
Qms Audit Expert
- 752 installs
- 23.5k repo stars
- Updated July 17, 2026
- alirezarezvani/claude-skills
qms-audit-expert is a Claude skill playbook that guides developers and quality engineers through ISO 13485:2016 Clause 8.2.4 internal audits aligned with MDR and FDA QSR expectations for medical-device quality management
About
qms-audit-expert is a structured ISO 13485:2016 internal audit playbook from alirezarezvani/claude-skills for medical-device teams preparing certification, surveillance, or post-CAPA verification audits. The skill answers how to conduct Clause 8.2.4 audits that satisfy certification-body expectations and supports MDR and FDA QSR alignment. It pairs with bundled scripts including audit_schedule_optimizer.py for cadence planning and references compliance-os audit_simulator.py for mock-audit preparation. Developers and QMS owners reach for qms-audit-expert during annual audit programmes, pre-stage-1 certification readiness, DHF closure audits, and bridge audits when harmonizing EU MDR with FDA QSR requirements.
- Delivers a complete ISO 13485:2016 Clause 8.2.4 internal audit playbook focused on design controls, process validation,
- Highlights the six core differences versus ISO 27001 audits with prescriptive medical device emphasis
- Pairs with audit_schedule_optimizer.py for cadence planning and audit_simulator.py for mock-audit preparation
- Supports annual programme, pre-certification readiness, surveillance audits, DHF closure, post-CAPA verification and FDA
- Produces audit findings with severity classification and traceable evidence mapping
Qms Audit Expert by the numbers
- 752 all-time installs (skills.sh)
- Ranked #438 of 2,203 Security skills by installs in the Skillselion catalog
- Security screen: MEDIUM risk (skills.sh audit)
- Data as of Jul 31, 2026 (Skillselion catalog sync)
npx skills add https://github.com/alirezarezvani/claude-skills --skill qms-audit-expertAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 752 |
|---|---|
| repo stars | ★ 23.5k |
| Security audit | 2 / 3 scanners passed |
| Last updated | July 17, 2026 |
| Repository | alirezarezvani/claude-skills ↗ |
How do you run ISO 13485 internal audits for medical devices?
Run structured internal audits that satisfy ISO 13485:2016 Clause 8.2.4 expectations for medical-device quality management systems.
Who is it for?
Quality engineers and regulated-software developers maintaining ISO 13485 QMS compliance for medical devices facing certification or surveillance audits.
Skip if: Teams without a medical-device QMS scope who only need generic software security scanning or non-regulated product audits.
When should I use this skill?
A developer or QMS owner asks to plan, conduct, or prepare evidence for an ISO 13485 Clause 8.2.4 internal audit.
What you get
Structured audit programme plan, Clause 8.2.4 evidence checklists, surveillance preparation notes, and CAPA verification audit records.
- Audit programme plan
- Clause 8.2.4 evidence checklist
- Surveillance preparation notes
By the numbers
- References ISO 13485:2016 Clause 8.2.4 as the primary audit scope
- Bundles audit_schedule_optimizer.py for audit cadence planning
Files
QMS Audit Expert
ISO 13485 internal audit methodology for medical device quality management systems.
---
Table of Contents
- Audit Planning Workflow
- Audit Execution
- Nonconformity Management
- External Audit Preparation
- Reference Documentation
- Tools
---
Audit Planning Workflow
Plan risk-based internal audit program:
1. List all QMS processes requiring audit 2. Assign risk level to each process (High/Medium/Low) 3. Review previous audit findings and trends 4. Determine audit frequency by risk level 5. Assign qualified auditors (verify independence) 6. Create annual audit schedule 7. Communicate schedule to process owners 8. Validation: All ISO 13485 clauses covered within cycle
Risk-Based Audit Frequency
| Risk Level | Frequency | Criteria |
|---|---|---|
| High | Quarterly | Design control, CAPA, production validation |
| Medium | Semi-annual | Purchasing, training, document control |
| Low | Annual | Infrastructure, management review (if stable) |
Audit Scope by Clause
| Clause | Process | Focus Areas |
|---|---|---|
| 4.2 | Document Control | Document approval, distribution, obsolete control |
| 5.6 | Management Review | Inputs complete, decisions documented, actions tracked |
| 6.2 | Training | Competency defined, records complete, effectiveness verified |
| 7.3 | Design Control | Inputs, reviews, V&V, transfer, changes |
| 7.4 | Purchasing | Supplier evaluation, incoming inspection |
| 7.5 | Production | Work instructions, process validation, DHR |
| 7.6 | Calibration | Equipment list, calibration status, out-of-tolerance |
| 8.2.2 | Internal Audit | Schedule compliance, auditor independence |
| 8.3 | NC Product | Identification, segregation, disposition |
| 8.5 | CAPA | Root cause, implementation, effectiveness |
Auditor Independence
Verify auditor independence before assignment:
- [ ] Auditor not responsible for area being audited
- [ ] No direct reporting relationship to auditee
- [ ] Not involved in recent activities under audit
- [ ] Documented qualification for audit scope
---
Audit Execution
Conduct systematic internal audit:
1. Prepare audit plan (scope, criteria, schedule) 2. Review relevant documentation before audit 3. Conduct opening meeting with auditee 4. Collect evidence (records, interviews, observation) 5. Classify findings (Major/Minor/Observation) 6. Conduct closing meeting with preliminary findings 7. Prepare audit report within 5 business days 8. Validation: All scope items covered, findings supported by evidence
Evidence Collection
| Method | Use For | Documentation |
|---|---|---|
| Document review | Procedures, records | Document number, version, date |
| Interview | Process understanding | Interviewee name, role, summary |
| Observation | Actual practice | What, where, when observed |
| Record trace | Process flow | Record IDs, dates, linkage |
Audit Questions by Clause
Document Control (4.2):
- Show me the document master list
- How do you control obsolete documents?
- Show me evidence of document change approval
Design Control (7.3):
- Show me the Design History File for [product]
- Who participates in design reviews?
- Show me design input to output traceability
CAPA (8.5):
- Show me the CAPA log with open items
- How do you determine root cause?
- Show me effectiveness verification records
See references/iso13485-audit-guide.md for complete question sets.
Finding Documentation
Document each finding with:
Requirement: [Specific ISO 13485 clause or procedure]
Evidence: [What was observed, reviewed, or heard]
Gap: [How evidence fails to meet requirement]Example:
Requirement: ISO 13485:2016 Clause 7.6 requires calibration
at specified intervals.
Evidence: Calibration records for pH meter (EQ-042) show
last calibration 2024-01-15. Calibration interval is
12 months. Today is 2025-03-20.
Gap: Equipment is 2 months overdue for calibration,
representing a gap in calibration program execution.---
Nonconformity Management
Classify and manage audit findings:
1. Evaluate finding against classification criteria 2. Assign severity (Major/Minor/Observation) 3. Document finding with objective evidence 4. Communicate to process owner 5. Initiate CAPA for Major/Minor findings 6. Track to closure 7. Verify effectiveness at follow-up 8. Validation: Finding closed only after effective CAPA
Classification Criteria
| Category | Definition | CAPA Required | Timeline |
|---|---|---|---|
| Major | Systematic failure or absence of element | Yes | 30 days |
| Minor | Isolated lapse or partial implementation | Recommended | 60 days |
| Observation | Improvement opportunity | Optional | As appropriate |
Classification Decision
Is required element absent or failed?
├── Yes → Systematic (multiple instances)? → MAJOR
│ └── No → Could affect product safety? → MAJOR
│ └── No → MINOR
└── No → Deviation from procedure?
├── Yes → Recurring? → MAJOR
│ └── No → MINOR
└── No → Improvement opportunity? → OBSERVATIONCAPA Integration
| Finding Severity | CAPA Depth | Verification |
|---|---|---|
| Major | Full root cause analysis (5-Why, Fishbone) | Next audit or within 6 months |
| Minor | Immediate cause identification | Next scheduled audit |
| Observation | Not required | Noted at next audit |
See references/nonconformity-classification.md for detailed guidance.
---
External Audit Preparation
Prepare for certification body or regulatory audit:
1. Complete all scheduled internal audits 2. Verify all findings closed with effective CAPA 3. Review documentation for currency and accuracy 4. Conduct management review with audit as input 5. Prepare facility and personnel 6. Conduct mock audit (full scope) 7. Brief personnel on audit protocol 8. Validation: Mock audit findings addressed before external audit
Pre-Audit Readiness Checklist
Documentation:
- [ ] Quality Manual current
- [ ] Procedures reflect actual practice
- [ ] Records complete and retrievable
- [ ] Previous audit findings closed
Personnel:
- [ ] Key personnel available during audit
- [ ] Subject matter experts identified
- [ ] Personnel briefed on audit protocol
- [ ] Escorts assigned
Facility:
- [ ] Work areas organized
- [ ] Documents at point of use current
- [ ] Equipment calibration status visible
- [ ] Nonconforming product segregated
Mock Audit Protocol
1. Use external auditor or qualified internal auditor 2. Cover full scope of upcoming external audit 3. Simulate actual audit conditions (timing, formality) 4. Document findings as for real audit 5. Address all Major and Minor findings before external audit 6. Brief management on readiness status
---
Reference Documentation
ISO 13485 Audit Guide
references/iso13485-audit-guide.md contains:
- Clause-by-clause audit methodology
- Sample audit questions for each clause
- Evidence collection requirements
- Common nonconformities by clause
- Finding severity classification
Nonconformity Classification
references/nonconformity-classification.md contains:
- Severity classification criteria and decision tree
- Impact vs. occurrence matrix
- CAPA integration requirements
- Finding documentation templates
- Closure requirements by severity
---
Tools
Audit Schedule Optimizer
# Generate optimized audit schedule
python scripts/audit_schedule_optimizer.py --processes processes.json
# Interactive mode
python scripts/audit_schedule_optimizer.py --interactive
# JSON output for integration
python scripts/audit_schedule_optimizer.py --processes processes.json --output jsonGenerates risk-based audit schedule considering:
- Process risk level
- Previous findings
- Days since last audit
- Criticality scores
Output includes:
- Prioritized audit schedule
- Quarterly distribution
- Overdue audit alerts
- Resource recommendations
Sample Process Input
{
"processes": [
{
"name": "Design Control",
"iso_clause": "7.3",
"risk_level": "HIGH",
"last_audit_date": "2024-06-15",
"previous_findings": 2
},
{
"name": "Document Control",
"iso_clause": "4.2",
"risk_level": "MEDIUM",
"last_audit_date": "2024-09-01",
"previous_findings": 0
}
]
}---
Audit Program Metrics
Track audit program effectiveness:
| Metric | Target | Measurement |
|---|---|---|
| Schedule compliance | >90% | Audits completed on time |
| Finding closure rate | >95% | Findings closed by due date |
| Repeat findings | <10% | Same finding in consecutive audits |
| CAPA effectiveness | >90% | Verified effective at follow-up |
| Auditor utilization | 4 days/month | Audit days per qualified auditor |
ISO 13485:2016 Internal Audit Playbook
This reference answers exactly one decision: how do we conduct an ISO 13485 QMS internal audit (Clause 8.2.4) that satisfies certification body expectations and supports MDR / FDA QSR alignment?
Pair with scripts/audit_schedule_optimizer.py (this skill) for cadence and with compliance-os/scripts/audit_simulator.py for mock-audit preparation.
When to Use This Playbook
- Annual Clause 8.2.4 internal audit programme
- Pre-stage-1 ISO 13485 certification readiness
- Surveillance audit preparation (year 2 / year 3)
- New medical device introduction (DHF closure audit)
- Post-CAPA closure verification audit
- Bridge audit for FDA QSR / EU MDR alignment
Key Difference from ISO 27001 Audits
ISO 13485 audits emphasize:
1. Design controls (Clause 7.3) — DHF/DMR completeness, design verification + validation evidence, traceability matrix 2. Process validation (Clause 7.5.6) — IQ/OQ/PQ for manufacturing + sterilization + cleaning processes 3. Document control (Clause 4.2) — strict version control + change control for all controlled documents 4. CAPA (Clause 8.5.2) — closed-loop with root cause analysis; "containment / correction / corrective action" distinction 5. Post-market surveillance (Clause 8.2.1) — vigilance reporting, customer feedback loop, trend analysis 6. Risk management (Clause 7.1 + ISO 14971) — risk file maintained across product lifecycle
ISO 13485 audits are more prescriptive than 27001 — auditors expect specific record formats, sign-offs, and traceability that 27001's risk-based approach does not require.
The 7-Phase Audit Workflow
Same 7-phase structure as ISO 27001 (Plan → Prepare → Open → Field → Close → Report → Track), with these QMS-specific differences:
Phase 1 Plan — Scope Selection
ISO 13485 organizes clauses by lifecycle activity. Audit fieldwork organizes by:
- Design controls (Clause 7.3) — DHF audit per product
- Production & service provision (Clause 7.5) — process validation evidence
- Management responsibility (Clause 5) — management review records
- Resource management (Clause 6) — competence + infrastructure + work environment
- Measurement, analysis, improvement (Clause 8) — internal audit programme + CAPA + nonconformity + statistical techniques
3-year rolling coverage: every clause audited at least once, with design + CAPA + post-market in higher rotation due to risk weight.
Phase 4 Field — QMS-Specific Sampling
For design controls (Clause 7.3) — sample DHFs:
- Stratified by product class (Class I, IIa, IIb, III per MDR; Class I/II/III per FDA)
- For each sampled DHF, verify:
- Design + development plan with stages + reviews defined
- Design inputs traceability to user needs / clinical requirements
- Design outputs verification evidence
- Design validation evidence (clinical evaluation per MDR Annex XIV / 510(k) summary per FDA)
- Design transfer evidence
- Design changes controlled per Clause 7.3.9
- DHF complete and archived
For CAPA (Clause 8.5.2) — sample CAPA records:
- Stratified by source (customer complaint, internal audit, management review, nonconformity)
- For each sampled CAPA, verify:
- Problem statement clear + measurable
- Root cause analysis evidence (5 Why, fishbone, Pareto, FMEA — pick the method)
- Containment + correction + corrective action distinction documented
- Effectiveness verification with evidence (re-test or sample post-implementation)
- Closure approved by appropriate authority
For post-market surveillance (Clause 8.2.1) — sample:
- Customer complaint log + investigation closure
- Vigilance reports (serious incident / FSCA) submitted per applicable regulation
- Trend analysis evidence + management review input
- Post-market clinical follow-up evidence (per MDR for high-risk devices)
Common Stage 1 / Stage 2 Findings (the patterns)
Based on practitioner reports of common ISO 13485:2016 findings:
1. Design changes not always controlled per Clause 7.3.9 — emergency changes bypass review 2. DHF incomplete — design history files missing one or more required elements 3. Process validation incomplete or stale — IQ/OQ/PQ done at original setup, never re-validated 4. CAPA effectiveness verification missing — corrective action closed without evidence of effectiveness 5. Risk management file not updated post-launch — ISO 14971 risk file frozen at release 6. Supplier evaluations exist but selection criteria not documented 7. Internal audit programme misses some clauses over 3-year cycle 8. Management review missing required inputs (audit results, nonconformity status, customer feedback, etc.) 9. Training records lack evidence of effectiveness verification 10. Document control: obsolete documents accessible in shared drives 11. Validation of software used in QMS (per Clause 4.1.6) not performed 12. Post-market surveillance plan exists but not executed quarterly
MDR 2017/745 + FDA QSR Overlap
ISO 13485 is the foundation for both EU MDR and FDA QSR compliance.
EU MDR cross-walk
| ISO 13485 clause | MDR article / annex |
|---|---|
| 4.2 Documentation | Annex II + Annex III (technical documentation) |
| 5 Management responsibility | Article 10(1)-(9) |
| 6 Resource management | Article 10(13) |
| 7.1 Risk management | Annex I §3 + ISO 14971 |
| 7.3 Design + development | Annex II + Annex VIII (design dossier) |
| 7.4 Purchasing | Article 10(4) + Annex II |
| 7.5.6 Process validation | Annex IX §3 |
| 8.2.1 Post-market surveillance | Article 83 + Article 86 + Annex III |
| 8.5.2 CAPA | Article 87 (vigilance) + Article 89 (CAPA) |
FDA legacy QSR (21 CFR 820, historical) cross-walk
⚠️ STATUS — QMSR transition (effective 2026-02-02): FDA's QMSR final rule (89 FR 7496) amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference and removed the legacy QSR subsection structure. The 820.x numbers below no longer exist in the CFR — they are retained only as a familiar index for auditors mapping pre-2026 documentation. Cite the ISO 13485 clauses in current audits.
| ISO 13485 clause (current authority) | Legacy QSR section (historical, pre-2026) |
|---|---|
| 4 QMS | 820.20 (Management responsibility) + 820.5 (QMS) |
| 7.3 Design controls | 820.30 |
| 7.4 Purchasing controls | 820.50 |
| 7.5.6 Process validation | 820.75 |
| 8.2.1 Post-market | 820.198 (Complaint files) + 803 (MDR reporting — unchanged) |
| 8.5.2 CAPA | 820.100 |
FDA finalized the QMSR rule in February 2024 (89 FR 7496) incorporating ISO 13485:2016 into 21 CFR 820, substantially harmonizing US and international requirements; it took effect 2026-02-02. An ISO 13485-certified QMS now substantially satisfies 21 CFR 820, with FDA-specific overlays in retained 820.10/820.35/820.45 (labeling, complaint records) and unchanged 21 CFR 803 MDR reporting.
Risk Management Audit (ISO 14971 Crosswalk)
Per Clause 7.1 + ISO 14971:2019, the risk management file (RMF) must be maintained for the device lifecycle. Audit should sample:
- Risk management plan exists per product
- Hazard identification covers reasonable foreseeable misuse
- Risk analysis applies probability × severity per ISO 14971
- Risk control measures applied per inherent safety → protective measures → information for safety hierarchy
- Residual risk evaluated + accepted (with rationale)
- Post-production information feeds back into RMF (concept drift equivalent for medical devices)
CAPA Discipline — The Highest-Stakes Audit Area
CAPA is the #1 cited area in 13485 + QSR audits. Auditors look for:
1. Containment vs correction vs corrective action distinction
- Containment: stop the bleeding (short-term)
- Correction: fix the symptom (medium-term)
- Corrective action: prevent recurrence by addressing root cause (long-term)
2. Root cause analysis depth — 5 Why minimum; ideally fishbone + Pareto for repeat issues 3. Effectiveness verification — measurable evidence the root cause is addressed; not "we updated the procedure" 4. Time to close — tracked + reported; aging CAPAs > 90 days are a smell 5. Trend analysis — repeat CAPAs across products signal systemic issue
Cross-Framework Reuse
This ISO 13485 audit playbook supports:
- EU MDR 745 — design dossier + technical documentation audits (see mdr-745-specialist)
- FDA QSR (21 CFR 820) — substantially harmonized post Feb 2026
- ISO 14971 — risk management file audit integrated with 7.1
- ISO 42001 for AI-enabled medical devices — A.6 lifecycle controls layer on top of 7.3 design controls
Pair with compliance-os/references/multi_framework_audit_playbook.md for medical-device multi-framework programs.
When This Reference Doesn't Help
- Specific medical device classification. See mdr-745-specialist + fda-consultant-specialist.
- Specific clinical evaluation. Per MDR Annex XIV; see mdr-745-specialist references.
- Software as medical device (SaMD). IEC 62304 specific; see risk-management-specialist + applicable references.
- External notified body audit. This is the internal audit playbook; external surveillance audits follow ISO 17021.
---
Source authorities (non-exhaustive):
- ISO 13485:2016 — Medical devices — Quality management systems (the standard)
- ISO 14971:2019 — Application of risk management to medical devices
- ISO/IEC 19011:2018 — Guidelines for auditing management systems
- ISO 17021-1:2015 — Conformity assessment requirements
- Regulation (EU) 2017/745 — Medical Device Regulation
- 21 CFR 820 — FDA Quality System Regulation (QSR / QMSR post-Feb 2026)
- FDA Final Rule (Feb 2024) — Quality Management System Regulation (incorporating ISO 13485 by reference)
- AAMI TIR45:2012 — Guidance on use of agile practices in development of medical device software
- IEC 62304:2006/A1:2015 — Medical device software lifecycle
- GHTF / IMDRF guidance documents — international harmonization context
ISO 13485 Audit Guide
Clause-by-clause audit methodology with sample questions and common findings.
---
Table of Contents
- Audit Approach
- Clause 4: Quality Management System
- Clause 5: Management Responsibility
- Clause 6: Resource Management
- Clause 7: Product Realization
- Clause 8: Measurement and Improvement
- Common Nonconformities
---
Audit Approach
Risk-Based Audit Planning
Prioritize audit focus based on:
| Risk Level | Audit Frequency | Scope Depth |
|---|---|---|
| High | Quarterly | Full clause review |
| Medium | Semi-annual | Targeted review |
| Low | Annual | Sampling-based |
Evidence Collection Methods
| Method | Best For | Examples |
|---|---|---|
| Document review | Procedures, records | SOPs, DHF, batch records |
| Interview | Process understanding | Operators, supervisors |
| Observation | Actual practice | Production, calibration |
| Tracing | Process flow | Order to delivery |
---
Clause 4: Quality Management System
4.1 General Requirements
Audit Questions:
- Show me documentation of your QMS scope and exclusions
- How do you identify processes needed for the QMS?
- Show me evidence of outsourced process control
Evidence to Review:
- [ ] Quality Manual or QMS description
- [ ] Process interaction diagram
- [ ] Outsourced process agreements
Common Findings:
- Scope exclusions not justified
- Outsourced processes not controlled
- Process interactions not defined
4.2 Documentation Requirements
4.2.1-4.2.2 Quality Manual and Documents
Audit Questions:
- Where is your documented quality policy?
- Show me the procedure for document control
- How do you ensure documents are current at point of use?
Evidence to Review:
- [ ] Quality Manual
- [ ] Document master list
- [ ] Sample of controlled documents
4.2.4 Control of Records
Audit Questions:
- What is your record retention policy?
- Show me the procedure for record storage and protection
- How do you ensure record legibility and retrievability?
Evidence to Review:
- [ ] Record control procedure
- [ ] Retention schedule
- [ ] Sample record retrieval test
Common Findings:
- Obsolete documents in use
- Records not legible or retrievable
- Retention periods not defined for all record types
---
Clause 5: Management Responsibility
5.1-5.2 Management Commitment and Customer Focus
Audit Questions:
- How does top management demonstrate commitment to QMS?
- Show me evidence of customer requirement determination
- How are regulatory requirements communicated?
Evidence to Review:
- [ ] Quality policy communication
- [ ] Management review minutes
- [ ] Customer feedback records
5.4 Planning
Audit Questions:
- Where are your quality objectives documented?
- Show me the plan for achieving quality objectives
- How do you maintain QMS integrity during changes?
Evidence to Review:
- [ ] Quality objectives (measurable, time-bound)
- [ ] Quality planning documentation
- [ ] Change management records
5.5 Responsibility and Authority
Audit Questions:
- Where are responsibilities and authorities defined?
- Who is the management representative?
- How is QMS performance communicated to top management?
Evidence to Review:
- [ ] Organization chart
- [ ] Job descriptions with QMS responsibilities
- [ ] Management representative appointment
5.6 Management Review
Audit Questions:
- Show me management review records from last 12 months
- What inputs are included in management review?
- What decisions and actions resulted?
Required Review Inputs:
- [ ] Audit results
- [ ] Customer feedback (including complaints)
- [ ] Process performance and product conformity
- [ ] CAPA status
- [ ] Changes affecting QMS
- [ ] Recommendations for improvement
- [ ] New/revised regulatory requirements
Common Findings:
- Management review not conducted at planned intervals
- Required inputs missing
- Action items not tracked to completion
---
Clause 6: Resource Management
6.1-6.2 Human Resources
Audit Questions:
- How do you determine competency requirements?
- Show me training records for personnel affecting quality
- How do you evaluate training effectiveness?
Evidence to Review:
- [ ] Competency requirements by role
- [ ] Training records
- [ ] Effectiveness evaluations
6.3-6.4 Infrastructure and Work Environment
Audit Questions:
- How do you determine infrastructure requirements?
- Show me maintenance records for critical equipment
- How is work environment controlled for product conformity?
Evidence to Review:
- [ ] Equipment list with maintenance schedules
- [ ] Environmental monitoring records
- [ ] Contamination control procedures (if applicable)
Common Findings:
- Training effectiveness not evaluated
- Preventive maintenance not performed on schedule
- Environmental conditions not monitored
---
Clause 7: Product Realization
7.1 Planning of Product Realization
Audit Questions:
- Show me the quality plan for a recent product
- How do you determine verification and validation activities?
- What records are required to demonstrate conformity?
Evidence to Review:
- [ ] Quality plan or project plan
- [ ] Risk management integration
- [ ] Required records defined
7.2 Customer-Related Processes
Audit Questions:
- How do you determine customer requirements?
- Show me the contract review process
- How do you handle customer communications?
Evidence to Review:
- [ ] Contract/order review records
- [ ] Customer requirement documentation
- [ ] Communication records
7.3 Design and Development
Audit Questions (per phase):
| Phase | Key Questions |
|---|---|
| Planning | Show me design plan with stages, reviews, responsibilities |
| Inputs | How are regulatory requirements identified? |
| Outputs | Show me design outputs addressing inputs |
| Review | Who participated in design reviews? |
| Verification | Show me verification activities and results |
| Validation | Show me validation under actual use conditions |
| Transfer | How was design transferred to production? |
| Changes | Show me design change control records |
Evidence to Review:
- [ ] Design History File (DHF)
- [ ] Design review records with participants
- [ ] Verification/validation protocols and reports
- [ ] Design change requests
7.4 Purchasing
Audit Questions:
- How do you evaluate and select suppliers?
- Show me approved supplier list with evaluation criteria
- How do you verify purchased product?
Evidence to Review:
- [ ] Supplier evaluation procedure
- [ ] Approved supplier list
- [ ] Incoming inspection records
- [ ] Supplier audit records
7.5 Production and Service Provision
Audit Questions:
- Show me work instructions for production
- How are special processes validated?
- Show me traceability records for a product lot
Evidence to Review:
- [ ] Production work instructions
- [ ] Process validation records
- [ ] Device history records (DHR)
- [ ] Traceability records
7.6 Control of Monitoring and Measuring Equipment
Audit Questions:
- Show me calibration records for measuring equipment
- How do you handle out-of-tolerance conditions?
- How is software used for monitoring validated?
Evidence to Review:
- [ ] Equipment calibration records
- [ ] Calibration procedure
- [ ] Out-of-tolerance investigation records
Common Findings:
- Design inputs not completely addressed in outputs
- Supplier evaluations not performed or documented
- Process validation not maintained after changes
- Calibration overdue
---
Clause 8: Measurement and Improvement
8.2.1 Feedback
Audit Questions:
- How do you collect customer feedback?
- Show me complaint handling records
- How is feedback data used for improvement?
Evidence to Review:
- [ ] Complaint procedure
- [ ] Complaint log with trending
- [ ] Feedback to design/production
8.2.2 Internal Audit
Audit Questions:
- Show me the internal audit schedule
- How do you ensure auditor independence?
- Show me audit records and follow-up actions
Evidence to Review:
- [ ] Audit program/schedule
- [ ] Auditor qualification records
- [ ] Audit reports and findings
- [ ] CAPA records from audits
8.2.3-8.2.4 Monitoring and Measurement
Audit Questions:
- How do you monitor process performance?
- Show me product acceptance records
- What happens when acceptance criteria not met?
Evidence to Review:
- [ ] Process monitoring data
- [ ] Inspection records
- [ ] Nonconforming product records
8.3 Control of Nonconforming Product
Audit Questions:
- Show me the procedure for nonconforming product
- How do you prevent unintended use of nonconforming product?
- Who authorizes concessions/deviations?
Evidence to Review:
- [ ] NC product procedure
- [ ] NC product records
- [ ] Concession authorizations
8.4 Analysis of Data
Audit Questions:
- What data do you analyze for QMS effectiveness?
- Show me trend analysis for complaints, NC, CAPA
- How does data drive improvement?
Evidence to Review:
- [ ] Data analysis reports
- [ ] Trend charts
- [ ] Management review inputs
8.5 CAPA
Audit Questions:
- Show me the CAPA procedure
- How do you determine root cause?
- Show me CAPA effectiveness verification
Evidence to Review:
- [ ] CAPA procedure
- [ ] Open/closed CAPA log
- [ ] Root cause analysis records
- [ ] Effectiveness verification records
Common Findings:
- Complaint trending not performed
- CAPA not initiated for recurring issues
- Root cause analysis superficial
- Effectiveness verification not documented
---
Common Nonconformities
Top 10 ISO 13485 Audit Findings
| Rank | Clause | Finding |
|---|---|---|
| 1 | 7.3 | Design inputs not traceable to outputs |
| 2 | 8.5 | CAPA effectiveness not verified |
| 3 | 4.2.4 | Records not retrievable or legible |
| 4 | 7.4 | Supplier evaluation not documented |
| 5 | 6.2 | Training effectiveness not evaluated |
| 6 | 7.5.2 | Process validation not maintained |
| 7 | 8.2.2 | Internal audits not covering all clauses |
| 8 | 5.6 | Management review inputs incomplete |
| 9 | 7.6 | Calibration records incomplete |
| 10 | 8.3 | NC product control inadequate |
Finding Severity Classification
| Severity | Definition | Response Required |
|---|---|---|
| Major | Systematic failure, absence of element | CAPA within 30 days |
| Minor | Isolated lapse, partial implementation | Correction within 60 days |
| Observation | Improvement opportunity | Optional action |
Nonconformity Classification
Severity classification, CAPA integration, and finding documentation guidance.
---
Table of Contents
---
Classification Criteria
Nonconformity Definitions
| Category | Definition | Examples |
|---|---|---|
| Major NC | Systematic failure or absence of required element | No design control procedure, no CAPA system |
| Minor NC | Isolated lapse or partial implementation | Single missing signature, one overdue calibration |
| Observation | Improvement opportunity, potential future NC | Trending toward noncompliance, unclear procedure |
Classification Decision Tree
Is required element absent or failed?
├── Yes → Is failure systematic (multiple instances)?
│ ├── Yes → MAJOR NONCONFORMITY
│ └── No → Could it cause product safety issue?
│ ├── Yes → MAJOR NONCONFORMITY
│ └── No → MINOR NONCONFORMITY
└── No → Is there deviation from procedure?
├── Yes → Isolated or recurring?
│ ├── Isolated → MINOR NONCONFORMITY
│ └── Recurring → MAJOR NONCONFORMITY
└── No → Is there improvement opportunity?
├── Yes → OBSERVATION
└── No → NO FINDING---
Severity Matrix
Impact vs. Occurrence Matrix
| Low Occurrence (1 instance) | Medium (2-3 instances) | High (Systematic) | |
|---|---|---|---|
| High Impact (Safety/Efficacy) | Major | Major | Major |
| Medium Impact (Quality/Compliance) | Minor | Major | Major |
| Low Impact (Administrative) | Observation | Minor | Minor |
Clause-Specific Severity Guidance
| Clause | Major If... | Minor If... |
|---|---|---|
| 4.2 Document Control | No document control system | Single obsolete document in use |
| 5.6 Management Review | Not conducted >12 months | Missing single input |
| 6.2 Training | No competency defined | Single training record missing |
| 7.3 Design Control | No design reviews | Review participant missing |
| 7.4 Purchasing | No supplier evaluation | Single evaluation overdue |
| 7.5 Production | Special process not validated | Minor deviation from WI |
| 8.2.2 Internal Audit | No audit program | Audit overdue <90 days |
| 8.5 CAPA | No CAPA system | Effectiveness not verified |
---
CAPA Integration
Finding-to-CAPA Workflow
1. Classify finding (Major/Minor/Observation) 2. Document finding with objective evidence 3. Determine CAPA requirement (see table below) 4. Initiate CAPA with finding as source 5. Track resolution through closure 6. Verify effectiveness at follow-up audit 7. Validation: Finding closed only after CAPA effective
CAPA Requirement by Severity
| Severity | CAPA Required | Timeline | Verification |
|---|---|---|---|
| Major | Yes | 30 days for root cause, 90 days for implementation | Next audit or within 6 months |
| Minor | Recommended | 60 days for correction | Next scheduled audit |
| Observation | Optional | As appropriate | Noted at next audit |
Root Cause Depth by Severity
| Severity | Root Cause Analysis Required |
|---|---|
| Major | Full 5-Why or Fishbone, systemic causes |
| Minor | Immediate cause identification |
| Observation | Not required |
---
Finding Documentation
Finding Statement Structure
FINDING STATEMENT TEMPLATE:
Requirement: [Specific clause or procedure requirement]
Evidence: [What was observed, reviewed, or heard]
Gap: [How the evidence fails to meet the requirement]
Example:
Requirement: ISO 13485:2016 Clause 8.2.2 requires internal audits
at planned intervals to determine QMS conformity.
Evidence: Audit schedule shows Design Control audit planned for
Q2 2024. No audit records exist. Interview with QA Manager
confirmed audit was not conducted.
Gap: Internal audit for Design Control process not conducted as
planned, representing a gap in audit program execution.Evidence Types and Requirements
| Evidence Type | How to Document | Retention |
|---|---|---|
| Document | Reference document number, version, date | Copy in audit file |
| Interview | Interviewee name, role, statement summary | Notes in audit file |
| Observation | What, where, when observed | Photo if appropriate |
| Record | Record identifier, date, content observed | Copy in audit file |
Finding Writing Guidelines
Do:
- State objective evidence clearly
- Reference specific requirements
- Use factual, neutral language
- Include document/record identifiers
Don't:
- Use judgmental language ("poor", "inadequate")
- Generalize without evidence ("always", "never")
- Combine multiple findings
- Include corrective action suggestions
---
Closure Requirements
Closure Criteria by Severity
Major Nonconformity:
- [ ] Root cause analysis completed
- [ ] Corrective action implemented
- [ ] Effectiveness verified (objective evidence)
- [ ] No recurrence observed
- [ ] QA Manager sign-off
- [ ] Auditor verification
Minor Nonconformity:
- [ ] Immediate correction completed
- [ ] Root cause addressed (if applicable)
- [ ] Evidence of correction reviewed
- [ ] QA Manager sign-off
Observation:
- [ ] Action taken (if any) documented
- [ ] Noted for future reference
Verification Methods
| Method | When to Use |
|---|---|
| Record review | Correction documented in records |
| Interview | Process change understood by personnel |
| Observation | Physical correction verified |
| Follow-up audit | Systematic correction verified over time |
Closure Documentation
CLOSURE RECORD TEMPLATE:
Finding ID: [NC-YYYY-XXX]
Original Finding: [Brief description]
Severity: [Major/Minor/Observation]
Corrective Action Taken:
[Description of action implemented]
Evidence of Implementation:
[Document numbers, dates, observations]
Effectiveness Verification:
[Method used, results, date]
Closure Approved By: [Name, Role, Date]---
Audit Finding Log
Log Template
| ID | Date | Clause | Finding | Severity | Status | Due Date | Closed Date |
|---|---|---|---|---|---|---|---|
| NC-2024-001 | |||||||
| NC-2024-002 |
Status Definitions
| Status | Definition |
|---|---|
| Open | Finding documented, CAPA not started |
| In Progress | CAPA underway |
| Pending Verification | Action complete, awaiting verification |
| Closed | Effectiveness verified |
| Escalated | Overdue or ineffective, requires management attention |
#!/usr/bin/env python3
"""
Audit Schedule Optimizer - Risk-Based Internal Audit Planning
Generates optimized audit schedules based on process risk levels,
previous findings, and resource constraints.
Usage:
python audit_schedule_optimizer.py --processes processes.json
python audit_schedule_optimizer.py --interactive
python audit_schedule_optimizer.py --processes processes.json --output json
"""
import argparse
import json
import sys
from dataclasses import dataclass, field, asdict
from datetime import datetime, timedelta
from typing import List, Dict, Optional
from enum import Enum
class RiskLevel(Enum):
HIGH = "High"
MEDIUM = "Medium"
LOW = "Low"
class AuditFrequency(Enum):
QUARTERLY = 90
SEMI_ANNUAL = 180
ANNUAL = 365
EXTENDED = 540 # 18 months
@dataclass
class Process:
name: str
iso_clause: str
risk_level: RiskLevel
last_audit_date: Optional[str] = None
previous_findings: int = 0
criticality_score: int = 5 # 1-10 scale
notes: str = ""
@dataclass
class AuditSlot:
process_name: str
iso_clause: str
scheduled_date: str
risk_level: str
priority_score: float
days_overdue: int = 0
rationale: str = ""
@dataclass
class AuditSchedule:
generated_date: str
schedule_period: str
total_audits: int
audits_by_quarter: Dict[str, int]
schedule: List[Dict]
recommendations: List[str]
class AuditScheduleOptimizer:
"""Optimizer for risk-based audit scheduling."""
# Frequency mapping by risk level
FREQUENCY_MAP = {
RiskLevel.HIGH: AuditFrequency.QUARTERLY,
RiskLevel.MEDIUM: AuditFrequency.SEMI_ANNUAL,
RiskLevel.LOW: AuditFrequency.ANNUAL,
}
# ISO 13485 required processes
REQUIRED_PROCESSES = [
("Document Control", "4.2"),
("Management Review", "5.6"),
("Training and Competency", "6.2"),
("Design Control", "7.3"),
("Purchasing", "7.4"),
("Production Control", "7.5"),
("Equipment Calibration", "7.6"),
("Customer Feedback", "8.2.1"),
("Internal Audit", "8.2.2"),
("Nonconforming Product", "8.3"),
("CAPA", "8.5"),
]
def __init__(self, processes: List[Process], audit_days_per_month: int = 4):
self.processes = processes
self.audit_days_per_month = audit_days_per_month
self.today = datetime.now()
def calculate_priority_score(self, process: Process) -> float:
"""Calculate audit priority score based on multiple factors."""
score = 0.0
# Base risk score (40% weight)
risk_scores = {RiskLevel.HIGH: 10, RiskLevel.MEDIUM: 6, RiskLevel.LOW: 3}
score += risk_scores[process.risk_level] * 0.4
# Overdue factor (30% weight)
if process.last_audit_date:
last_audit = datetime.strptime(process.last_audit_date, "%Y-%m-%d")
days_since = (self.today - last_audit).days
required_frequency = self.FREQUENCY_MAP[process.risk_level].value
overdue_ratio = days_since / required_frequency
score += min(overdue_ratio * 10, 10) * 0.3
else:
# Never audited = highest priority
score += 10 * 0.3
# Previous findings factor (20% weight)
findings_score = min(process.previous_findings * 2, 10)
score += findings_score * 0.2
# Criticality factor (10% weight)
score += process.criticality_score * 0.1
return round(score, 2)
def get_days_overdue(self, process: Process) -> int:
"""Calculate days overdue for audit."""
if not process.last_audit_date:
return 365 # Assume 1 year overdue if never audited
last_audit = datetime.strptime(process.last_audit_date, "%Y-%m-%d")
required_frequency = self.FREQUENCY_MAP[process.risk_level].value
next_due = last_audit + timedelta(days=required_frequency)
days_overdue = (self.today - next_due).days
return max(0, days_overdue)
def generate_schedule(self, months_ahead: int = 12) -> AuditSchedule:
"""Generate optimized audit schedule."""
# Calculate priority scores
prioritized = []
for process in self.processes:
priority = self.calculate_priority_score(process)
overdue = self.get_days_overdue(process)
prioritized.append((process, priority, overdue))
# Sort by priority (descending)
prioritized.sort(key=lambda x: x[1], reverse=True)
# Generate schedule slots
schedule = []
current_date = self.today
audits_per_quarter = {"Q1": 0, "Q2": 0, "Q3": 0, "Q4": 0}
for process, priority, overdue in prioritized:
# Determine schedule date based on priority
if overdue > 0:
# Overdue: schedule within next 30 days
scheduled_date = current_date + timedelta(days=min(30, overdue // 10 + 7))
elif priority > 7:
# High priority: within 60 days
scheduled_date = current_date + timedelta(days=30)
elif priority > 4:
# Medium priority: within 120 days
scheduled_date = current_date + timedelta(days=90)
else:
# Low priority: within 180 days
scheduled_date = current_date + timedelta(days=180)
# Cap at months_ahead
max_date = current_date + timedelta(days=months_ahead * 30)
if scheduled_date > max_date:
scheduled_date = max_date
# Track quarter distribution
quarter = f"Q{(scheduled_date.month - 1) // 3 + 1}"
audits_per_quarter[quarter] += 1
# Generate rationale
rationale_parts = []
if overdue > 0:
rationale_parts.append(f"{overdue} days overdue")
if process.previous_findings > 0:
rationale_parts.append(f"{process.previous_findings} previous findings")
if process.risk_level == RiskLevel.HIGH:
rationale_parts.append("high-risk process")
rationale = "; ".join(rationale_parts) if rationale_parts else "Scheduled per frequency"
slot = AuditSlot(
process_name=process.name,
iso_clause=process.iso_clause,
scheduled_date=scheduled_date.strftime("%Y-%m-%d"),
risk_level=process.risk_level.value,
priority_score=priority,
days_overdue=overdue,
rationale=rationale
)
schedule.append(slot)
# Generate recommendations
recommendations = self._generate_recommendations(prioritized)
return AuditSchedule(
generated_date=self.today.strftime("%Y-%m-%d"),
schedule_period=f"{self.today.strftime('%Y-%m-%d')} to {(self.today + timedelta(days=months_ahead * 30)).strftime('%Y-%m-%d')}",
total_audits=len(schedule),
audits_by_quarter=audits_per_quarter,
schedule=[asdict(s) for s in schedule],
recommendations=recommendations
)
def _generate_recommendations(self, prioritized: List) -> List[str]:
"""Generate recommendations based on analysis."""
recommendations = []
# Check for overdue audits
overdue_count = sum(1 for _, _, overdue in prioritized if overdue > 0)
if overdue_count > 0:
recommendations.append(
f"URGENT: {overdue_count} process(es) overdue for audit. "
"Prioritize these to maintain compliance."
)
# Check for high-risk processes
high_risk_count = sum(1 for p, _, _ in prioritized if p.risk_level == RiskLevel.HIGH)
if high_risk_count > 3:
recommendations.append(
f"High audit burden: {high_risk_count} high-risk processes. "
"Consider quarterly resource allocation."
)
# Check for processes with multiple findings
finding_processes = [(p.name, p.previous_findings) for p, _, _ in prioritized if p.previous_findings >= 3]
if finding_processes:
names = ", ".join([name for name, _ in finding_processes[:3]])
recommendations.append(
f"Recurring issues in: {names}. "
"Consider focused audits or process improvement initiatives."
)
# Check for never-audited processes
never_audited = [p.name for p, _, _ in prioritized if not p.last_audit_date]
if never_audited:
recommendations.append(
f"Never audited: {', '.join(never_audited[:3])}. "
"Include in next audit cycle."
)
if not recommendations:
recommendations.append("Audit program is on track. Maintain scheduled frequency.")
return recommendations
def format_text_output(schedule: AuditSchedule) -> str:
"""Format schedule as text report."""
lines = [
"=" * 70,
"AUDIT SCHEDULE OPTIMIZATION REPORT",
"=" * 70,
f"Generated: {schedule.generated_date}",
f"Period: {schedule.schedule_period}",
f"Total Audits: {schedule.total_audits}",
"",
"Quarterly Distribution:",
]
for q, count in schedule.audits_by_quarter.items():
bar = "█" * count + "░" * (10 - count)
lines.append(f" {q}: {bar} {count}")
lines.extend([
"",
"-" * 70,
"AUDIT SCHEDULE",
"-" * 70,
f"{'Process':<25} {'Clause':<8} {'Date':<12} {'Risk':<8} {'Priority':<8}",
"-" * 70,
])
for audit in schedule.schedule:
lines.append(
f"{audit['process_name']:<25} "
f"{audit['iso_clause']:<8} "
f"{audit['scheduled_date']:<12} "
f"{audit['risk_level']:<8} "
f"{audit['priority_score']:<8}"
)
lines.extend([
"",
"-" * 70,
"RECOMMENDATIONS",
"-" * 70,
])
for i, rec in enumerate(schedule.recommendations, 1):
lines.append(f"{i}. {rec}")
lines.append("=" * 70)
return "\n".join(lines)
def interactive_mode():
"""Run interactive schedule generation."""
print("=" * 60)
print("Audit Schedule Optimizer - Interactive Mode")
print("=" * 60)
processes = []
print("\nEnter processes (blank name to finish):\n")
while True:
name = input("Process name (or Enter to finish): ").strip()
if not name:
break
clause = input("ISO 13485 clause (e.g., 7.3): ").strip()
risk = input("Risk level (H/M/L): ").strip().upper()
risk_level = {
"H": RiskLevel.HIGH,
"M": RiskLevel.MEDIUM,
"L": RiskLevel.LOW
}.get(risk, RiskLevel.MEDIUM)
last_audit = input("Last audit date (YYYY-MM-DD, or Enter if never): ").strip()
if not last_audit:
last_audit = None
findings = input("Previous findings count (default 0): ").strip()
findings = int(findings) if findings.isdigit() else 0
processes.append(Process(
name=name,
iso_clause=clause,
risk_level=risk_level,
last_audit_date=last_audit,
previous_findings=findings
))
print(f"Added: {name}\n")
if not processes:
print("No processes entered. Using default ISO 13485 processes.")
processes = [
Process(name=name, iso_clause=clause, risk_level=RiskLevel.MEDIUM)
for name, clause in AuditScheduleOptimizer.REQUIRED_PROCESSES
]
optimizer = AuditScheduleOptimizer(processes)
schedule = optimizer.generate_schedule()
print("\n" + format_text_output(schedule))
def main():
parser = argparse.ArgumentParser(
description="Risk-Based Audit Schedule Optimizer"
)
parser.add_argument(
"--processes",
type=str,
help="JSON file with process definitions"
)
parser.add_argument(
"--output",
choices=["text", "json"],
default="text",
help="Output format"
)
parser.add_argument(
"--interactive",
action="store_true",
help="Run in interactive mode"
)
parser.add_argument(
"--months",
type=int,
default=12,
help="Planning horizon in months"
)
args = parser.parse_args()
if args.interactive:
interactive_mode()
return
if args.processes:
with open(args.processes, "r") as f:
data = json.load(f)
processes = []
for p in data.get("processes", []):
risk = RiskLevel[p.get("risk_level", "MEDIUM").upper()]
processes.append(Process(
name=p["name"],
iso_clause=p.get("iso_clause", ""),
risk_level=risk,
last_audit_date=p.get("last_audit_date"),
previous_findings=p.get("previous_findings", 0),
criticality_score=p.get("criticality_score", 5)
))
else:
# Use default processes
processes = [
Process(name=name, iso_clause=clause, risk_level=RiskLevel.MEDIUM)
for name, clause in AuditScheduleOptimizer.REQUIRED_PROCESSES
]
optimizer = AuditScheduleOptimizer(processes)
schedule = optimizer.generate_schedule(args.months)
if args.output == "json":
print(json.dumps(asdict(schedule), indent=2))
else:
print(format_text_output(schedule))
if __name__ == "__main__":
main()
Related skills
How it compares
Choose qms-audit-expert over generic security audit skills when the goal is regulated medical-device QMS compliance rather than application vulnerability scanning.
FAQ
What standard does qms-audit-expert cover?
qms-audit-expert targets ISO 13485:2016 Clause 8.2.4 internal audit requirements for medical-device quality management systems. The playbook also references MDR and FDA QSR alignment for certification and surveillance readiness.
When should teams use qms-audit-expert?
qms-audit-expert fits annual Clause 8.2.4 programmes, pre-stage-1 ISO 13485 certification, surveillance audits in years 2 and 3, DHF closure checks, and post-CAPA verification. Use it before certification-body visits.
Is Qms Audit Expert safe to install?
skills.sh reports 2 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.