Since the Quality Management System Regulation (QMSR) took effect on February 2, 2026, FDA inspectors have been evaluating device manufacturers directly against ISO 13485:2016 rather than the legacy 21 CFR Part 820 framework. That shift means the standard’s clause structure is no longer just a certification requirement. It is now the roadmap FDA investigators use during an inspection.
Not every clause is getting the same level of attention. Based on the new Compliance Program 7382.850 and the QMS Areas it organizes inspections around, a handful of clauses are drawing noticeably closer scrutiny. If your organization has not reviewed how these specific sections are documented and practiced, now is the time.
Clause 7.1: Risk Management Sets the Tone for the Whole Inspection
Risk management has become the starting point for many QMSR inspections rather than a supporting document reviewed later. Clause 7.1 requires that risk be addressed throughout product realization, and FDA investigators are increasingly using the risk management file as a map for where to look next, tracing risk controls into design records, process validation, and CAPA.
Organizations that treat ISO 14971 risk management as a standalone exercise disconnected from daily quality activities are the ones most likely to struggle here. Risk files need to visibly connect to design decisions, supplier controls, and complaint trends, not just exist as a compliance artifact.
Clauses 5.6 and 8.2.4: Internal Audits and Management Review Are No Longer Formalities
Under the prior QSR, internal audit records and management review minutes were largely exempt from FDA review. Under QMSR, that exemption is gone. Clause 8.2.4 (internal audit) and Clause 5.6 (management review) records are now inspectable, and investigators are checking whether audits are conducted with real independence and whether management review actually drives follow-up action.
A management review that repeats the same agenda items quarter after quarter without documented decisions or resulting corrective actions is a clear signal to an inspector that the QMS is not functioning as intended.
Clause 7.3: Design and Development Controls
Design and development remains one of the most heavily reviewed areas under QMSR, and Clause 7.3 covers the full lifecycle, from design inputs and outputs through verification, validation, transfer, and design change control. Because ISO 13485 also expects software used in the device or in a controlled quality process to be validated, inspectors are paying closer attention to software validation records that older QSR-based systems sometimes treated loosely.
Design history documentation does not need to be renamed to match ISO terminology, but it does need to demonstrate traceability from input requirements through final verification and validation, with any changes clearly controlled.
Clauses 8.2.2 and 8.2.3: Complaint Handling and Regulatory Reporting
Complaint files are a standing target in device inspections, and QMSR sharpens that focus. Clause 8.2.2 requires a documented procedure for receiving, evaluating, and investigating complaints, while Clause 8.2.3 covers reporting to regulatory authorities. Inspectors are looking closely at whether complaint evaluations consistently and correctly determine reportability, and whether complaint trends are actually feeding back into risk management and CAPA rather than being closed out individually with no aggregate review.
Clauses 8.5.2 and 8.5.3: Corrective and Preventive Action
CAPA remains the clause area where FDA has always focused the most attention, and QMSR raises the bar further by evaluating it through both an ISO lens and FDA’s regulatory expectations for investigation depth, root cause analysis, and effectiveness verification. Preventive action in particular tends to be underdeveloped in many quality systems, with organizations defaulting to reactive corrective action instead of identifying potential nonconformities before they occur.
Expect inspectors to ask not just whether a CAPA was closed, but how effectiveness was verified and whether the same root cause has resurfaced elsewhere in the system.
Clause 7.4: Supplier and Outsourced Process Controls
Supplier and outsourcing controls under Clause 7.4 are drawing more attention as FDA looks for documented evidence of supplier qualification and ongoing oversight of any outsourced manufacturing or service. A supplier approval file that was created once and never revisited is unlikely to hold up under a risk-based inspection model.
How to Prepare
For most organizations, the practical starting point is a clause-by-clause internal review focused on these areas, ideally structured the way an FDA investigator would now approach it: starting with the risk management file and tracing it outward into design records, supplier controls, complaint data, and CAPA. Our ISO 13485 consulting services are built around exactly this kind of gap assessment, and our ISO 13485 auditing services can provide an independent, inspection-style review before FDA does.
If your internal audit team needs to sharpen its approach to these higher-scrutiny clauses, our ISO training programs cover internal auditor preparation specific to the medical device sector.
Reach out to Cavendish Scott to talk through where your quality system stands against these specific clauses.
