What you will learn
By the end of this topic, you should be able to explain what MDSAP does, identify the seven audit processes and their connections, determine which jurisdictional requirements belong in the audit scope, organise objective evidence around real processes, and prepare a proportionate response to audit findings.
One audit, several regulatory purposes
MDSAP allows a recognised Auditing Organization (AO) to conduct a single regulatory audit of a medical-device manufacturer's quality management system. The audit is designed to satisfy the relevant requirements of the regulatory authorities participating in the programme.
MDSAP does not replace each jurisdiction's law with one universal rulebook. It applies a common audit method to ISO 13485 and the applicable regulatory requirements of the markets included in the manufacturer's scope.
The value is regulatory reliance: authorities can use a consistent report and certificate rather than independently repeating the same routine QMS audit work.
Understand what MDSAP does not do
An MDSAP certificate is evidence about the audited QMS, sites, activities, devices and regulatory criteria shown on the certificate. It is not product approval, market authorisation or proof that every individual device conforms.
- It does not remove the manufacturer's legal responsibility for its products and QMS.
- It does not make the participating jurisdictions' requirements identical.
- It does not prevent a regulator from requesting information or conducting an inspection when necessary.
- It does not automatically cover activities, sites, product families or jurisdictions outside the certified scope.
- It does not necessarily replace special, for-cause, pre-approval or combination-product inspections.
Use MTL-301 — ISO 13485 and Design Controls to understand the QMS foundation and MTL-320 — US FDA Medical-device Regulations — 21 CFR Overview for the wider US regulatory context.
The criteria combine ISO 13485 with jurisdictional requirements
The audit model starts with ISO 13485:2016 and adds the applicable requirements of the participating authorities. These additions cover matters such as registration, market authorisation, complaint and adverse-event reporting, advisory notices, records, distribution, recall and other national QMS obligations.
Create a controlled applicability matrix showing the markets supplied, legal entities, sites, device families, activities and requirements in scope. Link each applicable requirement to the process, procedure, responsible role and objective evidence that demonstrates conformity.
The US portion should be aligned with the current FDA Quality Management System Regulation and other applicable Title 21 requirements; MTL-320 — US FDA Medical-device Regulations — 21 CFR Overview provides the broader map.
The audit follows seven connected processes
Management, Measurement, Analysis and Improvement, Design and Development, and Production and Service Controls are primary processes. Purchasing supports them, while market authorisation and regulatory reporting address specific jurisdictional obligations.
Management must demonstrate an effective system
Auditors look for more than a signed policy or completed management-review agenda. They follow how management establishes responsibilities, provides competent resources, sets measurable objectives, reviews performance, responds to regulatory change and maintains an effective QMS across the organisation.
- Ensure the organisation, legal-manufacturer role and delegated responsibilities are clear.
- Make management review a decision forum using current quality, regulatory and product evidence.
- Show how resources and competence follow product and compliance risk.
- Control significant organisational, product, process and supplier changes.
- Demonstrate that unresolved issues are escalated and decisions are followed through.
Management should be able to explain the system in its own words. See MTL-202 — Medical-device Development for SME Management for practical organisational guidance.
Improvement evidence begins with trustworthy data
The Measurement, Analysis and Improvement process connects complaints, feedback, nonconforming product, data analysis, internal audit and corrective action. Auditors use these sources to choose trails into design, production, suppliers and reporting.
- Define consistent intake, coding, evaluation and escalation of quality data.
- Investigate proportionately and identify systemic causes, not only immediate symptoms.
- Use trends and risk to set CAPA priorities.
- Verify implementation and effectiveness before closure.
- Feed lessons into risk management, design, production, suppliers and management review.
A polished CAPA form cannot compensate for incomplete complaints, unreliable data or recurring ineffective actions.
Adverse-event and advisory-notice decisions must be timely
The organisation needs a controlled process to determine whether events, field actions, recalls or safety communications are reportable in each applicable jurisdiction. The decision clock starts from the relevant awareness point defined by the law—not when an investigation is convenient to complete.
Evidence should show event intake, awareness date, reportability assessment, rationale, submission, follow-up, regulator communication and linkage to complaint, risk, CAPA and field-action records. Staff who receive information through service, sales, clinical support or distributors must know how and when to escalate it.
Design evidence must form a traceable control system
Auditors can select a design project using risk and quality information, then follow its intended purpose, inputs, risk controls, outputs, reviews, verification, validation, transfer and changes. The evidence needs to represent the approved device configuration and show that unresolved matters were controlled.
Use MTL-104 — Design Controls and Technical Documentation for the connected evidence chain and MTL-106 — Verification and Validation for the distinction between confirming specified requirements and intended use.
Production and service controls must preserve conformity
The audit follows how approved design outputs become consistently conforming devices. Typical trails include process controls, work instructions, infrastructure, environmental controls, validation of processes whose output cannot be fully verified, identification, traceability, acceptance, release, installation, servicing and control of nonconforming product.
Records must identify what was made or serviced, to which approved configuration, using which equipment, materials and processes, by competent people, with what result and release decision.
Purchasing is audited through the processes it supports
Supplier control is not an isolated approved-supplier list. Auditors may start from a design control, production problem or complaint and trace it to supplier selection, defined requirements, change notification, incoming or other verification, performance monitoring and corrective action.
The manufacturer remains responsible for outsourced processes. The degree of control should reflect the effect of the supplied product or service on device safety, performance, conformity and continuity of supply.
Risk management and process linkages shape the audit trail
The Audit Approach is founded on risk-management principles. Auditors deliberately move between processes: a complaint can lead to risk analysis, design change, supplier controls, production records, regulatory reporting and management review.
Select one significant product issue and trace the complete organisational response. If the records tell different stories, use different identifiers or stop at departmental boundaries, the QMS is not functioning as one connected system.
MTL-302 — ISO 14971 Risk Management explains the standard framework, while MTL-105 — Medical-device Risk Management focuses on practical lifecycle implementation.
Certification operates through an audit cycle
Stage 1
Documentation review and readiness evaluation before progressing to the main certification audit.
Stage 2
Evaluation of effective implementation across applicable QMS and regulatory requirements.
Surveillance
Periodic audits sample defined processes and confirm continued conformity during the certification cycle.
Recertification
A broader re-audit supports renewal of certification at the end of the cycle.
Special audit
Additional audit activity may address significant changes, complaints, findings or other defined needs.
Delivery method
Depending on purpose and circumstances, activity may be on-site, off-site, remote, hybrid or a combination.
The AO determines the plan, competent audit team and duration using the prescribed method and the organisation's scope and activities.
Prepare evidence by process, product and jurisdiction
Auditors review documents, records, facilities and interviews, then sample evidence to determine whether requirements are effectively implemented. A document index helps, but staff must be able to retrieve the underlying records and explain how their work fits the process.
- Confirm legal entities, sites, activities, devices and jurisdictions included in scope.
- Use current organisation, process and product maps.
- Reconcile registrations, licences, certificates, device lists and facility information.
- Prepare recent examples spanning design, production, complaints, reporting, CAPA and suppliers.
- Check that electronic systems provide complete, legible and controlled records.
- Make translations and jurisdiction-specific evidence accessible where needed.
Nonconformities are graded from 1 to 5
MDSAP uses standard criteria and a common Nonconformity Grading and Exchange form. The grade communicates regulatory significance and affects the evidence and timing expected in the manufacturer's response. It is not simply a familiar “minor” or “major” label.
Every nonconformity requires a response. Current MDSAP manufacturer guidance recommends a remediation plan—including investigation, cause, corrections and corrective actions—within 15 calendar days of the audit end date. Evidence of implementation for grade 4 and 5 nonconformities is recommended within 30 calendar days.
A grade 5 finding, more than two grade 4 findings, a public-health threat, fraud or counterfeit product can trigger notification to the MDSAP authorities within five working days. Organisations should consult the current grading procedure and AO instructions rather than rely on remembered thresholds.
Outsourcing and multiple sites need deliberate control
Map every site and external party that performs design, manufacture, sterilisation, testing, storage, distribution, servicing, regulatory or other QMS activity. Define who owns each process, which records exist, how performance is monitored and how changes or problems are escalated.
A commercial contract does not transfer the manufacturer's regulatory responsibility. Critical suppliers and outsourced processes should be visible in risk management, purchasing controls, process validation, change control, complaint investigations and management review.
Prepare by exercising the system, not rehearsing answers
Use the current MDSAP Audit Approach as an internal-audit framework, but do not reduce readiness to a task-by-task checklist. The goal is effective, sustained conformity in the actual organisation.
Respond to findings as regulatory signals
At the closing meeting, confirm the requirement, evidence and scope of each finding. After the audit, investigate whether the observed example is isolated or systemic, contain immediate risk, determine cause, define corrections and corrective actions, assign accountable owners and verify effectiveness.
The AO prepares a standardised report and submits the audit package and nonconformity information to the secure Regulatory Exchange Platform, where participating authorities can access it for regulatory work. Responses should therefore be clear, factual and supported by controlled evidence.
Common misconceptions
“MDSAP is just a longer ISO 13485 audit.”
No. ISO 13485 is the foundation, but the audit also covers applicable participating-authority requirements through a prescribed regulatory audit model.
“One certificate approves products in five countries.”
No. Each authority retains its own market-authorisation decisions and uses MDSAP outputs according to its legislation and policy.
“The quality team can handle the audit.”
No. Audit trails reach management, design, production, suppliers, service, complaints, reporting and other operating functions.
“Passing the last audit proves continuing compliance.”
No. Certification depends on sustained implementation, surveillance and effective response to product, process and regulatory change.
“An outsourced process sits outside our QMS.”
No. The manufacturer must define and maintain controls proportionate to the outsourced process's effect on conformity.
“Every finding can wait for the next surveillance audit.”
No. All findings require response, and critical patterns can trigger rapid evidence expectations and regulatory notification.
Practical MDSAP readiness checklist
- Select a recognised MDSAP Auditing Organization and agree an accurate certification scope.
- Confirm every applicable jurisdiction, legal entity, site, device family and activity.
- Use the current MDSAP Audit Approach and jurisdictional requirements.
- Map the seven processes, their owners, interfaces and objective evidence.
- Reconcile certificates, licences, registrations, device lists and facility records.
- Test high-risk audit trails from quality data through risk, design, production and reporting.
- Evaluate critical suppliers and outsourced processes as part of the connected QMS.
- Complete an internal audit and management review using current performance evidence.
- Train staff to explain real practice and retrieve controlled records promptly.
- Prepare a disciplined process for containment, investigation, CAPA and graded response.
Authoritative references
- MDSAP — What is MDSAP?
- MDSAP — Audit Approach overview
- MDSAP AU P0002.011 — Current Audit Approach
- MDSAP — Benefits and use by participating authorities
- MDSAP — What to expect at an initial audit
- MDSAP AU P0008 — Audit Time Determination Procedure
- MDSAP AU P0019 — Medical Device Regulatory Audit Reports Policy and forms
- US FDA — Medical Device Single Audit Program
MDSAP procedures and participating-authority requirements change. Confirm the current Audit Approach, forms, AO instructions and jurisdictional rules for the organisation's actual scope.