International Programs
MDSAP: Medical Device Single Audit Program
The Medical Device Single Audit Program lets a manufacturer undergo one QMS audit that covers the requirements of several regulators at once. The audit is conducted by an auditing organization recognized under the program, and the participating regulators use the results in their own oversight.
At a Glance
- Regulation
- MDSAP
- Subject
- Medical Device Single Audit Program
- Group
- International Programs
- Industries
- 3 industry guides reference it
A plain-language summary, not legal advice. Always read the current official text.
What It Covers
MDSAP's participating regulators are Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA. An MDSAP audit assesses the QMS against ISO 13485 together with the country-specific requirements of these regulators, such as device reporting, registration and labeling obligations. The audit is organized into processes that follow a defined sequence, and nonconformities are graded so regulators can see their significance.
Audits are performed by recognized auditing organizations, not by the regulators themselves. An MDSAP cycle has an initial certification audit, annual surveillance audits and a recertification audit. Participating regulators may still conduct their own inspections.
For the US market, FDA accepts MDSAP audit reports in place of its routine surveillance inspections. That substitution does not extend to for-cause inspections or PMA pre-approval inspections, which FDA continues to perform itself. For manufacturers selling in several participating markets, MDSAP can replace multiple separate audits with one program, though it requires readiness for every participating jurisdiction's requirements, not just one.
Who It Applies To
- Device manufacturers selling in two or more of the participating markets
- Manufacturers seeking access to the Canadian market, where Health Canada relies on MDSAP for QMS certification
- US manufacturers that want an MDSAP audit report to stand in place of routine FDA surveillance inspections
- Firms with ISO 13485 certification that are adding country-specific requirements
What Auditors Check
Management and Process Ownership
Whether top management engages with the QMS and whether processes are owned, measured and reviewed.
Country-Specific Requirements
Whether the QMS covers the reporting, registration, labeling and other requirements of each participating jurisdiction where the firm sells.
Device Marketing Authorization and Facility Registration
Whether marketing authorizations and registrations are current for the markets in scope.
Measurement, Analysis and Improvement
CAPA, complaint handling, internal audits and data analysis, with evidence that problems lead to effective action.
Adverse Event and Advisory Notice Reporting
Whether events and field actions are reported to each relevant regulator according to its requirements.
Design, Production and Purchasing Controls
Design and development, production and service controls, and supplier controls, sampled in the program's process sequence.
Related Services
MDSAP Readiness
Prepare for one audit covering ISO 13485 and the country-specific requirements of participating regulators.
ISO 13485 Certification Readiness
Prepare your QMS, records and people for a certification body's Stage 1 and Stage 2 audits.
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
Industry Guides That Reference MDSAP
Questions
Does an MDSAP audit replace FDA inspections?
FDA accepts MDSAP audit reports in place of routine surveillance inspections. It does not accept them in place of for-cause inspections or PMA pre-approval inspections, which FDA still conducts. So MDSAP can reduce routine FDA visits, but it does not remove the need to be inspection-ready.
Which regulators participate in MDSAP?
The participating regulators are Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA. An MDSAP audit covers the QMS requirements of all of them, scoped to the markets where your devices are sold.
How does the MDSAP audit cycle work?
The cycle starts with an initial certification audit, continues with annual surveillance audits, and ends with a recertification audit before the next cycle. Audits are performed by auditing organizations recognized under the program.
How is MDSAP different from an ISO 13485 audit?
MDSAP uses ISO 13485 as its base but also audits the country-specific requirements of each participating regulator, and it follows a structured audit sequence with graded nonconformities. Firms that are ready for ISO 13485 often have gaps in reporting and registration obligations for the other markets.
MDSAP
Check Your Quality System Against MDSAP
An AI-assisted first pass maps your existing documents against the requirements in scope, and an advisor reviews every result. Please don't send confidential documents yet: secure upload is set up after onboarding.


