QMSAdvisor

Certification and Regulatory Audits

ISO 13485 Surveillance Audit

Once you hold ISO 13485 certification, your certification body returns at least once a year to confirm the system is still working. Surveillance audits sample rather than cover everything, but they look closely at what changed and whether last year's findings were really closed.

At a Glance

Conducted by
Your certification body
Frequency
At least annually during the three-year certificate cycle
Scope
A sample of processes, plus changes and prior nonconformities
Standard
ISO 13485:2016
Possible outcome
Continued certification, or nonconformities to close; unresolved issues can put the certificate at risk

What It Is

A certificate isn't a one-time event. Between initial certification and recertification, the certification body runs surveillance audits at least annually to confirm the quality system continues to meet ISO 13485:2016.

Surveillance audits are shorter than the initial audit and sample a subset of processes. Over the cycle the certification body plans coverage so the whole system gets looked at, while certain items (internal audit, management review, complaints, CAPA, changes and follow-up on prior nonconformities) tend to come up every time.

The audit is also where significant changes get discussed: new products, sites, key suppliers or scope changes, some of which may need the certification body's evaluation.

Who Conducts It

Your certification body conducts it. The auditor will have the previous report and your nonconformity responses, and will usually start from there.

What Triggers It

  • The surveillance schedule in your certification body's audit program
  • Open nonconformities from a previous audit that need verification
  • Significant changes to products, processes, sites or the organization
  • Scope extensions you've requested, which may be assessed during a surveillance visit

What They Look At

  • Closure of Prior Nonconformities

    Whether corrective actions for last year's findings were implemented and are effective, not just documented.

  • Internal Audit and Management Review

    Whether both happened as planned and produced decisions and actions.

  • Complaints, Feedback and CAPA

    How complaints were handled and trended over the year, and whether CAPA addressed what the data showed.

  • Changes Since the Last Audit

    Products, processes, suppliers, sites and people that changed, and whether each change was controlled.

  • Scheduled Processes

    The processes the audit program has planned for this visit, examined in depth.

  • Use of the Certificate

    Whether certificate and scope references in marketing and documents are accurate.

How to Prepare

  1. 01

    Reread Last Year's Report

    List every nonconformity and observation, and gather evidence of what changed and whether it worked.

  2. 02

    Summarize the Year's Changes

    Prepare a short, accurate list of changes since the last audit, with the change records behind each one.

  3. 03

    Confirm Internal Audit Coverage

    Check that the internal audit schedule was followed and that findings were closed.

  4. 04

    Hold a Real Management Review

    Make sure the review covered its required inputs and recorded decisions, not just a slide deck.

  5. 05

    Look at the Trends

    Pull complaint, nonconformance and CAPA trends for the year and be ready to explain them.

Common Pitfalls

  • Corrective actions closed on paper with no evidence they prevented recurrence.
  • An internal audit schedule that slipped during busy periods, leaving gaps in coverage.
  • Not telling the certification body about significant changes, such as a new site or product type.
  • The same observation repeating year after year until it becomes a nonconformity.
  • Preparing only for the processes on the plan and neglecting the items checked at every visit.

How QMSAdvisor Helps

  • Every nonconformity from the last audit becomes a tracked finding with an owner, due date and evidence checklist, and advisors review what you submit.
  • An AI-assisted first pass over the year's records to flag stale CAPAs, overdue internal audits and missing management review inputs.
  • CAPA records that keep correction, root cause, corrective action and effectiveness verification together, so a closure stands on its evidence.
  • Ongoing advisory between audits, so readiness doesn't depend on a scramble each year.

Standards and Regulations Involved

Questions About the ISO 13485 Surveillance Audit

How often are surveillance audits?

At least annually during the three-year certificate cycle. Your certification body sets the exact schedule in its audit program.

What happens if the auditor raises a major nonconformity?

You'll need to address it within the time your certification body sets, with correction, root cause and corrective action, and the certification body may need to verify it. Unresolved major nonconformities can put the certificate at risk.

Do surveillance audits cover the whole system?

Not each time. They sample, and the certification body plans coverage across the cycle. Some items, like follow-up on prior nonconformities, internal audit and management review, are typically reviewed at every visit.

Should we tell the certification body about changes?

Yes. Significant changes such as new products, sites, key processes or ownership typically need to be reported, and some may need evaluation before your certificate covers them. Your certification agreement defines what counts and when.

Request an Assessment

Prepare for Your ISO 13485 Surveillance Audit With an Advisor

Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.