What Does MDSAP Require of Your eQMS?
Part 1 of a series on building an MDSAP-ready electronic quality management system.
[By: QMLogic team]
Summary:
MDSAP is a single audit that satisfies the medical device regulators of five countries. It is built on ISO 13485, so a quality system built properly to that standard already covers a large part of what MDSAP examines.
For the electronic QMS specifically, the requirements are a defined set: control of documents, control of records, and training and competence, together with the record and signature integrity that regulators such as the FDA expect. This article sets out that set, and shows where an ISO 13485 system already answers it.
What MDSAP is
MDSAP, the Medical Device Single Audit Program, lets one audit by one recognized auditing organization satisfy the quality management system requirements of five regulators at once: Australia's TGA, Brazil's ANVISA, Health Canada, Japan's MHLW and PMDA, and the US FDA. One audit, five markets, instead of a separate inspection for each.
The program is built on ISO 13485, the international standard for medical device quality management systems. Each participating country then layers its own regulatory requirements on top of that shared base. The audit itself follows a defined method, set out in the MDSAP Audit Approach (document AU P0002), which auditing organizations apply consistently across every audit.
For most companies, MDSAP enters the picture for one of a few reasons.
Canada requires it: since 2019, a valid MDSAP certificate has been the route to holding a Medical Device Licence there.
Others adopt it to reach the United States or Australia through a single recognized audit rather than several.
And for manufacturers based in the EU, an MDSAP certificate can also support MDR surveillance, since notified bodies may take MDSAP audit reports into account under the European guidance MDCG 2020-14.
The result is one audit that carries weight across several of the markets a growing manufacturer is likely to enter.
Why MDSAP Audits by Process
MDSAP does not walk through ISO 13485 from clause 4 to clause 8. It audits the quality system as a set of linked processes, and follows how work moves between them.
The Audit Approach defines a primary set of processes:
Management
Measurement, Analysis and Improvement
Design and Development
Production and Service Controls
Alongside these sit supporting processes, including Purchasing, and two that are specific to the regulators:
Device Marketing Authorization and Facility Registration
Medical Device Adverse Events and Advisory Notices Reporting
The auditor moves through these processes and tests the links between them, rather than checking clauses against a list.
This matters for how an electronic QMS is judged. The system is not audited as a standalone product. It is audited through the processes it supports.
An auditor examining the Management process will look at how the quality manual, quality policy, and controlled procedures are approved, kept current, and made available. An auditor checking any process will expect to see that the people carrying it out are trained on the current versions of the documents that govern it.
The eQMS earns its place by making those processes controlled and evidenced.
What MDSAP Requires of The eQMS
An electronic QMS is the backbone for controlling documents, records, and training. So the part of MDSAP that lands directly on the eQMS is a defined slice of ISO 13485, and it is worth stating precisely, because it is smaller and clearer than the program as a whole can make it seem.
These are the three requirements that carry the most weight:
| Requirement | ISO 13485 reference | What the system has to do |
|---|---|---|
| Control of documents | 4.2.4 | Approve documents before use; review, update, and re-approve them; make the current version available where it is needed; identify changes and current revision status; prevent the use of obsolete documents while retaining them as needed. |
| Control of records | 4.2.5 | Keep records legible, readily identifiable, and retrievable; protect them from loss or alteration; define and apply retention periods. |
| Competence and training | 6.2 | Determine the competence needed for each role; provide training; ensure people are aware of the documents relevant to their work; keep records of the training completed. |
Read together, these describe a specific behaviour. At any moment, one version of a document is in force. The people who rely on that document can find it, are working from that version and not an earlier one, and have been trained on it.
When the document changes, the previous version is retired, the current one takes its place, and training follows the change. Every one of those actions leaves a record that can be produced on request.
That is the requirement. It is finite, and it is the same whether a company is preparing for MDSAP, an FDA inspection, or an ISO 13485 recertification.
A quality system built properly to ISO 13485 already meets most of it. Where a specific eQMS falls short, the requirement does not change; the system has to be configured or extended to meet it.
Where The Five Countries Add Their Own Requirements
On top of the shared ISO 13485 base, each of the five regulators adds their own national requirements.
Most of these concern the wider quality system and sit outside the document, record, and training control an eQMS provides. A smaller number reach the eQMS directly, and they concern the integrity of electronic records and signatures.
The clearest example is the United States. FDA expects electronic records and electronic signatures to meet 21 CFR Part 11, which sets requirements for matters such as attributable signatures, secure and time-stamped audit trails, and controls over who can create, change, or approve a record.
An eQMS used for FDA-regulated work is expected to support these controls, and to produce the evidence that they are in place. Part 11 applies to the electronic records themselves, and remains in force independently of the quality system regulation.
Other jurisdictions carry their own record and retention expectations, and a system serving several markets has to satisfy the strictest that applies to it.
For an eQMS, the practical effect is consistent: signatures have to be attributable to a named individual, records have to be protected from undocumented change, and the history of who did what, and when, has to be available for audit.
What Changed in 2026, and Why The ISO 13485 Matters
Two changes took effect in early 2026:
The FDA's Quality Management System Regulation (QMSR) came into effect on 2 February 2026. It amends 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, aligning the US quality system requirement with the same standard the rest of MDSAP is built on.
The MDSAP Audit Approach was updated to version P0002.010, revised on 6 February 2026, to reflect the new US position and remove references to the previous US regulation.
The effect on an electronic QMS is straightforward. ISO 13485 was already the shared base across the program. With the United States now aligned to it as well, that base carries even more of what MDSAP readiness depends on.
A system built properly to ISO 13485 is now closer to satisfying all five regulators at the document, record, and training level than it was before.
One point remains separate. QMSR concerns the quality system requirement; 21 CFR Part 11 concerns electronic records and signatures, and it continues to apply on its own terms. An eQMS still has to meet both.
What MDSAP Compliance Translates to
MDSAP readiness for an electronic QMS comes down to a defined set of requirements.
Control of documents, so that one current version is in force and available and obsolete versions are retired
Control of records, so that evidence is legible, retrievable, retained, and protected
Training and competence, so that people are trained on the current documents, and that training is recorded
The record and signature integrity that regulators such as the FDA expect
A quality system built properly to ISO 13485 already answers most of this. That is the standard we built our own eQMS to, and it is the reason a large part of MDSAP readiness is a matter of doing ISO 13485 well rather than building something new.
Meeting the requirement is one thing. Running a system that meets it, day to day, without slowing the people who depend on it, is another.
In Part 2, we take the requirements set out here and go through our own eQMS against them: how it controls a document from draft to effective, how it retires the previous version, how it ties training to the document that changed, and how it produces the record of all of it.
We will show where the system meets the standard, and how it is built to be operated rather than only inspected.
Frequently asked questions
What is MDSAP?
MDSAP is the Medical Device Single Audit Program. It allows a single audit, performed by a recognized auditing organization, to satisfy the medical device quality management system requirements of five regulators: Australia, Brazil, Canada, Japan, and the United States. It is built on the ISO 13485 standard.
Does MDSAP replace ISO 13485?
No. MDSAP is built on ISO 13485 and uses it as its foundation. Each participating country adds its own national requirements on top, and the audit is conducted by process rather than clause by clause. A quality system built to ISO 13485 already meets a large part of what MDSAP examines.
Which countries participate in MDSAP?
Five: Australia (TGA), Brazil (ANVISA), Canada (Health Canada), Japan (MHLW and PMDA), and the United States (FDA). Canada requires a valid MDSAP certificate for market access.
What does MDSAP require for document control?
At the electronic QMS level, MDSAP relies on ISO 13485 clause 4.2.4: documents are approved before use, reviewed and re-approved when changed, made available in their current version where they are needed, and controlled so that obsolete versions are not used unintentionally.
Does 21 CFR Part 11 still apply after QMSR?
Yes. The Quality Management System Regulation (QMSR), effective 2 February 2026, concerns the quality system requirement and incorporates ISO 13485:2016 by reference. 21 CFR Part 11 concerns electronic records and signatures, and continues to apply independently.
What changed for MDSAP in 2026?
The FDA's QMSR took effect on 2 February 2026, aligning the US quality system requirement with ISO 13485:2016. The MDSAP Audit Approach was updated to version P0002.010 on 6 February 2026 to reflect this. Both changes reinforce ISO 13485 as the shared basis of the program.
