In an increasingly globalised medical device market, regulatory harmonisation is more critical than ever. The Medical Device Single Audit Program (MDSAP) offers an innovative approach by allowing a single regulatory audit to satisfy the requirements of multiple jurisdictions. For medical device manufacturers, understanding the structure, types, and intent of MDSAP audits is essential for successful certification and sustained compliance.
Based on the principles laid out in the MDSAP Audit Approach Document Version 009, this comprehensive guide explores the full three-year MDSAP audit cycle, including Initial Certification, Surveillance, Recertification, and Special Audits—including Unannounced and Regulatory Authority-conducted audits.
The MDSAP audit cycle spans a three-year period, designed to ensure ongoing compliance with ISO 13485:2016 and participating regulatory authorities’ requirements. It consists of:
Each of these audit stages has defined goals and methodologies governed by ISO/IEC 17021-1:2015 and tailored through MDSAP-specific procedures.
The Initial Certification Audit is a full assessment of a medical device organisation’s Quality Management System (QMS) and is conducted in two stages.
In line with Clause 9.3.1.2 of ISO/IEC 17021-1:2015, and considering all relevant MDSAP audit process activities and applicable regulatory requirements, this stage focuses on reviewing the organisation’s QMS documentation, including:
This stage may be performed off-site and lays the groundwork for audit planning.
In line with Clause 9.3.1.3 of ISO/IEC 17021-1:2015, and incorporating all applicable MDSAP audit process tasks, this on-site audit evaluates the implementation and effectiveness of the QMS, including:
Sites included in Stage 2 must appear on the certification; off-site-reviewed locations are not eligible for listing.
Conducted in Years 2 and 3, surveillance audits are partial evaluations, designed to monitor the QMS between initial certification and recertification. They align with Clause 9.6.2.2 of ISO/IEC 17021-1:2015 and Clause 9.6.2 of IMDRF/MDSAP WG/N3:2016, and use applicable MDSAP Audit Process tasks and include:
Each surveillance audit need not assess all MDSAP criteria, but across both years, all critical aspects must be covered.
Changes in legislation or internal QMS modifications may trigger the need for a Stage 1 audit within the surveillance cycle.
At the end of the 3-year audit cycle, the Recertification Audit (or Re-audit) validates the continued suitability and performance of the QMS.
In accordance with Clause 9.6.3 of ISO/IEC 17021-1:2015, and incorporating all applicable MDSAP audit process tasks, this audit assesses:
This audit also ensures:
If significant changes have occurred, such as in response to new regulatory legislation, a Stage 1 audit may be required.
Special audits fall outside the routine audit cycle, triggered by circumstances requiring urgent or focused assessments. As specified in ISO/IEC 17021-1:2015 Clause 9.6.4, along with any additional requirements set by the MDSAP-recognised auditing organisation and/or, where applicable, the MDSAP participating regulatory authorities, these audits may include:
Audit reports from special audits conducted at the request of regulatory authorities must be submitted within 15 days.
A subset of special audits, unannounced audits, is executed in response to high-grade nonconformities or regulatory red flags. These audits serve as:
The IMDRF/MDSAP WG/N3:2016 document defines the criteria applicable to these audits.
Apart from audits conducted by recognised MDSAP Auditing Organisations, participating regulatory authorities themselves may conduct audits at any point, especially:
These audits play a pivotal role in quality oversight and ensuring the MDSAP system functions as intended.
For sterile medical devices, the MDSAP audit must include a thorough assessment of sterilisation controls during:
Surveillance audits can verify the maintenance of validated sterilisation parameters, but remote reviews alone are not sufficient. On-site verification remains critical.
Auditors must follow audit trails that may lead back to documents assessed remotely to ensure a comprehensive evaluation of sterility control measures.
For medical device manufacturers, MDSAP certification is more than a regulatory checkbox—it’s a testament to global quality, safety, and compliance. Understanding the MDSAP audit cycle and the types of audits it encompasses enables organisations to:
By embedding MDSAP principles into everyday QMS operations, organisations not only achieve regulatory harmony across borders but also cultivate a culture of continuous quality improvement.
At Maven Profcon Services LLP, we specialise in providing comprehensive support for all types of MDSAP audits, including Initial Certification, Surveillance, Recertification, Special, and Unannounced audits. Our expert team ensures your Quality Management System is audit-ready and fully aligned with ISO 13485:2016 and all applicable regulatory requirements from participating MDSAP jurisdictions. From gap assessments and document preparation to mock audits and on-site audit support, we guide you through every step of the MDSAP audit cycle. Partnering with Maven means securing your compliance, reducing regulatory risks, and enhancing confidence with global regulators and stakeholders. Let us help you navigate MDSAP with confidence.
Vijay Kureel
Are You Looking For Medical Devices Certifications?
Contact Us