Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.
iso13485-audit-prep
Security Scan Summary
Status: Safe
Source: Syntic Skills registry
Automated security scan completed with no high-risk patterns detected. Manual review is still required.
About This Skill
Use when preparing an ISO 13485 QMS audit: before annual Clause 8.2.4 review, MDR/FDA QSR alignment, a DHF closure at launch, CAPA effectiveness checks, or post-recall root-cause audits.
Downloadable SKILL.md
Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.
--- name: iso13485-audit-prep description: Use when preparing an ISO 13485 QMS audit: before annual Clause 8.2.4 review, MDR/FDA QSR alignment, a DHF closure at launch, CAPA effectiveness checks, or post-recall root-cause audits. category: Compliance version: 1.0.0 tools: [] --- # ISO 13485 QMS Audit Prep — Six Forcing Questions Pressure-test any medical-device QMS work with six traceability-obsessed questions before an internal audit, MDR / FDA QSR review, or product launch. ## When to Run - Before annual Clause 8.2.4 internal audit - Before MDR / FDA QSR alignment review (substantially harmonized post Feb 2026) - Before new-device commercial launch (DHF closure audit) - After a significant CAPA closure event (effectiveness verification audit) - Post-recall event (root cause + corrective action audit) - Quarterly during regulatory submission preparation ## The Six QMS Questions ### 1. Pull three random DHFs. Are design verification and validation evidence complete? Most-cited finding area. A DHF must include: design plan, inputs, outputs, verification, validation, transfer, and changes. Sample stratified by product class (I, IIa, IIb, III per MDR). Verify the traceability matrix runs from user needs through clinical evidence. ### 2. Show the last 5 CAPAs with effectiveness verification evidence. Second-most-cited finding area. Confirm containment/correction/corrective action are distinguished and documented. Root cause analysis depth: 5 Why minimum. Effectiveness verification must be measurable evidence, not "we updated the procedure." Closure must be approved by the appropriate authority. Repeat CAPAs across products signal a systemic issue. ### 3. When was process validation (IQ/OQ/PQ) last revalidated? Clause 7.5.6 — often stale. Initial validation happens at process introduction; revalidation triggers include process change, equipment change, material change, or a periodic schedule. Trend monitoring (SPC) applies where statistical techniques are used per Clause 8.4. Cross-check against 21 CFR 820.75 for FDA alignment. ### 4. Show the risk management file for the highest-risk product. Clause 7.1 + ISO 14971:2019. Confirm a risk management plan exists per product, hazard identification covers reasonably foreseeable misuse, and the risk control hierarchy is applied: inherent safety > protective measures > information for safety. Residual risk must be evaluated and accepted with rationale, and post-production information must feed back into the RMF. For AI-enabled medical devices, layer an ISO 42001 Annex A.5 impact assessment on top. ### 5. Show post-market surveillance evidence from the last 6 months. Clause 8.2.1 — high-stakes for MDR and FDA. Check the customer complaint log and investigation closure, vigilance reports (serious incident / FSCA) submitted per applicable regulation, trend analysis feeding management review, and post-market clinical follow-up (PMCF) for MDR high-risk devices. Cross-check MDR reports against 21 CFR 803 for US-marketed devices. ### 6. Where's the management review evidence covering all Clause 5.6 inputs? Annual minimum; semi-annual for mature programs. Required inputs per Clause 5.6.2: audit results, customer feedback, process performance, product conformity, status of preventive and corrective actions, follow-up from prior reviews, changes that could affect the QMS, recommendations for improvement, regulatory requirements. Required outputs per Clause 5.6.3: improvement decisions, product requirement changes, resource needs. An integrated review across frameworks (see compliance-readiness) is preferable to separate reviews. ## Method Optimize the audit programme by mapping every Clause 4-10 requirement and applicable MDR/FDA QSR clause to a sampling plan across DHFs, CAPAs, validations, RMFs, and surveillance evidence. Run a mock-audit readiness check against that plan before the real audit. Route CAPA-system review and risk-management-file review to the relevant specialist. ## Output Produce a verdict report covering: the decision being made (programme-plan / DHF-closure / CAPA-health / post-market-trend / pre-cert / MDR-FDA-alignment); design control status per sampled DHF (verification, validation, clinical evidence, traceability matrix); CAPA health (count sampled, root-cause depth, effectiveness verification, CAPAs aging past 90 days, repeat issues); process validation status (% on schedule, validations stale beyond 12 months, Clause 8.4 statistical techniques applied); risk management file status (sampled RMFs, post-production updates in the last 12 months, residual risk sign-off); post-market surveillance (complaint trend, MDR/vigilance timeliness %, PMCF schedule); management review status (last date, Clause 5.6.2 inputs present, overdue action items); and cross-framework impact (EU MDR alignment, FDA QSR alignment, ISO 42001 AIMS overlay if AI-enabled). Close with a verdict — READY, CLOSE-DHF-GAPS-FIRST, or NOT-READY — and the top 3 actions with owner and corrective-action timeline. ## Routing Escalate to a multi-framework compliance-readiness review, an FDA-specific QSR overlay, an ISO 42001 AI-enabled-device layer, or a GDPR audit for personal-data overlap (clinical/customer data). Route executive-level findings to a CPO-level product strategy review, and log the verdict.
Bundle Download
Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.
Install Targets
Syntic App
- 1. Create a dedicated folder for this skill in your local skills library.
- 2. Place SKILL.md into that folder.
- 3. Restart Syntic and invoke this skill on matching tasks.
Syntic Code (CLI)
- 1. Save SKILL.md in your local Syntic Code skills directory.
- 2. Keep related files in the same skill folder.
- 3. Run in a safe environment and validate outputs.
Source
https://github.com/alirezarezvani/claude-skills/blob/main/compliance-os/skills/iso13485-audit-prep/SKILL.md
Open Source LinkRelated Skills
ai-act-readiness
Use when doing AI-system intake, preparing for EU deployment, or running the annual compliance refresh — the...
Complianceaims-audit
Use when preparing for ISO/IEC 42001 certification stage 1, running an annual internal audit cycle, or...
Compliancecompliance-os
Use when standing up a multi-framework compliance program, planning the annual audit calendar, or preparing...
Compliancecompliance-readiness
Use when adopting a new compliance framework, finalizing the annual audit calendar, or signing off on...