Who We Serve: Business Model
Established Manufacturers Expanding to New Markets
A quality system built for FDA covers much of what other markets expect, but not all of it. The gaps tend to sit in regulatory roles, technical documentation, post-market surveillance and country-specific requirements a US-only system never needed. We help established manufacturers find them before an auditing organization or notified body does.
Standards and Regulations to Know
- ISO 13485Quality Management Systems for Medical Devices
- MDSAPMedical Device Single Audit Program
- EU MDR (Regulation (EU) 2017/745)European Union Medical Device Regulation
- EU IVDR (Regulation (EU) 2017/746)European Union In Vitro Diagnostic Regulation
- ISO 14971Risk Management for Medical Devices
- ISO 20417Information Supplied by the Manufacturer
- ISO 15223-1Symbols for Medical Device Labeling
- ISO 14155Clinical Investigation of Medical Devices in Human Subjects
Typical Regulatory Exposure
ISO 13485 certification is often the first step. A certification body runs a Stage 1 audit of documentation and readiness and a Stage 2 audit of implementation, and certificates run on a three-year cycle with surveillance audits at least annually and a recertification audit before expiry. Because the QMSR incorporates ISO 13485:2016, a well-run US system is a strong starting point, but certification bodies audit against the standard itself and expect it to be implemented as written.
MDSAP lets one audit by a recognized auditing organization cover the requirements of the participating regulators: Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA. FDA accepts MDSAP audit reports in place of routine surveillance inspections, though not for-cause or pre-approval inspections. The cycle runs from an initial certification audit through annual surveillance audits to recertification, and each audit covers jurisdiction-specific requirements as well as ISO 13485.
The EU MDR and IVDR require notified body involvement for most devices beyond the lowest risk class, with conformity assessment audits, surveillance audits and unannounced audits at least once every five years. They also bring requirements a US system may never have had: a person responsible for regulatory compliance, technical documentation in a defined structure, a post-market surveillance system with periodic reporting, clinical or performance evaluation kept current, and labeling under EU rules.
Where Audits Find Gaps
- 01
No Person Responsible for Regulatory Compliance
The role the MDR and IVDR require has not been assigned, or was assigned to someone without documented qualifications or defined responsibilities.
- 02
Technical Documentation Built From a 510(k)
The EU technical documentation was assembled by reformatting the 510(k), leaving gaps against the general safety and performance requirements, clinical evaluation and post-market surveillance.
- 03
Jurisdiction-Specific Requirements Missing
Procedures cover FDA reporting and recalls but not the adverse event reporting, field action and registration requirements of the other MDSAP jurisdictions.
- 04
Post-Market Surveillance Limited to Complaints
The surveillance process is complaint handling under another name, with no plan for proactive data collection, trend reporting or periodic summaries.
- 05
Labeling Not Adapted for New Markets
Labels and instructions lack the symbols, languages or manufacturer and representative details the new markets require.
- 06
Internal Audits Scoped to FDA Only
The internal audit program covers QMSR areas but not the added requirements of the new markets, so the first external audit is the first time anyone checks them.
Relevant Standards and Regulations
- ISO 13485Quality Management Systems for Medical Devices
- MDSAPMedical Device Single Audit Program
- EU MDR (Regulation (EU) 2017/745)European Union Medical Device Regulation
- EU IVDR (Regulation (EU) 2017/746)European Union In Vitro Diagnostic Regulation
- ISO 14971Risk Management for Medical Devices
- ISO 20417Information Supplied by the Manufacturer
- ISO 15223-1Symbols for Medical Device Labeling
- ISO 14155Clinical Investigation of Medical Devices in Human Subjects
Relevant Services
MDSAP Readiness
Prepare for one audit covering ISO 13485 and the country-specific requirements of participating regulators.
EU MDR and IVDR Readiness
Prepare your QMS and technical documentation for notified body audits under the EU MDR or IVDR.
ISO 13485 Certification Readiness
Prepare your QMS, records and people for a certification body's Stage 1 and Stage 2 audits.
AI-Assisted QMS Gap Assessment
An AI-assisted first pass over the QMS documents you already have, with every result reviewed by an advisor.
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
Audits and Inspections You May Face
MDSAP Audit
One audit by a recognized auditing organization that covers several participating regulators, including FDA.
EU Notified Body Audit (Including Unannounced Audits)
Conformity assessment, surveillance and unannounced audits by an EU notified body under the MDR or IVDR.
ISO 13485 Certification Audit (Stage 1 and Stage 2)
The Stage 1 and Stage 2 audits a certification body runs before granting ISO 13485 certification.
Questions
Does MDSAP replace FDA inspections?
Partly. FDA accepts MDSAP audit reports in place of routine surveillance inspections, but not for-cause or pre-approval inspections. You can still receive those, so FDA readiness stays part of the plan.
Should we prepare for ISO 13485 certification and MDSAP together?
Often, yes. An MDSAP audit covers ISO 13485 along with each participating regulator's requirements, so preparing for both at once avoids duplicate work. Ask your auditing organization how it handles certification alongside the MDSAP audit.
What does a notified body look at that FDA might not?
Expect the audit to test your quality system against the regulation, not only ISO 13485, and to sample technical documentation, clinical or performance evaluation and post-market surveillance records. Notified bodies can also arrive unannounced, so readiness has to hold between scheduled audits.
Established Manufacturers Expanding to New Markets
Get an Advisor's View of Your Quality System
Tell us about your devices and the audit or inspection ahead, and an advisor will scope an assessment for your kind of product. Please don't send confidential documents yet: secure upload is set up after onboarding.


