QMSR After Eight Months: What FDA Investigators Are Asking
Eight months into the Quality Management System Regulation (QMSR), medical device manufacturers are operating under a fundamentally different FDA inspection framework.
The QMSR became effective on February 2, 2026, replacing the former Quality System Regulation framework under 21 CFR Part 820 with a regulation that incorporates ISO 13485:2016 by reference. At the same time, FDA discontinued the Quality System Inspection Technique (QSIT) and implemented a new risk-based inspection process under Compliance Program 7382.850, Inspection of Medical Device Manufacturers.
For manufacturers, the practical question is no longer simply whether the quality system contains the required procedures.
FDA investigators are looking at how the quality system operates as an interconnected system, how risks are managed, and whether records demonstrate that the manufacturer actually follows its processes.
What Has Changed Under QMSR?
The QMSR brings the FDA’s device quality requirements more closely into alignment with ISO 13485:2016.
This does not mean that FDA inspections have simply become ISO 13485 audits.
FDA inspections remain focused on compliance with FDA requirements and are conducted using FDA’s risk-based inspection process. An ISO 13485 certificate or participation in the Medical Device Single Audit Program (MDSAP) does not exempt a manufacturer from an FDA inspection.
The new inspection program organizes the evaluation around interconnected QMS areas and focuses on risks to patients and users.
FDA’s inspection program identifies areas including:
- Management oversight
- Production and service provision
- Design and development
- Change control
- Outsourcing and purchasing
- Measurement, analysis, and improvement
- Other applicable FDA requirements
Risk management is central to the inspection approach.
FDA Investigators Are Looking at the QMS as a Connected System
One of the most important practical changes is the way investigators can move between different parts of the quality system.
A finding in one area may lead an investigator to examine related processes elsewhere.
For example, an issue involving a supplier may lead to questions about:
- Supplier qualification
- Purchasing controls
- Incoming inspection
- Nonconforming product
- CAPA
- Risk management
- Management review
FDA’s new inspection process specifically recognizes that evaluating one requirement may require evaluating related requirements in other areas of the QMS.
This means manufacturers should avoid preparing for an inspection by reviewing individual procedures in isolation.
The evidence needs to tell a consistent story across the entire QMS.
1. What Is Management Doing With Quality Data?
Management oversight is a major area of the new inspection framework.
Investigators may evaluate whether top management has established and maintained an effective QMS and whether management uses risk-based decision-making appropriately.
This can include reviewing:
- Quality objectives
- Quality policy
- Management responsibilities
- Resources
- Management review
- Quality metrics
- Product and process performance
- Corrective and preventive actions
- Risk-related information
FDA’s inspection materials specifically identify management review, quality planning, management commitment, customer focus, resources, and related QMS elements within the Management Oversight area.
The practical question is not simply whether a management review meeting occurred.
Investigators may look at whether management review actually uses meaningful quality information to identify problems and make decisions.
2. Are Your Risk Management Processes Actually Working?
Risk management is one of the most important areas to prepare for under the QMSR.
FDA’s new inspection process is explicitly risk-based. Investigators are expected to identify risks that could adversely affect patients or users, identify associated risk controls, and review the manufacturer’s risk management documentation.
Manufacturers should be prepared to demonstrate how risk management connects with:
- Design and development
- Manufacturing processes
- Supplier controls
- Changes
- Complaints
- Nonconformities
- CAPA
- Post-market information
A risk management file that exists separately from the rest of the QMS may create questions if the company’s operational records do not reflect the risks identified in that file.
3. Can You Show Evidence of Effective CAPA?
CAPA remains a critical area of FDA inspection.
Investigators may look beyond whether a CAPA procedure exists and examine whether the system is capable of identifying the true causes of quality problems and preventing recurrence.
Questions may include:
- What triggered the CAPA?
- Was the problem appropriately investigated?
- Was the root cause adequately identified?
- Was the scope of the problem evaluated?
- Were appropriate corrective actions implemented?
- Was effectiveness verified?
- Were related risks reassessed?
- Did the CAPA lead to changes elsewhere in the QMS?
FDA enforcement activity continues to demonstrate the importance of CAPA systems. For example, an FDA warning letter issued in 2026 cited failures involving CAPA procedures, investigation of nonconformities, effectiveness verification, and related quality-system controls.
4. What Are Your Internal Audits Finding?
One notable QMSR change is the FDA’s ability to review records that were previously exempt from review under the former QS Regulation.
FDA specifically states that investigators may review:
- Internal quality audits
- Supplier audits
- Management review reports
The previous exceptions under §820.180(c) are not maintained in the QMSR.
That means manufacturers should expect internal audit records to receive meaningful attention during inspections.
An internal audit program that repeatedly identifies no problems may raise questions if other QMS records show significant recurring issues.
Companies should ensure that internal audits are:
- Planned appropriately
- Based on applicable requirements
- Documented
- Objective
- Followed by appropriate corrective action
- Used to evaluate QMS effectiveness
5. How Are Suppliers Controlled?
Outsourcing and purchasing are another important part of the QMSR inspection framework.
Investigators may examine how the manufacturer evaluates and controls suppliers based on the risks associated with purchased products and services.
Areas to review include:
- Supplier qualification
- Supplier evaluation criteria
- Approved supplier lists
- Purchasing requirements
- Supplier performance
- Incoming verification
- Supplier changes
- Supplier-related nonconformities
- Supplier corrective actions
The level of control should make sense for the risk posed by the supplier and the purchased product or service.
FDA enforcement activity has also identified supplier-control deficiencies, including inadequate supplier evaluations, undefined supplier controls, and incomplete approved-supplier records.
6. Are Your Design Controls Connected to Risk?
Design and development remains an important part of the QMS.
Investigators may evaluate whether design activities are appropriately planned, documented, reviewed, verified, validated, transferred, and changed.
They may also examine how design decisions connect to risk management.
Manufacturers should be able to explain the relationship between:
Design inputs → Risk analysis → Design outputs → Verification → Validation → Design changes → Post-market information
A disconnect between these records can make it difficult to demonstrate that the design process is operating effectively.
7. How Are Changes Controlled?
Change control is specifically identified as one of the QMS areas in FDA’s risk-based inspection model.
Investigators may examine whether changes are:
- Properly documented
- Reviewed before implementation
- Evaluated for regulatory impact
- Evaluated for quality impact
- Evaluated for risk
- Verified or validated when appropriate
- Communicated to affected functions
Manufacturers should also consider whether changes to suppliers, processes, software, materials, specifications, and manufacturing locations trigger appropriate reassessment of risk.
8. What Do Your Complaints Tell You?
Complaint information can provide investigators with evidence about whether the QMS is functioning as intended.
Investigators may consider whether complaints are:
- Properly received and documented
- Evaluated consistently
- Investigated when required
- Connected to nonconformities
- Considered in CAPA decisions
- Considered in risk management
- Evaluated for reporting obligations
The important issue is not simply having a complaint procedure.
The manufacturer should be able to demonstrate how complaint information flows into the broader quality system.
9. Are Nonconformities Being Properly Controlled?
FDA investigators may also examine how manufacturers identify, document, evaluate, and control nonconforming product and processes.
This may include reviewing:
- Nonconformance records
- Disposition decisions
- Rework
- Scrap
- Concessions
- Investigations
- Recurring issues
- Links to CAPA
- Risk assessments
Recurring nonconformities should be evaluated carefully.
If the same problem repeatedly appears without an effective systemic response, investigators may question the effectiveness of the manufacturer’s improvement processes.
10. Can Your Records Demonstrate What Actually Happened?
Documentation is particularly important under the QMSR.
FDA states that investigators may review QMS records created before February 2, 2026, not just records created after the QMSR became effective. FDA recommends that manufacturers consider conducting a comparative analysis to demonstrate how earlier records meet applicable QMSR requirements.
Manufacturers should therefore avoid assuming that older records are irrelevant.
Records should be:
- Accurate
- Complete
- Contemporaneous
- Traceable
- Consistent with related records
- Controlled according to the QMS
Creating records retrospectively can create significant compliance concerns.
FDA enforcement activity in 2026 has already highlighted concerns with management-review records that were created retrospectively from emails and memory rather than maintained contemporaneously.
11. What About Management Review Records?
Under the QMSR, management review records are no longer protected from FDA inspection by the former QS Regulation’s exemptions.
FDA specifically confirms that investigators may review management review reports.
Companies should therefore make sure management reviews demonstrate meaningful evaluation of the QMS.
Useful inputs may include:
- Audit results
- Customer feedback
- Complaint trends
- Process performance
- Product conformity
- CAPA status
- Supplier performance
- Changes affecting the QMS
- Resource needs
- Quality objectives
- Opportunities for improvement
Management review should result in documented decisions and actions when problems or resource needs are identified.
12. FDA Is Not Conducting an MDSAP Audit
Manufacturers should also understand the difference between an FDA QMSR inspection and an MDSAP audit.
FDA inspections under QMSR do not follow the MDSAP audit plan or procedures.
FDA also does not require an ISO 13485 certificate as a substitute for an FDA inspection, and an ISO 13485 certificate does not exempt a manufacturer from FDA inspection.
Manufacturers participating in MDSAP should therefore avoid assuming that successful MDSAP audits automatically mean they are prepared for every aspect of an FDA inspection.
What Should Manufacturers Do Eight Months Into QMSR?
The first eight months of QMSR implementation provide a useful opportunity to evaluate whether the quality system is actually operating as intended.
Manufacturers should consider conducting a focused QMSR readiness assessment covering:
Risk Management
Confirm that risk management is integrated with design, production, suppliers, changes, complaints, CAPA, and post-market information.
Management Review
Review whether management receives meaningful quality data and documents appropriate decisions and actions.
Internal Audits
Evaluate whether audits are objective, effective, and capable of identifying systemic problems.
Supplier Controls
Review supplier qualification, monitoring, performance, and risk-based controls.
CAPA
Test whether CAPA investigations identify systemic root causes and whether effectiveness checks are meaningful.
Change Control
Verify that changes receive appropriate quality, regulatory, and risk assessment.
Records
Review whether records are complete, consistent, controlled, and readily retrievable.
A Practical QMSR Inspection Preparation Checklist
Before an FDA inspection, manufacturers should be able to quickly locate and explain:
☐ Quality policy and objectives
☐ Management review records
☐ Internal audit records
☐ Supplier qualification and monitoring records
☐ Risk management files
☐ Design and development records
☐ Change-control records
☐ CAPA records
☐ Complaint records
☐ Nonconformance records
☐ Production and process records
☐ Training and competency records
☐ Applicable regulatory records
☐ Previous inspection observations and corrective actions
More importantly, the records should tell a consistent story.
If a risk is identified in one document, the manufacturer should be able