Medical devices fail users in small, everyday moments. Some might have a confusing button or alarm, while others might have a label that's easy to misread.…
Choosing suppliers is one of the biggest decisions a medical device company makes. A supplier issue does not just create a paperwork problem. It can delay a launch, trigger a recall, or put a patient at risk. That is why ISO 13485 puts so much weight on supplier management, and why a well-run supplier audit gives your team real visibility into how a partner operates. It’s important to understand what you should review during an ISO 13485 supplier audit.
Key Takeaways:
- Decide which suppliers need an audit by looking at risk level, product impact, and past performance.
- Review documentation before the audit, including quality certifications, previous audit reports, and corrective action records.
- Evaluate key areas during the audit such as process controls, staff training, and traceability records.
- Document findings clearly and follow up with the supplier on any corrective actions needed.
How Do You Decide Which Suppliers Need an Audit?
ISO 13485 expects you to apply a risk-based approach, which means the suppliers with the deepest involvement in your product deserve the closest attention. Start by sorting your suppliers into categories based on factors such as:
- Product impact: Does this supplier provide raw materials, components, or services that directly affect device safety or performance?
- Process complexity: Does the supplier perform a specialized process, like sterilization or precision machining, that is hard to verify after the fact?
- Track record: Has this supplier had quality issues, late deliveries, or nonconformances in the past?
- Regulatory exposure: Would a failure at this supplier affect your ability to meet FDA or EU MDR requirements?
Suppliers who meet these areas usually need an on-site or remote audit. Lower-risk suppliers, such as those providing standard office materials, may only need periodic documentation reviews.
What Should You Review Before the Audit Begins?
A good audit starts long before anyone walks through the supplier’s door. Preparation gives your team the information needed to ask smart, targeted questions instead of generic ones. Before the audit, pull together:
- Quality certifications: Confirm the supplier holds a current ISO 13485 certificate or equivalent, and check the scope listed on it.
- Previous audit reports: Review past findings from your own team or from the supplier’s other customers, if available.
- Corrective action history: Look at any open or closed CAPAs tied to this supplier.
- Contracts and quality agreements: Check that the terms match what you plan to verify during the audit.
- Incoming inspection data: Review rejection rates, nonconformance reports, and any trends in product quality.
This step also gives you a chance to build a checklist specific to that supplier, rather than relying on a generic template that misses what actually matters for their process.
What Should You Evaluate During a Supplier Audit?
Once you arrive at the audit, your job is to confirm that what the supplier says on paper matches what actually happens on the floor. A few areas deserve close attention:
- Process controls: Watch how the supplier executes key steps in their process, and compare it against their documented procedures.
- Staff training and competency: Ask how employees are trained on quality procedures, and check training records for a sample of staff.
- Equipment calibration and maintenance: Confirm that equipment used in production is calibrated on schedule and properly maintained.
- Traceability: Follow a batch or lot through the supplier’s system to confirm materials, in-process steps, and final inspection all connect back to clear records.
- Nonconformance handling: Ask how the supplier identifies, documents, and resolves quality issues when they come up.
- Change control: Check how the supplier notifies you of changes to materials, processes, or subcontractors.
Bring a written checklist into the audit and take detailed notes as you go. Photos, sample records, and direct quotes from staff all add weight to your final report.
How Do You Document Findings and Follow Up With the Supplier?
The audit itself is only half the job. What you do with your findings determines whether the audit actually improves supplier performance. After the audit:
- Write a clear report that separates observations, minor findings, and major findings.
- Rate each finding by severity so the supplier understands what needs attention first.
- Set deadlines for corrective action plans, typically 30 to 90 days depending on severity.
- Request evidence of correction, not just a written promise, before closing out a finding.
- Schedule a follow-up review to confirm the correction actually solved the problem, rather than just addressing the symptom.
You should keep all audit records organized and easy to retrieve. Auditors will want to see that your supplier audit program is active, documented, and produces actual results.
Bring Structure to Your Supplier Audit Program
A strong supplier audit process protects your product, your patients, and your company’s reputation. It also gives you a paper trail that stands up when regulators come asking questions. If your team needs a hand building out an ISO 13485 supplier audit program from scratch, or tightening up one that already exists, MedLaunch can walk through the details with you and help set up a process that holds up over time. Schedule a consultation with our team today.
Tags: ISO 13485, medical device compliance
Every great device deserves a clear path to market.
Connect with MedLaunch today and take the first step toward approval and success.