ISO 13485:2016
Measurement, analysis and improvement – ISO 13485:2016

ISO 13485:2016 8.2.4: Internal audit

At planned intervals, the organization carries out internal audits to establish whether the quality management system meets the planned and documented arrangements, the requirements of the standard, the requirements the organization has set for its own system, and the applicable regulatory requirements, and whether it is implemented and maintained effectively. A documented procedure sets out who is responsible for planning and carrying out audits and for recording and reporting their results, and what those activities involve. The audit programme is planned taking into account how important and how sound the processes and areas to be audited are, and what earlier audits found. The criteria, scope, frequency and methods of each audit are defined and recorded. Auditors are chosen, and audits are carried out, in a way that keeps the audit process objective and impartial, and no auditor audits their own work. Audit records and results are kept, and they identify which processes and areas were audited and what was concluded. The management responsible for the area audited makes sure any corrections and corrective actions needed are taken promptly, and follow-up activities check the actions taken and report the results of that check.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 38 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4.5.5 Internal Audit
  • SPC1-4.5.6 Internal Audit

ISO 14001:2015 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme

ISO 19011:2018 · 2 controls

  • 6.2 Initiating audit
  • 6.6 Completing audit
  • ISO-37002-9.2 Internal audit
  • ISO37002-9.2 Internal Audit

ISO 37301:2021 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-39001-9.2 Internal audit
  • ISO39001-9.2 Internal Audit
  • ISO-41001-9.2 Internal audit
  • ISO41001-9.2 Internal Audit

ISO 45001:2018 · 2 controls

  • 9.2 Internal audit
  • 9.2.2 Internal audit programme
  • ISO-50001-9.3 Internal audit
  • 9.2 Internal audit

ISO 56002 · 2 controls

  • ISO-56002-9.2 Internal audit
  • ISO56002-9.2 Internal audit

ISO/IEC 27003:2017 · 2 controls

  • CPS220-11 Annual Audit Review of the Framework
  • AS9100D-9.2 Internal Audit

ISO 14004:2016 · 1 control

  • 9.2 Internal audit

ISO 22000:2018 · 1 control

  • 9.2 Internal audit

ISO 22301:2019 · 1 control

  • 9.2 Internal audit

ISO 27001:2022 · 1 control

  • 9.2.2 Internal audit programme

ISO 27701:2019 · 1 control

  • ISO28001-4.17 Internal audit

ISO 30401 · 1 control

  • ISO30401-9.2 Internal audit

ISO 37001:2016 · 1 control

  • 9.2 9.2 Internal audit

ISO 55001:2014 · 1 control

  • 9.2 Internal audit

ISO 9001:2015 · 1 control

  • 9.2 Internal audit

ISO/IEC 27031:2011 · 1 control

  • 27031-9.2 Internal Audit

ISO/IEC 42001:2023 · 1 control

  • 9.2 Internal audit

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Measurement, analysis and improvement – ISO 13485:2016

Query this from an agent

The graph holds this control, the 38 it maps to, and the evidence behind each claim, over MCP and REST.