ISO 13485 Internal Audit Procedure Template and Guide

ISO 13485 Internal Audit Procedure Template and Guide

$149
A complete, editable ISO 13485 Clause 8.2.4 internal audit procedure. Covers the documented procedure the clause mandates, the auditors-shall-not-audit-their-own-work rule, and the follow-up step almost every device system omits: reporting the verification result.

ISO 13485:2016 · Clause 8.2.4 Internal audit

ISO 13485 is the only one of the five standards MSI supports that requires a documented internal audit procedure by name. Clause 8.2.4 states it directly, which means the procedure is itself an inspectable artifact rather than an optional convenience.

Since February 2, 2026, ISO 13485:2016 is incorporated by reference into 21 CFR Part 820. The exemption that previously shielded internal audit reports from FDA review was not carried across. Your audit reports are now inspectable records.

The step almost no device system performs

Clause 8.2.4 requires follow-up activities to include the verification of the actions taken AND the reporting of verification results. Verifying is intuitive and common. Reporting the verification is required and rare.

The mechanism is simple: by the time anyone would report it, the CAPA is closed and the audit file is filed. The requirement sits in the audit clause rather than in Clause 8.5.2, so a CAPA-driven checklist never points at it.

What this template does about it: Verification and the reporting of its result are two separate named steps, each with an owner, a recipient, and a date, recorded on Appendix A Part 8 and logged in the program register at Appendix B.

What this variant carries that the others do not

RequirementWhere it comes fromHow the template handles it
A documented procedure, mandatedClause 8.2.4The only standard in the family that requires the procedure by name. This document is written to be that artifact.
Applicable regulatory requirements as a conformity testClause 8.2.4Conformity is measured against regulatory requirements, not only the standard and your own arrangements. Most audit plans list neither.
Interval and methods recorded per auditClause 8.2.4Four elements defined and recorded, where ISO 9001 requires two. Appendix A carries all four.
Auditors shall not audit their own workClause 8.2.4Stated plainly here and nowhere else in the family. Written as a declaration on the audit plan, so its absence is a finding rather than an argument.
Records identify areas audited and the conclusionsClause 8.2.4Three named record elements. A report that lists findings and stops does not satisfy the clause.
QMSR inspectability21 CFR Part 820, effective February 2, 2026The § 820.180(c) exemption was not maintained. An exception path tells the Quality Manager to provide the records rather than withhold on the basis of the former exemption.

What you get

36 pages, editable Microsoft Word format. The process interaction map ships alongside as an editable SVG.

  • Complete internal audit procedure in editable Microsoft Word format
  • Audit program built as a controlled document, with defined re-planning triggers rather than a rolling annual calendar
  • Risk-based audit planning section, with the five levers risk actually changes
  • Per-audit objectives field, with worked examples of well-formed and poorly-formed objectives
  • Method-selection step — on-site, remote, or hybrid, chosen against the evidence the objective demands, with the rationale recorded
  • Platform-specific auditor competence prerequisite (MSI house standard)
  • Evidence-reliability check for remote and digital evidence (MSI house standard)
  • Auditor independence rules written as a decision test, not an intention
  • Finding classification scheme with stated criteria, so a finding means the same thing whoever raised it
  • Follow-up and closure path, with the handoff to corrective action defined at one named point
  • Records table with a location, an owning role, and a retention basis for every record
  • Maturity ladder — eight elements, four levels, scoreable as a self-assessment, with Level 3 named as a legitimate place to stop
  • Full clause cross-reference table mapping every obligation to where it is addressed
  • Section mapping to the ISO 19011:2026 published clause structure
  • Process interaction map — editable SVG plus the embedded image, so you can redraw it to your own process names
  • Appendix A — audit plan, built to function as the gate that opens an audit
  • Appendix B — audit program register with the re-planning log
  • Appendix C — desk-level auditor work instruction with a worked example

Risk-based audit planning, written as a mechanism

Clause 8.2.4 requires the audit program to be planned taking into consideration the status and importance of the processes and areas to be audited. That is the requirement that makes risk-based prioritization mandatory. The template turns it into a mechanism, with device classification and the ISO 14971 interface as two of the lenses.

What variesHigher riskLower risk
FrequencyEvery cycle, re-audited early where findings recurLonger interval, with the basis recorded
DepthWalked end to end, including handoffsKey controls sampled
Sample sizeLarge enough to support a conclusion about the systemSufficient to confirm the control operates
MethodOn-site, including the shift where supervision is thinnestRecords reviewed remotely
AuditorMost experienced available; second auditor where contestedAny qualified auditor on the register

Why this matters: Most programs answer the importance-of-processes requirement by adjusting frequency alone. A low-risk and a high-risk process both audited annually, same checklist, same two-hour slot, have not been differentiated in any way that changes what the audit finds.

Who this is for

Quality and regulatory managers at ISO 13485 certified manufacturers, contract manufacturers, and specification developers. Particularly useful where the audit procedure was adapted from an ISO 9001 document and never rebuilt to the device clause.

What it does for you

  • Discharge the documented-procedure mandate. Clause 8.2.4 requires the procedure by name; this is written to be that document.
  • Audit against the criteria the clause actually names. Applicable regulatory requirements are a conformity test under 8.2.4, and most audit plans list only the standard.
  • Close the verification-reporting gap. Verifying that an action worked is common. Reporting that verification result is required and rare.
  • Put accountability where the clause puts it. The management of the audited area owns the correction, not the audit program manager.
  • Write for a reader you did not expect. Under the QMSR your audit reports are inspectable, which is a reason to write them precisely rather than softly.

$149

Single-standard variant. ISO 13485:2016 Clause 8.2.4, in full.

One-time payment. Immediate download. Editable Microsoft Word format.

Questions

Are our internal audit reports really inspectable now?

Yes. Under the legacy Quality System Regulation, 21 CFR 820.180(c) exempted internal quality audit reports, supplier audit reports, and management review records from FDA review during inspection. The QMSR did not carry that exemption across, and FDA's own QMSR guidance states the agency has authority to inspect those records. The template includes an exception path covering what to do when an investigator asks.

Does the climate change amendment apply to us?

Not through ISO 13485. The February 2024 climate action amendment added climate wording to Clauses 4.1 and 4.2 of more than thirty management system standards, but ISO 13485 is not built on the harmonized structure and was not amended. The template says so explicitly, so nobody carries a climate criterion into a device audit on the assumption that it applies. If you also hold ISO 9001, it applies there.

Is this a template or a finished procedure?

Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — thresholds, roles, systems, retention periods, audit frequency. You are editing a working document rather than filling in a hollow outline.

What format does it arrive in?

Editable Microsoft Word (.docx). Adapt it, rebrand it, adopt it into your document control system.

Is this built to ISO 19011:2026?

It is structured to the ISO 19011:2026 clause architecture, and it implements the change ISO names in its own foreword — expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012. Everything beyond that, including the platform-specific competence prerequisite and the evidence-reliability check, is MSI's house standard drawn from 200+ audits attended, and is labeled as such in the document. ISO 19011 is guidance rather than a requirements standard, so no organization is certified against it and no clause of it can be raised as a nonconformity.

Will this pass an audit?

A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over a program that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.

Where does corrective action sit?

Outside this procedure, deliberately. This one owns the audit program, the audit, the report, finding classification, and the follow-up verification. Root cause analysis, the corrective action record, and effectiveness evaluation belong in your corrective action procedure. The handoff is defined at one named point so nothing falls between them.

We use different clause numbering or a different document system.

Every cross-reference is held in a table at the back rather than baked into the body text, precisely so you can renumber to your own system without unpicking the procedure.

Can you help us implement it?

Yes. Call MSI at 760-434-9141 to schedule a planning session.

Not sure where your program stands?

The free Internal Audit Maturity Check scores eight elements of your audit program in under five minutes and returns an element-by-element breakdown with a priority order. It is the same maturity ladder built into this template, so it will tell you which sections matter most to you before you spend anything.

Take the free Internal Audit Maturity Check

Related training

MSI's QMS process interview course covers how to run the interviews an internal audit depends on: QMS Process Interviews

About Management Systems International

Management Systems International, LLC is a veteran-owned, female-owned ISO consulting firm co-founded in 1998. MSI has 28 years of experience, has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

This template encodes the patterns that recur across that work — not one organization’s approach generalized, but the structural weaknesses that show up again and again.

To discuss your audit program directly, call MSI at 760-434-9141 or 888-914-9141.

© 2026 Management Systems International, LLC · All rights reserved.