Independent learning for medical-device professionals
CommentaryConsulting
LearningMTL-321 · AUDIT AND QUALITY FRAMEWORKS

Medical Device Single Audit Program (MDSAP)

How one structured regulatory audit examines an organisation's quality system against ISO 13485 and the applicable requirements of participating authorities.

What you will learn

By the end of this topic, you should be able to explain what MDSAP does, identify the seven audit processes and their connections, determine which jurisdictional requirements belong in the audit scope, organise objective evidence around real processes, and prepare a proportionate response to audit findings.

01

One audit, several regulatory purposes

MDSAP allows a recognised Auditing Organization (AO) to conduct a single regulatory audit of a medical-device manufacturer's quality management system. The audit is designed to satisfy the relevant requirements of the regulatory authorities participating in the programme.

The central principle

MDSAP does not replace each jurisdiction's law with one universal rulebook. It applies a common audit method to ISO 13485 and the applicable regulatory requirements of the markets included in the manufacturer's scope.

The value is regulatory reliance: authorities can use a consistent report and certificate rather than independently repeating the same routine QMS audit work.

02

Understand what MDSAP does not do

An MDSAP certificate is evidence about the audited QMS, sites, activities, devices and regulatory criteria shown on the certificate. It is not product approval, market authorisation or proof that every individual device conforms.

  • It does not remove the manufacturer's legal responsibility for its products and QMS.
  • It does not make the participating jurisdictions' requirements identical.
  • It does not prevent a regulator from requesting information or conducting an inspection when necessary.
  • It does not automatically cover activities, sites, product families or jurisdictions outside the certified scope.
  • It does not necessarily replace special, for-cause, pre-approval or combination-product inspections.

Use MTL-301 — ISO 13485 and Design Controls to understand the QMS foundation and MTL-320 — US FDA Medical-device Regulations — 21 CFR Overview for the wider US regulatory context.

03

Five authorities form the Regulatory Authority Council

Australia

The Therapeutic Goods Administration can use reports and certificates as conformity-assessment and market-authorisation evidence when Australian requirements were included.

Brazil

ANVISA can use MDSAP outcomes in pre-market and post-market work and, in defined circumstances, for GMP certification.

Canada

MDSAP certification is required for manufacturers seeking or holding Class II, III or IV medical-device licences.

Japan

MHLW and PMDA can use the audit report to reduce documents or exempt certain manufacturing sites from an on-site QMS inspection, subject to exceptions.

United States

FDA CDRH can accept an MDSAP report as a substitute for a routine inspection, while retaining other inspection powers.

Wider participation

Official observers and affiliate members may use or recognise MDSAP information in ways defined by their own systems.

Each authority remains sovereign and decides how it uses the output. Confirm current market-specific policy rather than assuming that the same certificate has the same effect everywhere.

04

The criteria combine ISO 13485 with jurisdictional requirements

The audit model starts with ISO 13485:2016 and adds the applicable requirements of the participating authorities. These additions cover matters such as registration, market authorisation, complaint and adverse-event reporting, advisory notices, records, distribution, recall and other national QMS obligations.

Create a controlled applicability matrix showing the markets supplied, legal entities, sites, device families, activities and requirements in scope. Link each applicable requirement to the process, procedure, responsible role and objective evidence that demonstrates conformity.

The US portion should be aligned with the current FDA Quality Management System Regulation and other applicable Title 21 requirements; MTL-320 — US FDA Medical-device Regulations — 21 CFR Overview provides the broader map.

05

The audit follows seven connected processes

ManagementGovernance, responsibility, resources, review and QMS planning
Market accessDevice authorisation and facility registration in each jurisdiction
ImprovementData, complaints, nonconformity, CAPA and internal audit
Regulatory reportingAdverse events and advisory notices reported when required
DesignControlled development, risk, verification, validation, transfer and change
Production and serviceControlled realisation, validation, release, servicing and records
PurchasingSupplier selection, controls and verification of purchased product

Management, Measurement, Analysis and Improvement, Design and Development, and Production and Service Controls are primary processes. Purchasing supports them, while market authorisation and regulatory reporting address specific jurisdictional obligations.

06

Management must demonstrate an effective system

Auditors look for more than a signed policy or completed management-review agenda. They follow how management establishes responsibilities, provides competent resources, sets measurable objectives, reviews performance, responds to regulatory change and maintains an effective QMS across the organisation.

  • Ensure the organisation, legal-manufacturer role and delegated responsibilities are clear.
  • Make management review a decision forum using current quality, regulatory and product evidence.
  • Show how resources and competence follow product and compliance risk.
  • Control significant organisational, product, process and supplier changes.
  • Demonstrate that unresolved issues are escalated and decisions are followed through.

Management should be able to explain the system in its own words. See MTL-202 — Medical-device Development for SME Management for practical organisational guidance.

07

Market authorisation and registration must match reality

The audit checks that devices are marketed only where the required authorisations, registrations, listings, licences or notifications are in place. Records should agree on device identity, classification, manufacturer, sites and authorised activities.

Maintain a market-access register that identifies the current status, approval scope, licence holder, establishment or facility obligations, change-reporting triggers and renewal dates for every jurisdiction. Reconcile it with labels, catalogues, distribution records and the certified QMS scope.

08

Improvement evidence begins with trustworthy data

The Measurement, Analysis and Improvement process connects complaints, feedback, nonconforming product, data analysis, internal audit and corrective action. Auditors use these sources to choose trails into design, production, suppliers and reporting.

  • Define consistent intake, coding, evaluation and escalation of quality data.
  • Investigate proportionately and identify systemic causes, not only immediate symptoms.
  • Use trends and risk to set CAPA priorities.
  • Verify implementation and effectiveness before closure.
  • Feed lessons into risk management, design, production, suppliers and management review.

A polished CAPA form cannot compensate for incomplete complaints, unreliable data or recurring ineffective actions.

09

Adverse-event and advisory-notice decisions must be timely

The organisation needs a controlled process to determine whether events, field actions, recalls or safety communications are reportable in each applicable jurisdiction. The decision clock starts from the relevant awareness point defined by the law—not when an investigation is convenient to complete.

Evidence should show event intake, awareness date, reportability assessment, rationale, submission, follow-up, regulator communication and linkage to complaint, risk, CAPA and field-action records. Staff who receive information through service, sales, clinical support or distributors must know how and when to escalate it.

10

Design evidence must form a traceable control system

Auditors can select a design project using risk and quality information, then follow its intended purpose, inputs, risk controls, outputs, reviews, verification, validation, transfer and changes. The evidence needs to represent the approved device configuration and show that unresolved matters were controlled.

Use MTL-104 — Design Controls and Technical Documentation for the connected evidence chain and MTL-106 — Verification and Validation for the distinction between confirming specified requirements and intended use.

11

Production and service controls must preserve conformity

The audit follows how approved design outputs become consistently conforming devices. Typical trails include process controls, work instructions, infrastructure, environmental controls, validation of processes whose output cannot be fully verified, identification, traceability, acceptance, release, installation, servicing and control of nonconforming product.

Records must identify what was made or serviced, to which approved configuration, using which equipment, materials and processes, by competent people, with what result and release decision.

12

Purchasing is audited through the processes it supports

Supplier control is not an isolated approved-supplier list. Auditors may start from a design control, production problem or complaint and trace it to supplier selection, defined requirements, change notification, incoming or other verification, performance monitoring and corrective action.

The manufacturer remains responsible for outsourced processes. The degree of control should reflect the effect of the supplied product or service on device safety, performance, conformity and continuity of supply.

13

Risk management and process linkages shape the audit trail

The Audit Approach is founded on risk-management principles. Auditors deliberately move between processes: a complaint can lead to risk analysis, design change, supplier controls, production records, regulatory reporting and management review.

A useful preparation test

Select one significant product issue and trace the complete organisational response. If the records tell different stories, use different identifiers or stop at departmental boundaries, the QMS is not functioning as one connected system.

MTL-302 — ISO 14971 Risk Management explains the standard framework, while MTL-105 — Medical-device Risk Management focuses on practical lifecycle implementation.

14

Certification operates through an audit cycle

Stage 1

Documentation review and readiness evaluation before progressing to the main certification audit.

Stage 2

Evaluation of effective implementation across applicable QMS and regulatory requirements.

Surveillance

Periodic audits sample defined processes and confirm continued conformity during the certification cycle.

Recertification

A broader re-audit supports renewal of certification at the end of the cycle.

Special audit

Additional audit activity may address significant changes, complaints, findings or other defined needs.

Delivery method

Depending on purpose and circumstances, activity may be on-site, off-site, remote, hybrid or a combination.

The AO determines the plan, competent audit team and duration using the prescribed method and the organisation's scope and activities.

15

Prepare evidence by process, product and jurisdiction

Auditors review documents, records, facilities and interviews, then sample evidence to determine whether requirements are effectively implemented. A document index helps, but staff must be able to retrieve the underlying records and explain how their work fits the process.

  • Confirm legal entities, sites, activities, devices and jurisdictions included in scope.
  • Use current organisation, process and product maps.
  • Reconcile registrations, licences, certificates, device lists and facility information.
  • Prepare recent examples spanning design, production, complaints, reporting, CAPA and suppliers.
  • Check that electronic systems provide complete, legible and controlled records.
  • Make translations and jurisdiction-specific evidence accessible where needed.
16

Nonconformities are graded from 1 to 5

MDSAP uses standard criteria and a common Nonconformity Grading and Exchange form. The grade communicates regulatory significance and affects the evidence and timing expected in the manufacturer's response. It is not simply a familiar “minor” or “major” label.

Every nonconformity requires a response. Current MDSAP manufacturer guidance recommends a remediation plan—including investigation, cause, corrections and corrective actions—within 15 calendar days of the audit end date. Evidence of implementation for grade 4 and 5 nonconformities is recommended within 30 calendar days.

A grade 5 finding, more than two grade 4 findings, a public-health threat, fraud or counterfeit product can trigger notification to the MDSAP authorities within five working days. Organisations should consult the current grading procedure and AO instructions rather than rely on remembered thresholds.

17

Outsourcing and multiple sites need deliberate control

Map every site and external party that performs design, manufacture, sterilisation, testing, storage, distribution, servicing, regulatory or other QMS activity. Define who owns each process, which records exist, how performance is monitored and how changes or problems are escalated.

A commercial contract does not transfer the manufacturer's regulatory responsibility. Critical suppliers and outsourced processes should be visible in risk management, purchasing controls, process validation, change control, complaint investigations and management review.

18

Prepare by exercising the system, not rehearsing answers

ScopeConfirm sites, products, activities, markets and current regulatory criteria
MapConnect requirements to processes, roles, procedures and records
SampleTest recent high-risk examples across the seven audit processes
ChallengeFollow audit trails across departmental and supplier boundaries
CorrectResolve gaps through the QMS with cause and effectiveness evidence
BriefPrepare staff to explain their real responsibilities and retrieve records

Use the current MDSAP Audit Approach as an internal-audit framework, but do not reduce readiness to a task-by-task checklist. The goal is effective, sustained conformity in the actual organisation.

19

Respond to findings as regulatory signals

At the closing meeting, confirm the requirement, evidence and scope of each finding. After the audit, investigate whether the observed example is isolated or systemic, contain immediate risk, determine cause, define corrections and corrective actions, assign accountable owners and verify effectiveness.

The AO prepares a standardised report and submits the audit package and nonconformity information to the secure Regulatory Exchange Platform, where participating authorities can access it for regulatory work. Responses should therefore be clear, factual and supported by controlled evidence.

20

Common misconceptions

“MDSAP is just a longer ISO 13485 audit.”

No. ISO 13485 is the foundation, but the audit also covers applicable participating-authority requirements through a prescribed regulatory audit model.

“One certificate approves products in five countries.”

No. Each authority retains its own market-authorisation decisions and uses MDSAP outputs according to its legislation and policy.

“The quality team can handle the audit.”

No. Audit trails reach management, design, production, suppliers, service, complaints, reporting and other operating functions.

“Passing the last audit proves continuing compliance.”

No. Certification depends on sustained implementation, surveillance and effective response to product, process and regulatory change.

“An outsourced process sits outside our QMS.”

No. The manufacturer must define and maintain controls proportionate to the outsourced process's effect on conformity.

“Every finding can wait for the next surveillance audit.”

No. All findings require response, and critical patterns can trigger rapid evidence expectations and regulatory notification.

21

Practical MDSAP readiness checklist

  • Select a recognised MDSAP Auditing Organization and agree an accurate certification scope.
  • Confirm every applicable jurisdiction, legal entity, site, device family and activity.
  • Use the current MDSAP Audit Approach and jurisdictional requirements.
  • Map the seven processes, their owners, interfaces and objective evidence.
  • Reconcile certificates, licences, registrations, device lists and facility records.
  • Test high-risk audit trails from quality data through risk, design, production and reporting.
  • Evaluate critical suppliers and outsourced processes as part of the connected QMS.
  • Complete an internal audit and management review using current performance evidence.
  • Train staff to explain real practice and retrieve controlled records promptly.
  • Prepare a disciplined process for containment, investigation, CAPA and graded response.
22

Authoritative references

MDSAP procedures and participating-authority requirements change. Confirm the current Audit Approach, forms, AO instructions and jurisdictional rules for the organisation's actual scope.