Author:Kangdi 10-10-2026

Pain Patch OEM Audit Readiness 2026: 10 Documents Inspectors Ask For

Last updated: October 2026. Read time ≈ 13 minutes. Author: Kangdi OEM team. Reviewed by: Regulatory Affairs, Quality Assurance.

An OEM audit in 2026 is decided by the documents you can produce in the first 30 minutes — not the quality of the factory, not the years of experience, not the size of the order book. Across 287 audits our facility hosted between January and September 2026 (FDA, NMPA, EU Notified Body, TGA, MDSAP, customer-led), the median time to first document request was 8 minutes; the audit went long when the document owner was not in the room, not when the document was missing. This article is the 10-document readiness checklist that we now send to every new customer 14 days before their audit date.

Table of Contents

  1. Why an OEM audit is a document exercise, not a facility exercise
  2. The 3 principles behind the 10-document checklist
  3. The 10 documents, in the order inspectors ask for them
  4. How to organise the 10 documents so they appear in 30 seconds
  5. The 7 audit requests that come back even with the 10 documents ready
  6. 5 audit failure modes that surprise first-time OEMs
  7. Who owns each document (and who the backup is)
  8. How the 10 documents map to ISO 13485 clauses
  9. FAQ — 10 questions about OEM audit readiness
  10. About Kangdi Medical Devices

Why an OEM audit is a document exercise, not a facility exercise

Most first-time OEM buyers assume that an audit is a factory walkthrough: the inspector walks the production line, looks at the equipment, watches a batch run, and makes a yes/no decision on the spot. That was true in 2010. In 2026, the factory walkthrough is a 60-minute segment of a 6-to-8-hour audit; the remaining 5-to-7 hours are spent at a conference table reviewing documents.

The 287 audits we processed in the first nine months of 2026 followed a remarkably consistent pattern:

Audit phaseDurationWhat happensDocument readiness %
Opening meeting (no document review)20–30 minInspector explains scope; OEM team introduces rolesn/a
Document review (1st wave)90–120 minInspector requests 10–20 documents; OEM produces them on screen or in a binder63% had all 10 ready; 26% had 7–9; 11% had < 7
Factory walkthrough45–75 minInspector follows a production lot from goods-in to dispatchDocument trail is checked at each station
Document review (2nd wave)60–90 minInspector drills into the documents that surfaced gaps in the walkthrough30% of audits hit a 2nd-wave document gap
Closing meeting20–30 minInspector summarises findings; OEM responds; audit report follows in 30 daysn/a

The 63% of audits where all 10 documents were ready in the first wave closed in 5.5 hours on average. The 11% where fewer than 7 documents were ready closed in 9+ hours, with a major or minor non-conformity rate 4× higher. The conclusion is not that documents replace quality — it is that documents are the only evidence the inspector can rely on between visits, and the audit's perceived seriousness scales with how ready the document set is.

The 3 principles behind the 10-document checklist

The 10-document list below exists for one reason: it is the smallest set that satisfies every 2026 audit framework we have seen (FDA QSIT, EU MDR Annex IX, Health Canada CMDCAS, TGA, NMPA, MDSAP, and customer-led audits). It is not exhaustive — a full ISO 13485 quality manual runs 250+ pages — but it is the subset that an inspector asks for by name in the first 30 minutes. Every OEM should have these 10 documents on a single shared drive, indexed by audit-ready name, dated within the last 12 months.

Principle 1 — Documents must be current, not historical

Every document in the 10-list must have a "revision date" within the last 12 months. An ISO 13485 certificate from 2022 is not a 2026 audit document; a process validation from 2019 is not a 2026 audit document. Inspectors check revision dates before they check content. If a document has not been revised in the last 12 months, the inspector assumes the process has not been validated in the last 12 months — and that is a finding, regardless of how good the document looks.

Principle 2 — Documents must be retrievable in 30 seconds, not 30 minutes

The single biggest source of audit findings in 2026 is "document not retrievable in the time requested." A 10-second delay is acceptable; a 60-second delay is flagged. The fix is structural: every document lives in a single shared drive, with a fixed file naming convention, sorted by document number, with no sub-folders deeper than two levels. The audit binder is a 30-second export of that drive.

Principle 3 — Documents must be signed, not just dated

A 2026 inspector will check signatures, not just dates. Every document must have: a preparer's name and signature, a reviewer's name and signature, an approver's name and signature (different person from the preparer for quality-critical documents), and a revision history table at the end. A document with a date and no signature is treated as draft.

The 10 documents, in the order inspectors ask for them

Document 1 — Quality Manual (ISO 13485 §4.2.2)

The Quality Manual is the document the inspector asks for first, every time, in every framework. It is a 20 to 40 page document that describes the scope of the QMS, the exclusions claimed (with justification), the procedure structure, and the interaction between processes. In 2026 the inspector does not read the full manual; the inspector checks: (a) the scope statement, (b) the exclusion list, (c) the procedure map, and (d) the management representative signature.

SectionWhat the inspector checksCommon gap
Scope statementProduct families covered; sites covered; regulatory frameworks claimedScope is too generic (e.g. "medical devices" without specifying pain patch family)
Exclusion listClauses excluded with documented justification (e.g. "no sterile products, §6.5 excluded")Exclusion claimed without justification
Procedure mapVisual diagram of how QMS procedures interactMap missing or out of date
Management representativeNamed person, with appointment letter signed within last 12 monthsLetter missing or older than 12 months

Document 2 — Site Master File (or Drug Establishment File)

The Site Master File (SMF) is required for EU MDR and PIC/S audits; the equivalent for FDA is the Drug Establishment File. The SMF is a 30 to 60 page document covering site description, personnel, facilities, equipment, sanitation, production, quality control, distribution, complaints, and recalls. In 2026, the inspector typically has the SMF on a tablet and uses it to navigate the audit; missing sections become immediate findings.

SMF sectionInspector focus in 2026Common gap
Site descriptionTotal area, production area, storage area, lab area, controlled environment zonesFloor plan not updated; new building not reflected
PersonnelHeadcount by function, org chart, key qualificationsOrg chart older than 6 months; turnover not reflected
EquipmentCritical equipment list, qualification status, calibration cycleNew equipment not added; old equipment still listed
ProductionProduct families, batch sizes, annual throughputThroughput out of date by 30%+
Quality controlIn-house lab scope, outsourced tests, OOS handlingOutsourced lab not listed; OOS procedure not cross-referenced
Complaints & recallsLast 24 months' complaints and recalls, with status2026 complaint trend not analysed; CAPA not linked

Document 3 — Organisation Chart and Job Descriptions

The organisation chart and the top-10 job descriptions are the inspector's way to verify the "responsibility and authority" required by ISO 13485 §5.5. In 2026 the inspector will: (a) point to a name on the org chart, (b) ask for that person's job description, (c) check the signature date is within 12 months, (d) ask who backs up that person during absence. If the backup is not named, the inspector flags it.

Role on org chartWhat the inspector verifiesCommon gap
Management RepresentativeAppointment letter signed by CEO, dated within 12 monthsLetter older than 12 months; no MR signature on Quality Manual
Production ManagerJob description, qualifications, training recordsQualifications not documented; training records missing for new processes
QC ManagerIndependent reporting line to MR or top managementQC reports to Production (a finding, not a gap)
Regulatory Affairs LeadNamed, with document control authority for product registrationsRA function outsourced without a contract on file
Document ControllerNamed, with authority to issue and recall documentsMultiple people with document authority; no single point of accountability

Document 4 — List of Validated Processes and Validation Reports

Process validation is the inspector's #1 evidence that the factory can actually make the product. The list of validated processes is a 1 to 2 page index; the validation reports are the underlying evidence. In 2026 the inspector asks for: (a) the validated process list, (b) the most recent validation report for the most complex process (typically the mixing or filling process), and (c) the change control log to see what has changed since validation.

Validated processInspector focusCommon gap
Mixing / formulationActive ingredient homogeneity, mix time, temperature rangeValidation on a lab-scale mixer; production-scale not validated
Coating / laminationCoat weight uniformity, laminate bond strengthValidation on a single line; multiple lines not separately validated
Die cuttingDimension tolerance, edge qualityValidation only on the original die; new dies not re-validated
Pouching / sealingSeal strength, leak rateValidation only on the original film supplier; film change not re-validated
Stability testingProtocol, ongoing programme, OOS handlingStability only at one condition; intermediate not run

Document 5 — List of Regulatory Submissions and Approvals

The regulatory submission list tells the inspector what markets the factory is currently approved in and what the approval status is. The list is 1 to 3 pages with one row per market-product-approval. The inspector uses it to verify that the factory's claimed market reach is real. Common requests: 510(k) letters, CE certificates, Health Canada DEL, TGA ARTG entries, NMPA approvals, ANVISA notifications, SFDA / MoHAP registrations.

Document 6 — Complaints Log and Adverse Event Register

The complaints log is the inspector's evidence that the factory is monitoring post-market performance. In 2026 the inspector asks for the last 24 months' complaints, the CAPA status of each, and the trend analysis. The trend analysis is the 2026 specific ask: the inspector wants to see that the factory is identifying patterns, not just closing tickets.

Complaint metric2026 inspector expectation
VolumeTracked monthly, with rolling 12-month total
Closure rate> 95% closed within target days; backlog explained
Trend analysisAt least 2 trends identified per quarter, with action
CAPA linkageEvery complaint category above threshold has an open CAPA
Reportable eventsReportable events separated, with regulator notification evidence

Document 7 — CAPA Log and CAPA Effectiveness Check Records

The CAPA log is the inspector's evidence that the factory is improving, not just operating. In 2026, the inspector asks for: (a) all open CAPAs, (b) the closure evidence for the last 12 months' closed CAPAs, and (c) the effectiveness check records. Effectiveness check is the 2026 specific ask: a CAPA is not closed until someone has measured that the action actually solved the problem.

Document 8 — Internal Audit Reports and Management Review Minutes

Internal audits and management reviews are the two self-check mechanisms required by ISO 13485 §8.2.4 and §5.6. The inspector will ask for: (a) the last 12 months' internal audit reports, (b) the management review minutes (at least one full review per year, often more), and (c) evidence that the action items from these are tracked. The inspector specifically checks whether the management review has the right data: complaint trends, CAPA trends, audit results, customer feedback, regulatory changes, and recommendations for improvement.

Document 9 — Calibration Records and Equipment Qualification

Calibration records are the inspector's evidence that measurement is reliable. The inspector asks for: (a) the calibration schedule, (b) the certificates for critical instruments, (c) the out-of-tolerance handling procedure, and (d) the last 12 months' calibration summary. Equipment qualification is the broader category, covering IQ/OQ/PQ for production equipment; the inspector typically checks the most recent qualification report and the change control log for any post-qualification modifications.

Instrument categoryCalibration frequencyInspector focus
Analytical balanceDaily check; annual external calibrationDaily check records; certificate traceability
pH meterEach use; weekly verificationBuffer traceability; verification records
HPLCSystem suitability each sequence; annual PMSystem suitability records; PM certificates
Temperature/humidity loggersContinuous monitoring; annual calibrationMapping study; data integrity (no gaps)
Seal strength testerAnnual calibrationCertificate; standard traceability

Document 10 — Training Records and Competency Matrix

Training records are the inspector's evidence that the people doing the work are qualified to do it. The competency matrix maps each role to the skills required, the training provided, the assessment method, and the recertification frequency. In 2026, the inspector will: (a) pick a name from the org chart, (b) check the training file for that person, (c) verify the training covers the current process (not the 2018 process), and (d) ask for the assessment evidence.

RoleRequired competenciesRecertification frequency
Production operator (mixing)Mixing procedure, GMP basics, safetyAnnual + on procedure change
QC analystTest methods, data integrity, OOS handlingAnnual + on method change
Document controllerDocument control SOP, QMS structureAnnual
Internal auditorISO 13485 / 14971 lead auditor course, audit technique3-yearly + on standard change
Regulatory affairsTarget market regulations, submission processAnnual + on regulation change

How to organise the 10 documents so they appear in 30 seconds

Document organisation is a 30-second job or a 30-minute job, and the difference is whether the document is in the right place. We use a fixed file structure for every audit: a top-level folder named with the audit date and customer, then ten sub-folders numbered and named for each of the 10 documents, each sub-folder containing the current document with a one-page summary card showing the revision, the approver, and the last update date. An index file at the top level links to all ten sub-folders.

This structure means the auditor can request any one of the 10 documents and the OEM team can produce the file in 15 seconds, including the time to navigate. No searching, no asking, no excuse. The 15-second response is the single biggest reason our audit average is 5.5 hours instead of 9+.

The 7 audit requests that come back even with the 10 documents ready

Even with the 10 documents on the table, the inspector will ask follow-up questions. Seven requests come back in nearly every audit; the prepared OEM has them ready. First, the change control log for the last 12 months — the inspector checks that the validated state has not drifted. Second, the most recent complaint walked through the full file from receipt to closure, not the log. Third, the training file for a specific named person, not a general statement. Fourth, the last internal audit finding plus the related CAPA plus the effectiveness check. Fifth, the data file for the specific monitoring parameter the product is most sensitive to. Sixth, the last batch that failed release with the disposition record. Seventh, the supplier qualification file for a critical supplier such as the active ingredient vendor.

The OEM that has these 7 follow-up documents pre-pulled looks substantially more prepared than the OEM that has to dig for them. The difference is 30 minutes of pre-audit work.

5 audit failure modes that surprise first-time OEMs

Failure mode 1 — The Quality Manual is too long

A 200-page Quality Manual is harder to audit than a 25-page one. The inspector reads the scope, the exclusion list, and the procedure map; everything else is a level-2 detail. A 200-page manual signals that the OEM is hiding weak points in detail. The 2026 best practice is a 25-page manual with a procedure map pointing to a 50-procedure structure.

Failure mode 2 — Document control is centralised, not distributed

A single document controller handling more than 1,000 documents for a 200-person factory is a finding in itself. The 2026 best practice is a document control coordinator with 3 to 5 document owners per department, each with a defined document type. The coordinator owns the index; the owners own the content.

Failure mode 3 — CAPAs close without effectiveness check

Closing a CAPA because the action was taken is not the same as closing a CAPA because the action solved the problem. The 2026 inspector specifically asks for effectiveness check evidence: a measurement, a re-inspection, a complaint trend reduction. CAPAs without effectiveness check are a top-3 finding in 2026 audits.

Failure mode 4 — Training is on paper, not on competency

Attendance sheets and test scores are inputs, not evidence of competency. The 2026 inspector wants a competency matrix that shows: what the role requires, how the person was trained, how competency was assessed (typically observation, not test), and when re-assessment happens. A test score alone is a 2026 finding.

Failure mode 5 — The audit binder is a snapshot, not a system

The OEM that produces a beautifully formatted audit binder the week before the audit, but whose day-to-day document control is chaos, will fail the audit. The inspector will spot the inconsistency. The 2026 best practice is that the audit binder is a 30-second export of the live QMS, generated on the day of the audit. If the live QMS is not in shape, the audit fails; if the live QMS is in shape, the binder is automatic.

Who owns each document (and who the backup is)

Document ownership is the 2026 audit's #1 unstated requirement. The inspector will not just ask for a document; the inspector will ask "who owns this, and who is the backup?" If the answer is "we all do" or "I don't know", the inspector flags the QMS as having unclear authority — and that is a finding that affects every other document. The pattern that works: the Management Representative owns the Quality Manual with the QA Manager as backup; the Regulatory Affairs Lead owns the Site Master File and the Regulatory Approvals list, again with QA as backup; the HR Manager owns the Org Chart plus Job Descriptions; the Production Manager owns the Process Validation with the R&D Lead as backup; the QA Manager owns Complaints, CAPA, and Internal Audit plus Management Review; the Engineering Manager owns Calibration plus Qualification; and the QA Manager is the cross-cutting backup for half the documents because the QA function is the safety net. The line functions own the content; the QA function ensures the ownership is real.

How the 10 documents map to ISO 13485 clauses

For an ISO 13485 audit, the inspector will cross-reference each document to a specific clause. The 2026 mapping: Quality Manual maps to section 4 on quality management system, including documentation requirements. Site Master File maps to the same plus section 6 on resource management, particularly the environment and infrastructure sub-clauses. Org Chart plus Job Descriptions maps to management responsibility plus competence. Process Validation maps to production and service provision plus validation. Regulatory Approvals maps to planning plus regulatory compliance. Complaints maps to customer-related processes plus measurement, analysis, and improvement. CAPA maps to control of nonconforming product plus corrective and preventive action. Internal Audit plus Management Review maps to monitoring plus management review. Calibration plus Qualification maps to control of monitoring and measuring devices plus infrastructure. Training plus Competency maps to human resources plus competence, awareness, and training. The 10 documents cover the entire ISO 13485 framework with no gaps; the 2026 audit map is one-to-one with the standard's clause structure.

For an EU MDR audit, the same 10 documents also satisfy the Annex IX section 3 quality management system requirements, with the addition of: a clinical evaluation report, a post-market surveillance plan, and a post-market clinical follow-up plan. Those three are MDR-specific and not in the 10-document core; add them for EU-specific audits.

FAQ — 10 questions about OEM audit readiness

1. How long does it take to build the 10-document set from scratch?

For a new OEM that has never had an audit, the realistic timeline is 4 to 6 months: 1 month to draft the Quality Manual + SMF, 1 month to define the procedure structure, 2 months to do the first round of internal audits and management review, 1–2 months to compile the validation evidence and training records. This is why "audit-ready" is rarely a same-quarter project.

2. Can a consultant host the audit on the OEM's behalf?

No. A consultant can pre-audit (gap analysis), but the audit itself must be hosted by the OEM with the OEM's people in the room. The inspector is assessing the OEM's QMS, not the consultant's. Bringing a consultant to the audit is allowed (and often smart) but does not replace the OEM's presence.

3. What is the difference between a pre-audit and a mock audit?

A pre-audit (or gap analysis) is a third-party review of the QMS against the audit framework, typically producing a written report. A mock audit is a simulated audit, with a former inspector playing the inspector role, typically producing findings as if it were a real audit. Pre-audit is a 2-week project; mock audit is a 2-day project. Both are useful; both should happen 30–60 days before the real audit.

4. How often should internal audits run?

ISO 13485 requires that all QMS processes are audited at least once per year. In practice, a mid-sized OEM runs 8–12 internal audits per year, each covering 2–3 processes, with the full QMS covered in 12 months. The 2026 best practice is to schedule internal audits to lead the certification audit by 30–60 days, so that the certification audit sees a fresh internal audit result.

5. What is the most common 2026 audit finding?

Across the 287 audits we processed in the first nine months of 2026, the top-3 findings are: (1) CAPA effectiveness check insufficient (cited in 41% of audits), (2) complaint trend analysis missing (cited in 33%), (3) training/competency evidence insufficient (cited in 28%). The common thread is that the documentation looks like it is being done, but the depth of the evidence is shallow.

6. How do I handle a finding during the audit?

The best practice is: acknowledge the finding, ask clarifying questions, do not argue, and commit to a corrective action timeline before the closing meeting. A finding acknowledged and committed-to during the closing meeting becomes a 30-day CAPA, not a 90-day re-audit. A finding argued becomes a major non-conformity, regardless of whether the argument is right.

7. Can I push back on a finding?

Yes, but only on factual matters (the inspector is wrong about a date, a clause reference, a fact). Pushback on interpretation ("we believe our process is sufficient") is a losing strategy. The 2026 best practice is to push back on facts only, accept interpretation findings, and provide evidence in the response that addresses the inspector's concern.

8. How long does a typical audit response take?

Most audit reports require a response within 30 days. The response is a CAPA plan: for each finding, what was the root cause, what is the corrective action, who owns it, when will it be complete, and how will effectiveness be checked. A 30-day CAPA response is the standard; some frameworks allow 60 or 90 days for major findings.

9. What is the cost of a typical audit finding?

It depends on the severity. A minor finding (single document gap) typically costs 5–10K USD to close (the CAPA work, the re-audit, the lost production time). A major finding (systemic gap, e.g. CAPA program broken) costs 50–200K USD and can delay product launches. A critical finding (immediate risk to product or patient) can shut down a production line or trigger a regulator notification, costing 500K+ USD and 6+ months to recover.

10. How do I know if my OEM is actually audit-ready?

Three signals: (1) the OEM can produce the 10 documents within 60 seconds of the request, (2) the OEM has had a recent mock audit with a former regulator inspector, and (3) the OEM can show you a trend analysis of complaints and CAPAs over the last 12 months. If any of these three is missing, the OEM is not audit-ready, regardless of what their marketing says.

About Kangdi Medical Devices

Henan Kangdi Medical Devices Co., Ltd. is an OEM/ODM manufacturer of pain patch, heat patch, cooling gel patch, and herbal patch products, with 18+ years of formulation and production experience serving 412 B2B accounts across 47 countries. Our facility is ISO 13485 certified, FDA Establishment Registered, and CE marked under MDR. We process 200+ RFQs per month with a median 9-hour quote turnaround, and we ship to 47 countries through three logistics hubs (Shanghai, Shenzhen, Hamburg). We host 30+ customer audits per year and have processed 287 audits between January and September 2026, with a 5.5-hour average audit duration and a 4% major-finding rate.

Want a copy of our 10-document audit binder template? Email /kangdi.php?s=message/message and we'll send you the full file structure, naming convention, and the 30-second export script. We share this with all serious buyers before their audit.

For more OEM compliance and operations guidance, see:

Henan Kangdi Medical Devices Co., Ltd. — 18+ years OEM/ODM pain patch manufacturing. Henan, China. ISO 13485 / FDA / CE MDR. Home · Contact · News & articles