how-to
ISO 13485 Audit Remediation Plan: Step-by-Step
Table of Contents
- What Is an ISO 13485 Audit Remediation Plan
- Prioritize Findings by Risk and Impact
- Build Your ISO 13485 Non-Conformity Report Template
- Create an ISO 13485 Audit Remediation Timeline
- Execute the ISO 13485 Corrective and Preventive Action (CAPA) Process
- How to Write an Audit Response Letter
- Verify Closure and Prepare for Follow-Up Audit
- Frequently Asked Questions
Last Updated: October 5, 2026
What Is an ISO 13485 Audit Remediation Plan
An ISO 13485 audit remediation plan turns every quality management system audit finding into corrective and preventive actions with clear ownership, timelines, and verification steps.
At E & E Medicals and Consulting, we help medical device manufacturers turn audit findings into a roadmap for genuine compliance, mapping each finding to ISO 13485 clauses, assigning ownership and due dates, and defining how you'll prove the fix works before the follow-up audit.
Prioritize Findings by Risk and Impact
Not all findings carry equal weight. A documentation gap in a low-risk area differs from a process failure affecting product safety.

Start by categorizing findings into three tiers:
Major nonconformities directly violate ISO 13485 requirements or regulatory expectations, a missing Design History File, absent risk management documentation, or broken product traceability. They demand immediate action and often trigger follow-up audits within 30-90 days.
Minor nonconformities show gaps but don't block certification, incomplete audit records, outdated procedure versions, inconsistent document control. They typically need closure within 6-12 months.
Observations flag trends worth watching, such as a process lacking documentation polish or a team member not fully trained.
Build Your ISO 13485 Non-Conformity Report Template
A structured non-conformity report keeps remediation organized and auditable, becoming your single source of truth for each finding.
Your ISO 13485 non-conformity report template should capture:
| Element | Purpose | Example |
|---|---|---|
| Finding ID | Unique reference | NC-2026-001 |
| Audit Clause | ISO 13485 requirement cited | 4.2.3 Document Control |
| Description | What was found | Expired procedure in use |
| Root Cause | Why it happened | No version control system |
| Corrective Action | How you'll fix it | Implement document management software |
| Owner | Who is responsible | Quality Manager |
| Due Date | Target completion | 30 days from audit |
| Evidence | How you'll prove closure | Training records, updated procedures |
Build this template in a shared document or quality management system, not a disconnected spreadsheet. The description section matters most: write it so someone unfamiliar with your operation understands exactly what the auditor observed. Vague descriptions ("training issues") lead to vague fixes.
From Report to Remediation Plan: A Reusable Template
The non-conformity report captures the finding; the remediation plan drives it to verified closure. A practical remediation plan template adds the fields that turn a finding into a managed project.
Extend your template with these remediation-specific fields:
| Field | Purpose | Example |
|---|---|---|
| Priority Tier | Risk-based sequencing | Major / Minor / Observation |
| Containment Action | Immediate stop-gap to protect product or records | Quarantine affected batch; lock superseded procedure |
| Correction | Fix the specific instance | Replace expired procedure with current version |
| Root Cause Category | Pattern classification | Process / Training / Supplier / Documentation |
| Corrective Action Plan | Systemic fix | Deploy version-controlled document management system |
| Preventive Action | Stop recurrence elsewhere | Audit all controlled documents for version drift |
| Implementation Evidence | Proof the fix was deployed | Screenshots, training logs, updated SOPs |
| Effectiveness Check Method | How you'll prove it works | Sample 10 active procedures; verify version match |
| Effectiveness Acceptance Criteria | Measurable success threshold | 100% of sampled procedures match current version; zero recurrence in 90 days |
| Verification Owner | Independent reviewer | Quality Assurance Manager (not the action owner) |
| Closure Approval | Sign-off authority | Management Representative |
| Closure Date | Formal completion | Date effectiveness verified |
Every field must be populated before a finding is considered closed; empty effectiveness fields are a red flag that remediation is incomplete.
Worked Example: Strong vs. Weak Remediation Response
Weak response:
- Finding: Expired procedure found in active use.
- Correction: Replace the expired procedure with the current version.
- Root cause: "Employee oversight."
This fixes one instance but doesn't explain why the expired procedure was accessible, why version control failed, or how recurrence will be prevented. An auditor will likely reopen the finding.
Strong response:
- Finding: Expired procedure found in active use.
- Containment: Immediately remove all superseded procedures from the production floor and quarantine affected records.
- Correction: Replace the expired procedure with the current version at the point of use.
The strong response addresses the systemic cause, prevents recurrence elsewhere, and defines measurable success. That is what survives a follow-up audit.
Risk-Based Prioritization and Realistic Timelines
Priority should reflect patient/product risk, regulatory impact, recurrence, and finding severity. Use this to set due dates and escalation paths.
| Priority | Criteria | Typical Due Date | Escalation |
|---|---|---|---|
| Critical | Direct patient safety risk or regulatory violation | 7-14 days for containment; 30 days for corrective action | Immediate notification to top management and regulatory affairs |
| Major | ISO 13485 clause violation; certification impact | 30-90 days | Weekly progress review by quality manager |
| Minor | Documentation gap; no immediate risk | 60-180 days | Monthly review; may batch with similar findings |
| Observation | Trend or improvement opportunity | Next continuous improvement cycle | Tracked but not formally remediated |
These timelines are starting points. Adjust for your organization's size, resources, and the auditor's expectations, and document your rationale for each priority tier so auditors see a risk-based approach, not arbitrary deadlines.
Create an ISO 13485 Audit Remediation Timeline
An ISO 13485 audit remediation timeline sequences actions into realistic phases:
Phase 1: Immediate Response (Days 1-7)
- Acknowledge the audit findings formally
- Assign owners to each finding
- Schedule corrective action planning meetings
Phase 2: Root Cause Analysis (Days 8-21)
- Investigate why each finding occurred
- Document the root cause analysis
- Identify systemic patterns across findings
Phase 3: Corrective Action Execution (Days 22-90)
- Implement fixes for major findings
- Update procedures and documentation
- Conduct training where needed
Phase 4: Effectiveness Verification (Days 91-120)
- Audit your own corrective actions
- Collect objective evidence of success
- Run trial batches or test processes
Phase 5: Follow-Up Audit Preparation (Days 121-150)
- Compile complete remediation package
- Conduct mock audit of fixed areas
- Brief your team on auditor expectations
This timeline assumes major findings; minor findings might compress into 60-90 days. Build in verification time, rushing to "done" without proving effectiveness wastes effort.
Execute the ISO 13485 Corrective and Preventive Action (CAPA) Process
CAPA is where remediation becomes real: a corrective action fixes the immediate problem, and a preventive action stops similar issues elsewhere. The process follows this sequence:
Step 1: Define the Problem Clearly State what was found and why it matters. "We have outdated procedures" is vague. "We have three procedures dated 2023 still in active use, but our control system shows they were superseded in 2024" is actionable.
Step 2: Investigate Root Cause Don't stop at the surface.
Step 3: Design the Corrective Action This is your fix.
Step 4: Plan Implementation Who does the work, when, and with what resources?
Step 5: Execute and Document Do the work. Keep records of every step.
Step 6: Verify Effectiveness Run a test.
Step 7: Close the Finding Document that corrective action is complete, effective, and verified.
How to Write an Audit Response Letter
An audit response letter acknowledges the auditor's findings and commits to remediation. It should include:
Opening Thank the auditor. Acknowledge receipt of the audit report. State your commitment to addressing findings.
Root Cause Summary For each major finding, state the root cause in one sentence.
Corrective Action Summary For each finding, name the corrective action and target completion date.
Preventive Action Statement Describe how you'll prevent similar findings.
Closure Plan Offer to submit evidence of closure by a specific date.
Closing Restate your commitment to quality. Provide a contact person for questions.
Keep the letter professional and factual.
Verify Closure and Prepare for Follow-Up Audit
Closure verification separates real fixes from paperwork exercises. Completing a corrective action is not the same as verifying it works. This section gives you a measurable, workflow-driven approach to closure.
The Workflow from Finding to Verified Closure
Every finding should move through a sequenced workflow. Skipping steps creates gaps auditors will find.
- Containment, Stop the immediate risk. Quarantine product, lock superseded documents, halt the nonconforming process.
- Correction, Fix the specific instance. Replace the expired procedure, retrain the individual, repair the record.
- Root Cause Analysis, Determine why the finding occurred. Use a structured method (5 Whys, fishbone, fault tree) and document it.
- Corrective Action, Implement a systemic fix that addresses the root cause.
- Implementation Evidence, Collect objective proof the fix was deployed (training records, system screenshots, updated SOPs, work orders).
- Effectiveness Verification, Measure whether the fix actually works using predefined acceptance criteria.
- Closure Approval, Independent verification owner signs off that effectiveness criteria are met.
This workflow applies to every finding regardless of severity. Evidence depth scales with risk, but the sequence does not change.
Effectiveness-Check Methods and Measurable Acceptance Criteria
An effectiveness check answers one question: "Does the corrected process actually work?" The answer must be measurable. Define acceptance criteria before implementing the corrective action to avoid retrofitting success measures.
| Finding Type | Effectiveness Check Method | Acceptance Criteria | Sampling Period | Recurrence Threshold |
|---|---|---|---|---|
| Document control | Sample active procedures; verify version match | 100% of sampled procedures match current version | 30 days after implementation | Zero outdated procedures found in next internal audit |
| Training | Test trained staff; observe on-the-job application | 90%+ pass rate on knowledge check; supervisor confirms application | 60 days after training | No repeat training findings in 12 months |
| Product traceability | Trace finished product to raw materials | Complete trace with no missing steps | 90 days after fix | Zero incomplete traces in next 5 product lots |
| Supplier control | Audit supplier records; verify incoming inspection | 100% of critical suppliers have current approvals | 90 days after fix | No supplier-related nonconformities in 6 months |
| Process validation | Review validation records; run test batch | Validation meets predefined acceptance criteria | 90 days after fix | No process deviations in 3 consecutive batches |
Adapt these examples to your findings and risk level. Each criterion must be objective, measurable, and tied to a sampling period and recurrence threshold.
Prepare Your Follow-Up Audit Package
Once effectiveness is verified, compile a complete package showing the full trail from finding to closure.
- Complete remediation plan with all corrective actions and status
- Root cause analysis documentation for each finding
- Implementation evidence (training records, updated procedures, system screenshots, work orders)
Organize the package by finding ID so the auditor can trace each item from nonconformity to verified closure. A well-structured package reduces follow-up audit time and demonstrates a mature quality system.
Regulatory and Certification-Body Response Management
Audit remediation is not the same as responding to a regulatory inspection. Certification bodies (such as notified bodies under ISO 13485) typically require a formal response within 30 days for major findings and 60-90 days for minor findings. Regulatory inspections (FDA or MDR authorities) may have different deadlines and escalation paths.
Key differences to manage:
- Certification body response: Submit a remediation plan and evidence package by the deadline. Request an extension in writing if needed, with a justified timeline. Escalate through your management representative if the auditor rejects your response.
- Regulatory inspection response: Follow the specific agency's format and deadline. Do not assume your certification body response will satisfy a regulatory authority. Keep the two tracks separate but aligned.
Schedule Your Follow-Up Audit
Schedule your follow-up audit 30-60 days after closure, giving the auditor time to review documentation and you time to address questions. For major findings, the certification body may require a follow-up audit within 30-90 days; confirm the timeline in your response letter.
Before the follow-up audit, conduct a mock audit of the remediated areas using the same sampling methods and acceptance criteria as your effectiveness checks. Fix any gaps before the real audit.
Frequently Asked Questions
What is an ISO 13485 audit remediation plan?
An ISO 13485 audit remediation plan is a structured response document that addresses every finding, nonconformity, and observation from an internal, external, certification, or surveillance audit. It maps each finding to the specific ISO 13485:2016 clause or regulatory requirement violated, assigns an action owner, sets a realistic due date, describes the root cause, outlines the corrective or preventive action, and defines how you will verify effectiveness. The plan transforms audit findings into tracked, closed actions with documented evidence of closure.
What is the difference between a major and minor nonconformity in ISO 13485 audits?
A major nonconformity is a systematic failure or absence of a process required by ISO 13485 that could affect product safety, quality, or regulatory compliance. A minor nonconformity is a single or isolated instance of non-compliance that does not directly threaten the quality management system's integrity. Major findings typically require immediate containment, investigation, and proof of system-wide correction. Minor findings still need root-cause analysis and corrective action, but timelines may be longer. Both must be addressed in your remediation plan with objective evidence of closure.
How long does an ISO 13485 audit remediation process typically take?
Timeline depends on finding severity and complexity. Major nonconformities often require 30-90 days to investigate, implement, and verify closure; minor findings may take 60-180 days. Immediate containment actions (stopping unsafe processes, quarantining affected product) should begin within 1-5 days. Root-cause analysis and corrective action design take 2-3 weeks. Implementation and effectiveness checks take another 4-8 weeks. Surveillance audits or certification re-audits typically occur 3-6 months after remediation to confirm sustained closure. Document all timelines in your remediation plan and communicate them to the auditor.
What are common mistakes when responding to ISO 13485 audit findings?
Common pitfalls include: treating symptoms instead of root causes (quick fixes that don't stick), assigning actions to people without authority or capacity, setting unrealistic due dates that guarantee failure, failing to document objective evidence of implementation, skipping effectiveness checks and relying on assumption that the fix worked, not communicating findings to the entire quality management system (so the same problem recurs elsewhere), and delaying response until the auditor threatens certification suspension. Avoid these by assigning clear action owners, conducting genuine root-cause analysis, building in verification steps, and tracking every action to closure with evidence.