ASQ Certified Medical Device
Auditor (CMDA) Examination
Preparation 150 Advanced
Multiple-Choice Questions
Covering the Complete Body of
Knowledge for the September 1–
30, 2026 Testing Window.
Table of Contents
Section Topic Questions
I Auditing Fundamentals 1–18
II Auditing and Inspection Processes 19–48
III Medical Device Quality Management System Requirements 49–88
IV Technical Medical Device Knowledge 89–130
,Section Topic Questions
V Quality Tools and Techniques 131–150
Correct Answers and Rationales All
Section I: Auditing Fundamentals (Questions 1–18)
1. During an annual review, the quality assurance director tasks a compliance specialist with
verifying that a newly implemented automated assembly line meets all documented operational
parameters and yields. What type of audit is specifically being requested?
A. System audit
B. Process audit
C. Product audit
D. Supplier qualification audit
Correct Answer: B. Process audit
Rationale: A process audit examines the effectiveness and efficiency of specific processes against
defined criteria. The scenario describes verification of operational parameters and yields for a specific
manufacturing process, which is characteristic of a process audit. System audits evaluate the entire
QMS, product audits examine finished devices, and supplier audits evaluate external vendors.
2. An auditor is assigned to evaluate whether a contract manufacturer's quality management system
conforms to ISO 13485:2016 requirements. This is best classified as which type of audit?
A. First-party audit
B. Second-party audit
C. Third-party audit
D. Internal audit
Correct Answer: B. Second-party audit
Rationale: A second-party audit is conducted by an organization on its suppliers or contractors. Since
the auditor represents the organization evaluating its contract manufacturer, this is a second-party
audit. First-party audits are internal, and third-party audits are conducted by independent certification
bodies.
3. Which of the following best describes the primary purpose of a for-cause audit?
,A. To verify routine compliance with established procedures
B. To investigate a specific problem, complaint, or regulatory concern
C. To qualify a new supplier before contract award
D. To satisfy annual certification surveillance requirements
Correct Answer: B. To investigate a specific problem, complaint, or regulatory concern
Rationale: For-cause audits are triggered by specific events such as complaints, adverse events,
regulatory observations, or significant process deviations. The purpose is to investigate the root cause
and determine the extent of the issue, not to perform routine verification or supplier qualification.
4. According to ISO 19011:2018, which principle requires auditors to report truthfully and
accurately, even when findings are unfavorable to the auditee?
A. Integrity
B. Fair presentation
C. Due professional care
D. Independence
Correct Answer: B. Fair presentation
Rationale: Fair presentation is the principle that requires auditors to report truthfully, accurately, and
objectively. Integrity is the foundation of professionalism, due professional care relates to diligence and
judgment, and independence refers to being free from bias and conflict of interest.
5. An auditor discovers that a medical device manufacturer's internal audit program has not covered
the design control process in over three years. Which clause of ISO 13485:2016 is most directly
implicated?
A. Clause 4.2.4 (Control of Records)
B. Clause 8.2.2 (Internal Audit)
C. Clause 7.3 (Design and Development)
D. Clause 5.6 (Management Review)
Correct Answer: B. Clause 8.2.2 (Internal Audit)
Rationale: Clause 8.2.2 requires that internal audits be conducted at planned intervals to determine
whether the QMS conforms to planned arrangements and the requirements of the standard. Failure to
audit a critical process such as design control constitutes a nonconformity against the internal audit
clause.
6. Which audit method involves examining records and documents remotely before an on-site visit
to optimize the use of on-site time?
, A. Desk audit
B. Process audit
C. Product audit
D. Management audit
Correct Answer: A. Desk audit
Rationale: A desk audit is a review of documentation and records conducted off-site, often as a
precursor to an on-site audit. It allows auditors to identify areas of concern and focus their on-site
activities. Process, product, and management audits are classifications by scope, not by location.
7. The ASQ Code of Ethics requires auditors to avoid conflicts of interest. Which situation represents
the most significant conflict of interest?
A. An auditor who previously worked for the auditee five years ago
B. An auditor who owns stock in a competitor of the auditee
C. An auditor who has a close family member employed by the auditee in a non-managerial role
D. An auditor who is auditing a process they helped design
Correct Answer: D. An auditor who is auditing a process they helped design
Rationale: Auditing a process one helped design creates a direct self-review threat, compromising
objectivity. While the other options may present potential conflicts, they are either time-removed,
indirect, or less directly related to the audit scope.
8. A medical device company is preparing for a certification audit. The audit team leader is
developing the audit plan. Which factor is LEAST relevant when determining the audit duration?
A. The complexity of the device and its manufacturing processes
B. The size of the organization and number of employees
C. The auditor's personal preference for a shorter workday
D. The results of previous audits and identified risk areas
Correct Answer: C. The auditor's personal preference for a shorter workday
Rationale: Audit duration should be determined by factors such as complexity, size, scope, and risk.
Personal preferences of auditors are not a legitimate factor. The audit plan must be based on objective
criteria to ensure a thorough and effective audit.
9. During an audit, the auditee refuses to provide access to a specific quality record, citing
confidentiality concerns. What is the auditor's BEST course of action?
A. Immediately terminate the audit and report the auditee to the regulatory authority
B. Document the refusal as a nonconformity and escalate to the audit program manager
Auditor (CMDA) Examination
Preparation 150 Advanced
Multiple-Choice Questions
Covering the Complete Body of
Knowledge for the September 1–
30, 2026 Testing Window.
Table of Contents
Section Topic Questions
I Auditing Fundamentals 1–18
II Auditing and Inspection Processes 19–48
III Medical Device Quality Management System Requirements 49–88
IV Technical Medical Device Knowledge 89–130
,Section Topic Questions
V Quality Tools and Techniques 131–150
Correct Answers and Rationales All
Section I: Auditing Fundamentals (Questions 1–18)
1. During an annual review, the quality assurance director tasks a compliance specialist with
verifying that a newly implemented automated assembly line meets all documented operational
parameters and yields. What type of audit is specifically being requested?
A. System audit
B. Process audit
C. Product audit
D. Supplier qualification audit
Correct Answer: B. Process audit
Rationale: A process audit examines the effectiveness and efficiency of specific processes against
defined criteria. The scenario describes verification of operational parameters and yields for a specific
manufacturing process, which is characteristic of a process audit. System audits evaluate the entire
QMS, product audits examine finished devices, and supplier audits evaluate external vendors.
2. An auditor is assigned to evaluate whether a contract manufacturer's quality management system
conforms to ISO 13485:2016 requirements. This is best classified as which type of audit?
A. First-party audit
B. Second-party audit
C. Third-party audit
D. Internal audit
Correct Answer: B. Second-party audit
Rationale: A second-party audit is conducted by an organization on its suppliers or contractors. Since
the auditor represents the organization evaluating its contract manufacturer, this is a second-party
audit. First-party audits are internal, and third-party audits are conducted by independent certification
bodies.
3. Which of the following best describes the primary purpose of a for-cause audit?
,A. To verify routine compliance with established procedures
B. To investigate a specific problem, complaint, or regulatory concern
C. To qualify a new supplier before contract award
D. To satisfy annual certification surveillance requirements
Correct Answer: B. To investigate a specific problem, complaint, or regulatory concern
Rationale: For-cause audits are triggered by specific events such as complaints, adverse events,
regulatory observations, or significant process deviations. The purpose is to investigate the root cause
and determine the extent of the issue, not to perform routine verification or supplier qualification.
4. According to ISO 19011:2018, which principle requires auditors to report truthfully and
accurately, even when findings are unfavorable to the auditee?
A. Integrity
B. Fair presentation
C. Due professional care
D. Independence
Correct Answer: B. Fair presentation
Rationale: Fair presentation is the principle that requires auditors to report truthfully, accurately, and
objectively. Integrity is the foundation of professionalism, due professional care relates to diligence and
judgment, and independence refers to being free from bias and conflict of interest.
5. An auditor discovers that a medical device manufacturer's internal audit program has not covered
the design control process in over three years. Which clause of ISO 13485:2016 is most directly
implicated?
A. Clause 4.2.4 (Control of Records)
B. Clause 8.2.2 (Internal Audit)
C. Clause 7.3 (Design and Development)
D. Clause 5.6 (Management Review)
Correct Answer: B. Clause 8.2.2 (Internal Audit)
Rationale: Clause 8.2.2 requires that internal audits be conducted at planned intervals to determine
whether the QMS conforms to planned arrangements and the requirements of the standard. Failure to
audit a critical process such as design control constitutes a nonconformity against the internal audit
clause.
6. Which audit method involves examining records and documents remotely before an on-site visit
to optimize the use of on-site time?
, A. Desk audit
B. Process audit
C. Product audit
D. Management audit
Correct Answer: A. Desk audit
Rationale: A desk audit is a review of documentation and records conducted off-site, often as a
precursor to an on-site audit. It allows auditors to identify areas of concern and focus their on-site
activities. Process, product, and management audits are classifications by scope, not by location.
7. The ASQ Code of Ethics requires auditors to avoid conflicts of interest. Which situation represents
the most significant conflict of interest?
A. An auditor who previously worked for the auditee five years ago
B. An auditor who owns stock in a competitor of the auditee
C. An auditor who has a close family member employed by the auditee in a non-managerial role
D. An auditor who is auditing a process they helped design
Correct Answer: D. An auditor who is auditing a process they helped design
Rationale: Auditing a process one helped design creates a direct self-review threat, compromising
objectivity. While the other options may present potential conflicts, they are either time-removed,
indirect, or less directly related to the audit scope.
8. A medical device company is preparing for a certification audit. The audit team leader is
developing the audit plan. Which factor is LEAST relevant when determining the audit duration?
A. The complexity of the device and its manufacturing processes
B. The size of the organization and number of employees
C. The auditor's personal preference for a shorter workday
D. The results of previous audits and identified risk areas
Correct Answer: C. The auditor's personal preference for a shorter workday
Rationale: Audit duration should be determined by factors such as complexity, size, scope, and risk.
Personal preferences of auditors are not a legitimate factor. The audit plan must be based on objective
criteria to ensure a thorough and effective audit.
9. During an audit, the auditee refuses to provide access to a specific quality record, citing
confidentiality concerns. What is the auditor's BEST course of action?
A. Immediately terminate the audit and report the auditee to the regulatory authority
B. Document the refusal as a nonconformity and escalate to the audit program manager