DEV Community

Priya Nair
Priya Nair

Posted on

The internal audit that finds nothing is the one that ticks 'procedure exists' and moves on

I sat through an internal audit last quarter where the auditor opened the complaints SOP, confirmed it had a revision number, ticked the box, and moved on. The procedure existed. The audit was technically complete. Nothing useful came out of it.

The audits that find something are the ones that pick one real record and follow it from end to end. Complaint goes in. CAPA comes out. Change gets raised. Training gets delivered. Does the loop close? That is the actual question. ISO 13485:2016 clause 8.2.4 wants internal audits at planned intervals, and ISO 19011:2018 nudges you toward the process approach — inputs, outputs, interfaces, effectiveness. None of that is satisfied by "the SOP exists."

What the tick-box audit looks like

You have probably seen it. The auditor:

  • Opens the relevant procedure (complaint handling, CAPA, change control)
  • Confirms revision number, approval date, and sign-offs are present
  • Confirms a template exists for the CAPA form
  • Ticks "complaint handling: compliant"
  • Moves to the next clause

The procedure exists. The form exists. The process might be a shambles. Nobody is looking.

What a record-tracing audit looks like

Pick a real complaint. Say, a complaint received eight months ago about a delivery issue with a Class IIa sterile barrier component. Now ask the following, in order:

  • Where is the complaint record — in the eQMS, a spreadsheet your QA lead maintains, or somewhere worse
  • Was it acknowledged within the timeline your SOP promises
  • Did it become a CAPA? If not, why not — and is the reasoning documented
  • If yes, what was the root cause methodology (5-why, fishbone, fault tree)
  • Did the CAPA raise a change, and what was the change impact mapping
  • Was the change implemented, and who signed it off
  • Was training triggered, who was in the audience, and did they actually complete it
  • Was effectiveness verified after a defined period

This is one record. It will take you an hour or two to walk through properly. It will surface three or four findings a procedure-existence audit would never see. Granted, an existence check is not nothing — it confirms the documented intent exists. The problem is what it does not confirm.

Where the loop usually breaks

After running this exercise with several meddev SMEs — and quietly inside my own Technical File reviews — the breakages tend to cluster in the same five places:

  • CAPA raised, change raised, change implemented, training never triggered
  • Training triggered, completion tracked, but no competency check (the training is treated as the assessment)
  • Change raised, but the change impact mapping did not update the risk management file per ISO 14971
  • Effectiveness check written into the CAPA closure, but never actually performed
  • Complaint logged in a spreadsheet, the CAPA logged in the eQMS — two systems that do not talk to each other

That last point is the one I want to dwell on. The complaint does not appear in the CAPA. The CAPA does not appear in the change. The change does not trigger training. Your traceability chain has gaps, and your next notified body audit (TÜV, BSI, DEKRA — pick your favourite) will absolutely find them under MDR Annex II section 6.1 or ISO 13485 clause 8.2.3.

How to keep the programme honest

A few things that have worked in practice, in order of how easy they are to implement:

  1. Define your audit programme around processes, not clauses. "Audit the complaint-to-retraining process" beats "audit clause 8.2.1 today."
  2. Require every internal audit to include at least one record-tracing exercise. Make it non-negotiable in the audit plan.
  3. Pre-select the record before the audit. The auditor should not get to choose a friendly example.
  4. Train internal auditors in the process approach per ISO 19011:2018 clause 6. Reading the SOP is not an audit skill.
  5. Feed the findings into management review with the full chain visible — complaint, CAPA, change, training, effectiveness check.

If your QMS supports process automation, the easier this gets. AI-driven CAPA assistance can flag a CAPA that closed without an effectiveness check, or a change that implemented without a training record. The technology is the easy part. The harder part is a culture where an auditor feels allowed to say "this record is broken" and a process owner who treats that as a gift.

A tick-box audit is comfortable. Nobody has to make a judgement call. Nobody has to write a finding that will land in front of a notified body at the next surveillance audit. The procedure exists. The audit passes. Everyone moves on.

Until the next complaint comes in, and the same thing happens again, and the notified body audit lands and the finding is not "your SOP is missing" but "your process does not work" — which is a much harder thing to remediate.

Over to you

For those of you running internal audit programmes in medtech: how do you pick the records you trace? Do you sample randomly, or do you bias toward recent complaints, older open CAPAs, or supplier-heavy changes? I am particularly interested in whether anyone has had pushback from process owners on record-tracing audits, and how you handled it.

Top comments (0)