What FDA and EU MDR Auditors Really Look for During Quality System Audits

images-2_2026-08-20-152214_zwac.jpeg

For many medical device companies, a quality system audit is one of the most challenging regulatory milestones.

Whether the audit is conducted by the FDA, a Notified Body, an MDSAP Auditing Organization, or another Competent Authority, the objective is the same: to determine whether your Quality Management System (QMS) is being followed—not just documented.

A polished Quality Manual and well-written procedures are only the starting point. Auditors want objective evidence that your quality processes are implemented consistently, supported by records, and embedded throughout the organization.

At RQMIS, we help companies prepare for FDA inspections, EU MDR audits, MDSAP audits, supplier audits, and remediation efforts. One of the most common misconceptions we encounter is that documentation alone demonstrates compliance.

It doesn't.

A compliant QMS is one that is operational, traceable, and consistently executed.

Design Controls

Design Controls remain one of the first—and most heavily scrutinized—areas during an audit.

Auditors evaluate whether product development has been properly planned, documented, reviewed, approved, and controlled throughout the product lifecycle.

Typical records include:

  • Design and development plans
  • Design inputs and outputs
  • Design reviews
  • Verification and validation activities
  • Design transfer documentation
  • Design changes
  • Requirements and design traceability
  • Risk management integration

For Software as a Medical Device (SaMD), AI-enabled devices, and connected products, auditors are placing even greater emphasis on software lifecycle documentation and traceability.

Risk Management

Risk management is no longer viewed as a standalone file.

FDA and EU MDR auditors increasingly expect risk management to be integrated across the entire quality system, including:

  • Design requirements
  • Verification and validation
  • Complaint investigations
  • CAPA activities
  • Human Factors engineering
  • Cybersecurity
  • Post-market surveillance

Weak connections between risk files and operational activities remain one of the most common audit observations.

CAPA Effectiveness

Corrective and Preventive Action (CAPA) continues to be a primary audit focus.

Auditors want evidence that organizations:

  • Identify true root causes
  • Implement effective corrective actions
  • Verify effectiveness
  • Monitor trends
  • Prevent recurring issues

A CAPA system that exists only on paper is a significant compliance risk.

Complaint Handling and Post-Market Surveillance

Complaint handling provides auditors with a direct view into how an organization responds to product issues.

They typically review:

  • Complaint intake and investigation procedures
  • Timeliness of investigations and closure
  • MDR/Vigilance reporting decisions
  • Trend analysis
  • CAPA escalation
  • Post-market surveillance (PMS) activities

Under EU MDR, auditors also expect a mature PMS program that actively collects and evaluates real-world performance data.

Backlogs, inconsistent investigations, or weak trend analysis often lead to expanded audit scrutiny.

Supplier Controls

Supplier oversight is another area receiving increased attention.

Auditors commonly review:

  • Supplier qualification
  • Critical supplier evaluations
  • Quality agreements
  • Incoming inspection activities
  • Supplier monitoring
  • Oversight of outsourced processes

As software and cybersecurity become increasingly important, organizations are expected to apply the same level of oversight to software vendors and external development partners.

Training

Training records often reveal how well a quality system is functioning.

Auditors verify that personnel:

  • Were trained before performing assigned tasks
  • Maintain current training records
  • Follow documented procedures
  • Understand the processes they perform

If employees cannot clearly explain their responsibilities, auditors may question whether procedures are truly being followed.

Document Control and Change Management

Document control forms the foundation of every compliant QMS.

Auditors expect to see:

  • Controlled document revisions
  • Approval histories
  • Formal change management
  • Removal of obsolete documents
  • Controlled document distribution
  • Complete and traceable records

For software-based products, configuration management and software version control are also becoming routine audit topics.

Cybersecurity and Software Lifecycle Controls

As connected devices and software products become more common, cybersecurity expectations continue to grow.

Auditors increasingly review:

  • Software lifecycle processes
  • Secure software development practices
  • Cybersecurity risk management
  • Vulnerability management
  • Penetration testing documentation
  • Software Bill of Materials (SBOM)
  • Software change control

Rather than treating cybersecurity as a separate activity, regulators expect it to be fully integrated into the QMS.

Internal Audits

A strong internal audit program is often one of the clearest indicators of a mature quality system.

Auditors expect internal audits to be:

  • Conducted regularly
  • Risk-based
  • Independent and objective
  • Well documented
  • Followed by timely corrective actions

A weak internal audit program frequently signals broader quality system deficiencies.

FDA vs. EU MDR: Different Emphasis, Same Goal

While FDA and EU MDR audits evaluate many of the same quality system elements, each places greater emphasis on different areas.

FDA inspections typically focus on:

  • Design Controls
  • Complaint Handling
  • CAPA
  • Manufacturing controls
  • Process validation
  • Medical Device Reporting (MDR)

EU MDR audits often emphasize:

  • Clinical evidence
  • Post-Market Surveillance (PMS)
  • Post-Market Clinical Follow-up (PMCF)
  • Risk management integration
  • Technical Documentation
  • Supplier oversight
  • Lifecycle compliance

Organizations operating globally should build a QMS that satisfies both regulatory frameworks rather than optimizing for only one.

Auditors Look for Consistency

Perhaps the most important principle to understand is that auditors are evaluating consistency.

They routinely compare:

  • Procedures versus actual practice
  • Risk files versus complaint data
  • CAPAs versus trend analysis
  • Design inputs versus verification evidence
  • Training records versus employee understanding
  • Software documentation versus release history

When records tell different stories, auditors dig deeper.

Audit Readiness Starts Long Before the Audit

Companies that consistently achieve successful audit outcomes typically:

  • Build their QMS early in development
  • Maintain documentation continuously
  • Perform meaningful internal audits
  • Address issues before they become findings
  • Integrate risk management into daily operations
  • Treat quality as a business process—not a regulatory obligation

Attempting to "clean up" a quality system just before an inspection rarely produces lasting results.

Final Thoughts

FDA and EU MDR auditors are not looking for perfection—they are looking for confidence.

They want objective evidence that your organization:

  • Understands its processes
  • Follows documented procedures
  • Manages risk effectively
  • Responds appropriately to quality issues
  • Maintains compliance throughout the product lifecycle

Organizations that invest in a mature, scalable Quality Management System are typically better prepared for audits, move more efficiently through regulatory submissions, and require far less remediation over time.

A quality system shouldn't exist simply to pass an audit—it should enable consistent product quality, regulatory compliance, and long-term business success.

Need Help Preparing for Your Next Audit?

RQMIS helps medical device, IVD, SaMD, AI-enabled, and combination product manufacturers prepare for FDA inspections, EU MDR audits, and MDSAP assessments through audit readiness evaluations, internal audits, CAPA remediation, complaint handling improvements, cybersecurity integration, and Quality Management System development.

If your organization would benefit from a QMS Audit Readiness Assessment, our regulatory and quality experts can evaluate your current system, identify compliance gaps, and provide practical recommendations to strengthen your readiness before your next inspection or audit.

Back to Blog