COMMON NONCONFORMITIES IN ISO 13485:2016 CERTIFICATION AUDITS – WHAT SHOULD ORGANIZATIONS PAY ATTENTION TO?
In the medical device industry, product quality and safety are always top priorities. Therefore, many organizations choose to implement ISO 13485:2016 to establish a Medical Device Quality Management System (QMS) that meets customer requirements and applicable regulatory requirements.
However, during ISO 13485 certification audits, many organizations still receive NCs (Nonconformities). In most cases, NCs do not arise from a lack of documentation, but rather from inconsistent implementation of the QMS, records that do not accurately reflect actual practices, or ineffective control activities.
Identifying common ISO 13485 NCs at an early stage enables organizations to proactively improve their QMS, minimize risks during the certification audit, and increase the likelihood of achieving certification at the first attempt.
What Is a Nonconformity (NC) Under ISO 13485?
ISO 13485 Certification Audit: Nonconformities Organizations Should Avoid
A Nonconformity (NC) is the failure to fulfill a requirement of ISO 13485:2016, applicable regulatory requirements, or the organization's own established procedures.
Nonconformities may be identified during internal audits or certification audits and are commonly classified as Minor Nonconformities and Major Nonconformities, depending on their nature and significance.
An NC does not necessarily mean that an organization will fail the audit. However, if it is not appropriately addressed and corrected, it may affect the certification outcome and the effectiveness of the Quality Management System.
Why Do Organizations Commonly Receive NCs?
Based on practical audit experience, the root cause is often not the absence of procedures, but the lack of consistency between documented procedures, records, and actual practices.
Common causes include:
- Documentation has not been adequately updated.
- Records are incomplete or difficult to retrieve.
- Employees do not consistently follow established work instructions.
- Internal audits fail to identify weaknesses within the QMS.
- Risk management and CAPA processes are not effectively implemented.
These are also areas that certification bodies typically focus on during ISO 13485 certification audits.
1. Ineffective Control of Documents and Records
Documents and records provide objective evidence that an organization has established and implemented its Quality Management System in accordance with ISO 13485 requirements. If document and record control is not effectively maintained, the organization may easily receive nonconformities.
Common issues include:
- Use of obsolete documents or forms.
- Documents issued without the required approval.
- Changes to documents are not adequately controlled.
- Records are incomplete or not retained for the specified retention period.
Such deficiencies may result in inconsistent practices across departments and reduce the effectiveness of the QMS.
2. Risk Management Does Not Fully Meet Requirements
ISO 13485 requires organizations to establish and maintain a risk management process covering applicable stages throughout the lifecycle of the medical device.
However, some organizations develop risk management documentation primarily for audit purposes without effectively integrating risk management into actual operational activities.
Common NCs include:
- Hazards have not been comprehensively identified.
- Risk management files have not been adequately updated.
- Risks are not reassessed when products or processes are changed.
- Risk control measures have not been adequately verified for effectiveness.
Ineffective risk management may result in hazards being overlooked, potentially affecting the quality and safety of medical devices.
3. Inconsistent Control of Production Processes
One of the key requirements of ISO 13485 is that production activities be carried out under controlled conditions in accordance with established procedures and requirements.
In practice, NCs commonly arise when:
- Employees do not follow approved work instructions.
- Production records are incomplete or inconsistent.
- Measuring and monitoring equipment has not been calibrated as planned.
- Production environmental conditions are not adequately controlled.
These deficiencies may reduce product traceability, affect product quality, and increase the risk of defects during the manufacturing process.
4. Inadequate Supplier Control
The quality of incoming materials and components can directly affect the quality of medical devices. Therefore, ISO 13485 requires organizations to establish criteria for the evaluation and selection of suppliers and to monitor supplier performance in a systematic manner.
Common nonconformities include:
- Supplier evaluation criteria have not been established.
- Suppliers are not evaluated or re-evaluated at defined intervals.
- Supplier evaluation records are incomplete.
- Supplier performance is not adequately monitored, or appropriate actions are not taken when suppliers fail to meet specified requirements.
Effective supplier control helps organizations reduce risks at the input stage and improve product consistency and reliability.
5. Ineffective Personnel Competence Management and CAPA
People are a key factor in determining the effectiveness of a Quality Management System. ISO 13485 requires organizations to ensure that personnel are competent, appropriately trained, and aware of their responsibilities.
At the same time, identified nonconformities need to be appropriately addressed through the organization's Corrective and Preventive Action (CAPA) processes, with actions focused on addressing root causes and preventing recurrence, where applicable.
Common NCs include:
- Inadequate training plans and training records.
- Training effectiveness is not evaluated.
- Employees do not adequately understand applicable procedures or work instructions.
- CAPA addresses the immediate issue but fails to determine and address the root cause.
- The effectiveness of corrective actions is not evaluated after implementation.
If personnel competence is not maintained and CAPA is ineffective, the organization may experience recurring nonconformities across multiple audit cycles.
6. Internal Audit and Management Review Are Not Effective
Internal audits and management reviews are two critical processes for evaluating the effectiveness of the QMS and supporting continual improvement.
However, some organizations conduct these activities merely as a formality, resulting in NCs such as:
- The full scope of the QMS is not adequately audited.
- Internal audit reports do not accurately reflect the actual status of the QMS.
- Identified nonconformities are not adequately tracked through to completion.
- Management reviews are not conducted as planned.
- Decisions or improvement actions are not clearly established and followed up after management review meetings.
When these activities are ineffective, organizations may fail to identify internal issues before the certification body conducts its audit.
7. Inadequate Control of Nonconforming Product and Traceability
ISO 13485 requires organizations to establish processes for the identification, segregation, control, and disposition of nonconforming product, as well as appropriate traceability throughout applicable stages of production and product realization.
Common NCs include:
- Nonconforming product is not clearly identified.
- Records of nonconforming product disposition or related investigation are incomplete.
- Raw materials, work-in-process, or finished products cannot be adequately traced.
- Information such as lot numbers, serial numbers, or quality inspection records is incomplete.
- The traceability system does not adequately support investigation, corrective action, or product recall activities when required.
This category of NC may directly affect an organization's ability to control product quality and manage associated risks.
What Do Auditors Typically Check During an ISO 13485 Certification Audit?
During an ISO 13485 certification audit, auditors do not simply review documents and records. They also verify the effective implementation and effectiveness of the QMS as a whole.
Key areas typically include:
Documented Information Review
Auditors assess the adequacy, currency, and control of procedures, work instructions, forms, and other relevant documented information.
Implementation Records Review
Auditors review records such as production records, training records, risk management documentation, CAPA records, calibration records, quality inspection records, and internal audit records to verify actual implementation.
On-Site Observation
Auditors observe production conditions, compliance with established procedures, product identification, equipment control, working environment conditions, and other activities that may affect product quality.
Personnel Interviews
Auditors interview employees to assess their understanding of their duties, responsibilities, applicable procedures, work instructions, and relevant QMS requirements.
Consistency and Effective Implementation of the QMS
Auditors cross-check documented information, records, and actual practices to determine whether the organization has effectively implemented and maintained its ISO 13485 QMS in practice.
What Can Organizations Do to Minimize NCs?
To minimize ISO 13485 NCs and improve the likelihood of achieving certification, organizations should proactively review and evaluate their QMS before the certification audit.
Key actions include:
- Ensure that QMS documentation is current and effectively controlled.
- Review records to ensure completeness, accuracy, and traceability.
- Conduct objective internal audits according to the established audit program.
- Complete management reviews as planned and follow up on resulting decisions and improvement actions.
- Effectively manage risks, CAPA, and supplier control activities.
- Provide appropriate training and continually improve personnel competence and awareness.
- Verify compliance with established procedures and requirements at the workplace before the certification audit.
Thorough preparation not only helps organizations reduce nonconformities but also improves the effectiveness of the Medical Device Quality Management System throughout its operation.
Conclusion
Most ISO 13485 NCs arise from inconsistencies between documented information, records, and actual practices rather than from a lack of procedures.
When the QMS is systematically established, consistently implemented, regularly maintained, and continually improved, organizations can proactively manage risks, enhance product quality, and be better prepared for ISO 13485 certification audits.
Rather than focusing solely on preparation immediately before an audit, organizations should treat the maintenance and continual improvement of their ISO 13485:2016 QMS as an ongoing management activity. This provides a solid foundation for meeting applicable regulatory requirements, strengthening competitiveness, and building lasting confidence among customers and regulatory authorities.

main.comment_read_more