Medical Device Supplier Audit Checklist: ISO 13485 Procurement Guide
Medical Device Supplier Audit Checklist: ISO 13485 Procurement Guide
TL;DR: A medical device supplier audit should prove that a supplier can consistently meet defined quality, regulatory, delivery, traceability, and change-control requirements. Start with risk classification, request evidence before the visit, test records rather than accepting policies at face value, score critical controls separately from general maturity, and convert every finding into an owner, deadline, and sourcing decision. The checklist below gives procurement and supplier-quality teams a repeatable 50-point framework. Once a supplier passes the quality gate, AuraVMS can carry the approved requirement set into a controlled RFQ and quote-comparison workflow without forcing suppliers to create accounts.
Supplier audits in medical devices are not ceremonial factory tours. A weak audit can admit a supplier whose processes later create nonconforming material, delayed releases, incomplete traceability, or an expensive field action. An overbuilt audit can be nearly as damaging: procurement spends weeks collecting documents, qualified suppliers disengage, and sourcing milestones slip without improving patient safety.
The practical answer is a risk-based audit that separates three questions. Can the supplier make the item? Can it prove control of the process? Can your organization detect and contain a failure before it reaches a patient? This guide turns those questions into an auditable checklist and a defensible supplier decision.
This article is operational guidance, not legal or regulatory advice. Your quality and regulatory teams should adapt it to the device, market, supplier role, and applicable requirements.
1. Why medical device supplier audits matter more in 2026
The regulatory context has changed for organizations selling finished devices in the United States. The FDA Quality Management System Regulation became effective on February 2, 2026. It amended 21 CFR Part 820 and incorporates ISO 13485:2016 by reference. The FDA also moved away from its former Quality System Inspection Technique and began using an updated medical-device-manufacturer inspection program.
That does not mean every supplier must hold an ISO 13485 certificate. It means finished-device manufacturers need a coherent quality system that controls outsourced processes and purchased products in proportion to risk. A certificate can support qualification, but it does not replace your assessment of the exact site, process, component, service, and controls involved in your product.
The commercial implication is easy to miss. Procurement cannot treat quality approval as an attachment added after price negotiation. Supplier controls affect the sourcing strategy from the beginning: who may bid, what evidence must accompany a bid, which changes require approval, how much inspection is needed, and whether a lower quoted price creates a higher total risk-adjusted cost.
A good medical device supplier audit therefore has five outputs:
- A documented view of the supplier's ability to meet your requirements.
- Objective evidence for each important conclusion.
- A list of gaps classified by risk and contractual impact.
- A clear disposition: approved, conditionally approved, or not approved.
- Controls that flow into the quality agreement, specification, RFQ, purchase terms, incoming inspection plan, and monitoring cadence.
The FDA's current QMSR overview is available at https://www.fda.gov/medical-devices/postmarket-requirements-devices/quality-management-system-regulation-qmsr. ISO describes the scope and purpose of ISO 13485 at https://www.iso.org/iso-13485-medical-devices.html. Use the current official material and your own regulatory assessment when interpreting requirements.
2. Define audit scope and supplier risk before the visit
Do not begin with a universal questionnaire. Begin with the harm that could follow if this supplier fails. A contract sterilizer, implantable-component manufacturer, calibration laboratory, packaging converter, commodity fastener distributor, and software service provider do not present the same risks. Giving them the same checklist creates paperwork, not control.
Build a one-page supplier risk profile before scheduling the audit. At minimum, record:
| Risk factor | Questions to answer | Why it changes the audit |
|---|---|---|
| Product impact | Can failure affect safety, performance, sterility, labeling, or regulatory compliance? | Determines audit depth and approval authority |
| Detectability | Will incoming inspection reliably detect a defect before use? | Low detectability raises supplier-control importance |
| Process criticality | Is the output of the process fully verifiable later? | Special or outsourced processes need deeper validation review |
| Supply exposure | Is the supplier sole-source, capacity-constrained, or difficult to replace? | Raises continuity and change-control risk |
| Data exposure | Will the supplier handle device records, personal data, drawings, or software access? | Adds security, privacy, and access-control checks |
| Regulatory role | Is the supplier performing manufacturing, sterilization, testing, calibration, storage, or distribution activities? | Shapes the evidence and competence required |
| Performance history | Are there complaints, escapes, late deliveries, repeat deviations, or weak CAPA closure? | Directs sampling toward known failure modes |
Classify the supplier as critical, major, or standard using documented rules. Avoid a score that allows a severe patient-safety risk to be averaged away by strong delivery performance. A supplier with excellent on-time delivery and uncontrolled sterilization cannot be considered acceptable because its total score happens to exceed 80 percent.
Set the audit objective after classification. It might be initial qualification, periodic surveillance, for-cause investigation, new-process approval, site-transfer approval, or requalification after a major change. Each objective requires a different sample. A for-cause audit should trace the actual failure and related lots. An initial qualification audit should test whether the system works across representative records. A site-transfer audit should focus on equipment, validation, training, equivalence, and transfer controls.
Request the pre-audit evidence seven to ten business days before the audit. Ask only for material you will review. Typical items include the quality manual, organization chart, certifications, process flow, recent audit summary, complaint and nonconformance trends, validation list, calibration status, business continuity plan, change-notification procedure, and examples of records relevant to your product.
Procurement should also provide the auditor with commercial context: projected volume, demand volatility, target lead time, tooling ownership, nominated sub-tier suppliers, forecast expectations, and any single-source constraint. Quality risk and supply risk interact. The audit team needs both.
Use a simple agenda with named process owners, required records, sample periods, and time boxes. AuraVMS can be used before the audit to issue the controlled requirement package to candidate suppliers, collect consistent technical and commercial responses, and preserve which version each supplier received. That prevents the audit team from qualifying one promise while procurement prices another.
3. The 50-point medical device supplier audit checklist
Use the following checklist as a starting framework. For every item, record status, evidence sampled, the person interviewed, and any finding reference. A yes or no without evidence is not an audit trail.
A. Quality management system and governance
- Is the legal entity, manufacturing site, and scope of supplied activity clearly identified?
- Is the quality management system scope appropriate to the products and services supplied?
- Are applicable certifications current, site-specific, and issued by a credible certification body?
- Are management responsibilities and quality authorities documented?
- Does management review include relevant quality, delivery, complaint, CAPA, audit, and supplier metrics?
- Are internal audits planned by risk and performed by competent, independent personnel?
- Are quality records retained, protected, retrievable, and disposed of under controlled rules?
Evidence to sample: current certificate and scope, quality manual, management-review minutes, internal-audit schedule, two completed audits, record-retention procedure, and overdue-action report.
B. Document, specification, and change control
- Are customer drawings, specifications, and revisions received and reviewed before use?
- Can operators access only the current approved work instruction at the point of use?
- Are obsolete documents removed or clearly prevented from unintended use?
- Are supplier-originated process, material, site, equipment, software, and sub-tier changes formally assessed?
- Does the supplier notify customers before changes that require approval?
- Are deviations, concessions, and temporary instructions time-bound and authorized?
- Can the supplier prove which revision governed any sampled production lot?
Evidence to sample: one recent drawing change, one process change, a temporary deviation, distribution records, training acknowledgment, and a completed customer-notification record.
C. Purchasing and sub-tier supplier controls
- Are the supplier's own critical vendors identified and classified by risk?
- Are sub-tier suppliers approved against defined requirements before use?
- Are purchasing specifications complete and revision-controlled?
- Are sub-tier performance and quality trends monitored?
- Are critical outsourced processes, such as sterilization or special processing, controlled and periodically reassessed?
- Are unauthorized substitutions and broker purchases prevented?
- Can the supplier trace a sampled material or service back to the approved sub-tier source?
Evidence to sample: approved supplier list, two sub-tier qualification files, recent purchase orders, scorecards, a sub-tier change, certificate verification, and traceability for a sampled lot.
D. Production, process validation, and infrastructure
- Are production processes defined with measurable acceptance criteria?
- Are process parameters controlled and recorded where output quality depends on them?
- Are processes validated when results cannot be fully verified by later inspection or testing?
- Are validation protocols approved before execution and reports approved after objective review?
- Are equipment maintenance and utilities controlled to prevent quality drift?
- Are environmental conditions monitored where they can affect product quality?
- Are line clearance, contamination control, and mix-up prevention effective?
- Are workstations, fixtures, tools, and software configured to approved versions?
- Are rework and repair instructions reviewed and authorized before use?
Evidence to sample: process flow, control plan, device or batch records, validation protocol and report, maintenance history, environmental excursions, line-clearance record, software version record, and a rework authorization.
E. Inspection, test, calibration, and release
- Are incoming, in-process, and final acceptance activities linked to current specifications?
- Are sampling plans statistically or risk justified rather than copied by habit?
- Is inspection and test equipment suitable, calibrated, identified, and protected?
- Does the supplier assess product impact when equipment is found out of tolerance?
- Are test methods validated or verified for their intended use where appropriate?
- Is final release performed by authorized personnel using complete records?
- Are certificates of analysis or conformity backed by actual controlled results?
Evidence to sample: three lots across different dates, a failed inspection, calibration certificates, an out-of-tolerance investigation, test-method records, release signatures, and source data supporting a certificate.
F. Nonconformance, CAPA, complaints, and traceability
- Is nonconforming product identified, segregated, evaluated, and dispositioned by authorized personnel?
- Are concessions communicated to the customer when required?
- Does CAPA distinguish correction, root cause, corrective action, and effectiveness verification?
- Are repeat issues detected across products, lines, and time periods?
- Are customer complaints investigated promptly and escalated according to risk?
- Can the supplier complete forward and backward traceability for a sampled lot within the expected time?
- Are recall, field-action, and crisis contacts current and periodically tested?
Evidence to sample: two nonconformances, one scrap and one use-as-is disposition, two CAPAs including effectiveness checks, complaint trend, trace exercise, mock recall, and escalation contacts.
G. People, continuity, security, and commercial execution
- Are personnel competent for assigned work, with effectiveness checked after training?
- Are temporary staff and contractors controlled to the same applicable standards?
- Does the continuity plan cover critical equipment, utilities, people, sub-tier supply, cyber events, and logistics disruption?
- Are capacity claims supported by demonstrated output, yield, staffing, and maintenance assumptions?
- Are sensitive drawings, records, credentials, and customer data protected by role-based access and backup controls?
- Can the supplier meet quoted lead time, minimum order quantity, change-notice, documentation, and service commitments consistently?
Evidence to sample: competency matrix, training-effectiveness record, contractor controls, business-impact analysis, continuity test, capacity model, recent production attainment, access list, backup test, and delivery trend.
Do not send all 50 questions to every supplier without adaptation. Mark each item critical, applicable, not applicable with justification, or informational. Add product-specific checks for sterilization, cleanroom operations, biological materials, software lifecycle controls, packaging validation, cold chain, or other relevant processes.
4. Score evidence without hiding critical failures
A useful scoring system is transparent enough that another reviewer can reproduce the result. Score each applicable item from zero to three:
| Score | Meaning | Minimum evidence expectation |
|---|---|---|
| 3 | Effective | Control is defined, implemented, supported by sampled records, and producing acceptable results |
| 2 | Generally effective | Control works but has a limited weakness that does not create immediate unacceptable risk |
| 1 | Weak | Control exists partially or inconsistently; evidence is incomplete or failures recur |
| 0 | Absent or ineffective | No reliable control, no credible evidence, or an observed critical breakdown |
Calculate the percentage only from applicable items: points earned divided by maximum applicable points. Then apply a separate critical-finding gate. This is essential because arithmetic should never neutralize a severe control failure.
Use finding classes such as:
| Finding class | Typical meaning | Sourcing consequence |
|---|---|---|
| Critical | Immediate or plausible serious safety, regulatory, integrity, or traceability risk | Do not approve; escalate and contain affected supply |
| Major | Systemic failure or material weakness that could affect conformity or continuity | Conditional approval only with accepted remediation and safeguards |
| Minor | Isolated lapse with low immediate risk and an otherwise effective system | Approval may proceed with dated correction |
| Observation | Improvement opportunity without demonstrated nonconformity | Track if useful; do not inflate it into a finding |
A sensible decision rule might require no critical findings, no unresolved majors affecting the intended product, and a minimum overall score. Your organization should define its own thresholds before the audit. Changing thresholds after seeing a supplier's price is governance theatre, not risk management.
Evidence quality matters as much as the answer. A procedure proves intent. A completed record proves execution. A trend proves sustained control. An interview explains the process but does not replace records. Triangulate important controls across all four.
Sample vertically when possible. Pick a finished lot and trace backward through release, inspection, production, equipment, training, material receipt, and sub-tier purchasing. Then trace forward from a raw-material receipt to every affected lot. This exposes handoff failures that isolated department interviews often miss.
For remote audits, identify limitations explicitly. Request live system demonstrations, timestamped records, and screen-sharing from the source system. Do not pretend a remote audit provided the same facility, housekeeping, segregation, or physical-control evidence as an on-site visit. Adjust residual risk and verification plans accordingly.
Store the final evidence package under controlled access. It should include the plan, attendance, scope, checklist, sampled records, findings, responses, CAPA commitments, approval decision, and next review date. AuraVMS can complement the quality record by preserving the exact bid invitation, requirement set, supplier response, clarification trail, and commercial comparison used after the quality gate.
5. Convert findings into CAPA, contracts, and award decisions
An audit is unfinished until its findings change a decision or a control. Sending a report and waiting for a polished corrective-action presentation does not reduce risk.
For each finding, require five elements:
- Immediate correction or containment, including affected lots and customers where relevant.
- Root-cause analysis proportionate to the problem.
- Corrective action that changes the system, not merely retrains an operator by reflex.
- An accountable owner and realistic due date.
- Effectiveness criteria that can prove recurrence risk was reduced.
Procurement, supplier quality, engineering, regulatory, operations, and security should agree on the disposition. The supplier can be approved, conditionally approved, or rejected for the defined scope. Avoid global labels. A site may be approved for a catalog component but not a validated special process; approved for prototypes but not production; or approved below a volume cap until capacity evidence is demonstrated.
Translate the residual controls into enforceable sourcing documents. Depending on risk, include:
- Exact specification and revision hierarchy.
- Approved manufacturing site and sub-tier sources.
- Required process validations and acceptance records.
- Change-notification and prior-approval conditions.
- Traceability, retention, and certificate requirements.
- Nonconformance notification and concession rules.
- Complaint, investigation, and CAPA response times.
- Audit rights and regulatory-access provisions.
- Business-continuity and cybersecurity commitments.
- Delivery, service, and escalation expectations.
Then build a bid comparison that keeps quality eligibility separate from commercial ranking. First apply the pass/fail quality gate. Next compare total landed cost, capacity, lead time, payment terms, service, resilience, and other weighted criteria among eligible suppliers. A low bid from an unqualified source is not a saving. It is deferred failure cost.
AuraVMS supports this transition by letting procurement issue the same controlled RFQ to approved suppliers, receive responses without supplier signup, and compare quotations in one place. Anonymous bidding can reduce bias during commercial evaluation. The audit decision remains owned by your quality system; the sourcing platform makes it harder for email threads, inconsistent spreadsheets, or late clarifications to undermine that decision.
After award, define monitoring triggers. These can include defect rate, lot acceptance, on-time delivery, response time, CAPA aging, complaint recurrence, unauthorized change, capacity variance, and financial or geopolitical alerts. Set escalation thresholds and reassessment rules in advance. Critical suppliers may need scheduled surveillance plus event-driven audits. Lower-risk suppliers may be managed through performance monitoring and document review.
The strongest supplier-control loop is circular: risk determines qualification depth; qualification determines sourcing eligibility; performance changes risk; and changed risk adjusts monitoring, audit frequency, and future award decisions.
6. Build a controlled audit-to-RFQ workflow with AuraVMS
Medical device sourcing often fails at the seams between quality and procurement. Quality qualifies a specific site and process, while procurement later sends a revised drawing to a sales contact, accepts an alternate material in email, or compares quotes with different assumptions. No individual step looks reckless, but the combined record cannot show that every bidder priced the same approved requirement.
Use this eight-step operating model:
- Classify supplier and product risk before market engagement.
- Prequalify candidate sites using required quality evidence.
- Audit critical candidates against an adapted checklist.
- Close or formally control findings before commercial approval.
- Freeze the approved specification, quality clauses, volumes, and bid rules.
- Issue one consistent RFQ to eligible suppliers.
- Compare compliant bids separately from exceptions and clarifications.
- Record the award rationale and feed performance back into supplier risk.
AuraVMS is designed for the RFQ portion of that model. Procurement teams can send requests, collect supplier quotations without requiring supplier accounts, use anonymous bidding where appropriate, and compare responses in a structured workspace. It costs from $5 per month, which gives smaller manufacturers a practical alternative to running regulated sourcing through scattered inboxes or buying an enterprise suite before they need one.
The product does not replace your quality management system, supplier audit, regulatory judgment, or electronic-record validation obligations. Its job is narrower and useful: create a consistent, visible trail from approved sourcing requirements to comparable supplier bids and a documented commercial decision.
For the next audit, start with the checklist above and delete everything that does not serve the defined risk. For the next award, stop rebuilding the comparison in email. Run the approved supplier RFQ in AuraVMS and keep quality requirements, supplier answers, clarifications, and price comparisons aligned.
CTA: Book an AuraVMS demo or start your next supplier RFQ at https://www.auravms.com. Give suppliers a zero-signup response path and give your procurement team a faster route from approved requirements to a defensible award.
7. Frequently asked questions
Does every medical device supplier need ISO 13485 certification?
No. The required qualification should reflect the supplier's role, the product or service, applicable regulations, your markets, and the risk of failure. Certification may be required by your policy or contract for certain supplier types, but a certificate alone does not prove that the exact site and process can meet your requirements. Verify scope, site, validity, and actual implementation.
How often should a medical device supplier be audited?
Set frequency by risk and performance rather than using one calendar rule. Consider product criticality, process verifiability, audit history, defect and complaint trends, changes, delivery performance, CAPA effectiveness, and supply dependence. A serious event can trigger reassessment before the scheduled date; stable lower-risk suppliers may justify less intensive oversight.
What is the difference between a supplier audit and a supplier questionnaire?
A questionnaire gathers declarations and documents. An audit tests implementation through interviews, observation, record sampling, and traceability. Questionnaires are useful for screening and lower-risk monitoring, but they should not be presented as equivalent to an audit when the risk requires deeper verification.
Can a medical device supplier audit be performed remotely?
Yes, when the objective and risk make remote methods adequate. Remote audits can review systems, records, interviews, and live demonstrations. They are weaker for facility conditions, physical segregation, equipment state, material flow, and other observations. Document those limits and add on-site verification or other controls when residual risk remains too high.
What should procurement do when a supplier has a major finding but is the only viable source?
Escalate through the defined cross-functional authority. Document the supply and patient risks, immediate containment, additional inspection or testing, restricted scope, CAPA milestones, contingency plan, and approval duration. Conditional approval is a controlled exception, not a way to relabel unacceptable risk. Some failures should stop sourcing regardless of scarcity.
Should audit scores be included in bid evaluation?
Use audit results first as an eligibility gate and then, where appropriate, as a risk input. Do not let a low price compensate mathematically for a critical quality failure. Among qualified suppliers, residual quality risk, capacity, delivery, service, resilience, and total landed cost can inform a weighted award model.
What records should be retained after the supplier audit?
Retain the approved audit plan, scope, agenda, participants, checklist, evidence references, findings, supplier responses, CAPA records, effectiveness verification, disposition, approvals, and reassessment date under your document-retention rules. Also retain the sourcing requirement, supplier exceptions, clarifications, bid comparison, and award rationale so the commercial record matches the quality decision.
How can procurement make the checklist usable instead of bureaucratic?
Start with supplier and product risk, remove irrelevant questions, pre-request evidence, time-box interviews, sample connected records, and write findings against defined requirements. Measure whether the audit changes qualification, controls, or monitoring. If an item cannot affect a decision and is not required evidence, question why it is on the checklist.