ISO 13485:2016 clause 8: Measurement, analysis and improvement
The 65 audit questions covering clause 8, each with the objective evidence to request, the nonconformities most often raised against it and what to sample. Part of the free ISO 13485:2016 internal audit checklist, which holds 334 items across 5 clauses.
All 65 questions for clause 8
Open any row for its objective evidence, common nonconformities and auditor tips. You can check items off as you go. This browser remembers your progress across all 5 clauses of this checklist.
§8 Measurement, analysis and improvement
8 Is there a documented framework linking measurement, analysis, and improvement processes (complaints, CAPA, internal audit, data analysis, nonconforming product control) into a closed-loop system? Does evidence confirm that outputs from one sub-process feed as inputs into others?
- QMS process interaction diagram or turtle diagram showing how Section 8 sub-processes (feedback, complaints, audit, NC product, data analysis, CAPA) interconnect and feed each other
- Management review meeting minutes from the last 2 reviews -- verify that inputs include complaint trends, audit findings, NC product data, CAPA status, and process performance metrics
- Quality manual or process map section describing the measurement, analysis, and improvement framework including data flow between sub-processes
- KPI dashboard or quality metrics summary showing the organization tracks and trends key Section 8 outputs (complaint rates, CAPA closure times, NC product rates, audit finding closure)
- Evidence that improvement inputs (complaints, audits, NC data, post-market surveillance) actually result in improvement outputs (CAPAs, process changes, procedure updates)
- Section 8 sub-processes operate in silos -- complaint handling, internal audit, and CAPA are managed by different departments with no formal mechanism to connect recurring complaint themes to audit focus areas or CAPA priorities
- Management review inputs do not include all required Section 8 data sources; the last 3 management reviews discussed CAPA status but did not address complaint trends, internal audit findings, or post-market surveillance data
- The organization has documented procedures for each Section 8 sub-process but no overarching framework showing how they interconnect -- resulting in gaps where complaint patterns are not triggering CAPAs and audit findings are not feeding data analysis
- Quality metrics exist but are limited to lagging indicators (complaint count, NC count) with no leading indicators or trend analysis to drive proactive improvement
Use this introductory item to map the organization's closed-loop improvement system before diving into details. Ask them to draw the connections on a whiteboard. This reveals systemic weaknesses early -- most organizations have the pieces (complaints, audits, CAPA) but struggle with the connections between them. Look for evidence that the system actually closes the loop: does a complaint trend trigger a CAPA? Does a CAPA result in a procedure change? Does the next internal audit verify the change was effective?
Ask for one end-to-end example: a complaint or audit finding that triggered a CAPA, resulted in a documented change, and was verified effective. Trace the full chain.
- Can you give me a specific example from the last 12 months where a complaint trend led to a CAPA, which led to a process change, which was verified effective?
- How does your management review process ensure all Section 8 data sources are reviewed and acted upon?
§8.1 General (measurement, analysis, improvement)
8.1 Is there a documented plan for monitoring, measurement, analysis, and improvement that defines what is measured, methods, frequency, acceptance criteria, and responsible parties? Does the plan address all three purposes: product conformity, QMS conformity, and QMS effectiveness?
- Quality plan or monitoring and measurement plan that defines what is measured, measurement methods, frequency, acceptance criteria, responsible parties, and how results are used for improvement
- Quality objectives with defined KPIs, targets, measurement methods, and review frequency -- verify at least 5 objectives have measurable targets and are actually tracked
- Process performance dashboard or metrics summary showing data is being collected and analyzed across QMS processes (not just manufacturing)
- Management review inputs demonstrating that monitoring and measurement results are systematically reviewed and acted upon
- Evidence that the plan was actually followed -- compare planned measurement activities to actual records for the last 6 months
- No formal monitoring and measurement plan exists; the organization performs inspections and audits but has never documented a systematic plan defining what QMS processes are measured, how, and at what frequency
- Quality objectives are defined but lack measurable targets -- e.g., 'improve customer satisfaction' without a defined metric, baseline, or target value
- Monitoring activities are limited to product inspection and internal audits; QMS support processes (document control, training, purchasing, CAPA) have no defined performance metrics
- The measurement plan was created during initial certification and has never been updated to reflect new products, processes, or regulatory requirements added since
Ask to see the quality plan or metrics framework first. If they cannot produce a single document showing what is measured across the QMS, that itself is a finding. Then spot-check: pick a QMS process (e.g., document control or training) and ask what metrics are tracked for that process. Organizations frequently have robust product monitoring but neglect QMS process monitoring. Also verify that the plan addresses all three purposes in 8.1(a)-(c): product conformity, QMS conformity, and QMS effectiveness.
Request the quality metrics dashboard or KPI report for the most recent quarter. Verify that metrics exist for at least 3 different QMS process areas (not just product quality).
- How do you distinguish between monitoring for product conformity versus monitoring for QMS effectiveness?
- When was the last time you revised your measurement plan, and what triggered the revision?
- How do you ensure measurement results actually lead to improvement actions rather than just being reported?
8.1 (Statistics) Are applicable statistical techniques identified, documented, and justified? Do sampling plans reference recognized standards with risk-based rationale, and are personnel trained in the statistical methods they apply?
- Statistical techniques procedure or section in quality manual defining which statistical methods are used, where they are applied, their basis (e.g., ANSI/ASQ Z1.4 for sampling), and competency requirements for personnel applying them
- Sampling plans for incoming and final inspection -- verify they reference a recognized standard (AQL tables, LTPD, etc.) and that the sampling level is justified based on product risk
- Process capability study (Cpk) for at least one critical process parameter -- verify the study uses sufficient data points and the Cpk meets the organization's defined minimum (typically 1.33)
- Trend analysis reports for complaint data, NC product data, or CAPA data using defined statistical methods -- verify the method is appropriate for the data type
- Training records showing personnel who apply statistical techniques have been trained and are competent in the methods they use
- The organization uses AQL sampling for incoming inspection but cannot justify why the selected AQL level is appropriate for the risk level of the product -- the same AQL 2.5 General Inspection Level II is applied to all components regardless of criticality
- No process capability studies have been performed for critical manufacturing processes; the organization relies on 100% inspection rather than demonstrating process capability through statistical evidence
- Statistical techniques procedure states 'statistical techniques will be applied as needed' without defining which techniques, where, or by whom -- no substantive content
- Trend analysis for complaints and CAPAs consists of simple bar charts with no statistical tests for significance; an upward trend of 3 data points is interpreted as 'significant' without statistical basis
- Personnel performing capability studies and sampling plan administration have no documented training in statistical methods
Many organizations treat this requirement superficially. Ask them to show you every place they use a statistical technique, then verify each one is documented and justified. Common gaps: sampling plans with no documented basis, trend 'analysis' that is just plotting data without statistical interpretation, and process capability claims without sufficient data. If the organization says 'we don't use statistical techniques,' challenge that -- if they do any sampling-based inspection, they are using a statistical technique and must define it.
Pull one incoming inspection sampling plan and one final inspection sampling plan. Verify the AQL level, inspection level, and lot size are documented and appropriate for the product risk classification.
- How do you determine when to tighten or switch sampling plans based on inspection results?
- Who reviews and approves the statistical methods used?
- How do you validate that your statistical software produces correct results?
8.1(a) Are monitoring and measurement activities defined at each stage of product realization (incoming, in-process, final) to demonstrate product conformity? Are acceptance criteria traceable to design output specifications, and do Device History Records contain complete inspection and test results?
- Product inspection and test plans for at least 2 product families -- verify they define inspection stages, characteristics measured, acceptance criteria traceable to design outputs, sample sizes, and test methods
- Incoming inspection records for 3 recent lots of critical raw materials -- verify acceptance criteria are defined and met, and that the records identify who performed the inspection
- In-process inspection records for one recent production batch -- verify that in-process checkpoints match the inspection plan and that out-of-spec results triggered appropriate action
- Final release records for 3 recently shipped batches -- verify all planned activities were completed and release was authorized by designated personnel
- Device History Records (DHRs) for 2 recent production lots -- verify they contain all required test results, inspection records, and acceptance evidence
- Incoming inspection plan references supplier Certificates of Conformity as the sole acceptance method for a critical biocompatible raw material, with no independent verification testing performed by the organization
- In-process inspection checkpoints do not include dimensional measurements specified in the design output drawings -- only visual inspection is performed at the production stage despite critical tolerances
- Final release records for several sampled lots show product was released before environmental conditioning test results were available; test results were added to the DHR retroactively
- No product monitoring is defined for software-based devices -- the measurement plan covers hardware inspection but has no provisions for software verification at production
Trace backward from a shipped product: pull the DHR and verify every inspection and test result matches the requirements in the inspection plan, which should trace to design outputs. The goal is an unbroken chain from customer requirement to design output to inspection plan to test record. Pay special attention to acceptance criteria -- vague criteria like 'acceptable appearance' without defined standards are a frequent finding.
Pull 2 DHRs for recently released product lots. Trace each test result back to the inspection plan and then to the design output specification to verify the chain is complete.
- How do you ensure acceptance criteria in your inspection plans remain aligned with current design output specifications after design changes?
- What happens when a test result is borderline -- just barely within specification?
8.1(b) Are methods defined for monitoring and measuring QMS conformity beyond internal audits? Are ongoing conformity indicators (document control compliance, training completion, CAPA closure rates) tracked between audit cycles to provide continuous conformity assessment?
- Internal audit program and schedule showing coverage of all QMS processes and ISO 13485 clauses over the audit cycle -- verify the schedule has been followed
- QMS conformity metrics or compliance dashboard -- verify the organization tracks conformity indicators beyond just audit findings (e.g., document control compliance rates, training completion rates, CAPA on-time closure)
- Most recent internal audit report covering a Section 8 process -- verify the audit assessed not just whether procedures exist but whether they are effectively implemented
- Management review slides or minutes showing QMS conformity data was presented, discussed, and resulted in specific actions
- External audit results (registrar, notified body) and evidence that findings were addressed
- Internal audit program covers only production-related processes; QMS support processes (management review, document control, human resources, infrastructure) have not been audited in the current 3-year cycle
- QMS conformity is assessed solely through internal audits -- no ongoing process performance metrics exist to provide continuous conformity monitoring between audit cycles
- Internal audit findings from the last cycle identified 4 minor nonconformities in CAPA effectiveness, but the management review did not discuss them and no improvement actions were initiated
- The organization cannot demonstrate how it verifies conformity to its own QMS requirements that exceed ISO 13485 minimums -- only ISO clauses are audited, not company-specific procedures
Look for evidence of QMS conformity monitoring between internal audits. Many organizations rely exclusively on annual audits for conformity assessment, creating 11-month blind spots. Effective organizations supplement audits with ongoing metrics (training completion rates, document review timeliness, CAPA aging). Also check whether the internal audit scope covers regulatory requirements in addition to ISO 13485 clauses.
Request the internal audit schedule and verify all QMS processes (not just production) have been audited within the defined cycle. Check that at least 2 support processes have recent audit reports.
- Between internal audits, how do you know your QMS is conforming?
- How do you verify conformity to regulatory requirements that go beyond ISO 13485?
8.1(c) Are QMS effectiveness metrics defined with trend data over at least 12 months? Does evidence demonstrate that adverse trends trigger improvement actions, and that those actions produce measurable results?
- QMS effectiveness metrics or KPIs with trend data over at least 12 months -- verify there are metrics that measure outcomes (defect rates trending down, CAPA closure time improving) not just activity counts
- Management review records showing effectiveness data was analyzed and specific improvement actions were assigned with due dates and responsible parties
- At least 2 examples of improvement actions initiated from monitoring data (not from audits or complaints) -- verify the improvement was implemented and its effect measured
- Quality objectives performance report showing actual vs. target for each objective -- verify that objectives not meeting targets have documented improvement plans
- Evidence that improvement actions from prior management reviews were followed up and their effectiveness verified
- Management review records show quality metrics are presented but there is no evidence of analysis, discussion, or decisions -- minutes consist only of data tables with no action items or conclusions
- Quality objectives have been unchanged for multiple years despite consistently meeting all targets, suggesting objectives are not challenging enough to drive meaningful improvement
- CAPA on-time closure rate has been declining for 6 consecutive months (from 85% to 62%) but no improvement action has been initiated -- the data is collected but not acted upon
- Effectiveness measurement is limited to 'no recurrence of the specific problem' rather than demonstrating systemic improvement; CAPA effectiveness checks are perfunctory sign-offs with no objective data
This is where you test whether the QMS is a living system or a paper exercise. Ask for trend data over 12 months and look for evidence of response to adverse trends. If every metric shows green/on-target, be skeptical -- either the targets are too easy or the data is not reflecting reality. The gold standard is an organization that can show you a specific metric that trended unfavorably, the action they took, and the measurable improvement that resulted.
Pull the quality objectives performance report and pick the 2 objectives closest to or below their targets. Trace whether improvement actions were initiated and whether they produced measurable improvement.
- Can you show me a specific metric that trended negatively and what you did about it?
- How do you set targets for quality objectives -- are they based on historical data, benchmarks, or regulatory expectations?
§8.2 Monitoring and measurement
8.2.1 Is there a documented system for gathering and monitoring customer feedback across all channels (complaints, returns, service calls, surveys, post-market surveillance)? Does feedback data feed into the QMS through trend analysis and management review?
- Customer feedback procedure defining all feedback channels (complaints, returns, service calls, surveys, sales feedback, social media monitoring, post-market surveillance) and how each is captured, categorized, and routed
- Feedback log or database showing entries from at least 3 different feedback channels over the last 12 months -- verify entries are categorized and include the action taken or disposition
- Post-market surveillance plan and most recent report -- verify it includes proactive data collection (not just reactive complaint handling) from clinical users, literature, similar devices, and regulatory databases
- Quarterly or annual feedback trend analysis report showing complaint rates, return rates, service call categories, and satisfaction scores with trend direction and commentary
- Management review inputs showing feedback data was presented and specific actions were taken based on feedback trends
- Feedback system captures only formal written complaints; verbal feedback from sales representatives and service technicians is not systematically recorded, resulting in loss of valuable field intelligence about product performance issues
- Post-market surveillance plan exists but only covers complaint monitoring -- there is no proactive monitoring of scientific literature, regulatory databases (MAUDE, EUDAMED), competitor recalls, or clinical outcome data for similar devices
- Customer satisfaction is measured by a single annual survey with a 12% response rate; the organization cannot demonstrate it has a representative understanding of customer satisfaction across its user base
- Feedback data is collected and reported but there is no evidence it triggers improvement actions -- complaint trends showing a 40% increase in a specific failure mode over 6 months resulted in no investigation or CAPA
Complaint handling is the #1 focus area for FDA and notified body audits. Start broad: ask what channels exist for feedback (not just complaints), then narrow to the complaint system. Key red flags: feedback that is received but not logged, verbal complaints that are never formalized, and trend data that exists but triggers no action. Under EU MDR, post-market surveillance is significantly expanded -- verify the organization's PMS plan goes beyond just complaint monitoring to include proactive data collection.
Request the feedback log and identify 3 entries from different channels (one complaint, one service call, one field report). Trace each through the system to verify it was properly categorized, investigated where appropriate, and linked to CAPA if needed.
- How do you ensure that verbal feedback from service technicians and sales representatives gets formally captured in your feedback system?
- What triggers an escalation from routine feedback to a formal complaint investigation?
- How does your post-market surveillance plan satisfy EU MDR Article 83 requirements for proactive data collection?
8.2.1 (Complaint) Are complaints closed without corrective or preventive action supported by documented, risk-based justification? Is the decision approved by authorized personnel, and are trend analyses performed on complaints closed without CAPA to identify emerging patterns?
- Complaint log for the last 12 months showing all complaints received, their investigation status, and whether CAPA was initiated -- filter for complaints closed without CAPA
- Justification records for at least 5 complaints closed without CAPA -- verify each justification is specific (not boilerplate), addresses the risk to the patient/user, and was approved by an authorized individual
- Risk assessment or reportability evaluation for each complaint closed without action -- verify the risk assessment considered probability of recurrence and severity of potential harm
- Procedure defining who has authority to close a complaint without CAPA and what justification criteria must be met
- Trend analysis of complaints closed without action -- verify the organization monitors whether 'no action' complaints are clustering around a specific failure mode that should trigger CAPA
- A significant proportion of complaints were closed without CAPA, but justification for many of them consists of a single boilerplate statement: 'isolated incident, no further action required' -- no risk-based rationale is provided and the same boilerplate is used regardless of the complaint nature or severity
- Authority to close complaints without CAPA is not defined in the procedure; junior quality technicians are closing complaints without action using their own judgment with no supervisory review or approval
- Three complaints about the same device malfunction were each individually justified as 'isolated incident' and closed without CAPA; when viewed as a trend, they represent a recurring failure pattern that should have triggered investigation
- Justification records do not address patient safety impact -- complaints involving potential patient harm were closed without action based solely on the observation that the device still functioned (ignoring degraded performance)
This is a high-value audit trail. Pull the complaint log and immediately filter for complaints closed without CAPA. These are where regulators find the biggest issues. Read the justifications carefully -- look for boilerplate language, missing risk assessments, and junior staff making closure decisions without authority. Then cross-reference: are there multiple 'no action' complaints about the same failure mode? If so, the justification for each individual complaint may be undermined by the collective pattern.
Pull 5 complaints closed without CAPA -- select those involving the highest-risk device or most serious complaint description. Review each justification for specificity, risk assessment, and authorization.
- Who specifically has the authority to close a complaint without initiating CAPA?
- Do you perform periodic aggregate reviews of complaints closed without action to look for emerging patterns?
- Can you show me the risk criteria you use to determine whether a complaint warrants CAPA?
8.2.1 (Procedures) Is there a documented feedback procedure covering both production and post-production activities? Does it define how feedback from field service, manufacturing observations, long-term device performance, and post-market surveillance is captured, routed, and analyzed?
- Documented feedback procedure with revision history -- verify it explicitly addresses both production-stage feedback (in-process defects, yield issues, operator observations) and post-production feedback (field complaints, service data, returns, PMS data)
- Production feedback records showing how manufacturing floor observations, process deviations, and yield data are captured and analyzed as feedback on product and process performance
- Post-production data collection records -- verify the organization collects data beyond complaints (service records, warranty claims, clinical follow-up, literature surveillance, registry data if applicable)
- Feedback routing procedure or flowchart showing how different types of feedback are triaged to the appropriate department for action (quality, engineering, regulatory, service)
- Evidence the procedure is followed -- compare 3 recent feedback entries to the procedure steps and verify each step was completed
- Feedback procedure covers only post-market complaints; there is no provision for capturing and analyzing production-stage feedback such as in-process rejections, operator-reported issues, or process deviations as feedback on product design adequacy
- Post-production feedback is limited to the first 2 years after launch; for devices with a 10-year expected service life, the organization has no mechanism to collect or analyze long-term field performance data
- Procedure defines feedback channels but does not define how feedback is analyzed -- individual entries are processed but there is no requirement for periodic aggregate analysis to identify patterns
- Service department collects detailed field failure data during device repairs but this data is maintained in a separate system and is not routed to quality for inclusion in the feedback process
The key word here is 'production as well as post-production.' Many organizations have robust complaint handling but miss production-stage feedback. Ask how in-process rejections, scrap, rework, and operator observations feed back into the system. Also probe the post-production side for more than just complaints -- service data, warranty claims, and clinical follow-up data should all be captured. Under EU MDR, post-market surveillance requirements are significantly expanded.
Request one example of production-stage feedback (e.g., recurring in-process defect) and one post-production feedback entry (e.g., service call or field report). Verify both were processed per the procedure.
- How does your manufacturing team's feedback on producibility issues get captured in this system?
- For devices on the market for more than 5 years, how do you continue to collect and analyze performance data?
8.2.1 (Regulatory) Are applicable regulatory requirements for post-production experience collection identified for each market? Is post-market surveillance data (clinical follow-up, literature monitoring, registry data, adverse event databases) integrated into the feedback process, including PMCF plans and reports where required by EU MDR?
- Regulatory requirements matrix identifying all post-production experience requirements by market (FDA post-market surveillance, EU MDR PMCF, EU MDR PSUR, Health Canada PMS, etc.) and how each is addressed
- Post-market clinical follow-up (PMCF) plan for at least one device -- verify it defines data sources, evaluation criteria, update frequency, and how results feed into the clinical evaluation and risk management
- Most recent PMCF evaluation report or periodic safety update report (PSUR) -- verify it includes clinical data analysis, comparison to state of the art, and conclusions about benefit-risk
- Evidence of literature surveillance showing systematic searches of scientific databases for publications relevant to the organization's devices -- verify search terms, databases searched, frequency, and how findings are evaluated
- Records showing post-market data has been fed back into risk management (risk file updates), clinical evaluation, and design inputs as required by EU MDR Article 83
- The organization markets Class IIb devices under EU MDR but has not established a PMCF plan; post-market surveillance is limited to complaint monitoring with no proactive clinical data collection as required by MDR Annex XIV Part B
- Literature surveillance is performed once annually by a quality engineer with no clinical background; search strategy covers only the organization's brand name, missing publications about the generic device type, materials, or similar devices
- Post-market data is collected but not fed back into the clinical evaluation or risk management file -- the clinical evaluation was last updated at time of initial CE marking and does not incorporate 3 years of post-market clinical data
- PSUR is overdue but has not been prepared; the organization was unaware of the reporting frequency requirement for their device class under EU MDR Article 86
Under EU MDR, post-market surveillance requirements are dramatically expanded compared to MDD. Verify the organization understands what is required for their specific device class and market. For Class IIb and III devices, PMCF is essentially mandatory and must be proactive (not just complaint monitoring). Check that PMS data feeds back into clinical evaluation updates and risk management file reviews. For FDA-regulated products, verify compliance with 21 CFR 803 (MDR) and any post-market surveillance orders under Section 522.
Pull the PMCF plan for the organization's highest-risk device. Verify it defines proactive data collection methods beyond complaint handling and that the most recent report demonstrates these methods are being executed.
- How does your PMCF data feed into your clinical evaluation update cycle?
- When was your risk management file last updated based on post-market surveillance findings?
- How do you monitor MAUDE, EUDAMED, and other regulatory databases for adverse events involving similar devices?
8.2.2 Is there a documented complaint handling procedure with defined timelines for each stage (intake, investigation, reportability assessment, closure)? Do complaint records demonstrate timely processing, and are overdue complaints tracked with justification?
- Complaint handling SOP with revision history -- verify it defines timelines for each stage (intake acknowledgment, investigation initiation, reportability assessment, investigation completion, closure) and that these timelines align with regulatory requirements
- 3 complete complaint files from the last 6 months -- verify each contains: intake record with date received, initial risk assessment, investigation report with root cause, reportability determination with rationale, CAPA decision, and closure with authorization
- Complaint database or log showing complaint aging -- verify no complaints exceed the SOP-defined timelines without documented justification for extension
- Complaint metrics report showing average investigation cycle time, percentage closed on time, and overdue complaint count with aging breakdown
- Evidence of regulatory requirement integration -- verify the procedure incorporates applicable reporting timelines (FDA 30-day MDR, EU MDR vigilance 15-day, etc.)
- Complaint handling procedure defines no specific timelines for investigation or closure; there is no SOP-defined expectation for how quickly a complaint must be investigated, resulting in complaints that remain open for 6-8 months without documented justification
- A significant proportion of complaints exceeded the SOP-defined investigation timeline; for many of these, there is no documented justification or management approval for the extension
- Complaint investigation for a device malfunction that caused patient injury was initiated 47 days after receipt; the procedure defines 'timely' as 'as soon as practicable' but does not escalate high-risk complaints for expedited investigation
- Complaint handling procedure has not been updated to incorporate EU MDR vigilance reporting requirements despite the organization transitioning from MDD to MDR
Timeliness is the key word in this clause. Pull the complaint log sorted by aging and immediately look at the oldest open complaints -- these reveal systemic backlog issues. Then trace 3 complaints end-to-end, mixing one that resulted in CAPA, one closed without action, and one involving a serious event. For each, verify that every procedure step was followed and timelines were met. FDA expects complaint investigations to be completed within a reasonable timeframe; any complaint open more than 120 days without documented justification is a red flag.
Pull 5 complaints: 1 involving a serious injury or death, 1 that resulted in CAPA, 1 closed without action, 1 currently open, and 1 involving a reportable event. Trace each through the complete procedure.
- What is your current complaint backlog, and how many complaints exceed your SOP-defined investigation timeline?
- How do you escalate high-risk complaints for expedited investigation?
- What resources are dedicated to complaint investigation, and is the team appropriately staffed for your complaint volume?
8.2.2 (Records) Does the complaint procedure address all four required elements: investigation responsibilities, regulatory reporting determination, complaint-related product handling, and CAPA determination? Do complaint records demonstrate each element was executed?
- Complaint investigation procedure section defining investigation methodology, required investigation steps, responsibility for conducting investigations, and escalation paths for complex or high-risk investigations
- Regulatory reporting decision tree or flowchart showing how each complaint is assessed against applicable reporting criteria (FDA MDR, EU MDR vigilance, Health Canada mandatory problem reporting) with documented decision at each node
- Complaint-related product handling procedure -- verify it covers return authorization, chain of custody for returned product, examination and testing protocols, retention and disposal requirements
- CAPA determination procedure showing criteria for deciding whether a complaint requires CAPA, corrective action only, or no action -- with required approvals at each decision point
- 5 complaint investigation records -- verify each addresses all 4 required elements: investigation findings, reportability decision with rationale, product handling (if applicable), and CAPA determination with justification
- Complaint investigations are performed by the same person who receives the complaint with no independent review; a single quality technician investigates, determines reportability, and decides on CAPA with no supervisory oversight or approval
- Regulatory reporting decision tree addresses FDA MDR criteria but does not include EU MDR vigilance reporting criteria, Health Canada requirements, or other applicable national reporting requirements for markets where the device is sold
- No procedure exists for handling complaint-related product; returned devices are stored in an unlabeled area of the warehouse with no chain of custody, no examination protocol, and no retention policy
- CAPA determination for complaints is binary (CAPA or no CAPA) with no consideration of whether a correction (without full CAPA) might be appropriate; this results in either full CAPA for minor issues or no action for moderate issues
This clause requires procedures to address four specific elements. During the audit, verify each element is both documented and practiced. The regulatory reporting determination is the most legally sensitive -- verify that every complaint is assessed for reportability (not just those the organization considers 'serious') and that the decision is documented with rationale. For product handling, visit the area where returned product is stored and verify physical controls are in place.
Select the 3 most recent complaints involving returned product. Verify the product was received, logged, examined, and that examination results informed the investigation conclusions.
- Who performs the reportability assessment, and what training have they received on applicable reporting criteria?
- Show me where returned complaint-related product is stored and how chain of custody is maintained.
- How do you ensure that complaints from all markets (not just the largest) are assessed against local reporting requirements?
8.2.2(a) Is there a defined complaint intake process that captures complaints from all channels (phone, email, distributors, regulatory databases)? Are intake records complete with device identification, event description, and receipt date, and are all intake personnel trained?
- Complaint intake form or electronic record template -- verify it captures: date received, source, contact information, device identification (model/lot/serial), description of event, patient involvement, initial risk classification, and receipt acknowledgment
- Complaint log showing all intake channels (phone, email, web, distributor reports, field service, regulatory databases) with evidence that complaints from each channel are recorded consistently
- 3 recent intake records -- verify they are complete, legible, and were recorded promptly (same business day or within SOP-defined timeframe)
- Procedure for handling complaints received through distributors or agents -- verify there is a defined mechanism and timeline for distributors to forward complaints
- Evidence of intake training for all personnel who might receive complaints (customer service, sales, technical support)
- Complaints received by the sales team via phone or in-person are not systematically forwarded to quality; interviews with 3 sales representatives reveal they handle 'minor' product issues directly with customers without logging them in the complaint system
- Complaint intake form does not capture device identification information (lot number, serial number, catalog number); 60% of complaint records have 'unknown' in the device identification field, making trending by lot or serial impossible
- Distributor in South America forwards complaints quarterly in a batch report; complaint dates show 30-90 day delays between the customer's initial report to the distributor and the organization's receipt of the complaint
- After-hours complaints received via voicemail are not retrieved until the following business day; no procedure exists for urgent after-hours complaint intake for safety-critical events
Test all intake channels, not just the primary one. Ask customer service, sales, technical support, and field service personnel how they handle a product complaint. Look for shadow systems where complaints are handled informally without entering the formal complaint system. Also check distributor complaint forwarding -- delays between customer report and manufacturer receipt are a common finding, especially in international distribution networks.
Pick 3 complaints from different intake channels (direct customer email, distributor report, field service report). Compare the date the customer first reported the issue to the date it was entered in the complaint system.
- If a customer calls your sales representative with a product complaint on a Friday evening, what happens?
- How do you verify that all distributors are forwarding complaints within the required timeframe?
8.2.2(b) Is there a documented definition of "complaint" consistent with ISO 13485 and applicable regulatory definitions? Are classification criteria defined for distinguishing complaints from general feedback, and are non-complaint classifications documented with rationale and reviewed by authorized personnel?
- Documented definition of 'complaint' consistent with ISO 13485 (any written, electronic, or oral communication alleging deficiencies related to identity, quality, durability, reliability, usability, safety, or performance of a device after release) and any applicable regulatory definitions
- Classification criteria or decision tree for distinguishing complaints from general feedback, service requests, user error reports, and inquiries
- 5 feedback records evaluated as 'not a complaint' -- verify each has a documented rationale for why it does not meet the complaint definition and was reviewed by an authorized individual
- Training records showing intake personnel understand the complaint definition and classification criteria
- Periodic review of 'non-complaint' classifications to verify they are being applied consistently and that complaints are not being improperly excluded
- Definition of complaint in the SOP excludes 'user error' events, but the organization classifies 35% of all feedback as 'user error' without investigation -- some of these may involve design deficiencies that contribute to use errors, which should be investigated as complaints
- Service requests and warranty claims are handled by a separate department and are not evaluated against the complaint definition; a review of 10 recent warranty claims reveals 4 that describe device malfunctions meeting the complaint definition
- Classification as 'inquiry' versus 'complaint' is made by customer service representatives with no quality training and no supervisory review; the decision is subjective with no documented criteria
- The organization does not include reports of device non-performance (device did not work as expected but no harm occurred) in its complaint definition, contrary to FDA's broad definition of complaint under 21 CFR 820.3(b)
This is a common area for under-reporting. Organizations sometimes define 'complaint' narrowly to exclude events they do not want to track (user error, cosmetic issues, device non-performance without harm). Compare the organization's definition to the ISO 13485 definition and to FDA 21 CFR 820.3(b). Then audit the 'non-complaint' bin -- this is where improperly excluded complaints hide. Ask to see the last 20 feedback entries classified as 'not a complaint' and independently evaluate whether any should have been classified as complaints.
Review the last 20 feedback entries classified as 'not a complaint.' Independently evaluate whether any describe device deficiencies that meet the ISO 13485 complaint definition.
- How do you distinguish between a 'use error' that is a complaint and one that is not?
- Are service requests and warranty claims screened against the complaint definition?
- Who has the authority to classify feedback as 'not a complaint,' and is that decision reviewed?
8.2.2(c) Are complaint investigations conducted using a structured root cause analysis methodology? Do investigation reports document investigative steps performed, evidence collected, root cause identified, root cause verification, and conclusions reviewed by an independent authority?
- Complaint investigation procedure defining investigation methodology, required investigation steps (timeline reconstruction, failure analysis, root cause analysis), evidence requirements, and documentation standards
- 3 complete investigation reports -- verify each includes: problem statement, investigation steps performed, evidence collected, root cause analysis using a structured method (5-Why, Ishikawa, fault tree), root cause verification, and conclusions
- Evidence of physical examination or testing of returned complaint product where applicable -- verify examination findings are documented and correlated with the complaint description
- Root cause analysis records using structured methodology -- verify the analysis goes beyond the immediate cause to systemic factors (training, procedure, design, process capability)
- Investigation closure review records showing someone with appropriate authority reviewed the investigation completeness and conclusions before closure
- Investigation reports for a majority of sampled complaints identify root cause as 'operator error' or 'handling damage' with no further analysis of why the error occurred or what systemic factors contributed
- Complaint investigation for a device failure that caused patient injury consists of a single paragraph stating 'unable to determine root cause -- returned device was not available for examination' with no further investigative steps attempted
- Investigation of a recurring sterility breach complaint did not include environmental monitoring data review, sterilization validation records, or packaging integrity testing -- investigation was limited to reviewing the complaint description
- Complaint investigations are closed by the same individual who performed the investigation with no independent review; there is no quality assurance check on investigation thoroughness or conclusions
Read the investigation reports critically. The most common weakness is superficial root cause analysis -- stopping at the immediate cause ('operator error') without asking why the error was possible (was the process error-proofed? was training adequate? was the procedure clear?). Look for investigations where the returned product was not examined, investigations closed as 'cannot determine' without exhausting reasonable investigative steps, and investigations where the conclusion does not logically follow from the evidence. If root cause is consistently 'operator error,' the real root cause is likely a system problem.
Pull 5 investigation reports: 2 with root cause 'operator error,' 1 with root cause 'cannot determine,' 1 involving a serious event, and 1 that led to CAPA. Evaluate each for investigative rigor.
- What percentage of your complaint investigations identify root cause as 'operator error,' and what do you do with that information?
- When a returned device is not available for examination, what alternative investigative steps do you perform?
- How do you verify that your identified root cause is actually the true root cause and not just a contributing factor?
8.2.2(d) Is each complaint assessed for regulatory reportability against all applicable requirements (FDA MDR, EU MDR vigilance, Health Canada)? Are reportability assessments completed within required timeframes, documented with rationale, and performed by trained personnel?
- Regulatory reporting decision tree or assessment form covering all applicable reporting requirements (FDA MDR under 21 CFR 803, EU MDR vigilance under Article 87, Health Canada mandatory problem reporting, MDSAP market-specific requirements)
- 5 reportability assessments for complaints involving device malfunction, injury, or death -- verify each assessment was performed within the regulatory timeframe, documented the decision rationale, and was approved by a qualified individual
- List of all regulatory reports filed in the last 24 months -- cross-reference against the complaint log to verify all reportable events were reported and no reportable complaints were missed
- Training records for personnel who perform reportability assessments -- verify they have documented training on applicable regulatory reporting criteria
- Vigilance report copies (FDA MedWatch, EU Manufacturer Incident Reports, etc.) with evidence of timely submission
- Reportability assessment was not performed within the regulatory-required awareness period for several complaints involving device malfunction that could cause serious injury; assessments were completed well after the deadline
- Reportability decision tree addresses only FDA MDR criteria; the organization sells devices in 14 countries but has not developed reporting criteria for EU MDR vigilance, Health Canada, or other applicable national requirements
- Two complaints involving device malfunction during surgical procedures were assessed as 'not reportable' because no actual injury occurred; the assessment did not consider that the malfunction 'could have caused or contributed to' a serious injury, which is the FDA reporting threshold
- Regulatory affairs manager who performs reportability assessments has no documented training on current FDA MDR criteria or EU MDR vigilance requirements; last training was on the legacy MDD reporting system in 2019
Reportability assessment is where the highest legal exposure exists. Focus on two things: (1) timeliness -- was the assessment done within regulatory timeframes (FDA: 5-day awareness, EU MDR: without delay upon awareness), and (2) accuracy -- was the assessment applied correctly. The FDA reporting threshold is lower than many organizations realize: if a malfunction 'could have' caused harm, it is reportable even if no harm occurred. Pull the complaint log and independently identify complaints that appear reportable, then check whether the organization assessed and reported them.
Pull all complaints from the last 12 months involving device malfunction, injury, or death. For each, verify that a reportability assessment was completed within the applicable regulatory timeframe and that the decision is defensible.
- How do you define 'date of awareness' for the purpose of regulatory reporting timelines?
- For device malfunctions where no injury occurred, how do you assess whether the malfunction 'could have' caused serious injury?
- How do you handle reportability for complaints involving devices sold through distributors in multiple countries?
8.2.2(e) Is there a procedure for handling complaint-related returned product that defines receipt logging, chain of custody, segregation, examination protocols, and disposition? Are returned products stored in a segregated, identified, access-controlled area with complete traceability to complaint files?
- Returned product handling procedure defining receipt logging, chain of custody documentation, storage conditions, segregation requirements, examination protocols, testing requirements, and disposition options
- Physical examination of the returned product storage area -- verify it is segregated, identified, access-controlled, and that stored products are traceable to specific complaint files
- Chain of custody records for 3 returned complaint products -- verify the chain is unbroken from receipt through examination and final disposition
- Examination and testing records for returned products -- verify examination was performed by qualified personnel, test methods were appropriate, and findings are correlated with the complaint investigation
- Disposition records showing what happened to the returned product after examination (retained for further analysis, returned to customer, destroyed, etc.) with authorization
- Returned complaint products are stored in the same area as general product returns with no segregation, identification, or access controls; two returned complaint products could not be located during the audit
- Chain of custody is broken: receiving department logs incoming packages but does not record when or how the returned product was transferred to quality for examination; quality has no record of when they received the product
- Returned device involved in a patient injury complaint was examined visually but not tested functionally because 'the device appeared undamaged' -- no documented risk assessment justifying why functional testing was not needed
- Three returned complaint products were disposed of (destroyed) before the complaint investigation was complete, eliminating the possibility of further examination if the initial investigation was inconclusive
Ask to physically visit the returned product storage area. This is a high-impact audit activity that reveals problems documentation review alone cannot detect. Look for proper segregation, labeling (tied to complaint numbers), access controls, and environmental conditions appropriate for the product type. Then trace 2-3 returned products from the storage area back to their complaint files to verify the chain of custody is complete. Organizations that handle returned product well typically have a dedicated, access-controlled area with a log book.
Physically inspect the returned product storage area. Select 3 items and trace each back to its complaint file. Verify chain of custody, examination records, and disposition documentation.
- How long do you retain complaint-related product after investigation closure?
- If a returned device is damaged beyond examination, how do you document that and adjust your investigation approach?
- Who authorizes the final disposition of complaint-related product?
8.2.2(f) Is the need for corrective or preventive action determined for each complaint using documented, risk-based criteria? Are CAPA determination records specific (not boilerplate), approved by authorized personnel, and reviewed in aggregate to identify patterns across individually closed complaints?
- CAPA determination criteria or decision matrix used to evaluate whether each complaint requires full CAPA, correction only, or no action -- verify criteria are risk-based and consider factors like severity, probability of recurrence, and patient safety impact
- CAPA determination records for 10 recently closed complaints -- verify each has a specific, documented rationale (not boilerplate) and was approved by an authorized individual
- Complaints that resulted in CAPA -- verify the CAPA record references the complaint number and the CAPA addresses the root cause identified in the complaint investigation
- Complaints that resulted in correction only (no CAPA) -- verify the correction was appropriate and the rationale for not escalating to full CAPA is documented and reasonable
- Trend analysis of CAPA decisions showing the organization monitors whether patterns in 'no action' complaints should collectively trigger CAPA
- CAPA determination for a majority of reviewed complaints consists of a checkbox marked 'No CAPA required' with no documented rationale or risk assessment explaining why the complaint does not warrant corrective action
- Organization opened CAPA for only a small fraction of complaints in the past year; many of the remaining complaints describe recurring failure modes that individually do not meet the CAPA threshold but collectively indicate a systemic issue requiring corrective action
- Corrections are performed (e.g., device replaced, customer credited) but no evaluation is done to determine whether the underlying cause needs corrective action to prevent recurrence -- the correction is treated as the final disposition
- Three complaints involving the same software anomaly were each individually assessed as 'not requiring CAPA' because each was classified as 'isolated'; no mechanism exists to aggregate related complaints for collective CAPA determination
Look at the CAPA conversion rate -- the percentage of complaints that result in CAPA. While there is no universal benchmark, a rate below 5% should raise questions about whether the organization's threshold is too high. Conversely, a rate above 50% may indicate the organization is not distinguishing between issues that need systemic correction and those that can be addressed with simple corrections. The key question is: is the organization making thoughtful, risk-based decisions, or just checking a box? Also look for complaint clusters that individually do not trigger CAPA but collectively should.
Pull the last 20 closed complaints. Calculate the CAPA conversion rate. Review 5 'no CAPA' decisions and 3 'CAPA initiated' decisions for consistency and appropriateness of the criteria application.
- What is your complaint-to-CAPA conversion rate, and is that rate tracked and reviewed?
- How do you aggregate related complaints to identify when a pattern of individual issues should trigger CAPA?
- Can you show me a complaint where the initial determination was 'no CAPA' but was later changed based on new information or trend data?
8.2.3 Is there a documented adverse event reporting procedure covering all markets where devices are sold? Are reporting criteria, timelines, forms, and follow-up requirements defined for each jurisdiction, and do regulatory report logs demonstrate timely submissions with complete documentation?
- Adverse event reporting SOP covering all applicable regulatory requirements by market -- verify it includes reporting criteria, timelines, responsible personnel, report forms, and follow-up reporting requirements for each jurisdiction
- Regulatory reporting matrix showing all markets where devices are sold, applicable reporting authority for each, reporting criteria, and required timelines (e.g., FDA 30-day/5-day, EU MDR 15-day/2-day, trend reporting)
- Copies of the last 5 adverse event reports submitted to regulatory authorities -- verify each was submitted within the required timeframe and contains all required information
- Adverse event reporting log showing all reports submitted in the last 24 months, the complaint that triggered each report, and the submission date versus the awareness date
- Follow-up and supplemental reports -- verify that initial reports requiring follow-up had supplemental reports submitted as additional investigation information became available
- Adverse event reporting procedure covers FDA MDR reporting only; the organization sells devices in 8 EU member states but has no documented procedure for EU MDR vigilance reporting, including no defined process for Manufacturer Incident Reports or Field Safety Corrective Actions
- Two reportable events were identified in the complaint investigation but the regulatory report was not submitted until 52 and 67 days after awareness, exceeding the 30-day FDA MDR timeline; the organization was unaware of the awareness clock starting at complaint receipt
- No trend reporting procedure exists; the organization has filed 6 individual MDR reports for the same device malfunction over 18 months but has not submitted an FDA MDR trend report as required when the failure rate exceeds expected levels
- Follow-up reports are not tracked; several FDA MDRs submitted as initial reports indicated 'investigation ongoing' but no supplemental reports were filed after investigation completion to update the regulatory authority with findings and corrective actions
Regulatory reporting is a legal obligation with strict timelines. The two most common findings are: (1) late submissions -- the clock starts at 'awareness' which FDA defines as when any employee becomes aware of a reportable event, not when quality finishes the investigation; and (2) incomplete market coverage -- organizations report to FDA but miss reporting obligations in other markets. Also check for trend reporting obligations (FDA requires manufacturers to report when device experience exceeds expected levels). Cross-reference the complaint log against the regulatory report log to independently verify that all reportable events were reported.
Cross-reference the complaint log (filter for malfunctions, injuries, deaths) against the regulatory report log. Verify every reportable complaint resulted in a timely regulatory submission. Check for gaps.
- How do you ensure that the 'awareness' clock starts correctly -- at initial complaint receipt, not at investigation conclusion?
- Do you submit trend reports to FDA when you see recurring events for the same device?
- How do you manage Authorized Representative obligations for vigilance reporting in markets where you do not have direct presence?
8.2.4 Is there a documented internal audit program with a schedule covering all QMS processes, qualified and independent auditors, completed audit reports, and timely corrective action follow-up? Is the audit schedule completion rate tracked, and are auditor independence and competency requirements met?
- Internal audit procedure defining audit planning, preparation, execution, reporting, follow-up, and record retention requirements
- Current audit schedule showing planned audit dates, scope, assigned auditors, and status -- verify all QMS processes are covered within the audit cycle
- Auditor qualification records for all active internal auditors -- verify they meet the organization's defined competency criteria (training, experience, independence) and that qualifications are current
- Audit reports for the most recent complete audit cycle -- verify all scheduled audits were actually performed and that reports meet the documented reporting requirements
- Evidence of auditor independence -- verify no auditor audited their own department or work area, and that the audit program manager has authority to assign auditors regardless of departmental pressure
- Corrective action follow-up records showing audit findings were addressed within defined timelines
- Audit schedule shows 12 QMS processes scheduled for audit in the current 12-month cycle, but only 7 have been completed with 2 months remaining; the organization has a pattern of completing only 60-70% of scheduled audits annually
- Two internal auditors audited processes within their own department: the quality manager audited the CAPA process and the production supervisor audited the manufacturing process -- auditor independence was not maintained
- Auditor qualification file for several internal auditors contains only a generic quality system auditor certificate from years ago; no evidence of ISO 13485-specific training, medical device regulatory awareness, or ongoing competence development
- Corrective actions from an internal audit were due within the defined timeframe; the majority remain open well past the due date with no documented justification for the delay or management escalation
Start with the audit schedule and verify completion status. Then check auditor independence -- this is a frequent finding, especially in small organizations where few people are qualified to audit. For auditor qualifications, look for ISO 13485-specific competency (not just generic ISO 9001 auditor training). Also verify that audit findings result in timely corrective action -- the audit program loses credibility when findings are not addressed. Finally, check that the audit procedure requires auditing against regulatory requirements in addition to ISO 13485.
Review the audit schedule for the last 2 complete cycles. Verify (1) all QMS processes were covered, (2) auditors were independent, (3) audits were completed on schedule, and (4) findings resulted in timely corrective action.
- What percentage of scheduled audits were actually completed in the last 2 cycles?
- How do you maintain auditor independence in a small organization with limited qualified auditors?
- What happens when an audit finding corrective action is overdue?
8.2.4 (Program) Is the audit program risk-based, with audit frequency and depth determined by process status, importance, and results of previous audits? Is there evidence that the program is adjusted when problems emerge, regulatory findings occur, or prior audits identify significant nonconformities?
- Risk-based audit program planning methodology -- verify it defines criteria for determining audit frequency and depth based on process risk, process importance, previous audit results, change history, and regulatory focus
- Audit program risk assessment or priority matrix showing how each QMS process was rated and how that rating translates to audit frequency (e.g., high-risk processes audited annually, low-risk processes every 2 years)
- Evidence of program adjustment based on previous audit results -- verify that a process with significant findings in the last audit was scheduled for follow-up or increased frequency in the current cycle
- Evidence of program adjustment based on external inputs -- verify that regulatory inspection findings, customer complaints, or industry recalls influenced audit program priorities
- Audit program review records showing the program is periodically reviewed and updated by management
- Audit schedule assigns identical frequency (annual) to all QMS processes regardless of risk; CAPA, complaint handling, and sterilization are audited at the same frequency as infrastructure, purchasing of office supplies, and document control of non-QMS documents
- Audit program has not been adjusted despite significant findings: the previous cycle identified a major nonconformity in design control, but the current cycle allocates the same audit duration and depth to design control as before the finding
- Risk criteria for audit planning exist in the procedure but were not actually applied; when asked to show the risk assessment behind the current schedule, the organization cannot produce documentation of how audit priorities were determined
- External inputs are not considered in audit planning; the organization received a regulatory action for complaint handling deficiencies but did not increase internal audit coverage of the complaint handling process
- Previous audit results show 5 repeat findings in purchasing over 3 consecutive cycles, but audit frequency and depth for purchasing remain unchanged -- the program is not responding to evidence of persistent noncompliance
A fixed annual schedule for all processes is not risk-based and does not meet this requirement. Ask the organization to show you the documented rationale for each process's audit frequency. Then test the system: identify a process that had significant findings in the last audit and verify the program was adjusted. Also check whether external events (regulatory findings, recalls, complaint spikes) triggered program changes. The best audit programs dynamically allocate more time and frequency to high-risk and troubled processes while reducing coverage of consistently compliant low-risk processes.
Compare the audit schedule for the current cycle to the previous cycle's findings. Verify that at least one process with significant prior findings received increased audit coverage (frequency, depth, or both).
- When was the last time you changed an audit frequency or scope based on new risk information?
- How do regulatory inspection findings influence your internal audit program?
- If a process receives a major finding, what is the automatic follow-up audit timeline?
8.2.4(a) Do internal audits verify conformance to all three categories: planned arrangements, ISO 13485 requirements, and the organization's own QMS requirements? Do audit checklists include process-specific questions based on internal procedures, not just generic ISO clause questions?
- 3 recent internal audit reports -- verify the scope statement for each audit explicitly references planned arrangements (quality plan, procedures), ISO 13485 clause requirements, and organization-specific QMS requirements
- Audit checklists used during the audits -- verify they include questions addressing ISO 13485 clauses, applicable regulatory requirements, and internal procedure requirements (not just ISO clauses)
- Evidence of audit against planned arrangements -- verify the auditor checked whether processes are operating as documented in procedures, quality plans, and work instructions
- Audit findings categorized by type: nonconformity against ISO 13485, nonconformity against internal procedure, nonconformity against planned arrangement, or observation
- Evidence that regulatory requirements applicable to the audited process were included in the audit scope
- Internal audit checklists consist entirely of generic ISO 13485 clause questions with no process-specific questions based on the organization's own procedures; auditors verify clause conformance but never check whether the organization is following its own detailed work instructions
- Audit of the manufacturing process checked ISO 13485 Section 7.5 requirements but did not verify conformance to the validated process parameters, in-process inspection plans, or production quality plans that define 'planned arrangements'
- No internal audit checklist includes regulatory requirements beyond ISO 13485; the organization is FDA-registered but internal audits do not verify compliance with 21 CFR 820-specific requirements that go beyond ISO 13485
- Audit reports document whether procedures exist but do not assess whether the procedures are actually being followed on the production floor -- implementation verification is missing from all 3 sampled audit reports
Internal audits must verify three things: (1) conformance to planned arrangements (are you doing what you said you would do?), (2) conformance to ISO 13485 requirements (do your practices meet the standard?), and (3) conformance to the organization's own QMS requirements (do you meet your own additional requirements?). Most internal audit programs are strong on #2 but weak on #1 and #3. Ask to see the audit checklist and check whether it includes questions specific to the organization's own procedures, not just generic ISO clauses.
Select 2 internal audit reports and compare the checklist questions to the organization's own procedures for the audited process. Verify that procedure-specific requirements were assessed, not just ISO clauses.
- How do your audit checklists incorporate requirements from your own procedures that go beyond ISO 13485?
- How do auditors verify that procedures are actually being followed, not just that they exist?
8.2.4(b) Do internal auditors verify effective QMS implementation through observation, interviews, and records review -- not just document existence? Do audit reports contain evidence of all three verification methods and findings that identify gaps between documented procedures and actual practice?
- Internal audit reports showing evidence of implementation verification -- verify auditors observed actual work practices (not just reviewed documents), interviewed personnel at the working level, and compared actual practices to documented procedures
- Audit evidence logs or notes showing the auditor's sampling methodology: which records were reviewed, which personnel were interviewed, which processes were observed in real-time
- Audit findings that cite a gap between documented procedures and actual practice -- this demonstrates the auditor was looking for implementation gaps, not just documentation gaps
- Interview records or notes from process operators confirming they were asked about their actual practices during the audit
- Audit program guidance or training materials that instruct auditors to verify implementation through observation and interviews, not just document review
- All 5 sampled internal audit reports consist exclusively of document reviews; there is no evidence that auditors observed work in progress, interviewed shop floor personnel, or compared documented procedures to actual practices
- Internal audit of the CAPA process reviewed 3 CAPA files for completeness but did not assess whether CAPAs were effective in preventing recurrence -- the audit verified documentation but not QMS effectiveness
- Auditor's notes for the production process audit show only document reference numbers reviewed; there are no records of process observations, operator interviews, or real-time verification of process controls
- Internal audit program does not include criteria for assessing 'effective implementation' -- auditors are trained to check for procedure existence and record completeness but not to evaluate whether the system is actually working
The difference between a document review and an audit is implementation verification. When reviewing internal audit reports, look for three types of evidence: (1) document review (did they check records?), (2) observation (did they watch processes?), and (3) interviews (did they talk to people doing the work?). An audit report that contains only document references and no evidence of observation or interviews is a desk review, not an audit. Also look for findings about gaps between documented practice and actual practice -- their absence may indicate the auditor was not checking implementation.
Review 3 internal audit reports and check each for evidence of all three verification methods: document review, process observation, and personnel interviews. Note which methods are present and which are absent.
- Can you show me an example where an internal auditor found a gap between a documented procedure and actual shop floor practice?
- How do your auditors verify that training is effective, not just that training records exist?
8.2.5 Are QMS processes monitored and measured with defined metrics, targets, and action triggers -- not just manufacturing processes but also quality processes (CAPA, complaints) and support processes (training, document control)? Is action taken when metrics fall below target?
- Process monitoring plan or KPI matrix showing metrics, targets, measurement methods, frequency, and responsible parties for each QMS process -- verify coverage extends beyond manufacturing to include quality and support processes
- Process performance data for 3 selected processes over the last 12 months -- verify data is actually being collected at the defined frequency and that trends are visible
- Evidence of action taken when a process metric fell below target -- verify the organization investigated the cause and took action (not just recorded the deviation)
- Process capability studies (Cpk/Ppk) for critical manufacturing processes -- verify capability meets defined minimums and is recalculated at appropriate intervals
- Management review records showing process performance data was presented and acted upon
- Examples of process improvements initiated based on monitoring data (not just responding to problems)
- Process monitoring covers manufacturing yield and inspection results but no metrics are defined for QMS support processes; document control turnaround time, training completion rates, CAPA cycle time, and supplier delivery performance are not measured
- CAPA process metric is 'number of open CAPAs' with no target and no trend analysis; the organization cannot demonstrate whether the CAPA process is achieving planned results (timely closure, effective root cause analysis, prevention of recurrence)
- Manufacturing process for critical dimension shows Cpk of 0.87 for 6 consecutive months, below the organization's minimum of 1.33; no corrective action or process improvement has been initiated despite the ongoing capability gap
- Process metrics are collected and reported monthly but the reporting is informational only -- there are no defined action triggers, no responsible parties for metric review, and no evidence that adverse trends have ever resulted in improvement actions
Most organizations can show manufacturing metrics. The real test is whether they monitor QMS support processes with equal rigor. Ask about CAPA cycle time, complaint investigation timeliness, training completion rates, document control response time, and internal audit completion rates. If these are not measured, the organization cannot demonstrate that these processes achieve planned results. Also look for action triggers -- metrics without defined thresholds and response plans are just data collection exercises, not process monitoring.
Request KPIs for one manufacturing process, one quality process (CAPA or complaints), and one support process (training or document control). Verify targets exist, data is current, and adverse trends triggered action.
- What happens when a process metric misses its target for 3 consecutive months?
- How do you determine whether your process metrics are measuring the right things -- outcomes versus activity?
- Can you show me a process that was improved based on monitoring data?
8.2.6 Are product monitoring and measurement activities defined at each stage of realization with acceptance criteria traceable to design outputs? Do Device History Records contain complete inspection results at each defined stage, and are out-of-specification results investigated rather than simply retested?
- Inspection and test plan for the highest-risk product family -- verify it defines inspection stages (incoming, in-process, final), characteristics tested at each stage, acceptance criteria traceable to design outputs, test methods, equipment, and sample sizes
- 3 Device History Records (DHRs) for recently manufactured lots -- verify each contains all required inspection and test results at each stage defined in the inspection plan
- Acceptance criteria documentation showing traceability from design output specifications to inspection plan acceptance criteria to actual test records
- In-process inspection records showing checkpoints are actually being performed at defined intervals (not just final inspection)
- Records of product monitoring equipment calibration -- verify measurement equipment used at each inspection stage is within calibration
- Out-of-specification investigation records from the last 6 months -- verify OOS results are investigated, not just repeated until a passing result is obtained
- Inspection plan for a Class III implant defines multiple in-process checkpoints, but DHR review reveals several were not performed for sampled lots -- in-process inspections were skipped with no documented justification or deviation
- Acceptance criteria for a critical biocompatibility characteristic state 'meets specification' without defining the numerical specification value; the inspector must cross-reference a separate design output document to determine the actual acceptance limit
- Final inspection records for sterile devices show product was released based on visual inspection only; the inspection plan requires sterility assurance but the DHR contains no reference to sterilization process records or parametric release data
- Three out-of-specification results in the last quarter were handled by retesting until a passing result was obtained; investigation records do not address the initial failing result or evaluate whether the product batch is affected
The DHR is the product's quality biography -- it must tell the complete story of how the product was made and verified. Pull 3 DHRs and compare each against the inspection plan. Check for skipped inspections, missing records, and acceptance criteria that are vague or not traceable to design outputs. Pay special attention to how out-of-specification results are handled -- retesting without investigation is a significant finding. Also verify that inspection personnel are qualified and that measurement equipment is calibrated.
Pull 3 DHRs from the last 30 days. For each, verify every inspection checkpoint in the inspection plan has a corresponding record in the DHR with documented acceptance criteria and results.
- How do you handle an out-of-specification result -- do you have a defined investigation procedure before retesting?
- How are acceptance criteria updated when design outputs change?
- Can you show me how your inspection plan maps to the design output specifications?
8.2.6 (Release) Is product release controlled by a defined procedure with authorized personnel, documented prerequisites, and a systematic verification that all planned activities are completed before release? Do release records demonstrate that all verifications preceded the release authorization?
- Product release procedure defining release prerequisites, authorized release personnel, release documentation requirements, and the process for handling incomplete verifications or conditional holds
- Release authorization matrix showing by name or role who is authorized to release product -- verify the matrix is current and includes training/qualification records for each authorized individual
- 5 recent release records -- verify each shows (1) all planned verifications were completed before release, (2) the releasing individual is on the authorization matrix, (3) acceptance criteria were met, and (4) the release is dated and signed
- Evidence of a release hold -- at least one instance where product was held pending completion of outstanding verifications, demonstrating the system actually prevents premature release
- Batch record review checklist or release checklist showing systematic verification that all planned activities are satisfactorily completed before authorization
- Release records for several sampled lots show product was released before environmental test results were available; the results were added to the DHR retroactively after release, and the final release signature pre-dates the test completion
- Release authorization is not restricted to specific individuals; any member of the quality team can release product, and there is no documented competency requirement or authorization matrix defining who has this authority
- Release checklist does not include verification of sterilization records, calibration status of test equipment, or component lot traceability -- the checklist covers only final inspection results and packaging verification
- Product released on 4 occasions before the associated nonconformity investigation was complete; investigation later determined the nonconformity affected the released product, requiring a field correction
- Electronic signatures on release records do not include a date/time stamp, making it impossible to verify that release authorization occurred after all verifications were complete
Product release is a gate that must not open prematurely. Pull release records and check timestamps: verify every verification (testing, inspection, review) was completed BEFORE the release signature. Look for retroactively added test results -- these indicate product was released before all verifications were complete. Also verify that release authority is restricted to qualified individuals. In production environments under schedule pressure, premature release is one of the most common findings.
Pull 5 release records from the last 60 days. For each, verify the timestamp of every verification activity precedes the release authorization timestamp. Flag any where the sequence is out of order.
- Has product ever been released before all verifications were complete? If so, how was it handled?
- How do you prevent release under production schedule pressure when test results are pending?
- What is your process when a verification fails after product has already been released to the next stage?
§8.3 Control of nonconforming product
8.3.1 Is there a documented procedure for control of nonconforming product covering identification, documentation, segregation, evaluation, and disposition? Are nonconforming material areas physically segregated and access-controlled, with all items identified and traceable to nonconformity reports?
- Nonconforming product SOP defining identification methods (labels, tags, electronic flags), documentation requirements, segregation procedures, evaluation criteria, disposition options, authority matrix, and record retention requirements
- Physical inspection of nonconforming material area(s) -- verify dedicated segregation area exists, is clearly identified, access-controlled, and that all items in the area are properly tagged and traceable to NCR numbers
- 5 recent nonconformity reports (NCRs) -- verify each contains: description of nonconformity, identification of affected product (lot/serial), quantity affected, immediate containment actions, root cause investigation, disposition decision with authority signature, and evidence of disposition completion
- Authority matrix showing who can make disposition decisions at each level (scrap, rework, use-as-is, return to supplier) and what approval levels are required
- Nonconforming product log or database showing all NCRs for the last 12 months with status, disposition, and closure date -- verify no NCRs remain open beyond the SOP-defined timeline without justification
- Nonconforming material area contains multiple items, but several have no NCR tags; unidentified items have no traceability to an NCR, making it impossible to determine their status, disposition, or how long they have been in segregation
- NCR for a critical implant component documents the nonconformity but has no containment action; the lot was partially distributed before the NCR was opened, and there is no evidence that shipped product was evaluated for the same defect
- Disposition authority matrix requires engineering manager approval for use-as-is decisions on safety-critical components, but several sampled use-as-is dispositions were approved by personnel without the required authority
- NCR database shows 23 open NCRs, 8 of which are more than 6 months old; the SOP requires disposition within 30 days but there is no escalation mechanism and management has not reviewed the backlog
- Nonconforming product segregation relies on a colored tag system, but tags are the same size and shape as production work order tags; two operators interviewed could not correctly identify which tag color indicates nonconforming status
Always visit the nonconforming material area physically. This is one of the highest-value activities in a medical device audit. Check that every item in the area is identified and traceable, that the area is access-controlled, and that items are not aging without disposition. Then pull 5 NCRs and trace them through the complete lifecycle. Key red flags: NCRs without containment actions (means affected product may be in the field), use-as-is dispositions without adequate risk justification, and NCRs that remain open for months without resolution.
Physically inspect the nonconforming material area and verify every item is identified and traceable. Then pull 5 NCRs: 1 rework, 1 scrap, 1 use-as-is, 1 return-to-supplier, and 1 currently open.
- How do you ensure all affected product is contained when a nonconformity is identified -- including product already shipped?
- What triggers a review of NCR aging to identify stalled dispositions?
- How do operators on the production floor identify and segregate nonconforming product during a shift?
8.3.1 (Evaluation) Are criteria defined for determining when a nonconformity requires investigation and when external parties (suppliers, customers, regulators) must be notified? Are decisions not to investigate documented with risk-based rationale and approved by authorized personnel?
- NCR evaluation procedure defining criteria for when a full investigation is required (e.g., safety-related, recurring, process capability issue) versus when simple correction is sufficient
- Criteria for determining when external parties must be notified -- including supplier notification for incoming material NC, customer notification for product already shipped, and regulatory notification for events meeting reporting thresholds
- 3 NCRs that triggered full investigation -- verify the investigation addressed root cause, extent of impact, and whether other lots/products are affected
- 2 NCRs closed without full investigation -- verify the rationale is documented, risk-based, and approved by an authorized individual
- Records of supplier notification for at least one incoming material nonconformity -- verify notification was timely and included specific defect information and corrective action expectations
- NCR evaluation procedure does not define criteria for when a full investigation is required; the decision is left to the judgment of the individual quality inspector with no documented criteria, resulting in inconsistent investigation triggers
- Supplier notification for incoming material nonconformities is inconsistent; some sampled incoming NCRs resulted in supplier notification while others did not -- with no documented rationale for why some suppliers were notified and others were not
- NCR for a labeling error was dispositioned as 'relabel and release' with no investigation into why the wrong labels were applied; similar labeling NCRs appear multiple times in recent months, indicating a recurring issue that has not been addressed through CAPA
- No procedure exists for evaluating whether customers need to be notified when a nonconformity is identified in product that has already been shipped; the evaluation focuses only on the product in-house
The evaluation step is where the organization decides how seriously to treat each nonconformity. Look for two extremes: organizations that investigate everything (creating CAPA backlog) and organizations that investigate nothing (missing systemic issues). The right approach uses defined criteria. Also check the notification element -- when incoming material fails, is the supplier notified? When the nonconformity may affect shipped product, is the customer notified? These external notification decisions are often overlooked.
Pull 5 NCRs for incoming material nonconformities. Verify each includes an evaluation for investigation need and supplier notification. Check for consistency in how the criteria are applied.
- How do you determine whether a nonconformity might affect product already in the field?
- When you notify a supplier of a nonconformity, what do you require them to do in response?
- How do you distinguish between a nonconformity that needs root cause investigation and one that can be addressed with simple correction?
8.3.1 (Records) Do nonconformity records document the nature of the nonconformity, affected product identification, evaluation, investigation results (if applicable), disposition decision with rationale, authorization, and evidence of disposition completion? Does the recording system support trending and analysis?
- 5 complete NCR records -- verify each documents: the nature and description of the nonconformity (what failed, against which requirement), affected product identification (lot/serial/quantity), evaluation of investigation need, investigation results if applicable, disposition decision, rationale for the decision, authorization, and evidence the disposition was carried out
- NCR record format or template -- verify it contains mandatory fields for all required information elements and does not allow closure without completing required sections
- NCR database or log with search and trending capability -- verify the records support analysis by nonconformity type, product, process, supplier, and time period
- Example of trend analysis produced from NCR records -- verify the organization is using NCR data to identify patterns and drive improvement
- Record retention evidence -- verify NCR records are retained for the required period (at least the lifetime of the device or as defined by regulatory requirements)
- NCR records describe the nonconformity as 'does not meet spec' without identifying which specification or what the actual measurement was versus the requirement -- the record is useless for trending or root cause analysis because the nonconformity is not specifically characterized
- Disposition rationale for several sampled NCRs consists solely of the word 'scrap' with no documentation of why scrap was chosen over rework, who authorized the decision, or whether the nonconformity warranted investigation
- NCR records are maintained in a paper-based system with no indexing or search capability; the organization cannot produce a list of NCRs by nonconformity type, product, or process area -- making trend analysis impossible
- NCR database shows disposition decisions but no evidence that dispositions were actually carried out; 3 NCRs with 'scrap' disposition have no scrap verification records (witness signatures, destruction records)
Records are the evidence trail. Read 5 NCR records critically: can you understand what went wrong, why, what was decided, and whether it was done? If any of those questions cannot be answered from the record alone, the documentation is insufficient. Also test whether the recording system supports trending -- if records cannot be searched and analyzed by type, product, and process, the organization cannot identify patterns. The rationale for disposition decisions is particularly important for medical devices where patient safety is at stake.
Pull 5 NCRs and evaluate each for completeness against the required elements: nonconformity description, affected product ID, evaluation, investigation (if applicable), disposition rationale, authorization, and evidence of completion.
- Can you run a query showing all NCRs for a specific component type over the last 24 months?
- How do you verify that scrap dispositions were actually carried out?
- Who reviews NCR records for completeness before closure?
8.3.2 Are disposition options (correction, use-as-is, reject/scrap, return to supplier) defined with criteria, required approvals, and an authority matrix? Are use-as-is/concession decisions supported by documented risk assessments evaluating the effect on device safety, performance, and regulatory compliance?
- Nonconforming product disposition procedure defining available disposition options (correct/rework, use-as-is/concession, reject/scrap, return to supplier), criteria for selecting each option, required approvals, and restrictions for medical devices
- Disposition authority matrix showing who can authorize each type of disposition, with escalation requirements for safety-critical decisions
- Examples of each disposition type used in the last 12 months -- at least 1 rework, 1 scrap, 1 return to supplier, and 1 use-as-is/concession
- Use-as-is/concession records with full risk justification, regulatory impact assessment, and evidence that concession does not compromise product safety or regulatory compliance
- Disposition completion records showing each disposition was carried out as decided (rework records, scrap records, return-to-supplier records)
- Use-as-is dispositions for 4 NCRs in the last year reference 'engineering judgment' as the sole justification, with no documented risk assessment evaluating the effect of the nonconformity on device safety, performance, or regulatory compliance
- Disposition procedure does not restrict use-as-is decisions for safety-critical nonconformities; the same approval level is required whether the nonconformity affects a cosmetic feature or a life-sustaining function
- Return-to-supplier disposition for critical raw material was executed, but no record shows the nonconforming material was actually removed from the facility; follow-up reveals the material remained in the warehouse for several months after the disposition decision
- No disposition tracking system exists; the organization can show the disposition decision in the NCR but cannot verify whether the disposition was actually carried out for several sampled records
Focus heavily on use-as-is and concession dispositions. In the medical device industry, accepting nonconforming product requires rigorous risk justification because patient safety is at stake. Look for concession decisions that reference 'engineering judgment' without a documented risk assessment -- this is insufficient for regulated products. Also verify that all dispositions are actually executed: a scrap decision means nothing if the product remains in the warehouse. Physically verify disposition completion for at least 2 NCRs.
Pull all use-as-is/concession dispositions from the last 12 months. Review the risk justification for each. Verify at least 2 physically: is the product actually in use as decided?
- For use-as-is dispositions, is a formal risk assessment always performed? Who reviews it?
- How do you track that dispositions are actually completed -- not just decided?
- Are there any regulatory restrictions on your ability to accept nonconforming product as use-as-is?
8.3.2(a) Is rework authorized in advance, carried out by trained staff against specific written instructions, and fully re-checked against the original acceptance criteria, with the rework's potential effect on other product characteristics assessed before it proceeds?
- Rework/correction procedure defining how rework is authorized, documented, performed, and verified -- verify it requires rework instructions, trained personnel, and reverification against original acceptance criteria
- 3 rework records -- verify each includes: authorization for rework, specific rework instructions (not generic), identification of personnel who performed the rework, reverification results against acceptance criteria, and release authorization
- Rework instructions or work orders showing specific steps to eliminate the nonconformity -- verify they are clear enough for the operator to follow and include quality checkpoints
- Reverification records after rework -- verify the same acceptance criteria used for original acceptance were applied, not relaxed criteria
- Adverse effect evaluation for each rework -- verify the potential impact of the rework on other product characteristics was considered
- Rework was performed based on verbal instructions from the production supervisor; no documented rework instructions exist, and the operator who performed the rework could not describe the specific steps they were told to follow
- Reverification after rework of a precision machined component checked only the characteristic that was out of specification; other critical dimensions that could have been affected by the rework operation were not remeasured
- Rework of a sterile device packaging seal was performed in the production area rather than in the cleanroom where original sealing occurs; the rework procedure does not address environmental requirements for rework operations
- Three rework records show the same operator authorized the rework, performed the rework, and signed off on reverification -- there is no separation of duties or independent verification
Rework in medical device manufacturing carries risk because the additional processing could introduce new defects or compromise other characteristics. Key things to verify: (1) were rework instructions documented and specific (not just 'fix it'), (2) was the adverse effect of rework evaluated before it was performed, (3) was the full reverification performed (not just the failed characteristic), and (4) was the reverification performed by someone independent of the person who did the rework.
Pull 3 rework records from the last 6 months. For each, verify rework instructions were documented, reverification included all potentially affected characteristics, and an adverse effect evaluation was performed.
- How do you determine whether rework might adversely affect other product characteristics?
- Is there a limit on how many times a product can be reworked?
- How are rework activities tracked for trending -- is recurring rework of the same type flagged for investigation?
8.3.2(b) Are use-as-is/concession dispositions supported by risk assessments per ISO 14971 methodology, with consideration of customer and regulatory notification requirements? Is the concession rate tracked to identify whether it masks underlying process capability issues?
- All use-as-is/concession records from the last 12 months -- count them and calculate as a percentage of total dispositions to assess whether this is a routine practice
- Risk assessment for each concession -- verify it specifically evaluates the effect of the nonconformity on device safety, performance, and regulatory compliance using the organization's risk management methodology (ISO 14971)
- Customer or regulatory notification records where applicable -- verify the organization considered whether concession requires customer approval or regulatory notification
- Authorization records showing concessions were approved at the appropriate level per the authority matrix -- verify higher risk concessions received higher level approval
- Trending of use-as-is dispositions by product, nonconformity type, and frequency -- verify the organization monitors whether concession is being used to avoid addressing underlying process capability issues
- Use-as-is dispositions account for 35% of all NC dispositions over the last 12 months, but the organization has not investigated whether this high rate indicates underlying process capability problems that should be addressed through corrective action
- Risk assessment for a dimensional nonconformity on an orthopedic implant states 'minor deviation within functional tolerance' but provides no supporting data: no comparison to design output tolerance, no stress analysis, no clinical impact assessment
- Concession for a Class III device component was approved without notified body notification or customer notification; the procedure does not address when concessions for regulated products require external notification
- Same dimensional nonconformity has been accepted via use-as-is concession 7 times in the last year; each concession is evaluated individually but the pattern has never been reviewed collectively to determine whether the process specification or tooling needs correction
Use-as-is is the highest-risk disposition option in medical device manufacturing. The risk justification must be thorough -- 'engineering judgment' without a documented risk assessment is never sufficient. Track the use-as-is rate: if it exceeds 10-15% of total dispositions, the organization may be using concessions to avoid fixing process problems. Also look for repeat concessions -- the same nonconformity accepted as use-as-is multiple times indicates the organization is tolerating a process capability issue rather than correcting it. Under EU MDR, concessions for safety-critical characteristics may require notified body involvement.
Pull all use-as-is dispositions from the last 12 months. Calculate the concession rate. Identify any characteristic with more than 2 concessions and verify whether the underlying process issue has been addressed.
- What is your use-as-is rate as a percentage of total dispositions, and do you track this?
- Can you show me a concession request that was denied? What was the rationale?
- For repeat concessions on the same characteristic, at what point do you investigate the underlying process?
8.3.2(c) Is there a documented scrap/disposal procedure that ensures nonconforming product is rendered physically unusable, with witnessed destruction, documented records, and serialized inventory reconciliation? Are environmental disposal requirements addressed?
- Scrap/disposal procedure defining how nonconforming product is rendered unusable, who witnesses destruction, how destruction is documented, and environmental disposal requirements
- 5 scrap/destruction records -- verify each documents: the product identified and quantity destroyed, the method of destruction (shredding, incineration, deformation), witness signature, date of destruction, and disposal of waste
- Physical inspection of the scrap area -- verify scrapped product is rendered physically unusable (not just labeled 'scrap' but otherwise intact and usable)
- Environmental compliance records for disposal of hazardous or regulated materials (if applicable)
- Evidence that serialized or lot-tracked scrap is recorded in the inventory system to prevent accidentally shipping scrapped product
- Scrapped medical devices are placed in an open waste bin in the production area without being rendered unusable; intact devices labeled 'scrap' could be retrieved from the bin and used, creating a risk of nonconforming product re-entering the supply chain
- No witness requirement for destruction of nonconforming product; the operator who places product in the scrap bin is the same person who logs the destruction -- no independent verification that the product was actually destroyed
- Scrap records consist of a log entry showing the product was scrapped with a quantity but no identification of which specific lots or serial numbers were destroyed, making inventory reconciliation impossible
- Scrapped product containing hazardous materials (batteries, chemicals) is disposed of in general waste without environmental compliance evaluation
Visit the scrap area and look at what is in it. Intact medical devices labeled 'scrap' but not physically rendered unusable are a significant finding -- they could be retrieved and used. Effective scrap processes include physical destruction (cutting, crushing, shredding) before disposal, witnessed by a second person. Also verify that serialized products are removed from inventory when scrapped, and that disposal complies with environmental regulations for the materials involved.
Visit the scrap area. Inspect 3 items to verify they have been rendered physically unusable. Then pull the corresponding scrap records and verify documentation is complete.
- How do you physically render scrapped medical devices unusable?
- How do you reconcile inventory when product is scrapped?
- Who has access to the scrap area, and is access controlled?
8.3.3 Is there a documented procedure for handling nonconforming product discovered after delivery or during use? Do field action records demonstrate timely risk assessment, scope determination, regulatory and customer notification, and effectiveness verification?
- Post-delivery nonconforming product procedure including Field Safety Corrective Action (FSCA) procedure, recall procedure, and advisory notice procedure -- verify it addresses risk assessment, scope determination, customer/user notification, regulatory notification, effectiveness checks, and root cause investigation
- Records of the last 2 field actions -- verify each includes: risk assessment of effects or potential effects, scope determination (which lots, serial numbers, distribution), regulatory notifications filed, customer notifications sent, effectiveness of the action verified
- Risk assessment records for post-delivery nonconformities showing how the organization evaluated actual and potential effects on patients, users, and third parties
- Distribution records used to determine the scope of affected product in the field
- Effectiveness check records showing the organization verified that the field action achieved its objective (product returned, corrected, users notified)
- Organization identified a software defect in a field-deployed diagnostic device that can produce false negative results under specific conditions, but assessed the risk as 'low' based on the probability of the conditions occurring -- the severity of a missed diagnosis was not adequately considered in the risk assessment
- Field Safety Corrective Action was initiated but effectiveness check shows a minority of affected customers acknowledged the notice; the organization has no procedure for following up with non-responsive customers
- Post-delivery nonconformity was identified but the field action has not yet been initiated because the organization is still determining root cause; meanwhile, affected devices remain in clinical use with no interim risk communication to users
- Distribution records are incomplete: the organization can identify which distributors received affected product but cannot trace to the end-user level, limiting the effectiveness of the recall notification
Post-delivery nonconforming product is where patient safety risk is highest because the product is already in use. The key test is whether the organization's response was proportionate to the risk. Look for delays between identification and action -- if the risk assessment takes months while affected product remains in clinical use, the process is failing. Also check effectiveness: a recall or FSCA that reaches a minority of affected customers is not effective. Distribution traceability is often the bottleneck -- verify the organization can trace product to at least the customer level.
Pull the last 2 field actions (recalls, FSCAs, or advisory notices). For each, verify the timeline from discovery to action, the risk assessment, the scope determination, and the effectiveness verification.
- How quickly can you identify all affected customers when a post-delivery nonconformity is discovered?
- What is your threshold for initiating a recall versus an advisory notice?
- How do you handle non-responsive customers during a recall or FSCA?
8.3.3 (Records) Are field action records complete, including triggering event, investigation, risk assessment, decision record, regulatory notifications, customer notifications, product tracking, effectiveness verification, and linked CAPA? Do timelines demonstrate regulatory notification requirements were met?
- Complete field action file for the most recent recall, FSCA, or advisory -- verify it contains: triggering event, initial investigation, risk assessment, decision record, scope determination, regulatory notifications (with submission dates and agency acknowledgments), customer notification letters, product tracking records, return/correction logs, effectiveness verification, and CAPA reference
- Timeline reconstruction showing dates of each action from initial awareness through final closure -- verify regulatory notification timelines were met
- Regulatory agency correspondence including acknowledgments, questions, and the organization's responses
- Root cause investigation and CAPA record linked to the field action -- verify the CAPA addresses the root cause and not just the immediate correction
- Lessons learned or post-action review documenting what went well and what could be improved in the field action process
- Field action file is missing the effectiveness verification record; the recall was initiated months ago but there is no documented assessment of whether the recall achieved its objective (e.g., percentage of affected devices returned or corrected)
- No CAPA was initiated in connection with the field action; the immediate correction (product replacement) was completed but the root cause was never investigated to prevent recurrence
- Regulatory notification was filed 47 days after the decision to initiate the field action, exceeding the applicable regulatory timeline; the delay is not explained in the records
- Records do not demonstrate that the scope of the field action was correct; there is no distribution review showing how affected lots/serial numbers were identified, raising the question of whether all affected product was captured
A field action file should tell the complete story from trigger to closure. Read it as a narrative: does it make sense? Can you follow the logic from the triggering event through the risk assessment to the action taken? Look for gaps in the timeline and missing records. The most common omissions are effectiveness verification (was the action successful?) and CAPA linkage (was the root cause addressed?). If the organization has never conducted a field action, verify they have a procedure and have tested it through a mock recall exercise.
If the organization has conducted a field action, review the complete file. If not, request evidence of a mock recall exercise and evaluate its adequacy.
- If you have never conducted a field action, have you performed a mock recall to test your procedure?
- How do you determine when a field action can be closed -- what are the closure criteria?
- How are lessons from field actions incorporated into your product development process to prevent similar issues in future designs?
8.3.4 Is there a documented rework procedure that defines permissibility criteria, adverse effect evaluation requirements, specific rework instructions, reverification requirements, and approval authorities? Are adverse effects evaluated before rework is authorized, and is rework frequency trended?
- Rework SOP defining rework permissibility criteria (when rework is allowed vs. prohibited), adverse effect evaluation requirements, documentation requirements, reverification requirements, and approval authorities
- 3 rework records with complete adverse effect evaluations -- verify each evaluation considers the impact of the rework process on product safety, performance, biocompatibility, sterility, dimensional integrity, material properties, and any other relevant characteristics
- Rework instructions or work orders showing step-by-step rework procedures specific to the nonconformity and product -- verify they are detailed enough for the operator to follow
- Reverification records after rework showing the product was tested against original acceptance criteria (not relaxed criteria) for all characteristics potentially affected by the rework
- Rework trending data showing the organization monitors rework frequency by product, nonconformity type, and root cause to identify systemic issues
- Rework procedure does not include an adverse effect evaluation requirement; rework is authorized based on whether the nonconformity can be corrected, without assessing whether the rework process itself could introduce new defects or compromise other characteristics
- Adverse effect evaluation for rework of a heat-sealed sterile package states 'no adverse effect expected' without evaluating the impact of reheating on seal integrity, package material properties, or sterility assurance
- Rework instructions are generic ('rework per standard procedure') with no specific steps for the particular nonconformity; operators interpret 'standard procedure' differently, resulting in inconsistent rework execution
- Same nonconformity type (surface finish out-of-spec on a critical implant component) has been reworked 12 times in 6 months, indicating a process capability issue that is being managed through repeated rework rather than corrective action
Rework is often treated as routine in manufacturing, but for medical devices it requires careful evaluation. The key question is: does the rework process itself introduce risk? A second heat cycle on a sterile package, additional machining on a precision component, or re-soldering on an electronic assembly can all introduce adverse effects that are not present in the original manufacturing process. Verify that adverse effects are evaluated BEFORE rework is performed, not after. Also look for chronic rework -- if the same product and nonconformity are repeatedly reworked, the organization has a process capability problem that should be addressed through CAPA, not managed through ongoing rework.
Pull 3 rework records including the adverse effect evaluation. Verify each evaluation was performed before rework was executed and that it addressed all potentially affected product characteristics.
- Are there any products or nonconformity types for which rework is prohibited?
- How do you ensure the rework process itself has been validated when it differs from the original manufacturing process?
- At what rework frequency for a given product do you escalate to CAPA?
8.3.4 Is rework performed in accordance with documented procedures? Do rework records demonstrate that adverse effect evaluations, supervisory approvals, and appropriate equipment/environment were in place before rework execution, and that trained personnel performed the work?
- 3 rework records compared side-by-side with the rework procedure requirements -- verify each step in the procedure was followed and documented
- Training records for personnel who performed the rework -- verify they are trained on the rework procedure and, where applicable, on the specific rework operation they performed
- Adverse effect evaluations dated before the rework execution date -- verify the evaluation was completed before rework began, not documented retroactively
- In-process and post-rework verification records -- verify rework quality checkpoints were performed as required by the procedure
- Rework records showing the correct equipment, materials, and environment were used for the rework operation
- Adverse effect evaluation for rework is dated after the rework execution date -- the evaluation was completed after the rework, not before, defeating the purpose of evaluating potential adverse effects prior to rework execution (Major NC)
- Rework procedure requires supervisory approval before rework begins, but several sampled rework records show the supervisor's approval signature was added after the rework was complete, indicating the approval is retrospective rather than prospective
- Personnel performing rework on a Class III device component have no documented training on the specific rework operation; their training records show general manufacturing training but not rework-specific competency
- Rework was performed in the general production area using standard production tooling; the rework procedure specifies that rework on this component type requires calibrated precision fixtures that were not used
Compare paper to practice. Pull rework records and check whether the documented sequence matches the procedure. Key sequence checks: (1) adverse effect evaluation dated before rework execution, (2) supervisory approval dated before rework execution, (3) rework performed by trained personnel, (4) correct equipment and environment used. These timing and compliance checks reveal whether the rework process is controlled or just documented after the fact.
Pull 3 rework records and verify the chronological sequence: adverse effect evaluation, authorization, rework execution, reverification. Flag any where the sequence is out of order.
- How do you verify that the rework operation was performed correctly during the rework -- not just after the fact?
- What quality controls are in place during rework operations?
- How do you ensure rework is performed in the correct environment (cleanroom, ESD, temperature, etc.)?
8.3.4 Is reworked product reverified against original acceptance criteria (not relaxed criteria)? Does the reverification scope cover all characteristics potentially affected by the rework, and is reverification performed by qualified personnel independent of those who performed the rework?
- 3 reverification records after rework -- verify the acceptance criteria are identical to the original production acceptance criteria (not relaxed or modified)
- Reverification scope documentation showing which characteristics were tested after rework and the rationale for the scope -- verify all characteristics potentially affected by the rework were included, not just the characteristic that was originally nonconforming
- Calibration records for test equipment used during reverification -- verify equipment was within calibration at the time of reverification
- Reverification performed by qualified personnel independent of the person who performed the rework
- Release records showing reworked product was only released after reverification confirmed conformity to all applicable acceptance criteria
- Reverification after rework of a dimensional nonconformity checked only the reworked dimension; three other critical dimensions that could have been affected by the machining rework were not remeasured, creating risk of an undetected out-of-spec condition
- Reverification acceptance criteria for a reworked component were relaxed from the original specification: original spec required surface roughness Ra 0.4, but reverification accepted Ra 0.8 with no documented justification or engineering change order
- Reverification was performed by the same operator who performed the rework; no independent verification by quality or a different qualified individual
- Reworked sterile product was reverified for dimensional conformity but was not revalidated for sterility assurance after the package was opened and resealed during rework
Reverification must be against the original acceptance criteria -- not relaxed criteria. The most common gap is insufficient reverification scope: the organization retests the failed characteristic but does not test other characteristics that could have been affected by the rework process. For example, if a dimension was corrected by additional machining, surface finish and adjacent dimensions could also be affected and should be re-checked. Also verify that reverification personnel are independent of the rework operator.
Pull 3 rework records with reverification results. Compare reverification acceptance criteria to original acceptance criteria. Verify the reverification scope covers all characteristics potentially affected by the rework.
- How do you determine the reverification scope -- which characteristics to test after rework?
- Has a reworked product ever failed reverification? What happened?
- Are reverification criteria ever different from original acceptance criteria? Under what circumstances?
§8.4 Analysis of data
8.4 Is there a documented data analysis procedure? Are analysis reports produced at defined intervals covering all required data sources, and do they contain actual analysis (trends, patterns, conclusions, recommendations) rather than raw data summaries?
- Data analysis SOP defining data sources, collection methods, analysis methods (including statistical techniques where applicable), analysis frequency, responsible parties, and how results are communicated and acted upon
- Data analysis reports from the last 12 months -- verify reports cover all six required areas (feedback, product conformity, process/product trends, suppliers, audits, service reports) and include actual analysis (not just data dumps)
- Evidence that analysis reports include conclusions and recommendations -- not just charts and tables but interpretation of what the data means and what actions are needed
- Management review records showing data analysis results were presented and specific improvement actions were assigned based on the analysis
- Training records or qualifications for personnel who perform data analysis -- verify they have competency in the analytical and statistical methods they use
- Data analysis consists of monthly reports showing raw counts (number of complaints, number of NCRs, number of CAPAs) with no trend analysis, statistical evaluation, or comparison to targets -- the reports present data but do not analyze it
- Data analysis reports are generated by quality but are not presented to management or used as inputs to management review; there is no mechanism to translate analysis findings into improvement actions
- Analysis is performed for complaint data and product conformity data, but no analysis is performed for supplier performance data, audit results, or service reports despite the standard requiring analysis in all six areas
- One annual quality report covers all data analysis requirements; it is produced 3 months after year-end, meaning negative trends are not identified for up to 15 months after they begin
The difference between data reporting and data analysis is interpretation. A bar chart showing complaint counts by month is reporting. That same chart with trend line analysis, comparison to prior year, identification of outlier months, root cause categorization, and recommended actions is analysis. Ask to see the analysis outputs and evaluate whether they contain actionable conclusions. Also check timing -- if analysis is done only annually, the organization is missing actionable signals in the interim. Best practice is quarterly analysis with monthly monitoring of key indicators.
Request the most recent data analysis report covering all six required areas. Evaluate each section for actual analysis (trends, patterns, conclusions, recommendations) versus raw data presentation.
- How often do you perform formal data analysis, and who decides the frequency is appropriate?
- Can you show me an example where a data analysis finding directly led to a CAPA or process improvement?
- How do you validate that your analysis methods are appropriate for the data being analyzed?
8.4 (Data) Are data collected from both internal sources (complaints, inspections, audits, CAPA, process metrics, supplier data, service data) and external sources (regulatory databases, industry benchmarks, literature, competitor recalls)? Is cross-functional data integrated for holistic analysis?
- Data source inventory showing all internal sources (complaint data, inspection data, audit findings, CAPA data, process metrics, supplier data, service data) and external sources (regulatory databases, industry benchmarks, literature, competitor recalls, standards updates)
- Evidence of external data integration -- verify the organization monitors at least one external data source (MAUDE, EUDAMED, FDA recall database, industry publications) and incorporates findings into their analysis
- Data collection procedures showing how data from each source is captured, validated, and made available for analysis
- Cross-functional data integration -- verify that data from different departments (quality, manufacturing, service, regulatory) is brought together for holistic analysis rather than analyzed in silos
- Data quality records showing how the organization ensures data accuracy and completeness before analysis
- Data analysis relies exclusively on internal data sources; the organization does not monitor FDA MAUDE database, competitor recalls, published literature, or industry benchmarking data that could provide early warning of emerging issues
- Manufacturing yield data, service call data, and complaint data are collected by different departments using different systems; no mechanism exists to combine these data sources for holistic analysis, resulting in missed correlations (e.g., a process change that improves yield but increases field failures)
- Data from outsourced processes (sterilization, testing, calibration) is not integrated into the organization's data analysis; contractor-provided data is filed but never analyzed
- No data validation process exists; analysis reports use raw database queries without verification, resulting in known data quality issues (duplicate records, miscategorized complaints) affecting analysis accuracy
Good data analysis requires good data inputs. Check whether the organization is drawing from all relevant sources or just the most convenient ones. External data sources are frequently neglected but are increasingly important for post-market surveillance under EU MDR. Also check for data silos: if manufacturing, quality, service, and regulatory each analyze their own data independently, the organization is missing cross-functional insights. The most valuable analysis often comes from combining data sources that normally live in different departments.
Request a list of all data sources feeding into the quality data analysis program. Verify at least 2 external sources are included and that data from at least 3 internal departments is integrated.
- Do you monitor the FDA MAUDE database or EU vigilance databases for events involving similar devices?
- How do you ensure data from different systems is compatible for combined analysis?
- What external benchmarking data do you use to contextualize your internal quality metrics?
8.4 (Output) Does the data analysis program produce outputs covering all six required areas: feedback, product conformity, process and product trends, suppliers, audits, and service reports? Does each analysis output contain actionable conclusions and recommendations?
- Analysis outputs covering all six required areas with the most recent analysis report for each -- verify each area has been analyzed within the last 12 months (or more frequently per the organization's schedule)
- Feedback analysis: complaint trends by type, product, severity; satisfaction scores; post-market surveillance findings
- Product conformity analysis: inspection yield, first-pass rates, defect Pareto, out-of-specification trends
- Process/product trends: SPC charts, capability indices, trend projections, predictive indicators
- Supplier analysis: scorecards, quality trends, delivery performance, audit results
- Audit analysis: finding trends, systemic issues, repeat findings, corrective action effectiveness
- Service report analysis: failure modes, service call trends, reliability data (if applicable)
- Analysis outputs cover only a subset of the required areas; several required data sources (such as process trends, audit results, or service reports) have no documented analysis
- Service report analysis is marked 'not applicable' because the organization states it does not provide service; however, the organization performs installation, calibration, and warranty repairs which constitute service activities whose data should be analyzed
- Audit analysis consists of counting the number of findings per audit cycle with no categorization, trend analysis, or identification of systemic issues; the analysis does not distinguish between repeat findings and new findings
- Analysis outputs are produced but remain in the quality department; they are not distributed to process owners or presented at management review, limiting the organizational value of the analysis
Count the six required areas and verify each is covered. The most commonly missed areas are service reports (organizations claim 'not applicable' when they actually provide installation, training, or warranty service), audit results (analysis often limited to counting findings), and process/product trends (organizations report current status but do not analyze trends over time). For each area, evaluate whether the analysis provides actionable information or is just a data summary.
Request the most recent analysis output for each of the six required areas. Verify each contains actual analysis (trends, patterns, conclusions) and is dated within the expected analysis cycle.
- For each of the six analysis areas, who is responsible for performing the analysis and at what frequency?
- Can you show me a specific action that was taken as a direct result of one of these analyses?
- How do you define 'service reports' for your organization, and what data is collected from service activities?
8.4 (Records) Are data analysis activities and resulting actions documented with a traceable chain from analysis finding to decision to action to verified result? Are analysis records maintained in the controlled document system and presented as inputs to management review?
- Data analysis records including analysis reports, meeting minutes from review sessions, and documented conclusions with supporting evidence for each conclusion
- Action records linked to analysis findings -- verify each action references the specific analysis finding that triggered it, with assigned owner, due date, and current status
- 3 complete chains from analysis finding to action to result -- verify the organization can demonstrate a clear trail: (1) analysis identified the issue, (2) action was determined and assigned, (3) action was implemented, (4) result was verified
- Management review records showing data analysis results were an input and specific actions were an output
- Record retention evidence showing analysis records are maintained for the required period and are retrievable for regulatory review
- Data analysis is performed and documented, but there is no formal mechanism to assign improvement actions from the analysis; findings are presented in reports but not tracked as action items with owners and due dates
- Management review minutes show data analysis was discussed, but the minutes do not document specific decisions or actions taken based on the analysis -- the analysis is received but not acted upon
- Three improvement projects were initiated based on data analysis, but only the most recent one has records showing the result; the other two were implemented but effectiveness was never documented
- Data analysis records are stored in individual analysts' personal files rather than in the controlled document system; when the quality analyst left the organization, 18 months of analysis records could not be located
This clause closes the loop: analysis must produce records, and actions must produce records. The most common gap is the missing link between analysis and action. Ask the organization to show you 3 examples of the complete chain: data analysis report showing a finding, the action assigned, the action implemented, and the result measured. If they cannot produce this chain, the data analysis program is not driving improvement. Also check that analysis records are maintained in the controlled document system, not in personal files.
Request 3 improvement actions initiated from data analysis in the last 12 months. For each, trace the complete chain: analysis finding, action assignment, implementation evidence, and effectiveness verification.
- How are improvement actions from data analysis tracked to completion?
- Where are data analysis records stored, and who is responsible for their retention?
- How do you verify that actions taken based on data analysis actually improved the metric that triggered the action?
8.4(a) Is feedback data analyzed with trend analysis over at least 12 months, including complaint rates by type, product, and severity? Are rates normalized for volume, and do identified patterns trigger improvement actions such as CAPA or design reviews?
- Complaint trend analysis for the last 12-24 months showing complaints by type (malfunction, injury, performance, labeling), product family, and severity -- with trend lines and identification of significant changes
- Normalized complaint rates (complaints per 1000 units sold or per device-years in use) to distinguish real increases from volume-driven increases
- Pareto analysis of complaint types showing the vital few categories driving the majority of complaints
- Actions initiated from feedback analysis -- verify at least one CAPA, design change, or process improvement was initiated based on trend analysis (not just individual complaint response)
- Post-market surveillance analysis integrating complaint data with other feedback sources (returns, service, surveys) for a holistic view of customer experience
- Complaint analysis shows a 25% increase in complaint rate over 12 months, but the analysis does not normalize for the 40% increase in units sold during the same period; the actual complaint rate per unit shipped decreased, but the raw count increase triggered unnecessary alarm
- Feedback analysis is limited to complaints; customer satisfaction survey results, service call data, and return data are collected by other departments but not integrated into the feedback analysis
- Complaint trend analysis identifies 'connector failure' as the #1 complaint type for 3 consecutive quarters, but no CAPA or design review has been initiated -- the analysis identifies the pattern but does not trigger action
- Analysis uses monthly complaint counts only; no Pareto analysis, no categorization by root cause type, no comparison to prior year, and no identification of statistically significant trend changes
Effective feedback analysis goes beyond counting complaints. Look for normalized rates, Pareto analysis, root cause categorization, trend detection with statistical significance, and comparison to benchmarks or targets. The critical test is whether the analysis triggers action: if the same top-3 complaint types appear quarter after quarter without improvement actions, the analysis is not serving its purpose. Also check whether feedback from all channels (not just complaints) is integrated into the analysis.
Request the feedback analysis report for the last 12 months. Verify it includes trend analysis, root cause categorization, normalization for volume, and documented actions taken based on findings.
- How do you define a statistically significant change in complaint rate?
- Are complaint rates benchmarked against industry data or your own targets?
- When a feedback trend is identified, what is the trigger for initiating CAPA versus monitoring?
8.4(b) Is product conformity data analyzed including first-pass yield, defect rates, and defect Pareto by product line with trend data over time? Is process capability tracked for critical characteristics, and do top defect contributors trigger corrective action?
- Product conformity analysis report showing first-pass yield, final yield, defect rates, and reject rates by product line over at least 12 months -- with trend analysis and identification of significant changes
- Defect Pareto analysis showing top defect categories by product family and the contribution of each to overall nonconformity rate
- Process capability data (Cpk/Ppk) for critical product characteristics -- verify capability is tracked over time and not just a one-time study
- Improvement actions initiated based on conformity analysis -- verify at least one process improvement or CAPA was triggered by conformity trend data
- Comparison of current conformity performance to targets or historical baselines showing whether the organization is improving, stable, or declining
- Product conformity analysis reports only final inspection pass/fail rates; in-process rejection data, rework rates, and scrap rates are not included in the analysis, obscuring the true cost of quality and missing early indicators of emerging problems
- No process capability studies are performed; the organization relies on 100% inspection to catch nonconformities rather than demonstrating process capability through statistical evidence
- Defect analysis shows the same top-3 defect types for 4 consecutive quarters with no improvement; the data is analyzed and reported but the top contributors are not being addressed through corrective action
- Conformity analysis is performed only for the highest-volume product; 3 lower-volume product lines have no conformity analysis despite having higher defect rates
Product conformity analysis should tell you whether the manufacturing system is capable and stable. Look for trend data over time -- not just the current month's yield. Check whether the analysis includes all product lines or only the ones where performance looks good. Also look for the connection between analysis and action: if the top defect type has been the same for over a year without improvement, the analysis is not driving change.
Request conformity data for 2 product lines over 12 months. Verify trend analysis is performed, top defect types are identified, and improvement actions have been taken for the top contributors.
- What is your in-process rejection rate versus your final inspection rejection rate, and what does the difference tell you?
- How do you track the cost of quality associated with nonconformities, scrap, and rework?
- At what defect rate threshold do you initiate corrective action?
8.4(c) Are process and product characteristics trended over time with control limits or statistical methods to distinguish normal variation from significant shifts? Are improvement opportunities identified from trend analysis, and is process capability monitored and acted upon when it degrades?
- Trend charts for critical process parameters over at least 12 months -- verify charts include control limits, trend identification, and annotation of significant shifts or out-of-control conditions
- SPC implementation evidence for at least one critical process -- verify control charts with calculated control limits (not specification limits), run rules, and evidence of operator response to signals
- Improvement opportunities identified from trend analysis -- verify specific opportunities were documented and acted upon (not just observed)
- Process capability trend data showing Cpk/Ppk over time for critical characteristics -- verify capability is monitored regularly and actions are taken when capability degrades
- Product trend analysis including field performance data (complaint rates, failure rates, reliability data) correlated with process and design changes
- Process monitoring consists of pass/fail results at each inspection checkpoint with no trending of actual measurement values; a critical dimension measured at 9.95mm, 9.97mm, 9.98mm, and 9.99mm against a 10.0mm upper limit shows a clear trend toward the limit, but the organization only sees 4 consecutive 'pass' results
- Organization claims to use SPC but control charts plot measurements against specification limits rather than calculated control limits -- this detects nonconforming product but does not detect process shifts, which is the purpose of SPC
- No improvement opportunities have been identified from trend analysis in the last 2 years despite declining first-pass yield and increasing rework rates; the data shows negative trends but the analysis does not characterize them as improvement opportunities
- Process trends are analyzed independently from product trends; a process change implemented to improve yield has not been correlated with an increase in field complaints for that product line -- the potential link between the process change and field performance has not been investigated
This clause specifically requires identification of improvement opportunities from trend data. Many organizations analyze trends but do not use the analysis to drive proactive improvement. Look for organizations that only react to nonconformities rather than predicting them from trend data. If SPC is used, verify it is implemented correctly (control limits, not spec limits). If SPC is not used, ask how process stability is monitored. Also look for connections between process changes and product performance changes -- organizations that make process changes without monitoring the downstream effect on product quality are missing a critical feedback loop.
Request trend charts for 3 critical process parameters over 12 months. Verify they include control limits or trend analysis, and that at least one trend observation led to an improvement action.
- Can you show me a process trend that led to a proactive improvement before a nonconformity occurred?
- How do you correlate process changes with field performance data?
- For critical processes, how do you distinguish normal variation from a meaningful process shift?
8.4(d) Is supplier performance analyzed with scorecards covering quality metrics (incoming defect rate, NCR count, CAPA responsiveness) and delivery performance? Are declining trends acted upon through supplier corrective action requests, and does analysis cover both product and service suppliers?
- Supplier performance scorecards for top 5 critical suppliers -- verify they include quality metrics (incoming defect rate, NCR count, CAPA responsiveness), delivery metrics, and an overall score with trend over at least 4 quarters
- Supplier performance analysis report showing aggregate supplier trends, identification of top-performing and underperforming suppliers, and year-over-year comparison
- Supplier improvement actions -- verify at least one supplier corrective action request (SCAR) or improvement plan was initiated based on performance data analysis
- Evidence of supplier status changes based on analysis -- probation, conditional approval, disqualification, or enhanced controls applied based on declining performance data
- Comparison of incoming inspection reject rates by supplier showing which suppliers contribute most to incoming material nonconformities
- Supplier scorecards track only on-time delivery; quality metrics (incoming rejection rate, NCR count, CAPA responsiveness) are not included in the scorecard despite quality data being available from incoming inspection records
- Supplier performance scores have been declining for 2 critical suppliers over 4 consecutive quarters, but no supplier corrective action requests or improvement plans have been initiated; the scores are reported but not acted upon
- Supplier analysis covers only product suppliers; service suppliers (sterilization, calibration, testing labs) are excluded from performance monitoring despite their direct impact on device quality
- Organization has 45 approved suppliers but only monitors performance for the top 10 by volume; 8 critical component suppliers that are low-volume but high-impact on device safety are not monitored
Supplier analysis must go beyond tracking delivery performance. Look for quality-specific metrics: incoming reject rates, NCR frequency, CAPA response timeliness, and audit findings. Then check the action loop: when supplier data shows declining performance, what happens? Organizations that collect supplier data but never take action based on it are missing the point. Also verify that the supplier analysis covers all critical suppliers, not just the highest-volume ones -- a low-volume supplier of a safety-critical component needs monitoring as much as a high-volume commodity supplier.
Pull scorecards for 3 critical suppliers and 2 service suppliers. Verify quality metrics are tracked, trends are analyzed, and declining performance triggered appropriate action.
- At what performance score do you trigger a supplier corrective action request?
- Has any supplier been disqualified or placed on probation based on performance data in the last 2 years?
- How do you monitor performance of service suppliers like sterilization contractors and testing labs?
8.4(e) Are audit results analyzed across cycles to identify patterns, repeat findings, systemic issues, and finding concentration by process area? Do audit analysis results feed into audit program planning for the subsequent cycle?
- Audit results analysis report covering internal and external audit findings over at least 2 complete cycles -- verify it categorizes findings by process area, type (major NC, minor NC, observation), and identifies trends and patterns
- Repeat finding analysis -- verify the organization tracks whether the same or similar findings recur across audit cycles, which indicates corrective action ineffectiveness
- Systemic issue identification from audit data -- verify the organization looks for cross-process patterns (e.g., training gaps appearing in multiple process audits, document control issues recurring across departments)
- Evidence that audit analysis feeds into audit program planning -- verify areas with more findings or higher risk received increased audit coverage in the subsequent cycle
- Corrective action effectiveness analysis for audit findings -- verify the organization measures whether corrective actions closed from prior audits actually prevented recurrence
- Audit analysis consists of counting findings per audit cycle with no categorization, no trend analysis, and no identification of systemic issues; the analysis cannot distinguish whether 15 findings in a cycle are 15 different issues or 1 systemic issue manifesting in 15 processes
- The same document control finding (outdated procedures at point of use) has appeared in 3 consecutive audit cycles; no analysis has been performed to understand why the corrective action from each cycle is not preventing recurrence
- Audit analysis covers only internal audit results; notified body audit findings and customer audit findings are not integrated into the analysis despite identifying significant issues
- Audit results are compiled in a list format with no cross-referencing or pattern analysis; the organization cannot answer 'which process area has the most findings' without manually counting
Audit result analysis should reveal the health of the QMS over time. Look for: (1) repeat findings -- these indicate corrective action is not working, (2) finding concentration -- processes with disproportionately many findings need attention, (3) systemic patterns -- the same type of finding appearing across multiple processes indicates a QMS-level issue, and (4) trend direction -- are total findings increasing or decreasing over cycles? The analysis should feed directly into audit program planning for the next cycle.
Request audit analysis data for the last 2 complete cycles. Check for repeat finding tracking, process-level categorization, and evidence that the analysis influenced audit program planning.
- How many repeat findings from the previous cycle appeared again in the current cycle?
- Which QMS process has the highest concentration of audit findings over the last 2 cycles?
- How do you categorize audit findings to enable meaningful cross-process analysis?
8.4(f) Is service data (installation, maintenance, repair, calibration, technical support) collected, categorized by failure mode, and analyzed for patterns? Are service data findings fed back to design or manufacturing to drive product or process improvements?
- Service report analysis covering all service activities (installation, maintenance, repair, calibration, technical support) for the last 12 months -- verify failure mode categorization, frequency analysis, and trend identification
- Top service call categories by product and failure type -- verify the analysis identifies which issues drive the most service activity and cost
- Reliability data derived from service records (mean time between failures, failure rate by product age, common replacement components) -- if applicable to the product type
- Evidence that service data analysis has been fed back to design or manufacturing -- verify at least one design change or process improvement was initiated based on service findings
- Service data integrated with complaint data and post-market surveillance -- verify service insights complement rather than duplicate complaint analysis
- Organization provides field service, installation, and repair for its devices but classifies all these activities as 'not service' and does not analyze the data; service technician field reports are filed but never reviewed or analyzed for patterns
- Service data analysis shows the same battery failure accounts for 45% of repair calls, but this finding has not been fed back to design engineering to evaluate alternative battery specifications or design changes to improve battery life
- Service reports from third-party authorized service centers are not collected or analyzed; only service performed by the organization's own technicians is included, missing data from approximately 60% of total service activity
- Service data is analyzed in isolation from complaint data and post-market surveillance; device failures identified during preventive maintenance visits are not cross-referenced with field complaints for the same failure modes
Many organizations claim this clause is 'not applicable' because they do not provide service. Challenge this: if the organization provides installation, training, preventive maintenance, calibration, repair, warranty service, or technical support, it is providing service and must analyze the data. Service data is particularly valuable because service technicians see device performance in real use conditions that testing cannot fully replicate. Verify that service findings feed back into design reviews and process improvements.
Request service activity data for the last 12 months. Verify it includes categorized failure modes, frequency analysis, and evidence that at least one service finding was fed back to design or manufacturing.
- What service activities does your organization provide, either directly or through authorized third parties?
- How do you collect service data from third-party service providers?
- Can you show me an example where a service trend led to a product design improvement?
§8.5 Improvement
8.5.1 Does the organization systematically improve QMS effectiveness using inputs from quality policy, objectives, audit results, post-market surveillance, data analysis, corrective action, preventive action, and management review? Can specific improvement examples be traced to different input sources?
- Improvement process description showing how each of the seven listed inputs (quality policy, quality objectives, audit results, post-market surveillance, data analysis, corrective action, preventive action, and management review) feeds into QMS improvement
- At least 3 specific examples of QMS improvements implemented in the last 12 months, each traceable to a different input source (e.g., one from audit findings, one from data analysis, one from management review)
- Management review records showing improvement actions were identified, assigned, and tracked -- with evidence of completion and effectiveness verification
- Quality objectives performance showing the organization is driving measurable improvement, not just maintaining the status quo
- Evidence that the QMS itself (procedures, processes, resources) has been changed based on improvement inputs -- not just product corrections but system-level improvements
- Improvement activities are limited to CAPA; there is no systematic process for identifying and implementing improvements from quality objectives, audit results, data analysis, or management review -- the organization only improves in response to problems, not proactively
- Management review identifies improvement opportunities (e.g., 'improve CAPA closure timeliness') but improvement actions are vague, have no assigned owners, and are not tracked to completion; the same improvement opportunity appears in 3 consecutive management reviews without progress
- Quality objectives have remained unchanged for multiple years with targets consistently met, indicating the organization is maintaining performance rather than driving improvement; no stretch targets or new objectives have been introduced
- Post-market surveillance data shows increasing field failure rates for a device but this data has not been used as an input to the improvement process -- the failure rate is monitored but not acted upon through the QMS improvement mechanisms
Section 8.5.1 requires systematic improvement through multiple inputs -- not just CAPA. Test this by asking for specific examples of improvements from each input source. Most organizations can show CAPA-driven improvements but struggle to demonstrate improvements driven by quality objectives, audit results, or post-market surveillance. Also distinguish between corrections (fixing individual problems) and true improvement (changing the system to prevent classes of problems). A QMS that has not changed its procedures, processes, or objectives in over a year is not improving.
Request the improvement action log or management review action items for the last 12 months. Verify that improvement actions originate from at least 3 different input sources and that completed actions resulted in measurable system improvements.
- What QMS procedure or process was changed in the last 12 months as a result of improvement activities?
- How do you distinguish between a correction (fixing a single problem) and an improvement (enhancing the system)?
- Can you show me an improvement that was initiated proactively from data analysis rather than reactively from a problem?
8.5.2 Is there a documented corrective action procedure? Do CAPA records demonstrate timely initiation, thorough root cause analysis using structured methodology, effective corrective actions addressing systemic causes, and verified effectiveness with objective data?
- 5 CAPA files as described (from different sources) -- verify each contains: source description, problem statement, immediate containment action, root cause analysis, corrective action plan, implementation evidence, and effectiveness verification with objective data
- CAPA metrics: average closure time, on-time closure rate, effectiveness verification rate, recurrence rate after CAPA closure -- verify these metrics are tracked and trended
- CAPA log or database showing all CAPAs opened in the last 24 months with source, status, age, and effectiveness verification status
- Evidence that CAPAs are initiated 'without undue delay' -- verify the timeline from triggering event to CAPA initiation for the 5 sampled CAPAs
- Root cause analysis records using structured methodology -- verify the analysis identifies systemic root causes, not just immediate causes
- CAPA initiated from a complaint involving a device malfunction during use; root cause was identified as 'manufacturing defect' with no further analysis of what caused the manufacturing defect, what process control failed to detect it, or why it reached the field (Major NC)
- Average CAPA closure time significantly exceeds the target; multiple open CAPAs have been outstanding for over a year with no documented justification for the extended timeline and no management escalation
- Effectiveness verification for a CAPA consists of a single line: 'no recurrence observed in 30 days -- effective.' The monitoring period is insufficient given the recurrence rate that triggered the CAPA, and no objective measurement data is provided (Minor NC)
- A majority of sampled CAPAs identify root cause as 'training deficiency' and corrective action as 'retrain personnel'; this pattern suggests the organization is not investigating true systemic root causes (process design, procedure clarity, equipment capability, organizational factors)
CAPA is the #1 finding area in FDA warning letters. The three most common weaknesses are: (1) superficial root cause analysis that stops at 'operator error' or 'training deficiency,' (2) corrective actions that address symptoms rather than root causes (retraining instead of error-proofing), and (3) ineffective or absent effectiveness verification. When reviewing CAPAs, ask: 'If the same conditions recur, would this corrective action prevent the problem?' If the answer is no, the CAPA addresses the symptom, not the cause. For effectiveness verification, the organization must define what success looks like BEFORE implementing the corrective action, then verify with objective data AFTER sufficient time has passed.
Pull 5 CAPAs: 1 from complaint, 1 from audit, 1 from NC product, 1 from trend analysis, 1 currently open. For the 4 closed CAPAs, critically evaluate root cause depth and effectiveness verification rigor.
- What percentage of your CAPAs identify root cause as 'training' or 'human error'?
- How do you define the effectiveness verification criteria at the time of CAPA planning, before implementation?
- When a CAPA is found to be ineffective, what is the escalation process?
8.5.2 (Procedure) Does the corrective action procedure define requirements for all elements in 8.5.2(a) through (f): reviewing nonconformities, determining causes, evaluating need for action, implementing action, recording results, and reviewing effectiveness? Does it include escalation mechanisms for overdue CAPAs?
- Corrective action SOP covering all required elements: reviewing nonconformities including complaints (a), determining causes (b), evaluating need for action (c), determining and implementing action (d), recording results (e), reviewing effectiveness (f)
- CAPA form or electronic record template -- verify it contains fields for all required elements and does not allow closure without completing each section
- One complete CAPA record traced through each procedure step -- verify every step in the SOP was followed and documented
- Procedure for escalating overdue CAPAs, reassigning CAPAs when the responsible party leaves, and managing CAPA priority changes
- Training records showing all personnel involved in the CAPA process have been trained on the current procedure revision
- Corrective action procedure does not define a method or methodology for root cause analysis; it requires 'determining the cause' but provides no guidance on which root cause tools to use (5-Why, Ishikawa, fault tree) or when each is appropriate
- Procedure requires effectiveness verification but does not define when verification should occur (how long after implementation), what success criteria should be (defined before implementation), or what to do if the CAPA is found ineffective
- CAPA procedure does not address how to handle CAPAs that involve multiple departments or require cross-functional action plans; the procedure assumes a single responsible party and a linear workflow
- No escalation mechanism in the procedure for overdue CAPAs; when a CAPA exceeds the target timeline, there is no automatic notification to management or mandatory review of the extended timeline
Read the procedure and check that every element in (a) through (f) is addressed with specific, actionable requirements. Common gaps: no defined root cause methodology, no effectiveness verification criteria, no escalation mechanism for overdue CAPAs, and no procedure for CAPAs that are found to be ineffective (what happens next?). Also check that the procedure addresses CAPA from all sources -- not just audit findings but also complaints, nonconformities, trend data, and management review actions.
Compare the CAPA procedure to the 6 required elements in 8.5.2(a)-(f). For each element, verify the procedure provides specific, actionable requirements -- not just a restatement of the ISO clause.
- What root cause analysis methodologies are available in your procedure, and how do you select which to use?
- What happens when a CAPA effectiveness verification shows the action was not effective?
- How does the procedure handle the handoff when a CAPA owner leaves the organization?
8.5.2(a) Are nonconformities from all sources (NCRs, complaints, audit findings) reviewed against defined, risk-based criteria to determine whether corrective action is needed? Are review decisions documented with specific rationale, and is pattern analysis performed across related nonconformities?
- Nonconformity review criteria defining how the organization evaluates each nonconformity (from any source) to determine whether it warrants corrective action, correction only, or no action -- verify the criteria are risk-based
- 10 nonconformity review records from different sources -- verify each has a documented review decision with rationale, and that the decision is consistent with the criteria
- Review of complaint-sourced nonconformities specifically -- verify complaints are reviewed with the same rigor as internal nonconformities (complaints are often under-investigated compared to internal findings)
- Evidence that the review process identifies patterns -- verify the organization considers whether the nonconformity is related to other recent nonconformities that collectively warrant CAPA
- Review authority records showing who performed the review and whether they had appropriate competency and authority
- Review criteria do not include pattern analysis; each nonconformity is evaluated individually without checking whether similar nonconformities have occurred recently, resulting in repeated 'isolated incident' determinations for what is actually a recurring problem
- Complaint-sourced nonconformities are reviewed by customer service with a lower bar than internally detected nonconformities; 3 complaints describing the same failure mode as an internal NCR that triggered CAPA were each closed without action
- Review decisions for several sampled nonconformities have no documented rationale; the CAPA field simply says 'N/A' without explaining why corrective action is not warranted
- Review criteria consider only severity (did harm occur?) without considering probability (how likely is recurrence?) or detectability (would we catch it before it reaches the patient?) -- resulting in 'no action' decisions for highly probable but low-severity nonconformities that accumulate into a systemic issue
The review of nonconformities is where the organization decides which problems to fix systemically and which to correct individually. The criteria must be risk-based and must consider patterns, not just individual events. Pull nonconformities from different sources (complaints, audits, NCRs) and compare the review rigor -- is there consistency? Also check for recency bias: are nonconformities from months ago reviewed with the same urgency as those from last week? The most revealing test is to pull 10 nonconformities and ask 'should any of these have triggered CAPA?' independently of the organization's determination.
Pull 10 nonconformities from 3 different sources (4 NCRs, 3 complaints, 3 audit findings). For each, verify the CAPA initiation decision, review the rationale, and assess consistency of criteria application.
- How do you ensure consistency in CAPA initiation decisions across different reviewers?
- When multiple low-severity nonconformities of the same type occur, at what point does the pattern trigger CAPA?
- Are complaints reviewed against the same criteria as internally detected nonconformities?
8.5.2(b) Are root cause analyses conducted using structured methodologies that identify systemic causes beyond immediate triggers? Is the identified root cause verified through evidence, and does the root cause categorization distribution show causes beyond "human error" and "training deficiency"?
- Root cause analysis records for 5 CAPAs -- verify each uses a structured methodology (5-Why, Ishikawa/fishbone, fault tree, Kepner-Tregoe, etc.) and documents the analysis steps, not just the conclusion
- Root cause verification evidence -- verify the organization tested or confirmed the identified root cause (e.g., reproduced the failure under root-cause conditions, or verified that removing the root cause prevents the failure)
- Systemic root causes identified -- verify the analysis went beyond immediate causes to identify system-level factors (process design, procedure gaps, resource constraints, management system weaknesses)
- Root cause categorization data showing the distribution of root cause types across CAPAs -- verify categories go beyond 'human error' and 'training' to include process, design, resource, management system, and supplier categories
- Training records for personnel who perform root cause analysis -- verify they have documented competency in the methodologies they use
- 5-Why analysis for a labeling defect reaching the field: Why 1: wrong label applied. Why 2: operator selected wrong label. Why 3: labels were stored side by side. The analysis stopped at Why 3 without asking why labels for different products were stored together, why the process did not detect the wrong label, or why the final inspection did not catch the error -- the analysis was not completed to the systemic level (Major NC)
- Root cause for multiple CAPAs is documented as 'inadequate training' with corrective action 'retraining'; no analysis was performed to determine why the training was inadequate (unclear procedure, insufficient practice time, incompatible learning method) or whether training is the true root cause
- Fishbone diagram was completed but no root cause was selected from the potential causes identified; the analysis documents multiple potential causes but does not narrow to the verified root cause with supporting evidence (Minor NC)
- Root cause analysis for a recurring assembly defect identifies 'operator error' despite the same error occurring across 4 different operators on 3 different shifts -- a pattern that strongly suggests a process or design issue rather than individual error
Root cause analysis quality is the single best predictor of CAPA effectiveness. If the root cause is wrong, the corrective action will not prevent recurrence. Red flags: (1) 'human error' or 'training' root causes that do not analyze WHY the error was possible, (2) 5-Why analyses that stop at 2-3 levels instead of reaching systemic causes, (3) fishbone diagrams with no root cause selection or verification, and (4) the same root cause identified for unrelated CAPAs (indicates a template-filling exercise, not actual analysis). Challenge the root cause by asking: 'If we put a different trained operator in the same conditions, would the error recur?' If yes, the root cause is the conditions, not the operator.
Pull root cause analyses for 5 CAPAs. Evaluate the depth of each analysis: does it reach systemic causes? Was the root cause verified? Would the corrective action prevent recurrence if the same conditions arise?
- If the root cause is 'operator error,' what conditions allowed the error to occur and why were they not error-proofed?
- How do you verify that the identified root cause is correct before implementing corrective actions?
- What percentage of your CAPAs have root cause categories other than 'training' or 'human error'?
8.5.2(c) Are decisions not to initiate CAPA for nonconformities supported by documented, risk-based evaluation criteria? Is pattern analysis performed to identify when individually acceptable "no CAPA" decisions collectively indicate a systemic issue being missed?
- CAPA evaluation criteria defining when a nonconformity requires full CAPA versus correction-only versus no action -- verify criteria consider severity, probability of recurrence, detectability, patient safety impact, and regulatory implications
- 5 nonconformities closed without CAPA -- verify each has a documented risk-based evaluation and specific rationale for why corrective action to prevent recurrence is not needed
- Pattern analysis for 'no CAPA' decisions -- verify the organization checks whether the nonconformity is related to prior events that collectively suggest a systemic issue
- Approval records showing 'no CAPA' decisions were reviewed and approved by personnel with appropriate authority
- Periodic review of 'no CAPA' decisions showing the organization monitors whether the aggregate of individually acceptable decisions indicates a systemic problem being missed
- CAPA evaluation criteria are subjective ('use professional judgment') with no defined scoring or decision framework; two reviewers presented with the same nonconformity could reasonably reach opposite conclusions about whether CAPA is needed
- Organization applies CAPA to every nonconformity regardless of risk, creating a backlog of 47 open CAPAs, 30 of which are overdue; the inability to prioritize has overwhelmed the CAPA system, causing critical CAPAs to receive the same attention as minor ones
- Evaluation for not initiating CAPA on a nonconformity found in the field states 'product returned and replaced, customer satisfied' without evaluating whether other units in the field may have the same nonconformity or whether recurrence is likely
- No periodic review of 'no CAPA' decisions is performed; over the last 18 months, 14 nonconformities involving the same connector type were each individually assessed as not requiring CAPA, but the pattern was never identified because each decision was made in isolation
This clause tests the organization's judgment about when CAPA is warranted. Both extremes are problematic: CAPAing everything creates unsustainable backlog, while CAPAing nothing allows systemic issues to persist. The ideal system uses defined, risk-based criteria to make consistent decisions. Test by presenting a hypothetical scenario to two different people in the organization and check whether they reach the same conclusion using the criteria. Also check whether 'no CAPA' decisions are aggregated periodically to catch patterns that individual decisions miss.
Pull 5 nonconformities closed without CAPA and 5 that triggered CAPA. Compare the severity and characteristics of each group to verify the evaluation criteria are being applied consistently.
- How many nonconformities in the last 12 months were closed without CAPA, and what was the distribution of rationale categories?
- If I asked two different people to evaluate the same nonconformity using your criteria, would they reach the same conclusion?
- How often do you review the aggregate of 'no CAPA' decisions to look for missed patterns?
8.5.2(d) Are corrective action plans specific, assigned to named responsible parties with due dates, and tracked to completion? Are interim containment measures in place during implementation, and are overdue CAPAs escalated to management with documented justification?
- CAPA action plans for 3 recent CAPAs -- verify each plan includes: specific actions (not vague), responsible parties by name, due dates, resource requirements, and interim controls if the permanent fix takes time
- Implementation records for each action item -- verify the action was completed as planned, on time, and that completion evidence is documented
- CAPA tracking dashboard or report showing all open CAPAs with status, age, and overdue items highlighted
- Overdue CAPA management records -- verify overdue CAPAs are escalated to management, that extension requests require justification and approval, and that interim risk mitigation is in place while the CAPA is delayed
- Evidence of interim containment actions while permanent corrective actions are being implemented -- verify affected product or processes have additional controls during the implementation period
- Corrective action is defined as 'update procedure' with no specifics about what will change in the procedure, who will write the update, or when it will be completed -- the action plan is too vague to be actionable or verifiable (Major NC)
- CAPA implementation timeline was 60 days, but the CAPA has been open for 210 days; there is no documented extension request, no management escalation, and no evidence of interim risk controls during the extended implementation period
- CAPA for a sterility breach identifies corrective actions for the manufacturing process but does not address product already in the field or in the distribution pipeline that may have been produced under the same conditions
- CAPA action plan assigns all 5 action items to the same quality engineer with overlapping due dates; no resource allocation review was performed, and the engineer's other workload was not considered, resulting in all 5 actions being overdue
Effective CAPA action plans are specific, measurable, assigned, realistic, and time-bound (SMART). Vague actions like 'update training' or 'revise procedure' without specifics are a red flag. Also check whether interim containment measures are in place while the permanent corrective action is being implemented -- if a CAPA takes 6 months to implement, what prevents the problem from recurring during those 6 months? The most common implementation failure is overloaded CAPA owners: too many actions assigned to too few people without realistic resource assessment.
Pull 3 recently closed CAPAs. For each, verify that action items were specific, assigned, time-bound, and completed on schedule. Check for interim containment actions during the implementation period.
- What interim controls are in place while permanent corrective actions are being implemented?
- How do you determine whether a CAPA action plan is realistic given the responsible party's other commitments?
- When a CAPA is overdue, what is the automatic escalation path?
8.5.2(e) Are CAPA investigation and action records complete enough for a reviewer with no prior knowledge to reconstruct the full chain: what happened, why, what was done, and whether it worked? Are supporting documents referenced and accessible?
- 5 complete CAPA files -- verify each contains all required records: source document, problem statement, immediate containment, investigation plan, investigation evidence, root cause analysis, corrective action plan, implementation records, effectiveness verification, and closure authorization
- Investigation records showing the evidence collected and analyzed -- verify the records go beyond the root cause conclusion to include the evidence that supports the conclusion
- Traceability within the CAPA record -- verify the record references related documents (complaint file, NCR, audit finding, design changes, procedure revisions, training records) and that these references are accurate
- CAPA closure checklist or review showing all required fields and records were completed before the CAPA was closed
- Records accessible and retrievable -- verify records can be located and reviewed within a reasonable timeframe (15 minutes)
- CAPA investigation record states: 'Root cause: inadequate process control. Corrective action: improved process controls implemented. Effective.' The record provides no specifics about which process control was inadequate, what improvement was made, or what evidence supports the effectiveness conclusion (Major NC)
- CAPA file references one source document, which references another, which references yet another -- the records are circular with no actual source description in the CAPA file itself
- Investigation evidence for multiple CAPAs consists only of meeting minutes summarizing verbal discussions; no physical evidence (test data, photographs, measurements, process data) is included in the investigation record
- CAPA was closed but the file does not contain the updated procedure that was cited as the corrective action; the record states 'procedure updated' but the revised procedure is not attached or referenced with a revision number and date
CAPA records must tell a complete, self-contained story. Read each record as if you know nothing about the issue and evaluate whether you can understand: (1) what happened and how it was discovered, (2) what the investigation found, (3) what was done about it, and (4) whether it worked. Records that require verbal explanation to understand are insufficient. Also verify that references within the CAPA record are accurate and accessible -- a CAPA that references a complaint file that cannot be found is a record integrity issue.
Pull 5 CAPA files and read each from start to finish. Evaluate whether the record tells a complete, self-contained story that a reviewer with no prior knowledge could follow.
- If the person who investigated this CAPA leaves the organization, could someone else understand the investigation from the records alone?
- How do you ensure all supporting documents referenced in the CAPA are attached or retrievable?
- Who reviews CAPA records for completeness before authorizing closure?
8.5.2(f) Are CAPA effectiveness verification criteria defined before implementation, using objective and measurable success measures? Is the monitoring period appropriate for the defect frequency, is objective data collected, and are CAPAs found ineffective escalated for re-investigation?
- Effectiveness verification criteria for 5 closed CAPAs -- verify criteria were defined at CAPA planning (not after implementation), are objective and measurable, and relate directly to preventing recurrence of the original problem
- Effectiveness verification timing records -- verify sufficient time elapsed between implementation and verification to allow the corrective action to be tested (not verified the next day after a change that would take months to show effect)
- Effectiveness verification data for each CAPA -- verify objective data was collected (measurements, occurrence counts, process data) not just subjective assessment ('no recurrence observed')
- At least 1 example of a CAPA found ineffective and the subsequent actions taken (re-investigation, additional corrective action, escalation)
- Effectiveness verification authority records -- verify verification was performed or reviewed by someone other than the person who implemented the corrective action
- Effectiveness verification was performed shortly after implementation by checking 'no rejects in the last week' -- insufficient monitoring period for a defect that occurred at a low but recurring rate, providing no statistical confidence that the corrective action was effective (Minor NC)
- Effectiveness criteria were not defined at CAPA initiation for any of the 5 sampled CAPAs; criteria were written retroactively at the time of verification, raising the concern that criteria were tailored to show effectiveness rather than objectively measuring it
- Effectiveness verification for the majority of CAPAs consists of a single sentence: 'No recurrence observed -- effective.' No objective data (defect rate comparison, before/after measurement, process capability study) supports the conclusion
- The organization has never found a CAPA to be ineffective; all CAPAs were verified as effective on the first attempt over a multi-year period, which statistically suggests verification rigor is insufficient to detect ineffective actions
Effectiveness verification is the #1 CAPA weakness across the medical device industry. The standard requires the organization to REVIEW effectiveness, which means more than looking for absence of recurrence. Key questions: (1) Were criteria defined before implementation? If not, they can be reverse-engineered to show effectiveness. (2) Was sufficient time allowed? A CAPA for a monthly defect verified after 1 week is meaningless. (3) Was objective data collected? 'No recurrence observed' is subjective. (4) Has any CAPA ever been found ineffective? If the answer is 'never,' either the verification criteria are too lenient or the organization is not honestly assessing effectiveness. A mature CAPA system should find approximately 10-20% of CAPAs ineffective on first verification.
Pull 5 closed CAPAs and focus exclusively on effectiveness verification. For each, verify: (1) criteria defined before implementation, (2) appropriate monitoring period, (3) objective data collected, (4) conclusion supported by data. Flag any with 'no recurrence = effective' as the sole basis.
- What percentage of your CAPAs have been found ineffective on first verification, and what happened next?
- How do you determine the appropriate monitoring period between implementation and effectiveness verification?
- Can you show me a CAPA where the effectiveness criteria were defined at the time of CAPA planning, not at verification?
8.5.3 Is there a functional preventive action system that addresses potential problems not yet occurred? Are preventive actions genuinely proactive (originating from risk analysis, trend projection, industry intelligence, near-miss events) rather than corrective actions mislabeled as preventive?
- Preventive action log or database showing all preventive actions initiated in the last 24 months -- verify there are genuine preventive actions (not corrective actions mislabeled as preventive)
- 3 preventive action records -- verify each addresses a potential problem that has NOT yet occurred (not a problem that has occurred and is being prevented from recurring -- that is corrective action)
- Sources of preventive action inputs -- verify preventive actions originate from risk analysis, trend analysis, industry intelligence, regulatory changes, near-miss events, and proactive review (not just from audit findings or nonconformities)
- Risk assessment evidence linking the potential problem to a justified preventive action -- verify the action is proportionate to the potential effect
- Evidence of preventive action effectiveness verification -- verify the organization monitors whether the potential problem has been prevented
- All items in the 'preventive action' log are corrective actions mislabeled as preventive: each addresses a problem that already occurred (complaint, nonconformity, audit finding) rather than a potential problem identified proactively before occurrence
- No preventive actions have been initiated in the last 18 months; the organization is entirely reactive, addressing problems only after they occur rather than identifying and preventing potential problems proactively
- Preventive action PA-2024-005 was initiated because of 'potential for labeling errors' but the trigger was 3 actual labeling errors in the past quarter -- this is corrective action for a recurring problem, not preventive action for a potential problem
- Preventive actions are initiated from risk assessments but the risk assessment does not consider current controls and residual risk; preventive actions are taken for risks that are already adequately controlled, while uncontrolled risks are not addressed
The distinction between corrective and preventive action is critical and frequently confused. Corrective action addresses a problem that HAS occurred to prevent recurrence. Preventive action addresses a problem that has NOT YET occurred to prevent initial occurrence. Ask the organization to explain the source of each preventive action. If the answer involves a complaint, NCR, audit finding, or any event that already happened, it is corrective action, not preventive. Genuine preventive action sources include: risk analysis identifying new hazards, trend analysis projecting future problems, industry alerts about similar devices, regulatory changes requiring proactive compliance, technology changes, and near-miss events.
Pull all preventive actions from the last 24 months. For each, verify the trigger was a potential (not actual) problem. Count genuine preventive actions versus mislabeled corrective actions.
- How does your risk management process (ISO 14971) feed into preventive action?
- What external information sources do you monitor for early warning of potential problems?
- Can you describe a potential problem you identified and prevented BEFORE any occurrence?
8.5.3 (Procedure) Does the preventive action procedure define a distinct process for proactive identification of potential problems, risk-based evaluation, action determination, implementation, recording, and effectiveness verification? Does it specify systematic identification methods rather than relying on ad hoc reporting?
- Preventive action SOP -- verify it defines a distinct process for: (a) identifying potential nonconformities and their causes, (b) evaluating the need for action, (c) determining and implementing action, (d) recording results, (e) reviewing effectiveness, (f) updating documentation
- Procedure addresses proactive identification methods (risk analysis, trend projection, industry monitoring, near-miss analysis, process FMEA updates) as inputs to preventive action -- not just nonconformity review
- Procedure defines evaluation criteria for determining whether a potential problem warrants action -- verify criteria consider probability of occurrence, severity of effect, and current control effectiveness
- Procedure defines how preventive action effectiveness is verified -- since the problem has not occurred, verification must show the risk has been reduced or the potential cause eliminated
- Training records showing personnel understand the distinction between corrective and preventive action and know how to initiate a preventive action
- Preventive action procedure is a verbatim copy of the corrective action procedure with 'nonconformity' replaced by 'potential nonconformity' -- the procedure does not address how potential problems are proactively identified, which is the core distinction
- Procedure does not define any proactive identification methods; it waits for someone to report a 'potential nonconformity' but does not require systematic scanning of risk analyses, trend data, or external sources to identify potential problems
- Effectiveness verification for preventive action is defined as 'no occurrence of the potential problem' which is logically unprovable -- the procedure does not define a monitoring period or alternative verification methods (risk reduction measurement, control effectiveness testing)
- No personnel have been trained on how to initiate a preventive action; interview with 5 quality team members reveals confusion about the distinction between corrective and preventive action
The preventive action procedure must be genuinely different from the corrective action procedure, particularly in how inputs are identified. A corrective action starts with a problem that occurred. A preventive action starts with a risk, trend, or intelligence signal indicating a problem could occur. If the procedure does not define how the organization proactively scans for potential problems, the procedure is incomplete. Also check the effectiveness verification approach -- for preventive action, this requires creative thinking since you cannot simply check for non-recurrence of something that never occurred.
Compare the preventive action procedure to the corrective action procedure side by side. Verify the preventive action procedure has distinct provisions for proactive problem identification that are not present in the corrective action procedure.
- How does your procedure define the distinction between corrective and preventive action inputs?
- What systematic methods does your procedure require for identifying potential problems?
- How do you verify that a preventive action was effective when the problem never occurred?
8.5.3(a) Are proactive methods in place to identify potential nonconformities before they occur? Are at least three systematic methods active (risk management updates, FMEA reviews, trend projection, industry monitoring, near-miss reporting, literature surveillance), and have they produced actionable findings in the last 12 months?
- Proactive identification methods documented and implemented -- verify the organization uses at least 3 of the following: risk management updates (ISO 14971), process FMEA reviews, trend projection from quality data, industry alert monitoring (FDA recalls, field safety notices), literature surveillance, near-miss reporting, technology change assessment
- Records of potential problems identified through proactive methods in the last 12 months -- verify at least 2 potential problems were identified from different sources
- Near-miss reporting system -- verify the organization has a mechanism for personnel to report situations that could have resulted in nonconformity but did not, and that these reports are analyzed for preventive action
- Industry monitoring records showing the organization reviews competitor recalls, FDA warning letters, and field safety notices for applicability to their own products and processes
- Risk management file reviews showing updated risk assessments identify new or emerging risks that trigger preventive action
- Organization has no near-miss reporting system; only actual nonconformities are reported and tracked, meaning potential problems that were caught before becoming nonconformities are not captured and analyzed
- Risk management files have not been reviewed since initial product launch; no mechanism exists to update risk assessments based on post-market data, manufacturing experience, or changes in the state of the art
- Organization does not monitor FDA MAUDE database, recall databases, or competitor field safety notices; when a competitor recalled a similar device for the same connector failure mode the organization is experiencing, the information was not identified or acted upon
- Process FMEA was completed during process validation and has never been updated; new failure modes identified during production are not fed back into the FMEA to update risk controls
This is where preventive action systems most frequently fail -- at the input stage. If the organization does not systematically scan for potential problems, the entire preventive action system is inactive. Ask specifically about: (1) near-miss reporting -- do operators report close calls?, (2) industry monitoring -- do they watch competitor recalls and regulatory actions?, (3) risk management updates -- is the risk file a living document or a launch artifact?, and (4) trend projection -- do they project quality trends forward to anticipate future problems? If none of these are active, the organization has no functional preventive action identification mechanism.
Request evidence of at least 3 different proactive identification methods being actively used. For each, verify it produced at least one potential problem identification in the last 12 months that was evaluated for preventive action.
- Can a production operator report a near-miss? If so, show me the reporting mechanism and recent examples.
- When was the last time you updated a product risk management file based on manufacturing or field experience?
- How do you become aware of competitor recalls or field safety notices for similar devices?
8.5.3(b) Are potential nonconformities evaluated against defined criteria (probability, severity, existing control effectiveness) to determine whether preventive action is warranted? Are evaluation records documented with risk-based rationale, including decisions not to take action?
- Evaluation criteria for determining whether a potential problem warrants preventive action -- verify criteria consider probability of occurrence, severity of potential effect, effectiveness of existing controls, and cost-benefit of preventive action
- 3 evaluation records for potential problems -- verify each includes a documented risk assessment and a clear decision (take action / do not take action) with supporting rationale
- At least 1 evaluation where the decision was not to take preventive action -- verify the rationale is documented, risk-based, and considers whether existing controls are adequate
- Priority matrix or similar tool for ranking potential problems to allocate preventive action resources to the highest-risk opportunities
- Approval records showing evaluations were reviewed by an individual with appropriate authority and risk management competency
- Evaluation criteria do not consider existing controls; a potential problem assessed as 'high severity, medium probability' is given the same treatment whether current controls reduce the risk to acceptable levels or provide no risk reduction
- All potential problems identified are automatically given preventive action without evaluation, creating a backlog that overwhelms the system and dilutes attention from the most critical potential issues
- No evaluation records exist for potential problems that were identified but not acted upon; the organization cannot demonstrate that the decision not to take action was risk-based and deliberate
- Evaluation criteria consider only product risk; potential problems related to QMS effectiveness, regulatory compliance, or supply chain resilience are not evaluated using the same framework
Not every potential problem requires preventive action -- but the decision must be deliberate and documented. Look for a risk-based evaluation that considers the probability and severity of the potential problem against the effectiveness of existing controls. If existing controls already reduce the risk to an acceptable level, preventive action may not be needed. But the evaluation must document this reasoning. Also verify that the organization can handle the volume of preventive actions it initiates -- taking on too many preventive actions with insufficient resources is as problematic as taking on none.
Request 3 evaluation records for potential problems. Verify each includes a risk assessment, a clear decision, and specific rationale. At least 1 should be a 'no action' decision with documented justification.
- How do you prioritize among multiple potential problems competing for preventive action resources?
- Can you show me a potential problem that was evaluated and determined not to need action? What was the rationale?
- How do you factor existing risk controls into the evaluation of whether additional preventive action is needed?
8.5.3(c) Are preventive actions proportionate to the potential effect, with specific action plans, assigned responsibilities, implementation timelines, and interim controls? Are high-risk potential problems addressed with substantive controls rather than training-only responses?
- 3 preventive action plans -- verify each defines specific actions proportionate to the potential effect, responsible parties, implementation timelines, and interim controls where the potential problem could manifest during the implementation period
- Implementation records showing actions were completed as planned, on time, and verified by someone independent of the implementer
- Evidence that preventive actions were proportionate -- verify high-risk potential problems received substantive controls (error-proofing, design changes, process redesign) while low-risk items received proportionate responses
- Resource allocation evidence showing the organization dedicated appropriate resources to implement the preventive actions
- Communication records showing affected personnel were informed of the preventive action and any resulting changes to processes or procedures
- Preventive action for a high-risk potential failure mode (identified through FMEA update) is limited to 'add to operator training' without any process or design change; the action is not proportionate to the severity of the potential effect (patient injury)
- Preventive action was initiated based on an industry recall of a similar device, but the action plan has not been started; meanwhile, the organization continues to manufacture and ship the potentially affected product
- Action plans for preventive actions are identical to corrective action plans in format and content, with no consideration of the unique aspects of preventing a problem versus correcting one -- specifically, no monitoring plan to detect early occurrence of the potential problem during implementation
- Preventive actions are implemented in quality department procedures only; production floor processes, operator work instructions, and incoming inspection criteria that would need updating to prevent the potential problem are not included in the action plan
Preventive actions must be proportionate to the potential effects. A potential patient safety issue should receive robust preventive controls (error-proofing, design change, automated detection), while a potential administrative issue may need only a procedure update. Look for actions that are substantive versus actions that are token gestures. Also check implementation timeliness -- if a potential problem is serious enough to warrant preventive action, delayed implementation suggests the organization does not take the risk seriously.
Pull 3 preventive action implementation records. Verify actions were specific, proportionate to the risk, implemented on time, and that implementation evidence is documented.
- How do you ensure preventive actions are proportionate to the severity of the potential problem?
- For a preventive action that requires process changes, how do you manage the transition without creating new risks?
- How do you measure whether the preventive action actually reduced the risk?
8.5.3(d) Are preventive action records complete, with traceable documentation from source identification through risk analysis, action determination, implementation, and effectiveness verification? Are records maintained with the same rigor as corrective action records?
- Complete preventive action records for all PAs initiated in the last 12 months -- verify each contains: source of the potential problem, risk analysis, action determination, implementation plan and evidence, and effectiveness verification
- Investigation records for the potential problem -- verify the organization analyzed the potential causes (not just identified the potential effect) using appropriate methods such as prospective risk analysis, FMEA, or scenario analysis
- Action determination records with documented rationale for the specific actions chosen -- verify the rationale explains why these actions will address the potential causes identified
- Traceability between records -- verify the investigation references the source, the action plan references the investigation, and the verification references the action plan
- Record retention and accessibility -- verify preventive action records are maintained in the controlled document system with the same rigor as corrective action records
- Preventive action records are less detailed than corrective action records; the organization invests significant effort in CAPA documentation but treats preventive action documentation as a lower priority -- 4 of 6 PA records lack investigation evidence or documented rationale
- No investigation of potential causes was performed; the preventive action jumps from 'potential problem identified' to 'action taken' without analyzing why the problem might occur or which root causes to address
- Records exist but are scattered across multiple systems (risk management file, quality database, engineering change orders) with no cross-referencing; it is not possible to trace the full preventive action trail from a single starting point
- Preventive actions initiated from management review action items have no formal PA record; they exist only as entries in management review meeting minutes with no investigation, no implementation evidence, and no effectiveness verification
Preventive action records should be as complete as corrective action records. The investigation is particularly important because it deals with something that has not happened yet -- the organization must demonstrate analytical rigor in identifying potential causes and selecting actions that address those causes. If records consist only of 'we identified a risk and took action' without investigation of potential causes, the process lacks the analytical depth needed to be effective.
Pull all preventive action records from the last 12 months. For each, verify the complete record trail exists: source, investigation, action determination, implementation, and verification. Flag any with missing elements.
- Are preventive action records maintained with the same rigor and in the same system as corrective action records?
- How do you investigate potential causes for a problem that has not yet occurred?
- Can you trace a preventive action from its source through implementation and verification in under 15 minutes?
8.5.3(e) Is preventive action effectiveness verified using methods beyond "the problem has not occurred"? Are verification criteria defined before implementation, and do methods include risk-level comparison, control effectiveness testing, or leading-indicator monitoring?
- Effectiveness verification methodology for preventive actions -- verify the methodology addresses the challenge of verifying prevention of something that has not occurred (e.g., risk level comparison before/after, control effectiveness testing, simulation, monitoring for leading indicators)
- 3 preventive action effectiveness verification records -- verify each defines success criteria, uses appropriate verification methods, collects objective evidence, and reaches a defensible conclusion
- Monitoring plans for verified preventive actions -- verify the organization continues to monitor for the potential problem after verification to confirm sustained effectiveness
- Risk management file updates showing the preventive action reduced the risk level for the identified potential problem
- At least 1 example where a preventive action was found to be insufficient and additional action was required
- Effectiveness verification for all preventive actions consists of 'problem has not occurred -- preventive action effective.' This is circular reasoning: the problem may not have occurred regardless of the preventive action, and the absence of occurrence does not demonstrate the action was the cause
- No effectiveness verification criteria were defined before implementing the preventive action; verification was performed retroactively by checking whether the problem occurred, which is the same conclusion that would be reached whether or not any action had been taken
- Preventive action to reduce risk of contamination involved adding a new environmental monitoring point; effectiveness verification checked that the monitoring point was installed and operating, but did not evaluate whether environmental data showed risk reduction
- No preventive action has ever been found insufficient; 100% effectiveness on first verification suggests either the organization is fortunate or the verification is not rigorous enough to detect ineffective actions
This is one of the hardest elements of the QMS to do well. Verifying that you prevented something from happening is inherently more difficult than verifying that a problem stopped recurring. Effective approaches include: (1) before/after risk comparison using the same risk assessment methodology, (2) testing the preventive control to verify it functions as intended, (3) monitoring leading indicators that would precede the potential problem, and (4) simulation or failure mode testing to verify the system can handle the scenario. 'It did not happen' is necessary but not sufficient evidence of effectiveness.
Pull 3 closed preventive actions and focus on effectiveness verification. Evaluate whether the verification method could actually demonstrate the action was effective, or whether it relies solely on absence of the problem.
- How do you distinguish between 'the preventive action worked' and 'the problem would not have occurred anyway'?
- What leading indicators do you monitor to detect early warning of the potential problem after preventive action?
- Can you show me a preventive action where the verification included testing the preventive control itself, not just monitoring for the problem?
8.5.3(f) When preventive actions result in process or procedure changes, are associated documents updated through document control, affected personnel trained, and current revisions verified at the point of use? Is traceability maintained between the preventive action and resulting documentation changes?
- 3 preventive actions that resulted in procedure or process changes -- verify the associated documents were updated through the document control process (formal revision, review, approval, distribution)
- Change control records linking the preventive action to the document change -- verify the change was initiated because of the preventive action and the change description matches the preventive action intent
- Training records for personnel affected by the document changes -- verify training was completed before or concurrent with the implementation of the changes, not months after
- Point-of-use verification -- verify the updated documents are available at the point of work in their current revision (not obsolete versions)
- Communication records showing affected departments and personnel were informed of the changes and their rationale
- Preventive action PA-2024-008 resulted in a new incoming inspection requirement, but the incoming inspection procedure has not been updated 4 months after the preventive action was closed; operators are performing the new inspection based on verbal instructions with no documented procedure
- Procedure was updated to incorporate the preventive action change, but affected operators were not retrained; operators interviewed on the production floor are unaware of the procedure change
- Document change was made but the change control record does not reference the preventive action as the trigger; the traceability between the preventive action and the resulting system change is lost
- Updated procedure is available electronically, but the point-of-use copy at the workstation is still the previous revision; the operator is following the old procedure despite the update being 'released' in the document control system
Preventive actions that result in process or procedure changes must flow through the document control system and training program. This is where preventive actions often fail to complete the loop: the action is implemented in practice but the documentation is not updated, or the documentation is updated but affected personnel are not trained. Verify the complete chain: PA action plan specifies the documentation change, document control processes the revision, training is provided to affected personnel, and the current revision is available at point of use. Visit the work area to verify current documents are in use.
Pull 3 preventive actions that resulted in document changes. For each, verify the document revision was completed, training was delivered, and the current revision is available at the point of work.
- How do you ensure that all documents affected by a preventive action are identified and updated?
- What is the typical lag time between closing a preventive action and completing all associated document updates and training?
- How do you verify that personnel are actually following the updated procedure, not just that the procedure was distributed?
Each item shows its evidence, common nonconformities and auditor tips. The clause index has the PDF of all 334 items, formatted for a clipboard.
The rest of the ISO 13485:2016 internal audit checklist
334 items across 5 clauses. Back to the clause index.