Everything You Should Know About Internal Audits: Requirements, Methods, and Benefits
Internal audits are often viewed as a simple formal requirement dictated by standards, but they go beyond mere compliance. A thorough internal audit helps pinpoint discrepancies, enhance the quality management system (QMS), and prepare for external audits, particularly those conducted by notified bodies under the MDR 2017/745 regulation.
ISO 13485:2016
ISO 13485:2016 is the international standard that defines the requirements for a quality management system for medical devices. It mandates that manufacturers perform regular internal audits to ensure their QMS meets regulatory and operational standards.
Article 8.2.4 of ISO 13485:2016 states that :
- The organization must conduct internal audits at planned intervals to verify the QMS’s compliance with regulatory and internal requirements.
- These audits must be documented, and corrective actions must be taken in case of non-conformities.
- The goal is to ensure continuous improvement and maintain the robustness of the QMS.
How often should an internal audit be conducted?
ISO 13485:2016 does not specify a particular frequency but requires internal audits to be conducted at planned intervals. The frequency depends on several factors:
- The maturity of the quality system
- The risk level of the medical device
- The results of previous audits
Generally, companies conduct an annual internal audit but may adjust the frequency based on their level of compliance and process control.
Internal audit: a constraint or an opportunity?
Although ISO 13485:2016 mandates internal audits, they should be seen as a true opportunity to:
- Identify and correct gaps before an official audit
- Strengthen internal processes
- Raise team awareness of quality best practices
- Facilitate obtaining and maintaining CE marking
How to conduct an effective internal audit?
An effective internal audit involves several key steps:
- Audit Planning
- Define the objectives, scope, and audit criteria.
- Create an annual audit schedule.
- Choose the auditor (note: an individual cannot audit their own process to maintain objectivity).
- Audit Execution
- Gather evidence (documents, interviews, on-site observations).
- Check the compliance of procedures with normative and regulatory requirements.
- Identify discrepancies and areas for improvement.
- Audit Report Writing
- Summarize findings (both compliant and non-compliant points).
- Provide improvement recommendations.
- Outline a corrective action plan.
- Corrective Action Implementation
- Develop and track action plans.
- Assess the effectiveness of corrective actions.
- Integrate insights into the QMS for continuous improvement.
Why is a well-conducted internal audit a strategic asset?
An internal audit should not be seen as a burden but as a performance lever. Some of its tangible benefits include:
- Better anticipation of certification audits,
- Reduced risk of non-compliance,
- Optimization of internal processes,
- Strengthened quality culture within the company.
Who can perform the internal audit?
- A trained internal auditor: they must be independent of the audited process to ensure objectivity and impartiality.
- An external auditor: to provide a neutral perspective and expert insight into current practices.
Why hire a qualified external auditor? An external, impartial perspective adds significant value. A certified auditor has the expertise to:
- Identify gaps that may be invisible internally,
- Support compliance and continuous improvement efforts,
- Provide concrete, actionable recommendations.
Need support for your internal audits? Contact us to discuss: https://arqe-cst.com/en/contactus/