ra-qm-team/skills/qms-audit-expert/SKILL.md
ISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use for internal audit planning, audit execution, finding classification, external audit preparation, or audit program management.
npx skillsauth add alirezarezvani/claude-skills qms-audit-expertInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
ISO 13485 internal audit methodology for medical device quality management systems.
Plan risk-based internal audit program:
| Risk Level | Frequency | Criteria | |------------|-----------|----------| | High | Quarterly | Design control, CAPA, production validation | | Medium | Semi-annual | Purchasing, training, document control | | Low | Annual | Infrastructure, management review (if stable) |
| Clause | Process | Focus Areas | |--------|---------|-------------| | 4.2 | Document Control | Document approval, distribution, obsolete control | | 5.6 | Management Review | Inputs complete, decisions documented, actions tracked | | 6.2 | Training | Competency defined, records complete, effectiveness verified | | 7.3 | Design Control | Inputs, reviews, V&V, transfer, changes | | 7.4 | Purchasing | Supplier evaluation, incoming inspection | | 7.5 | Production | Work instructions, process validation, DHR | | 7.6 | Calibration | Equipment list, calibration status, out-of-tolerance | | 8.2.2 | Internal Audit | Schedule compliance, auditor independence | | 8.3 | NC Product | Identification, segregation, disposition | | 8.5 | CAPA | Root cause, implementation, effectiveness |
Verify auditor independence before assignment:
Conduct systematic internal audit:
| Method | Use For | Documentation | |--------|---------|---------------| | Document review | Procedures, records | Document number, version, date | | Interview | Process understanding | Interviewee name, role, summary | | Observation | Actual practice | What, where, when observed | | Record trace | Process flow | Record IDs, dates, linkage |
Document Control (4.2):
Design Control (7.3):
CAPA (8.5):
See references/iso13485-audit-guide.md for complete question sets.
Document each finding with:
Requirement: [Specific ISO 13485 clause or procedure]
Evidence: [What was observed, reviewed, or heard]
Gap: [How evidence fails to meet requirement]
Example:
Requirement: ISO 13485:2016 Clause 7.6 requires calibration
at specified intervals.
Evidence: Calibration records for pH meter (EQ-042) show
last calibration 2024-01-15. Calibration interval is
12 months. Today is 2025-03-20.
Gap: Equipment is 2 months overdue for calibration,
representing a gap in calibration program execution.
Classify and manage audit findings:
| Category | Definition | CAPA Required | Timeline | |----------|------------|---------------|----------| | Major | Systematic failure or absence of element | Yes | 30 days | | Minor | Isolated lapse or partial implementation | Recommended | 60 days | | Observation | Improvement opportunity | Optional | As appropriate |
Is required element absent or failed?
├── Yes → Systematic (multiple instances)? → MAJOR
│ └── No → Could affect product safety? → MAJOR
│ └── No → MINOR
└── No → Deviation from procedure?
├── Yes → Recurring? → MAJOR
│ └── No → MINOR
└── No → Improvement opportunity? → OBSERVATION
| Finding Severity | CAPA Depth | Verification | |------------------|------------|--------------| | Major | Full root cause analysis (5-Why, Fishbone) | Next audit or within 6 months | | Minor | Immediate cause identification | Next scheduled audit | | Observation | Not required | Noted at next audit |
See references/nonconformity-classification.md for detailed guidance.
Prepare for certification body or regulatory audit:
Documentation:
Personnel:
Facility:
references/iso13485-audit-guide.md contains:
references/nonconformity-classification.md contains:
# Generate optimized audit schedule
python scripts/audit_schedule_optimizer.py --processes processes.json
# Interactive mode
python scripts/audit_schedule_optimizer.py --interactive
# JSON output for integration
python scripts/audit_schedule_optimizer.py --processes processes.json --output json
Generates risk-based audit schedule considering:
Output includes:
{
"processes": [
{
"name": "Design Control",
"iso_clause": "7.3",
"risk_level": "HIGH",
"last_audit_date": "2024-06-15",
"previous_findings": 2
},
{
"name": "Document Control",
"iso_clause": "4.2",
"risk_level": "MEDIUM",
"last_audit_date": "2024-09-01",
"previous_findings": 0
}
]
}
Track audit program effectiveness:
| Metric | Target | Measurement | |--------|--------|-------------| | Schedule compliance | >90% | Audits completed on time | | Finding closure rate | >95% | Findings closed by due date | | Repeat findings | <10% | Same finding in consecutive audits | | CAPA effectiveness | >90% | Verified effective at follow-up | | Auditor utilization | 4 days/month | Audit days per qualified auditor |
tools
Code review automation for TypeScript, JavaScript, Python, Go, Swift, Kotlin, C#, .NET, Java, C, C++, Rust, Ruby, PHP, and Dart/Flutter. Analyzes PRs for complexity and risk, checks code quality for SOLID violations and code smells, generates review reports. Use when reviewing pull requests, analyzing code quality, identifying issues, generating review checklists.
tools
Use when planning, funding, scoping, or synthesizing enterprise research across workstreams — clinical study design, R&D program finance, market sizing/surveys, or product/user research. Triggers on "design this clinical study", "what sample size", "R&D budget", "burn rate", "capitalize or expense", "TAM SAM SOM", "market sizing", "survey design", "segment the market", "plan user interviews", "usability test", "synthesize research insights". Forks context to route to one of four Research-Operations sub-skills (clinical-research, research-finance, market-research, product-research) and returns a digest. Distinct from ra-qm-team (regulatory submission), finance (corporate close/valuation), research/grants (funding discovery), product-team (persona/journey/live experiments), and marketing-skill (campaign analytics).
development
Use when managing the money for an internal R&D program or portfolio — building a multi-period program budget with the F&A (indirect) split, tracking burn rate and runway against value-inflection milestones, or routing R&D cost items to a capitalize-vs-expense determination. Every budget output surfaces its assumptions block; capitalize-vs-expense is decision-support only and routes to a named finance owner — it never books an entry or decides accounting treatment. Distinct from finance/financial-analysis (corporate DCF, close, valuation) and research/grants (funding discovery — this manages money already won).
development
Use when planning and synthesizing product/user research as a method-and-repository discipline — selecting the right method for the goal (generative interviews vs usability test vs concept test vs validation), computing method-based saturation/sample size with an explicit confidence level, or synthesizing coded observations into insights while flagging single-source anecdotes. Never fabricates user insight; an insight requires recurrence across independent participants. Distinct from product-team/ux-researcher-designer (persona/journey artifacts), product-discovery (discovery-sprint planning), and experiment-designer (live A/B) — this is the research-ops method + insight-repository layer.