QMSAdvisor

Quality System Remediation

Internal Audit Program

Internal audits are how your QMS finds its own problems before an auditor or investigator does. We help you build a risk-based program, run audits with your team or ours, and write reports that hold up now that FDA can read them under the QMSR.

What You Receive

  1. 01Internal Audit Procedure
  2. 02Risk-Based Audit Schedule
  3. 03Auditor Qualification Records
  4. 04Audit Reports and Follow-Up

Every finding is reviewed and approved by a qualified QMS advisor before it reaches you.

What It Is

ISO 13485:2016 requires planned internal audits that check whether the QMS conforms to your own arrangements, to the standard and to applicable regulatory requirements, and whether it's effectively implemented and maintained. The program has to account for the status and importance of the processes and areas audited and the results of earlier audits. Criteria, scope, frequency and methods have to be defined, and auditors can't audit their own work.

The QMSR raised the stakes. Under the QMSR, which took effect on February 2, 2026, internal audit records are open to FDA inspection; the former exception that kept them out of routine review is gone. A report that lists no findings year after year, or reads like a ticked checklist, now tells an investigator how seriously you look at your own system, and its findings can be followed straight into your CAPA records.

ISO 19011 gives widely used guidance on managing an audit program and conducting audits: planning, auditor competence, gathering objective evidence and reporting. A good program uses it to decide what to audit, how often and by whom, based on risk, process performance, complaints, changes and prior findings, instead of auditing every requirement on the same calendar every year.

When You Need It

  • Your audit schedule repeats the same calendar every year regardless of complaints, changes or prior findings
  • Internal auditors audit areas they work in, or there are no records of their training and competence
  • Past audit reports were written on the assumption FDA would never read them, and now it can
  • You need a full internal audit on record before an ISO 13485, MDSAP or notified body audit
  • Your team is too small to audit itself independently and you need outsourced audits
  • Audit findings go into a report and stop there, without reaching CAPA or management review

What We Do

  1. 01

    Review the Current Program

    We read your audit procedure, schedule, past reports and auditor records. The AI does a first pass that maps past audits against processes and findings, and an advisor reviews the result.

  2. 02

    Build a Risk-Based Schedule

    We set audit frequency and depth by process risk, using complaints, nonconformances, CAPA trends, changes and prior results, and organize coverage around the CP 7382.850 QMS areas so it lines up with how FDA inspects.

  3. 03

    Set Independence and Competence Rules

    We define who can audit what, the training and qualification records each auditor needs, and how to cover areas where no one on your team is independent.

  4. 04

    Conduct the Audits

    Our advisors can run audits for you, or alongside your auditors to build their skill. Audits follow ISO 19011 practice: a plan, sampled records, interviews and objective evidence.

  5. 05

    Write Reports an Investigator Can Read

    Findings state the requirement, the evidence and the gap, factually and without opinion. Each finding links to a correction or a CAPA so the follow-up is visible.

  6. 06

    Close the Loop

    We track follow-up through to verification of effectiveness and feed audit results into management review.

Deliverables

  • Internal Audit Procedure

    Planning, independence, competence, reporting and follow-up, aligned to ISO 13485:2016 and ISO 19011 guidance.

  • Risk-Based Audit Schedule

    A schedule by process and CP 7382.850 area, with the risk reasoning behind each frequency recorded.

  • Auditor Qualification Records

    Criteria and records for each internal auditor, including independence assignments.

  • Audit Reports and Follow-Up

    Completed reports for the audits we conduct, with findings linked to corrections or CAPA.

How the Platform Helps

  • Audit Findings in the Action Plan

    Findings carry severity, gap type, owner, due date and a what-to-submit checklist, so follow-up doesn't depend on someone rereading the report.

  • Evidence Reviewed Before Closure

    Owners submit evidence, and an advisor accepts it or requests a revision with a note before a finding closes.

  • CAPA Linked to Findings

    Where a finding needs more than a correction, the CAPA record holds root cause, corrective action and effectiveness verification.

  • A History You Can Show

    An immutable activity history shows when each finding was raised, who acted on it and when it closed.

See the full platform

Audits and Inspections It Prepares You For

Standards and Regulations in Scope

Questions About This Service

Can FDA see our internal audit reports now?

Yes. Under the QMSR, internal audit records are open to FDA inspection because the former exception was removed. Write reports assuming an investigator will read them, and make sure every finding has a visible path to correction or CAPA.

Can a small company audit itself independently?

Auditors can't audit their own work, which is hard on a small team. Common answers are cross-auditing between functions or bringing in an outside auditor for areas where no one internal is independent. Our advisors can conduct those audits for you.

How often should each process be audited?

The standard doesn't set a fixed interval. Frequency should reflect the importance and risk of the process, its performance, recent changes and the results of earlier audits. A higher-risk process with recent complaints deserves more attention than a stable, low-risk one.

Do we have to follow ISO 19011?

ISO 19011 is guidance for auditing management systems, not a requirement. It covers program management, auditor competence and how audits are conducted, and following it gives your program a recognizable, defensible method.

Should we soften findings now that FDA can read them?

No. An investigator who finds an issue your audit missed or minimized will question the whole program. Write findings factually and specifically, and show that you acted on them.

Request an Assessment

Discuss Internal Audit Program With an Advisor

Tell us about your devices, your documents and your timeline, and an advisor will scope the work with you. Please don't send confidential documents yet: secure upload is set up after onboarding.