QMSAdvisor

Certification and Regulatory Audits

EU Notified Body Audit (Including Unannounced Audits)

To place many devices on the EU market, a notified body has to assess your quality system and technical documentation under the MDR or IVDR. That means planned conformity assessment and surveillance audits, plus unannounced audits that can arrive at your site, or at critical subcontractors and suppliers, without warning.

At a Glance

Conducted by
A notified body designated under the EU MDR or IVDR
Audit types
Conformity assessment, surveillance and unannounced audits
Unannounced audits
At least once every five years under the MDR and IVDR
Reach
Can include critical subcontractors or suppliers; sample testing possible
Framework
Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR)

What It Is

Depending on device class and conformity assessment route, the MDR and IVDR require a notified body to assess the manufacturer. For most manufacturers in that position, this means a quality management system audit, review of technical documentation, and ongoing surveillance after certification.

Surveillance audits check that the system keeps working between certification decisions. Unannounced audits are required at least once every five years. They look at what is actually happening in production, can extend to critical subcontractors or suppliers, and may include checking or testing samples against the technical documentation.

Notified body audits look at the quality system as the MDR and IVDR define it. That goes beyond ISO 13485:2016 to include items such as the person responsible for regulatory compliance, post-market surveillance, vigilance, and the link to clinical or performance evaluation.

Who Conducts It

A notified body designated for your device types under the MDR or IVDR conducts the audits, with auditors and technical experts suited to your technologies.

Critical subcontractors and suppliers need to know they can be visited too. Your agreements with them should allow notified body access, including for unannounced audits.

What Triggers It

  • Initial conformity assessment for devices that require notified body involvement
  • Scheduled surveillance during the certificate period
  • The MDR and IVDR requirement for unannounced audits at least once every five years
  • Significant changes to devices or the quality system that need notified body assessment
  • Information suggesting nonconformity, which may prompt additional audits

What They Look At

  • Quality System Under the MDR or IVDR

    The quality system as the regulation defines it, including the regulatory compliance strategy and the person responsible for regulatory compliance.

  • Link to Technical Documentation

    Whether production matches the technical documentation and whether design changes flowed through to it.

  • Post-Market Surveillance and Vigilance

    Post-market surveillance plans and reports, trend analysis, vigilance reporting and field safety corrective actions.

  • Clinical or Performance Evaluation

    How clinical or performance evaluation is kept current and fed by post-market data.

  • Production on the Day

    During unannounced audits, what is actually running: production records, environmental controls, inspection and release.

  • Critical Subcontractors and Suppliers

    Controls over outsourced processes, and whether the notified body can see them in person.

  • Sample Checks and Testing

    Devices or samples from production checked against the technical documentation.

  • Labeling and UDI

    EU labeling, UDI and instructions for use that match the assessed documentation.

How to Prepare

  1. 01

    Be Ready Any Day

    Unannounced audits mean production records, line clearance and release must be audit-ready every shift, not just in audit weeks.

  2. 02

    Brief Reception and Security

    Make sure whoever meets the auditors knows how to verify their identity and who to call, and that a host can be reached quickly.

  3. 03

    Secure Supplier Access

    Check that agreements with critical subcontractors and suppliers allow notified body visits, and tell those suppliers what to expect.

  4. 04

    Keep Technical Documentation in Step

    Confirm that current production, labeling and suppliers match the technical documentation.

  5. 05

    Rehearse an Unannounced Visit

    Run a surprise internal walkthrough to see how quickly the team can host, retrieve records and answer questions.

Common Pitfalls

  • Quality agreements that don't give the notified body a right of access to critical suppliers.
  • Production records completed at the end of a shift or week rather than as work happens.
  • Technical documentation that lags behind changes already made in production.
  • No designated backup host when key quality staff are away.
  • Post-market surveillance reports that collect data but don't feed the risk file or clinical evaluation.

How QMSAdvisor Helps

  • An AI-assisted gap analysis of your quality system documents against MDR or IVDR expectations, reviewed and confirmed by an advisor.
  • Findings that flag mismatches between technical documentation, production records and supplier agreements, each citing its source.
  • An action plan for supplier access clauses, post-market surveillance gaps and documentation updates, with owners and due dates.
  • Ongoing advisory to keep the system ready between planned audits.

Standards and Regulations Involved

Questions About the EU Notified Body Audit

How often do unannounced audits happen?

The MDR and IVDR require notified bodies to conduct unannounced audits at least once every five years. They can happen more often, depending on the device and the notified body's assessment.

Can a notified body audit our suppliers?

Yes. Unannounced audits can extend to critical subcontractors or suppliers. Your agreements should allow that access, and those suppliers should know an audit could come.

Will they take product samples?

They may. Notified bodies can check or test samples to confirm devices conform to the technical documentation, so samples and their records should be readily traceable.

Is a notified body audit the same as ISO 13485 certification?

No. ISO 13485:2016 is a common foundation, but the audit is against the MDR or IVDR, which add requirements such as post-market surveillance, vigilance and the person responsible for regulatory compliance.

Request an Assessment

Prepare for Your EU Notified Body Audit With an Advisor

Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.