If you’re creating medical devices for the European market, you’re already aware that you are not solely responsible for the device’s production at your own factory floor. The EU MDR also makes you responsible for the suppliers of your components, materials, and outsourced processes. This is why many quality teams start this process by creating an EU MDR Documentation Checklist, a straightforward but effective approach to ensure that technical files, quality agreements, and supplier records are in place where they belong before an audit has even begun. A well-structured supplier file is one of the quickest ways to trigger findings in a notified body inspection, so it is best to get this right at the outset.
Which is more important than it ever has been before?
In the past, supplier oversight was seen merely as a compliance checklist item on the old MDD. The MDR changed all that. Nowadays, notified bodies want to see that you’re actively managing your supply chain, and not just filling out a certificate once a year. When suppliers’ audits are inconsistent or inadequately documented, that is often one of the more common gaps that will be flagged by an auditor. It’s therefore no bad idea to take this process seriously.
Start by Understanding Who Actually Needs an Audit
Not all of the vendors on your list are of equal risk. A vendor that provides sterilization services, or injection-molded parts that end up in your device, is a very different problem from the one that sends your shipping boxes. When you are deciding what to order, do so after you take time to think about who could really cause an issue if there was a problem that could impact patient safety. These are your priority. The rest can typically be addressed with less supervision and less regular monitoring.
Plan the Audit With a Clear Purpose
Once you know who you’re auditing, put together a plan that spells out what you’re checking and why. This means deciding which standards apply ISO 13485, relevant MDR annexes, maybe ISO 14971 if risk management is part of the scope and building out a checklist that reflects those requirements rather than a generic template. It also helps to let the supplier know in advance what you’ll be looking at and who you’ll need to speak with. Audits go much smoother when nobody is caught off guard.
What the Actual Audit Should Look Like
When you’re there, whether in person or remotely, the goal is to see evidence, not just hear reassurances. Walk the floor if you can. Talk to the people actually doing the work, not just the quality manager reciting procedures. Trace a component back through the system to see if the paperwork holds up. Look at how equipment is calibrated and how the supplier handles it when something goes wrong. A supplier that can show you a messy but honest deviation log is often in better shape than one that claims nothing has ever gone wrong.
Be Honest About What You Find
After the audit, findings usually fall somewhere between critical issues that need immediate attention and smaller observations worth noting for the future. What matters most is that everything you write down is backed by something concrete — a document, a photo, an observation you can point to. Vague findings are hard to act on and even harder to defend if a notified body ever asks about them.
Don’t Stop at the Report
This is where a lot of audit programs fall short. The audit report goes out, the supplier promises to fix things, and then nobody checks back in. A proper process requires the supplier to explain not just what they’ll fix, but why the problem happened in the first place. And it’s on you to confirm those fixes actually worked, whether that means reviewing updated documentation or going back for a closer look.
A Few Mistakes Worth Avoiding
The biggest one is treating audits as routine paperwork instead of genuine risk management. Close behind that is forgetting to re-audit after a supplier changes ownership, moves facilities, or shifts its processes significantly. It’s also easy to lose track of subcontractors working beneath your direct suppliers, even though they can carry just as much risk. None of these mistakes are dramatic on their own, but they tend to compound over time.
Final Thoughts
A well-run Supplier Audit Medical Device program isn’t really about satisfying a regulation; it’s about knowing, with real confidence, that everything going into your device meets the standard your patients depend on. The manufacturers who get the most value out of this process are the ones who treat it as an ongoing relationship with their suppliers rather than an annual formality. Build the habit of asking hard questions, following through on what you find, and keeping your documentation honest, and the compliance side of things tends to take care of itself.

