Before the Medical Device Single Audit Program, a manufacturer selling into several countries could expect a separate quality-system inspection from each regulator with jurisdiction over it, often in the same year. MDSAP replaces that with one audit whose report is meant to satisfy all of them — which only works if you know how to read what it actually says.

What the program actually replaces

MDSAP audits are conducted by an Auditing Organization jointly recognized by the program's participating regulators — FDA, Health Canada, Brazil's ANVISA, Australia's TGA, and Japan's MHLW/PMDA — and the resulting report is meant to stand in for each of their own routine inspections. Participation is voluntary, but a current MDSAP certificate is accepted by FDA as satisfying its routine surveillance inspection obligation for that site. What it doesn't replace is FDA's authority to show up anyway: a for-cause inspection tied to a complaint, a recall, or a signal from adverse event data isn't something an MDSAP certificate defers. In that sense it sits differently from an establishment inspection report, which documents an FDA inspection that already happened rather than one a certificate helped a firm avoid.

Reading the findings correctly

An MDSAP report isn't organized by department; it follows a fixed set of processes defined by the audit model itself — management, measurement and improvement, design and development, production and service controls, purchasing, and device events and advisory notices reporting among them — and every finding is tagged to one. Nonconformities are graded for severity on a scale that has no equivalent in a Form 483, which lists observations without ranking them; a grade tells you not just that something was found but how the auditor assessed its risk. Because the QMSR folds ISO 13485:2016 directly into 21 CFR Part 820, a finding written against an ISO 13485 clause now describes the same underlying requirement FDA enforces domestically — the same shift in framing that reshaped how management responsibility gets exercised under the current regulation.

Where people get stuck

Treating the certificate as blanket immunity

A current MDSAP certificate satisfies the routine surveillance obligation. It does nothing to limit FDA's for-cause inspection authority if a complaint or a signal warrants one.

Reading nonconformities like 483 observations

They're graded on a different scale and mapped to ISO 13485 clauses rather than specific 21 CFR 820 citations. Conflating the two misreads how serious a finding actually is.

Treating a zero-finding report as a clean bill of health

It reflects what the audit sampled during the days the auditor was on-site — not an exhaustive review of every process, every time.

Most practitioners encounter an MDSAP report as something to interpret rather than produce — handed one from a contract manufacturer, or asked to explain a grade to someone who's never seen one. Reading it as a structured, graded assessment against a recognized standard, rather than as a foreign cousin of a 483, is most of what separates a useful read from a superficial one.

Sources & further reading

  1. FDA — Medical Device Single Audit Program (MDSAP) fda.gov
  2. 21 CFR Part 820, Subpart A — Quality Management System Regulation ecfr.gov
  3. Regulatory Academy — How to Read an FDA Establishment Inspection Report regulatoryacademy.com
  4. Regulatory Academy — Moving from Individual Contributor to RA Manager regulatoryacademy.com

This essay is provided for general educational purposes and reflects the regulatory landscape as of its publication date. It is not legal, regulatory, or career advice.