Top ISO 13485 Internal Audit Findings: Common Issues and How to Fix Them

Top ISO 13485 Internal Audit Findings: Common Issues and How to Fix Them

If your internal audits are not finding issues, your system is not working.

The reality is simple: external auditors rarely find new problems. They find the problems your internal audits failed to detect.

Direct Answer: Common ISO 13485 internal audit findings include weak CAPA systems, poor document control, inadequate training records, ineffective risk management, and lack of process monitoring.

Why Internal Audit Findings Matter

Internal audits are designed to identify nonconformities before certification auditors do.

Under ISO 13485, audits are a required mechanism to verify compliance and effectiveness of the QMS. :contentReference[oaicite:0]{index=0}

Strong internal audit findings lead to:

  • Stronger CAPA systems
  • Better audit outcomes
  • Reduced regulatory risk
If your internal audit findings are weak, your QMS maturity is weak.

Top ISO 13485 Internal Audit Findings

1. Weak CAPA System

  • Root causes not properly identified
  • Corrective actions not linked to root cause
  • Effectiveness checks missing or superficial

Fix: Implement structured root cause analysis and enforce effectiveness verification.

2. Poor Document Control

  • Obsolete documents still in use
  • Missing approvals
  • Uncontrolled external documents

Fix: Enforce strict document approval, revision control, and distribution processes.

3. Incomplete or Missing Records

  • Training records incomplete
  • Missing production records
  • Untraceable documentation

Fix: Define clear record requirements and enforce retention and traceability controls.

4. Ineffective Risk Management

  • Risk files not updated
  • Risks not linked to CAPA or complaints
  • Risk analysis treated as a one-time activity

Risk management must be applied throughout the lifecycle, including monitoring and control. :contentReference[oaicite:1]{index=1}

Fix: Integrate risk management into real processes—not just documentation.

5. Internal Audits Not Effective

  • Checklist-only audits
  • No process-based auditing
  • Findings not linked to CAPA

Fix: Train auditors and shift to process-based auditing.

6. Lack of Process Monitoring

  • No KPIs defined
  • No evidence of process performance tracking
  • No trend analysis

Fix: Define measurable indicators and review them regularly.

7. Training and Competency Gaps

  • No defined competency requirements
  • Training effectiveness not evaluated
  • Personnel unaware of their impact on quality

Fix: Define competencies, train accordingly, and verify effectiveness.

8. Supplier Control Issues

  • No supplier evaluation criteria
  • Missing supplier performance monitoring
  • No quality agreements

Fix: Implement structured supplier qualification and monitoring.

9. Complaint Handling Gaps

  • Complaints not fully investigated
  • No linkage to CAPA
  • Regulatory reporting not assessed

Fix: Ensure complaints feed directly into CAPA and risk systems.

10. Management Review Weaknesses

  • Missing required inputs
  • No evidence of decisions or actions
  • Reviews treated as a formality

Fix: Structure management reviews around data, decisions, and outputs.

What These Findings Have in Common

Almost all findings come down to one issue:

  • Systems exist—but are not implemented effectively

ISO 13485 requires processes to be monitored, measured, and improved—not just documented. :contentReference[oaicite:2]{index=2}

How to Prevent These Findings

  • Shift from document-based to process-based auditing
  • Integrate CAPA, risk, and audit systems
  • Focus on effectiveness, not compliance alone
  • Audit high-risk areas more frequently
  • Track trends across audits
The goal is not to reduce findings—it is to improve the system.

Major vs Minor Findings (What’s the Difference?)

Minor Major
Isolated issue Systemic failure
Low impact High regulatory risk
Does not affect system integrity Compromises QMS effectiveness

FAQ: ISO 13485 Internal Audit Findings

What is the most common ISO 13485 finding?

Weak CAPA systems are consistently the most common finding.

Are internal audit findings required?

Yes. Internal audits must identify and document nonconformities where they exist.

How should findings be documented?

Clearly, with objective evidence, clause reference, and defined corrective actions.

What happens if internal audits find nothing?

This usually indicates ineffective auditing—not a perfect system.

Final Takeaway

The purpose of internal audits is not to pass—it is to expose weaknesses.

The companies that pass audits easily are the ones that find their problems first.

Back to blog

Leave a comment

About ISO Cloud Consulting

Structured, regulator-aligned guidance for medical-device teams building ISO 13485 systems, MDR/FDA documentation, PMS/Vigilance frameworks, and validated digital QMS environments.

Ultra-clean white–blue regulatory workspace with structured binders labeled Document Control, Risk Management, Supplier Lifecycle, Training & Competence. Faint ISO 13485 documents layered in background. Crisp clinical lighting, no people.

Need a Fully Structured, Audit-Ready QMS?

Implement ISO 13485, MDR, FDA QMSR, and complete documentation systems with validated workflows and regulator-aligned templates.

Contact Us Today