ultimate-guide
How to Prepare for ISO 13485 Audit: 7 Steps
Table of Contents
- Understanding ISO 13485 Audit Stages and Scope
- Step 1: Conduct a Gap Analysis Against ISO 13485 Requirements
- Step 2: Build Your ISO 13485 Internal Audit Checklist
- Step 3: Establish Your ISO 13485 Audit Preparation Timeline
- Step 4: Document Your Quality Management System
- Step 5: Train Staff and Build Team Competency
- Step 6: Run Mock Audits and Address Common ISO 13485 Non-Conformities
- ISO 13485 Audit Best Practices for Certification Success
- Frequently Asked Questions
Last Updated: September 30, 2026
Understanding ISO 13485 Audit Stages and Scope
To prepare for ISO 13485 audit success, you must formally assess your Quality Management System against the ISO 13485:2016 standard to verify compliance with medical device design, production, and distribution requirements. Most organizations face two stages: Stage 1 (document review) and Stage 2 (on-site assessment).
Stage 1 reviews your quality manual, procedures, and audit scope documentation to verify your system is documented. This stage typically reveals gaps between written procedures and ISO 13485:2016 requirements.
Stage 2 is the intensive on-site audit where auditors observe operations, interview staff, and verify that your team follows documented procedures. Auditors trace product traceability, review design controls, examine risk management documentation, and confirm that your internal audit program works.
Audit scope depends on product classification and manufacturing complexity. A Class II device manufacturer faces a narrower scope than a Class III manufacturer with complex design controls and supplier management.
Step 1: Conduct a Gap Analysis Against ISO 13485 Requirements
A gap analysis compares your current Quality Management System against ISO 13485:2016 section by section, preventing surprises during the formal audit.
Map your documentation against the standard's 8 main clauses: context, leadership, planning, support, operation, performance evaluation, improvement, and competence. For each, list what you have, what's missing, and what needs updating.
Use a spreadsheet with columns for: ISO 13485 requirement, current status, required action, owner, and target completion date. This keeps accountability clear and progress trackable.
Step 2: Build Your ISO 13485 Internal Audit Checklist
Your internal audit program demonstrates compliance. The certification body examines your results closely to see you're catching non-conformities before they do. A thorough checklist ensures systematic auditing.
Create a checklist mirroring ISO 13485:2016 structure with sections for management responsibility, resource management, product realization, and measurement/analysis/improvement. Include specific audit questions tied to the standard, such as: "Are design inputs documented and approved before work begins? Is design output verified before release?"
Prompt auditors to request evidence; don't settle for verbal confirmations. Assign internal auditors who understand operations but aren't directly responsible for audited areas, ensuring objectivity.
| Audit Area | Key Questions | Evidence Required | Frequency |
|---|---|---|---|
| Design Control | Are inputs documented and approved? | Design input records, approval signatures | Per product |
| Risk Management | Is ISO 14971 applied? | Risk analysis documents, mitigation evidence | Per product |
| Supplier Management | Are suppliers qualified? | Supplier assessments, audit reports | Annual |
| Internal Audit | Are findings tracked and closed? | Audit reports, corrective action records | Quarterly |
Step 3: Establish Your ISO 13485 Audit Preparation Timeline
Start preparation 4-6 months before your scheduled audit to identify gaps, implement corrections, run internal audits, and close findings. Major gaps may require 6-9 months.
Break timeline into phases: Months 1-2 (gap analysis and ownership), Months 2-3 (build/update procedures), Months 3-4 (staff training and first internal audit), Months 4-5 (address findings and second audit), Month 6 (mock audit and readiness review).
Each phase builds on the previous one, ensuring your team practices processes multiple times before auditors arrive.
Step 4: Document Your Quality Management System
Quality Management System documentation, quality manual, procedures, work instructions, forms, and records, must be complete, current, and actually used by your team.
Start with a 10-20 page quality manual describing your organization, quality policy, and how you meet ISO 13485 requirements. Develop procedures for design control, supplier management, complaint handling, internal audit, and management review. Be specific: "Reviewed and approved by the Quality Manager within 5 business days" is clearer than "Reviewed by quality."
Work instructions guide day-to-day tasks. Documentation control is critical: every procedure and work instruction needs a version number, approval date, effective date, and approval signature to prevent use of outdated documents.
Step 5: Train Staff and Build Team Competency

Your team must understand the Quality Management System and their role. Auditors interview staff about procedures and quality expectations; weak training shows immediately.
Develop a training plan covering management (quality policy and strategy), engineers (design control and risk management), operators (specific procedures), and quality staff (entire system).
Document training with records showing content, attendees, and dates. Include competency assessments. Conduct annual refresher training and retrain staff when procedures change.
Step 6: Run Mock Audits and Address Common ISO 13485 Non-Conformities
Conduct a mock audit 4-6 weeks before certification using your internal audit checklist. Have auditors walk operations, interview staff, and request evidence. Document findings as if real, replicating the audit's intensity with challenging questions and on-the-spot evidence requests.
Brief your team on what to expect. Explain that auditors assess the system, not individual performance. A non-conformity reflects a process gap, not personal failure. Encourage honesty: if someone doesn't know an answer, they should say so.
Have a senior leader observe mock interviews and debrief staff afterward, clarifying misunderstandings and explaining how to handle similar questions in the real audit.
Identifying and Addressing Common Non-Conformities
Design Control gaps are the most frequent finding. Companies document inputs but skip verification or validation. Trace a product design from input through release, asking for input records, approvals, and verification results.
Risk Management gaps occur when organizations haven't integrated ISO 14971 properly or don't document mitigation verification. Ask for identified risks, mitigation methods, and verification evidence.
Supplier Management issues surface when companies haven't qualified suppliers or monitored performance. Request qualification records, audit reports, or performance data.
Document Control problems are common: outdated procedures in use, missing signatures, or unclear version control. Have auditors ask staff to show procedures they follow and verify they match current versions.
Complaint Handling gaps appear when companies don't investigate systematically or link complaints to corrective actions.
ISO 13485 Audit Best Practices for Certification Success
Designate an audit coordinator to manage auditors' schedule, arrange rooms, ensure document access, and answer logistical questions. Brief your team that auditors assess the system, not individual performance.
- Major non-conformities: Systemic failures that affect product safety, regulatory compliance, or the integrity of the Quality Management System. Major non-conformities must be corrected before certification is granted.
- Minor non-conformities: Isolated gaps or incomplete documentation that don't affect system integrity. Minor non-conformities must be corrected, but certification can be granted conditionally while you remediate them.
Post-Audit Corrective Action: The Critical Phase
For each non-conformity, your corrective action plan must include:
-
Root cause analysis: Why did the non-conformity occur? Identify the systemic cause, not just the symptom.
-
Corrective action: What specific steps will you take to fix the problem? Be concrete. Instead of "Improve design control," write: "Update design control procedure to include a mandatory design verification step before design release; assign responsibility to the Design Engineer; require Quality Manager sign-off; implement by [date]."
-
Preventive measures: How will you prevent this from happening again? This might include updated procedures, additional training, new oversight mechanisms, or system changes.
-
Timeline and owner: Who is responsible for implementing the corrective action, and by when? Assign a specific person, not a department.
-
Verification method: How will you confirm the corrective action is effective? Describe how you'll verify: "Review the next five design releases to confirm design verification records are complete and signed."
Submitting and Tracking Corrective Actions
Verification and Closure
Managing Observations
Timeline to Certification
The full timeline from closing meeting to certification typically looks like this:
- Closing meeting: Auditor presents findings
- Days 1-7: You receive formal audit report
- Days 8-30: You submit corrective action plan
- Days 31-45: Certification body reviews plan, may request clarification
- Days 46-90: You implement corrective actions and gather verification evidence
- Days 91-120: You submit verification evidence to certification body
- Days 121-135: Certification body reviews evidence and approves closure
- Day 136+: You receive ISO 13485 certificate
Common Corrective Action Mistakes to Avoid
- Treating symptoms, not root causes: If the non-conformity is "missing design verification," don't just add one missing record. Update the procedure, train the team, and implement oversight to prevent future gaps.
- Vague corrective actions: "Improve training" is too vague. "Conduct design control training for all engineers by [date], with competency assessment" is specific and verifiable.
- Unrealistic timelines: Be honest about what's achievable. Setting a 2-week deadline for a corrective action that requires procedure updates, training, and implementation sets you up for failure.
- Insufficient verification: Don't declare a corrective action closed based on one example. Verify across multiple instances to confirm the fix is systemic.
- Ignoring observations: Observations often become non-conformities in the next audit if ignored. Address them proactively.
Frequently Asked Questions
What is the difference between ISO 13485 Stage 1 and Stage 2 audit?
Stage 1 (Opening Meeting) reviews your Quality Management System documentation, processes, and readiness without detailed evidence examination. Stage 2 (Main Audit) evaluates actual implementation by examining records, observing processes, and interviewing staff. Both are essential to prepare for ISO 13485 audit. Stage 1 typically occurs 1-3 months before Stage 2, giving you time to address any gaps identified during the opening phase.
How long does it typically take to prepare for an ISO 13485 certification audit?
Most organizations require 6-12 months to prepare for ISO 13485 audit, depending on starting maturity. Startups building systems from scratch need 12+ months. Established companies with existing quality processes may need 4-6 months. Your ISO 13485 audit preparation timeline should account for gap analysis (4-8 weeks), documentation development (8-12 weeks), staff training (4-6 weeks), and mock audits (4-8 weeks). Begin planning immediately after engaging your Certification Body.
What are the most common ISO 13485 non-conformities found during audits?
Common ISO 13485 non-conformities include inadequate traceability in design history files, incomplete risk management documentation per ISO 14971, insufficient management review records, poor document control and change management, inadequate internal audit evidence, gaps in supplier evaluation and monitoring, incomplete corrective action follow-up, and weak staff competency documentation. Most occur because organizations misunderstand requirement depth rather than intent. Regular internal audits using a comprehensive ISO 13485 internal audit checklist prevent these findings.
What should you avoid saying to an auditor during an ISO 13485 assessment?
Never admit non-compliance you haven't documented as a corrective action, speculate about process details you're unsure of, or blame individuals for system failures. Avoid defensive language or making excuses. Do not contradict your documented procedures during interviews. Instead, answer truthfully, reference your documented QMS, and if you discover a gap during the audit, acknowledge it professionally and commit to addressing it. Auditors respect honesty and demonstrate ISO 13485 audit best practices through transparency and evidence-based responses.