Skip to content

Evidence request lists

FDA Quality Management System Regulation (QMSR)

Evidence request list. 13 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

QMSR: Clarification of Concepts and Definitions (§820.15)

QMSR-820.15
Clarification of concepts (§820.15)

Section 820.15 provides FDA-specific CLARIFICATIONS to ensure that ISO 13485:2016 terminology aligns with FDA's interpretation of the Federal Food, Drug, and Cosmetic Act + related FDA regulations. KEY CLARIFICATIONS include: (a) 'CUSTOMER' for QMSR purposes includes patients + clinicians + the FDA + healthcare facilities + procurement entities - broader than the ISO 13485 organizational customer; (b) 'PRODUCT' refers to FINISHED MEDICAL DEVICES (i.e. devices ready for placing on the market) + does not include components + materials + sub-assemblies that have not yet been assembled into a finished device; (c) 'REGULATORY REQUIREMENTS' includes all FDA + State + International medical device regulations applicable to the manufacturer + the finished device; (d) 'COMPLAINT' (under ISO 13485 Section 7.2.3) is harmonised with the FDA definition of complaint under §820.3 + §820.198 - includes a

Artefacts an auditor will ask for
  • Clarifications integrated into Quality Manual + procedures
  • Customer-definition register
  • Complaint procedure aligned with both ISO 13485 + FDA §820.198 + §806
Where this commonly fails
  • ISO 13485 terms used without FDA §820.15 clarifications
  • Customer narrowly defined to organizational customer only
  • Complaint procedure not addressing all §820.198 complaint sources

QMSR: Control of Records (§820.35) - Audit Trail, UDI, Reporting

QMSR-820.35
Control of records - record retention, audit trail, UDI, medical-device reporting (§820.35)

Section 820.35 establishes FDA-specific record-control requirements that supplement ISO 13485:2016 Section 4.2.5. SPECIFIC REQUIREMENTS: (a) RECORD RETENTION - records must be retained for a period of time equivalent to the design + expected life of the device + IN ANY CASE NOT LESS THAN 2 YEARS FROM THE DATE OF RELEASE FOR COMMERCIAL DISTRIBUTION BY THE MANUFACTURER. (b) AUDIT TRAIL - records must include audit trail meeting the criteria of FDA 21 CFR Part 11 (Electronic Records + Electronic Signatures) where electronic records are maintained - the audit trail must be: secure + computer-generated + time-stamped + tamper-evident + record who-what-when-where-why for every CRUD operation on regulated records. (c) UNIQUE DEVICE IDENTIFICATION (UDI) - records must include UDI per FDA Unique Device Identification Rule (21 CFR Part 830) where applicable - UDI on labelling + linked to records.

Artefacts an auditor will ask for
  • Record-retention policy specifying device-life-or-2-year-minimum + FDA inspection-readiness
  • Audit trail Part 11 conformance test + design specification
  • UDI traceability per Part 830
  • MDR + Part 806 records retention
Where this commonly fails
  • Records retention shorter than 2 years from commercial distribution release
  • Audit trail not Part 11 compliant
  • UDI traceability gap
  • MDR + Part 806 records not retained or not inspection-ready

QMSR: Coordination with ISO 13485:2016, EU MDR/IVDR, FDA Part 11

QMSR-Coord-ISO13485-MDR-IVDR-Part11
Coordination with ISO 13485:2016, EU MDR/IVDR, FDA Part 11, Cybersecurity Guidance

QMSR coordinates with multiple regimes. (a) ISO 13485:2016 (NEEDS LICENSED COPY) - incorporated by reference + the substantive QMS content lives in this copyrighted ISO standard. (b) EU MDR (Regulation (EU) 2017/745) + EU IVDR (Regulation (EU) 2017/746) parallel medical-device + IVD regulations - dual-validated manufacturers face MDR Article 10 + IVDR Article 10 manufacturer obligations alongside QMSR + ISO 13485:2016; the EU regulatory pathway typically requires ISO 13485:2016 certification from a Notified Body (NB) as the primary QMS evidence + the QMSR maps similar requirements to FDA QMS evidence. (c) FDA Part 11 - electronic records + electronic signatures used in QMSR record-keeping per §820.35. (d) FDA Premarket Cybersecurity Guidance (2014 + 2018 + 2023 + 2024 updates) + Cures Act Section 524B - cybersecurity built into design controls + risk management for medical device softwar

Artefacts an auditor will ask for
  • ISO 13485:2016 licensed + current + integration evidence
  • EU MDR/IVDR cross-reference matrix + Notified Body engagement
  • Part 11 record + audit trail alignment evidence
  • Premarket cybersecurity submission + SBOM
Where this commonly fails
  • ISO 13485:2016 not licensed or stale version
  • No cross-reference between QMSR + EU MDR/IVDR for dual validation
  • Part 11 record control not extended to QMSR records
  • Premarket cybersecurity gap

QMSR: Device Labelling and Packaging Controls (§820.45)

QMSR-820.45
Device labelling and packaging controls (§820.45)

Section 820.45 establishes FDA-specific DEVICE LABELLING + PACKAGING controls supplementing ISO 13485:2016 Section 7.5.11 (preservation of product). REQUIREMENTS: (a) LABELLING - the manufacturer must establish + maintain procedures to control labelling activities to ensure that LABELLING IS LEGIBLE + DURABLE + AFFIXED OR ATTACHED to the device + APPROPRIATE LABELLING IS RELEASED FOR COMMERCIAL USE - including device identification + manufacturer name + intended use + warnings + cautions + instructions for use (IFU). (b) UDI ON LABEL - the UDI must appear on the LABEL OF THE DEVICE + on each higher level of packaging in human-readable + AIDC (Automatic Identification and Data Capture) format per 21 CFR Part 830. (c) LABELLING INSPECTION + STORAGE - procedures for inspection of labelling for accuracy including identification number + lot number + expiration date + control number + similar

Artefacts an auditor will ask for
  • Labelling control procedure
  • UDI labelling evidence per Part 830
  • Labelling inspection records + supervision
  • Packaging validation per ISO 11607 where applicable
Where this commonly fails
  • Labelling procedures missing UDI integration
  • UDI on label only without AIDC format
  • Labelling inspection limited to first article without ongoing
  • Packaging validation absent for sterile devices

QMSR: Quality Management System Requirements (§820.10 incorporating ISO 13485:2016 Sec. 4-8)

QMSR-820.10
Requirements for a Quality Management System - ISO 13485:2016 Sections 4-8 incorporation (§820.10)

Section 820.10 establishes the substantive QMS requirements by incorporating ISO 13485:2016 SECTIONS 4 THROUGH 8 in full. Manufacturers must implement: ISO 13485:2016 SECTION 4 General QMS requirements + documentation (Quality Manual + Medical Device File + control of documents + records); SECTION 5 Management responsibility + customer focus + quality policy + planning + responsibility / authority / communication + management review; SECTION 6 Resource management (provision of resources + human resources + infrastructure + work environment + contamination control); SECTION 7 Product realization (planning + customer-related + design and development - the medical-device 'design controls' parallel + purchasing + production and service provision + control of monitoring + measuring equipment); SECTION 8 Measurement + analysis + improvement (monitoring + measurement + control of nonconforming

Artefacts an auditor will ask for
  • ISO 13485:2016 Section 4-8 compliance file
  • Internal audit programme + records
  • Management review records + frequency
  • Cross-reference matrix between QMSR + ISO 13485:2016 + EU MDR/IVDR + FDA Part 11
Where this commonly fails
  • ISO 13485:2016 implemented in parts without full Section 4-8 coverage
  • Internal audit infrequent or scope-limited
  • Management review absent + meeting minutes incomplete
QMSR-ISO13485-Sec5
Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)

ISO 13485:2016 Section 5 (Management Responsibility) incorporated via §820.10. ELEMENTS: (5.1) MANAGEMENT COMMITMENT to develop + implement + maintain the QMS + improve its effectiveness; (5.2) CUSTOMER FOCUS - identify + meet customer + regulatory requirements; (5.3) QUALITY POLICY appropriate to the purpose of the organization + commitment to comply + continually improve; (5.4) PLANNING - quality objectives at relevant functions + levels + planning of changes affecting the QMS; (5.5) RESPONSIBILITY + AUTHORITY - clear definition + communication; designation of management representative who has the authority + responsibility for the QMS; internal communication processes appropriate to the effectiveness of the QMS; (5.6) MANAGEMENT REVIEW - at planned intervals to ensure continuing suitability + adequacy + effectiveness of the QMS; review of feedback + complaints + monitoring + measureme

Artefacts an auditor will ask for
  • Management commitment evidence + quality policy + objectives
  • Management representative designation + responsibility / authority matrix
  • Management review records + frequency
Where this commonly fails
  • Management commitment treated as one-time without ongoing reinforcement
  • Management representative dual-hatted without adequate time / authority
  • Management review not at planned intervals
QMSR-ISO13485-Sec6
Resource management (ISO 13485:2016 Section 6 - incorporated via §820.10)

ISO 13485:2016 Section 6 (Resource Management) incorporated via §820.10. ELEMENTS: (6.1) PROVISION OF RESOURCES - determine + provide resources needed for the QMS + product realization; (6.2) HUMAN RESOURCES - competence + training + awareness; personnel performing work affecting product quality must be competent on the basis of education + training + skills + experience; documented procedures for establishing competence + training needs + providing training + evaluating effectiveness of actions; awareness records; (6.3) INFRASTRUCTURE - buildings + workspace + utilities + process equipment + supporting services; maintenance activities to prevent product / process risks; (6.4) WORK ENVIRONMENT + CONTAMINATION CONTROL - work environment requirements documented per product / process; planned controls for environment-sensitive products; contamination control including personnel cleanliness

Artefacts an auditor will ask for
  • Resource provision evidence
  • Competence + training records
  • Infrastructure maintenance schedule
  • Work environment + contamination control records + Part 11 computer system validation
Where this commonly fails
  • Resource provision tied only to capacity not to QMS effectiveness
  • Competence based on job-title without evidence
  • Infrastructure maintenance gaps
  • Work environment definition not extended to computer systems
QMSR-ISO13485-Sec7_DesignControls
Product realization - Design and Development controls (ISO 13485:2016 Section 7.3)

ISO 13485:2016 Section 7.3 (Design and Development) - the medical-device DESIGN CONTROLS framework. (7.3.1) PLANNING - design + development planning at the start of each design project; (7.3.2) INPUTS - functional + performance + usability + safety requirements + applicable regulatory requirements + applicable standards + risk-management outputs + previous similar designs + other essential requirements; (7.3.3) OUTPUTS - in a form that enables verification against inputs + approved prior to release + provide appropriate information for purchasing + production + service + acceptance criteria; (7.3.4) REVIEW - systematic + planned + multi-disciplinary + records; (7.3.5) VERIFICATION - confirming that outputs meet input requirements; (7.3.6) VALIDATION - confirming that the design meets user needs + intended use - performed under defined operating conditions on initial production units or e

Artefacts an auditor will ask for
  • Design planning records
  • Design input + output traceability matrix
  • Design review + verification + validation records
  • Design transfer + change-control records
  • DHF / DDF complete + accessible
Where this commonly fails
  • Design inputs not traceable to user needs + intended use
  • Design verification limited to prototype without final production
  • Design validation not under defined operating conditions
  • DHF / DDF incomplete or scattered across systems
QMSR-ISO13485-Sec7_Purchasing
Purchasing controls + supplier management (ISO 13485:2016 Section 7.4)

ISO 13485:2016 Section 7.4 (Purchasing) - the supplier-management framework. (7.4.1) PURCHASING PROCESS - documented procedures for evaluation + selection + monitoring + re-evaluation of suppliers based on supplier's ability to supply product meeting requirements; criteria for evaluation including impact on quality of medical device + risk associated with medical device; periodic monitoring + re-evaluation per planned intervals; records of evaluation + selection + monitoring + re-evaluation + actions arising. (7.4.2) PURCHASING INFORMATION - description of product to be purchased including: (a) product specifications; (b) requirements for acceptance + qualification of personnel; (c) QMS requirements; (d) regulatory requirements; the manufacturer must ensure that requirements are adequate. (7.4.3) VERIFICATION OF PURCHASED PRODUCT - inspection + verification activities for purchased produ

Artefacts an auditor will ask for
  • Supplier evaluation + selection + monitoring records
  • Approved supplier list (ASL) + monitoring KPIs
  • Purchasing information adequacy review
  • Incoming inspection + verification + supplier audit records
Where this commonly fails
  • Supplier evaluation one-time without ongoing monitoring
  • Purchasing information missing regulatory requirements
  • Verification limited to incoming inspection without supplier audit
  • Risk-based criteria not applied to high-risk suppliers
QMSR-ISO13485-Sec8
Measurement, analysis and improvement (ISO 13485:2016 Section 8)

ISO 13485:2016 Section 8 - the MEASUREMENT + ANALYSIS + IMPROVEMENT framework. (8.1) GENERAL - planning + monitoring + measurement + analysis + improvement processes; (8.2) MONITORING + MEASUREMENT (8.2.1 FEEDBACK from production + post-production + complaint handling; 8.2.2 COMPLAINT HANDLING; 8.2.3 REPORTING TO REGULATORY AUTHORITIES; 8.2.4 INTERNAL AUDIT; 8.2.5 MONITORING + MEASUREMENT OF PROCESSES; 8.2.6 MONITORING + MEASUREMENT OF PRODUCT); (8.3) CONTROL OF NONCONFORMING PRODUCT - identification + documentation + segregation + evaluation + disposition + records; corrective actions where nonconforming product is detected after delivery (CORRECTIONS AND REMOVALS); (8.4) ANALYSIS OF DATA - feedback + customer satisfaction + product conformity + process performance + suppliers + improvement opportunities + outcomes; (8.5) IMPROVEMENT (8.5.1 GENERAL; 8.5.2 CORRECTIVE ACTION - identify ca

Artefacts an auditor will ask for
  • Feedback + complaint handling records + classification
  • Adverse event reporting per FDA + EU regulators
  • Internal audit programme + records
  • Nonconforming product log + disposition
  • CAPA records + effectiveness verification
Where this commonly fails
  • Feedback channels limited + complaint handling slow
  • Adverse events not reported per FDA timelines
  • Internal audit not covering all QMS processes
  • CAPA records lacking effectiveness verification + root cause analysis

QMSR: Scope, Definitions, Incorporation by Reference (§§820.1-820.7)

QMSR-820.1_3_7
Scope, definitions and incorporation by reference (§§820.1, 820.3, 820.7)

Section 820.1 (Scope): the QMSR establishes requirements for the methods used in + the facilities + controls used for the design + manufacture + packaging + labelling + storage + installation + servicing of all finished medical devices intended for human use. Section 820.3 (Definitions) incorporates the definitions in ISO 13485:2016 Sections 3.1-3.20 + adds 7 FDA-specific definitions: (a) act + (b) finished device + (c) manufacturer + (d) device master record (DMR) + (e) device history record (DHR) + (f) design history file (DHF) + (g) quality system. Section 820.7 (Incorporation by reference): the FDA incorporates ISO 13485:2016 by reference making the ISO standard MANDATORY for QMSR compliance. The FDA + ISO 13485:2016 + the QMSR Final Rule together form the harmonised US medical-device quality framework. Compliance with QMSR requires manufacturers to: (a) hold a current copy of ISO 13

Artefacts an auditor will ask for
  • Finished-device classification per §820.1
  • DMR + DHR + DHF inventory + ISO 13485:2016 cross-reference
  • Licensed ISO 13485:2016 copy + QMSR Final Rule on file
Where this commonly fails
  • QMSR scope misapplied to non-finished-device activities
  • ISO 13485:2016 copy not licensed (purchased + maintained current)
  • FDA-specific definitions not understood (e.g. DMR / DHR / DHF roles)

QMSR: Transition Plan from Prior QSR, FDA Inspection Approach, Status

QMSR-Status
FDA QMSR - corpus status, enforcement landscape, future evolution

21 CFR Part 820 (QMSR) Final Rule 89 FR 7496 published 31 January 2024 + applies from 2 February 2026. The QMSR replaces the prior Quality System Regulation (QSR) which had been in effect since 1996. Key transitions: (a) HARMONISATION with ISO 13485:2016 + incorporation by reference; (b) reduced FDA-specific regulatory text - QSR §820.20-820.250 replaced with QMSR §820.10/15/35/45 + the ISO 13485 substance; (c) FDA-specific additions retained where US-specific requirements differ from ISO (UDI + MDR + Part 11 audit trail + §820.45 device labelling). FUTURE EVOLUTION: (a) FDA continued harmonisation with international standards including IEC 62304 medical device software + ISO 14971 risk management + ISO 14155 clinical investigation + IEC 62366-1 usability; (b) cybersecurity integration via Cures Act 524B + 2024 FDA Premarket Cybersecurity Guidance + SBOM expectations; (c) AI/ML integrati

Artefacts an auditor will ask for
  • Tracking of QMSR + related FDA guidance updates
  • Cybersecurity + SBOM integration into QMSR
  • AI/ML PCCP if applicable
  • QMM voluntary participation
Where this commonly fails
  • QMSR transition not tracked
  • Cybersecurity treated as separate from QMS
  • AI/ML PCCP not considered
  • QMM not evaluated for participation
QMSR-Transition
Transition from prior QSR + 2 February 2026 application + FDA inspection approach

TRANSITION PATH from prior QSR to QMSR: the FDA Final Rule (89 FR 7496) provides a 2-year implementation period - the QMSR applies from 2 FEBRUARY 2026 + manufacturers must fully implement the harmonised QMSR by that date. KEY TRANSITION ACTIVITIES: (a) GAP ANALYSIS between existing QSR-compliant QMS + the QMSR (incorporating ISO 13485:2016) - identify procedures that must be updated; (b) DOCUMENTATION UPDATE - update Quality Manual + procedures + work instructions to reference ISO 13485:2016 Section 4-8 + the §820.15 clarifications + §820.35 record controls + §820.45 labelling; (c) TRAINING - retrain QMS personnel on harmonised terminology + ISO 13485:2016 Section structure + FDA clarifications; (d) ISO 13485:2016 CERTIFICATION CONSIDERATION - manufacturers who do not already hold ISO 13485:2016 certification should consider obtaining it from an FDA-accredited Notified Body or Conformit

Artefacts an auditor will ask for
  • QSR-to-QMSR transition plan + completion evidence
  • Documentation update register
  • Training records on harmonised QMSR
  • ISO 13485:2016 certification audit results
  • MDSAP audit reports where applicable
Where this commonly fails
  • Transition incomplete by 2 February 2026 (post-deadline FDA inspections likely to issue 483 + warning letters)
  • ISO 13485:2016 certification not pursued (creates dual EU + US validation friction)
  • MDSAP audit programme not leveraged for multi-regulator efficiency
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FDA Quality Management System Regulation (QMSR) framework page.