“We Audit Everything Once a Year” Is a Red Flag, Not a Program

Once a year, in most quality departments across the land, the same small miracle occurs. Someone realizes the internal audit for the year hasn’t happened. A conference room is booked. A checklist last touched eleven months ago is dusted off. Two exhausting days later, the QMS has been “audited,” the box is checked, and everyone goes home for the holidays feeling vaguely virtuous.

I’ve run that annual sprint. I’ve also been the outside auditor who watched a company try to compress an entire year of internal auditing into 48 hours, and let me tell you: it shows. When your whole program lives in one frantic week, you’re not finding your own problems before someone with a badge does — which, as we covered last time, is the entire point of auditing at all. You’re performing an audit. It’s theater. And the audience is getting more sophisticated.

What §8.2.4 actually asks for

ISO 13485 §8.2.4 — which the FDA’s QMSR now makes law — says you shall conduct internal audits “at planned intervals” to determine whether your QMS conforms to requirements and is effectively implemented and maintained. Then it adds the part everyone skims: you shall document a procedure that defines the audit criteria, scope, interval, and methods, and the planning shall take into consideration the status and importance of the processes and areas to be audited, as well as the results of previous audits.

Read that last clause again slowly, because it’s the whole ballgame. “Status and importance” and “results of previous audits” is the standard’s polite way of saying: audit the risky stuff more, and audit the stuff that already bit you more. That is a risk-based schedule, spelled out in plain regulatory English. A single annual pass that treats your sterilization validation and your office supply closet with identical rigor is, by definition, not taking status and importance into consideration.

What a real program looks like

ISO 19011 — the guidelines for auditing management systems, freshly updated in 2026 — is where the craft lives. It describes an audit program: a planned set of audits, spread across a cycle (usually twelve months), that together cover the whole system. The key word is spread. Instead of one heroic event, you have a schedule that breathes across the year.

Building one isn’t complicated. Start with a list of every process in your QMS. Then rate each one on risk — how much harm results if it fails, how often it’s changed lately, how it performed in your last audit, whether it’s tied to a recent complaint or CAPA. Design controls, sterilization, supplier management, and CAPA itself tend to float to the top. Document retention and internal comms tend to sink. Then you schedule accordingly: the high-risk, high-change, recently-troubled processes get looked at more than once a year; the quiet, stable ones can go on a longer interval, as long as everything gets covered within the cycle.

The result is a living schedule, not a calendar with one entry on it. And when a surprise shows up — a warning letter in your space, a supplier who just changed hands, a spike in a particular complaint — you can pull an audit forward. That flexibility is a feature, not a deviation.

The new reason this matters

Here’s what changed under your feet. The old QSR had a provision — §820.180(c) — that kept your internal audit reports out of FDA’s hands during an inspection. Investigators could confirm you audited, but they couldn’t read what you found. That exemption is gone under the QMSR.

And the new inspection approach that replaced QSIT — Compliance Program 7382.850 — is explicitly risk-based and process-focused. Put those two facts together. An investigator can now open your audit schedule, look at a once-a-year cadence with no documented rationale, and reasonably ask: how is this frequency commensurate with the risk of your product and processes? “Because that’s when we had time” is not the answer that ends the conversation. A schedule that shows your riskiest processes audited more often, with the reasoning written down, is.

Do this today

You don’t need software or a consultant to start. Open a spreadsheet. List your processes. Add a column for risk rationale — a sentence each is fine. Add a column for last-audit results. Then lay out the next twelve months so that coverage is complete and the risky, recently-bruised areas show up more than once. Write a short paragraph at the top explaining how you chose. That paragraph is your risk-based justification, and it’s the thing that turns a calendar into a program.

The part that’s genuinely hard isn’t building the schedule — it’s keeping it honest all year. Findings pile up, a process turns risky mid-cycle, an audit slips, and you’re back in the annual sprint. This is exactly the kind of thing a real system of record is built to prevent: one that tracks which areas produced findings, nudges the schedule when risk shifts, and won’t let audits quietly vanish off the calendar. (It’s also, not coincidentally, what we built Candor — our managed internal-audit program — to do. But a well-tended spreadsheet beats a beautiful tool nobody updates. And if you’d rather hand the whole schedule to an independent lead auditor, that’s what our internal audit services are for.)

The goal isn’t a schedule that impresses an auditor. It’s a schedule that means you already found the problem in March, fixed it by May, and by the time anyone with a badge shows up, it’s an old story with a happy ending.

Next up: what auditors actually look at when they get in the room — objective evidence, sampling, and why “show me” beats “tell me” every time.

Leave a Comment

Scroll to Top