CFR 21 Part 820 (QMSR) Internal Auditing Services

Our 21 CFR Part 820 QMSR Internal Audit services help medical device manufacturers evaluate the effectiveness and compliance of their Quality Management System against current FDA requirements. Patient Guard provides independent, expert internal audits aligned with the FDA Quality Management System Regulation (QMSR) and ISO 13485:2016, helping you identify compliance gaps, strengthen your QMS, reduce regulatory risk and prepare with confidence for FDA inspection.

500+ Manufacturers Supported
BSI ISO 13485 Certified
UK & EU Offices
Former MHRA Expertise
Established 2017
Patient Guard medical device regulatory consultancy illustration showing UKCA, CE MDR, FDA, ISO 13485, IVDR and technical documentation.

CFR 21 Part 820 (QMSR) Internal Auditing Services

Medical device manufacturers subject to 21 CFR Part 820 must maintain a Quality Management System that complies with the FDA’s Quality Management System Regulation (QMSR).

Effective from 2 February 2026, the QMSR incorporates ISO 13485:2016 by reference while retaining additional FDA-specific regulatory requirements applicable to medical device manufacturers operating in the United States.

Internal audits are an essential part of evaluating whether your Quality Management System is effectively implemented, maintained and compliant with applicable requirements.

Patient Guard provides independent 21 CFR Part 820 QMSR internal audit services, assessing your Quality Management System against applicable QMSR, ISO 13485:2016 and FDA-specific requirements.

Our auditors help identify compliance gaps, weaknesses and opportunities for improvement before they become significant regulatory issues, providing clear findings and practical recommendations to support corrective action.

Whether you are preparing for an FDA inspection, assessing your transition to the QMSR, or maintaining ongoing compliance, Patient Guard provides an objective assessment of your QMS to help strengthen your quality processes and maintain FDA inspection readiness.

Alex Lewis - Patient Guard - Quality Assurance Manager
“Effective QMSR compliance requires more than documented procedures—it requires evidence that your Quality Management System is effectively implemented and maintained. Our independent internal audits assess your QMS against 21 CFR Part 820 QMSR, ISO 13485:2016 and applicable FDA-specific requirements, helping identify compliance gaps, strengthen quality processes and prepare your organisation for FDA inspection.”
Alex Lewis BSc, Lead Auditor Qualified

Quality Assurance Manager

Patient Guard 21 CFR Part 820 QMSR internal audit infographic showing ISO 13485:2016 alignment, compliance assessment, risk-based auditing and FDA inspection readiness.

Why Choose Patient Guard for QMSR Internal Auditing?

Independent QMS Assessment

We provide an objective assessment of your Quality Management System against 21 CFR Part 820 QMSR, ISO 13485:2016 and applicable FDA-specific requirements.

Experienced Medical Device Auditors

Our auditors understand medical device quality systems and FDA regulatory expectations, providing a focused assessment of the areas that matter to your organisation.

Risk-Based Audit Approach

We focus audit activities on regulatory compliance, process effectiveness and higher-risk areas to identify weaknesses that could affect product quality or inspection readiness.

Clear & Actionable Findings

Audit findings are clearly documented and supported by practical observations, helping your team understand identified gaps and prioritise appropriate corrective actions.

FDA Inspection Readiness

Our audits help evaluate whether your QMS is effectively implemented and provide valuable insight into potential compliance issues before an FDA inspection takes place.

Ongoing Compliance Support

Following the audit, Patient Guard can support remediation, corrective actions, QMS improvements and future internal audits to help maintain continued compliance.

What Our CFR 21 Part 820 Internal Auditing Service Includes

QMS Governance & Management

Assessing management responsibilities, quality objectives, organisational roles, management review and oversight of the Quality Management System.

Document & Record Controls

Reviewing the control, approval, maintenance and retention of QMS documentation and quality records to assess effective implementation and compliance.

Design & Development

Auditing applicable design and development processes including planning, inputs, outputs, reviews, verification, validation, transfer and design changes.

Supplier & Production Controls

Assessing supplier management, purchasing activities, production controls, process validation, identification, traceability and other applicable operational processes.

CAPA & Complaint Handling

Reviewing nonconformities, corrective action, complaint handling, post-market information and applicable FDA reporting processes for effectiveness and compliance.

Audit Findings & Reporting

Providing a structured audit report detailing identified nonconformities, observations and opportunities for improvement to support corrective action and inspection readiness.

Who Requires CFR 21 Part 820 Internal Auditing?

FDA QMSR (21 CFR Part 820) Requirements

Under the U.S. FDA regulatory framework, medical device manufacturers subject to 21 CFR Part 820 must maintain an effective Quality Management System that complies with the FDA Quality Management System Regulation (QMSR).

The QMSR incorporates ISO 13485:2016 by reference alongside applicable FDA-specific requirements. Manufacturers must not only establish appropriate quality processes but also ensure they are effectively implemented, maintained and supported by objective evidence.

A comprehensive 21 CFR Part 820 QMSR internal audit typically assesses the following areas:

NoAudit AreaWhat We Assess
1.QMS Governance & ManagementManagement responsibilities, quality objectives, organisational roles, management review and evidence that the QMS is effectively implemented and maintained.
2.Document & Record ControlsApproval, control, availability, retention and integrity of QMS documentation and quality records, including evidence that documented processes are followed in practice.
3.Design & DevelopmentDesign planning, inputs, outputs, reviews, verification, validation, transfer and change controls, including supporting records and objective evidence where applicable.
4.Supplier & Production ControlsSupplier qualification and monitoring, purchasing controls, production activities, process validation, identification, traceability and control of outsourced processes.
5.Nonconformity & Corrective ActionIdentification and control of nonconforming outputs, investigation of quality issues, corrective action, effectiveness checks and use of quality data to identify systemic issues.
6.Complaints & FDA RequirementsComplaint handling and applicable FDA-specific requirements, including Medical Device Reporting, corrections and removals, and associated records and escalation processes.
7.QMS Effectiveness & Inspection ReadinessOverall QMS effectiveness, implementation evidence, recurring compliance risks and areas that may require attention before an FDA inspection.

Our Process

01

Audit planning

We define scope, schedule, and audit objectives.

02

Audit execution

We conduct the audit, including interviews, document review, and process assessment.

03

Reporting

We provide findings, identify non-conformities, and support corrective actions.

Patient Guard QMSR internal audit infographic showing the audit process, ISO 13485:2016 alignment, FDA requirements, CAPA, risk management and FDA inspection readiness.

Areas we assess

We assess all key areas of your QMS, including:

Cost of Service

Premium

CFR 21 Part 820 QMSR Internal Auditing

£ 2,000

From

Ensure ongoing  compliance and Inspection readiness with expert CFR21 Part 820 quality Internal audits. 

Audit Costs

  • Small Size Organisation (<10 employees) 2 day audit £2,000
  • Medium Size Organisation (10-50 employees) 3 day audit £3,000
  • Large Size Organisation (>50 employees) 4 day audit £4,000

Time Lines

01

Planning

1-2 weeks

02

Audit

2-4 days depending on organisation size

03

Reporting

2-4 days depending on organisation size

Frequently Asked Questions (FAQs)

A CFR 21 Part 820 internal audit is a systematic review of a manufacturer’s Quality Management System to ensure compliance with FDA Quality System Regulation requirements.

While not explicitly labelled the same as ISO standards, internal audits are expected as part of maintaining an effective quality system and ensuring ongoing compliance.

Yes, outsourcing internal audits ensures independence, objectivity, and access to experienced FDA regulatory experts.

Audits should be conducted at planned intervals, typically annually or more frequently depending on risk and organisational complexity.

The duration depends on the size and complexity of your QMS but typically ranges from 2–5 days.

Related Services

Click on the links below to discover more:

Recent Blog Posts

How to Become NHS Procurement Ready: From DTAC to NHS Market Access

Preparing to sell digital health technology to the NHS requires more than completing DTAC. This guide explains how manufacturers can build a procurement-ready position by aligning regulatory compliance, clinical safety, data protection, cybersecurity, interoperability, accessibility and commercial evidence for NHS market access.

Read More »

DCB0129 and Clinical Safety: What Digital Health Manufacturers Need for NHS DTAC

For digital health manufacturers preparing to enter the NHS, clinical safety can be one of the most important—and sometimes misunderstood—parts of DTAC.
It is not enough to demonstrate that your software works.
Manufacturers need to consider what could happen if the technology fails, produces incorrect information, presents information incorrectly, contributes to a workflow error or is used in circumstances that could expose patients to harm.
This is where clinical risk management and DCB0129 become particularly important.
NHS England identifies DCB0129 as the clinical risk management standard for manufacturers of health IT systems. Its counterpart, DCB0160, applies to health organisations deploying and using health IT systems. NHS England states that compliance with these standards is required under the Health and Social Care Act 2012.
For manufacturers working towards NHS DTAC readiness, understanding the distinction—and having the right clinical safety evidence—is essential.

Read More »

DTAC Requirements Explained: The 5 Areas Digital Health Manufacturers Need to Get Right

If your digital health technology is heading towards the NHS, understanding the Digital Technology Assessment Criteria (DTAC) should be part of your market-access planning.
But one of the biggest mistakes manufacturers can make is treating DTAC as simply another questionnaire to complete.
The questions are only part of the process.
Behind your answers needs to be evidence showing that your technology and organisation have appropriate arrangements for clinical safety, data protection, technical security, interoperability, and usability and accessibility.
These five areas form the core of NHS DTAC. NHS England describes DTAC as national baseline criteria for digital health technologies entering NHS and social care.
For digital health manufacturers, the practical question is therefore not simply:
“Can we complete the DTAC assessment?”
It is:
“Can we demonstrate that our product meets the requirements?”
This guide looks at each of the five DTAC areas, the types of evidence manufacturers should consider and some of the common gaps that can delay NHS readiness.

Read More »

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance

Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

Read More »

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up

Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

Read More »
Posted on Google Google
Nafiul Shelim profile picture
Nafiul Shelim
2 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I worked with Eleanor Shackleton, from Patient Guard, for the purpose of MDR, CE and UKCA marking. Her diligence, and knowledge in clinical and regulatory requirements for medical device software was critical for us. Would highly recommend
Posted on Google Google
Jay Verma profile picture
Jay Verma
27 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I found Patient Guard Ltd to be an exceptional partner. Their assessment was thorough, their guidance clear, and their support instrumental in helping us achieve our objectives. Steve and Ellie, in particular, were outstanding in steering us through the MHRA Class I medical device registration process.
Posted on Google Google
Munna P profile picture
Munna P
80 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.
Posted on Google Google
Peter Reeve profile picture
Peter Reeve
107 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.
Posted on Google Google
Derek Timm profile picture
Derek Timm
107 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South Lımıted
Posted on Google Google
BMSCriticalCare profile picture
BMSCriticalCare
144 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,
Posted on Google Google
Thomson Software profile picture
Thomson Software
815 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.
Posted on Google Google
Hannah Maddison profile picture
Hannah Maddison
918 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Fantastic, knowledgeable team that are always there to help. My appointments have always been booked in very promptly and have always ended with all my queries resolved. I have found the team very flexible and their breadth of knowledge is second to none. Patient Guard are without doubt my go-to for all the regulatory aspects of my medical device role.
Posted on Google Google
Richard Crow profile picture
Richard Crow
953 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Patientguard are an excellent source of Medical regulatory compliance advice, we have taken advantage of their various services from their EU Rep service, to helping with Technical Files all the way through to using their ISO Templates to implement our ISO 13485 system.
Posted on Google Google
George Kitching profile picture
George Kitching
956 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
David Small and PatientGuard have been extremely helpful and supportive in assisting us with producing and updating our Technical File and Appendices for MDR certification.
Verified by Trustindex
Trustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more

Get in touch

Our Friendly Team are here to help.

Book a Free Consultation

Speak to one of our regulatory and compliance experts to arrange an obligation-free call. Our experienced team is ready to help you get your medical device to market.

UK Office

Get the Medical Device Technical Checklist

Thank you! The checklist is now ready to download.