🏆 ISO 13485 & QMS

The 10 Most Frequent Nonconformities in ISO 13485 Certification Audits

A CAPA without root cause analysis, an expired calibration or missing software validation surface in nearly every ISO 13485 audit. Ten recurring nonconformities that can be neutralised before the certification body arrives.

8 min read

After dozens of ISO 13485 certification audits and preparation support engagements, certain nonconformities recur with predictable regularity. Knowing them allows you to correct them before the auditor finds them. Here are the ten I encounter most often.

Nonconformity 1: insufficient root cause analysis in CAPAs

By far the most frequent finding. The corrective action describes what was done without documenting why the problem occurred. The auditor asks for the root cause analysis. If it does not exist, or if it amounts to “operator error” or “lack of training”, it is an immediate nonconformity. A poorly identified root cause produces an ineffective corrective action: the problem recurs.

Nonconformity 2: missing or merely formal CAPA effectiveness verification

The CAPA is closed administratively without evidence that the action has eliminated the cause. The effectiveness verification must be planned before the action (criteria defined in advance), carried out after a sufficient period, and documented with objective data. “No recurrence observed” without follow-up data is not an effectiveness verification.

Nonconformity 3: internal audit programme incomplete over the cycle

Some QMS processes have not been audited over the last three years. The “difficult” processes — production, supplier control, equipment management — are often avoided in favour of documentary processes. The auditor checks the coverage of the programme over the full cycle.

Nonconformity 4: missing validation of QMS software

The software used in the QMS (ERP, manufacturing resource planning, document management tool, tracking spreadsheet) has not been validated in accordance with section 4.1.6. This is a systematic nonconformity in digital SMEs. The validation does not need to be heavy — but it must exist and be documented.

Nonconformity 5: supplier re-evaluation not performed

Suppliers were qualified initially and are no longer subject to periodic re-evaluation. Or the re-evaluations are planned but not performed. The auditor asks for the re-evaluation records: their absence is a nonconformity.

Nonconformity 6: calibration of one or more pieces of equipment expired

A measuring instrument whose calibration has lapsed at the time of the audit. This is a factual, immediate nonconformity, with no possible discussion. Setting up a reminder system (shared calendar, automatic alert) is the simplest solution to avoid it.

Nonconformity 7: management review with missing inputs

The management review does not cover all the mandatory inputs of section 5.6.2. Typically: no analysis of post-market feedback, no review of new regulatory requirements, or no data on process effectiveness. A record that amounts to a round-table discussion without data is not a compliant management review.

Nonconformity 8: documents without version, without date, or with obsolete versions still accessible

Procedures without a revision number, forms without an approval date, or obsolete versions still available on the shared network. Document control remains a classic source of audit findings, including in long-established QMSs.

Nonconformity 9: training documented but competencies not verified

The training records exist: attendance sheets, certificates. But the verification that competencies were acquired is not traced. Section 6.2 requires ensuring the effectiveness of training, not merely delivering it. A test, a quiz, an assessed practical exercise: something must prove that the competency has been acquired.

Nonconformity 10: QMS not connected to applicable regulatory requirements

The QMS does not refer to the MDR, the IVDR, or the applicable national regulations. The quality policy mentions customer satisfaction and continual improvement, without mentioning regulatory requirements. Section 4.1 requires regulatory requirements to be identified and integrated into the QMS. A QMS that ignores its regulatory context is not compliant with the 2016 version.

Topics covered:

ISO 13485 audit nonconformities ISO 13485 certification nonconformities preparing for ISO 13485 audit