Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
    • ISO 13485 Medical Devices
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

ISO 13485 Consulting, Internal Audits and Mentoring for Medical Device Businesses

The short answer

ISO 13485 is the quality management system standard for medical devices. It applies to businesses that design, make, sterilise, import, distribute or service medical devices or their components. It’s built on the same foundations as ISO 9001, but it adds requirements for risk management, design control, traceability, complaint handling and reporting to regulators.

In Australia, a manufacturer’s QMS that complies with ISO 13485:2016 is treated, under a TGA Order, as meeting the relevant parts of the quality management system conformity assessment procedures. For sponsors and distributors, certification is usually a customer or supplier requirement rather than a legal one.

The 2016 edition was reviewed and confirmed by ISO in October 2025, so there is no new version to transition to.

Reviewed October 2026. Checked against the TGA, the Federal Register of Legislation, the FDA and ISO.

Talk to an ISO Lead Auditor →

If you make, import or supply medical devices, ISO 13485 has probably already come up. A hospital or health service asks for it in a tender. An overseas manufacturer wants it before appointing you as their Australian distributor. A customer you make components for sends you a supplier questionnaire with it on page one.

It’s the right standard for the job, and it’s a more demanding one than ISO 9001. Streamline audits, gap-assesses and mentors ISO 13485 systems for Australian medical device businesses, often alongside an existing ISO 9001 system.

On this page

  • What ISO 13485 is
  • Who needs ISO 13485
  • Where it sits with the TGA
  • What it adds to ISO 9001
  • Running ISO 13485 alongside ISO 9001
  • How we help
  • Getting certified
  • Common questions

What ISO 13485 is

ISO 13485:2016 is titled Medical devices. Quality management systems. Requirements for regulatory purposes. The last three words are the important ones. Where ISO 9001 is built around customer satisfaction and continual improvement, ISO 13485 is built around safe, effective devices and meeting the regulatory requirements of the markets you sell into.

Australia adopted it unchanged as AS ISO 13485:2017. It underpins the TGA’s quality system assessment, the international Medical Device Single Audit Program (MDSAP), and the US FDA’s Quality Management System Regulation (QMSR), which has incorporated ISO 13485:2016 by reference since 2 February 2026.

There is no new edition coming. ISO reviewed the standard in 2025 and confirmed the 2016 edition on 31 October 2025. If you have been following the ISO 9001:2026 transition, none of that applies here.

Quality professional checking a barcoded sterile device pack against a batch record on a tablet in a clean medical device facility
ISO 13485 asks you to know where every batch went. Traceability, complaints and recalls are where a medical device quality system earns its keep.

Who needs ISO 13485

  • Manufacturers of medical devices, including in vitro diagnostics, whether you design the device or make it to someone else’s design.
  • Contract manufacturers and component suppliers whose customers are device manufacturers. It usually arrives as a supplier requirement.
  • Sterilisation, packaging and calibration service providers working on devices.
  • Australian sponsors, importers and distributors. You hold the ARTG entry or move the product, so the law gives you post-market duties: distribution records, passing on complaints, adverse event reporting and recalls. ISO 13485 gives that work a structure an overseas manufacturer, a hospital or an auditor will recognise.
  • Businesses that service or install devices, where traceability and records follow the device into the field.

Where it sits with the TGA

This is where most of the confusion lives, so it’s worth being precise.

For manufacturers, the Medical Devices Regulations 2002 set out conformity assessment procedures, including quality management system procedures. The Therapeutic Goods (Conformity Assessment Standard for Quality Management Systems) Order 2019 names ISO 13485:2016. A quality management system that complies with it is treated as having had the relevant parts of those procedures applied. The Order is a deeming provision rather than a mandate, but in practice ISO 13485 is how manufacturers show the TGA their quality system works.

For evidence, the TGA accepts MDSAP certificates as manufacturing evidence and can use MDSAP audit reports to shorten its own assessment. It accepts MDSAP certificates and audit reports only where the audit covered the Australian requirements and the certificate includes Australia in scope.

What the TGA finds. In its own audit programme the TGA reports averages of 2.9 major and 8.3 minor nonconformities per audit across domestic and overseas audits (financial years 2021 to 2023). The most frequent areas are:

  • general QMS requirements and documentation (clauses 4.1 and 4.2.1)
  • purchasing (7.4.1)
  • production and service provision (7.5.1)
  • corrective action (8.5.2)
  • internal audit (8.2.4)

One of the corrective action examples it gives is “corrections instead of corrective action”. We find the same pattern at internal audit, and it is cheaper to find it there.

For sponsors and distributors, the Act and Regulations put obligations on you directly: being able to provide the manufacturer’s evidence, keeping distribution records, passing complaints to the manufacturer and assisting investigations, reporting adverse events and running recalls. ISO 13485 certification is not a legal requirement for a sponsor. It is very often a commercial one, and the post-market clauses of the standard line up closely with what the TGA expects of you anyway.

ISO 13485 certification is not market approval. It does not put a device on the ARTG, and it does not replace TGA conformity assessment. Which regulatory pathway applies depends on the device’s classification and where it is made, and that sits with your regulatory affairs adviser or the TGA. We work on the quality system that sits underneath.

What it adds to ISO 9001

AreaISO 13485:2016Why it matters
Risk managementRisk-based approach across the QMS (4.1.2) and documented risk management in product realisation (7.1)Risk is about patient and user safety, not only business risk. Most manufacturers work to ISO 14971 for this
Medical device fileA file for each device type or family (4.2.3)Holds the specifications, labelling, manufacturing and servicing requirements in one place
RecordsKept for at least the lifetime of the device, and never less than two years from release (4.2.5)Often much longer than businesses expect
QMS softwareSoftware used in the QMS has to be validated (4.1.6)Includes inventory, ERP and complaint systems, not just production software
Work environmentRequirements for work environment and contamination control (6.4)Cleanrooms, health and clothing of personnel, and control of contaminated product
Design and developmentDetailed controls through to design transfer, design changes and a design file (7.3)Can be excluded only where regulations allow, for example a distributor that designs nothing
PurchasingSupplier criteria proportionate to the risk of what you buy (7.4)A common finding in TGA audits
ValidationProcess validation (7.5.6), plus sterilisation and sterile barrier validation where relevant (7.5.7)Where you can’t fully verify the output, you validate the process
Identification and traceabilityProduct identification including UDI where required (7.5.8), traceability, and extra requirements for implantable devices (7.5.9)You need to know where every batch went
Feedback and complaintsFeedback (8.2.1), complaint handling (8.2.2), reporting to regulatory authorities (8.2.3)The post-market link to the regulator
Nonconforming productCovers product found nonconforming after delivery, and advisory notices (8.3.3)This is where recalls and field actions live
ImprovementMaintain the effectiveness of the QMS, rather than continually improve itA deliberate difference: the regulatory goal is a stable, controlled system
Clause references are to ISO 13485:2016.

The structure is different too. ISO 13485:2016 follows the older ISO 9001:2008 clause layout, not the harmonised structure ISO 9001, ISO 14001 and ISO 45001 now share. It asks for more documented procedures than ISO 9001 does. That matters most when you run the two together.

Running ISO 13485 alongside ISO 9001

Many medical device businesses hold both: ISO 13485 for the devices, ISO 9001 for the wider business or for customers who ask for it by name. The clause numbers don’t line up, so a combined system needs a map.

In a recent combined ISO 9001 and ISO 13485 internal audit for an Australian surgical supplies business, we tested traceability the way a recall would test it. We pulled batch numbers from the inventory system and followed a mock recall through to the customer list. We also built the business a conformity matrix: each clause of both standards against a plain English summary of the requirement and the evidence that meets it.

That matrix outlasts any one audit. When the person who looks after the system is away, or leaves, whoever picks it up can still show a certification auditor how every requirement is met.

Two practical points for a combined system:

  • One manual, two maps. Write the system around how the business works, then map it to each standard. Don’t run two parallel sets of procedures.
  • Two certificates. ISO 13485 certification is not ISO 9001 certification. If customers ask for both, both have to be in your certification body’s scope.

How we help

  • Gap analysis. An independent assessment of where your system stands against ISO 13485, with a prioritised action list. For a business with ISO 9001 already, it is usually the fastest way to scope the extra work.
  • Independent internal audits. Clause 8.2.4 requires them, and they’re one of the TGA’s most common findings. We audit against ISO 13485, ISO 9001 or both in one visit, on site or remotely, and test traceability, complaints and supplier control on real records.
  • ISO mentoring. For a capable quality or regulatory person building or extending the system themselves, with an experienced auditor checking the work as it goes.
  • Conformity matrices and combined systems. Mapping ISO 13485 and ISO 9001 to one set of processes, so the system is run once and audited twice.
  • Management system maintenance. Keeping internal audits, management reviews and corrective actions on schedule between certification audits.

Getting certified

Certification is through an accredited certification body, with the usual Stage 1 and Stage 2 audits followed by surveillance. Check that the body’s accreditation actually covers ISO 13485 and the technical area your devices fall into. Then decide early whether you also want MDSAP, which audits to ISO 13485 plus the requirements of the participating regulators (Australia, Brazil, Canada, Japan and the US) in one programme. Our guide to choosing an ISO certification body in Australia covers the checks.

How long it takes: three to six months for most organisations, longer for larger, multi-site or multinational ones. The variable that matters most is design control and validation. A distributor with a working ISO 9001 system is extending what it has. A manufacturer that designs its own devices, starting from scratch, has far more to build and evidence.

We don’t publish a cost range for ISO 13485. Whether you design devices, sterilise them or only distribute them moves the number too much for a range to be honest. Tell us your scope and we’ll give you a real figure.

Been asked for ISO 13485 in a tender or supplier questionnaire?

Send us the clause or questionnaire and we’ll tell you what it does and does not require, and whether your existing system is closer than you think. No obligation and no sales pitch.

Book a free consultation →

Common questions

Is ISO 13485 mandatory in Australia?

Not as a blanket legal requirement. For manufacturers, a quality system complying with ISO 13485:2016 is treated as meeting the relevant parts of the TGA’s quality management system conformity assessment procedures, which makes it the practical route. For sponsors and distributors it isn’t a legal requirement, though health customers and overseas manufacturers often ask for it.

What is the difference between ISO 9001 and ISO 13485?

ISO 13485 is a quality management system standard for medical devices. It adds risk management, design control, validation, traceability, complaint handling and regulatory reporting to ISO 9001’s foundations. It asks you to maintain the effectiveness of the system rather than continually improve it. It also follows the older ISO 9001:2008 clause structure, so the two don’t line up clause by clause.

Does ISO 13485 certification mean my device is approved by the TGA?

No. Certification shows your quality management system meets the standard. Putting a device on the Australian Register of Therapeutic Goods is a separate regulatory process that depends on the device’s classification and evidence.

Is there a new version of ISO 13485 coming?

Not at present. ISO completed its review in 2025 and confirmed the 2016 edition on 31 October 2025, so ISO 13485:2016 remains current.

Do distributors need ISO 13485?

They don’t need it by law, but it is common. The parts of the standard covering traceability, complaints, adverse event reporting and recalls describe work an Australian sponsor or distributor has to do anyway, and certification is how many overseas manufacturers and health customers check it is done.

Can design and development be excluded from ISO 13485?

Yes, where the applicable regulatory requirements allow it, for example a distributor that designs nothing. The exclusion and the reason for it have to be recorded in the quality manual.

What is MDSAP?

The Medical Device Single Audit Program lets one audit satisfy the quality system requirements of several regulators: Australia’s TGA, Brazil’s ANVISA, Health Canada, Japan’s regulators and the US FDA. The TGA accepts MDSAP certificates as manufacturing evidence.

Do you need an ISO 13485 internal audit before certification?

Yes. Clause 8.2.4 requires planned internal audits, and certification bodies normally expect to see internal audits and a management review completed, with findings followed through, before Stage 2.

How long does ISO 13485 take?

Three to six months for most organisations, longer for larger, multi-site or multinational ones. It depends mostly on how much design and validation work is in scope, and whether a working ISO 9001 system already exists.

Where Streamline fits

Streamline is run by a practising ISO Lead Auditor who audits quality management systems across manufacturing, healthcare and technical businesses, and has recently audited a combined ISO 9001 and ISO 13485 system. You deal with the auditor from the first conversation.

The honest first step is usually not certification. It’s finding out how far your current system is from the standard, and whether the clause someone has asked for applies to you at all. A gap analysis answers both. If you already hold ISO 9001, you’re extending it, not starting again.

Sources

  • ISO, ISO 13485:2016 Medical devices. Quality management systems. Requirements for regulatory purposes, confirmed 31 October 2025
  • Standards Australia, AS ISO 13485:2017
  • Federal Register of Legislation, Therapeutic Goods (Conformity Assessment Standard for Quality Management Systems) Order 2019
  • Therapeutic Goods Administration, Medical device TGA update: audit program and compliance trends
  • US Food and Drug Administration, Quality Management System Regulation (QMSR)
  • US Food and Drug Administration, Medical Device Single Audit Program (MDSAP)

Talk to an ISO Lead Auditor

If you have been asked for ISO 13485, or you need an internal audit before your next surveillance visit, email hello@streamline.business or book a free consultation.

Book a free consultation →

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • ISO 9001 quality management inspection
    ISO 9001 Quality Management Consulting, Audits & Mentoring
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Workshop supervisor checking a steel delivery against a purchase order while a contractor in hi-vis signs in, with an approved suppliers and contractor inductions whiteboard on the wall
    ISO 9001 Clause 8.4 and ISO 45001 Clause 8.1.4: One…

Quick Contact Form

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Citation Certification ISO 9001 certification mark, the JAS-ANZ accreditation symbol and the ASQ logo

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Trust Centre · Privacy Policy · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire