Device Internal Audit Procedure Template and Guide (ISO 9001 + ISO 13485)

Device Internal Audit Procedure Template and Guide (ISO 9001 + ISO 13485)

$249
One internal audit procedure serving ISO 9001 and ISO 13485 together, with the divergences resolved rather than averaged. Includes the integration decision record showing every genuine difference and which standard won.

ISO 9001:2015 + ISO 13485:2016 · Clause 9.2 and Clause 8.2.4

Running one audit procedure across ISO 9001 and ISO 13485 sounds like a merge. It is not. The two clauses diverge in ways that cannot both be true at once, and a procedure that papers over the differences fails one standard or the other.

Where the standards differ, this procedure takes the stricter as the house standard and says so. Device-scope content is marked inline. The scope determination comes first: general, device, or uncertain — and uncertain defaults to device scope pending determination.

Ten divergences, and one that runs the other way

ISO 13485 mandates a documented procedure; ISO 9001 does not. ISO 13485 requires interval and methods recorded; ISO 9001 requires criteria and scope. ISO 13485 states that auditors shall not audit their own work; ISO 9001 asks for objectivity without saying how. ISO 13485 measures conformity against applicable regulatory requirements; ISO 9001 does not. ISO 13485 requires the reporting of follow-up verification results; ISO 9001 requires nothing of the kind.

Nine of the ten run that way. The tenth does not: the February 2024 climate amendment applies to ISO 9001 Clauses 4.1 and 4.2, and ISO 13485 is not built on the harmonized structure and was not amended. So climate is an audit criterion for the general scope and explicitly not one for the device scope.

Appendix D is why this variant costs more: Every divergence, the house standard adopted, the alternative that was rejected, and where in the procedure it applies. It is the work a buyer cannot easily assemble alone, and it is what an auditor asks about.

What this variant carries that the others do not

RequirementWhere it comes fromHow the template handles it
Scope determination firstSection 2.1General, device, or uncertain. Uncertain defaults to device scope, which is the stricter path, pending determination.
Marked device content[Q] and [M] markersEvery obligation carries the standard it comes from, inline and in headings, so nothing gets lost in the merge.
Appendix D integration decision recordMSI house standardTen divergences with the resolution and the rejected alternative for each, plus six decisions to confirm before adoption.
Four conformity tests, not twoClause 8.2.4Planned arrangements, the standard, your own QMS requirements, and applicable regulatory requirements. Stated separately in the conclusions.
Verification reporting across both scopesClause 8.2.4The step almost no device system performs, applied to general-scope audits too.
Process interaction map with device interfaces markedISO 9001 Clause 4.4.1Editable SVG plus embedded image, with diamond markers on device-scope and regulatory interfaces.

What you get

42 pages, editable Microsoft Word format. The process interaction map ships alongside as an editable SVG.

  • Complete internal audit procedure in editable Microsoft Word format
  • Audit program built as a controlled document, with defined re-planning triggers rather than a rolling annual calendar
  • Risk-based audit planning section, with the five levers risk actually changes
  • Per-audit objectives field, with worked examples of well-formed and poorly-formed objectives
  • Method-selection step — on-site, remote, or hybrid, chosen against the evidence the objective demands, with the rationale recorded
  • Platform-specific auditor competence prerequisite (MSI house standard)
  • Evidence-reliability check for remote and digital evidence (MSI house standard)
  • Auditor independence rules written as a decision test, not an intention
  • Finding classification scheme with stated criteria, so a finding means the same thing whoever raised it
  • Follow-up and closure path, with the handoff to corrective action defined at one named point
  • Records table with a location, an owning role, and a retention basis for every record
  • Maturity ladder — eight elements, four levels, scoreable as a self-assessment, with Level 3 named as a legitimate place to stop
  • Full clause cross-reference table mapping every obligation to where it is addressed
  • Section mapping to the ISO 19011:2026 published clause structure
  • Process interaction map — editable SVG plus the embedded image, so you can redraw it to your own process names
  • Appendix A — audit plan, built to function as the gate that opens an audit
  • Appendix B — audit program register with the re-planning log
  • Appendix C — desk-level auditor work instruction with a worked example
  • Appendix D — integration decision record: every divergence between the standards, what this procedure does, and what the alternative was

Risk-based audit planning, written as a mechanism

Both clauses require the program to take account of process importance — ISO 13485 phrases it as the status and importance of the processes and areas to be audited. The template turns it into a mechanism with four lenses, including device classification and the ISO 14971 interface.

What variesHigher riskLower risk
FrequencyEvery cycle, re-audited early where findings recurLonger interval, with the basis recorded
DepthWalked end to end, including handoffsKey controls sampled
Sample sizeLarge enough to support a conclusion about the systemSufficient to confirm the control operates
MethodOn-site, including the shift where supervision is thinnestRecords reviewed remotely
AuditorMost experienced available; second auditor where contestedAny qualified auditor on the register

Why this matters: Most programs answer the importance-of-processes requirement by adjusting frequency alone. A low-risk and a high-risk process both audited annually, same checklist, same two-hour slot, have not been differentiated in any way that changes what the audit finds.

Who this is for

Quality managers at organizations holding both ISO 9001 and ISO 13485, and consultants supporting them. Particularly useful where two audit procedures exist and have drifted, or where one procedure is quietly serving both and satisfying neither fully.

What it does for you

  • One procedure, both standards, no averaging. The divergences are resolved explicitly and the resolution is recorded.
  • See the decisions rather than inherit them. Appendix D lists every difference and the alternative that was rejected.
  • Default safely. Uncertain scope routes to device scope, which is the stricter path, pending determination.
  • Catch the divergence that runs backwards. Climate is a ISO 9001 criterion and not a 13485 one, and both failure modes are named.
  • Justify the design to an auditor. A recorded integration decision answers the question before it is asked.

$249

Combined variant. Both clauses in full, with the divergences resolved and recorded.

One-time payment. Immediate download. Editable Microsoft Word format.

Questions

Why not just buy both single-standard variants?

You can, and for some organizations that is right — particularly where the two systems are genuinely separate. What the combined variant adds is the resolution of the divergences: ten places where the two clauses cannot both be followed as written, with a stated house standard and a recorded rejected alternative. Two separate procedures leave that work to you, and leave you maintaining two documents that will drift.

What does 'uncertain defaults to device scope' mean in practice?

Where you cannot yet classify a process as general or device — a shared production line, a support function serving both, a product whose classification is unsettled — treat it as device scope until you have determined otherwise. Device scope is the stricter path, so the risk of over-applying it is administrative, while the risk of under-applying it is a finding at inspection.

Is this a template or a finished procedure?

Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — thresholds, roles, systems, retention periods, audit frequency. You are editing a working document rather than filling in a hollow outline.

What format does it arrive in?

Editable Microsoft Word (.docx). Adapt it, rebrand it, adopt it into your document control system.

Is this built to ISO 19011:2026?

It is structured to the ISO 19011:2026 clause architecture, and it implements the change ISO names in its own foreword — expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012. Everything beyond that, including the platform-specific competence prerequisite and the evidence-reliability check, is MSI's house standard drawn from 200+ audits attended, and is labeled as such in the document. ISO 19011 is guidance rather than a requirements standard, so no organization is certified against it and no clause of it can be raised as a nonconformity.

Will this pass an audit?

A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over a program that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.

Where does corrective action sit?

Outside this procedure, deliberately. This one owns the audit program, the audit, the report, finding classification, and the follow-up verification. Root cause analysis, the corrective action record, and effectiveness evaluation belong in your corrective action procedure. The handoff is defined at one named point so nothing falls between them.

We use different clause numbering or a different document system.

Every cross-reference is held in a table at the back rather than baked into the body text, precisely so you can renumber to your own system without unpicking the procedure.

Can you help us implement it?

Yes. Call MSI at 760-434-9141 to schedule a planning session.

Not sure where your program stands?

The free Internal Audit Maturity Check scores eight elements of your audit program in under five minutes and returns an element-by-element breakdown with a priority order. It is the same maturity ladder built into this template, so it will tell you which sections matter most to you before you spend anything.

Take the free Internal Audit Maturity Check

Related training

MSI's QMS process interview course covers how to run the interviews an internal audit depends on: QMS Process Interviews

About Management Systems International

Management Systems International, LLC is a veteran-owned, female-owned ISO consulting firm co-founded in 1998. MSI has 28 years of experience, has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

This template encodes the patterns that recur across that work — not one organization’s approach generalized, but the structural weaknesses that show up again and again.

To discuss your audit program directly, call MSI at 760-434-9141 or 888-914-9141.

© 2026 Management Systems International, LLC · All rights reserved.