
Audits & Inspections for Medical Devices & IVD
A Notified Body audit or regulatory inspection doesn't wait for you to be ready. We align your management systems now, so your team is prepared before the auditor is at the door.
Audits and inspections are structured reviews of your quality, regulatory, clinical, and post-market systems against a defined standard. conducted internally, by a supplier, or by a regulator or Notified Body.
Why this gets harder every year
Regulatory expectations keep evolving, supply chains keep distributing across geographies, and documentation that made sense at one site rarely translates cleanly to another. None of that causes a finding on its own. It causes one when nobody's checked the connections between them before a Notified Body, FDA, or NMPA inspector does it for you.
How Qserve supports your program
Our auditors bring regulatory insight and operational experience across quality, clinical, and information-security systems. We design, conduct, and support audits tailored to your business model, whether you're preparing for certification, responding to a finding, or building internal capability your own team will eventually run.
Satisfied Clients
Discover how we can help:
Clinical Audits
We audit clinical trial or PMCF activities, CRO oversight, investigator sites, and documentation to meet ISO 14155, GCP, and MDR expectations.
Internal audits
We conduct comprehensive internal audits across your QMS to assess compliance with ISO 13485, MDR/IVDR, or FDA QSR requirements—identifying gaps before regulators do.
Mock audits and inspections
We simulate notified body or authority inspections (e.g. FDA, ISO, MDSAP) under real-world conditions to prepare teams and stress-test systems.
Supplier audits
We assess and qualify your critical and contract manufacturers, testing labs, and component suppliers—ensuring they meet regulatory and QMS standards.
Legal Entity Auditing
We audit individual legal entities within your group for organizational compliance, registration accuracy, and corporate regulatory obligations.
Post-Market Surveillance (PMS) and vigilance system audits
We review PMS plans, vigilance processes, complaint handling, and trend reporting for regulatory alignment and readiness.
(IVD) Laboratory compliance audits
We assess your diagnostic labs against ISO 15189, IVDR Annex I requirements, and national lab regulations to ensure clinical and analytical validity.
Device Registration Audits
We verify that your product registrations are current, traceable, and consistent across markets, minimizing the risk of expired or misaligned approvals.
SaMD & Cybersecurity Audits
We conduct comprehensive internal and mock audits to assess compliance of your Software as a Medical Device (SaMD) QMS with, among other standards and regulations, IEC 62304, ISO 27001/27002, cybersecurity, and data privacy and protection requirements, including the EU GDPR, Data Act, Cyber Resilience Act (CRA), and US HIPAA — identifying gaps before regulators do.
Without a regular audit rhythm, small issues compound. An undocumented change, a CAPA that never quite closes, a registration that quietly lapses. None of these are dramatic on their own, but they accumulate into the kind of finding that delays market access. We treat auditing as a proactive tool, not a compliance chore: assessed with regulator-grade rigor, reported with prioritized findings, and followed up until it's actually closed.
Couldn't find your question?
How often should internal audits be conducted?
Internal audits should be planned annually at minimum, with higher frequency for high-risk processes, new product introductions, or post-certification.
How far in advance should we schedule an MDSAP, FDA, or NMPA mock audit?
Ideally 2–3 months before the real inspection. Enough time to close findings from the mock audit without rushing the fix.
Are supplier audits mandatory under MDR/IVDR?
Yes, for critical suppliers and subcontractors, regular audits are expected to demonstrate sufficient control and compliance with regulatory requirements.
What happens after the audit?
You receive a detailed audit report, risk-based findings, and a remediation roadmap. We can also support implementation of CAPAs and follow-up readiness checks.
Latest blogs
-1.png)
Plan your IVDR performance study with confidence: classification, ISO 20916 design, the submission pathway, and how to select the right IVD CRO.

Discover the learning paths, essential training courses and key skills for Quality Assurance, Regulatory Affairs and Clinical Affairs professionals.

CEP and CER are not the same document. Learn the critical difference between a Clinical Evaluation Plan and Report under EU MDR, and why it matters.
