CFR 21 Part 820 (QMSR) Internal Auditing Services
Our 21 CFR Part 820 QMSR Internal Audit services help medical device manufacturers evaluate the effectiveness and compliance of their Quality Management System against current FDA requirements. Patient Guard provides independent, expert internal audits aligned with the FDA Quality Management System Regulation (QMSR) and ISO 13485:2016, helping you identify compliance gaps, strengthen your QMS, reduce regulatory risk and prepare with confidence for FDA inspection.
CFR 21 Part 820 (QMSR) Internal Auditing Services
Medical device manufacturers subject to 21 CFR Part 820 must maintain a Quality Management System that complies with the FDA’s Quality Management System Regulation (QMSR).
Effective from 2 February 2026, the QMSR incorporates ISO 13485:2016 by reference while retaining additional FDA-specific regulatory requirements applicable to medical device manufacturers operating in the United States.
Internal audits are an essential part of evaluating whether your Quality Management System is effectively implemented, maintained and compliant with applicable requirements.
Patient Guard provides independent 21 CFR Part 820 QMSR internal audit services, assessing your Quality Management System against applicable QMSR, ISO 13485:2016 and FDA-specific requirements.
Our auditors help identify compliance gaps, weaknesses and opportunities for improvement before they become significant regulatory issues, providing clear findings and practical recommendations to support corrective action.
Whether you are preparing for an FDA inspection, assessing your transition to the QMSR, or maintaining ongoing compliance, Patient Guard provides an objective assessment of your QMS to help strengthen your quality processes and maintain FDA inspection readiness.
Quality Assurance Manager
Why Choose Patient Guard for QMSR Internal Auditing?
Independent QMS Assessment
We provide an objective assessment of your Quality Management System against 21 CFR Part 820 QMSR, ISO 13485:2016 and applicable FDA-specific requirements.
Experienced Medical Device Auditors
Our auditors understand medical device quality systems and FDA regulatory expectations, providing a focused assessment of the areas that matter to your organisation.
Risk-Based Audit Approach
We focus audit activities on regulatory compliance, process effectiveness and higher-risk areas to identify weaknesses that could affect product quality or inspection readiness.
Clear & Actionable Findings
Audit findings are clearly documented and supported by practical observations, helping your team understand identified gaps and prioritise appropriate corrective actions.
FDA Inspection Readiness
Our audits help evaluate whether your QMS is effectively implemented and provide valuable insight into potential compliance issues before an FDA inspection takes place.
Ongoing Compliance Support
Following the audit, Patient Guard can support remediation, corrective actions, QMS improvements and future internal audits to help maintain continued compliance.
What Our CFR 21 Part 820 Internal Auditing Service Includes
QMS Governance & Management
Assessing management responsibilities, quality objectives, organisational roles, management review and oversight of the Quality Management System.
Document & Record Controls
Reviewing the control, approval, maintenance and retention of QMS documentation and quality records to assess effective implementation and compliance.
Design & Development
Auditing applicable design and development processes including planning, inputs, outputs, reviews, verification, validation, transfer and design changes.
Supplier & Production Controls
Assessing supplier management, purchasing activities, production controls, process validation, identification, traceability and other applicable operational processes.
CAPA & Complaint Handling
Reviewing nonconformities, corrective action, complaint handling, post-market information and applicable FDA reporting processes for effectiveness and compliance.
Audit Findings & Reporting
Providing a structured audit report detailing identified nonconformities, observations and opportunities for improvement to support corrective action and inspection readiness.
Who Requires CFR 21 Part 820 Internal Auditing?
- Medical device manufacturers selling in the United States
- Organisations preparing for FDA inspections
- Companies maintaining FDA QMSR compliance
- Start-ups entering the US medical device market
FDA QMSR (21 CFR Part 820) Requirements
Under the U.S. FDA regulatory framework, medical device manufacturers subject to 21 CFR Part 820 must maintain an effective Quality Management System that complies with the FDA Quality Management System Regulation (QMSR).
The QMSR incorporates ISO 13485:2016 by reference alongside applicable FDA-specific requirements. Manufacturers must not only establish appropriate quality processes but also ensure they are effectively implemented, maintained and supported by objective evidence.
A comprehensive 21 CFR Part 820 QMSR internal audit typically assesses the following areas:
| No | Audit Area | What We Assess |
|---|---|---|
| 1. | QMS Governance & Management | Management responsibilities, quality objectives, organisational roles, management review and evidence that the QMS is effectively implemented and maintained. |
| 2. | Document & Record Controls | Approval, control, availability, retention and integrity of QMS documentation and quality records, including evidence that documented processes are followed in practice. |
| 3. | Design & Development | Design planning, inputs, outputs, reviews, verification, validation, transfer and change controls, including supporting records and objective evidence where applicable. |
| 4. | Supplier & Production Controls | Supplier qualification and monitoring, purchasing controls, production activities, process validation, identification, traceability and control of outsourced processes. |
| 5. | Nonconformity & Corrective Action | Identification and control of nonconforming outputs, investigation of quality issues, corrective action, effectiveness checks and use of quality data to identify systemic issues. |
| 6. | Complaints & FDA Requirements | Complaint handling and applicable FDA-specific requirements, including Medical Device Reporting, corrections and removals, and associated records and escalation processes. |
| 7. | QMS Effectiveness & Inspection Readiness | Overall QMS effectiveness, implementation evidence, recurring compliance risks and areas that may require attention before an FDA inspection. |
Our Process
Audit planning
We define scope, schedule, and audit objectives.
Audit execution
We conduct the audit, including interviews, document review, and process assessment.
Reporting
We provide findings, identify non-conformities, and support corrective actions.
Areas we assess
We assess all key areas of your QMS, including:
- Design controls
- Corrective and Preventive Actions (CAPA)
- Document and record control
- Production and process controls
- Supplier management
- Complaint handling and vigilance
- Training and personnel competence
Cost of Service
CFR 21 Part 820 QMSR Internal Auditing
From
Ensure ongoing compliance and Inspection readiness with expert CFR21 Part 820 quality Internal audits.
Audit Costs
- Small Size Organisation (<10 employees) 2 day audit £2,000
- Medium Size Organisation (10-50 employees) 3 day audit £3,000
- Large Size Organisation (>50 employees) 4 day audit £4,000
Time Lines
Planning
1-2 weeks
Audit
2-4 days depending on organisation size
Reporting
2-4 days depending on organisation size
Frequently Asked Questions (FAQs)
What is a CFR 21 Part 820 internal audit?
A CFR 21 Part 820 internal audit is a systematic review of a manufacturer’s Quality Management System to ensure compliance with FDA Quality System Regulation requirements.
Are internal audits required under FDA QSR?
While not explicitly labelled the same as ISO standards, internal audits are expected as part of maintaining an effective quality system and ensuring ongoing compliance.
Can internal audits be outsourced?
Yes, outsourcing internal audits ensures independence, objectivity, and access to experienced FDA regulatory experts.
How often should QSR audits be conducted?
Audits should be conducted at planned intervals, typically annually or more frequently depending on risk and organisational complexity.
How long does a QSR internal audit take?
The duration depends on the size and complexity of your QMS but typically ranges from 2–5 days.
Related Services
Click on the links below to discover more:
Recent Blog Posts

The Complete Guide to NHS DTAC Compliance for Digital Health Manufacturers
A complete guide to NHS DTAC compliance for digital health manufacturers, covering the five DTAC assessment areas, required evidence, clinical safety, data protection, technical security, interoperability and usability, and how to prepare your digital health technology for NHS procurement.

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance
Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up
Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers
Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.

IVDR Performance Evaluation Explained: A Complete Guide for Manufacturers
Performance Evaluation is one of the most important requirements under the EU In Vitro Diagnostic Regulation (IVDR). Every manufacturer must demonstrate that their in vitro diagnostic medical device achieves its intended purpose through robust scientific validity, analytical performance and clinical performance evidence. This guide explains every stage of IVDR Performance Evaluation, including Performance Evaluation Plans (PEPs), Performance Evaluation Reports (PERs), Post-Market Performance Follow-up (PMPF) and how Performance Evaluation supports successful CE marking under Regulation (EU) 2017/746.

IVDR Classification Explained: A Complete Guide to Class A, B, C and D IVDs
Understanding how your in vitro diagnostic device is classified under the EU IVDR is one of the first and most important steps towards regulatory compliance. This guide explains the IVDR classification rules, the differences between Class A, B, C and D IVDs, how Annex VIII is applied, and how classification affects conformity assessment, technical documentation and Notified Body involvement.
Posted on Google![]()
Jay Verma3 days agoTrustindex verifies that the original source of the review is Google.
I found Patient Guard Ltd to be an exceptional partner. Their assessment was thorough, their guidance clear, and their support instrumental in helping us achieve our objectives. Steve and Ellie, in particular, were outstanding in steering us through the MHRA Class I medical device registration process.Posted on Google![]()
Munna P56 days agoTrustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.Posted on Google![]()
Peter Reeve83 days agoTrustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.Posted on Google![]()
Derek Timm83 days agoTrustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South LımıtedPosted on Google![]()
BMSCriticalCare120 days agoTrustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,Posted on Google![]()
Thomson Software791 days agoTrustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.Verified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more