Your Internal Audit Isn’t a Test — It’s a Confession (and the FDA Can Now Read It)

I once watched a quality manager prep for an internal audit by quietly fixing everything she already knew was broken, the week before, so the auditor wouldn’t write it up. She was proud of this. She’d hidden a dozen real problems so that her audit report would come back clean.

Reader, that is the exact opposite of the point.

If you’ve been in this industry for more than a hot minute, you’ve met that instinct — maybe you’ve had that instinct. An audit is coming, so we tidy up, we rehearse, we make sure the binder looks good. We treat it like a test to pass. And I get it. Nobody enjoys being written up. But an internal audit that you’ve carefully arranged to pass is a thermometer you’ve held under warm water before taking your temperature. The number looks great. It tells you nothing.

What internal audits are actually for

Here’s the whole idea, stripped of jargon: an internal audit is how an organization checks its own work before someone external does it for them — and a lot less gently. You audit yourself so that the gap, the missing record, the procedure nobody actually follows, gets found by you, on a Tuesday, when you have time to fix it — instead of by an FDA investigator, on the third day of an inspection, when you very much do not.

That’s it. That’s the intent. Internal audits are not a compliance tax. They are the cheapest, lowest-stakes early-warning system you will ever own. The goal is not a clean report. The goal is to find things. A good internal audit that surfaces eight real problems did its job. A “clean” audit that found nothing usually means the auditor didn’t look hard enough — or wasn’t allowed to.

What ISO 13485 §8.2.4 actually asks of you

Under the QMSR, this lives in ISO 13485 clause 8.2.4, and it’s refreshingly down-to-earth. You’re expected to:

  • Audit at planned intervals — on a schedule, not whenever someone remembers in December.
  • Base that schedule on what matters — the importance and status of each area. Your sterilization process and your bulletin-board procedure do not deserve equal attention. Audit the risky, the changed, and the historically troubled more often.
  • Check two things: that your QMS conforms to the requirements (ISO 13485, the QMSR, and your own procedures), and that it’s actually being implemented and maintained. “We have a procedure” and “we follow the procedure” are different findings.
  • Use objective auditors. People don’t audit their own work. More on that in a later post, but the principle is simple: you cannot grade your own homework and call it independent.
  • Act without undue delay. Findings get corrections, and the causes get dealt with. An audit that ends with a report nobody acts on is just expensive paperwork.
  • Keep records of the program, the audits, and the results.

Notice what’s not in there: any requirement that the audit come back clean. The standard assumes you’ll find things. It’s built around finding things.

The plot twist: FDA can now read these

Here’s where the new world changes the stakes. Under the old QSR, §820.180(c) kept your internal audit reports out of FDA’s hands during a routine inspection. It was a deliberate bargain: regulators traded visibility for candor, on the theory that you’d audit yourself more honestly if the results stayed private. The QMSR retired that exception. Your audit records are now fair game.

And I can already hear the instinct kicking in: well, then we’ll just write softer findings. Make the reports vaguer. Stop putting the scary stuff in writing.

Please don’t. That is the warm-water-thermometer move at the scale of your entire quality system. The fix isn’t to neuter your audits so the records look tame — it’s to audit honestly, and then actually close what you find, so that when FDA reads the file they see exactly what good looks like: a company that catches its own problems and fixes them. A documented finding with a completed, verified corrective action isn’t evidence against you. It’s the best evidence for you there is. An empty audit history, on the other hand, tells an investigator either that nothing was looked at or that something’s being hidden. Neither is the impression you want.

What to do Monday

Stop measuring your audit program by how clean the reports are. Start measuring it by whether the findings are real, whether they’re getting closed, and whether the same problems keep coming back (they shouldn’t — that’s a “show your work” failure for another day). Build a schedule that leans into your riskiest, most-changed areas. And if your team is too small to audit itself with a straight face — which is most small manufacturers — that’s exactly the kind of overwatch we built Candor and Red Hen Admin to provide: an independent set of eyes, a real schedule, and a system of record that keeps the whole thing honest.

An internal audit isn’t the test. It’s the dress rehearsal you get to fail in private. Use it that way.

Leave a Comment

Scroll to Top