What an auditor is really checking when a test report is opened
A quality system audit does not re-examine the laboratory's technical judgement. An auditor will not argue with you about how a tensile curve should be read or which culture medium should have been chosen. They are doing something different: confirming that the report has a traceable origin, a clear owner and a closed loop inside your quality system.
The same document is "data" from the laboratory's side and "evidence" from the ISO 13485 audit side. Evidence has to answer four questions:
- Which design input, or which risk control measure, was this data generated for?
- Do the submitted samples represent the product you intend to release?
- Is the party that issued the report one you evaluated, and one that remains under your monitoring?
- Did the conclusion actually flow back into design review, the risk management file and the release criteria?
Marks are usually lost on the first and the last of these. The testing itself is done carefully, but the report goes straight into a "registration dossier" folder when it comes back, with no pointer of any kind linking it to the design history file or the risk management file. The auditor only has to pick one risk control measure and ask which document verifies it, and the chain breaks.
A report that cannot be attributed: where nonconformities get raised
One: the product name and specification on the report cover do not match the current drawings, instructions for use and submission dossier. During development the samples were submitted under an internal project code or an engineering prototype number; after transfer to production the commercial name and commercial specification took over, and no document ever pinned the two together. The fix is not to go back and edit the report. Put an identification cross-reference note into the design history file stating that the identification used at the time of submission and the current identification point to the same design state, and have the design owner sign it.
Two: the applicant named on the report is not the actual manufacturer. In OEM and contract manufacturing arrangements the applicant is often the brand owner or a trading company while the manufacturing site belongs to someone else. The auditor will ask on what basis you treat that report as conformity evidence for your own product. It is usable, but it has to be supported by the contract manufacturing agreement, the technical file transfer record, and your evaluation record for that manufacturing site.
Three: nobody can say which post-change design state the report corresponds to. After a structural or material change the old report is still on the list of effective documents and so is the new one, and neither is annotated with the design state it applies to. When the auditor pulls that thread there is no way to defend it.
Four: the report conclusion does not match the actual scope of the product. The applicable conditions, sample configuration and test conditions stated in a report all have boundaries. Extrapolating the conclusion to specifications or use scenarios that were never covered is something both the system audit and the technical review will chase. For products with many specifications in a family, the coverage strategy has to be written at the protocol stage, together with the rationale for choosing the representative specifications.
An external laboratory is an outsourced process: an accreditation mark is not enough
Sending testing out is an outsourced process in ISO 13485 terms. Outsourcing does not transfer responsibility - you still own the result - so three kinds of record have to exist inside the system: supplier selection and evaluation, confirmation of the scope of capability, and ongoing monitoring.
There is one practical step that is easy to skip: check that the tests you are submitting fall inside the laboratory's accredited scope. Plenty of supplier evaluation forms get approved on the strength of a single tick box saying "holds CNAS accreditation". But accreditation is granted item by item, test by test and method by method. A laboratory accredited for biological evaluation is not automatically accredited for electrical safety or package integrity. The right approach is to obtain the scope of accreditation annexed to the certificate, compare it line by line against your specific test names and test methods, and file the comparison conclusion together with the certificate in the supplier record. Laboratories that operate a management system built on ISO/IEC 17025 and hold accreditation normally distinguish accredited from non-accredited items on the report itself, and that detail is worth confirming once when the report arrives.
One point is widely misunderstood and should be stated plainly: an accreditation mark only demonstrates that the laboratory has the technical competence within its accredited scope; it does not constitute a commitment regarding market access outcomes. CNAS, CMA and IAS (USA) accreditation are all third-party assessments of technical competence. Whether a report is accepted by a regulator in a given country or region depends on that jurisdiction's own regulatory requirements and review practice. Describing an accreditation mark as "this report can be used directly for submission in country X" will not survive either the system audit or the registration review.
Following on from that, two judgements need to be kept apart, and many companies merge them into one. The first is a system-level judgement: has this outsourced supplier been evaluated as acceptable, and is it under control? The second is a use-level judgement: can this report support the specific thing you are trying to do right now? The first is about whether your control of the outsourced process is adequate; the second depends on what the party receiving the report requires of the issuing body. Passing supplier evaluation does not mean the report will be accepted in every situation; conversely, a report that is accepted for a given use does not replace your own supplier evaluation record.
In practice you do not need to memorise which credential supports which use. Working backwards from the use is more reliable. Write down first who the report finally goes to and at which step it is used - internal design verification, registration submission, customer audit, tendering or product release - then, for that specific use, confirm with the receiving party or its current published requirements what it stipulates about the qualification of the issuing body, the report format and its validity, and record both the confirmation and its source in the pre-contract review record. The relationship between a given credential and the uses it can support changes as competent authorities adjust their requirements, so the current valid official requirements and the receiving party's own answer govern. Do not carry across the experience of a past project, and do not treat one precedent of acceptance as a general rule.
| Source of report | Records that must exist alongside it in the system | What auditors typically ask |
|---|---|---|
| In-house laboratory | Equipment calibration and status confirmation, personnel competence confirmation, method validation or verification records, traceable raw data | How was the competence of the person who ran this test confirmed? |
| External third-party laboratory | Supplier evaluation and approval record, line-by-line scope comparison conclusion, testing agreement, report receipt and review record | Is the test you submitted inside their accredited scope? |
| Report supplied by a raw material supplier | Supplier evaluation, material specification, defined incoming inspection or verification method, re-testing of samples where needed | If the supplier changes production site or material grade, how would you find out? |
| Existing report from another plant in the group | Design state equivalence statement, manufacturing process equivalence assessment, approval record for the transferred use | Are the two plants' processes genuinely equivalent, and who approved that? |
Sample state and representativeness: the link that usually fails on paper
The auditor's questions in this area are plain: which batch did these samples come from? Where are the production records for that batch? Were the process conditions at the time the same ones used in routine production now? Three questions in a row make it obvious whether the samples were grabbed off a shelf or drawn according to a protocol.
Biological evaluation work is especially sensitive to sample state. This work draws on the ISO 10993 series and the GB/T 16886 series; where this article cites those two numbers it means the series as a whole. Which part of the series governs a particular test, and which edition of that part applies, has to be confirmed against the current valid version of the standard text and against your own evaluation route before it goes into the protocol - do not place an order based on a part number you remember. The object of evaluation under these series is the material or device in its final, finished state as it contacts the body. If what you submit is a pre-sterilisation semi-finished part while the finished product is ethylene oxide sterilised, then the residues and material changes introduced by sterilisation are not covered, and the applicability of the report conclusion will be challenged. In the same way, if the shelf life of the product is supported by an accelerated ageing study, whether the samples used for performance verification were taken from the aged state must be stated in the protocol and backed by a sampling record. Specific test parameters and acceptance limits are likewise governed by the current valid version of the standard text.
Write a short sampling statement before submission - batch number, who drew the samples, the basis for sampling and the sample state - and hand it in with the test request. The laboratory will record it as part of the sample information. That statement answers the representativeness question directly during a system audit; it costs very little and pays back a great deal. For what to prepare before submission, work through testing requirements and the testing process item by item.
Retesting after a change: a decision path you can actually operate
Change control is where nonconformities involving test records cluster. Two extremes are common. One is to retest everything after any modification, which no budget survives. The other is "we only changed the colour, it cannot affect performance", released on instinct. The sensible approach is to turn the judgement into a set of questions that must be answered in writing, so different people reach the same conclusion.
The sequence below is an engineering analysis based on failure paths and mass transfer mechanisms, not a statistical conclusion; treat it as a reference when you build your own decision rules.
| Type of change | Questions to answer in writing first | Direction the analysis tends to point |
|---|---|---|
| Grade, formulation or supplier change for a body-contacting material | Has the nature or duration of contact changed? Is the additive package of the new material fully known? | Tends towards re-evaluation, with at least a chemical-level comparison rationale |
| Change of sterilisation method or sterilisation process conditions | Do the residue species change? Can the material degrade differently under the new method? | Tends towards re-confirming sterilisation-related tests and material compatibility |
| Change to the structural load path (ribs, welds, joining method) | Does the load travel along a new path? Has the weak section moved? | Tends towards repeating the relevant strength and durability tests |
| Colour change on a cosmetic part only, no body contact and no load | Does the masterbatch introduce new chemical substances? Does it affect legibility of visual markings? | Tends towards a documented assessment, with local verification where needed |
| Change of manufacturing site or key equipment | Can the process window be fully reproduced? Have operators been re-qualified? | Tends towards process re-confirmation, with finished-product testing selected on risk |
The value of that table is not the conclusions themselves but the way it turns "do we retest?" into a string of questions that must be answered on paper. The auditor is looking at whether you handled every change with the same logic, not at whether one particular judgement was perfectly defensible. One practical note: a change review record that says "assessed, no retesting required" with no rationale attached is almost certain to be questioned. Even one added line - contact nature unchanged, processing temperature window unchanged - changes the character of the record entirely.
Two-way traceability between the risk file and the test list
The ISO 14971 risk management file and the test reports should be navigable in both directions. From any risk control measure you should be able to reach the evidence that verifies its effectiveness; from any test report you should be able to say which risk or which design input it belongs to.
This section deals only with how test reports hang off design inputs and the risk file. How use errors trace through to risk control measures and are then verified by a summative evaluation is a chain that belongs to usability engineering; it is not covered here and will be picked up in a separate article on that topic.
In practice the chain breaks in two places.
The first is a risk control measure written too abstractly. "Reduce biological risk through material selection" cannot be tied to any concrete verification activity. The fix is to rewrite the measure as a verifiable statement pointing at a defined evaluation route and acceptance basis: where the material sits, what the nature of the contact is, and which evaluation route you intend to use to show acceptability. Only at that level of granularity does a matching report exist.
The second is that the testing was done and the report exists, but the risk management file never cites it in the residual risk evaluation and still carries "to be performed" wording. Auditors are sensitive to that phrasing - planned and completed have to be distinguishable on paper.
A simple and effective habit is to maintain a cross-reference table putting the risk control measure, the corresponding verification activity, the report number, the conclusion, and the date the conclusion was written back into the risk file all on one row. The format is not prescribed by any standard, but it saves a great deal of searching on the audit floor. It has a useful side effect too: filling it in exposes the risk control measures for which no evidence exists at all, and those blank rows are exactly what to fix first. For related methods and how tests are grouped, see the biological evaluation and sterilisation validation topics in the knowledge centre.
Record control: raw data, report status and superseded documents
The generic record requirements of a quality system take a few concrete forms when applied to testing.
Raw data and the report must reconcile. In-house laboratories should pay particular attention here: instrument export files, handwritten records and the issued report must agree one-to-one on both data and sample identification. Where electronic records are used, access rights, retention of change history and backup strategy come into play as well.
Receipt and review of a report must leave a trace. Once an external report comes back, there should be a record of who reviewed it and how an unexpected conclusion was handled. Reacting to an unfavourable conclusion by quietly sending the samples to a different laboratory with no record at all is a serious finding, and is readily judged as a failure to handle nonconforming results.
Superseded reports need a defined disposition. An old report replaced after a design change must either be marked obsolete or removed from the list of effective documents. Producing two reports with different conclusions and no status marking during an audit is very hard to explain.
Retention periods are set by you and then followed. How long records are kept is written in your procedures, and practice must match the procedure; writing a period you cannot meet is worse than not writing one.
Run the self-check before the audit
| Self-check item | How to judge whether it passes |
|---|---|
| Every effective test report points to a design input or a risk control measure | A cross-reference table exists, or the design history file cites the report explicitly |
| The laboratory's accredited scope has been compared item by item with the tests ordered | The supplier file holds the comparison conclusion, not just a copy of the certificate |
| The intended use of the report and that use's requirements on the issuing body have been confirmed | The pre-contract review states the use and the source of the confirmation, rather than being written up afterwards |
| Batch number, state and sampling basis of the submitted samples are traceable | A sampling statement exists and reconciles with production records |
| Product identification on the report agrees with current drawings and instructions for use | Where it does not, an approved identification cross-reference note exists |
| Change review records state whether retesting is required and why | Every change has a written conclusion, with no blanks |
| The risk management file cites test conclusions that were actually completed | The wording is "verified", not "to be verified" |
| Superseded reports are marked or removed from the effective list | Spot checks turn up no duplicate reports of unclear status |
| The scope of the report conclusion covers all submitted specifications | A representative specification rationale and coverage strategy are documented |
Running this table during an internal audit is far more useful than assembling documents the night before. Worth noting: most of the problems this self-check turns up do not require rerunning any test. What is missing is the pointers between records and the written rationale. The items that genuinely need resubmission are usually just the one or two that could not be explained at change review.
What SUNGO Lab can do
SUNGO Lab (Shanghai Shage Medical Technology Co., Ltd.) operates laboratories in Shanghai and Hefei, accredited by CNAS, CMA and IAS (USA), and covers biocompatibility, sterilisation and residues, packaging and transport, electrical safety and EMC testing for medical devices. To repeat the point made above: an accreditation mark only demonstrates that the laboratory has the technical competence within its accredited scope and does not constitute a commitment regarding market access outcomes; whether a report is accepted in a target market still depends on local regulations and review requirements.
For ISO 13485 audit preparation we can work with you on three things: issuing a line-by-line scope comparison statement per test so it can go straight into your supplier file; agreeing sample state, sampling statement and specification coverage strategy at the request stage, so representativeness gaps do not surface only after the report is issued; and stating the applicable sample configuration and test conditions clearly on the report so you can cite it in the design history file and the risk management file. You can also tell us the intended use of the report before placing the order, so we can confirm together whether the report format and issuing arrangement match that use. On the biocompatibility testing side we can also help map the evaluation route and the resulting test list.
If you have a submission plan or an audit date coming up, call us to discuss the approach: +86 132 4819 8029, or submit your requirements online and request a quote.