Audits that find problems. CAPAs that fix them.
Internal audits are the primary mechanism for identifying QMS gaps before regulators do. CAPA is how you demonstrate systemic correction. We run rigorous audits, write defensible CAPAs, and help you build the internal audit programme to sustain it.
ISO 13485:2016 Clause 8.2.4 requires a documented internal audit programme covering all processes within the QMS scope. Audits must be conducted by personnel independent of the activity being audited, using documented procedures and checklists. Audit findings must be recorded, NCRs raised where required, and CAPAs opened for systemic issues. The programme must ensure that all areas of the QMS are audited at planned intervals, with frequency reflecting risk.
We design and conduct internal audit programmes for manufacturers who lack the internal resource or independence to audit effectively. Our audit team uses process-based audit methodology — following the product lifecycle through your QMS rather than checking clauses in sequence — which finds real operational gaps rather than documentation inconsistencies. Every audit produces a formal report with findings graded by severity, root cause analysis where indicated, and a recommended CAPA.
For ongoing programmes, we provide a trained lead auditor on a scheduled basis, typically quarterly or semi-annually, covering different process areas to the planned audit schedule. We also train your internal auditors and can co-audit with your team to develop their audit skills alongside completing the audit requirement.
Annual audit schedule, process coverage map, audit procedure, and NCR/CAPA linkage process designed to meet ISO 13485 Clause 8.2.4 requirements.
Full internal audit conducted against your QMS scope, using process-based methodology, with a formal report, NCR log, and severity-graded findings.
Formal audit report with executive summary, process findings by area, NCRs raised, observations, and recommended corrective actions with priority ranking.
Practical training for your internal auditors covering audit planning, evidence gathering, interview technique, findings classification, and report writing.
ISO 13485:2016 Clause 7.4 requires evaluation and selection of suppliers based on their ability to meet requirements, with the extent of supplier controls proportionate to the risk of the supplied product or service to device safety and performance. Critical suppliers — those providing components incorporated into the device, sterilisation services, or critical testing — should be audited at a frequency reflecting their risk profile and performance history.
We conduct supplier audits for medical device manufacturers who lack the regulatory expertise or travel capacity to assess suppliers independently. Our supplier audits assess quality management system effectiveness, process control, calibration and measurement, and compliance with applicable standards — not just the presence of an ISO 9001 or 13485 certificate. A certificate tells you a system was audited once; our audit tells you whether it is working today.
On-site or remote audit of new critical suppliers against your quality requirements, with a formal audit report and approval recommendation.
Scheduled surveillance audit of approved critical suppliers, verifying continued conformity and any changes since approval.
Documented procedure for supplier qualification and surveillance auditing, meeting ISO 13485 Clause 7.4 requirements, for your QMS.
A well-written CAPA is the difference between closing an audit finding and re-opening it at the next audit. Regulators and certification bodies look for four things: that the immediate problem was contained (correction), that the root cause was correctly identified, that the root cause was eliminated (corrective action), and that the effectiveness of the corrective action was verified before closing. Generic CAPAs that say "procedure updated and staff retrained" without demonstrating root cause analysis consistently fail effectiveness checks.
We write CAPAs for your most significant audit findings and regulatory observations, using formal root cause analysis tools (5-Why, Ishikawa, fault tree) where the depth of analysis is proportionate to the severity of the finding. For systemic CAPA programmes, we set up the CAPA log, effectiveness review process, and trend analysis that turns individual CAPAs into QMS improvement data.
Root cause analysis and CAPA document for individual findings, using formal RCA tools and written to satisfy regulatory reviewer expectations.
CAPA log, effectiveness review schedule, and trending procedure to manage your complete corrective and preventive action programme per Clause 8.5.2.
Documented effectiveness check protocol and verification record for closed CAPAs, with escalation criteria if the corrective action has not worked.
Ready to move forward?
Tell us what triggered your audit need — certification preparation, a regulatory observation, or a recurring quality problem. We will scope the right audit approach.
Start a Project →