---
title: "Internal Audit, Definition | MedTech Terms"
description: "Planned, independent evaluation of QMS conformity and effectiveness. Plain-English Quality &amp; Risk definition for MedTech teams, with examples and related terms."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/internal-audit#term",
        "name": "Internal Audit",
        "description": "Internal audits per ISO 19011 evaluate whether the QMS conforms to planned arrangements, regulatory requirements, and the standard, and whether it is effectively implemented and maintained.",
        "url": "https://medtechterms.com/terms/internal-audit",
        "termCode": "internal-audit",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/internal-audit#article",
        "headline": "Internal Audit",
        "description": "Planned, independent evaluation of QMS conformity and effectiveness.",
        "url": "https://medtechterms.com/terms/internal-audit",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/internal-audit"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/internal-audit#term"
        },
        "articleSection": "Quality & Risk",
        "inLanguage": "en",
        "keywords": "Internal Audit, Quality & Risk, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "ISO 19011 Auditing Guidelines",
            "url": "https://www.iso.org/standard/70017.html",
            "publisher": {
              "@type": "Organization",
              "name": "ISO"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "MDIC Case for Quality",
            "url": "https://mdic.org/program/case-for-quality/",
            "publisher": {
              "@type": "Organization",
              "name": "MDIC"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "FDA - Quality Systems",
            "url": "https://www.fda.gov/medical-devices/postmarket-requirements-devices/quality-system-qs-regulationmedical-device-good-manufacturing-practices",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/iso-13485#term",
            "name": "ISO 13485",
            "url": "https://medtechterms.com/terms/iso-13485"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/management-review#term",
            "name": "Management Review",
            "url": "https://medtechterms.com/terms/management-review"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/capa#term",
            "name": "Corrective and Preventive Action",
            "alternateName": "CAPA",
            "url": "https://medtechterms.com/terms/capa"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Quality & Risk",
            "item": "https://medtechterms.com/terms?cat=Quality%20%26%20Risk"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Internal Audit",
            "item": "https://medtechterms.com/terms/internal-audit"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/internal-audit#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "How often should internal audits be conducted?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "The frequency of internal audits should be determined by a risk-based approach, considering the importance of the process, changes affecting the organization, and results of previous audits. ISO 13485:2016 requires a documented procedure for internal audits at planned intervals."
            }
          },
          {
            "@type": "Question",
            "name": "Who can perform an internal audit?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Internal audits should be performed by personnel independent of the activity being audited. These individuals must be competent, with appropriate training in auditing principles and the specific requirements being assessed."
            }
          },
          {
            "@type": "Question",
            "name": "What is the primary output of an internal audit?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "The primary output is an audit report detailing findings, including nonconformities, observations, and opportunities for improvement. These findings then feed into the corrective and preventive action (CAPA) process and management review."
            }
          },
          {
            "@type": "Question",
            "name": "How do internal audits differ from external audits?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Internal audits are conducted by or on behalf of the organization for internal purposes, such as confirming QMS effectiveness. External audits are conducted by third parties, like regulatory bodies or certification bodies, to assess compliance with regulations or standards for certification or market access."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Quality & Risk](/terms?cat=Quality%20%26%20Risk)
6.  /
7.  Internal Audit

[All terms](/terms)

Quality & Risk [Quality System](/ecosystems/quality-system)[Startup Lifecycle](/ecosystems/startup-lifecycle)

# Internal Audit

Planned, independent evaluation of QMS conformity and effectiveness.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

Internal audits per ISO 19011 evaluate whether the QMS conforms to planned arrangements, regulatory requirements, and the standard, and whether it is effectively implemented and maintained. 

What the regulation says

The FDA expects internal audits as part of a robust Quality System, as outlined implicitly in 21 CFR Part 820,  [Quality System Regulation](/terms/qsr). Similarly,  [ISO 13485](/terms/iso-13485):2016, clause 8.2.4, explicitly mandates internal audits to determine if the quality management system conforms to planned arrangements and the requirements of the standard itself, as well as being effectively implemented and maintained. The  [EU Medical Device Regulation](/terms/mdr) (EU  [MDR](/terms/mdr-reporting) 2017/745) Annex IX, Chapter I, Section 2.2, also requires manufacturers to establish and maintain an internal audit system as part of their quality management system. 

## What this means in practice

Auditors must be independent of the activity audited. Findings feed  [CAPA](/terms/capa) and  [management review](/terms/management-review).  [ISO 13485](/terms/iso-13485) requires a documented program covering all processes on a risk basis. 

## Examples

-   A MedTech company audits its software development process annually due to its high risk classification and frequent updates, checking adherence to IEC 62304.
-   An internal auditor reviews the sterilization records for a Class III implantable device, verifying compliance with validated cycles and ISO 11135.
-   During an internal audit, a manufacturer identifies that their supplier qualification process does not fully align with their updated purchasing procedures, leading to a corrective action.

Common pitfalls

-   • Failing to establish a risk-based internal audit program can lead to inadequate coverage of critical processes. 
-   • Using personnel to audit their own work compromises auditor independence and the objectivity of audit findings. 
-   • Treating internal audits solely as a compliance check rather than an opportunity for continuous improvement is a common pitfall. 
-   • Inadequate documentation of audit plans, findings, and follow-up actions can result in non-compliance during external inspections. 
-   • Not linking internal audit findings to the CAPA process diminishes their effectiveness in driving corrective actions and improvements. 

## Frequently asked questions

How often should internal audits be conducted? 

The frequency of internal audits should be determined by a risk-based approach, considering the importance of the process, changes affecting the organization, and results of previous audits.  [ISO 13485](/terms/iso-13485):2016 requires a documented procedure for internal audits at planned intervals. 

Who can perform an internal audit? 

What is the primary output of an internal audit? 

How do internal audits differ from external audits? 

## Cross-references

### Precedes

Comes before in a typical workflow or lifecycle.

-   [
    
    Management Review
    
    
    
    ](/terms/management-review)

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Quality & Risk

Corrective and Preventive Action(CAPA) 

Systematic process to investigate and resolve quality issues and prevent recurrence.





](/terms/capa)[

Quality & Risk

Management Review

Top-management evaluation of QMS performance at planned intervals.





](/terms/management-review)[

Standards

ISO 13485

International standard for medical device quality management systems.





](/terms/iso-13485)

### More in Quality & Risk

· Same category 

[

Quality & Risk

Biocompatibility

Ability of a material to perform with an appropriate host response in a specific application.





](/terms/biocompatibility)[

Quality & Risk

CAPA Effectiveness Check

Verification step confirming a corrective or preventive action actually fixed the problem.





](/terms/capa-effectiveness)[

Quality & Risk

Change Control

Formal QMS process for evaluating, approving, and implementing changes that could affect product quality or compliance.





](/terms/change-control)[

Quality & Risk

Complaint Handling

Process for receiving, evaluating, and responding to device complaints.





](/terms/complaint-handling)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (2)

-   [Quality System](/ecosystems/quality-system)
-   [Startup Lifecycle](/ecosystems/startup-lifecycle)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

ISO· 1 MDIC· 1 FDA· 1 

1.  [1 
    
    ISO 19011 Auditing Guidelines
    
    Verified 
    
    ISO · iso.org 
    
    
    
    ](https://www.iso.org/standard/70017.html)
2.  [2 
    
    MDIC Case for Quality
    
    Verified 
    
    MDIC · mdic.org 
    
    
    
    ](https://mdic.org/program/case-for-quality/)
3.  [3 
    
    FDA - Quality Systems
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/medical-devices/postmarket-requirements-devices/quality-system-qs-regulationmedical-device-good-manufacturing-practices)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Tying cybersecurity into your QMS?

We help align cybersecurity activities with ISO 13485 design controls and ISO 14971 risk management.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Quality & Risk

Sources

3

Updated

5/5/2026

[Compare with another term](/compare?a=internal-audit)

Learn in 60 seconds

Card Lesson Quiz

Planned, independent evaluation of QMS conformity and effectiveness.

-   · Auditors must be independent of the activity audited. 
-   · Findings feed CAPA and management review. 
-   · ISO 13485 requires a documented program covering all processes on a risk basis. 

Remember this

Watch out: Failing to establish a risk-based internal audit program can lead to inadequate coverage of critical processes.

Related terms

-   [ISO 13485 ](/terms/iso-13485)
-   [Management Review ](/terms/management-review)
-   [Corrective and Preventive Action(CAPA) ](/terms/capa)

You may also need

Auto-suggested from Quality & Risk and shared keywords.

-   [CAPA Effectiveness Check ](/terms/capa-effectiveness)
-   [Medical Device Single Audit Program(MDSAP) ](/terms/mdsap)
-   [Production and Process Controls ](/terms/production-process-controls)
-   [Summative vs. Formative Evaluation ](/terms/summative-formative)
-   [Premarket Approval(PMA) ](/terms/pma)
-   [513(g) Request for Information(513(g)) ](/terms/513g)

[All Quality & Risk terms](/terms?cat=Quality%20%26%20Risk)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Truths 
    
    Common misconceptions about medical device development - debunked.
    
    ](https://mdcmisconceptions.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)