ra-qm-team/skills/qms-audit-expert/SKILL.md
ISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use when planning internal audits, executing audits, classifying findings, preparing for external audits, or managing an audit program.
npx skillsauth add alirezarezvani/claude-skills qms-audit-expertInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
ISO 13485 internal audit methodology for medical device quality management systems.
Plan risk-based internal audit program:
| Risk Level | Frequency | Criteria | |------------|-----------|----------| | High | Quarterly | Design control, CAPA, production validation | | Medium | Semi-annual | Purchasing, training, document control | | Low | Annual | Infrastructure, management review (if stable) |
| Clause | Process | Focus Areas | |--------|---------|-------------| | 4.2 | Document Control | Document approval, distribution, obsolete control | | 5.6 | Management Review | Inputs complete, decisions documented, actions tracked | | 6.2 | Training | Competency defined, records complete, effectiveness verified | | 7.3 | Design Control | Inputs, reviews, V&V, transfer, changes | | 7.4 | Purchasing | Supplier evaluation, incoming inspection | | 7.5 | Production | Work instructions, process validation, DHR | | 7.6 | Calibration | Equipment list, calibration status, out-of-tolerance | | 8.2.2 | Internal Audit | Schedule compliance, auditor independence | | 8.3 | NC Product | Identification, segregation, disposition | | 8.5 | CAPA | Root cause, implementation, effectiveness |
Verify auditor independence before assignment:
Conduct systematic internal audit:
| Method | Use For | Documentation | |--------|---------|---------------| | Document review | Procedures, records | Document number, version, date | | Interview | Process understanding | Interviewee name, role, summary | | Observation | Actual practice | What, where, when observed | | Record trace | Process flow | Record IDs, dates, linkage |
Document Control (4.2):
Design Control (7.3):
CAPA (8.5):
See references/iso13485-audit-guide.md for complete question sets.
Document each finding with:
Requirement: [Specific ISO 13485 clause or procedure]
Evidence: [What was observed, reviewed, or heard]
Gap: [How evidence fails to meet requirement]
Example:
Requirement: ISO 13485:2016 Clause 7.6 requires calibration
at specified intervals.
Evidence: Calibration records for pH meter (EQ-042) show
last calibration 2024-01-15. Calibration interval is
12 months. Today is 2025-03-20.
Gap: Equipment is 2 months overdue for calibration,
representing a gap in calibration program execution.
Classify and manage audit findings:
| Category | Definition | CAPA Required | Timeline | |----------|------------|---------------|----------| | Major | Systematic failure or absence of element | Yes | 30 days | | Minor | Isolated lapse or partial implementation | Recommended | 60 days | | Observation | Improvement opportunity | Optional | As appropriate |
Is required element absent or failed?
├── Yes → Systematic (multiple instances)? → MAJOR
│ └── No → Could affect product safety? → MAJOR
│ └── No → MINOR
└── No → Deviation from procedure?
├── Yes → Recurring? → MAJOR
│ └── No → MINOR
└── No → Improvement opportunity? → OBSERVATION
| Finding Severity | CAPA Depth | Verification | |------------------|------------|--------------| | Major | Full root cause analysis (5-Why, Fishbone) | Next audit or within 6 months | | Minor | Immediate cause identification | Next scheduled audit | | Observation | Not required | Noted at next audit |
See references/nonconformity-classification.md for detailed guidance.
Prepare for certification body or regulatory audit:
Documentation:
Personnel:
Facility:
references/iso13485-audit-guide.md contains:
references/nonconformity-classification.md contains:
# Generate optimized audit schedule
python scripts/audit_schedule_optimizer.py --processes processes.json
# Interactive mode
python scripts/audit_schedule_optimizer.py --interactive
# JSON output for integration
python scripts/audit_schedule_optimizer.py --processes processes.json --output json
Generates risk-based audit schedule considering:
Output includes:
{
"processes": [
{
"name": "Design Control",
"iso_clause": "7.3",
"risk_level": "HIGH",
"last_audit_date": "2024-06-15",
"previous_findings": 2
},
{
"name": "Document Control",
"iso_clause": "4.2",
"risk_level": "MEDIUM",
"last_audit_date": "2024-09-01",
"previous_findings": 0
}
]
}
Track audit program effectiveness:
| Metric | Target | Measurement | |--------|--------|-------------| | Schedule compliance | >90% | Audits completed on time | | Finding closure rate | >95% | Findings closed by due date | | Repeat findings | <10% | Same finding in consecutive audits | | CAPA effectiveness | >90% | Verified effective at follow-up | | Auditor utilization | 4 days/month | Audit days per qualified auditor |
development
Use when someone wants to run a weekly review, close open loops, audit stalled projects and commitments, get their system back to trusted, restart a lapsed review habit, or says "/cs:weekly-review". Walks David Allen's three-phase loop — GET CLEAR, GET CURRENT, GET CREATIVE — with deterministic scripts that inventory open loops, gate the checklist with named gaps, and score commitment health 0-100.
development
Use when someone wants to decide whether a meeting is worth calling, price a meeting in dollars, build a timeboxed agenda with desired outcomes, or turn messy meeting notes into owned action items — or says "should this be a meeting", "/cs:meeting-prep", or "/cs:meeting-actions". Runs a cost gate (ASYNC / NOT-READY / MEET), builds a decision-first agenda, and extracts an owner + due-date checklist that flags every orphan.
development
Convert a rambling description of a desired outcome into one polished, autonomous /goal prompt ready to paste into a fresh session. Use when the user says "/fable-goal", "turn this into a goal prompt", "write me a fable prompt", "write the prompt that builds X", or rambles about something they want made and asks for the prompt that makes it happen. The output is a single copy-paste prompt, never the build itself. Do NOT use when the user wants the thing built right now in this session — only when they want the PROMPT that will make it happen in a fresh session.
development
Use when someone wants to plan a deep work day, time-block their calendar or task list, budget or cut shallow work, protect focus hours, track deep-work sessions and streaks, run an end-of-day shutdown ritual, or says "/deep-work" or "/time-block". Classifies tasks deep vs shallow, builds an energy-first time-blocked schedule that refuses deep demand past the 4-hour ceiling, batches shallow work into at most two windows, and logs focus sessions against a weekly target.