For many medical device companies, a quality system audit is one of the most challenging regulatory milestones.
Whether the audit is conducted by the FDA, a Notified Body, an MDSAP Auditing Organization, or another Competent Authority, the objective is the same: to determine whether your Quality Management System (QMS) is being followed—not just documented.
A polished Quality Manual and well-written procedures are only the starting point. Auditors want objective evidence that your quality processes are implemented consistently, supported by records, and embedded throughout the organization.
At RQMIS, we help companies prepare for FDA inspections, EU MDR audits, MDSAP audits, supplier audits, and remediation efforts. One of the most common misconceptions we encounter is that documentation alone demonstrates compliance.
It doesn't.
A compliant QMS is one that is operational, traceable, and consistently executed.
Design Controls remain one of the first—and most heavily scrutinized—areas during an audit.
Auditors evaluate whether product development has been properly planned, documented, reviewed, approved, and controlled throughout the product lifecycle.
Typical records include:
For Software as a Medical Device (SaMD), AI-enabled devices, and connected products, auditors are placing even greater emphasis on software lifecycle documentation and traceability.
Risk management is no longer viewed as a standalone file.
FDA and EU MDR auditors increasingly expect risk management to be integrated across the entire quality system, including:
Weak connections between risk files and operational activities remain one of the most common audit observations.
Corrective and Preventive Action (CAPA) continues to be a primary audit focus.
Auditors want evidence that organizations:
A CAPA system that exists only on paper is a significant compliance risk.
Complaint handling provides auditors with a direct view into how an organization responds to product issues.
They typically review:
Under EU MDR, auditors also expect a mature PMS program that actively collects and evaluates real-world performance data.
Backlogs, inconsistent investigations, or weak trend analysis often lead to expanded audit scrutiny.
Supplier oversight is another area receiving increased attention.
Auditors commonly review:
As software and cybersecurity become increasingly important, organizations are expected to apply the same level of oversight to software vendors and external development partners.
Training records often reveal how well a quality system is functioning.
Auditors verify that personnel:
If employees cannot clearly explain their responsibilities, auditors may question whether procedures are truly being followed.
Document control forms the foundation of every compliant QMS.
Auditors expect to see:
For software-based products, configuration management and software version control are also becoming routine audit topics.
As connected devices and software products become more common, cybersecurity expectations continue to grow.
Auditors increasingly review:
Rather than treating cybersecurity as a separate activity, regulators expect it to be fully integrated into the QMS.
A strong internal audit program is often one of the clearest indicators of a mature quality system.
Auditors expect internal audits to be:
A weak internal audit program frequently signals broader quality system deficiencies.
While FDA and EU MDR audits evaluate many of the same quality system elements, each places greater emphasis on different areas.
FDA inspections typically focus on:
EU MDR audits often emphasize:
Organizations operating globally should build a QMS that satisfies both regulatory frameworks rather than optimizing for only one.
Perhaps the most important principle to understand is that auditors are evaluating consistency.
They routinely compare:
When records tell different stories, auditors dig deeper.
Companies that consistently achieve successful audit outcomes typically:
Attempting to "clean up" a quality system just before an inspection rarely produces lasting results.
FDA and EU MDR auditors are not looking for perfection—they are looking for confidence.
They want objective evidence that your organization:
Organizations that invest in a mature, scalable Quality Management System are typically better prepared for audits, move more efficiently through regulatory submissions, and require far less remediation over time.
A quality system shouldn't exist simply to pass an audit—it should enable consistent product quality, regulatory compliance, and long-term business success.
RQMIS helps medical device, IVD, SaMD, AI-enabled, and combination product manufacturers prepare for FDA inspections, EU MDR audits, and MDSAP assessments through audit readiness evaluations, internal audits, CAPA remediation, complaint handling improvements, cybersecurity integration, and Quality Management System development.
If your organization would benefit from a QMS Audit Readiness Assessment, our regulatory and quality experts can evaluate your current system, identify compliance gaps, and provide practical recommendations to strengthen your readiness before your next inspection or audit.