Internal Auditor Competency: How Much Is Enough?

A very common nonconformance I see is organisations using not using adequately competent auditors to conduct audits on their ISO 13485 Quality Management System. This can go further when auditors are auditing regulatory requirements globally.

Thanks for reading The Other Consultants! Subscribe for free to receive new posts and support my work.

Clause 6.2 b) of ISO 13485 specifies that the organisation shall:

Provide training or take other actions to achieve or maintain the necessary competence.

That’s pretty clear, right?

The usual audit scenario goes like this:

Auditor - Can you show me your internal audit schedule (please)?

Auditee - Sure thing, here you go.

Auditor - Which audits have been recently completed?

Auditee - We recently completed an audit on work environment and contamination control.

Auditor - Can I review that audit report please?

Auditee - Sure thing, here you go.

Auditor - Who completed this audit?

Auditee - Our wonderful internal auditor, <insert typical auditor name> completed this audit.

Auditor - Great, can I see their competency profile, and auditor training records, please?

Auditee - Here you go Presents training records

Auditor - notices that training has only been conducted to ISO 9001

Now, there is a bit of a situation.

The wonderful <insert typical auditor name> has not had any specific ISO 13485 internal auditor training in ISO 13485 and they were auditing a very specific element of ISO 13485 that is not present in ISO 9001.

What can be done now?

The auditor can look for experience within an ISO 13485 environment to determine overall competency.

Remember, training does not equal competency.

Competency is a combination of training, education and experience.

So it depends what else the auditor can see.

A lot of what I see is that auditors expect internal auditors to have completed a certain type of lead auditor course or 13485 internal auditor training from a specific provider. This is not the case, and it isn’t right that this is perceived and enforced as an unwritten requirement.

Training should be conducted, and evaluated to determine if it’s effective. Much similar to acceptance criteria during a validation. It is key and a fundamental requirement.

I’m thinking of doing an online course on this topic written by yours truly that gives manufacturers an easy way of refreshing, or establishing baseline understanding, or converting from ISO 9001 to ISO 13485 - you can register your interest here - https://www.theotherconsultants.com/iso-13485-internal-auditor-training-online-course

Previous
Previous

What Is a Class 1 Medical Device?

Next
Next

Internal Audit Report Template for ISO 13485