System-Wide vs Focused Audits: Which Do You Need?

Here we are here to discuss what is better; system wide or focused audits.

Thanks for reading The Other Consultants: MedTech Quality & Regulatory Insights! Subscribe for free to receive new posts and support my work.

System Wide audits are evaluations that provide a comprehensive and thorough assessment of the QMS or a complete device technical file.

These audits aim to:

  • Verify compliance across multiple clauses of ISO 13485 or MDR Annex IX

  • Hit multiple legislation that one QMS complies with

  • Assess interdependencies between processes (e.g., design control, CAPA, production, and post-market surveillance)

  • Super high level sampling of technical documentation: focus on structure, integrity of the entire technical documentation — including GSPRs, clinical evaluation, risk management (per ISO 14971), and labeling (per ISO 15223)

Ideal Use Cases:

  • Resource limitations: when an organisation has a limited amount of internal auditors available for example.

  • If the QMS is “immature”, and data is limited in terms of prioritising the areas that should be focused on.

  • Pre-certification or re-certification audits.

  • Management review inputs or quality maturity assessments.

Focused or For Cause Audits

Focused audits are often called For Cause audits, for particular things.

These are narrow in scope but deep in analysis. These audits target specific processes, product lines, or clauses and are often triggered by:

  • CAPAs, non-conformities, or internal audit findings

  • Changes in regulations (e.g., IVDR updates) or standards (e.g., ISO 14971:2019 implementation)

  • High-risk processes like sterilization validation (ISO 11135/ISO 11137) or complaint handling

  • Supplier qualification or performance issues

  • Trends identified by QMS trending

Ideal Use Cases:

  • When there are a number of internal auditors to select from to prevent conflicts of independence.

  • Within mature QMS’ where plentiful data is available to identify areas that are a cause for concern.

  • Verifying the effectiveness of new procedures

  • As a result of specific deficiencies raise from customers, NB/UKABs (Isn’t it so annoying to constantly have to differentiate between these).

Duality: A hybrid audit schedule

The most effective audit programs integrate both broad and focused audits using a risk-based approach, and are dynamic throughout the audit cycle.

System wide audits mimic more the inspections that an organisation will receive from 3rd party audits, so this can be good preparation for audit teams in handling audit trails, audit creep as well as understanding how auditors conducting system wide audits will behave.

Focused audits are generally not representative of the 3rd party audit experience, however they will most definitely have an impact due to the limited and focused nature of it.

Here are some tips I can give to get the most out of your audit schedule:

  • Utilise a blend of both system and focused audits.

  • Leverage Past Data: Use QMS trending metrics to understand NC trends, CAPAs, and audit history to guide scope and frequency.

  • Cross-functional Involvement: Get other departments apart from QARA trained on how to audit.

  • Document the 'Why': Always record the rationale for system and focused audits—this is key during regulatory inspections or NB assessments.

Closing thoughts for now

In the medical device industry, we are not just working to ISO 9001. Not even just 13485. QMS have became really complex, with so much activity being driven through it.

In times where we have limited data, or someone needs to get a strong and independent understanding of the QMS, system wide audits are great for this. On the other hand, our focused audit provides us a real detailed insight into a particular area of the QMS.

What’s better? The answer as usual…it depends.

If you need a hand planning your audit schedule you can have a look at my AI audit scheduling tool here - https://www.theotherconsultants.com/internal-audit-schedule-tool.

Or if you need a hand conducting some audits - feel free to reach out on LinkedIn - https://www.linkedin.com/in/adam-isaacs-rae/

Thanks!

Adam

Previous
Previous

Should You Audit Your Own Technical Documentation?

Next
Next

Team NB's Best Practice Guidance v3, Explained