QMSAdvisor

Customer, Supplier and Internal Audits

Internal Audit

Internal audits are how a quality system checks itself. Under the QMSR they matter more than ever: the old exception that kept internal audit reports away from FDA investigators is gone, so your audits are now evidence an investigator can read.

At a Glance

Conducted by
Your own trained auditors, or an independent auditor acting for you
Requirement
ISO 13485:2016, as incorporated by the QMSR
FDA access
Records open to FDA inspection (820.180(c) exception removed)
Guidance
ISO 19011 for auditing management systems
Independence
Auditors don't audit their own work

What It Is

ISO 13485:2016, and through it the QMSR, requires a planned program of internal audits to check that the quality system meets requirements and is working. The program is shaped by the importance of each process and by what earlier audits found.

ISO 19011 gives guidance on auditing management systems: audit principles, managing an audit program, conducting audits and auditor competence. It's guidance rather than a requirement, but it's the common reference for building a credible program.

The QMSR changed the stakes. Under the former 820.180(c), FDA didn't inspect internal audit reports. That exception was removed, so investigators can now read your internal audit records, see what you found and check whether you acted. A program that finds nothing, or finds problems and leaves them open, is now visible.

Who Conducts It

Trained internal auditors from your own organization, or an outside auditor acting for you. Auditors shouldn't audit their own work, so small companies often bring in an independent party for the areas their few auditors own.

The audit program owner, usually in quality, plans the schedule, assigns auditors, tracks findings and reports results into management review.

What Triggers It

  • The planned audit schedule in your internal audit program
  • Process importance and risk, which should set how often each area is audited
  • Previous audit results, complaints or CAPA trends that point to weak areas
  • Preparation for an FDA inspection, certification audit or MDSAP audit
  • Significant changes, such as new products, new sites or new requirements like the QMSR

What They Look At

  • Coverage of All Processes

    Whether every process in the quality system is audited over the program's cycle, with more frequent audits where risk is higher.

  • Effectiveness, Not Just Conformance

    Whether processes achieve their intended results, not only whether procedures exist.

  • Follow-Up on Findings

    Corrections and corrective actions taken promptly, and verification that they worked.

  • FDA-Specific Requirements

    MDR, corrections and removals, UDI, and the 820.35 and 820.45 provisions, alongside ISO 13485 requirements.

  • Auditor Independence and Competence

    Auditors who don't audit their own work and are trained for the processes they cover.

  • Input to Management Review

    Audit results reported to leadership and used in decisions.

How to Prepare

  1. 01

    Plan by Risk

    Set audit frequency by process importance and history, and document why.

  2. 02

    Audit Against the CP 7382.850 Areas

    Organize at least one audit cycle around the six QMS areas and four other FDA requirements that FDA inspections now use.

  3. 03

    Write Factual Reports

    Record objective evidence and clear findings, on the assumption that an investigator will read them.

  4. 04

    Track Findings to Verified Closure

    Use CAPA where warranted, and verify effectiveness before closing.

  5. 05

    Train and Rotate Auditors

    Build auditor competence and keep auditors out of their own areas.

Common Pitfalls

  • Audits that check whether procedures exist rather than whether they work.
  • Findings softened or dropped because the report might be read by FDA.
  • A schedule that slips for months without a documented reason.
  • Auditors auditing their own processes in small teams.
  • Findings left open across several audit cycles.
  • Checklists built for ISO 13485 alone that skip FDA-specific requirements.

How QMSAdvisor Helps

  • Design of an internal audit program organized by risk and by the CP 7382.850 areas, alongside ISO 13485:2016 requirements.
  • Independent internal audits of areas your own auditors can't cover without auditing their own work.
  • An AI-assisted first pass over the documents in scope, so audit time goes into interviews and records rather than hunting for files.
  • Findings tracked to closure with advisor evidence review and an immutable activity history.

Standards and Regulations Involved

Questions About the Internal Audit

Can FDA read our internal audit reports?

Yes. The QMSR removed the former 820.180(c) exception, so internal audit records, along with management review and supplier audit records, are open to FDA inspection.

Should we write vaguer reports now that FDA can see them?

No. Vague reports undermine the purpose of the audit and are a warning sign in their own right. Write factual findings and show that you acted on them; a program that finds and fixes problems is the best evidence you can offer.

How often should we audit each process?

ISO 13485:2016 doesn't set a fixed frequency. Base it on process importance, risk and previous results, and record the rationale in your audit program.

Can we outsource internal audits?

Yes. An external auditor can conduct internal audits for you, which helps with independence in small teams. You still own the program, the findings and the follow-up.

What standard guides internal auditing?

ISO 19011 provides guidance on auditing management systems, including audit program management and auditor competence. It's widely used as the reference for internal audit programs.

Request an Assessment

Prepare for Your Internal Audit With an Advisor

Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.