Supplier Audit Checklist for Medical Device Sourcing

This guide provides a practical, copyable checklist for conducting supplier audits on medical devices. It covers quality management systems, risk controls, materials, and documentation. It helps buyers identify red flags and verify compliance before awarding contracts.
- Use this checklist to verify supplier quality management systems before awarding contracts.
- Focus on risk controls, material traceability, and change management.
- Identify red flags like missing records or uncontrolled changes.
- Document findings and follow up on corrective actions.
- Re-audit critical suppliers regularly to maintain compliance.
What to Verify First in a Supplier Audit
Start with the quality management system. Before touching physical products or machines, confirm the supplier operates a documented system that covers design, manufacturing, and service. Ask for the quality manual, process flow diagrams, and the latest internal audit reports. A supplier with a real system shows you how it works without being asked.
The quality manual is not a brochure. It is the central document that links policy to daily operations. It should define who is responsible for design verification, who approves process changes, and how nonconforming products are handled. Look for specific references to your product or component family within that manual. If the supplier claims to follow ISO 13485, the manual should explicitly state the scope. For example, if you buy surgical trays, the manual must cover assembly, packaging, and sterilization compatibility, not just machining.
Check the certification status. If the supplier claims ISO 13485 compliance, ask for the certificate and the scope of coverage. Verify that your specific product or component falls within that scope. A certificate for general manufacturing does not cover your specific device.
Certificates expire, and scope changes are common. A supplier might have expanded their facility to add injection molding. Their certificate may now cover injection molding, but if it previously covered only machining, they may have had to undergo a surveillance audit to add the new process. Ask for the certificate number and the issuing body. Cross-reference the product code or description on the certificate with your purchase order. If the certificate says “surgical instruments” but you are buying “implantable devices,” that is a mismatch.
Also verify the validity date. Audits are not just about the certificate. They are about the state of the system. A certificate from five years ago is less relevant than the most recent internal audit report. The internal audit report shows how the supplier self-polices. If the last internal audit was two years ago and the certificate is current, ask why the internal audit cycle was missed. A supplier that maintains an active internal audit program demonstrates a culture of continuous improvement.
Key Items to Check in Quality Management
Use the checklist below to verify core quality management elements. This list works for both on-site and remote audits.
-
Quality manual and objectives
Review the quality manual. Check that it defines the quality policy, objectives, and roles. Look for evidence that objectives are measured and reviewed. Red flag: objectives exist on paper but no data shows progress.Objectives should be measurable. “Improve quality” is not an objective. “Reduce first-pass yield defects by 5% within six months” is. Ask to see the dashboard or report that tracks this metric. If the supplier cannot show you the current status of their quality objectives, the system is likely dormant.
-
Document and record control
Verify how documents are issued, revised, and retired. Check that only current versions are available at workstations. Red flag: handwritten notes or outdated forms in use.Walk the production floor. Pick up a work instruction. Check the date and revision number. Go to the document control office and verify that this is the latest version. If there is a discrepancy, the document control system is broken. Look for signs of obsolescence. Are there old forms in the trash or on the desk? Are there handwritten modifications on printed work instructions? These are common in small manufacturers but indicate a lack of discipline.
-
Training and competency
Review training records for production and quality staff. Check that training covers specific tasks, not just general awareness. Red flag: no records for new hires or no refresher training after process changes.Training records should link to the specific task. For a laser cutting operator, the record should show training on the specific laser model, the safety interlocks, and the material parameters. General “safety training” is not sufficient for complex medical device manufacturing. Ask to see the competency assessment. How does the supplier prove the operator can perform the task without error? Look for sign-offs from a qualified trainer.
-
Internal audits and management review
Ask for the last two internal audit reports. Check if nonconformances were closed. Review management review minutes for evidence of system effectiveness. Red flag: recurring nonconformances with no root cause analysis.Management review minutes are often overlooked. They should show that leadership is actively looking at quality data, not just signing off. Check that the minutes discuss trends in customer complaints, internal audits, and process capability. If the minutes are a single page with no data, the review is likely a formality.
-
Corrective and preventive action (CAPA)
Examine the CAPA log. Check that actions are effective and not just closed on paper. Red flag: same root cause appearing in multiple CAPAs.CAPA is where the system either works or fails. Pick a recent CAPA. Trace the problem through the log. What was the root cause? What was the action? How was effectiveness verified? Look for evidence that the action worked. Did the defect rate drop? Did the customer stop complaining? If the same root cause appears in multiple CAPAs, the supplier is treating symptoms, not causes.
Risk Management Controls
Risk management is the backbone of medical device quality. Verify how the supplier identifies and controls risks across the product lifecycle.
- Ask for the risk management plan for your product.
- Check that risk controls are integrated into design and manufacturing.
- Verify that residual risks are acceptable and documented.
- Review how changes to the process or design trigger risk reassessment.
Risk management is not a one-time exercise. It is a continuous process. For each product, the supplier should have a risk file that includes the risk analysis, risk evaluation, risk control, and risk reevaluation. The risk analysis should identify hazards, such as a component failure during use or a sterilization defect. The risk control should describe how those hazards are mitigated, such as through material selection or testing.
The key is integration. Risk controls should be embedded in the design and manufacturing processes. For example, if a risk is that a screw might strip, the risk control might be a torque specification in the assembly work instruction. Check that the work instruction actually has that specification. If the risk file says “verify torque” but the work instruction says “tighten screw,” the risk control is not implemented.
Red flag: a single risk document for all products. This suggests no product-specific risk analysis.
Material and Component Traceability
Material traceability prevents the wrong part from reaching the final device. Check how raw materials and purchased components are identified, stored, and used.
- Verify lot or batch number tracking from receipt to final product.
- Check inspection records for incoming materials.
- Review the method for identifying and segregating nonconforming materials.
- Confirm that critical components have certificates of conformance or test reports.
Traceability starts at the receiving dock. When a pallet of stainless steel arrives, it must be identified with the supplier, material grade, heat number, and lot number. Check the receiving log. Does it match the purchase order? Go to the warehouse. Is the material labeled clearly? Are the labels legible?
For critical components, such as electronic sensors or implants, traceability must extend to the individual unit or batch. Ask for the certificate of conformance from the component supplier. Does it match the lot number on the component? If the supplier cannot trace a component back to its raw material supplier, they cannot prove the safety and performance of the final device.
Red flag: no traceability for critical components, or materials stored without identification labels.
Measurement and Test Equipment
Accurate measurement ensures product dimensions and performance meet specifications. Check the calibration and maintenance of all test equipment.
- Request the calibration records for all measurement instruments.
- Verify that calibration intervals are appropriate for the equipment class.
- Check that out-of-calibration events trigger investigation and impact assessment.
- Review the method for verifying measurement uncertainty.
Measurement equipment includes calipers, micrometers, torque drivers, and test racks. Each instrument must be calibrated against a standard. The calibration record should show the date of calibration, the next due date, the standard used, and the result. Check that the calibration intervals are appropriate. A high-precision micrometer might need calibration every three months, while a simple ruler might need it once a year.
Check the out-of-calibration procedure. If an instrument fails calibration, what happens? The supplier must investigate which products were measured with that instrument since the last valid calibration. They must determine if those products meet specifications. If they cannot answer this question, their quality system is weak.
Red flag: no calibration stickers on instruments, or no records for recalibration after maintenance.
Change Management
Uncontrolled changes are a major source of quality issues. Verify how the supplier manages changes to design, process, materials, or suppliers.
- Ask for the change control procedure.
- Check that changes require formal approval before implementation.
- Verify that risk reassessment is part of the change process.
- Review how changes are communicated to affected customers.
Change management controls the introduction of new materials, new suppliers, new processes, or new designs. For example, if the supplier switches to a new supplier for a plastic housing, they must assess the impact on the product. They must test the new material for dimensional stability, chemical compatibility, and sterilization performance.
Check the change control log. Pick a recent change. Was it approved before implementation? Who approved it? Was a risk reassessment performed? Was the customer notified? If the supplier made a change without approval, the entire quality system is at risk. Uncontrolled changes can introduce new defects that were not considered in the original design.
Red flag: verbal changes without documentation, or changes made after production without review.
Documentation and Recordkeeping
Complete records protect your organization during regulatory inspections. Check the supplier’s record retention and retrieval system.
- Verify that records are stored securely and access-controlled.
- Check that records are available for the required retention period.
- Review the method for retrieving specific records quickly.
- Confirm that electronic records are backed up and protected from tampering.
Records include test reports, calibration certificates, training logs, and CAPA files. They must be retained for a defined period. For medical devices, this is often the lifetime of the device or a specific number of years, depending on the regulatory jurisdiction. Check the retention policy. Is it clear? Is it followed?
If records are stored electronically, check the access controls. Who can view or modify the records? Are there audit trails? If the supplier stores records on a local hard drive without a backup, they are at risk of data loss. If they store them in a shared folder without access controls, they are at risk of unauthorized modification.
Red flag: records stored on unsecured local drives, or no defined retention period.
Supplier Audit Checklist Summary
Use this table to track your audit findings during the visit.
| Category | Key Item | Verification Method | Red Flag |
|---|---|---|---|
| Quality System | Quality Manual | Review document, check objectives | Objectives not measured |
| Risk Management | Risk Plan | Review product-specific risk file | Single plan for all products |
| Traceability | Material Control | Check lot tracking, storage labels | No ID labels on materials |
| Calibration | Equipment Records | Review calibration logs | No out-of-calibration procedure |
| Change Control | Change Log | Review approval records | Verbal changes only |
This table is a starting point. Customize it for your specific product and risk profile. For a supplier that manufactures active devices, add a line for software validation. For a supplier that manufactures passive devices, add a line for material certification. The goal is to have a consistent way to track findings across multiple audits.
How to Structure a Remote Supplier Audit
Remote audits require a different approach. You cannot observe physical processes, so you rely on document review and video walkthroughs.
- Request the document package in advance.
- Conduct a pre-audit call to clarify scope.
- Review documents for internal consistency.
- Schedule a video tour of the production area.
- Interview key staff by video call.
- Request additional evidence for any gaps.
Start with a pre-audit call. This is not a waste of time. It allows you to clarify the scope and identify any documentation gaps before the formal audit. Ask the supplier to prepare specific documents, such as the risk management plan for your product, the calibration log for the last six months, and the training records for the key operators.
During the document review, look for internal consistency. Do the process flow diagrams match the work instructions? Do the risk controls match the test procedures? Inconsistencies are common and often indicate that the system is not being followed.
For the video tour, ask the supplier to walk you through the production area. Focus on the areas where your product is manufactured. Look for visual cues. Are the workstations organized? Are the labels legible? Are the operators following the work instructions? Ask specific questions. “Can you show me where you verify the torque on this screw?” “Where do you store the nonconforming materials?”
Interview key staff by video call. This includes the quality manager, the production manager, and the operator. Ask open-ended questions. “How do you handle a process deviation?” “What do you do if a measurement is out of specification?” Listen for hesitation or vague answers.
Red flag for remote audits: refusal to provide records, or staff unable to explain processes.
Common Red Flags to Watch For
Watch for these signs during any audit, on-site or remote.
- Vague answers: Staff cannot explain how a specific process works.
- Missing records: No documentation for critical steps.
- Uncontrolled changes: Process changes without approval.
- Recurring nonconformances: Same issue appearing multiple times.
- Lack of ownership: No clear person responsible for quality.
Vague answers are a common sign of a weak quality culture. If an operator cannot explain why a step is performed, they are likely following a habit, not a process. If a quality manager cannot explain how a risk is controlled, the risk management system is likely theoretical.
Missing records are a critical issue. If a supplier cannot provide a calibration record for an instrument, they cannot prove that the instrument is accurate. If they cannot provide a training record, they cannot prove that the operator is competent.
Uncontrolled changes are a major risk. If a supplier changes a process without approval, they may introduce new defects. If they change a material without approval, they may compromise the performance of the device.
Recurring nonconformances indicate a lack of root cause analysis. If the same issue appears multiple times, the supplier is not addressing the underlying cause. They are treating the symptom, not the disease.
Lack of ownership is a sign of a disorganized system. If no one is responsible for quality, the system will fail. If no one is responsible for traceability, the system will fail.
If you see multiple red flags, pause the audit and escalate. Do not proceed with a contract until issues are resolved.
Final Steps After the Audit
Complete the audit report within 48 hours. Record findings, evidence, and risk ratings. Share the report with your quality team.
- Classify findings by severity.
- Request a corrective action plan.
- Set a follow-up date for verification.
- Update your supplier risk profile.
- Schedule the next audit based on risk.
The audit report is a formal document. It should include the scope of the audit, the date, the auditor, and the findings. Each finding should be classified by severity. For example, a missing calibration record for a critical instrument is a major finding. A missing label on a non-critical material is a minor finding.
Request a corrective action plan from the supplier. The plan should include the root cause, the action, the responsible person, and the due date. Set a follow-up date to verify that the action was effective. Do not assume the issue is resolved. Verify it.
Update your supplier risk profile. A supplier with multiple major findings should be moved to a higher risk category. This may require more frequent audits or more detailed inspections. A supplier with no findings or only minor findings can be moved to a lower risk category.
Schedule the next audit based on risk. High-risk suppliers should be audited more frequently. Low-risk suppliers can be audited less frequently. The goal is to allocate your audit resources to the suppliers that need them most.
A good supplier audit is not a one-time event. It is a continuous process that builds confidence in your supply base. Use this checklist to maintain that confidence.
Frequently asked questions
How often should I audit a critical supplier?
Audit critical suppliers at least annually. Increase frequency if the supplier has a high defect rate or undergoes significant changes.
What is the difference between a supplier audit and a customer audit?
A supplier audit evaluates the supplier's quality system. A customer audit is conducted by the customer to verify compliance with specific requirements.
Can I use this checklist for a remote audit?
Yes. This checklist works for remote audits. Focus on document review and video walkthroughs instead of physical observation.
What should I do if a supplier fails the audit?
Issue a formal nonconformance report. Request a corrective action plan. Set a follow-up date to verify effectiveness.
Do I need to audit every supplier?
No. Prioritize audits based on risk. Critical suppliers need full audits. Low-risk suppliers can use questionnaires or document review.


