Certification and Regulatory Audits
EU Notified Body Audit (Including Unannounced Audits)
To place many devices on the EU market, a notified body has to assess your quality system and technical documentation under the MDR or IVDR. That means planned conformity assessment and surveillance audits, plus unannounced audits that can arrive at your site, or at critical subcontractors and suppliers, without warning.
At a Glance
- Conducted by
- A notified body designated under the EU MDR or IVDR
- Audit types
- Conformity assessment, surveillance and unannounced audits
- Unannounced audits
- At least once every five years under the MDR and IVDR
- Reach
- Can include critical subcontractors or suppliers; sample testing possible
- Framework
- Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR)
What It Is
Depending on device class and conformity assessment route, the MDR and IVDR require a notified body to assess the manufacturer. For most manufacturers in that position, this means a quality management system audit, review of technical documentation, and ongoing surveillance after certification.
Surveillance audits check that the system keeps working between certification decisions. Unannounced audits are required at least once every five years. They look at what is actually happening in production, can extend to critical subcontractors or suppliers, and may include checking or testing samples against the technical documentation.
Notified body audits look at the quality system as the MDR and IVDR define it. That goes beyond ISO 13485:2016 to include items such as the person responsible for regulatory compliance, post-market surveillance, vigilance, and the link to clinical or performance evaluation.
Who Conducts It
A notified body designated for your device types under the MDR or IVDR conducts the audits, with auditors and technical experts suited to your technologies.
Critical subcontractors and suppliers need to know they can be visited too. Your agreements with them should allow notified body access, including for unannounced audits.
What Triggers It
- Initial conformity assessment for devices that require notified body involvement
- Scheduled surveillance during the certificate period
- The MDR and IVDR requirement for unannounced audits at least once every five years
- Significant changes to devices or the quality system that need notified body assessment
- Information suggesting nonconformity, which may prompt additional audits
What They Look At
Quality System Under the MDR or IVDR
The quality system as the regulation defines it, including the regulatory compliance strategy and the person responsible for regulatory compliance.
Link to Technical Documentation
Whether production matches the technical documentation and whether design changes flowed through to it.
Post-Market Surveillance and Vigilance
Post-market surveillance plans and reports, trend analysis, vigilance reporting and field safety corrective actions.
Clinical or Performance Evaluation
How clinical or performance evaluation is kept current and fed by post-market data.
Production on the Day
During unannounced audits, what is actually running: production records, environmental controls, inspection and release.
Critical Subcontractors and Suppliers
Controls over outsourced processes, and whether the notified body can see them in person.
Sample Checks and Testing
Devices or samples from production checked against the technical documentation.
Labeling and UDI
EU labeling, UDI and instructions for use that match the assessed documentation.
How to Prepare
- 01
Be Ready Any Day
Unannounced audits mean production records, line clearance and release must be audit-ready every shift, not just in audit weeks.
- 02
Brief Reception and Security
Make sure whoever meets the auditors knows how to verify their identity and who to call, and that a host can be reached quickly.
- 03
Secure Supplier Access
Check that agreements with critical subcontractors and suppliers allow notified body visits, and tell those suppliers what to expect.
- 04
Keep Technical Documentation in Step
Confirm that current production, labeling and suppliers match the technical documentation.
- 05
Rehearse an Unannounced Visit
Run a surprise internal walkthrough to see how quickly the team can host, retrieve records and answer questions.
Common Pitfalls
- Quality agreements that don't give the notified body a right of access to critical suppliers.
- Production records completed at the end of a shift or week rather than as work happens.
- Technical documentation that lags behind changes already made in production.
- No designated backup host when key quality staff are away.
- Post-market surveillance reports that collect data but don't feed the risk file or clinical evaluation.
How QMSAdvisor Helps
- An AI-assisted gap analysis of your quality system documents against MDR or IVDR expectations, reviewed and confirmed by an advisor.
- Findings that flag mismatches between technical documentation, production records and supplier agreements, each citing its source.
- An action plan for supplier access clauses, post-market surveillance gaps and documentation updates, with owners and due dates.
- Ongoing advisory to keep the system ready between planned audits.
EU MDR and IVDR Readiness
Prepare your QMS and technical documentation for notified body audits under the EU MDR or IVDR.
Supplier Audits and Supplier Controls
Risk-based supplier selection, quality agreements, monitoring and supplier audits that hold up under QMSR.
ISO 13485 Certification Readiness
Prepare your QMS, records and people for a certification body's Stage 1 and Stage 2 audits.
Ongoing Advisory and Continuous Readiness
Periodic re-assessments, a live action plan and yearly mock inspections that keep readiness from decaying.
Standards and Regulations Involved
Questions About the EU Notified Body Audit
How often do unannounced audits happen?
The MDR and IVDR require notified bodies to conduct unannounced audits at least once every five years. They can happen more often, depending on the device and the notified body's assessment.
Can a notified body audit our suppliers?
Yes. Unannounced audits can extend to critical subcontractors or suppliers. Your agreements should allow that access, and those suppliers should know an audit could come.
Will they take product samples?
They may. Notified bodies can check or test samples to confirm devices conform to the technical documentation, so samples and their records should be readily traceable.
Is a notified body audit the same as ISO 13485 certification?
No. ISO 13485:2016 is a common foundation, but the audit is against the MDR or IVDR, which add requirements such as post-market surveillance, vigilance and the person responsible for regulatory compliance.
Related Audits and Inspections
ISO 13485 Certification Audit (Stage 1 and Stage 2)
The Stage 1 and Stage 2 audits a certification body runs before granting ISO 13485 certification.
MDSAP Audit
One audit by a recognized auditing organization that covers several participating regulators, including FDA.
Supplier Audit
Audits you perform of your own suppliers and contract manufacturers as part of purchasing controls.
Request an Assessment
Prepare for Your EU Notified Body Audit With an Advisor
Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.


