A Day in the Life of a MedTech Quality Auditor: What Manufacturers Should Know
Simon Föger
The Types of Medical Device Audits (and Which One Tom Is Running)
Before we follow Tom through his three days, it helps to know where his audit fits. Medical device manufacturers deal with several types of audits, and they are easy to mix up:
- Internal audits – required by ISO 13485. The company audits its own QMS to find gaps before someone else does.
- Supplier audits – the manufacturer audits its suppliers to verify that purchased products and processes are under control.
- Notified body audits – certification, surveillance and recertification audits under MDR. This is what pays Tom's hotel bills.
- Unannounced audits – notified bodies are required to perform these under MDR. Product-focused, verification of ongoing production, sometimes even at a critical supplier. And no warning.
- MDSAP audits – one audit covering the requirements of five jurisdictions, with its own documentation logic.
- FDA inspections – strictly speaking not an audit but an inspection. Different legal basis, different dynamics, and since QMSR the FDA inspects against requirements built on ISO 13485.
Tom's assignment this week is a notified body surveillance audit of a manufacturer of non-active medical devices. But here is the thing: the mechanics you are about to see – the evidence trail, the sampling, the judgment calls – are the same in every audit type. Only the criteria change.
How This Story Started: A Pizza, an Old Friend, and Three Audit Days
It is Wednesday evening. I am sitting in a restaurant near my hotel, eating pizza, when someone taps me on the shoulder.
It is Tom, an old friend of mine. He looks tired in that very specific way auditors look tired: not dramatic, not broken, just quietly aware that his day is not over even though everyone else thinks it is.
Tom audits medical device companies. For the last three days, he has been auditing a manufacturer of non-active medical devices for a notified body. The client was not new to the notified body, but it was new to him. Before the audit, his project handler had told him the company was “okay” and that the quality management system seemed “quite compliant.” That sounded reassuring.
Still, anyone who has worked in medical device quality knows that “quite compliant” can mean many things. So I invited him to dinner and asked him what a MedTech quality audit really looks like from the auditor’s side. This is his story.
Audit Preparation: The Work Starts Before the Auditor Enters the Building
The official audit starts the next morning. For Tom, the work starts the evening before.
He is sitting on his hotel bed, preparing the audit trail. The audit trail is not just a personal note file. It is the foundation of the final audit report. If something is reviewed, discussed, challenged or accepted, it needs to be captured clearly enough to support the audit conclusion later.
This has become more demanding over the years.
Under frameworks such as MDSAP, auditors need to document more objective evidence. It is no longer enough to say that a topic was reviewed. The report needs to show what was sampled, what was seen and why the conclusion was justified. That is one thing manufacturers sometimes underestimate. The auditor is not only listening. The auditor is building a defensible record. And sometimes, the first issue appears before the opening meeting even begins.
The First Finding Can Happen Online
It is around 10 p.m. Tom has not yet entered the company’s facility, but he has already found something worth discussing. The company website describes the device’s intended use in one way. The instructions for use describe it slightly differently. The technical documentation, which had recently been assessed, supports the version in the IFU. That mismatch matters.
Marketing content is not separate from regulatory responsibility. Website claims, brochures and product pages can all raise questions during a medical device quality audit, especially if they suggest a different intended purpose, clinical benefit or use environment than the approved documentation.
Tom does not jump to conclusions. Maybe there is a justification. Maybe the website text is outdated. Maybe the difference is explainable. But he marks it for the opening meeting.
For the manufacturer, this is already a lesson: audit readiness does not only live inside the QMS folder. It also lives on the website.
The Opening Meeting Sets the Tone
The next morning starts well. Breakfast is good. The hotel is close enough. The coffee helps.
At 8:30, the opening meeting begins. Top management is present, which Tom sees as a good sign. When management joins the opening meeting, it usually suggests that the company takes the audit seriously and that the quality team is not being left alone to defend the system.
The agenda is familiar: audit scope, criteria, schedule, logistics, confidentiality, reporting and communication rules. Then management raises its own concerns: certification costs, timelines and delays during technical documentation assessment.
Tom listens and agrees to pass the feedback to the project handler. This is part of the job too. Audits are not only about findings. They are also moments where manufacturers explain where the certification process itself creates pressure.
After that, the facility tour begins. A short tour can be surprisingly useful. It gives the auditor a feeling for the company that documents alone cannot provide: process flow, physical constraints, handovers, storage areas, production reality and the distance between what the procedure says and how work actually happens.
How a Medical Device Audit Actually Runs: Question, Evidence, Discussion
A few hours later, the audit has found its rhythm. Question. Evidence. Follow-up question. More evidence. Discussion. Clarification. Another sample.
This is the real structure of a MedTech quality audit. Not drama. Not interrogation. Just a constant loop of trying to understand whether the quality management system works as described.
One topic is last year’s audit findings. This is always part of the audit. If a company committed to corrections and corrective actions, the auditor needs to verify whether they were implemented effectively.
In this case, the previous finding related to management review. The company had promised to revise its templates to better capture new regulatory requirements. The template had been revised. That was good. But the latest management review still did not clearly show that new regulatory inputs had been assessed. There was no documented assessment of relevant MDCG guidance. The latest revision of the MDSAP audit approach was also not clearly captured.
So what should the auditor do? Write a non-conformity? Escalate it to a major one? Accept the revised template because the regulatory person can explain the assessment verbally?
This is where audits become less mechanical than people imagine. The auditor has to judge the evidence, not the intention. A capable employee explaining the logic in the room can help, but the system still needs to retain that logic when the employee is not present. In this case, Tom accepts the explanation after the regulatory person provides a last-minute gap assessment and explains why certain guidance documents were not applicable. The company avoids a finding. But just barely.
Good Work That Is Not Documented Can Still Hurt You
This pattern appears again and again during the audit. The company is not careless. In some areas, it is strong. The R&D team knows the product well. The technical discussions are solid. People can explain why decisions were made.
The problem is that the rationale is not always documented.
This is one of the most frustrating situations in medical device audits. The team may have done the thinking, but the file does not show it. And if the file does not show it, the auditor has to ask whether the QMS really controlled the decision.
That does not mean every thought needs to become a 40-page report. But critical decisions need traceability. Why was a design change accepted? Why was a guidance document considered not applicable? Why was a risk acceptable? Why was no notified body notification submitted?
If those answers only exist in someone’s head, the audit becomes harder than it needs to be.
The Finding Nobody Wants: A Change That Should Have Been Notified
By day two or three, the atmosphere is still good. There is enough coffee and food in the audit room. The team has even started to understand Tom’s black humor.
Then comes the discussion that changes the mood.
The company made a design change that affected sterilization parameters. From the company’s perspective, the change was technically justified. The R&D team can explain the reasoning. The product still works. The process still makes sense.
But the issue is not only whether the change was technically reasonable. The issue is whether the notified body should have been informed.
Changes involving sterilization can be highly sensitive in medical device regulation. If the change affects validated parameters, safety, performance, intended use or the conditions under which conformity was assessed, the company needs to evaluate whether a notified body change notification is required. In this case, Tom concludes that the change should have been notified. That becomes a significant non-conformity.
For the manufacturer, this is painful. Not because the team did nothing. They did a lot. But they missed the regulatory consequence of the change. That is the difference between technical confidence and regulatory control.
The Closing Meeting Is Where Every Word Matters
By the time the closing meeting approaches, the client is still sending documents to clarify open points. This happens often. Teams try to close as many gaps as possible before the auditor finalizes the finding list. Tom reviews what he can. If evidence is valid, he considers it. But eventually, time is over.
Now the pressure shifts to him. The finding list must be precise. Every non-conformity needs to be written against a clear requirement. The wording matters because the client will sign the list to confirm that the findings were understood. The company may still appeal later, but the closing meeting is where the audit result becomes real. The management team challenges the findings, as expected. That is not necessarily a bad thing. A good audit can handle discussion. If a finding is justified, it should survive questions.
At the end, the general manager says something that stays with Tom: "It was a tough audit and harder than the ones before. But it was reasonable, and we learned a lot."
For an auditor, that is probably close to positive feedback.
After the Medical Device Audit, the Auditor Is Not Finished
For the client, the audit ends when the auditor leaves. For Tom, it does not.
The reports still need to be completed. The opening and closing documents need to be scanned. The finding list needs to be processed. Depending on the audit scope, there may be different reporting requirements for MDR, MDD legacy devices or MDSAP.
Some auditors finish this weeks later. Tom prefers to do it the same day or the next day, while the evidence is still fresh.
Then the next client is waiting. Tomorrow.
How to Prepare for a Medical Device Audit: Lessons from the Auditor's Side
The story is not really about Tom. It is about what the audit reveals.
A medical device quality audit does not only test whether documents exist. It tests whether the system works when someone follows the trail:
- from website claims to intended use
- from previous findings to effective corrective action
- from regulatory updates to management review
- from design changes to notified body notification decisions
- from technical rationale to documented evidence
- from audit discussion to signed findings
Most audit findings do not appear out of nowhere. They usually come from gaps that were already visible, but not fully closed.
The good news is that many of these issues can be addressed before the audit. Manufacturers can review claims, strengthen management review, document regulatory assessments, check change notification decisions and make sure rationales are visible in the file.
Audit readiness is not about making the company look perfect for three days. It is about making sure the QMS can show how decisions are made, controlled and documented when no one is there to explain them from memory.
Conclusion: A Tough Medical Device Audit Can Still Be a Useful Audit
No manufacturer enjoys receiving findings. No auditor enjoys writing them either.
But a well-run audit can do something valuable: it can show where the QMS is strong, where it depends too much on individual knowledge and where documentation does not yet match the quality of the work being done.
In MedTech, that matters. Patient safety, regulatory compliance and market access all depend on a QMS that can withstand scrutiny.
SIFo Medical supports medical device manufacturers with QMS improvement, audit preparation, MDR and ISO 13485 implementation, technical documentation and corrective action support.
If your next audit is approaching, SIFo Medical can help you look at your system before the auditor does — and close the gaps while there is still time.
Need support before your next audit? Contact SIFo Medical and make your QMS more transparent, compliant and audit-ready.
Why Your Visual Inspection Fails the Audit
The 6 steps that turn visual inspection into evidence that holds up – learn what auditors expect to see, the gaps they keep finding, and the framework that closes them.
Supplier Documentation
Stop Relying on Certificates – Learn the 5 Non-Negotiables Every Auditor Actually Probes
In this webinar, you'll learn the 5 Non-Negotiables that decide every ISO 13485 audit – and how to satisfy them without dragging your team onto the audit-prep treadmill.
Close the gaps. Pass the audit. Stay qualified.
Risk-Based Samples Sizes
Learn how to justify sample sizes using a clear, risk-based and statistically sound approach that reduces validation effort and cost.
Gain a practical framework you can confidently defend in audits across TMV, design verification, packaging, and process validation.
The 7 Deadly Sins of TMV
Stop reacting to audit findings – start leading.
Learn where MedTech companies repeatedly fail, what regulators truly expect, and how to set the right priorities – before inspections force your hand.
Join our free live webinar and walk away with:
- - Clear insights of the 7 most common mistakes in TMV
- - Practical principles you can apply immediately
- - Confidence to lead TMV decisions instead of firefighting them
Get audit-ready. Gain clarity. Take the lead. Secure your seat now!
Frequently Asked Questions
What are the different types of medical device audits?
The main types are internal audits (required by ISO 13485, performed by the company itself), supplier audits (the manufacturer audits its suppliers), notified body audits (certification, surveillance and recertification under MDR, including unannounced audits), MDSAP audits (one audit covering five jurisdictions) and FDA inspections. The criteria differ, but the mechanics – evidence sampling, interviews and documented findings – are largely the same.
What happens during a medical device quality audit?
A MedTech quality audit usually includes an opening meeting, facility tour, process review, evidence sampling, interviews, review of previous findings, documentation checks and a closing meeting where findings are presented.
What do auditors look for in a medical device quality audit?
Auditors look for objective evidence that the quality management system is implemented, effective and compliant with applicable requirements. This includes procedures, records, risk-based decisions, change control, management review, corrective actions and technical documentation.
Why can website claims become an audit issue?
Website claims can create audit issues if they do not match the intended use, instructions for use or technical documentation. Public claims may suggest a different use, benefit or performance level than the approved documentation supports.
Why is documentation so important during an audit?
Auditors need documented evidence to verify that decisions were made, reviewed and controlled. If the rationale only exists verbally, the QMS may appear weaker than the actual work behind it.
How can manufacturers prepare for a notified body audit?
Manufacturers should review previous findings, update management review inputs, check website and marketing claims, verify change notification decisions, ensure technical rationales are documented and confirm that objective evidence is easy to retrieve.
About the Author
Simon Föger is the founder and CEO of SIFo Medical. With more than a decade in medical device engineering, he has led validation, supplier qualification and compliance projects worldwide – from setting up MedTech manufacturing sites in Asia to training quality professionals at the TÜV SÜD Academy.
He shares his hands-on experience beyond consulting – in blog posts, in our newsletter, and as a guest on the Medical Device made Easy Podcast, where he talked about validation and supplier management.