Audit

Audit ISO 13485.
Clarity on your system.
Control of your risks.

We assess the conformity and performance of your quality management system against ISO 13485 and applicable regulatory requirements.

Objective review

Independent and structured analysis

Systemic approach

A global view of processes and their effectiveness

Recommendations

Targeted actions to strengthen conformity and control

ISO 13485 audit: three situations, three distinct interventions

Where are you in your ISO 13485 journey? Each situation calls for a different type of intervention.

Your certification audit is approaching.

The notified body has set a date. The audit programme has been received. The team knows there are gaps: incomplete records, procedures that have not been updated since the last product change. An internal audit conducted now identifies what an external auditor will find in six weeks.

The same non-conformities keep coming back.

The last audit report listed gaps in records control or non-conformity management. Corrective actions were closed. The same findings recur at the next audit. This is not a rigour problem — it is a QMS problem. A gap addressed superficially reappears because the root cause was never addressed at system level.

You are building your ISO 13485 QMS.

First certification, or a rebuild after years of operating without a formalised system. The standard has been read; the requirements are known. What is missing: an external perspective from someone who has seen the same mistakes at other manufacturers, before the notified body does.

What we deliver, depending on where you are

You do not know exactly where you stand.

Your QMS exists, but no one has looked at the whole system for a long time. Procedures have evolved with products, records have accumulated, responsibilities have changed. Before committing to a certification or a rebuild, an honest assessment is needed.

What we deliver

A report structured by severity level, distinguishing major non-conformities, minor non-conformities, and observations. Each finding is referenced to the relevant ISO 13485 clause. A prioritised action plan with recommended timelines is attached to the report.

Diagnostic audit

You are maintaining your certification and your QMS.

ISO 13485 requires an annual internal audit covering the entire system. In practice, critical clauses (non-conformity control, complaint management, process validation) deserve more regular attention. Outsourcing this audit brings a perspective the internal team cannot have on its own system.

What we deliver

A full audit conducted in accordance with ISO 19011, a report with findings classified by severity, a review of open corrective actions. Deliverables transmitted within 10 business days after the intervention.

ISO 13485 internal audit

Your certification audit is approaching.

The notified body has set a date. A mock audit conducted under the same conditions as the real audit identifies the remaining non-conformities before the official assessment. This is not a rehearsal — it is the only way to know what an external auditor will find before they find it.

What we deliver

An audit simulation conducted by an AFNOR-qualified auditor, under certification audit conditions. Full findings report, prioritised corrective action plan, follow-up checkpoint before the audit date.

Mock audit

What we audit, and what others no longer see

The critical gaps in a medical device SME's QMS are not in clause numbers. They are in the interfaces nobody documents: between design and production, between risk management and validation, between written procedures and what actually happens at the workstation.

An auditor who has only ever audited systems does not see these areas. We see them because we built and maintained QMSs before auditing them. The difference is not methodological. It is a matter of perspective.

Our priority: verifying that conformity evidence exists where a notified body will look for it, and that the system's critical interfaces are documented — not just the clauses.

100+
field audit days

Conducted at class I to IIb manufacturers across France and Europe. Internal audits, pre-certification diagnostics and mock audits in accordance with ISO 19011.

14 years
of medical device field experience

We understand the constraints of an SME maintaining a QMS with a small team.

35
organisations audited

Manufacturers, subcontractors, importers. Classes I, IIa and IIb. Sectors: imaging, orthopaedics, in vitro diagnostics, connected devices.

FAQ

Frequently asked questions about ISO 13485 audits

It is not a legal requirement for class I devices under self-declaration. For all higher classes, notified bodies require a QMS compliant with ISO 13485:2016 as a precondition for reviewing the technical file. In practice, even for a class I device, the absence of a structured QMS makes demonstrating conformity with the GSPRs (MDR Annex I) difficult to sustain.
Yes. ISO 13485:2016 (§8.2.4) requires internal audits at planned intervals, conducted by auditors independent of the scope being audited. We offer annual contracts covering planning, audit execution and corrective action follow-up, in accordance with ISO 19011.
Yes. A notified body surveillance audit identifies findings without necessarily supporting their resolution. We intervene to support non-conformity closure, process redesign, or preparation for a re-audit.
An internal audit is conducted by the organisation itself (or a mandated external auditor) to verify QMS conformity and effectiveness. It is mandatory under ISO 13485. A mock audit is a simulation of the certification audit: conducted under the same conditions as the real audit by a qualified auditor, it identifies remaining non-conformities before the official assessment. It is not mandatory but strongly recommended, particularly for organisations that have never been audited by a certification body. A certification audit is conducted by an accredited body and results in the issuance of the ISO 13485 certificate upon conformity.

Request a mock audit with ISOFAC GROUP
A non-conformity (NC) raised by a notified body must be addressed with a structured response within the allotted timeframe, typically 30 to 90 days depending on severity. The response includes: root cause analysis (why the NC occurred), immediate corrective actions (correcting the finding), systemic corrective actions (preventing recurrence), and evidence of implementation. A minor NC not closed within the deadline may become a major NC at the next audit. ISOFAC GROUP regularly intervenes on an urgent basis in these situations, with knowledge of the specific expectations of the main European notified bodies.

Address your non-conformities with ISOFAC GROUP
A supplier audit under ISO 13485 is an assessment conducted at a critical subcontractor or supplier to verify that their quality practices meet applicable requirements. It is triggered at the initial qualification of a new supplier, at the periodic re-evaluation of critical suppliers, following a quality incident at the supplier, or in preparation for a certification or surveillance audit by a notified body. It is also a preventive tool: a proactive audit at a strategic supplier is preferable to a non-conformity discovered during the certification audit.

Plan a supplier audit with ISOFAC GROUP

Schedule a diagnostic audit

A 30-minute initial call is sufficient to assess your situation and define the scope of intervention. Quote provided within 48 hours; intervention possible within 3 weeks.

Describe your need

A written, reasoned reply within 48 working hours. If your request falls outside our scope, we point you to the right resource.