Certification and Regulatory Audits
ISO 13485 Surveillance Audit
Once you hold ISO 13485 certification, your certification body returns at least once a year to confirm the system is still working. Surveillance audits sample rather than cover everything, but they look closely at what changed and whether last year's findings were really closed.
At a Glance
- Conducted by
- Your certification body
- Frequency
- At least annually during the three-year certificate cycle
- Scope
- A sample of processes, plus changes and prior nonconformities
- Standard
- ISO 13485:2016
- Possible outcome
- Continued certification, or nonconformities to close; unresolved issues can put the certificate at risk
What It Is
A certificate isn't a one-time event. Between initial certification and recertification, the certification body runs surveillance audits at least annually to confirm the quality system continues to meet ISO 13485:2016.
Surveillance audits are shorter than the initial audit and sample a subset of processes. Over the cycle the certification body plans coverage so the whole system gets looked at, while certain items (internal audit, management review, complaints, CAPA, changes and follow-up on prior nonconformities) tend to come up every time.
The audit is also where significant changes get discussed: new products, sites, key suppliers or scope changes, some of which may need the certification body's evaluation.
Who Conducts It
Your certification body conducts it. The auditor will have the previous report and your nonconformity responses, and will usually start from there.
What Triggers It
- The surveillance schedule in your certification body's audit program
- Open nonconformities from a previous audit that need verification
- Significant changes to products, processes, sites or the organization
- Scope extensions you've requested, which may be assessed during a surveillance visit
What They Look At
Closure of Prior Nonconformities
Whether corrective actions for last year's findings were implemented and are effective, not just documented.
Internal Audit and Management Review
Whether both happened as planned and produced decisions and actions.
Complaints, Feedback and CAPA
How complaints were handled and trended over the year, and whether CAPA addressed what the data showed.
Changes Since the Last Audit
Products, processes, suppliers, sites and people that changed, and whether each change was controlled.
Scheduled Processes
The processes the audit program has planned for this visit, examined in depth.
Use of the Certificate
Whether certificate and scope references in marketing and documents are accurate.
How to Prepare
- 01
Reread Last Year's Report
List every nonconformity and observation, and gather evidence of what changed and whether it worked.
- 02
Summarize the Year's Changes
Prepare a short, accurate list of changes since the last audit, with the change records behind each one.
- 03
Confirm Internal Audit Coverage
Check that the internal audit schedule was followed and that findings were closed.
- 04
Hold a Real Management Review
Make sure the review covered its required inputs and recorded decisions, not just a slide deck.
- 05
Look at the Trends
Pull complaint, nonconformance and CAPA trends for the year and be ready to explain them.
Common Pitfalls
- Corrective actions closed on paper with no evidence they prevented recurrence.
- An internal audit schedule that slipped during busy periods, leaving gaps in coverage.
- Not telling the certification body about significant changes, such as a new site or product type.
- The same observation repeating year after year until it becomes a nonconformity.
- Preparing only for the processes on the plan and neglecting the items checked at every visit.
How QMSAdvisor Helps
- Every nonconformity from the last audit becomes a tracked finding with an owner, due date and evidence checklist, and advisors review what you submit.
- An AI-assisted first pass over the year's records to flag stale CAPAs, overdue internal audits and missing management review inputs.
- CAPA records that keep correction, root cause, corrective action and effectiveness verification together, so a closure stands on its evidence.
- Ongoing advisory between audits, so readiness doesn't depend on a scramble each year.
ISO 13485 Certification Readiness
Prepare your QMS, records and people for a certification body's Stage 1 and Stage 2 audits.
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
CAPA System Remediation
Fixing a CAPA system auditors keep citing: the procedure, the records, root cause, effectiveness and backlog.
Ongoing Advisory and Continuous Readiness
Periodic re-assessments, a live action plan and yearly mock inspections that keep readiness from decaying.
Standards and Regulations Involved
Questions About the ISO 13485 Surveillance Audit
How often are surveillance audits?
At least annually during the three-year certificate cycle. Your certification body sets the exact schedule in its audit program.
What happens if the auditor raises a major nonconformity?
You'll need to address it within the time your certification body sets, with correction, root cause and corrective action, and the certification body may need to verify it. Unresolved major nonconformities can put the certificate at risk.
Do surveillance audits cover the whole system?
Not each time. They sample, and the certification body plans coverage across the cycle. Some items, like follow-up on prior nonconformities, internal audit and management review, are typically reviewed at every visit.
Should we tell the certification body about changes?
Yes. Significant changes such as new products, sites, key processes or ownership typically need to be reported, and some may need evaluation before your certificate covers them. Your certification agreement defines what counts and when.
Related Audits and Inspections
ISO 13485 Certification Audit (Stage 1 and Stage 2)
The Stage 1 and Stage 2 audits a certification body runs before granting ISO 13485 certification.
ISO 13485 Recertification Audit
The pre-expiry audit that reviews the whole ISO 13485 system and how it performed over the three-year cycle.
Internal Audit
Audits your own team runs of your quality system, now open to FDA inspection under the QMSR.
Primary Sources
Request an Assessment
Prepare for Your ISO 13485 Surveillance Audit With an Advisor
Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.


