Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.
qms-audit-expert
Security Scan Summary
Status: Safe
Source: Syntic Skills registry
Automated security scan completed with no high-risk patterns detected. Manual review is still required.
About This Skill
Use when planning internal audits, executing ISO 13485 QMS audits, classifying findings, preparing for external audits, or managing an audit program.
Downloadable SKILL.md
Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.
--- name: qms-audit-expert description: Use when planning internal audits, executing ISO 13485 QMS audits, classifying findings, preparing for external audits, or managing an audit program. category: Regulatory & Quality version: 1.0.0 tools: [] --- # QMS Audit Expert ISO 13485 internal audit methodology for medical device quality management systems. ## Audit Planning Workflow Plan a risk-based internal audit program: 1. List all QMS processes requiring audit 2. Assign risk level to each process (High/Medium/Low) 3. Review previous audit findings and trends 4. Determine audit frequency by risk level 5. Assign qualified auditors (verify independence) 6. Create the annual audit schedule 7. Communicate schedule to process owners 8. Validate: all ISO 13485 clauses covered within the cycle ### Risk-Based Audit Frequency | Risk Level | Frequency | Criteria | |------------|-----------|----------| | High | Quarterly | Design control, CAPA, production validation | | Medium | Semi-annual | Purchasing, training, document control | | Low | Annual | Infrastructure, management review (if stable) | ### Audit Scope by Clause | Clause | Process | Focus Areas | |--------|---------|-------------| | 4.2 | Document Control | Document approval, distribution, obsolete control | | 5.6 | Management Review | Inputs complete, decisions documented, actions tracked | | 6.2 | Training | Competency defined, records complete, effectiveness verified | | 7.3 | Design Control | Inputs, reviews, V&V, transfer, changes | | 7.4 | Purchasing | Supplier evaluation, incoming inspection | | 7.5 | Production | Work instructions, process validation, DHR | | 7.6 | Calibration | Equipment list, calibration status, out-of-tolerance | | 8.2.2 | Internal Audit | Schedule compliance, auditor independence | | 8.3 | NC Product | Identification, segregation, disposition | | 8.5 | CAPA | Root cause, implementation, effectiveness | Verify auditor independence before assignment: auditor not responsible for the area being audited, no direct reporting relationship to the auditee, not involved in recent activities under audit, and documented qualification for the audit scope. ## Audit Execution Conduct a systematic internal audit: 1. Prepare the audit plan (scope, criteria, schedule) 2. Review relevant documentation before the audit 3. Conduct an opening meeting with the auditee 4. Collect evidence (records, interviews, observation) 5. Classify findings (Major/Minor/Observation) 6. Conduct a closing meeting with preliminary findings 7. Prepare the audit report within 5 business days 8. Validate: all scope items covered, findings supported by evidence ### Evidence Collection | Method | Use For | Documentation | |--------|---------|---------------| | Document review | Procedures, records | Document number, version, date | | Interview | Process understanding | Interviewee name, role, summary | | Observation | Actual practice | What, where, when observed | | Record trace | Process flow | Record IDs, dates, linkage | Sample audit questions by clause — Document Control (4.2): "Show me the document master list," "How do you control obsolete documents?" Design Control (7.3): "Show me the Design History File for [product]," "Show me design input-to-output traceability." CAPA (8.5): "Show me the CAPA log with open items," "How do you determine root cause?" Document each finding as: **Requirement** (the specific ISO 13485 clause or procedure), **Evidence** (what was observed, reviewed, or heard), **Gap** (how the evidence fails to meet the requirement). Example: Requirement — ISO 13485:2016 Clause 7.6 requires calibration at specified intervals. Evidence — calibration records for pH meter EQ-042 show last calibration 2024-01-15 against a 12-month interval; today is 2025-03-20. Gap — equipment is 2 months overdue for calibration. ## Nonconformity Management Classify and manage audit findings: 1. Evaluate the finding against classification criteria 2. Assign severity (Major/Minor/Observation) 3. Document the finding with objective evidence 4. Communicate to the process owner 5. Initiate CAPA for Major/Minor findings 6. Track to closure 7. Verify effectiveness at follow-up 8. Validate: finding closed only after effective CAPA ### Classification Criteria | Category | Definition | CAPA Required | Timeline | |----------|------------|---------------|----------| | Major | Systematic failure or absence of element | Yes | 30 days | | Minor | Isolated lapse or partial implementation | Recommended | 60 days | | Observation | Improvement opportunity | Optional | As appropriate | Classification decision logic: if a required element is absent or failed, classify Major when systematic (multiple instances) or when it could affect product safety, otherwise Minor. If not absent but a deviation from procedure, classify Major when recurring, otherwise Minor. If neither, and it's simply an improvement opportunity, classify as Observation. CAPA depth follows severity: Major findings require full root cause analysis (5-Why, Fishbone) with verification at the next audit or within 6 months; Minor findings require immediate cause identification, verified at the next scheduled audit; Observations require no CAPA, just a note at the next audit. ## External Audit Preparation Prepare for a certification body or regulatory audit: 1. Complete all scheduled internal audits 2. Verify all findings closed with effective CAPA 3. Review documentation for currency and accuracy 4. Conduct a management review with the audit as input 5. Prepare facility and personnel 6. Conduct a mock audit (full scope) 7. Brief personnel on audit protocol 8. Validate: mock audit findings addressed before the external audit Pre-audit readiness checklist — documentation: Quality Manual current, procedures reflect actual practice, records complete and retrievable, previous findings closed. Personnel: key people available, subject matter experts identified, personnel briefed on protocol, escorts assigned. Facility: work areas organized, point-of-use documents current, calibration status visible, nonconforming product segregated. Mock audit protocol: use an external or qualified internal auditor, cover the full scope of the upcoming external audit, simulate actual audit conditions (timing, formality), document findings as for a real audit, and address all Major and Minor findings before the external audit. ## Audit Program Metrics Track audit program effectiveness: | Metric | Target | Measurement | |--------|--------|-------------| | Schedule compliance | >90% | Audits completed on time | | Finding closure rate | >95% | Findings closed by due date | | Repeat findings | <10% | Same finding in consecutive audits | | CAPA effectiveness | >90% | Verified effective at follow-up | | Auditor utilization | 4 days/month | Audit days per qualified auditor |
Bundle Download
Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.
Install Targets
Syntic App
- 1. Create a dedicated folder for this skill in your local skills library.
- 2. Place SKILL.md into that folder.
- 3. Restart Syntic and invoke this skill on matching tasks.
Syntic Code (CLI)
- 1. Save SKILL.md in your local Syntic Code skills directory.
- 2. Keep related files in the same skill folder.
- 3. Run in a safe environment and validate outputs.
Source
https://github.com/alirezarezvani/claude-skills/blob/main/ra-qm-team/skills/qms-audit-expert/SKILL.md
Open Source LinkRelated Skills
agent-decision-receipts
Use when an autonomous agent takes a consequential, side-effecting action (deploy, delete, pay, grant-access...
Regulatory & Qualitycapa-officer
Use when running CAPA investigations, 5-Why or fishbone root cause analysis, corrective action planning and...
Regulatory & Qualityeu-ai-act-specialist
Use when classifying an AI system's EU AI Act risk tier, planning Article 43 conformity assessment for a...
Regulatory & Qualityfda-consultant-specialist
Use when handling FDA submission pathway selection (510(k)/PMA/De Novo), QMSR/ISO 13485 compliance, medical...