Certification and Regulatory Audits
ISO 13485 Recertification Audit
Every three years your ISO 13485 certificate comes up for renewal. The recertification audit happens before expiry and looks at the whole quality system again, along with how it has performed across the cycle.
At a Glance
- Conducted by
- Your certification body
- Timing
- Before the current certificate expires, at the end of the three-year cycle
- Scope
- The full quality system and its performance over the cycle
- Standard
- ISO 13485:2016
- Decision
- Recertification decision by the certification body
What It Is
Recertification is closer in scope to the initial Stage 2 audit than to a surveillance visit. The auditor reviews the full system rather than a sample and confirms it still fits your current scope, and the certification body then decides whether to renew.
What's different from the first time is history. The auditor can look at three years of internal audits, management reviews, complaints, CAPAs and surveillance findings and ask whether the system has improved, held steady or drifted.
Timing matters. The audit and any nonconformity closure need to be finished before the certificate expires, so plan the date with your certification body well ahead of the deadline.
Who Conducts It
Your certification body conducts the audit and makes the recertification decision. If you're changing certification bodies at renewal, transfer rules apply, and the new body will want to see your prior reports and any open nonconformities.
What Triggers It
- The approaching expiry of your current certificate
- Changes to scope, sites or products over the cycle that the renewed certificate needs to reflect
- A move to a different certification body at renewal
What They Look At
Performance Over the Cycle
Trends in complaints, nonconformances, CAPA and audit results across three years, and what management did about them.
Continued Fit of the Scope
Whether the certificate scope still matches your products, processes and sites.
Full System Review
All processes in scope, including those that surveillance sampling touched lightly.
Management Review Outputs
Evidence that leadership used the system's data to make decisions and improve it.
Closure History
Whether nonconformities from the cycle's surveillance audits stayed closed.
Response to Regulatory Change
How the system adapted to changed requirements during the cycle, such as the QMSR for firms selling in the US.
How to Prepare
- 01
Schedule Early
Agree the audit date with your certification body with enough margin to close any findings before expiry.
- 02
Review the Whole Cycle
Pull every surveillance report and internal audit from the cycle and confirm each finding is closed and stayed closed.
- 03
Run a Full-Scope Internal Audit
Audit every process in scope before the recertification audit, not just this year's sample.
- 04
Update the Scope Statement
Make sure the requested scope reflects current products, processes and sites.
- 05
Present Your Trends
Prepare a clear view of quality data across the cycle and the decisions it drove.
Common Pitfalls
- Leaving the audit until close to expiry, with no time to close findings.
- Processes that slipped through surveillance sampling and haven't been examined in three years.
- A scope statement that no longer matches what the company makes.
- Recurring findings across the cycle that show corrective action isn't working.
- Treating recertification like another surveillance visit and preparing only a sample.
How QMSAdvisor Helps
- A full-scope AI-assisted gap analysis against ISO 13485:2016, reviewed by an advisor, to find what three years of sampling missed.
- Findings from across the cycle consolidated into one action plan, so recurring issues stand out.
- Evidence review that confirms each closure with records, not statements.
- Internal audit support for a full-scope audit ahead of recertification.
ISO 13485 Certification Readiness
Prepare your QMS, records and people for a certification body's Stage 1 and Stage 2 audits.
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
Full Audit Readiness Assessment
Documents, records, evidence and interviews, checked against the specific audit you're facing next.
QMSR Transition
Bringing a QSR-era or ISO 13485 quality system in line with FDA's QMSR, which is now in effect.
Standards and Regulations Involved
Questions About the ISO 13485 Recertification Audit
How is recertification different from a surveillance audit?
Surveillance samples part of the system. Recertification reviews the whole system and its performance over the cycle, more like the original Stage 2 audit.
What if the certificate expires before recertification is complete?
A lapse can interrupt certification and complicate restoring it, and customers who rely on your certificate may notice. Plan the audit early, and if timing gets tight, talk to your certification body about the options before the expiry date.
Can we change certification bodies at recertification?
Yes, though transfers follow rules, and the new body will review your certification history, prior reports and open nonconformities. Start that conversation well before expiry.
Will the auditor look at the QMSR?
The certification audit is against ISO 13485:2016, not FDA regulations. If you sell in the US, though, recertification is a good moment to confirm the system also covers the FDA-specific QMSR additions, since FDA inspects for them separately.
Related Audits and Inspections
ISO 13485 Surveillance Audit
The periodic audits, at least annually, that support continued ISO 13485 certification between renewals.
ISO 13485 Certification Audit (Stage 1 and Stage 2)
The Stage 1 and Stage 2 audits a certification body runs before granting ISO 13485 certification.
MDSAP Audit
One audit by a recognized auditing organization that covers several participating regulators, including FDA.
Primary Sources
Request an Assessment
Prepare for Your ISO 13485 Recertification Audit With an Advisor
Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.


