Customer, Supplier and Internal Audits
Internal Audit
Internal audits are how a quality system checks itself. Under the QMSR they matter more than ever: the old exception that kept internal audit reports away from FDA investigators is gone, so your audits are now evidence an investigator can read.
At a Glance
- Conducted by
- Your own trained auditors, or an independent auditor acting for you
- Requirement
- ISO 13485:2016, as incorporated by the QMSR
- FDA access
- Records open to FDA inspection (820.180(c) exception removed)
- Guidance
- ISO 19011 for auditing management systems
- Independence
- Auditors don't audit their own work
What It Is
ISO 13485:2016, and through it the QMSR, requires a planned program of internal audits to check that the quality system meets requirements and is working. The program is shaped by the importance of each process and by what earlier audits found.
ISO 19011 gives guidance on auditing management systems: audit principles, managing an audit program, conducting audits and auditor competence. It's guidance rather than a requirement, but it's the common reference for building a credible program.
The QMSR changed the stakes. Under the former 820.180(c), FDA didn't inspect internal audit reports. That exception was removed, so investigators can now read your internal audit records, see what you found and check whether you acted. A program that finds nothing, or finds problems and leaves them open, is now visible.
Who Conducts It
Trained internal auditors from your own organization, or an outside auditor acting for you. Auditors shouldn't audit their own work, so small companies often bring in an independent party for the areas their few auditors own.
The audit program owner, usually in quality, plans the schedule, assigns auditors, tracks findings and reports results into management review.
What Triggers It
- The planned audit schedule in your internal audit program
- Process importance and risk, which should set how often each area is audited
- Previous audit results, complaints or CAPA trends that point to weak areas
- Preparation for an FDA inspection, certification audit or MDSAP audit
- Significant changes, such as new products, new sites or new requirements like the QMSR
What They Look At
Coverage of All Processes
Whether every process in the quality system is audited over the program's cycle, with more frequent audits where risk is higher.
Effectiveness, Not Just Conformance
Whether processes achieve their intended results, not only whether procedures exist.
Follow-Up on Findings
Corrections and corrective actions taken promptly, and verification that they worked.
FDA-Specific Requirements
MDR, corrections and removals, UDI, and the 820.35 and 820.45 provisions, alongside ISO 13485 requirements.
Auditor Independence and Competence
Auditors who don't audit their own work and are trained for the processes they cover.
Input to Management Review
Audit results reported to leadership and used in decisions.
How to Prepare
- 01
Plan by Risk
Set audit frequency by process importance and history, and document why.
- 02
Audit Against the CP 7382.850 Areas
Organize at least one audit cycle around the six QMS areas and four other FDA requirements that FDA inspections now use.
- 03
Write Factual Reports
Record objective evidence and clear findings, on the assumption that an investigator will read them.
- 04
Track Findings to Verified Closure
Use CAPA where warranted, and verify effectiveness before closing.
- 05
Train and Rotate Auditors
Build auditor competence and keep auditors out of their own areas.
Common Pitfalls
- Audits that check whether procedures exist rather than whether they work.
- Findings softened or dropped because the report might be read by FDA.
- A schedule that slips for months without a documented reason.
- Auditors auditing their own processes in small teams.
- Findings left open across several audit cycles.
- Checklists built for ISO 13485 alone that skip FDA-specific requirements.
How QMSAdvisor Helps
- Design of an internal audit program organized by risk and by the CP 7382.850 areas, alongside ISO 13485:2016 requirements.
- Independent internal audits of areas your own auditors can't cover without auditing their own work.
- An AI-assisted first pass over the documents in scope, so audit time goes into interviews and records rather than hunting for files.
- Findings tracked to closure with advisor evidence review and an immutable activity history.
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
QMSR Transition
Bringing a QSR-era or ISO 13485 quality system in line with FDA's QMSR, which is now in effect.
CAPA System Remediation
Fixing a CAPA system auditors keep citing: the procedure, the records, root cause, effectiveness and backlog.
Full Audit Readiness Assessment
Documents, records, evidence and interviews, checked against the specific audit you're facing next.
Standards and Regulations Involved
Questions About the Internal Audit
Can FDA read our internal audit reports?
Yes. The QMSR removed the former 820.180(c) exception, so internal audit records, along with management review and supplier audit records, are open to FDA inspection.
Should we write vaguer reports now that FDA can see them?
No. Vague reports undermine the purpose of the audit and are a warning sign in their own right. Write factual findings and show that you acted on them; a program that finds and fixes problems is the best evidence you can offer.
How often should we audit each process?
ISO 13485:2016 doesn't set a fixed frequency. Base it on process importance, risk and previous results, and record the rationale in your audit program.
Can we outsource internal audits?
Yes. An external auditor can conduct internal audits for you, which helps with independence in small teams. You still own the program, the findings and the follow-up.
What standard guides internal auditing?
ISO 19011 provides guidance on auditing management systems, including audit program management and auditor competence. It's widely used as the reference for internal audit programs.
Related Audits and Inspections
Supplier Audit
Audits you perform of your own suppliers and contract manufacturers as part of purchasing controls.
Mock Audit and Mock Inspection
A realistic practice inspection, with an advisor playing the FDA investigator, before the real one arrives.
ISO 13485 Surveillance Audit
The periodic audits, at least annually, that support continued ISO 13485 certification between renewals.
Request an Assessment
Prepare for Your Internal Audit With an Advisor
Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.


