How do MedTech, IVD, pharma, and biotech manufacturers become audit-ready under ISO 13485 and ISO 9001?
We systematically prepare manufacturers for internal, supplier, and external certification audits to ISO 9001:2015 and ISO 13485:2016, from the gap analysis through the internal audit program to ISO 19011 and on to the mock audit ahead of the notified body. The decisive lever rarely lies in the standard itself but in the sequence: completing the gap analysis and closing the major findings before the internal audit program and the certification date are underway avoids the corrective loops that push an audit back.
- MedTech
- IVD
- Pharma
- Biotech
Overview
What challenges do ISO audits pose for life sciences manufacturers?
Audit preparation across internal, supplier, and certification audits · ISO 13485:2016, ISO 9001:2015, ISO 19011
Last updated: 2026-06-13
For medical device and IVD manufacturers under MDR (EU 2017/745) and IVDR (EU 2017/746), ISO 13485:2016 is effectively the baseline, because notified bodies require a certified quality management system. The points where audits most often get stuck:
- Incomplete or disconnected process documentation leads to major findings in the certification audit, because the notified body demands concrete evidence for every requirement of ISO 13485:2016.
- Internal audits are carried out irregularly or not in line with ISO 19011 and thus remain a box-ticking exercise rather than a steering instrument that surfaces nonconformities ahead of the external audit.
- Suppliers, CMOs, and sterilization service providers are inadequately qualified and controlled, even though under ISO 13485:2016 they count as part of the manufacturer's own quality management system.
- The step from an ISO 9001:2015 system to ISO 13485:2016 is underestimated, because the stricter risk approach, the traceability, and the regulatory link to MDR and IVDR have to be built from scratch.
Services
How we support you
Gap analysis to ISO 13485 / ISO 9001
A target-versus-actual comparison of the quality management system against ISO 13485:2016 or ISO 9001:2015. Deliverable: a prioritized action plan that maps each gap to the relevant requirement of the standard, with a timeline to audit readiness.
Internal audits and audit program setup
Planning, conducting, and documenting internal audits to ISO 19011, plus enabling your staff to run the audit program themselves. Deliverable: an audit program, audit plans, and documented audit reports with traceable actions.
Supplier and subcontractor audits
Audits of CMOs, sterilization service providers, and critical suppliers against the requirements of ISO 13485:2016, on site across Europe as well as remote or hybrid audits to ISO 19011. Deliverable: an audit report per supplier and a qualification program for the supplier network.
Mock audits for certification preparation
A simulated certification audit under real conditions before the notified body arrives. Deliverable: a written findings report with classification of the findings, plus a corrective action plan to work through before the actual date.
Learn more →How we work together
What it comes down to
An ISO audit is rarely failed on the standard, but on the sequence. At the outset, the gap analysis against ISO 13485:2016 or ISO 9001:2015 exposes which processes do not hold up today. Only once the major findings derived from it are closed and backed by concrete evidence in the documentation does the internal audit program to ISO 19011 work as a steering instrument that surfaces the remaining nonconformities before the notified body arrives. Anyone who starts these steps in parallel or in the wrong order audits a system that is not yet in place and pushes the corrections into the certification audit, where they jeopardize the date as findings.
The second bottleneck lies in the supply chain. Under ISO 13485:2016, CMOs, sterilization service providers, and critical suppliers count as part of the manufacturer's own quality management system, so supplier and CMO audits as well as qualification records must be in place before the audit itself begins. The mock audit completes the preparation: it simulates the certification audit under real conditions, gives the team an audit routine, and creates the time to work through major and minor findings before the real date, rather than seeing them there for the first time.
Our approach
Our approach
Step
Result
Gap analysis
Prioritized action plan: which processes do not hold up to ISO 13485:2016 or ISO 9001:2015 today, what is critical, and what is effort.
Actions and documentation
Gaps closed, process documentation reworked with evidence for each requirement of the standard.
Internal audit program
Audit program built to ISO 19011, internal audits conducted, team trained in the audit routine.
Supplier audits
Critical suppliers and CMOs audited, qualification status documented.
Mock audit
Simulated certification audit completed, findings report and corrective action plan worked through.
Certification audit
Notified body's audit supported, findings closed in a structured way, certification achieved.
Common pitfalls
Where projects commonly fail
The internal audit program runs as a box-ticking exercise rather than to ISO 19011.
If audits are conducted irregularly, without an audit plan, or without independent auditors, the system fails to surface the nonconformities that then show up as findings in the external audit.
The move from ISO 9001:2015 to ISO 13485:2016 is treated as an extension rather than a rebuild.
The stricter risk approach, the end-to-end traceability, and the link to MDR and IVDR are missing, so the existing system does not hold up in the audit.
Suppliers and CMOs are not treated as part of the manufacturer's own quality management system.
Where supplier audits and qualification records are missing, the notified body challenges the purchasing and outsourcing processes under ISO 13485:2016.
The process documentation exists but is not linked to concrete evidence.
The notified body demands proof in the system for every requirement; blanket references or outdated versions lead to major findings instead of a clean certification.
The mock audit is skipped or scheduled too late.
Without a realistic trial audit before the date, there is no time to close the major and minor findings found, and open points hit the team only at the real audit.
FAQ
Frequently asked questions
Sources
- ISO 13485:2016: Quality management systems for medical devices
- ISO 9001:2015: Quality management systems, requirements
- ISO 19011: Guidelines for auditing management systems
- Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR): primary text, QMS requirements
- Writer material: iso-audits.md (source material, Entourage website writer)
- https://theentourage.de/expertise/iso-audits/ (existing page content, reworked)
Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Case Studies
What this looks like in practice
Related insights
All insights →Regulations & standards considered
- ISO 13485:2016 (quality management systems for medical devices)
- ISO 9001:2015 (quality management systems)
- ISO 19011 (guidelines for auditing management systems)
- Regulation (EU) 2017/745 (MDR)
- Regulation (EU) 2017/746 (IVDR)
- ISO/IEC 27001 (out of scope, see related pages)
Related topics
ISO 13485 Certification →
The full certification path to ISO 13485:2016
Mock Audits →
Simulated certification audits for preparation, in detail
GxP Audits (GMP, GLP, GCP) →
Out of scope here: audits to GMP, GLP, and GCP instead of ISO standard audits
Inspection Readiness →
Preparing for regulatory inspections beyond the ISO audit
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences


