The internal audit is defined by section 8.2.2 of ISO 13485. It has two functions: to verify that the QMS is compliant with the standard and with regulatory requirements, and to verify that it is effectively implemented and maintained. A well-conducted internal audit is a management tool. A botched internal audit is a ticked box that gives a false impression of control.
The structure of the annual programme
The standard requires a planned audit programme, taking into account the status and importance of the processes, as well as the results of previous audits. In practice, an annual programme must cover all the QMS processes over the certification cycle (3 years), with a higher frequency for high-risk processes or those that have shown recent non-conformities.
The programme must be established at the start of the cycle, with dates blocked out in calendars. An audit programme that takes shape on the fly, between operational emergencies, always ends up incomplete.
The qualification of internal auditors
Internal auditors must be trained in the ISO 13485 standard, in the applicable regulatory requirements (MDR, IVDR), and in audit techniques. The ISO 19011 standard is the reference guide for conducting QMS audits.
Two requirements are non-negotiable.
Independence. Auditors cannot audit their own work. In a small organisation, this implies exchanges between functions or the use of an external auditor for the processes where internal independence is impossible to guarantee.
Practical training. Having completed an auditor training course is not enough. Experience in supervised observation — auditing in pairs with an experienced auditor before conducting an audit independently — is the condition for a genuine level of competence.
Using the results: the part that most SMEs neglect
An audit report that identifies gaps without anything happening afterwards is useless. The internal audit process must be connected to the CAPA process: each non-conformity identified generates a corrective action with an owner and a deadline, followed by an effectiveness check.
The results of internal audits feed into the management review. Management must see the trends over several cycles: do the same non-conformities reappear on the same processes? Are certain processes systematically more fragile? These trends guide the next audit programme.
An internal audit that never generates any non-conformities is suspect. Either the auditors lack rigour, or the audited scope is insufficient. A real QMS always generates opportunities for improvement.