Types of QMS Audits: A Guide to Quality Audits in MedTech
A quality audit — also called a QMS audit — is a systematic, independent check that your quality management system meets the requirements it is built against, and that your organisation actually follows it in practice. Those are two separate questions, and most audit findings come from the gap between them.
I know a lot of people dread audits, but they’re simply a fact of life in the medical device industry. And the better you understand and prepare for the audits you’ll inevitably face, the easier it will be to get safe and effective medical devices to market.
So, let’s go over the three main types of QMS audits you’ll undergo (or carry out) and look at some tips for preparing your team for those audits.
What are the different QMS audit types you’ll face?
|
Type
|
Who audits
|
What it looks like in MedTech
|
|---|---|---|
|
First-party (internal)
|
Your own team |
Scheduled internal audits of your own QMS processes, run by trained internal auditors who are independent of the area being audited |
|
Second-party (supplier)
|
You audit a supplier, or a customer audits you |
Supplier qualification and ongoing supplier audits; also customer audits of your facility when you manufacture for someone else |
|
Third-party (external)
|
A regulator or certification body |
FDA inspections, notified body conformity assessments, MDSAP audits and ISO 13485:2016 certification audits |
The three types that follow all sit inside this structure: an FDA inspection and a notified body conformity assessment are both third-party audits, and your internal audit programme is first-party. The one most MedTech teams under-invest in is second-party — auditing your own suppliers — even though supplier-driven nonconformances are one of the most common sources of quality events.
Broadly, QMS audits are either internal — run by your own team — or external, carried out by someone else. In the external category, the two you are most likely to meet in MedTech are the US Food and Drug Administration (FDA) and notified bodies.
QMS Audit #1: FDA inspection (third-party)
First, a note on terminology: When FDA comes knocking, it’s an inspection, though you may hear people refer to it casually as an audit and the FDA inspectors as auditors. FDA inspectors will determine whether your QMS complies with 21 CFR Part 820 — since 2 February 2026, the Quality Management System Regulation (QMSR). The QMSR replaced the older Quality System Regulation (QSR) and incorporates ISO 13485:2016 by reference, so an FDA inspection now assesses conformity to that standard alongside the FDA-specific requirements that remain in Part 820.
The FDA doesn't use a fixed inspection schedule for medical product facilities. Instead, it selects sites for inspection using a risk-based model that weighs factors like facility type, compliance history (including whether a site has been inspected in the last four years), hazard signals such as past product recalls, the inherent risk of the product being made (e.g., sterility, API concentration, emergency use), and whether a foreign regulatory partner has already inspected the facility. In practice, this means a facility making higher-risk products with little inspection history, like a never-inspected sterile device site, gets prioritized over a lower-risk one with a solid track record.
You can think of FDA inspections as the Super Bowl of audits. These are federal agents showing up at your company’s doorstep (sometimes unannounced!), and they have the power to shut your company down on the spot. The good news is that with the right attitude toward quality and the right QMS software, there should be nothing to panic about when FDA inspectors come knocking.
QMS Audit #2: Notified body conformity assessment
To market your device in the EU, your QMS will need to be certified to the international standard ISO 13485:2016. To get that certification, you’ll need to be audited by a notified body, which is a third-party organization that has been designated by an EU member state to assess the conformity of your QMS.
ISO 13485 is technically a voluntary standard and notified bodies are not law enforcement agencies. In fact, you’re paying them to come audit you. This means these audits are a little less tense than FDA inspection. More of a playoff game than the Super Bowl.
Of course, that doesn’t mean you’re paying them to pass you. If your QMS is in disarray, they will not certify your conformity with ISO 13485:2016, and you won’t be able to sell your product in the EU.
TIP: The timeline between your first contact with a notified body and the QMS audit can be as long as six months. So while you do need to be ready when they show up, you don’t need your QMS to be perfect when you first pick up the phone and call them.
QMS Audit #3: Internal audit (first-party)
Internal audits are simply the audits that an organization will perform on its own QMS to ensure it’s in compliance. Internal audits are required by both FDA regulations and ISO 13485:2016, so you must conduct these at least once a year.
Internal audits will be led by the Quality team within your own company. You can think of these as practice for the real thing—although that doesn’t mean you should take them lightly. The point is to proactively find any issues that may lead to findings when you’re facing FDA or a notified body.
If you’re looking for more information on conducting successful internal audits, I spoke with Greenlight Guru founder Jon Speer about this very topic not too long ago on this episode of the Global Medical Device Podcast.
QMS Audit #4: Supplier Audits
The three audits above are ones you undergo. This one you carry out.
Under ISO 13485:2016 you are responsible for the quality of what your suppliers provide, which means qualifying them before you use them and monitoring them after. For critical suppliers, that usually means an on-site or remote audit of their quality system, scoped to the processes that affect your device.
The practical difficulty is that supplier audit findings tend to live somewhere other than your QMS — a spreadsheet, an email thread, a folder on someone's drive. When an FDA investigator asks how you evaluated a supplier whose component turned up in a complaint, the answer needs to be a record, not a recollection. Keeping supplier qualification, audit findings, nonconformances and performance monitoring connected in the same system is what turns supplier management from an annual formality into something that actually catches problems.
How a QMS audit works, step by step
Whether it is internal, supplier or third-party, an audit follows the same four stages.
- Plan. Define the scope, the criteria you are auditing against, the schedule and the audit team. For internal audits, this is where the audit program matters more than any individual audit — a program covers every process in your QMS across a defined cycle, weighted toward the areas with the most risk and the worst history. Auditors must be independent of the area they audit.
- Conduct. The audit team reviews records, observes processes and interviews the people who run them. Auditors are checking two things at once: does the procedure meet the requirement, and does what people actually do match the procedure. Most findings come from the gap between the two.
- Report. Findings are documented and classified — typically as major nonconformities, minor nonconformities and observations or opportunities for improvement. The audit report is a controlled record and needs to be retained like one.
- Close. Findings are investigated, root causes identified, and corrective actions defined with owners and due dates. Significant findings should escalate into your CAPA process. The audit is not finished when the report is issued; it is finished when the actions are verified as effective.
That last stage is where most audit programs actually fail. Findings get logged, actions get assigned, and then nobody verifies whether the fix worked — which is how the same nonconformity turns up in the next audit cycle.
How to prepare for a QMS audit
Keeping your QMS audit-ready is about more than making a few tweaks to your SOPs—it’s about establishing a culture of quality within your organization.
The organizations where everyone understands that quality isn’t just the responsibility of the Quality department are the ones that tend to breeze through audits with zero findings. With that said, there are some steps you can take to start building that culture of quality and prepare for your next QMS audit.
Tip #1: Make the most of your internal audits
It’s sad to say, but internal audits are often looked at as an impediment to getting things done. For some companies, the internal audit is the last box that has to be checked at the end of the year.
Not only is this mentality missing the point of the internal audit, it’s also costing those companies valuable opportunities to improve their processes and catch problems that may result in findings during external audits.
Think of it this way: Would you rather find the problem yourself and fix it or let FDA find it and issue you a 483 or a warning letter? It seems like a pretty obvious choice to me.
Tip #2: Ask your new hires for feedback on your QMS procedures
New hires are an amazing source of insight into your SOPs because they’re subject matter experts, but they aren’t experts in the way you’ve been doing things. That means they’ll look at your QMS with the same fresh set of eyes as an auditor.
So, make sure you solicit their feedback on the SOPs for their role—and take that feedback seriously. When they look at those SOPs, are the procedures clear? Do they think they could follow these steps exactly and achieve the correct result?
If they’re struggling to understand how you do things, chances are an auditor will too.
Tip #3: Don’t let audit findings in your “parking lot” go to waste
There will be times during external audits when an auditor asks to see some documentation—and you have exactly what they’re looking for. But you also realize that if the auditor had asked for something slightly different, you would have had a hard time providing it.
Now, what you do with that little epiphany matters. You could just kind of forget about it, but there’s no guarantee it won’t come up in your next audit.
My recommendation is that you put the issue in what’s known as your “parking lot.” It could be a document or spreadsheet, but your parking lot is just an industry term for the place you record all the opportunities for improvement you noticed during an external audit. There’s no sense hoping you get lucky again next year, so make a plan for evaluating and acting on those opportunities for improvement as soon as possible.
Stay audit-ready with medical device-specific QMS software from Greenlight Guru
The truth is, your entire team can be committed to quality and bought in on the importance of QMS audits, but you still need the right tools for the job.
Companies that use a paper-based QMS or try to make generic QMS tools work for them are playing with fire when audit time comes around. Multiple document versions, missing signatures, or lost records will all come back to haunt teams that rely on inadequate QMS tools.
At Greenlight Guru, our eQMS platform was created by medical device professionals for medical device professionals. Our comprehensive, out-of-the-box solution helps you stay audit-ready at all times with Part 11 compliant e-signatures, flexible review and approval workflows, revision control and more. You’ll be able to provide auditors and inspectors with the signatures and objective evidence they need as soon as they ask for it. No more chasing down lost or missing records.
So, if you’re ready to see how a purpose-built eQMS can make audit panic a thing of the past, get your free demo of Greenlight Guru today.
Frequently Asked Questions
What is a quality management system audit?
What are the three types of quality audits?
What are the key components of a quality management system audit checklist?
What are the 7 principles of management system auditing?
Sara Adams has spent over 15 years helping MedTech companies prepare for FDA inspections and build strong quality systems. Her expertise spans startups and established organizations, where she has led teams through high-stakes audits, simplified compliance, and improved operations. Sara is skilled in Quality System...
Related Posts
What is an ISO Audit?
3 Things to Love about Internal Audits
Tips for Virtual Audits Your Medical Device Company Can Implement Today
Get your free PDF
FDA QSR, QMSR and ISO 13485:2016 Internal Audit Checklist




