MDSAP Updates Audit Approach Document with Expanded Process-Based Guidance

The Medical Device Single Audit Program has issued an updated version of its MDSAP Audit Approach document, identified as MDSAP AU P0002.011, with revision date 3 August 2026.

The document provides specific instructions for performing audits under the MDSAP program and supports a process-based audit approach focused on defined quality management system processes, process linkages and risk management.

Consolidation of MDSAP Audit Guidance

According to the document, this revision combines the previously separate MDSAP Audit Model and Process Companion documents into a single document.

The updated document includes additional detail regarding each audited process, as well as guidance for assessing conformity.

This consolidation is intended to support auditors in conducting MDSAP audits consistently and efficiently, while maintaining coverage of applicable regulatory requirements.

Process-Based Audit Sequence

The MDSAP audit sequence follows a process approach and includes four primary processes:

  • Management;

  • Measurement, Analysis and Improvement;

  • Design and Development;

  • Production and Service Controls.

The Purchasing process is audited in conjunction with other primary processes, while Device Marketing Authorization and Facility Registration and Medical Device Adverse Events and Advisory Notices Reporting are included as supporting processes.

The document emphasises that risk management is expected to be the foundation for the MDSAP quality management system processes.

Regulatory Coverage

The MDSAP Audit Approach is designed to support a single audit covering requirements from participating regulatory authorities.

The document references requirements including ISO 13485:2016, the Australian Therapeutic Goods medical device regulations, Brazilian Good Manufacturing Practices under RDC ANVISA 665/2022, the Canadian Medical Devices Regulations, Japan’s QMS Ordinance, the U.S. Quality Management System Regulation and specific requirements from participating MDSAP regulatory authorities.

Audit Cycle and Audit Types

The document describes the MDSAP three-year audit cycle.

This includes an initial audit, two surveillance audits and a recertification audit in the third year.

It also addresses special audits, unannounced audits and audits conducted by regulatory authorities.

The updated guidance highlights that surveillance audits should include review of changes to the organisation, its QMS or its products, as well as issues related to medical device safety and effectiveness such as complaints, vigilance reports, recalls, field corrections and advisory notices.

Risk-Based Audit Focus

The document reinforces the importance of risk-based decision-making throughout the audit.

Auditors are expected to consider process linkages, risk-based sample selection and the interrelationship between nonconformities.

The audit approach also highlights the need to evaluate how risk management is applied throughout the product lifecycle, including design and development, production, supplier selection, post-market monitoring and product decommissioning.

Impact on Medical Device Manufacturers

For medical device manufacturers participating in MDSAP, the updated Audit Approach reinforces the importance of a mature, well-documented and risk-based quality management system.

Manufacturers should pay particular attention to:

  • QMS planning and process interactions;

  • management responsibility and top management commitment;

  • risk management planning and lifecycle review;

  • marketing authorization and facility registration controls;

  • complaint handling and post-market quality data;

  • adverse event and advisory notice reporting;

  • design and development controls;

  • production and service controls;

  • supplier and outsourced process controls;

  • audit readiness across the three-year MDSAP cycle.

For manufacturers, this update underlines the importance of preparing not only for individual audit tasks, but also for how evidence flows across linked QMS processes.

Anterior
Anterior

TGA Updates Guidance on Selection Criteria for Medical Device Application Audits

Próximo
Próximo

NIST Publishes Generative AI Profile for the AI Risk Management Framework