MedTech Terms
    The authoritative reference
    All terms
    Quality & RiskQuality SystemGlobal MarketsMDSAP

    Medical Device Single Audit Program

    Single audit of a manufacturer's QMS satisfying multiple participating regulators.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    MDSAP allows a single regulatory audit of a medical device manufacturer's QMS that satisfies the requirements of multiple participating regulatory authorities, including the U.S. FDA, Health Canada, ANVISA, TGA, and PMDA.
    What the regulation says
    The Medical Device Single Audit Program (MDSAP) is a program allowing a single audit of a medical device manufacturer’s quality management system (QMS) to satisfy the regulatory requirements of multiple participating authorities. The U.S. FDA accepts MDSAP audit reports as a substitute for routine surveillance inspections, as noted in their guidance documents. Health Canada mandates MDSAP certification for medical device licensing, as specified in their Medical Devices Regulations (SOR/98-282), Section 43.1. Other participating regulatory authorities include Brazil’s ANVISA, Australia’s TGA, and Japan’s PMDA, all of whom utilize MDSAP audit outcomes for their regulatory oversight.

    What this means in practice

    MDSAP was developed by IMDRF and operationalized by the five participating regulators: US FDA, Health Canada, Brazil ANVISA, Australia TGA, and Japan MHLW/PMDA. Health Canada requires MDSAP for medical device licensure (mandatory since 2019). FDA accepts MDSAP audit reports in lieu of routine surveillance inspections (though for-cause and pre-approval inspections still occur). Audits are conducted by MDSAP-authorized Auditing Organizations against ISO 13485:2016 plus country-specific requirements documented in the MDSAP Audit Model. Audit duration is calculated from a formula in the MDSAP Companion Document based on employee count and site complexity.

    Examples

    • A mid-size Class II manufacturer replacing separate FDA, Health Canada, and TGA audits with a single MDSAP audit cycle, saving roughly 15 audit-days per year.
    • A contract manufacturer maintaining MDSAP certification to demonstrate to customers that its QMS satisfies five major regulators without additional audits.
    Common pitfalls
    • Assuming MDSAP replaces all FDA inspections. Pre-approval, for-cause, and Bioresearch Monitoring inspections are outside the MDSAP scope.
    • Under-scoping. MDSAP scope must cover all sites and processes relevant to devices marketed in participating countries; missed scope triggers gaps at surveillance audits.
    • Poor preparation for country-specific requirements. Each regulator layers requirements (e.g. Brazil GMP, Japan JPAL) on top of ISO 13485 that are frequently missed.
    • Treating the initial certification audit as a one-off. MDSAP requires annual surveillance audits and a three-year recertification cycle with sample-based coverage.

    Frequently asked questions

    The five regulatory authorities are the US FDA, Health Canada, Brazil ANVISA, Australia TGA, and Japan MHLW/PMDA. WHO Prequalification and EU Notified Bodies participate as observers but are not full members.

    Cross-references

    Grouped by theme

    Primary references

    3 sources
    Link health: 2 verified 1 unchecked· last checked 2026-06-20
    FDA·2MDIC·1
    1. 1
      FDA MDSAP
      Verified
      FDAfda.gov
    2. 2
      MDSAP Audit Approach & Companion Document
      Unchecked
      FDAfda.gov
    3. 3
      MDIC Case for Quality
      Verified
      MDICmdic.org

    Inline markers like [1] jump to the matching reference above.