On February 2, 2026, FDA's Quality Management System Regulation (QMSR) took effect, aligning 21 CFR Part 820 with ISO 13485:2016. The run-up was dominated by one worry: terminology, i.e. what to rename, remap, and reword. Seven months in, the early inspection trends tell a different story. Investigators are far less interested in what you call things than in whether your quality system actually works in practice. I recently joined Greenlight Guru's Global Medical Device Podcast to talk through what we are seeing in real QMSR inspections. Here is where companies are getting cited, and how to get ahead of it.
QMSR replaces the long-standing Quality System Regulation by incorporating ISO 13485:2016 by reference. For companies already certified to ISO 13485, much of the framework was familiar, so the industry spent two years focused on translating vocabulary between the old regulation and the standard. In practice, that translation turned out to be the easy part. (For a refresher on building and maintaining a compliant system Quality Management System services.)
The surprise was what didn't happen. Companies braced for investigators to interrogate renamed procedures and remapped clauses. Instead, FDA's focus has been on the operating model, whether processes are understood, followed, and evidenced. FDA's new compliance program, CP 7382.850, replaces the checklist-style QSIT with a risk-driven approach, which means an investigator is not simply ticking boxes. They are following the evidence into whichever process looks weakest, and asking for proof that it runs the way your documentation says it does.
Across early inspections, the same areas keep surfacing. Speaking at the Food and Drug Law Institute's annual conference in May 2026, FDA's Keisha Thomas ranked the leading observation areas from the agency's first wave of QMSR inspections: risk management, outsourcing and purchasing, complaint handling and feedback, UDI, and corrective actions. These are the five to pressure-test first.
This is the number one citation area, and the reason is simple: almost every company has a risk management file, but almost nobody treats risk management as a living process. Investigators now cross-reference the risk file against complaint and post-market data. When the field data shows harms or failure modes the risk file never anticipated, or never updated, that mismatch becomes a finding. The fix is to keep risk management current with real-world evidence, not frozen at launch.
As I put it on the podcast: a stale risk file is worse than an incomplete one. An incomplete file is a gap; a stale file actively points an investigator at the wrong things.
Supplier management has drawn sharply increased scrutiny, in part because internal supplier audit reports that were effectively out of view are now visible to investigators. That raises the bar on how you qualify, audit, and monitor suppliers, and on being able to show the controls actually operate. (Our auditing and quality support services help here.) The mechanism is specific: the old § 820.180(c) exemption that shielded management reviews, internal audits and supplier audit reports from routine FDA review has no successor in the amended Part 820, and FDA's QMSR FAQ confirms the agency can now inspect all three.
Complaint handling ranks third, and the failure is almost always an interface rather than the complaint system itself. Something that is functionally a complaint arrives through a channel that was never wired into complaint handling, returned goods are the classic example. The complaint process works, the returns process works, and nothing connects them. Trace every route by which a device or a report of a problem can come back to you and confirm each one reaches complaint evaluation.
Unique Device Identification is a recurring theme, and it is different in character from the others: it is a data accuracy and labelling requirement rather than a test of process maturity. QMSR requires the UDI to be recorded for each device or batch, and labelling to be examined for the correct identifier before release. It is a straightforward area to get right in advance, and an easy one to be cited on if it is treated as an afterthought.
Corrective action rounds out the top five, and it fails for much the same reason complaint handling does, information not moving between systems that each work perfectly well on their own. Nonconformances that never become CAPAs, root causes left blank, and actions closed without evidence of effectiveness all appear in the first wave of QMSR warning letters.
These two did not appear in FDA's top five, but they come up constantly in our own assessments and both follow directly from the changes above.
QMSR reinforces the shift from a design history file that is closed at launch to an active design and development file (DDF) maintained across the product lifecycle. For legacy products, that means a genuine gap analysis against current expectations, not an assumption that a product cleared years ago is still fully defensible under today's inspection approach.
Finally, management reviews and internal audits are being examined for substance, not just cadence. Investigators want to see that reviews surface real issues and drive action, and that internal audits are honest about gaps rather than formalities.
You do not have to do everything at once. We find it helps to map a quality system across three layers, terminology, clause conformity, and operational evidence, and to run a structured, multi-pass gap assessment rather than a single read-through. From there, the most important step is prioritization. As I put it on the podcast: at Kapstone, we typically advise customers to create a documented quality plan and prioritize it based on risk, then focus effort where a gap would most affect patient safety or inspection exposure. For a small team, a risk-prioritized plan beats trying to perfect every clause simultaneously. A focused gap analysis is usually the fastest way to find where you stand.
Two things are worth knowing before you start. First, the gap analysis is not a consultant's invention: FDA's own QMSR FAQ notes that a manufacturer may find it useful to complete a comparative analysis showing that records created before February 2, 2026 meet QMSR requirements, and the agency repeated that recommendation for legacy designs at its January 2026 town hall. Second, there is a defensible order - risk management first, then design and development files, then document and supplier controls, then the FDA-specific overlays such as UDI, reporting, and corrections and removals.
Preparing for QMSR inspections is less about vocabulary and more about demonstrating that your quality system operates as designed. Kapstone Medical provides a single-source team across quality assurance, regulatory affairs, and ISO 13485 manufacturing — including gap analysis, QMS development, auditing, and compliance remediation — to help you build a defensible, risk-prioritized quality system and reduce inspection exposure.
The Quality Management System Regulation (QMSR) is FDA's update to 21 CFR Part 820, which incorporates ISO 13485:2016 by reference to harmonize U.S. quality system requirements with the international standard.
QMSR took effect on February 2, 2026, following a two-year transition period after the final rule.
Early inspection trends point to risk management as the leading area, specifically, companies that maintain a risk management file but cannot demonstrate a living risk management process reconciled against complaint and post-market data.
No. FDA's QMSR FAQ is explicit: the agency will not require certificates of conformance to ISO 13485, will not issue them, and a certificate of conformance will not exempt a manufacturer from an FDA inspection. Certification tells you your system was designed correctly; an inspection asks whether you ran it. Certification can still support programs such as MDSAP. FDA does not conduct routine surveillance inspections at sites actively enrolled in MDSAP, but it does not replace FDA oversight.