The internal audit stays a checklist outside product context.
Without software / AI and field evidence anchoring, the report reassures on paper and misses the gaps that matter under MDR / IVDR.
Service · Internal audit
ISO 13485, MDR / IVDR for medical software.
BSI-certified auditors, prioritized gap plan.
30-min call · no commitment
+35 projects accompanied.



















The problem we solve
For manufacturers of software and AI systems in healthcare, an internal audit that is too light or too late lets ISO 13485, MDR / IVDR gaps through that get expensive in front of a notified body.
Without software / AI and field evidence anchoring, the report reassures on paper and misses the gaps that matter under MDR / IVDR.
Gaps found too late, improvised action plans, teams under pressure. An early internal audit secures the rhythm.
Long reports, little clarity on what blocks an NB. You need a useful ranking for product and quality.
Our approach
Two levers: a field audit led by BSI-certified auditors, and a prioritized report to secure ISO 13485, MDR / IVDR before external review.
How we deliver
Framed scope, interviews, evidence review and QMS / file challenge. Focus on medical software and SaMD, at your teams' pace.
You leave with
Ranked gaps, priority recommendations and watchpoints before management review, filing or notified body.
Often after a Programme PULSE, to verify its effectiveness, or ahead of a certification audit.
They secured their audit rhythm with us
This internal audit helped us see where we stood. I especially appreciated Floryan's timing and pedagogy with our team, for our first medical device creation.
Floryan led the internal audit of our Quality Management System with real attention to detail and strong knowledge of software medical device frameworks. A demanding but constructive exercise that truly helped us progress.
The logical next step
Classification, gap analysis and MDR/IVDR/AI Act roadmap before you commit file and teams.
ISO 13485 QMS, technical file and support through the notified body.
Digital QMS in Notion, Atlassian (Jira / Confluence), GitHub or GitLab.
If the foundation is in place: continuous compliance in your tools (does not replace eQMS).
FAQ
ISO 13485 calls for planned internal audits to check QMS conformity and effectiveness, including applicable regulatory requirements (MDR/IVDR). Beyond the standard expectation, it is the best dress rehearsal before an external review or notified-body audit: you find gaps while there is still time to fix them.
An internal audit (or one by a mandated third party) checks your system for you. A certification / notified-body audit is run by an accredited body and conditions the certificate or marking. A field internal audit anchored in medical software reduces day-J surprises.
Yes, and it is common to secure independence and a notified-body style reading. QARA PULSE works with BSI-certified auditors, focused on medical software and field evidence. You leave with prioritized findings and actionable watch-outs.
In practice, schedule the internal audit 2 to 3 months before a certification audit or notified-body review, so you have time to plan and close nonconformities. Too late, and action plans get improvised under pressure. QARA PULSE delivers a prioritized gap report, anchored in product / software — not an out-of-context checklist.
30 min to plan your next internal audit.