Certification and Regulatory Audits
MDSAP Audit
The Medical Device Single Audit Program lets one audit cover the quality system requirements of several regulators. An MDSAP audit is conducted by a recognized auditing organization against ISO 13485:2016 plus the specific requirements of the participating jurisdictions that apply to you.
At a Glance
- Conducted by
- An auditing organization recognized under MDSAP
- Participating regulators
- Australia TGA, Brazil ANVISA, Health Canada, Japan MHLW/PMDA and US FDA
- Audit cycle
- Initial certification audit, annual surveillance audits and a recertification audit
- FDA use
- Reports accepted in place of routine surveillance inspections, not for-cause or pre-approval inspections
What It Is
MDSAP was built so a manufacturer can be audited once for several markets. A recognized auditing organization audits against ISO 13485:2016 and adds the requirements of the participating regulators (Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA) that apply to the markets you sell in.
For US manufacturers the FDA link is a major reason to join: FDA accepts MDSAP audit reports in place of routine surveillance inspections. That doesn't extend to for-cause or pre-approval inspections, which FDA still conducts. Other participating regulators use MDSAP reports according to their own rules.
The audit model works through the quality system process by process: management; device marketing authorization and facility registration; measurement, analysis and improvement; medical device adverse events and advisory notices reporting; design and development; production and service controls; and purchasing. Findings are graded, and reports are shared with the participating regulators.
Who Conducts It
Auditing organizations recognized by the MDSAP regulators conduct the audits. Regulators oversee those organizations, so you may occasionally see a regulator assessor observing the auditor at your site.
The cycle has an initial certification audit, annual surveillance audits and a recertification audit, all run by your chosen auditing organization.
What Triggers It
- Selling, or planning to sell, in two or more of the participating markets
- Wanting MDSAP reports to stand in for routine FDA surveillance inspections
- A participating regulator whose market access process relies on MDSAP
- Annual surveillance and recertification within an existing MDSAP cycle
What They Look At
Management
Quality system planning, management review, resources, and how leadership connects the other processes.
Device Marketing Authorization and Facility Registration
Whether marketing authorizations and registrations are current in each jurisdiction and changes were notified where required.
Measurement, Analysis and Improvement
Complaints, data analysis, internal audit, nonconforming product and CAPA.
Adverse Event and Advisory Notice Reporting
Whether reportable events and field actions were reported to each relevant regulator under its own rules.
Design and Development
Design controls and risk management, where design is in scope.
Production and Service Controls
Process validation, traceability, servicing and the production controls behind each product.
Purchasing
Supplier selection, controls and monitoring, including outsourced processes.
Jurisdiction-Specific Requirements
Requirements layered on ISO 13485, such as FDA's MDR, UDI and QMSR additions for product sold in the US.
How to Prepare
- 01
Map Each Jurisdiction's Requirements
List the participating markets you sell in and the specific requirements each adds, then trace each one to a procedure.
- 02
Check Regulatory Reporting by Market
Confirm that adverse event and field action reporting procedures cover every relevant regulator, with decision criteria for each.
- 03
Verify Registrations and Authorizations
Make sure marketing authorizations and registrations are current and that change notifications were made where required.
- 04
Audit by Process
Run your internal audit along the MDSAP process sequence so gaps show up the way the auditor will see them.
- 05
Prepare for Linked Questions
The model links processes, so an issue in purchasing can lead into production and CAPA. Prepare process owners to follow those links.
Common Pitfalls
- Treating MDSAP as an ISO 13485 audit with a few extras, and missing jurisdiction-specific requirements.
- Reporting procedures written only for FDA, with nothing for the other participating markets the company sells in.
- Registration or authorization changes made without the required notifications.
- Expecting MDSAP to prevent every FDA visit, when for-cause and pre-approval inspections still happen.
- Slow nonconformity closure, which carries more weight because reports go to regulators.
How QMSAdvisor Helps
- An AI-assisted gap analysis that maps your documents to ISO 13485:2016 and the jurisdiction requirements that apply to your markets, reviewed by an advisor.
- Findings organized by MDSAP process, so each owner sees where the audit will probe.
- Evidence tracking for nonconformity closure, with advisor acceptance and a full activity history.
- Mock audits that follow the process-based structure of the MDSAP audit model.
MDSAP Readiness
Prepare for one audit covering ISO 13485 and the country-specific requirements of participating regulators.
ISO 13485 Certification Readiness
Prepare your QMS, records and people for a certification body's Stage 1 and Stage 2 audits.
QMSR Transition
Bringing a QSR-era or ISO 13485 quality system in line with FDA's QMSR, which is now in effect.
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
Standards and Regulations Involved
Questions About the MDSAP Audit
Does MDSAP replace FDA inspections?
FDA accepts MDSAP audit reports in place of routine surveillance inspections. It does not replace for-cause or PMA pre-approval inspections, so you still need to be ready for those.
Which regulators participate?
The participating regulators are Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA. Your audit covers the requirements of those whose markets apply to you.
Is an MDSAP audit the same as ISO 13485 certification?
MDSAP audits are built on ISO 13485:2016 but add each participating regulator's requirements, and the reports go to those regulators. Ask your auditing organization how its MDSAP and ISO 13485 certificates relate.
What does the MDSAP cycle look like?
An initial certification audit, then annual surveillance audits, then a recertification audit. The cycle repeats for as long as you stay in the program.
Does MDSAP cover the EU?
No. EU market access under the MDR or IVDR runs through notified bodies and their own audits, which are separate from MDSAP.
Related Audits and Inspections
ISO 13485 Certification Audit (Stage 1 and Stage 2)
The Stage 1 and Stage 2 audits a certification body runs before granting ISO 13485 certification.
FDA Baseline Surveillance Inspection
FDA's comprehensive surveillance inspection of your quality system under Compliance Program 7382.850.
EU Notified Body Audit (Including Unannounced Audits)
Conformity assessment, surveillance and unannounced audits by an EU notified body under the MDR or IVDR.
FDA Foreign Facility Inspection
FDA inspection of a manufacturer outside the US that makes devices for the US market.
Request an Assessment
Prepare for Your MDSAP Audit With an Advisor
Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.


