What Does MDSAP Require of Your eQMS?
By Vaclav Vlcek, MD
Summary:
MDSAP is a single audit that satisfies the quality management system requirements of five regulatory authorities. It does not certify an eQMS as a product. It examines how a manufacturer uses one, and three controls are particularly relevant to that system: control of documents and records, personnel competence, and validation of the software itself for its intended use. This article sets out what the current MDSAP Audit Approach asks an auditor to confirm, and what that means for the system a company runs its quality work on.
Most companies do not go looking for MDSAP.
They meet it because a market requires it, and what they want from that point is a quality system that is easy to use and easy to understand. Something the team can adopt in weeks, without losing hours to a tool that fights them.
For a company that already runs an ISO 13485 quality system, that raises a fair question. How much of what MDSAP expects is already in the system they have, and how much still has to be built?
We designed our eQMS to support an organisation's ISO 13485 quality system, and we extend it to the specific requirements a client needs for the markets they are entering. The organisation itself remains responsible for configuring, validating and operating the software for its intended use, which is a requirement of the audit rather than a formality.
This article sets out what MDSAP asks of an electronic QMS, and where a working quality system already answers it.
What MDSAP Is
MDSAP, the Medical Device Single Audit Program, lets one audit by one recognized auditing organisation address the quality management system requirements of five regulatory authorities: Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA.
One audit can reduce duplicate quality system auditing across those five jurisdictions.
It does not grant market access, and it does not replace every regulator inspection. Each authority uses the outputs on its own terms. Canada requires MDSAP certification for Class II, III and IV medical device licences, following the transition from the earlier CMDCAS programme completed in 2019. FDA accepts audit reports in place of certain routine inspections, while MDSAP participation is voluntary in the United States and does not prevent for-cause, follow-up or approval-related inspections. TGA, ANVISA and the Japanese authorities use reports and certificates within their own conformity assessment and inspection processes. Marketing authorisation remains each authority's own decision.
The program is built on ISO 13485. The Audit Approach lists the requirements its audits cover, beginning with ISO 13485:2016 and adding the quality system requirements of each jurisdiction: the Australian Therapeutic Goods (Medical Devices) Regulations, the Brazilian Good Manufacturing Practices under RDC ANVISA 665/2022, the Canadian Medical Devices Regulations, Japan's MHLW Ministerial Ordinance No. 169, and the US Quality Management System Regulation.
The audit follows a defined method, set out in the MDSAP Audit Approach, document AU P0002. Auditing organisations apply it consistently, which is what makes one audit usable by several authorities.
For manufacturers based in the EU there is a further use. Under the European guidance MDCG 2020-14, notified bodies may consider complete MDSAP audit reports when planning regular surveillance audits. Those reports do not replace initial audits, unannounced audits, or annual surveillance.
Why MDSAP Audits by Process
MDSAP audits the quality system as a set of linked processes, and follows how work moves between them. It goes beyond working through the standard clause by clause.
That is why the Audit Approach defines four primary processes:
Management
Measurement, Analysis and Improvement
Design and Development
Production and Service Controls
Purchasing is audited alongside them as a supporting process.
Two further supporting processes exist to meet requirements specific to the participating authorities:
Device Marketing Authorization and Facility Registration
Medical Device Adverse Events and Advisory Notices Reporting
Within each process the audit works through numbered tasks, and each task names the requirement it tests together with the clauses and regulations behind it.
This matters for how an electronic QMS is judged.
The system is examined through the processes it supports, and through the manufacturer's use of it. An auditor looking at the Management process will check how the quality manual, quality policy and controlled procedures are approved, kept current and made available. An auditor looking at any process will expect the people carrying it out to be competent for the work.
The eQMS earns its place by making those processes controlled and evidenced, and that is the standard it has to meet.
What MDSAP Requires of the eQMS
Three controls in the current Audit Approach are particularly relevant to an electronic QMS. They are worth reading closely, because they are more specific than the program as a whole can make it seem.
| Direct eQMS-facing control | What the auditor confirms |
|---|---|
| Document and record controls (Management, Task 8) | That procedures are defined, documented and implemented for the control of documents and records of both internal and external origin required by the quality management system. And that the organisation retains records, and at least one obsolete copy of controlled documents, for a period at least equivalent to the lifetime of the device, and not less than two years from the date of product release. |
| Personnel competency (Management, Task 6) | That the organisation has determined the necessary competence for personnel performing work affecting product quality, and established processes to demonstrate, achieve or maintain it. That personnel are aware of the relevance and importance of their activities. That records of competence are maintained, and that the methodology used to evaluate the effectiveness of actions taken is proportionate to the risk associated with the work. |
| Validation of software used in the quality management system (Production and Service Controls, Task 15) | That software used in the quality management system is validated for its intended use, according to an established protocol. Expected evidence includes a requirements document describing intended use and user needs, a validation protocol, records of results, and records that software changes are controlled. |
Table 1: eQMS-facing controls in the MDSAP Audit Approach
Read together, these describe a specific behaviour.
At any moment, one version of a document is in force. The people who rely on that document can find it and are working from that version. When the document changes, the previous version is retired and the current one takes its place, while a copy of the superseded version is kept for as long as the retention rule requires.
The people doing the work are competent for it, and the organisation can show how it determined that, what it did about any gaps, and how it checked those actions worked.
And the system holding all of this has itself been validated for the use the organisation puts it to.
The Retention Rule Is Easy to Underestimate
Keeping at least one obsolete copy of every controlled document, for the lifetime of the device and never less than two years from product release, means a document control system has to hold history rather than only the current state. A system that overwrites cannot satisfy it.
Competence Is Not the Same as Training
This changed in the current revision. The Audit Approach refocused the personnel task from training to competence, and the guidance is direct about the distinction: the evaluation should demonstrate that personnel have achieved the necessary competence, not merely that they attended training.
Training remains one action an organisation can take. The audit does not stop at attendance; it examines whether the action achieved the required competence. What an auditor looks for is how competence requirements were determined, what actions addressed any gaps, and whether the check on those actions was proportionate to the risk of the work.
For a document change, this means an assessment of the effect on competence. That assessment may lead to training, to some other action, or to no action where that is justified.
Software Validation Applies to the eQMS Itself
The audit expects software used in the quality management system to be validated for its intended use. That applies to off-the-shelf systems.
An organisation may not need to review a vendor's source code or test cases. It must still confirm the software functions according to its own needs, validated against a protocol with predetermined acceptance criteria. This is computer system validation work, and it belongs to the organisation.
The consequence is worth stating plainly. No vendor can supply MDSAP or ISO 13485 conformity with a product. Conformity belongs to the organisation and to how it configures, validates and operates the system.
That is the requirement, and it is the same whether a company is preparing for MDSAP, an FDA inspection, or an ISO 13485 recertification.
Meeting the audit criteria is the baseline. The harder test is maintaining those controls in everyday work, without making the system a burden.
Where the Five Authorities Add Their Own Requirements
On top of the shared base, each authority adds national requirements. Several reach the eQMS directly, and they concern retention, record content and record integrity.
Brazil adds three controls under document and record controls that bear directly on an eQMS. Change records must include a description of the change, identification of the affected documents, the signature of the approving individuals, the approval date and when the change becomes effective. The manufacturer must maintain a master list of approved and effective documents. Electronic records and documents must have backups.
Australia requires quality management system documentation and records in relation to a device to be retained for at least five years. Certain sponsor-related records are retained for up to ten years, covering distribution and information about malfunction, deterioration or inadequacy that has led to a complaint or problem, for Class III, implantable Class IIb and Class 4 IVDs.
Japan applies differentiated periods. Fifteen years for specially designated maintenance control required medical devices, five years for other products, with shelf-life qualifications that can extend either, and five years for training records and documentation.
The obligation is to meet every requirement that applies, not a single strictest rule. A common longer retention period is one way to implement that, and it is a choice rather than an obligation. What an eQMS has to support is a retention and control approach that satisfies each applicable jurisdiction.
For the United States, document and record controls cite the Quality Management System Regulation at 21 CFR 820.35, which adds FDA-specific requirements for certain complaint, servicing and device-identification records.
21 CFR Part 11 sits alongside this rather than inside it. For manufacturers subject to FDA requirements, Part 11 may apply to particular electronic records and signatures maintained in the eQMS. Its applicability depends on the underlying FDA record requirement and on how the organisation relies on the electronic record. Part 11 remains in force, and using an eQMS does not by itself bring every record within its scope. The Audit Approach does not cite Part 11 as a document and record controls criterion, so it is best treated as a separate FDA question rather than something MDSAP creates.
What Changed in 2026
Two changes took effect in February, and a third followed in August.
The FDA's Quality Management System Regulation came into effect on 2 February 2026. It amends 21 CFR Part 820 and brings in ISO 13485:2016 by reference, aligning the US quality system requirement with the standard the rest of MDSAP is built on.
The MDSAP Audit Approach was updated to version P0002.010 in February to match, removing references and citations to the former FDA Quality System Regulation throughout. In August it was revised again, to P0002.011 with a revision date of 3 August 2026, which is the version in force. That revision refocused the personnel task from training to competence, moved risk-based control of quality system processes into the first Management task, and added device cybersecurity provisions in several places.
One change under the QMSR reaches an eQMS in a way worth noting. The exception that existed at 21 CFR 820.180(c) is not carried forward, so FDA now has the authority to inspect management review, quality audit and supplier audit reports. Records that were previously shielded from routine review are expected to be readily available.
The effect on an electronic QMS is straightforward. ISO 13485 was already the shared base across the program, and with the United States aligned to it that base carries more of what MDSAP readiness depends on. A larger set of records is also now open to inspection, which raises the value of a system where evidence is produced by the work rather than assembled afterwards.
What MDSAP Readiness Comes Down To
For the electronic system itself, three controls deserve particular attention.
Control of documents and records, so that the current version is the one in force, superseded versions are retired and kept, and evidence is retrievable for as long as the applicable retention rules require. Personnel competence, so that the organisation can show how competence was determined, what addressed any gaps, and how those actions were checked. And validation of the software itself for the use the organisation puts it to.
None of this is conferred by a product. It belongs to the organisation, and a well-built system makes it achievable rather than making it true.
That is the standard we designed our own QMS software to support, and it is the reason a large part of MDSAP readiness is a matter of doing ISO 13485 well rather than building something new.
Meeting the audit criteria is the baseline. Running a system the team can use every day, without it slowing them down or taking months to adopt, is the part that decides whether a quality system holds up or turns into a burden.
In Part 2, we take the requirements set out here and go through our own eQMS against them: how it controls a document from draft to effective, how it retires the previous version and keeps it, how it treats a revision to the document differently from a change to a shared value, and how it produces the record of all of it.
We will show how the system supports the organisation in meeting the requirement, and how it is built for everyday use rather than only for inspection.
Frequently asked questions
What is MDSAP?
MDSAP is the Medical Device Single Audit Program. It allows a single audit, performed by a recognized auditing organisation, to address the medical device quality management system requirements of five regulatory authorities. It is built on the ISO 13485 standard, with each authority adding its own national requirements.
Which regulators are MDSAP members?
The five Regulatory Authority Council members are Australia (TGA), Brazil (ANVISA), Canada (Health Canada), Japan (MHLW and PMDA) and the United States (FDA). The program also has official observers and affiliate members, and further authorities accept its outputs, so participation extends beyond those five.
Does MDSAP replace ISO 13485?
No. MDSAP is built on ISO 13485 and uses it as its foundation. Each participating authority adds its own national requirements, and the audit is conducted by process rather than clause by clause.
Does an MDSAP certificate mean my eQMS is compliant?
No. MDSAP does not certify software as a product. It examines how a manufacturer uses its quality system, including whether the software has been validated for its intended use. Conformity belongs to the organisation, not to a vendor's product.
What does MDSAP require for document control?
The Audit Approach requires an auditor to verify that procedures are defined, documented and implemented for the control of documents and records of both internal and external origin, and to confirm that the organisation retains records and at least one obsolete copy of controlled documents for a period at least equivalent to the lifetime of the device, and not less than two years from the date of product release.
How long do controlled documents have to be kept for MDSAP?
At least one obsolete copy of each controlled document must be retained for a period at least equivalent to the lifetime of the device, and not less than two years from the date of product release. Individual jurisdictions add their own periods: Australia at least five years, with certain sponsor records up to ten; Japan fifteen years for specially designated maintenance control required devices and five years otherwise, with shelf-life qualifications.
Does MDSAP require QMS software to be validated?
Yes. The Audit Approach requires that software used in the quality management system is validated for its intended use according to an established protocol. This applies to off-the-shelf software: the organisation must confirm the software functions according to its own needs, against predetermined acceptance criteria.
Does MDSAP require retraining every time a document changes?
No. The current Audit Approach focuses on competence rather than training administration. A document change should prompt an assessment of its effect on competence, which may result in training, another action, or no action where justified. The audit looks for evidence that competence was achieved, not that training was attended.
Does 21 CFR Part 11 apply to an eQMS?
It may apply to particular electronic records and signatures, depending on the underlying FDA record requirement and how the organisation relies on the electronic record. Part 11 remains in force after the Quality Management System Regulation, and using an eQMS does not by itself bring every record within its scope. The MDSAP Audit Approach does not cite Part 11 as a document and record controls criterion.
What changed for MDSAP in 2026?
The FDA's Quality Management System Regulation took effect on 2 February 2026, aligning the US quality system requirement with ISO 13485:2016. The Audit Approach was updated to P0002.010 in February to remove references to the former FDA Quality System Regulation, and revised again to P0002.011 on 3 August 2026, which refocused the personnel task from training to competence.
