Free quality-system tool · No signup

ISO 13485 Audit Checklist & Readiness Assessment

Review the operating evidence behind your medical device quality system—not just whether a procedure exists. Mark each area, record where evidence lives, and turn the result into an internal audit worklist.

Browser-only workfileObjective-evidence promptsDownloadable gap summary

Review operating evidence

Check whether processes are implemented, not merely documented.

Keep information private

Inputs stay locally in your browser and never call an API.

Use current criteria

Verify findings against licensed and official source materials.

Start a readiness assessment

Assess implementation and objective evidence for each area. Your notes stay in this browser and are never sent to an API.

DJ Fang
DJ Fang
MedTech Regulatory Expert

Need help confirming a classification or planning your registration?

Pricing
Reviewed
0 / 15
Ready
0
Partial
0
Gaps
0
01 · QMS scope and documentationCore

Is the QMS scope defined, including sites, products, outsourced processes, applicable regulatory roles, justified exclusions, and interactions between processes?

Evidence to sample: Quality manual, scope statement, site/process map, regulatory-role matrix, exclusion rationale.

02 · Document and record controlCore

Are current documents approved and available where used, while obsolete versions, external documents, changes, retention, integrity, and confidential records are controlled?

Evidence to sample: Document master list, approval history, change records, retention matrix, access controls, sampled records.

03 · Management responsibilityCore

Can leadership show quality-policy deployment, measurable objectives, assigned authority, adequate resources, management reviews, and follow-up of decisions?

Evidence to sample: Objectives/KPIs, organization chart, management-review inputs and outputs, action tracking, resource decisions.

04 · Regulatory requirementsHigh

Does the organization identify and operationalize applicable market requirements throughout product realization and post-market activities?

Evidence to sample: Regulatory matrix, market approvals, standards list, change-assessment process, reporting and retention requirements.

05 · Risk-based controlsCore

Are risk-based methods used across QMS processes and linked to product risk management, changes, complaints, nonconformities, and CAPA?

Evidence to sample: Risk-management procedure/file, process-risk criteria, change records, complaint/CAPA links, risk acceptability decisions.

06 · Design and developmentHigh

Where design controls apply, are plans, inputs, outputs, reviews, verification, validation, transfer, changes, and design history complete and traceable?

Evidence to sample: Design plan, trace matrix, review minutes, V&V protocols/reports, transfer checklist, change history, design file.

07 · Purchasing and supplier controlCore

Are suppliers selected, monitored, re-evaluated, and controlled according to product/process risk, with purchasing requirements and change notification clearly defined?

Evidence to sample: Approved supplier list, evaluations, quality agreements, scorecards, audit reports, purchasing specifications, incoming controls.

08 · Production and service provisionCore

Are production instructions, infrastructure, environmental conditions, cleanliness, identification, status, preservation, servicing, and release controls implemented and recorded?

Evidence to sample: Travelers/batch records, work instructions, environmental logs, acceptance records, release authorization, service records.

09 · Process and software validationHigh

Are processes whose outputs cannot be fully verified—and QMS software affecting product quality—validated before use and after relevant changes?

Evidence to sample: Validation master plan, IQ/OQ/PQ or equivalent evidence, software validation, acceptance criteria, revalidation decisions.

10 · Sterile-device controlsHigh

If sterile devices are in scope, are contamination controls, sterilization validation, routine monitoring, sterile-barrier integrity, and batch traceability adequate?

Evidence to sample: Bioburden/cleanroom controls, sterilization validation, cycle records, packaging validation, release records, traceability.

11 · Monitoring and measuring resourcesCore

Are inspection and measuring resources suitable, calibrated or verified, protected, traceable, and assessed when found out of tolerance?

Evidence to sample: Equipment register, calibration certificates, status labels, traceability, out-of-tolerance impact assessments.

12 · Feedback, complaints and regulatory reportingCore

Are feedback and complaints captured, investigated, trended, linked to risk/CAPA, and assessed promptly for reportability in each market?

Evidence to sample: Complaint files, investigation rationale, trend reports, vigilance decisions/submissions, feedback inputs, escalation records.

13 · Nonconforming product and reworkCore

Are nonconformities identified, segregated, evaluated, dispositioned by authorized personnel, and controlled after delivery or rework?

Evidence to sample: NCRs, concessions, segregation/status controls, rework instructions, re-verification, post-delivery actions.

14 · CAPA and improvementCore

Do correction, root-cause analysis, action planning, implementation, effectiveness checks, and risk review match the significance and recurrence of the issue?

Evidence to sample: CAPA files, root-cause evidence, implementation records, effectiveness criteria/results, risk-file updates, trend data.

15 · Internal auditsCore

Does the audit program cover the full QMS based on status and importance, use independent auditors, document objective evidence, and verify timely correction?

Evidence to sample: Risk-based audit schedule, auditor competence/independence, reports, findings, corrections, follow-up and closure evidence.

Download the working gap list

The score summarizes reviewed items only. It is not an audit grade or certification prediction.

Turn checklist answers into audit evidence

Sample records across products, sites, shifts, and time periods. Look for consistent execution, traceability between connected processes, competent decision makers, and evidence that actions were effective.

Use every partial or gap result as a work item with an owner, target date, containment where needed, root-cause depth proportionate to risk, and an effectiveness check. Revisit the assessment after changes are implemented.

Review ISO 13485:2016 overview

Frequently asked questions

Is this an official ISO 13485 checklist?

No. It is an independent readiness tool with paraphrased process prompts. It does not reproduce the standard and does not replace a licensed copy of ISO 13485 or certification-body criteria.

Can this checklist certify an ISO 13485 QMS?

No. Certification can only be issued through the applicable accredited certification process. This tool helps organize an internal gap assessment.

Should every question be marked ready before an audit?

Applicable areas should have implemented, consistent, and objective evidence. A documented procedure alone may not demonstrate effective implementation.

Where is my assessment data stored?

Your selections and notes are stored only in this browser. They are not uploaded to Pure Global AI. Download the summary if you need a portable worklist.