MDSAP Audit Approach Rev. 11: Key Changes and Impact on Manufacturers’ QMS

20 August 2026

On August 3, 2026, Revision 11 of the MDSAP Audit Approach (AU P0002.011) was published. This document serves as the baseline reference for conducting audits under the Medical Device Single Audit Program (MDSAP) the international initiative allowing a single audit of a medical device manufacturer’s Quality Management System (QMS) to assess compliance with the regulatory requirements of participating jurisdictions: Australia, Brazil, Canada, Japan, and the United States.

The revision does not alter the overall framework of the MDSAP program but introduces targeted clarifications and updates (“Minor wording clarifications throughout”), acting directly on specific tasks and regulatory references. Although limited in scope, these changes may have a practical impact on manufacturers by clarifying how specific requirements are assessed during audit.

Key Changes across audit processes

  • Risk Management and Responsibility

Rev. 11 clarifies and relocates the risk-based approach applied to the control of QMS processes, moving the core requirements from Management Task 7 to Management Task 1: in practice, the evaluation of risk management begins immediately, during the planning and process control review of the quality system. Concurrently, Management Task 7 is refocused on top management oversight regarding product risk management throughout its entire lifecycle, including the post-market phase.

  • Personnel Competence

Management Task 6 has been refocused from training to competence. Audit attention therefore shifts from merely verifying training records to demonstrating that personnel actually possess the competencies required to perform their assigned roles.

Manufacturers must ensure objective evidence is available to demonstrate the competence criteria established for various functions and the actions taken to achieve and maintain the required level of competence through education, training, skills, and experience, as applicable.

  • Cybersecurity and Post-Market Surveillance

Cybersecurity represents one of the most notable updates in Rev. 11, embedding explicit cybersecurity expectations across Design and Development as well as monitoring processes. Under the Design and Development process, Task 7 incorporates U.S. FDA cybersecurity requirements and adds reference to Brazil’s RDC ANVISA 848/2024 (Art. 1), while Task 12 strengthens linkages with post-market monitoring.
Under Measurement, Analysis and Improvement (MAI)Task 12 incorporates specific provisions for handling post-market feedback and cybersecurity vulnerabilities. Manufacturers must ensure alignment across country-specific security requirements, design controls, and post-market signals.

  • UDI and Change Control

Revision 11 updates Unique Device Identification (UDI) expectations and change management according to target jurisdictions:

    • United States: the reference to Predetermined Change Control Plans (PCCP) has been revised, removing the prior limitation exclusively tied to artificial intelligence/machine learning-enabled devices (Registration Task 3). Additionally, design or packaging changes should be assessed to determine whether a new UDI assignment is required (Design and Development Task 13).
    • Australia: UDI responsibilities between manufacturer and sponsor are explicitly clarified (Management Task 5), alongside updated production-phase controls (Production and Service Controls Task 16).

Manufacturers must systematically assess the impact of design and process changes against market-specific regulatory registrations and identification rules.

  • Suppliers and Outsourced Activities

While the general requirement to qualify and control all critical suppliers under the Purchasing process remains fully in force, Rev. 11 updates Annex 2 by focusing audit instructions specifically on sterilization and laboratory service suppliers. Manufacturers must ensure that oversight of these outsourced operations is thoroughly documented through appropriate quality agreements, performance monitoring, supplier audits, and other applicable controls.

Impact on Manufacturers

For organizations already structured under ISO 13485:2016 and MDSAP, the objective is not to overhaul the QMS, but to verify that procedures, responsibilities, records, and objective evidence accurately reflect the clarifications in Rev. 11.

The most effective step is performing a targeted gap analysis to identify and address any documentation gaps prior to upcoming audits.

>>> Complife supports medical device manufacturers in implementing and maintaining their MDSAP programs, assessing the impact of Audit Approach revisions, and ensuring robust audit readiness. Contact us for a targeted gap assessment.

SOURCE: MDSAP Audit Approach (AU P0002.011

Share this article

Subscribe to our newsletter

Join us today and unleash your full potential