MDSAP audit
Prepare your QMS for an MDSAP audit across multiple markets
Audits are a routine part of working in an industry where patient safety, product quality and regulatory compliance are critical. But what happens when one audit must address the requirements of several countries and regulatory authorities?
That is the purpose of the Medical Device Single Audit Program, or MDSAP. It allows a recognised Auditing Organization to conduct a single regulatory audit of a medical device manufacturer’s quality management system against the relevant requirements of the participating markets included in the audit scope.
The five MDSAP members represent:
- Australia – Therapeutic Goods Administration (TGA)
- Brazil – Agência Nacional de Vigilância Sanitária (ANVISA)
- Canada – Health Canada
- Japan – Ministry of Health, Labour and Welfare (MHLW) and Pharmaceuticals and Medical Devices Agency (PMDA)
- United States – Food and Drug Administration (FDA)
This can reduce the burden of undergoing several separate audits. However, it also requires your quality management system, documentation and employees to address both ISO 13485 and the applicable regulatory requirements of each market.
The European Union participates as an official observer rather than an MDSAP member. An MDSAP audit therefore does not replace the conformity-assessment requirements that apply under the EU Medical Device Regulation or In Vitro Diagnostic Medical Device Regulation.
What does an MDSAP audit involve?
The MDSAP audit model follows a structured sequence covering seven process areas:
- Management
- Measurement, Analysis and Improvement
- Design and Development
- Production and Service Controls
- Purchasing
- Device Marketing Authorization and Facility Registration
- Medical Device Adverse Events and Advisory Notices Reporting
In practice, an MDSAP audit has much in common with an ISO 13485 audit, but it also incorporates the applicable requirements of the participating regulatory authorities.
For the United States, the framework changed when the FDA’s Quality Management System Regulation, or QMSR, took effect on 2 February 2026. The QMSR incorporates ISO 13485:2016 by reference but retains supplementary FDA requirements. Manufacturers must therefore understand both the shared ISO framework and the market-specific provisions that remain.
Where do organisations commonly fall short?
Focusing on ISO 13485 alone
ISO 13485 provides the foundation, but it is not the entire audit scope. Organisations may overlook country-specific requirements relating to areas such as registration, reporting, records, labelling or market authorisation.
Treating national requirements as an appendix
Market-specific requirements must be integrated into the relevant QMS processes. It is not enough to maintain a separate checklist that employees rarely use or cannot connect to their daily work.
Leaving audit preparation to Quality Assurance
MDSAP cuts across the organisation. Management, design and development, production, purchasing, regulatory affairs and post-market functions may all need to explain how their processes operate and provide objective evidence. A well-prepared QA team cannot compensate for process owners who do not understand their responsibilities.
How can you prepare effectively?
If your organisation is accustomed to ISO 13485 audits, MDSAP may initially look like an extension of a familiar process. However, the scope is broader because it combines the standard with requirements from the relevant participating markets.
1. Conduct a targeted gap analysis
Compare your current quality management system with the requirements that apply in each MDSAP market included in your scope.
Do not stop at ISO 13485. Examine national requirements concerning areas such as device registration, market authorisation, adverse-event reporting, advisory notices, record keeping and post-market activities. Document where each requirement is addressed in your QMS and identify any gaps or conflicting procedures.
2. Assign owners to the audit processes – and test the system
Assign a responsible process owner to each relevant area of the MDSAP audit model. Then conduct an internal audit or mock audit that follows the MDSAP sequence.
Test whether procedures, records and actual working practices are consistent. Process owners should be able to explain how their activities meet both ISO 13485 and the applicable national requirements – and support their answers with objective evidence.
3. Review CAPA, post-market activities and regulatory reporting
Measurement, analysis and improvement is central to the audit model. Your CAPA system must be actively used to identify, investigate and address quality problems – not simply documented in a procedure.
Review how complaints, nonconformities, service data and other post-market information feed into risk management, trend analysis and CAPA. You should also be able to demonstrate how reportability decisions are made for each relevant market, who is responsible and how reporting deadlines are controlled.
4. Involve senior management
Senior management must do more than attend management review meetings. Auditors may assess whether management understands the performance of the quality management system, provides adequate resources and acts on quality data.
Management should be able to explain the organisation’s quality objectives, key indicators, significant risks and improvement activities – and show how the QMS supports both product safety and continued market access.
5. Learn from previous audits and current regulatory developments
Review findings and observations from previous ISO 13485, MDSAP and regulatory inspections. Look for recurring weaknesses and confirm that corrective actions have been effective.
Also monitor current information from the relevant authorities, including updated MDSAP documents, regulatory guidance, inspection observations and FDA warning letters. Requirements and regulatory expectations evolve, and your audit preparation should reflect the rules in force at the time of the audit.
A successful MDSAP audit is not simply about obtaining or retaining a certificate. It is about demonstrating that your organisation manages quality systematically and can meet the regulatory requirements that apply across its markets.
Read more:
Contact
Get help now
Find relevante quality courses and further education.