DEV Community

Rajiv Iyer
Rajiv Iyer

Posted on

MDSAP: the one audit that can stop you paying for the same inspection five times

If you're shipping medical devices into the US, Canada, Australia, Brazil and Japan and you're not using MDSAP, you are probably paying for audits you don't need. I've been managing supplier quality and QMS automation at a CMO for a decade; the difference between five overlapping regulator reviews and one coordinated MDSAP-style assessment is practical — fewer interruptions, clearer CAPA expectations, and less audit fatigue on the shop floor.

What MDSAP actually gives you

MDSAP (the Medical Device Single Audit Program) is a single audit framework used by participating regulatory authorities to perform regulatory assessments. It uses ISO 13485:2016 as the backbone and folds in jurisdictional requirements from the participating regulators. In plain terms for a practitioner:

  • One process-based audit instead of separate process audits for each participating authority.
  • A consistent, documented audit report that regulators can use for their oversight activities.
  • Focus on core QMS processes: management, control of suppliers, production, CAPA, complaint handling, and traceability — the things that matter to both auditors and the factory floor.

For a factory with dozens of suppliers and a skeletal QA/RA team, that consistency is the operational win. You get one set of findings, one list of corrective actions, and one round of follow-ups — rather than juggling five similar but slightly different audit trails.

What it doesn't do (and why that matters)

MDSAP is not a magic wand. Important caveats I’ve learned the hard way:

  • It does not replace your EU/UK notified-body audit obligations (MDR/UKCA) or other non‑participating markets. If you ship to the EU, you still need your CE/MDR engagements.
  • Scope matters. MDSAP is relevant to the legal manufacturer or to those explicitly included in a manufacturer’s scope. If you are strictly a contract manufacturer and the OEM owns the regulatory files, the OEM's MDSAP status — or lack of it — will determine whether a regulator’s MDSAP report helps you.
  • Regulatory use varies. Participating authorities use MDSAP reports for different regulatory activities in different ways. Don’t assume a report will act as a full substitute for every inspection the regulator might want to do.

A CMO’s practical approach

At our CMO, we run incoming inspection automation and supplier COA verification across 40+ suppliers. That automation makes assembling audit evidence faster, but it doesn’t change whether the audit itself is duplicated across jurisdictions. Here’s how I advise CMOs to think about MDSAP:

  • Ask your customers. OEMs control registrations. Ask them if they or their legal manufacturing entity hold an MDSAP certificate and whether they can include your site in scope or share reports.
  • If you market or import devices yourself in any participating country, seriously consider enrolling. The administrative and operational relief can outweigh the upfront effort.
  • If you remain outside MDSAP scope, negotiate audit frequency with customers: show them your ISO 13485-aligned processes, your automated evidence trails, and the CAPA history. In some cases that can reduce customer-led audits.
  • Use automation to make MDSAP practical. A single audit only helps if you can produce a single set of records quickly — supplier certificates, incoming inspection logs, CAPA timelines, training records. Automation reduces the time to pull that evidence.

A short checklist to prepare for an MDSAP-style audit

If you decide to pursue MDSAP or want your site to be included in an OEM’s MDSAP scope, make sure these items are tidy and demonstrable:

  • QMS aligned to ISO 13485:2016 (documented processes, risk management links).
  • Robust supplier control: approved supplier lists, incoming inspection records, supplier performance monitoring.
  • CAPA program: clear initiation triggers, investigation records, verification of effectiveness.
  • Complaint handling and vigilance linkage: traceability from complaint to investigation to CAPA.
  • Document control and change control: current versions, training records, impact assessment.
  • A reproducible evidence pack: dashboards or exports that show dates, owners, and closure evidence (automation helps here).

If you use automated tools (we use Python + Postgres + Grafana internally for evidence collection), make sure exports are human‑readable and that your auditors can verify source records — auditors want traceability, not just a PDF dashboard.

Benefits for the shop floor (and for QA)

From the shop-floor perspective, fewer auditors walking through the production area is a real quality-of-life improvement. From QA’s perspective, the main gains I’ve seen:

  • Reduced audit fatigue and less disruption to production planning.
  • Single, harmonised CAPA expectations that allow you to prioritise effectively.
  • A clearer story to tell customers about how you manage risk across suppliers and production.

When MDSAP isn’t the right tool

If your customer base is primarily EU/UK or other non‑participating markets, or if you're only a sub-tier supplier never named in regulatory files, MDSAP might not move the needle. In those cases, focus on ISO 13485 maturity, clean supplier controls, and demonstrable traceability — those are the things notified bodies and OEM auditors always ask for.

I’m cautious about vendor marketing that promises MDSAP will “end audits.” It reduces duplication when applicable, but it does not erase regulatory responsibility.

If you use a commercial eQMS or a supplier-focused tool, check whether it can produce the documents regulators will ask for (audit trails, training certificates, COA history). Some products are aimed at device makers and assume the manufacturer owns the regulatory burden — fine for OEMs, less so for CMOs that need supplier-facing flexibility. qmsWrapper integrates well with custom automation and supplier workflows, which matters when you're a contract manufacturer managing dozens of suppliers.
I work on qmsWrapper and am giving an honest read of where it does and doesn't fit for CMOs.

What has your experience been — for CMOs or small device shops shipping to multiple countries: did MDSAP reduce audit burden in practice, or did scope and customer contracts blunt its impact?

Top comments (0)