FDA QMSR (21 CFR 820) Audit Checklist
Objective Evidence
- QMSR transition plan or project documentation showing planned activities, responsibilities, and timeline
- Completion records showing each transition activity was executed and verified
- Management review minutes where the transition status was discussed and approved
- Gap analysis report comparing old QSR requirements to new QMSR/ISO 13485 requirements
Common Nonconformities
- No formal transition plan exists — the organization assumes that ISO 13485 certification is sufficient without verifying QMSR-specific requirements are addressed
- Transition plan exists but completion was never verified — individual tasks were assigned but no one confirmed they were actually done
- Gap analysis was performed against ISO 13485 but did not address the FDA supplemental requirements in §820.35 and §820.45
Auditor Tips
Many organizations assume that an existing ISO 13485 certificate means QMSR compliance. This is mostly true but misses the supplemental requirements. Ask to see the gap analysis and verify it explicitly addresses §820.35 (UDI in records, complaint investigation triggers, service records) and §820.45 (label examination, packaging controls).
Follow-Up Questions
- When was the transition completed, and who signed off on it?
- Were any gaps identified between your existing QMS and QMSR requirements? How were they closed?
What to Sample
Review the transition plan, verify completion evidence for at least 3 key transition activities, and confirm the gap analysis covers §820.35 and §820.45.
Objective Evidence
- Quality manual referencing QMSR and ISO 13485:2016
- Sample of 3-5 procedures checked for updated regulatory references
- Regulatory requirements crosswalk mapping old QSR sections to new QMSR/ISO 13485 clauses
Common Nonconformities
- Quality manual still references old QSR subsections (e.g., '21 CFR 820.30 Design Controls') instead of ISO 13485:2016 §7.3
- Procedures reference both old QSR sections and ISO 13485 clauses inconsistently
- No crosswalk document exists — personnel cannot explain which ISO 13485 clause replaced which old QSR section
Auditor Tips
Pull 3 random procedures and check their regulatory reference sections. If any still cite old QSR subsections without the ISO 13485 equivalent, the transition is incomplete. Also check training materials — these are often forgotten during regulatory reference updates.
Follow-Up Questions
- Can you show me your crosswalk between old QSR sections and the new QMSR/ISO 13485 clauses?
- How did you ensure every document referencing old QSR was identified and updated?
What to Sample
Check 5 random procedures for regulatory reference updates. Verify training materials reference QMSR, not old QSR.
Objective Evidence
- Training records showing QMSR transition training was delivered to relevant personnel
- Training content covering key differences between old QSR and QMSR
- Attendance records or completion signatures
Common Nonconformities
- No QMSR-specific training was provided — the organization relied on existing ISO 13485 training without addressing the regulatory transition
- Training was delivered only to quality personnel but not production, design, or purchasing staff
- Training content does not address FDA supplemental requirements (§820.35, §820.45)
Auditor Tips
Ask a production supervisor: 'What changed when QMSR replaced QSR?' If they cannot articulate the key differences, the training was ineffective regardless of what the records show.
Follow-Up Questions
- Who received QMSR transition training? Was it limited to quality, or did it include other departments?
- How did you verify that the training was effective?
What to Sample
Review training records for 3 personnel from different departments. Interview one person to verify understanding.
Objective Evidence
- Controlled copy of ISO 13485:2016 available to personnel
- ISO 13485 certification from an accredited registrar (if applicable)
- Evidence of ISO 13485 internal audits within the last 12 months
- Management review records addressing ISO 13485 compliance
Common Nonconformities
- Organization references ISO 13485 but has never obtained a copy of the standard — personnel cannot verify requirements against the actual text
- ISO 13485 certification lapsed and was not renewed
- Internal audits are conducted against old QSR requirements, not ISO 13485 clauses
Auditor Tips
Not every QMSR-regulated manufacturer needs ISO 13485 certification, but they all must comply with its requirements. If not certified, verify through internal audit records and management review that they are actively monitoring compliance.
Follow-Up Questions
- Are your internal audits conducted against ISO 13485 clauses or old QSR sections?
- How do you stay current with ISO 13485 interpretations?
What to Sample
Verify the organization has ISO 13485:2016. Check the most recent internal audit plan for ISO 13485 clause references.
Objective Evidence
- Record retention procedure addressing all six control elements from ISO 13485 §4.2.5
- Records retention schedule with defined periods per record type
- Evidence of periodic review confirming records are retrievable
- Backup and disaster recovery procedures for electronic records
Common Nonconformities
- Record retention schedule does not define specific retention periods per record type — a blanket 'retain for the lifetime of the device' is used without defining lifetime
- Electronic records are stored on a shared drive with no access controls, backup schedule, or version management
- No defined process for destroying records when retention periods expire
Auditor Tips
Ask for a specific record type (e.g., a DHR from 3 years ago) and time how long it takes to retrieve. If retrieval takes more than a few minutes, the system is not effectively maintained.
Follow-Up Questions
- Can you retrieve a complete device history record from 2 years ago within 15 minutes?
- When was the last backup restoration test for electronic records?
What to Sample
Request retrieval of one DHR and one complaint file from at least 2 years ago. Verify the retention schedule covers all record types.
Objective Evidence
- DHR samples showing UDI or device identifier
- Complaint records showing UDI for the device involved
- CAPA records referencing UDI of affected products
- Procedure defining how and where UDI must be recorded
Common Nonconformities
- Quality records reference internal part numbers but not the UDI — UDI is treated as a labeling requirement only, not a record requirement
- UDI is included in DHRs but not in complaint, CAPA, or nonconformance records
- No procedure defines which records must include UDI
Auditor Tips
This is the most commonly missed QMSR supplemental requirement. Organizations transitioning from old QSR often overlook this because old 820 did not require UDI in records. Check DHRs, complaint files, and CAPA records.
Follow-Up Questions
- Which record types include the UDI? Is this defined in a procedure?
- How do you capture UDI for complaint records when the complainant may not provide it?
What to Sample
Check 3 different record types (DHR, complaint, CAPA) and verify each includes the UDI or device identifier.
Objective Evidence
- Records for devices without UDI showing alternative identification
- Procedure defining alternative identification methods when UDI is not applicable
Common Nonconformities
- Investigational or pre-market devices have no device identification in quality records
- No procedure defines what alternative identification to use when UDI is not applicable
Auditor Tips
This applies primarily to devices in development, investigational use, or exempt devices. Check that records for these devices have traceable identification even without a UDI.
Follow-Up Questions
- Do you have any devices without a UDI? How are they identified in quality records?
What to Sample
If the organization has pre-market or custom devices, check records for alternative device identification.
Objective Evidence
- Complaint handling procedure with investigation triggers aligned with §820.35(c)
- Complaint records showing investigation initiated for possible device failure
- Decision records where investigation was deemed not required, with rationale
Common Nonconformities
- Complaint procedure uses risk-based criteria that exclude low-risk complaints — §820.35(c) requires investigation for any 'possible failure' to meet specifications regardless of risk
- Complaints categorized as 'user error' are excluded from investigation without evaluating whether the complaint involves a possible specification failure
- Investigation trigger is based on complaint volume rather than individual evaluation
Auditor Tips
This is stricter than ISO 13485 §8.2.2. The key word is 'possible' — not 'confirmed' or 'probable'. Ask how complaints are triaged and what criteria determine whether an investigation is opened.
Follow-Up Questions
- What criteria determine whether a complaint triggers an investigation?
- Show me a complaint closed without investigation — what was the rationale?
- How do you distinguish a possible specification failure from a user preference issue?
What to Sample
Review 5 complaints: 2 with investigations, 3 without. Verify 'no investigation' decisions have documented rationale.
Objective Evidence
- Complaint investigation records showing MDR reportability evaluation
- MDR evaluation procedure or decision tree
- Records of MDR reports correlated with complaint files
- Training records for personnel performing MDR evaluations
Common Nonconformities
- Complaint investigations do not include MDR reportability assessment
- MDR evaluation performed only for 'serious' complaints — all complaints involving device failure should include an MDR assessment
- MDR evaluation documented as 'not reportable' with no supporting rationale
Auditor Tips
Every complaint investigation under §820.35(c) must include an MDR reportability evaluation. Even if not reportable, the evaluation must be documented with rationale referencing the MDR criteria (death, serious injury, or malfunction that could cause/contribute to either).
Follow-Up Questions
- Who performs MDR evaluations? What training do they have?
- Show me a complaint evaluated as not reportable — what was the rationale?
What to Sample
Review 5 complaint investigation files and verify each contains a documented MDR evaluation with rationale.
Objective Evidence
- Complaint records with documented rationale for not investigating
- Approval records from a qualified individual
- Procedure defining who has authority to waive investigation
Common Nonconformities
- Complaints closed without investigation have no documented rationale
- Rationale is generic ('no investigation needed') without complaint-specific justification
- Decision made by customer service without quality or regulatory approval
Auditor Tips
The regulation requires that if investigation is not conducted, the reason must be documented. Check who approved the decision and whether the rationale is specific to each complaint.
Follow-Up Questions
- Who has authority to decide that a complaint does not require investigation?
- How do you ensure the rationale is specific to each complaint?
What to Sample
Find 3 complaints closed without investigation. Verify each has documented rationale and appropriate approval.
Objective Evidence
- Service report procedure defining when a service event triggers the complaint process
- Service records showing integration with complaint handling
- Training records for field service personnel on reportable events
Common Nonconformities
- Service reports are managed by a separate system with no interface to complaint handling — reportable events may never reach quality
- Field service personnel are not trained to recognize MDR-reportable events
- No criteria defined for escalating service events to the complaint system
Auditor Tips
A field technician who discovers a device malfunction during service has found a potential MDR event. If the service system is not connected to complaint handling, these events can be lost.
Follow-Up Questions
- How does a field service event get escalated to complaint handling?
- Can you show me a service report that was identified as a potential complaint?
What to Sample
Review 5 recent service reports. Check if any involved malfunctions and verify those were routed to complaint handling.
Objective Evidence
- Service records including device identification (UDI, serial, or lot number)
- Service procedure referencing ISO 13485 §7.5.4
- Service report template with required device identification fields
Common Nonconformities
- Service records identify devices by customer and location but not by UDI, serial number, or lot number
- Service records do not document device condition before and after servicing
Auditor Tips
Service records often live in a CRM or field service system, not the QMS. Verify the service system captures ISO 13485 §7.5.4 data and includes device identification per §820.35.
Follow-Up Questions
- Do service records include the UDI or serial number of the device serviced?
What to Sample
Review 3 service records for device identification and ISO 13485 §7.5.4 compliance.
Objective Evidence
- Incoming label inspection procedure referencing §820.45(a)
- Inspection records showing comparison against approved specifications
- Approved label specifications used as inspection reference
- Records of label rejections due to accuracy discrepancies
Common Nonconformities
- Incoming inspection checks quantity and print quality but does not verify text accuracy against the approved specification
- Label specifications used for inspection are outdated and do not match current approved artwork
- UDI barcode encoding is not verified — barcode is scanned to confirm it reads but encoded data is not compared against GUDID
Auditor Tips
This is FDA-specific, not in ISO 13485. Ask to see the last 3 incoming label inspection records and verify the inspection compared received labels against an approved specification — not just a visual check for print quality.
Follow-Up Questions
- How do you verify that UDI barcodes encode the correct data, not just that they scan?
- What happens if a label discrepancy is found during incoming inspection?
What to Sample
Review 3 incoming label inspection records. Physically compare one label to its specification.
Objective Evidence
- Label storage area showing organized identification and segregation
- Access controls for label storage
- Procedure for label issuance, return, and destruction of obsolete labels
Common Nonconformities
- Labels for multiple products stored without clear segregation
- Obsolete label stock stored alongside current labels with no revision identification
- No procedure for issuing labels — operators self-serve without logging
Auditor Tips
Visit the label storage area physically. Check that labels for different products and revisions are clearly segregated. Ask what happens to leftover labels when a revision is approved.
Follow-Up Questions
- When a label revision is approved, what happens to the old stock?
- How do you prevent an operator from using a label for the wrong product?
What to Sample
Physically inspect label storage. Verify segregation, identification, and access controls.
Objective Evidence
- Labeling operation procedure defining verification steps during packaging
- Packaging batch records showing labeling verification
- Line clearance records between production runs
- First-article inspection records for packaged product
Common Nonconformities
- Packaging records have a checkbox for 'labeling verified' with no detail on what was checked
- No line clearance procedure between product changeovers on the packaging line
- Labeling verification performed by the same operator who applied the labels — no independent check
Auditor Tips
Line clearance is critical. Ask what happens between production runs on the same packaging line. If old labels are not removed and the line is not inspected, label mix-ups are inevitable.
Follow-Up Questions
- What is your line clearance process between production runs?
- Who verifies correct label application — is it an independent check?
What to Sample
Review 3 packaging batch records. Verify documented labeling verification. Observe a line clearance if possible.
Frequently Asked Questions
Get the Full 28-Item Checklist
Download the complete FDA QMSR (21 CFR 820) audit checklist with all 28 expert items, objective evidence requirements, common nonconformities, auditor tips, and a professional scoring rubric.
This checklist is an educational resource for audit preparation. It does not constitute professional regulatory advice. Always consult qualified auditors for certification decisions.