FDA QMSR (21 CFR 820) audit checklist
Practising auditors wrote these 28 audit questions, covering the full standard. Each item names the objective evidence to request, the nonconformities most often raised against it, and what to sample. It is free to read, with no sign-up required.
Download the PDF
Includes all 28 items, formatted for a clipboard.
You will get one email with the file. We will not send anything else.
What each item gives you
This is what an auditor needs at each item. You already hold the standard itself.
Phrases it the way you would ask it in the room.
Names the specific artefacts that satisfy the item, and how to tell a real one from a placeholder.
Lists the findings most often raised here, in the words they get written up in.
Shows where the item usually goes wrong, and what a mature answer sounds like against a rehearsed one.
Explains how many to take, how to choose them, and what to cross-reference them against.
Gives the second and third questions to ask when the first answer is too smooth.
All 28 items on this page
Questions below are grouped by section, and you can check items off as you go — this browser remembers your progress. Open any row for its evidence, common nonconformities and auditor tips.
§transition Qmsr transition verification
QMSR Transition Has the organization formally transitioned its QMS from the old 21 CFR 820 (QSR) to the new QMSR framework? Is there a documented transition plan with completion evidence?
- QMSR transition plan or project documentation showing planned activities, responsibilities, and timeline
- Completion records showing each transition activity was executed and verified
- Management review minutes where the transition status was discussed and approved
- Gap analysis report comparing old QSR requirements to new QMSR/ISO 13485 requirements
- No formal transition plan exists — the organization assumes that ISO 13485 certification is sufficient without verifying QMSR-specific requirements are addressed
- Transition plan exists but completion was never verified — individual tasks were assigned but no one confirmed they were actually done
- Gap analysis was performed against ISO 13485 but did not address the FDA supplemental requirements in §820.35 and §820.45
Many organizations assume that an existing ISO 13485 certificate means QMSR compliance. This is mostly true but misses the supplemental requirements. Ask to see the gap analysis and verify it explicitly addresses §820.35 (UDI in records, complaint investigation triggers, service records) and §820.45 (label examination, packaging controls).
Review the transition plan, verify completion evidence for at least 3 key transition activities, and confirm the gap analysis covers §820.35 and §820.45.
- When was the transition completed, and who signed off on it?
- Were any gaps identified between your existing QMS and QMSR requirements? How were they closed?
Regulatory References Have all QMS documents been updated to reference the current QMSR (21 CFR 820) instead of the old QSR? Are references to old QSR subsections replaced with the corresponding ISO 13485 clauses?
- Quality manual referencing QMSR and ISO 13485:2016
- Sample of 3-5 procedures checked for updated regulatory references
- Regulatory requirements crosswalk mapping old QSR sections to new QMSR/ISO 13485 clauses
- Quality manual still references old QSR subsections (e.g., '21 CFR 820.30 Design Controls') instead of ISO 13485:2016 §7.3
- Procedures reference both old QSR sections and ISO 13485 clauses inconsistently
- No crosswalk document exists — personnel cannot explain which ISO 13485 clause replaced which old QSR section
Pull 3 random procedures and check their regulatory reference sections. If any still cite old QSR subsections without the ISO 13485 equivalent, the transition is incomplete. Also check training materials — these are often forgotten during regulatory reference updates.
Check 5 random procedures for regulatory reference updates. Verify training materials reference QMSR, not old QSR.
- Can you show me your crosswalk between old QSR sections and the new QMSR/ISO 13485 clauses?
- How did you ensure every document referencing old QSR was identified and updated?
Personnel Training Have personnel been trained on the QMSR transition and the differences between the old QSR and new QMSR/ISO 13485 requirements?
- Training records showing QMSR transition training was delivered to relevant personnel
- Training content covering key differences between old QSR and QMSR
- Attendance records or completion signatures
- No QMSR-specific training was provided — the organization relied on existing ISO 13485 training without addressing the regulatory transition
- Training was delivered only to quality personnel but not production, design, or purchasing staff
- Training content does not address FDA supplemental requirements (§820.35, §820.45)
Ask a production supervisor: 'What changed when QMSR replaced QSR?' If they cannot articulate the key differences, the training was ineffective regardless of what the records show.
Review training records for 3 personnel from different departments. Interview one person to verify understanding.
- Who received QMSR transition training? Was it limited to quality, or did it include other departments?
- How did you verify that the training was effective?
ISO 13485 Compliance Does the organization comply with ISO 13485:2016, which is incorporated by reference in §820.10? Is there evidence of implementation, not just documentation?
- Controlled copy of ISO 13485:2016 available to personnel
- ISO 13485 certification from an accredited registrar (if applicable)
- Evidence of ISO 13485 internal audits within the last 12 months
- Management review records addressing ISO 13485 compliance
- Organization references ISO 13485 but has never obtained a copy of the standard — personnel cannot verify requirements against the actual text
- ISO 13485 certification lapsed and was not renewed
- Internal audits are conducted against old QSR requirements, not ISO 13485 clauses
Not every QMSR-regulated manufacturer needs ISO 13485 certification, but they all must comply with its requirements. If not certified, verify through internal audit records and management review that they are actively monitoring compliance.
Verify the organization has ISO 13485:2016. Check the most recent internal audit plan for ISO 13485 clause references.
- Are your internal audits conducted against ISO 13485 clauses or old QSR sections?
- How do you stay current with ISO 13485 interpretations?
§820.35 §820.35 records (fda supplemental)
§820.35(a) Records Do quality records comply with ISO 13485:2016 §4.2.5, including identification, storage, protection, retrieval, retention, and disposition?
- Record retention procedure addressing all six control elements from ISO 13485 §4.2.5
- Records retention schedule with defined periods per record type
- Evidence of periodic review confirming records are retrievable
- Backup and disaster recovery procedures for electronic records
- Record retention schedule does not define specific retention periods per record type — a blanket 'retain for the lifetime of the device' is used without defining lifetime
- Electronic records are stored on a shared drive with no access controls, backup schedule, or version management
- No defined process for destroying records when retention periods expire
Ask for a specific record type (e.g., a DHR from 3 years ago) and time how long it takes to retrieve. If retrieval takes more than a few minutes, the system is not effectively maintained.
Request retrieval of one DHR and one complaint file from at least 2 years ago. Verify the retention schedule covers all record types.
- Can you retrieve a complete device history record from 2 years ago within 15 minutes?
- When was the last backup restoration test for electronic records?
§820.35(a) UDI Do records include or reference the Unique Device Identifier (UDI) or device identifier where applicable?
- DHR samples showing UDI or device identifier
- Complaint records showing UDI for the device involved
- CAPA records referencing UDI of affected products
- Procedure defining how and where UDI must be recorded
- Quality records reference internal part numbers but not the UDI — UDI is treated as a labeling requirement only, not a record requirement
- UDI is included in DHRs but not in complaint, CAPA, or nonconformance records
- No procedure defines which records must include UDI
This is the most commonly missed QMSR supplemental requirement. Organizations transitioning from old QSR often overlook this because old 820 did not require UDI in records. Check DHRs, complaint files, and CAPA records.
Check 3 different record types (DHR, complaint, CAPA) and verify each includes the UDI or device identifier.
- Which record types include the UDI? Is this defined in a procedure?
- How do you capture UDI for complaint records when the complainant may not provide it?
§820.35(b) Alt ID Where UDI is not available, do records include alternative device identification (product code, lot, batch, model, or serial number)?
- Records for devices without UDI showing alternative identification
- Procedure defining alternative identification methods when UDI is not applicable
- Investigational or pre-market devices have no device identification in quality records
- No procedure defines what alternative identification to use when UDI is not applicable
This applies primarily to devices in development, investigational use, or exempt devices. Check that records for these devices have traceable identification even without a UDI.
If the organization has pre-market or custom devices, check records for alternative device identification.
- Do you have any devices without a UDI? How are they identified in quality records?
§820.35(c) Complaints Is a complaint investigation initiated whenever a complaint involves the possible failure of a device, labeling, or packaging to meet specifications?
- Complaint handling procedure with investigation triggers aligned with §820.35(c)
- Complaint records showing investigation initiated for possible device failure
- Decision records where investigation was deemed not required, with rationale
- Complaint procedure uses risk-based criteria that exclude low-risk complaints — §820.35(c) requires investigation for any 'possible failure' to meet specifications regardless of risk
- Complaints categorized as 'user error' are excluded from investigation without evaluating whether the complaint involves a possible specification failure
- Investigation trigger is based on complaint volume rather than individual evaluation
This is stricter than ISO 13485 §8.2.2. The key word is 'possible' — not 'confirmed' or 'probable'. Ask how complaints are triaged and what criteria determine whether an investigation is opened.
Review 5 complaints: 2 with investigations, 3 without. Verify 'no investigation' decisions have documented rationale.
- What criteria determine whether a complaint triggers an investigation?
- Show me a complaint closed without investigation — what was the rationale?
- How do you distinguish a possible specification failure from a user preference issue?
§820.35(c) MDR Does each complaint investigation include evaluation of whether the event requires reporting to FDA under 21 CFR Part 803 (Medical Device Reporting)?
- Complaint investigation records showing MDR reportability evaluation
- MDR evaluation procedure or decision tree
- Records of MDR reports correlated with complaint files
- Training records for personnel performing MDR evaluations
- Complaint investigations do not include MDR reportability assessment
- MDR evaluation performed only for 'serious' complaints — all complaints involving device failure should include an MDR assessment
- MDR evaluation documented as 'not reportable' with no supporting rationale
Every complaint investigation under §820.35(c) must include an MDR reportability evaluation. Even if not reportable, the evaluation must be documented with rationale referencing the MDR criteria (death, serious injury, or malfunction that could cause/contribute to either).
Review 5 complaint investigation files and verify each contains a documented MDR evaluation with rationale.
- Who performs MDR evaluations? What training do they have?
- Show me a complaint evaluated as not reportable — what was the rationale?
§820.35(c) No Investigation If investigation is not conducted for a complaint involving possible device failure, is the reason documented and approved?
- Complaint records with documented rationale for not investigating
- Approval records from a qualified individual
- Procedure defining who has authority to waive investigation
- Complaints closed without investigation have no documented rationale
- Rationale is generic ('no investigation needed') without complaint-specific justification
- Decision made by customer service without quality or regulatory approval
The regulation requires that if investigation is not conducted, the reason must be documented. Check who approved the decision and whether the rationale is specific to each complaint.
Find 3 complaints closed without investigation. Verify each has documented rationale and appropriate approval.
- Who has authority to decide that a complaint does not require investigation?
- How do you ensure the rationale is specific to each complaint?
§820.35(d) Service Are service events that represent MDR-reportable events automatically treated as complaints? Are service records integrated with the complaint system?
- Service report procedure defining when a service event triggers the complaint process
- Service records showing integration with complaint handling
- Training records for field service personnel on reportable events
- Service reports are managed by a separate system with no interface to complaint handling — reportable events may never reach quality
- Field service personnel are not trained to recognize MDR-reportable events
- No criteria defined for escalating service events to the complaint system
A field technician who discovers a device malfunction during service has found a potential MDR event. If the service system is not connected to complaint handling, these events can be lost.
Review 5 recent service reports. Check if any involved malfunctions and verify those were routed to complaint handling.
- How does a field service event get escalated to complaint handling?
- Can you show me a service report that was identified as a potential complaint?
§820.35(d) Service UDI Do service records include the UDI or device identifier and meet ISO 13485 §7.5.4 requirements?
- Service records including device identification (UDI, serial, or lot number)
- Service procedure referencing ISO 13485 §7.5.4
- Service report template with required device identification fields
- Service records identify devices by customer and location but not by UDI, serial number, or lot number
- Service records do not document device condition before and after servicing
Service records often live in a CRM or field service system, not the QMS. Verify the service system captures ISO 13485 §7.5.4 data and includes device identification per §820.35.
Review 3 service records for device identification and ISO 13485 §7.5.4 compliance.
- Do service records include the UDI or serial number of the device serviced?
§820.45 §820.45 labeling (fda supplemental)
§820.45(a) Label Exam Are labels physically examined upon receipt against the approved label specification for accuracy, including text, images, barcodes, and UDI encoding?
- Incoming label inspection procedure referencing §820.45(a)
- Inspection records showing comparison against approved specifications
- Approved label specifications used as inspection reference
- Records of label rejections due to accuracy discrepancies
- Incoming inspection checks quantity and print quality but does not verify text accuracy against the approved specification
- Label specifications used for inspection are outdated and do not match current approved artwork
- UDI barcode encoding is not verified — barcode is scanned to confirm it reads but encoded data is not compared against GUDID
This is FDA-specific, not in ISO 13485. Ask to see the last 3 incoming label inspection records and verify the inspection compared received labels against an approved specification — not just a visual check for print quality.
Review 3 incoming label inspection records. Physically compare one label to its specification.
- How do you verify that UDI barcodes encode the correct data, not just that they scan?
- What happens if a label discrepancy is found during incoming inspection?
§820.45(a) Storage Are labels stored with proper identification and controls to prevent mix-ups? Is access to label storage controlled?
- Label storage area showing organized identification and segregation
- Access controls for label storage
- Procedure for label issuance, return, and destruction of obsolete labels
- Labels for multiple products stored without clear segregation
- Obsolete label stock stored alongside current labels with no revision identification
- No procedure for issuing labels — operators self-serve without logging
Visit the label storage area physically. Check that labels for different products and revisions are clearly segregated. Ask what happens to leftover labels when a revision is approved.
Physically inspect label storage. Verify segregation, identification, and access controls.
- When a label revision is approved, what happens to the old stock?
- How do you prevent an operator from using a label for the wrong product?
§820.45(b) Packaging Are labeling and packaging operations examined and documented to ensure correct labels and instructions for use are applied?
- Labeling operation procedure defining verification steps during packaging
- Packaging batch records showing labeling verification
- Line clearance records between production runs
- First-article inspection records for packaged product
- Packaging records have a checkbox for 'labeling verified' with no detail on what was checked
- No line clearance procedure between product changeovers on the packaging line
- Labeling verification performed by the same operator who applied the labels — no independent check
Line clearance is critical. Ask what happens between production runs on the same packaging line. If old labels are not removed and the line is not inspected, label mix-ups are inevitable.
Review 3 packaging batch records. Verify documented labeling verification. Observe a line clearance if possible.
- What is your line clearance process between production runs?
- Who verifies correct label application — is it an independent check?
§inspection Fda inspection readiness
Registration Is the establishment registered with FDA and is the registration current? Are all marketed devices listed?
- FDA establishment registration confirmation
- Device listing records for all marketed devices
- Annual registration renewal records
- Registration has lapsed — annual renewal not completed
- New devices launched but not added to FDA device listing
- Contract manufacturer not independently registered when required
Registration and listing are separate from QMS compliance but will be checked during an inspection. Verify on the FDA FURLS database.
Verify registration status. Cross-check device listing against the product catalog.
- When was your last registration renewal?
- Are all distributed devices listed with FDA?
Document Retrieval Can QMS documents and records be produced promptly during an FDA inspection?
- Document retrieval procedure for regulatory inspections
- Demonstration of key document retrieval within minutes
- Designated inspection point of contact
- Key documents require IT support to access, causing delays
- Records from outsourced processes take days to obtain
- No designated point of contact for inspection document requests
Run a drill: ask for a DHR, a complaint file, and the CAPA log. If any take more than 15 minutes, the system needs work.
Request 3 document types and time retrieval. Over 15 minutes per document is a concern.
- Who is your FDA inspection point of contact?
- Can you produce a CAPA file from 2 years ago within 15 minutes?
483 Response Does the organization have a procedure for responding to FDA Form 483 observations?
- 483 response procedure with timelines and responsibilities
- Template or guidance for response letters
- Records of previous 483 responses if applicable
- No formal 483 response procedure — planned to be handled ad hoc
- Previous 483 responses not tracked as CAPAs
Having a 483 response procedure in advance demonstrates maturity. FDA expects a response within 15 business days.
Review the 483 response procedure. If prior 483s exist, verify responses were timely and corrections effective.
- Have you received a 483 before? How did you respond?
MDR System Is the Medical Device Reporting (MDR) system compliant with 21 CFR 803? Are reporting timelines met?
- MDR procedure referencing 21 CFR 803 with reporting timelines
- MDR log with all filed reports
- Training records for MDR evaluators
- Non-reportable evaluation records with rationale
- MDR reporting timelines not met — 30-day reports filed late
- Procedure does not address 5-day reports for events requiring urgent remedial action
- Complaints involving device malfunctions closed without MDR evaluation
Cross-reference the complaint log with the MDR log. Any complaint involving death, serious injury, or malfunction that could contribute to either should have an MDR evaluation.
Cross-reference complaint and MDR logs. Verify 3 complaint investigations include MDR evaluations.
- How do you ensure MDR-reportable events are identified within complaint handling?
- Walk me through your last MDR report — how was it identified and reported?
§iso13485.fda High-priority iso 13485 areas for fda
Design Controls Are design controls implemented per ISO 13485 §7.3, covering planning, inputs, outputs, review, verification, validation, transfer, and change control?
- Design control procedure covering all §7.3 sub-clauses
- Design history files for 2 recent projects
- Design review records with cross-functional attendance
- Verification and validation reports
- Design verification traceability matrix does not cover all design inputs
- Design validation performed on prototypes without rationale for not using production units
- Design review attendance excludes manufacturing or quality representatives
Design controls are the #1 area for FDA 483 observations. Select a design project and trace it end-to-end: inputs through outputs through V&V through transfer.
Select 1 completed and 1 in-progress project. Review DHF completeness. Trace 5 inputs through V&V.
- Can you show me a complete design history file for your most recent product launch?
- How do you verify every design input has a corresponding verification test?
CAPA Is the CAPA system effective at identifying root causes and preventing recurrence? Are CAPAs completed timely with effectiveness verification?
- CAPA procedure with investigation methodology and effectiveness requirements
- CAPA log showing open/closed CAPAs with timelines
- 3 completed CAPA files with root cause analysis and effectiveness verification
- Trend data on recurring issues
- Root cause analysis consistently cites 'human error' or 'training' without investigating systemic factors
- Effectiveness verification documented as 'no recurrence observed' with no defined monitoring period
- Excessive CAPA backlog with overdue items
CAPA is #2 for FDA 483s. Check 3 CAPAs end-to-end: root cause depth, corrective action adequacy, and effectiveness methodology. 'Operator error' is almost never the true root cause.
Review 3 closed CAPAs for root cause depth, action adequacy, and effectiveness. Check CAPA aging report.
- Show me a CAPA where root cause was something other than training or human error.
- How do you define and measure CAPA effectiveness?
Production Controls Are production processes controlled per ISO 13485 §7.5? Are special processes validated? Is the production environment controlled?
- Production process control procedures
- Process validation records (IQ/OQ/PQ) for special processes
- Environmental monitoring records
- In-process inspection records
- Special processes not identified as requiring validation
- Equipment replaced without revalidation
- Environmental monitoring shows excursions that were not investigated
FDA focuses on process validation and environmental controls. Ask for the special process list and verify each has current validation. Check environmental monitoring trends.
Review 2 special process validations. Check 6 months of environmental monitoring. Review 3 batch records.
- Which processes are classified as special? How did you determine that?
- When was the last revalidation? What triggered it?
Purchasing Are suppliers evaluated, selected, and monitored per ISO 13485 §7.4? Are controls commensurate with purchased product risk?
- Approved supplier list with evaluation status
- Supplier evaluation records for at least 3 suppliers
- Incoming inspection records
- Quality agreements with critical suppliers
- Supplier evaluation based only on price and delivery, not QMS capability
- Re-evaluations overdue for multiple suppliers
- No risk-based differentiation in supplier control levels
FDA expects risk-based supplier controls. Critical material suppliers should receive more rigor than office supply vendors.
Check ASL currency. Review 3 supplier evaluations (1 critical, 1 moderate, 1 low-risk). Verify incoming inspection records.
- How do you determine the control level for each supplier?
- Show me a quality agreement with a critical component supplier.
Nonconforming Product Is nonconforming product identified, documented, segregated, evaluated, and dispositioned per ISO 13485 §8.3? Are concessions properly justified?
- NC product procedure
- Physical inspection of nonconforming material area
- NCRs showing complete disposition records
- Concession/use-as-is records with justification
- Nonconforming material area contains unidentified items
- Use-as-is dispositions approved without safety/performance justification
- Rework performed without documented rework procedures
Visit the nonconforming material area. Every item should be identified and traceable. Check 3 use-as-is dispositions for documented justification.
Visit NC area. Review 5 NCRs with different dispositions. Verify complete documentation.
- Can you take me to the NC material area?
- Show me a use-as-is disposition and its justification.
§crosswalk Legacy qsr to qmsr crosswalk
820.30 → §7.3 Have design control procedures mapped to old §820.30 been updated to reference ISO 13485 §7.3, including all sub-clauses?
- Design control procedure referencing §7.3
- Coverage mapping showing all §7.3 sub-clauses addressed
- Procedure still references §820.30 subsections
- Updated to reference §7.3 but does not cover design transfer (§7.3.8) or design change files (§7.3.9)
Old QSR §820.30 and ISO 13485 §7.3 cover the same territory but are structured differently. Verify all §7.3 sub-clauses are addressed.
Review design control procedure for regulatory references and clause coverage.
- Does your design control procedure address design transfer (§7.3.8)?
820.90 → §8.5 Have CAPA procedures mapped to old §820.90 been updated to reference ISO 13485 §8.5.2 and §8.5.3? Is preventive action addressed separately?
- CAPA procedure referencing §8.5.2 and §8.5.3
- Evidence that preventive action is addressed separately from corrective action
- Procedure references §8.5 generically without addressing §8.5.2 and §8.5.3 separately
- Preventive action is absent — organization has corrective but no proactive preventive actions
ISO 13485 §8.5.3 requires proactive identification of potential problems — not just reacting to failures that already occurred.
Review CAPA procedure. Find at least one preventive action example.
- Can you show me a preventive action initiated proactively, not in response to a failure?
820.184 → §4.2.5 Have DHR requirements mapped to old §820.184 been updated? Do DHRs comply with ISO 13485 §4.2.5 and include UDI per §820.35(a)?
- DHR procedure referencing §4.2.5 and §820.35(a)
- Sample DHR showing UDI inclusion
- DHR content meeting ISO 13485 requirements
- DHR template updated to ISO 13485 but UDI field from §820.35(a) not added
- DHR procedure still references old §820.184 content requirements
DHR requirements changed structurally. Content now comes from ISO 13485 §4.2.5 plus §820.35(a) UDI. Verify the template covers both.
Review DHR template and one completed DHR. Verify UDI and current references.
- Does your DHR template include a UDI field?
820.198 → §8.2.2 Have complaint procedures mapped to old §820.198 been updated to reference ISO 13485 §8.2.2 AND QMSR §820.35(c)?
- Complaint procedure referencing both §8.2.2 and §820.35(c)
- Evidence that §820.35(c) investigation triggers are incorporated
- Updated to §8.2.2 but §820.35(c) supplemental requirements not incorporated
- Investigation triggers still follow old §820.198 criteria
Common gap: §820.35(c) adds requirements on top of ISO 13485 §8.2.2. Verify both are addressed.
Review complaint procedure for dual references. Verify investigation triggers match §820.35(c).
- Does your complaint procedure address both §8.2.2 and §820.35(c)?
Each item shows its evidence, common nonconformities and auditor tips. The PDF holds the same content, formatted for a clipboard.