QMSAdvisor

Certification and Regulatory Audits

MDSAP Audit

The Medical Device Single Audit Program lets one audit cover the quality system requirements of several regulators. An MDSAP audit is conducted by a recognized auditing organization against ISO 13485:2016 plus the specific requirements of the participating jurisdictions that apply to you.

At a Glance

Conducted by
An auditing organization recognized under MDSAP
Participating regulators
Australia TGA, Brazil ANVISA, Health Canada, Japan MHLW/PMDA and US FDA
Audit cycle
Initial certification audit, annual surveillance audits and a recertification audit
FDA use
Reports accepted in place of routine surveillance inspections, not for-cause or pre-approval inspections

What It Is

MDSAP was built so a manufacturer can be audited once for several markets. A recognized auditing organization audits against ISO 13485:2016 and adds the requirements of the participating regulators (Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA) that apply to the markets you sell in.

For US manufacturers the FDA link is a major reason to join: FDA accepts MDSAP audit reports in place of routine surveillance inspections. That doesn't extend to for-cause or pre-approval inspections, which FDA still conducts. Other participating regulators use MDSAP reports according to their own rules.

The audit model works through the quality system process by process: management; device marketing authorization and facility registration; measurement, analysis and improvement; medical device adverse events and advisory notices reporting; design and development; production and service controls; and purchasing. Findings are graded, and reports are shared with the participating regulators.

Who Conducts It

Auditing organizations recognized by the MDSAP regulators conduct the audits. Regulators oversee those organizations, so you may occasionally see a regulator assessor observing the auditor at your site.

The cycle has an initial certification audit, annual surveillance audits and a recertification audit, all run by your chosen auditing organization.

What Triggers It

  • Selling, or planning to sell, in two or more of the participating markets
  • Wanting MDSAP reports to stand in for routine FDA surveillance inspections
  • A participating regulator whose market access process relies on MDSAP
  • Annual surveillance and recertification within an existing MDSAP cycle

What They Look At

  • Management

    Quality system planning, management review, resources, and how leadership connects the other processes.

  • Device Marketing Authorization and Facility Registration

    Whether marketing authorizations and registrations are current in each jurisdiction and changes were notified where required.

  • Measurement, Analysis and Improvement

    Complaints, data analysis, internal audit, nonconforming product and CAPA.

  • Adverse Event and Advisory Notice Reporting

    Whether reportable events and field actions were reported to each relevant regulator under its own rules.

  • Design and Development

    Design controls and risk management, where design is in scope.

  • Production and Service Controls

    Process validation, traceability, servicing and the production controls behind each product.

  • Purchasing

    Supplier selection, controls and monitoring, including outsourced processes.

  • Jurisdiction-Specific Requirements

    Requirements layered on ISO 13485, such as FDA's MDR, UDI and QMSR additions for product sold in the US.

How to Prepare

  1. 01

    Map Each Jurisdiction's Requirements

    List the participating markets you sell in and the specific requirements each adds, then trace each one to a procedure.

  2. 02

    Check Regulatory Reporting by Market

    Confirm that adverse event and field action reporting procedures cover every relevant regulator, with decision criteria for each.

  3. 03

    Verify Registrations and Authorizations

    Make sure marketing authorizations and registrations are current and that change notifications were made where required.

  4. 04

    Audit by Process

    Run your internal audit along the MDSAP process sequence so gaps show up the way the auditor will see them.

  5. 05

    Prepare for Linked Questions

    The model links processes, so an issue in purchasing can lead into production and CAPA. Prepare process owners to follow those links.

Common Pitfalls

  • Treating MDSAP as an ISO 13485 audit with a few extras, and missing jurisdiction-specific requirements.
  • Reporting procedures written only for FDA, with nothing for the other participating markets the company sells in.
  • Registration or authorization changes made without the required notifications.
  • Expecting MDSAP to prevent every FDA visit, when for-cause and pre-approval inspections still happen.
  • Slow nonconformity closure, which carries more weight because reports go to regulators.

How QMSAdvisor Helps

  • An AI-assisted gap analysis that maps your documents to ISO 13485:2016 and the jurisdiction requirements that apply to your markets, reviewed by an advisor.
  • Findings organized by MDSAP process, so each owner sees where the audit will probe.
  • Evidence tracking for nonconformity closure, with advisor acceptance and a full activity history.
  • Mock audits that follow the process-based structure of the MDSAP audit model.

Standards and Regulations Involved

Questions About the MDSAP Audit

Does MDSAP replace FDA inspections?

FDA accepts MDSAP audit reports in place of routine surveillance inspections. It does not replace for-cause or PMA pre-approval inspections, so you still need to be ready for those.

Which regulators participate?

The participating regulators are Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA. Your audit covers the requirements of those whose markets apply to you.

Is an MDSAP audit the same as ISO 13485 certification?

MDSAP audits are built on ISO 13485:2016 but add each participating regulator's requirements, and the reports go to those regulators. Ask your auditing organization how its MDSAP and ISO 13485 certificates relate.

What does the MDSAP cycle look like?

An initial certification audit, then annual surveillance audits, then a recertification audit. The cycle repeats for as long as you stay in the program.

Does MDSAP cover the EU?

No. EU market access under the MDR or IVDR runs through notified bodies and their own audits, which are separate from MDSAP.

Request an Assessment

Prepare for Your MDSAP Audit With an Advisor

Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.