A procedure can be complete on paper and still fail to show that a medical-device quality system works in practice. An ISO 13485 certification audit checks whether documented controls are implemented and supported by traceable evidence, such as records showing how processes operate. Preparing well means checking that evidence against actual work, not just gathering documents.
Certification audits and regulatory assessments have different purposes. A certification audit independently assesses a quality management system (QMS) against the standard. It is not a regulatory inspection or product approval.
This guide explains what to expect at stage 1 and stage 2, and how surveillance and recertification fit into the certification cycle. It also provides practical ways to organise evidence, check records against current practice, and decide whether a certification route fits your organisation’s scope. Use it to identify what will be assessed and prepare the people, processes, and records involved.
Key Takeaways
- An ISO 13485 certification audit assesses whether your QMS conforms to applicable requirements. It does not replace regulatory assessment or product approval.
- Map process owners and evidence for design controls, supplier management, traceability, and corrective action to the activities in your certification scope.
- Plan for the different purposes of stage 1, stage 2, surveillance, and recertification.
- Build readiness by confirming scope, assigning process owners, reviewing implementation, organising records, and addressing known gaps.
- Compare certification routes by scope fit, independence, geographic coverage, audit planning, and clarity of reporting.
What an ISO 13485 certification audit assesses, and what it does not
Start by defining what you want the assessment to cover. An ISO 13485 certification audit evaluates whether the organisation’s QMS conforms to applicable requirements within the agreed scope. Auditors look for evidence that relevant processes are defined, implemented, and maintained. Procedures alone are not enough to demonstrate that a process is working.
Certification evaluates the quality system, not a blanket guarantee for every device. A certificate does not approve a product, confirm that every device meets every applicable requirement, or grant regulatory authorisation or market access. Those decisions depend on the jurisdiction and product-specific pathways.
Which organisations and activities may fall within audit scope?
Scope reflects the organisation’s activities, sites, and declared QMS boundaries. Depending on the work performed, relevant activities may include design and development, production, storage, distribution, or servicing. A manufacturer’s scope may differ from that of an organisation performing selected activities, so the boundaries should accurately describe the operations covered by the system.
Outsourcing an activity does not automatically remove its quality-system interfaces from consideration. Auditors may examine how the organisation controls relevant outsourced processes and suppliers, including how responsibilities, requirements, and records are managed. For example, if a supplier performs a process that could affect product conformity, the organisation’s controls and evidence for that relationship may be relevant to the audit.
Certification audit versus regulatory or product assessment
A certification audit assesses the QMS against the standard within its defined scope. A regulatory assessment, product conformity assessment, or market authorisation process serves a different purpose and may examine product-specific evidence and jurisdictional requirements. The processes can relate to the same quality activities, but a QMS certificate should not be treated as a substitute for obligations that apply to a device or market.
Requirements and terminology vary by jurisdiction, so identify the relevant regulatory route separately when planning market activity. Certification provides independent evidence about the management system; it does not automatically establish conformity with EU MDR, UKCA, or other market-access requirements. The ISO 13485 Wikipedia overview offers background on the standard and its relationship to quality management. For context on third-party assessment, see management-system certification.
Keep the distinction clear in internal planning. Define the organisation, sites, and activities the certificate is intended to cover, then map any separate product or regulatory assessments relevant to your markets. This helps prevent certification scope from being mistaken for product approval and aligns audit evidence with the QMS boundaries.
What auditors examine: processes, records, and implementation evidence
Auditors assess how responsibilities, controls, and records connect across the QMS. During an ISO 13485 certification audit, they may follow process inputs, decisions, outputs, and retained records rather than reviewing procedures in isolation. The evidence they examine depends on the organisation’s activities and declared scope.
Objective evidence is a record, observation, or other verifiable information that supports an audit finding. It might include an approved procedure, a completed record, an interview supported by consistent practice, or direct observation of a process. A document can describe the intended method, but it cannot by itself show that the method is being followed.
How auditors follow a process through the quality system
Consider supplier control. An auditor may identify who approves suppliers, review the selection criteria and documented controls, then sample records showing how a supplier was assessed and monitored. They may also examine how the organisation responds when a supplier issue affects a product or process. The aim is to see whether assigned responsibilities and documented controls are reflected in real decisions and retained evidence.
Auditors may trace other in-scope processes in the same way. They can compare a procedure’s requirements with implementation records and ask relevant personnel to explain their roles. Consistency between the approved method, completed records, and staff understanding helps demonstrate control. Where a current, approved document is required, it is necessary, but it is not proof on its own that the process is consistently implemented.
Medical-device controls that need coherent evidence
Evidence should connect across applicable controls. Depending on the organisation’s scope, auditors may examine how risk-management activities inform design and development, how supplier controls address relevant risks, and how traceability is maintained through applicable operations. The Official ISO 13485:2016 Standard is the authoritative reference for the standard’s requirements. The audit assesses how those requirements apply to the organisation’s system and scope.
Complaint handling and corrective action also need a clear record trail. For a sampled issue, records might show how it was received, assessed, investigated, and addressed, including whether actions were completed and their effectiveness evaluated where required. Auditors may check that the reported problem, decisions, assigned responsibilities, and follow-up evidence are consistent. A closed record should reflect the actual outcome, not just an administrative status.
To prepare, select representative records across relevant activities. Check that they identify owners, dates, decisions, approvals, and outcomes where applicable. Resolve inconsistencies between procedures and practice, and make sure staff can explain how their work supports controlled processes. For an overview of independent assessment, see management-system certification.
Stage 1, Stage 2, surveillance, and recertification: how the audits differ
Preparation depends on where the organisation is in its certification cycle. Stage 1 and stage 2 are the initial certification assessments. If certification is granted, periodic surveillance and recertification support continued assessment during the stated three-year cycle. The specific arrangements depend on the certification programme, scope, and applicable requirements.
| Assessment | Purpose | Typical focus | Preparation priority |
|---|---|---|---|
| Stage 1 | Initial review of the quality management system and readiness for further assessment | System scope, documented arrangements, and areas that may need attention before stage 2 | Make scope and system information accessible; identify readiness concerns and plan how to address them |
| Stage 2 | Initial assessment of whether the system is implemented and conforms within scope | Operational processes, records, responsibilities, and implementation evidence | Ensure process owners can explain and demonstrate their processes using current records |
| Surveillance | Periodic assessment of continuing conformity after certification | Relevant parts of the system and changes or issues within the certification scope | Maintain current records and ensure changes to processes, sites, or responsibilities are controlled |
| Recertification | Further assessment at the relevant point in the certification cycle | Continuing conformity and the system’s suitability across its certified scope | Review system performance, changes, and open issues in line with programme requirements |
What stage 1 and stage 2 are intended to establish
Stage 1 is an initial review, while stage 2 assesses implementation of the QMS. Their precise focus and terminology can vary by certification programme. Use readiness concerns identified during the initial review to guide later audit preparation. Assign owners to the issues, address gaps, and organise the evidence needed for stage 2.
Neither stage guarantees certification or follows a universal fixed duration. The certification body determines arrangements in line with the applicable programme and scope. Prepare for an ISO 13485 certification audit by demonstrating system readiness and providing credible evidence, rather than assuming a particular outcome or timetable.
Why surveillance and recertification matter after certification
Certification is not a one-time assessment. Periodic surveillance provides continued assessment during the certification cycle, while recertification is a further assessment at the relevant cycle point. Maintain the system between audits, keep records current, and control changes that affect certified activities instead of preparing evidence only when an assessment is approaching.
The management system certification process provides context for how assessments fit within certification. When planning each assessment, use the applicable programme requirements and scope to determine the arrangements and preparation needed.

How to prepare for an ISO 13485 certification audit
Effective preparation is a review of how the QMS operates, not an attempt to script an audit. Follow a practical sequence: confirm the certification scope, assign owners to in-scope processes, review implementation, organise representative records, and address known gaps. This helps the audit team find relevant evidence while keeping preparation grounded in normal work.
- Confirm scope. Check that relevant personnel understand the activities, sites, and system boundaries to be assessed.
- Assign process owners. Make responsibility clear for each in-scope process and its records.
- Review implementation. Compare actual practice with applicable controls. Review management review and internal audit records as evidence of oversight where relevant.
- Organise records. Make representative evidence current, retrievable, and clearly connected to the process it supports.
- Address known gaps. Record issues, assign responsibility, and retain follow-up evidence for actions taken.
Before relying on references in audit materials, verify the applicable standard edition, accreditation details, and jurisdiction-specific regulatory sources. These references can change and serve different purposes. Certification assesses the QMS within scope, while regulatory obligations depend on the relevant market and activities.
Build an audit-ready evidence trail
Make a simple map linking each in-scope process to its owner, documented controls, and representative records. Check that records are complete, retrievable, consistent with one another, and clearly related to the process being assessed. For example, confirm that an approval record can be linked to the applicable controlled document and that the responsible role is identifiable.
Prepare staff to describe their actual responsibilities and show how they carry out their work. Do not script answers or coach employees to repeat set phrases. Clear, accurate explanations supported by normal records provide a more reliable picture of implementation.
Address gaps and coordinate the audit team
Maintain a gap log that records the issue, accountable owner, planned or completed corrective action, and follow-up evidence. Prioritise actions according to their relevance to the system and scope, and do not present an unresolved issue as closed. Internal audit competence supports preparation, and relevant personnel can develop their skills through lead auditor training.
Coordinate access to the personnel, records, and sites included in the agreed scope. Confirm who will support each process discussion and how records will be retrieved, while preserving normal working arrangements. This is an internal readiness activity, not a guarantee of certification or a substitute for independent assessment.
For an independent assessment of your medical-device quality management system, explore ISO 13485 certification.
Choosing an ISO 13485 certification audit route and next steps
Choose a certification route that matches the boundaries of the quality system and the activities you want assessed. Start by checking whether the proposed scope reflects actual operations, including relevant sites and locations. If your organisation operates in more than one region, consider geographic coverage and how audit planning will account for the locations and activities in scope. A certificate does not fulfil every jurisdiction’s regulatory requirements.
Independence is central to third-party certification. Also look for clear information about the scope, the purpose of each audit stage, the evidence required, and how findings will be reported. These factors help you plan access to personnel and records, understand the assessment process, and distinguish certification decisions from product or regulatory assessments.
Factors that make an audit route fit the organisation
Compare the proposed route against four practical considerations: activities and sites in scope, stakeholder expectations, geographic reach, and the clarity of audit planning and reporting. A route that reflects the quality system’s real boundaries gives the assessment a useful focus. An unclear scope can leave teams uncertain about which processes or locations are included. Use these decision factors alongside your organisation’s operational needs when comparing certification bodies.
Before proceeding, define the certification objective and identify customer or stakeholder requirements that influence the decision. Keep certification separate from any product conformity or market-access process. This makes it easier to explain what the audit will assess and what it will not establish.
Plan the next step with International Associates Limited
Prepare a concise summary of your organisation’s activities, sites, quality-system boundaries, and certification objective. This gives audit planning a practical starting point and helps align the assessment with the system under review. International Associates Limited is a UK-based certification and auditing body with a global network and provides ISO 13485 medical-device certification.
The management-system certification process explains how certification is planned and maintained. The organisation’s scope and audit programme determine the applicable arrangements. Keep references for the standard, accreditation, and relevant jurisdictions distinct, since each serves a different purpose.
With your scope and objective defined, discuss your requirements for an ISO 13485 certification audit.
Make audit readiness part of operational planning
Make readiness a recurring part of quality-system planning, not a short-term exercise before an assessment. Use existing oversight activities to review whether responsibilities, records, and planned changes remain aligned with current operations. This supports a more sustainable approach to maintaining the system between audits.
As your organisation’s activities evolve, revisit whether the certification objective still reflects its priorities and stakeholder expectations. Reviewing upcoming changes can help identify when audit planning or internal coordination needs attention. Keep product-specific regulatory work distinct from certification planning.
For an ISO 13485 certification audit, discussing the intended scope and objectives early helps establish a sound basis for assessment planning. International Associates Limited provides independent certification and auditing, with a focus on structured assessment and a clear understanding of the system under review.
When you’re ready, discuss your ISO 13485 certification requirements.
Frequently Asked Questions
What does an ISO 13485 certification audit check?
An ISO 13485 certification audit checks whether the organisation’s QMS conforms to applicable requirements for the activities within scope. To prepare, identify who can explain how connected responsibilities work in practice. For example, consider how a change raised by one team is communicated to other affected roles. This helps show how the system operates across teams, rather than treating every procedure or department in isolation.
What is the difference between stage 1 and stage 2 of an ISO 13485 audit?
Stage 1 reviews the system and readiness; stage 2 assesses implementation. Assign an owner to each point raised during stage 1 and track any resulting document or operational updates. Before stage 2, check that affected teams use current approved versions and can explain changes relevant to their work. The certification programme determines the precise arrangements.
How often are ISO 13485 surveillance audits conducted?
Surveillance audits are periodic, and the applicable certification programme sets the schedule. Record planned dates from the certification arrangements in a shared calendar and assign an owner to coordinate internal preparation. If operational changes could affect the audit plan, record what changed and when so the organisation can discuss the impact during planning.
Is ISO 13485 certification the same as medical-device regulatory approval?
No. Certification and regulatory approval are separate processes. To keep responsibilities clear, maintain an internal reference showing which roles oversee the QMS certificate and which coordinate device-specific regulatory activities in each intended market. This does not replace jurisdiction-specific assessment, but it helps prevent teams from treating a certificate as evidence that a separate product-related step is complete.
What evidence should we prepare for an ISO 13485 certification audit?
Organise evidence so the team can retrieve records without relying on one person’s memory. A simple index can identify each record’s owner, location, version or date, and related process. Test the retrieval route before the audit, including access permissions for electronic records. This can reveal missing permissions or unclear file names before they delay access.
How long does an ISO 13485 certification audit take?
There is no single duration for every organisation. The audit plan depends on the agreed programme and scope, including the activities and locations to be assessed. For scheduling, identify when key personnel or records may be unavailable, such as during planned site closures, and raise those constraints during audit planning. The certification body’s confirmed arrangements provide the basis for coordinating the assessment calendar.