MDSAP Requirements: How One Audit Satisfies Regulators in the US, Canada, Japan, Australia, and Brazil

Medical device manufacturers selling into multiple markets have historically faced repeated quality management system inspections from each national regulator — a costly and disruptive cycle of overlapping audits covering largely the same ground. The Medical Device Single Audit Program (MDSAP) was created to replace that duplication with a single third-party audit accepted across five major jurisdictions, and understanding how each authority uses the audit result is essential for planning market entry and maintaining registrations.

The analysis below explains what MDSAP requires of manufacturers, which regulatory authorities participate, how the single audit is conducted against the combined requirements of all five jurisdictions, and how each regulator — the FDA, Health Canada, ANVISA, TGA, and Japan's MHLW/PMDA — incorporates the MDSAP audit report and certificate into its own regulatory process.

Want to ask Rhizome your own regulatory questions? Try it for free.

The Medical Device Single Audit Program (MDSAP): one audit, five regulators

The Medical Device Single Audit Program (MDSAP) is an international program, developed through the International Medical Device Regulators Forum (IMDRF), under which a recognized third-party auditing organization conducts a single audit of a manufacturer's quality management system (QMS) that is designed to satisfy the requirements of all participating regulators at once 133135136. Its purpose is to reduce duplicative inspections and to let participating authorities share and rely on a common audit result rather than each sending its own inspectors to the same manufacturing sites 133135136. In practice, a manufacturer contracts with an authorized auditing organization to run one audit against the combined requirements of the participating jurisdictions, and the resulting MDSAP audit report and certificate are then used by each authority within its own regulatory process 143.

The participating regulators

Five regulatory authorities participate in MDSAP and accept the single audit result 132133134135143:

  • United States Food and Drug Administration (FDA) 132133134143
  • Health Canada 132133134135136140
  • Brazil's ANVISA (Agência Nacional de Vigilância Sanitária) 132135143
  • Australia's Therapeutic Goods Administration (TGA) 132133134135142143
  • Japan's Ministry of Health, Labour and Welfare (MHLW) and the Pharmaceuticals and Medical Devices Agency (PMDA) 132134143

Beyond the five decision-making members, the program and its IMDRF parent body also carry official observers and affiliates. The European Union and the WHO Prequalification of In Vitro Diagnostics Programme are named as official observers 133, and at the IMDRF level the observers include WHO and APEC, with AHWP and PAHO as affiliate organizations 144. IMDRF's broader membership spans the EU, Brazil, Russia, Australia, Japan, South Korea, China, Canada, and the US, which is the pool from which MDSAP participation and observation are drawn 139144146147.

What the audit itself requires

MDSAP is a process-based audit built on the ISO 13485 quality management system standard, and firms enrolled in the program are typically audited rather than inspected 123. Rather than walking through the QMS clause by clause, the audit is organized around a set of linked processes 123:

  • Management
  • Measurement, analysis, and improvement
  • Design and development
  • Production and service controls
  • Purchasing
  • Device marketing authorization and facility registration
  • Medical device adverse events and advisory notices 123

The last two process areas are what make the "single audit" workable across borders: alongside the ISO 13485 QMS elements, the auditor also examines each jurisdiction's regulatory obligations, such as marketing authorization, facility registration, and adverse-event and advisory-notice (recall) reporting 123. The program is explicit that an MDSAP audit covers more than the QMS/ISO 13485 baseline alone 102. The common foundation is ISO 13485:2016, the standard that the MDSAP format maps across participating jurisdictions and toward which members such as Japan's PMDA and the US FDA aligned their own quality-system expectations 99102123.

The audit cycle and reporting duties

MDSAP audits are performed by recognized auditing organizations, not by the regulators themselves; the regulators then receive and rely on the reports 111143. FDA describes the mechanism as a recognized auditing organization conducting a single regulatory audit whose report the participating authorities have committed to use 111.

The program imposes defined reporting timelines on the auditing organization. When an audit reveals a public-health threat, fraudulent activity, or a counterfeit product, the auditing organization must notify the MDSAP regulatory authorities within 5 working days of the audit's conclusion, and it must submit the full audit report documentation for evaluation within 45 calendar days of the audit end date 113. These escalation and reporting duties are what allow the regulators to act on adverse findings even though they were not physically present for the audit 113.

How each regulator uses the result

The single audit does not mean identical treatment in every country. Each authority folds the MDSAP result into its own framework, and the practical weight of an MDSAP certificate ranges from mandatory (Canada) to voluntary and abridging (US, Australia).

JurisdictionStatus of MDSAPHow the authority uses the audit result
United States (FDA)Voluntary 122FDA reviews and classifies MDSAP audit reports from recognized auditing organizations and uses them as a substitute for routine agency surveillance inspections; sites actively enrolled in MDSAP are not given surveillance inspections 111122156. Participation does not remove other inspection types: for-cause inspections are separate and unaffected, EPRC-related activities remain subject to FDA inspection, and all manufacturers stay subject to non-surveillance inspections 118122. The device inspection program still lists compliance follow-up, for-cause, specific-product-risk (SPRA), PMA preapproval, and PMA postmarket inspections 166.
Canada (Health Canada)Mandatory since 1 January 2019 140150141A valid MDSAP certificate is required to legally sell Class II, III, and IV medical devices in Canada; Health Canada is the only consortium member to make MDSAP mandatory 140100. MDSAP replaced the Canadian Medical Devices Conformity Assessment System (CMDCAS), and Health Canada stopped accepting CMDCAS certificates ahead of the deadline; the underlying standard is ISO 13485:2016 102140150.
Australia (TGA)Voluntary evidence 5455The TGA is a participating member and considers MDSAP audit reports and certificates as comparable overseas-regulator evidence when assessing conformity assessment applications or ARTG inclusion 54556572. If the report is detailed enough and covers the same sites, device categories, and Australian requirements, the TGA may abridge its assessment and use a desktop rather than an on-site review, and may accept the audit in place of a TGA surveillance assessment where the scope is satisfactory and there are no safety signals 5255576165. An MDSAP certificate alone does not automatically satisfy every TGA requirement: where compliance cannot be established, the TGA may still perform further assessment or an on-site audit, and it conducts its own surveillance audits once a conformity assessment certificate is issued 55107.
Japan (MHLW / PMDA)Uses MDSAP reports 134Japan is a consortium regulator and uses MDSAP audit reports in its QMS process; MHLW/PMDA had already been transitioning to ISO 13485:2016, which is the standard the MDSAP format maps across jurisdictions 99134. MDSAP reports can substitute for routine inspections in Japan 134.
Brazil (ANVISA)Uses MDSAP reports 134ANVISA is a consortium regulator that uses MDSAP audit reports, which can substitute for routine inspections 134135.

Across the members, the shared design intent is that one audit report from a recognized auditing organization meets the requirements of all participating authorities, whether that report substitutes for a routine inspection (Japan, Brazil, the US), helps a manufacturer avoid a routine TGA inspection in Australia, or serves as the mandatory market-entry credential in Canada 111132134136.

Practical takeaways

For a manufacturer weighing MDSAP, the value proposition is consolidation: a single recognized audit against ISO 13485 plus five jurisdictions' regulatory requirements, in place of separate national inspections, reviewed and relied on by all five authorities 111133136. The important caveats are that participation is mandatory only in Canada 140100, that in the US and Australia it substitutes for or abridges routine/surveillance assessment but does not displace for-cause, PMA-related, or other non-surveillance inspections 55118122166, and that each authority retains the ability to act on escalated audit findings and to conduct its own further assessment where the evidence is insufficient 55113.

A natural follow-up worth asking Rhizome directly: the detailed MDSAP nonconformity grading scale and how each regulator triages a given grade, the current roster of recognized auditing organizations, or how MDSAP interacts with the EU MDR/IVDR notified-body regime for a manufacturer selling into both systems.