ISO 13485 supplier audits for medical device manufacturers
...we carry out quality audits for you!
What is it and who does it apply to?
An ISO 13485 supplier audit is the assessment, on site or on records, that a supplier or subcontractor meets the quality and regulatory requirements your device needs: specifications, process control, traceability, change and non-conformity management. It is the evidence behind your approved supplier list.
It is needed by manufacturers who outsource critical processes (contract manufacturing, sterilisation, software, test laboratories, critical components), by importers who must verify non-EU manufacturers, and by any company wanting an independent internal audit of its own system before the notified body arrives.
At MeDev Consulting we select, periodically evaluate and audit suppliers under EN ISO 13485 and EN ISO 9001, in Spain and abroad, and deliver reports with classified findings and an action plan.
What the regulation requires
EN ISO 13485 requires documented criteria to evaluate, select and monitor suppliers, proportionate to the risk their product or service poses to the medical device, and records of those evaluations. For critical suppliers signed quality agreements are expected.
Regulation (EU) 2017/745 (MDR) makes the manufacturer responsible for its subcontractors and critical suppliers: the notified body may audit them as part of the quality system assessment, including unannounced. Importers and distributors in turn have verification duties over the devices they place on the market and distribute.
Guidance MDCG 2022-17 recognises hybrid audits, partly on-site and partly remote, a format that can also be applied to suppliers when the risk allows it.
What we do at MeDev Consulting
Supplier Evaluation
We do the audits for you!
Selection
We select the best suppliers for your products, subprocesses, and services.
Periodic Evaluation
We periodically evaluate the performance and compliance of each supplier.
Regulatory Audit
We audit under EN ISO 13485 / 9001 standards according to your needs.
MeDev Consulting selects the best suppliers for your products, subprocesses, and services, evaluates them periodically and audits them under EN ISO 13485 / 9001 standards according to your needs.
Our qualified auditors guarantee a rigorous and documented process, providing detailed reports with findings, non-conformities, and opportunities for improvement.
How we work
- 1
Plan and checklist
We define scope, criteria and checklist according to the supplier's risk and your device's requirements.
- 2
Audit
On site, remote or hybrid, in Spain or abroad, with auditors qualified in EN ISO 13485 / 9001.
- 3
Report
Classified findings (major, minor, observations), evidence and recommendations, ready for your file.
- 4
Follow-up
We review the supplier's action plan and verify its closure to maintain the approval.
Frequently asked questions
Which suppliers do I have to audit?
The critical ones: those affecting the safety, performance or sterility of the device, such as contract manufacturers, sterilisers, laboratories, suppliers of critical components or of software. The rest are evaluated with lighter criteria. The classification must be justified in your quality system.
Is it enough to ask the supplier for its ISO 13485 certificate?
It is useful evidence, but it does not replace your own evaluation: the certificate says the supplier has a quality system, not that it meets your specifications or controls its product. For critical suppliers an audit or equivalent evidence is expected.
How often must a supplier be audited?
According to risk and track record. The usual pattern is an initial qualification audit, periodic re-evaluations and extraordinary audits after incidents or relevant changes at the supplier.
Can audits be remote or hybrid?
Yes. MDCG 2022-17 defined hybrid audits, partly on-site and partly remote, for notified bodies, and the same approach is valid for auditing suppliers when the risk allows it and records are accessible.
Can the notified body audit my suppliers?
Yes. The MDR provides for notified body audits of subcontractors and critical suppliers, including unannounced ones. That is why it pays to have them evaluated and under signed quality agreements before that visit comes.
I am an importer: do I have to audit the non-EU manufacturer?
The MDR requires you to verify that the manufacturer complies: CE marking, declaration of conformity, authorised representative, UDI and labelling. An audit is the most solid way to do so and the one that best protects you in an inspection.
What is a supplier quality agreement and why does the auditor ask for it?
The document that sets responsibilities, specifications, change notification, record control and the right to audit. ISO 13485 requires it for critical suppliers and it is the first thing an auditor reviews.
Related news
MDCG 2022-17 Hybrid audits
MDCG 2022-17 defines notified body hybrid audits: partly on-site and partly remote, and the requirements for carrying them out.
ISO publishes the new ISO 9001:2026
ISO 9001:2026 replaces the 2015 edition: quality culture, risks and opportunities, change management and a three-year transition ending on 30-09-2029.
IVD controls without assigned values: what MDCG 2020-16 rev.5 clarifies
Revision 5 of MDCG 2020-16 (September 2026) changes only Rule 7 of the IVDR. We explain where the class B boundary now lies for quality control materials.