Post-market Services

Regulatory, Quality and Information Security Audits

Ensure compliance with a full range of expert-led audits for

Services

  • AI Quickscans of technical documentation and QMS documentation
  • FDA Mock audits
  • ISO/IEC 27001, NEN 7510-1, QMSR, MDSAP, ISO 13485 Internal Audit (optional: supported using AI to ensure a full scope check)
  • Supplier & Subcontractor audits
  • Due Diligence audits
  • Regulatory audits for medical devices and External Audit support
Our Specialty

What Do We Offer?

Management systems such as a Quality Management Systems (QMS) or Information Security Management System (ISMS) continue to be subject to both medical device internal audit and external audits after the initial certification has been granted by a certification body or Regulatory Authority.

Information Security Management Systems per ISO/IEC 27001 and NEN 7510-1 require the organization to execute internal audits on a periodic basis to assess the effectiveness of the management system, and the implemented information security technical and organizational controls.

Quality Management Systems per ISO 13485, ISO 9001, QSR or QMSR, MDSAP and ISO/IEC 42001 similarly require the organization to execute internal audits on a periodic and planned basis to assess the compliance of the QMS, the implemented quality controls, procedures and changes implemented over time.

In addition, organizations may wish to exercise control over suppliers and subcontractors (supplier audits) or execute due diligence audits to understand the level of regulatory compliance to applicable regulations from an external party prior to entering into an acquisition.

At MedQAIR, our team of qualified auditors is ready to support Quality, Regulatory, Information Security and Privacy audits. Together with our expert auditors, we help draft an audit plan, plan for the relevant dates, execute the (hybrid) audits, and provide a detailed report with the relevant findings from the audit.

Relevant Resources - EU

  • MDCG Guidance on Using MDSAP Audit Reports for MDR/IVDR Surveillance Audits

Relevant Resources - US

  • FDA QMS Regulation Final Rule – FAQs
  • FDA Quality System (QS) Regulation & Medical Device CGMP

Relevant Resources - Others

  • IMDRF: MDSAP documents
Blog Hub

Latest Insights & Updates

Explore our blog posts on MDR, IVDR, and EU AI Act medical device compliance to stay ahead of regulatory changes.

Frequently Asked Questions

Find answers to common questions about our services, compliance processes, and how we can assist your business.

Why are internal audits important for medical device organisations?

Internal audits help organisations assess whether their quality, regulatory, information security, and operational processes remain compliant with applicable requirements. They also help identify gaps, verify implementation of procedures, and prepare for external audits and regulatory inspections.

Which standards and regulations typically require internal audits?

Internal audits are required or expected under various frameworks, including ISO 13485, ISO 9001, ISO/IEC 42001, ISO/IEC 27001, NEN 7510-1, MDSAP, FDA QMSR, and other management system standards. Audit activities help demonstrate ongoing compliance and system effectiveness.

How often should internal audits be performed?

Audit frequency depends on the applicable standard, organisational risks, previous findings, regulatory obligations, and business activities. Most organisations establish a risk-based audit programme that covers all relevant processes within a defined audit cycle. At the minimum the expectation is to execute audits on a yearly basis.

Can MedQAIR support ISO 13485, MDSAP, and FDA QMSR audits?

Yes. MedQAIR supports internal audits and audit preparation activities for quality management systems aligned with ISO 13485, MDSAP, FDA QMSR, and related regulatory frameworks.

What is the difference between an internal audit and an external audit?

Internal audits are conducted on behalf of the organisation to assess compliance and identify improvement opportunities. External audits are performed by certification bodies, notified bodies, regulators, customers, or other independent parties to evaluate compliance against specific requirements.

Can audits be performed remotely or in a hybrid format?

Yes. Depending on the audit scope, available documentation, and applicable requirements, audits may be performed on-site, remotely, or through a hybrid approach that combines both methods.

What is a supplier audit and when is it necessary?

Supplier audits assess whether suppliers and subcontractors maintain appropriate controls, quality processes, and compliance activities. They are often used for critical suppliers whose products or services may impact product quality, safety, cybersecurity, or regulatory compliance.

What is regulatory due diligence in the medical device industry?

Regulatory due diligence involves reviewing compliance status, quality systems, technical documentation, regulatory approvals, and operational risks before acquisitions, investments, licensing activities, or strategic partnerships.

Can MedQAIR review technical documentation as part of an audit?

Yes. Audit activities may include reviewing technical files, quality system documentation, software lifecycle records, cybersecurity documentation, clinical evidence, and other regulatory documentation relevant to the audit scope.

How do audits support MDR and IVDR compliance?

Audits help organisations assess whether processes, documentation, supplier controls, post-market activities, and management system requirements remain aligned with MDR and IVDR expectations throughout the product lifecycle.

Can audits include information security and cybersecurity requirements?

Yes. Information security audits may assess compliance with ISO/IEC 27001, NEN 7510-1, cybersecurity controls, supplier security management, vulnerability management processes, and related governance activities.

What are the most common findings identified during audits?

Common findings include incomplete procedures, insufficient records, gaps in supplier oversight, inadequate training evidence, weak change management controls, inconsistencies in technical documentation, and deficiencies in cybersecurity or risk management processes.

How should organisations prepare for an upcoming regulatory or certification audit?

Preparation typically includes reviewing procedures, ensuring documentation is current, closing known gaps, verifying training records, assessing supplier controls, and conducting internal audits or mock audits to identify potential findings before the external assessment.

Can MedQAIR provide independent auditors and audit support resources?

Yes. MedQAIR provides qualified auditors and specialists to support internal audits, supplier audits, information security audits, due diligence assessments, audit readiness activities, and remediation programmes across medical device, software, and AI-enabled healthcare technologies.

Book a Free 30-Minute Consultation

Schedule a Meeting With Our Experts

Get a Free Consultation