ISO 9001:2015 + ISO 13485:2016 · Clause 9.2 and Clause 8.2.4
Running one audit procedure across ISO 9001 and ISO 13485 sounds like a merge. It is not. The two clauses diverge in ways that cannot both be true at once, and a procedure that papers over the differences fails one standard or the other.
Where the standards differ, this procedure takes the stricter as the house standard and says so. Device-scope content is marked inline. The scope determination comes first: general, device, or uncertain — and uncertain defaults to device scope pending determination.
ISO 13485 mandates a documented procedure; ISO 9001 does not. ISO 13485 requires interval and methods recorded; ISO 9001 requires criteria and scope. ISO 13485 states that auditors shall not audit their own work; ISO 9001 asks for objectivity without saying how. ISO 13485 measures conformity against applicable regulatory requirements; ISO 9001 does not. ISO 13485 requires the reporting of follow-up verification results; ISO 9001 requires nothing of the kind.
Nine of the ten run that way. The tenth does not: the February 2024 climate amendment applies to ISO 9001 Clauses 4.1 and 4.2, and ISO 13485 is not built on the harmonized structure and was not amended. So climate is an audit criterion for the general scope and explicitly not one for the device scope.
Appendix D is why this variant costs more: Every divergence, the house standard adopted, the alternative that was rejected, and where in the procedure it applies. It is the work a buyer cannot easily assemble alone, and it is what an auditor asks about.
| Requirement | Where it comes from | How the template handles it |
|---|---|---|
| Scope determination first | Section 2.1 | General, device, or uncertain. Uncertain defaults to device scope, which is the stricter path, pending determination. |
| Marked device content | [Q] and [M] markers | Every obligation carries the standard it comes from, inline and in headings, so nothing gets lost in the merge. |
| Appendix D integration decision record | MSI house standard | Ten divergences with the resolution and the rejected alternative for each, plus six decisions to confirm before adoption. |
| Four conformity tests, not two | Clause 8.2.4 | Planned arrangements, the standard, your own QMS requirements, and applicable regulatory requirements. Stated separately in the conclusions. |
| Verification reporting across both scopes | Clause 8.2.4 | The step almost no device system performs, applied to general-scope audits too. |
| Process interaction map with device interfaces marked | ISO 9001 Clause 4.4.1 | Editable SVG plus embedded image, with diamond markers on device-scope and regulatory interfaces. |
42 pages, editable Microsoft Word format. The process interaction map ships alongside as an editable SVG.
Both clauses require the program to take account of process importance — ISO 13485 phrases it as the status and importance of the processes and areas to be audited. The template turns it into a mechanism with four lenses, including device classification and the ISO 14971 interface.
| What varies | Higher risk | Lower risk |
|---|---|---|
| Frequency | Every cycle, re-audited early where findings recur | Longer interval, with the basis recorded |
| Depth | Walked end to end, including handoffs | Key controls sampled |
| Sample size | Large enough to support a conclusion about the system | Sufficient to confirm the control operates |
| Method | On-site, including the shift where supervision is thinnest | Records reviewed remotely |
| Auditor | Most experienced available; second auditor where contested | Any qualified auditor on the register |
Why this matters: Most programs answer the importance-of-processes requirement by adjusting frequency alone. A low-risk and a high-risk process both audited annually, same checklist, same two-hour slot, have not been differentiated in any way that changes what the audit finds.
Quality managers at organizations holding both ISO 9001 and ISO 13485, and consultants supporting them. Particularly useful where two audit procedures exist and have drifted, or where one procedure is quietly serving both and satisfying neither fully.
$249
Combined variant. Both clauses in full, with the divergences resolved and recorded.
One-time payment. Immediate download. Editable Microsoft Word format.
You can, and for some organizations that is right — particularly where the two systems are genuinely separate. What the combined variant adds is the resolution of the divergences: ten places where the two clauses cannot both be followed as written, with a stated house standard and a recorded rejected alternative. Two separate procedures leave that work to you, and leave you maintaining two documents that will drift.
Where you cannot yet classify a process as general or device — a shared production line, a support function serving both, a product whose classification is unsettled — treat it as device scope until you have determined otherwise. Device scope is the stricter path, so the risk of over-applying it is administrative, while the risk of under-applying it is a finding at inspection.
Both, and that is deliberate. It is written as a filled-in worked example so you can see what each element looks like when done properly, with bracketed placeholders wherever a value is genuinely yours to set — thresholds, roles, systems, retention periods, audit frequency. You are editing a working document rather than filling in a hollow outline.
Editable Microsoft Word (.docx). Adapt it, rebrand it, adopt it into your document control system.
It is structured to the ISO 19011:2026 clause architecture, and it implements the change ISO names in its own foreword — expanded guidance on remote auditing methods, drawing on ISO/IEC TS 17012. Everything beyond that, including the platform-specific competence prerequisite and the evidence-reliability check, is MSI's house standard drawn from 200+ audits attended, and is labeled as such in the document. ISO 19011 is guidance rather than a requirements standard, so no organization is certified against it and no clause of it can be raised as a nonconformity.
A procedure does not pass an audit; an organization does. What this gives you is a procedure that addresses every requirement of the clause with a named owner and a named record, and that describes a process people can actually follow. Conformity is demonstrated by implementation and evidence — a perfect document over a program that ignores it is still a finding. Unfilled placeholders are unmet requirements, so fill them.
Outside this procedure, deliberately. This one owns the audit program, the audit, the report, finding classification, and the follow-up verification. Root cause analysis, the corrective action record, and effectiveness evaluation belong in your corrective action procedure. The handoff is defined at one named point so nothing falls between them.
Every cross-reference is held in a table at the back rather than baked into the body text, precisely so you can renumber to your own system without unpicking the procedure.
Yes. Call MSI at 760-434-9141 to schedule a planning session.
The free Internal Audit Maturity Check scores eight elements of your audit program in under five minutes and returns an element-by-element breakdown with a priority order. It is the same maturity ladder built into this template, so it will tell you which sections matter most to you before you spend anything.
Take the free Internal Audit Maturity Check
MSI's QMS process interview course covers how to run the interviews an internal audit depends on: QMS Process Interviews
Management Systems International, LLC is a veteran-owned, female-owned ISO consulting firm co-founded in 1998. MSI has 28 years of experience, has supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
This template encodes the patterns that recur across that work — not one organization’s approach generalized, but the structural weaknesses that show up again and again.
To discuss your audit program directly, call MSI at 760-434-9141 or 888-914-9141.
© 2026 Management Systems International, LLC · All rights reserved.
Notifications