# Plan ISO 13485 Quality Audits

Medical device teams need consistent ISO 13485 audit planning, evidence review, finding classification, and follow-up. This skill provides structured guidance for risk-based audits, CAPA verification, auditor competency, and external audit readiness.

## Install

```bash
npx skillstore add davila7/qms-audit-expert
```

## Metadata

- Status: approved
- Slug: davila7-qms-audit-expert
- Skillstore revision: r2
- Version status: missing
- Tree hash: c602bf45203146716817b3a57abdb87984ff2e73323849e468220b29d9c55340
- Author: davila7
- GitHub username: davila7
- License: MIT
- Repository: https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/enterprise-communication/qms-audit-expert
- Ref: c43861a65bb95efcae259cd161c9d6f4dc7eec6f
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: allowed
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands, env\_access
- Quality score: 83
- Quality tier: gold
- Public page: https://skillstore.pages.dev/skills/davila7-qms-audit-expert
- Manifest: https://skillstore.pages.dev/api/skills/davila7-qms-audit-expert/manifest

## Capabilities

- Structures risk-based audit schedules using process criticality, previous findings, regulatory changes, and performance data.
- Guides preparation, opening and closing meetings, evidence collection, finding development, reporting, and follow-up.
- Classifies audit results as major nonconformities, minor nonconformities, observations, or best practices.
- Links audit findings with CAPA initiation, root cause analysis, corrective action verification, and follow-up audits.
- Supports readiness planning for regulatory inspections, certification body audits, customer audits, and mock audits.
- Outlines auditor competency criteria and audit program performance metrics.

## Use Cases

- Prioritize an annual audit program: Build an annual internal audit program that prioritizes processes using risk, prior results, CAPA performance, complaints, and operational changes.
- Prepare a process audit: Prepare a process audit plan with scope, evidence sources, interview topics, finding criteria, and follow-up requirements.
- Coordinate external audit readiness: Organize a readiness assessment, mock audit, document review, staff roles, issue escalation, and CAPA verification before an external assessment.

## Prompt Templates

### Create a basic checklist

```
Create an internal ISO 13485 audit checklist for [process]. Include objectives, scope, evidence sources, interview questions, and relevant clause areas.
```

### Plan a risk-based schedule

```
Build a risk-based annual audit schedule for [organization]. Use process criticality, prior findings, changes, complaints, and CAPA performance. Explain each frequency and scope decision.
```

### Evaluate findings and CAPA

```
Review these audit observations: [observations]. Classify each as a major nonconformity, minor nonconformity, observation, or best practice. Identify evidence gaps and CAPA follow-up needs.
```

### Prepare for an external audit

```
Design an external audit readiness program for [audit type] scheduled on [date]. Include a mock audit, document review, role assignments, escalation, CAPA verification, and daily coordination. Highlight unresolved risks and required evidence.
```

## Limitations

- Named scripts, templates, checklists, and specialized guides are not included; bundled files are generic placeholders.
- The skill provides methodology guidance but does not inspect records, conduct interviews, or verify evidence independently.
- It does not replace qualified auditors, certification bodies, regulators, or legal counsel.
- Users must verify current standards, regulations, and organization-specific procedures from authoritative sources.

## Best Practices

- Provide current procedures, process maps, metrics, prior findings, CAPA status, complaints, and recent changes before requesting an audit plan.
- Separate objective evidence, applicable requirements, finding statements, risk judgments, and recommended actions in every audit record.
- Confirm cited clauses and regulatory expectations against current official sources before approving audit criteria or responses.

## Anti Patterns

- Do not assign finding severity from assumptions or incomplete evidence.
- Do not treat generic guidance as a certification decision, regulatory conclusion, or legal opinion.
- Do not rely on named resources that are absent from the installed skill.

## Security Audit

- Audited at: 2026-07-23T13:42:45.043\+00:00
- Summary: All 32 static findings are false positives caused by Markdown fences, inline filenames, and ordinary quality management terminology. The reviewed files contain no external command execution, environment access, network reconnaissance, prompt injection, or data exfiltration behavior.

## Stats

- Views: 309
- Downloads: 22
- Favorites: 0
- Popularity score: 0
