MedTech Terms
    The authoritative reference
    All terms

    Internal Audit

    Planned, independent evaluation of QMS conformity and effectiveness.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    Internal audits per ISO 19011 evaluate whether the QMS conforms to planned arrangements, regulatory requirements, and the standard, and whether it is effectively implemented and maintained.
    What the regulation says
    The FDA expects internal audits as part of a robust Quality System, as outlined implicitly in 21 CFR Part 820, Quality System Regulation. Similarly, ISO 13485:2016, clause 8.2.4, explicitly mandates internal audits to determine if the quality management system conforms to planned arrangements and the requirements of the standard itself, as well as being effectively implemented and maintained. The EU Medical Device Regulation (EU MDR 2017/745) Annex IX, Chapter I, Section 2.2, also requires manufacturers to establish and maintain an internal audit system as part of their quality management system.

    What this means in practice

    Auditors must be independent of the activity audited. Findings feed CAPA and management review. ISO 13485 requires a documented program covering all processes on a risk basis.

    Examples

    • A MedTech company audits its software development process annually due to its high risk classification and frequent updates, checking adherence to IEC 62304.
    • An internal auditor reviews the sterilization records for a Class III implantable device, verifying compliance with validated cycles and ISO 11135.
    • During an internal audit, a manufacturer identifies that their supplier qualification process does not fully align with their updated purchasing procedures, leading to a corrective action.
    Common pitfalls
    • Failing to establish a risk-based internal audit program can lead to inadequate coverage of critical processes.
    • Using personnel to audit their own work compromises auditor independence and the objectivity of audit findings.
    • Treating internal audits solely as a compliance check rather than an opportunity for continuous improvement is a common pitfall.
    • Inadequate documentation of audit plans, findings, and follow-up actions can result in non-compliance during external inspections.
    • Not linking internal audit findings to the CAPA process diminishes their effectiveness in driving corrective actions and improvements.

    Frequently asked questions

    The frequency of internal audits should be determined by a risk-based approach, considering the importance of the process, changes affecting the organization, and results of previous audits. ISO 13485:2016 requires a documented procedure for internal audits at planned intervals.

    Cross-references

    Precedes

    Comes before in a typical workflow or lifecycle.

    Grouped by theme

    Primary references

    3 sources
    Link health: 3 verified· last checked 2026-06-20
    ISO·1MDIC·1FDA·1
    1. 1
      ISO 19011 Auditing Guidelines
      Verified
      ISOiso.org
    2. 2
      MDIC Case for Quality
      Verified
      MDICmdic.org
    3. 3
      FDA - Quality Systems
      Verified
      FDAfda.gov

    Inline markers like [1] jump to the matching reference above.