ultimate-guide
MDSAP Audit Preparation for Medical Devices: 2026 Guide
Table of Contents
- What Is the Medical Device Single Audit Program (MDSAP) and Why It Matters
- Understanding the MDSAP Audit Cycle and Timeline
- The MDSAP Audit Approach and Methodology
- Building Your MDSAP Audit Checklist for Compliance
- How Long Does an MDSAP Audit Take: Duration and Planning
- MDSAP Audit Findings and Corrective Actions: Response Strategy
- Post-Audit Remediation and Common Pitfalls to Avoid
- Frequently Asked Questions
Last Updated: October 9, 2026
What Is the Medical Device Single Audit Program (MDSAP) and Why It Matters
The Medical Device Single Audit Program lets manufacturers demonstrate quality management system compliance across multiple countries through one integrated MDSAP audit covering all five regulatory jurisdictions, replacing separate audits for each market.
Each region historically demanded its own audit cycle, documentation review, and compliance verification, causing duplicated effort and extended timelines that MDSAP audit preparation now consolidates into one pathway.
The core principle: if your quality management system meets MDSAP audit criteria, it simultaneously satisfies requirements for FDA (United States), Health Canada, PMDA (Japan), TGA (Australia), and ANVISA (Brazil).
Understanding the MDSAP Audit Cycle and Timeline
The MDSAP audit cycle is a rolling three-year certification cycle with defined audit types, fixed scheduling windows, and a documented audit time calculation the Auditing Organization (AO) applies before the first on-site day.
The Three-Year Certification Cycle
After the initial certification audit, the AO schedules surveillance audits in the next two years, then a recertification audit in year three; the cycle resets after recertification. Each audit type has a different scope and duration:
- Initial certification audit: Full QMS and regulatory requirement coverage across all five jurisdictions (FDA, Health Canada, PMDA, TGA, ANVISA). Typically 3-5 on-site days for a single-site manufacturer.
- Year 1 and Year 2 surveillance audits: Reduced scope focused on changes since the last audit, previous findings, and high-risk processes. Typically 2-3 on-site days.
- Year 3 recertification audit: Returns to full scope, similar in depth to the initial audit. Typically 3-5 on-site days.
The AO schedules surveillance audits within a defined window around the certification decision anniversary. Missing that window can trigger an unannounced audit or certificate suspension, affecting market access in MDSAP-recognizing jurisdictions.
How Audit Time Is Determined
The AO calculates audit duration using a documented formula in the MDSAP Audit Approach document, but the practical inputs are consistent:
- Number of effective employees at each site, including temporary and contract personnel involved in device realization.
- Number of manufacturing sites and whether they are owned or contracted.
- Device classification and quantity of devices covered under the certificate.
Manufacturers commonly underestimate audit time by excluding contract sterilizers, calibration vendors, and design subcontractors, entities that extend audit scope and on-site days.
The Companion Document: Your Audit Roadmap
The MDSAP companion document is the formal scope document the AO uses to plan the audit. It lists legal manufacturer name and address per site, devices covered with classification and intended use, jurisdictions in scope, outsourced processes and suppliers, and regulatory contacts and prior audit references.
Errors propagate into the audit plan: wrong classification means wrong regulatory requirements, and an omitted outsourced sterilizer can surface as a nonconformity for incomplete scope disclosure. Review it against your actual device portfolio and supplier list before submission.
Country-Specific Scheduling Considerations
While MDSAP consolidates the audit, each jurisdiction retains its own recognition rules and timing:
- Health Canada requires a valid MDSAP certificate for certain device classes, in good standing throughout the licensing period.
- FDA accepts MDSAP audit reports in lieu of routine FDA inspections for participating firms, but the firm must still maintain its FDA registration and listing.
- ANVISA recognizes MDSAP for its own certification processes, with specific documentation requirements layered on top.
Because recognition rules differ, work backward from the earliest regulatory deadline to determine when each market needs the certificate or report.
A Realistic Preparation Timeline
A workable timeline for a single-site manufacturer preparing for an initial MDSAP audit:
- Months 1-2: Gap assessment against ISO 13485:2016 and the MDSAP Audit Approach; companion document drafting.
- Months 2-3: Internal audit using an MDSAP-aligned checklist; management review; corrective actions.
- Month 3: AO selection and audit scheduling; audit time confirmation.
Total elapsed time from kickoff to certificate is typically 4-6 months for a well-prepared single-site manufacturer. Multi-site or heavily outsourced operations should add 2-3 months.
Where the Cycle Breaks Down
The most frequent cycle failures are scheduling and scope failures: a companion document that does not match the actual device portfolio, a missed surveillance window, and treating the audit as a one-time project. Assign a named owner for the MDSAP cycle, track the surveillance window on a calendar, and review the companion document annually against the current device list.
The MDSAP Audit Approach and Methodology
The auditing organization applies a standardized methodology across all MDSAP audits, though criteria vary slightly by device classification and intended use. The audit examines your quality management system against ISO 13485:2016 plus regulatory-specific expectations from each of the five jurisdictions, typically following this structure:
- Opening meeting: Auditor outlines scope, timeline, and focus areas
- Management review: Discussion of your quality policy, management responsibility, and strategic compliance decisions
- Process audit: Deep dive into design and development, manufacturing controls, documentation, risk management
Nonconformity grading determines severity: a major nonconformity indicates a systematic breakdown that could affect product safety, efficacy, or regulatory submission integrity, while a minor one suggests isolated lapses. Major nonconformities trigger mandatory corrective action with evidence submission before certification is granted.
Building Your MDSAP Audit Checklist for Compliance
An effective MDSAP audit checklist translates regulatory requirements into operational verification points, revealing gaps before the auditor does.

Your checklist should cover these core domains:
Quality Management System Documentation
- Quality manual reflects current organizational structure and regulatory strategy
- Standard operating procedures align with actual manufacturing practices
- Records demonstrate consistent execution of documented procedures
Design Controls and Technical Documentation
- Design history file contains complete design input, output, review, and verification records
- Risk management documentation (per ISO 14971) is integrated into design decisions
- Design changes include impact assessment and re-verification where required
Manufacturing and Process Controls
- Process validation studies demonstrate reproducibility and consistency
- Batch records are complete, legible, and traceable to raw materials and finished product
- Equipment maintenance and calibration schedules are followed
Supplier and Outsourced Activity Management
- Supplier evaluation criteria are documented and consistently applied
- Purchasing specifications clearly define requirements
- Incoming material inspection or testing verifies supplier compliance
Post-Market Surveillance and Complaint Handling
- Complaint procedures define receipt, investigation, and trending
- Adverse event reporting follows regulatory timelines for each jurisdiction
- Trend analysis identifies patterns that might trigger corrective action
This checklist becomes your internal audit foundation. Many manufacturers run a mock MDSAP audit 4-6 weeks before the real one using the same checklist the AO will apply, revealing gaps while there is still time to fix them.
How Long Does an MDSAP Audit Take: Duration and Planning
MDSAP audit duration depends on device complexity, number of manufacturing sites, outsourced activities, and regulatory history. A straightforward Class II device at a single facility might require 3 days; a combination product with multiple partners or a Class III device typically demands 4-5 days.
Beyond the on-site days, plan for:
- Pre-audit preparation: 8-12 weeks for thorough readiness
- Documentation assembly: 2-4 weeks to organize records
- Internal audit execution: 1-2 weeks
The total timeline from audit initiation to certification typically spans 4-6 months. Compressed preparation often produces major nonconformities that delay certification and require significant rework.
MDSAP Audit Findings and Corrective Actions: Response Strategy
When the AO issues findings, your response strategy determines whether you achieve certification or face extended remediation. Major nonconformities require documented corrective action with evidence; minor ones may be addressed through corrective or preventive action. The corrective action response should follow this structure:
- Root cause analysis: Identify why the nonconformity occurred, not just what went wrong
- Corrective action plan: Describe specific steps to eliminate the root cause
- Implementation evidence: Document that corrective actions were actually executed
- Effectiveness verification: Demonstrate that the fix prevents recurrence
- Preventive measures: Identify similar risks elsewhere in your system and address them proactively
Treating corrective actions as administrative paperwork is a critical mistake. The AO expects genuine process improvement: if a nonconformity shows your design review wasn't catching requirements, the corrective action must redesign the review process, train personnel, and demonstrate the new process works with actual design examples. Most AOs allow 30-90 days for corrective action submission, and late or incomplete evidence extends the certification decision.
Post-Audit Remediation and Common Pitfalls to Avoid
Most MDSAP guides stop at the closing meeting, but post-audit remediation is where manufacturers either convert findings into a stronger QMS or spend the next surveillance cycle defending the same weaknesses.
A Post-Audit Remediation Roadmap
Treat remediation as a project with phases, owners, and evidence.
Phase 1, Triage (Days 1-5 after findings)
- Categorize each finding as major or minor and map it to the affected process.
- Identify findings that share a root cause; a single systemic fix may close several findings.
- Assign an accountable owner per finding. The owner should be the process owner, not the quality manager by default.
Phase 2, Root Cause Analysis (Days 5-20)
- Use a structured method (5 Whys, fishbone, fault tree) and document the reasoning, not just the conclusion.
- Distinguish the immediate cause from the systemic cause. "The procedure was not followed" is an immediate cause; "the procedure was impractical for the production schedule" is closer to the systemic cause.
- Validate the root cause against evidence: if the root cause is training, the training records should show the gap.
Phase 3, Corrective Action Design (Days 20-35)
- Define the specific change: procedure revision, process redesign, additional control, competency requirement, or supplier action.
- Identify the affected documents, training, and validation needs.
- Define the effectiveness check: what data will demonstrate the fix works, and over what period.
Phase 4, Implementation and Evidence (Days 35-70)
- Execute the change and collect evidence as it happens, not retrospectively.
- Include training records with comprehension verification, updated procedures with approval signatures, and process data from the new state.
- For supplier-related findings, include the supplier's corrective action and your verification of it.
Phase 5, Effectiveness Verification and Submission (Days 70-90)
- Review the effectiveness data against the criteria defined in Phase 3.
- Submit the response package to the AO with a clear index mapping each finding to its root cause, action, evidence, and effectiveness check.
- If effectiveness cannot yet be demonstrated, state the interim control and the date the final data will be available. AOs generally prefer a credible interim control over an unsupported claim of closure.
Frequently Cited Nonconformity Patterns
A small number of process areas account for a disproportionate share of MDSAP findings:
- Design controls: Incomplete design history files, design inputs not traceable to outputs, design changes without impact assessment, and design transfer not validated.
- Risk management: Risk files that were created once and not updated after design changes, complaints, or post-market data. ISO 14971 expects a living risk management process, not a one-time document.
- Supplier controls: Supplier evaluations not performed or not documented, purchasing specifications that do not define requirements, and no verification of outsourced sterilization or contract manufacturing.
A useful pre-audit exercise: walk each area and ask, if the auditor sampled five records here, what would they find? The answer identifies the highest-value remediation work.
Bridging ISO 13485 Internal Audits and MDSAP Audits
A common misconception is that a clean ISO 13485 internal audit means MDSAP readiness. It does not: ISO 13485 audits verify conformity to the standard, while MDSAP audits verify ISO 13485 plus each jurisdiction's regulatory requirements, the gap where many findings originate. To bridge it, add MDSAP-specific verification points on top of the ISO 13485 clauses:
- Jurisdiction-specific reporting: Does the complaint and adverse event procedure define reporting timelines and authorities for each of the five jurisdictions, not just a generic "regulatory authority"?
- Device-specific requirements: Are the regulatory requirements for each device class in scope documented and linked to the applicable QMS processes?
- Companion document accuracy: Does the internal audit verify that the companion document matches the actual device portfolio, sites, and outsourced processes?
Running one internal audit against the ISO 13485 checklist and a second against the MDSAP-augmented checklist is more work, but it surfaces jurisdiction-specific gaps a standard audit misses.
Common Pitfalls That Extend Certification
Beyond technical findings, several process pitfalls reliably delay certification:
- Treating corrective action as a documentation exercise. The AO expects process change, not a rewritten procedure with the same underlying behavior.
- Fixing the symptom, not the system. If one design file was incomplete, the corrective action should address the design control process, not just that file.
- Skipping preventive action. A finding in one product line is a signal to check the same process across all product lines.
Assigning Ownership and Tracking Progress
Remediation fails most often because ownership is diffuse. Assign a single accountable owner per finding, a target closure date, and a weekly review cadence. Track findings in the same CAPA system used for routine quality events, so remediation is visible in management review and feeds the next internal audit, evidence of sustained compliance should already exist in your records.
Frequently Asked Questions
How many stages are there in an MDSAP audit?
MDSAP audits typically consist of two main stages: the initial audit and surveillance audits. The initial audit assesses your quality management system (QMS) against ISO 13485:2016 and country-specific regulatory requirements across all five participating regulatory regions. Surveillance audits occur annually to verify ongoing compliance. Recertification audits happen every three years to renew your certification. Understanding this cycle helps you plan resource allocation and maintain continuous compliance.
What should I include in my MDSAP audit checklist to ensure readiness?
Your MDSAP audit checklist must cover documentation control, management responsibility, design and development, risk management (ISO 14971), post-market surveillance, and corrective action procedures. Verify that your technical documentation is complete and traceable. Ensure personnel records demonstrate training and competence. Review nonconformity grading documentation and verify that your audit scope aligns with your product classification. Cross-reference the MDSAP companion document against your current processes to identify gaps before the auditing organization arrives.
How long does an MDSAP audit take, and how is audit time determined?
Initial MDSAP audit duration depends on your product complexity, manufacturing scope, and organizational size. Audit time determination follows the MDSAP companion document guidance, typically ranging from three to seven business days for initial audits. Surveillance audits are shorter, usually one to three days. Factors affecting duration include the number of manufacturing sites, product lines, and identified nonconformities. Plan for additional time if the auditing organization requires clarification on documentation or process effectiveness.
What are common MDSAP audit findings, and how should we respond?
Common audit findings include inadequate design control documentation, incomplete risk management records, insufficient corrective action evidence, and gaps in management responsibility activities. When the auditing organization issues nonconformity grading reports, respond with a formal corrective action plan that addresses root causes, not just symptoms. Document preventive action steps and provide evidence of implementation. Submit your response within the timeline specified in the audit report. Severe nonconformities may require re-audit verification before certification is granted.
What is the difference between MDSAP and ISO 13485 audits?
MDSAP is a single audit program that assesses compliance with ISO 13485:2016 plus country-specific regulatory requirements across five regions (US, Canada, Japan, Brazil, Australia). ISO 13485 audits focus solely on the quality management system standard. MDSAP provides regulatory authority recognition across multiple markets, reducing the need for separate audits in each region. However, MDSAP requires additional compliance verification against each region's specific regulations, making it more comprehensive than a standalone ISO 13485 audit.
How can we prepare our team for MDSAP audit interviews?
Train your team on your quality management system, design controls, risk management processes, and post-market surveillance activities. Ensure personnel can explain their specific responsibilities and provide examples of how they follow documented procedures. Brief staff on the audit scope and which processes they may be questioned about. Conduct mock audits internally to build confidence. Emphasize that honest, straightforward answers are preferable to speculation. Ensure management is prepared to discuss process effectiveness, management responsibility activities, and corrective action outcomes.
What documents should be ready before an MDSAP audit arrives?
Prepare your Design History File (DHF), Device Master Record (DMR), and Device History Record (DHR). Organize management review records, training documentation, and competency assessments. Have your risk management file (ISO 14971) readily accessible with traceability to design and post-market activities. Compile corrective and preventive action (CAPA) records with evidence of implementation. Ensure your audit scope document is current and your quality manual reflects actual practices. Verify that all technical documentation is complete, dated, and controlled according to your documentation control procedures.