the level of effort and depth of software validation based on risk ISO 13485:2016 - Medical Device Quality Management Systems 10
P Conformity assessment based on a quality management system or production quality assurance EU Medical Device Regulations 3
DuncanGibbons Model-Based procedures and Architecting the QMS as a System Document Control Systems, Procedures, Forms and Templates 2

Similar threads

Top Bottom