FDA QMSR: cómo el cambio normativo de 2026 transforma las auditorías MDSAP y las inspecciones de cumplimiento de la FDA

Escrito por Joana Martins
Publicado el 20 de febrero de 2026 Última actualización el 23 de julio de 2026

El 2 de febrero de 2026, la Food and Drug Administration (FDA) de EE. UU. implementó la nueva Quality Management System Regulation (QMSR), sustituyendo formalmente a la anterior Quality System Regulation (21 CFR Part 820). Con esta transición, la FDA incorporó por referencia la ISO 13485:2016 a la legislación estadounidense e introdujo un nuevo modelo de inspección en el marco del Compliance Program 7382.850.

This article focuses on that second question. It explains how to structure a QMSR gap analysis, which areas almost always reveal gaps in practice, particularly for IVD and companion diagnostic manufacturers, and what FDA inspectors are finding in the first wave of QMSR inspections.

The insights below draw directly on MDx CRO’s quality and regulatory affairs experience supporting IVD manufacturers through QMSR readiness assessments.

Key point: ISO 13485 certification does not equal QMSR compliance. FDA-specific requirements remain fully enforceable, and under QMSR, inspectors now access records they previously could not.

Why the FDA QMSR Matters Beyond the February 2026 Deadline

The February deadline was the starting point, not the finish line. FDA’s Compliance Program 7382.850 is now the active inspection model. Manufacturers operating under the assumption that QMSR readiness was a one-time transition exercise are exposed to a different enforcement environment than the one they prepared for.

Under the former QSR model, inspections used QSIT subsystem checklists. Under QMSR, investigators evaluate how quality processes function as an integrated lifecycle framework, not whether each subsystem satisfies an individual checklist. That structural shift changes what inspectors look for and what they find.

Inspection change: FDA inspectors can now access internal audit reports, management reviews, and supplier audits. Under the previous QSR model, these records were largely outside inspection scope. Many manufacturers are unaware of this shift and have not reviewed the quality or completeness of these documents with inspection readiness in mind.

MDSAP Audit Approach 2026: How It Differs from FDA Inspections Under QMSR

MDSAP audits and FDA inspections serve fundamentally different regulatory functions and must not be conflated.

An MDSAP audit is conducted by an FDA-recognized Auditing Organization. It assesses conformity with harmonized quality management system requirements — ISO 13485 and the regulatory requirements of participating authorities including FDA. It is scheduled, structured, and conformity-focused. Participation remains voluntary.

An FDA inspection is a statutory enforcement activity conducted directly by FDA investigators. Its objective is not certification — it is the evaluation of compliance with US legal requirements and the identification of potential violations, systemic weaknesses, or public health risks.

MDSAP auditFDA inspection (CP 7382.850)
Conformity-focusedCompliance-driven and enforceable
Scheduled and structuredRisk-based, for-cause, or routine
Bound by MDSAP task structureNot limited by MDSAP scope or sampling
Outcome: certification reportOutcome: Form 483 / warning letter / no action
Internal records may not be reviewedInternal audits, supplier audits, management reviews now in scope

Strong MDSAP performance may influence FDA surveillance planning. It does not eliminate the possibility of inspection, nor does it guarantee a favourable outcome when one occurs.

Common Assumptions That Increase Inspection Risk

Several structural misconceptions remain widespread. Under QMSR, these assumptions translate directly into inspection exposure.

  • «MDSAP replaces FDA inspections.» It informs surveillance planning. It does not limit FDA’s statutory authority.
  • «If the MDSAP auditor didn’t find it, FDA won’t pursue it.» FDA investigators are not constrained by MDSAP audit depth or task sequencing.
  • «ISO 13485 certification ensures FDA compliance.» ISO 13485 is incorporated by reference into QMSR, but FDA-specific requirements — UDI, MDR, device listing, labeling controls — remain fully enforceable and are not covered by ISO 13485 alone.
  • «QMSR was a documentation update.» For ISO-certified manufacturers, many gaps are substantive — missing FDA-required record content, incomplete UDI integration, absent MDR linkage — not cosmetic.

QMSR vs QSR vs ISO 13485: What Actually Changed

QMSR incorporates ISO 13485:2016 by reference into US law. That is a structural alignment, not a reduction in FDA enforcement authority. Obligations related to UDI, MDR, device listing, and labeling controls continue to apply in full.

ElementFormer QSR (21 CFR 820)FDA QMSR (2026)ISO 13485:2016
Legal statusUS regulationUS regulation (ISO 13485 incorporated by reference)International standard
Inspection modelQSIT subsystem checklistsCP 7382.850 — lifecycle, risk-basedCertification audit
Internal audit accessLimited under §820.180(c)Internal audits and management reviews reviewableAuditor access at certification
CAPA focusCumplimiento procedimentalDemonstrated effectiveness + root cause verificationEffectiveness required
FDA-specific requirementsTotalmente integradosUDI, MDR, labeling still fully enforceableNo incluidos

Takeaway: ISO 13485 alignment does not eliminate FDA-specific compliance obligations. A manufacturer can hold ISO 13485 certification and still have substantive QMSR gaps.

FDA Compliance Program 7382.850: How Inspections Work

As of 2 February 2026, FDA retired QSIT and implemented Compliance Program 7382.850. Inspections are now organised around six integrated QMS areas and four Other Applicable FDA Requirements (OAFRs).

Six QMS areasFour OAFRs
Change ControlUnique Device Identification (UDI)
Design & DevelopmentMedical Device Reporting (MDR)
Management OversightCorrections & Removals
Outsourcing & PurchasingTracking
Production & Service Provision
Measurement, Analysis & Improvement

Under this model, FDA evaluates how quality subsystems operate as an interconnected framework — not as isolated elements. Inspectors assess whether risk information, design decisions, post-market data, and management oversight are aligned throughout the product lifecycle.

The Four Areas That Almost Always Reveal Gaps

Across QMSR gap assessments conducted on IVD and medical device manufacturers, four areas surface as gaps with consistent regularity — even in organisations that have maintained ISO 13485 certification for years.

1. Complaint handling and servicing records

Many companies aligned with ISO 13485 underestimate the level of record detail FDA expects. Under QMSR, complaint and servicing records must include specific, enumerated data fields that ISO 13485 does not explicitly define. Records are often incomplete from an FDA perspective even when they satisfy the certification standard.

2. UDI traceability and record integration

UDI compliance is not simply a matter of having a UDI assigned and registered in GUDID. QMSR requires the UDI to be consistently recorded across multiple record types: complaints, servicing records, and batch or device history records. That level of cross-system integration is frequently missing — particularly in manufacturers who completed UDI registration without reviewing how UDI flows through their quality records.

3. Labeling and packaging controls

FDA maintains specific requirements for label content — including UDI, expiry dates, and handling instructions — and expects documented procedures designed to ensure accuracy and prevent mix-ups. These requirements are often handled informally or through processes that do not meet FDA’s explicit documentation expectations, even when the labels themselves are technically correct.

4. Linkage between ISO processes and FDA regulatory requirements

This is the gap that most consistently surprises ISO-certified organisations. A company may have complaint handling aligned with ISO 13485 clause 8.2.2 and consider that requirement closed — but fail to explicitly connect that process to Medical Device Reporting obligations under 21 CFR Part 803. FDA does not treat ISO conformity as a substitute for regulatory linkage. Each process must demonstrably connect to the applicable FDA requirement in the documentation.

«Companies often assume that having a robust ISO-aligned procedure is sufficient. What we find in practice is that the procedure exists — but there is no explicit documented connection between that procedure and the FDA-specific obligation it is meant to fulfil. That gap is invisible until an inspector asks for it.»

Joana Martins, QA/RA Specialist, MDx CRO

Why QMSR Gap Analysis Is More Complex for IVD and CDx Manufacturers

ISO 13485 and QMSR do not formally distinguish between device types. However, the nature of IVDs fundamentally changes which gaps are most consequential and how difficult they are to close.

Ilustración del proceso de inspección de la FDA que enfatiza los sistemas de gestión de la calidad, las auditorías basadas en riesgo y la preparación del fabricante en la industria MedTech.

A QMSR gap analysis for an IVD manufacturer must extend beyond traditional quality system elements. It needs to integrate scientific validity, analytical performance, and clinical evidence into the assessment framework. Where a general medical device gap analysis evaluates whether a product is designed, manufactured, and controlled to ensure safety and functional performance, an IVD-focused analysis must additionally verify that the product generates clinically reliable results under real-world biological variability.

AreaGeneral medical deviceIVD / CDx — additional complexity
Design controlsUser needs, design inputs, outputs, V&VIntended use, specimen type, analyte definition, performance claims must link to analytical and clinical data
Risk managementDevice failure modesMust also cover false positive and false negative results, diagnostic decision risks, interfering substances, matrix effects
Production controlsProcess validation, specificationsLot-to-lot variability of biological materials must be validated against clinically relevant performance criteria
Post-market surveillanceComplaint handling, MDRMust detect performance drift — shifts in sensitivity or specificity — not just product failures
Purchasing controlsSupplier qualificationSupplier variability can directly affect assay performance outcomes

«For IVDs, failures may not manifest as product defects — they manifest as clinically incorrect results. That is a more insidious form of non-compliance, and it means the risk management and design control documentation needs to work harder than it does for a general medical device.»

Joana Martins, QA/RA Specialist, MDx CRO

What FDA Is Finding in QMSR Inspections: Warning Letter Patterns

Recent warning letters issued by CDRH following QMSR inspections show a consistent pattern. Deficiencies are not isolated — they are interconnected, reflecting a failure to operate an effective integrated quality system rather than individual documentation gaps.

Finding categoryMost common deficiency pattern
CAPAProcedures not defined or inadequate; failure to investigate root causes; CAPAs not verified for effectiveness
Complaint handlingComplaints not properly documented or evaluated; failure to assess whether complaints are reportable under MDR; no complaint trending or statistical analysis
Design controlsLack of design verification and validation; poor documentation of design changes and their impact; no design and development plan or procedure
Supplier controlsLack of defined quality requirements that suppliers must meet; no risk-based audit justification
Process validationManufacturing processes not validated; no revalidation after changes; validation protocols incomplete or not scientifically justified
Management responsibilityManagement not actively involved in QMS; no effective management review with documented decisions and follow-up

Important: The FDA has clarified that if previous inspections were conducted under the QS Regulation (prior to 2 February 2026), any corrective actions proposed or implemented must now be pursued pursuant to QMSR requirements — not the former QSR standard.

What FDA Inspectors Scrutinize Most

Based on regulatory inspection support experience, three documentation areas present heightened exposure under QMSR.

1. Internal audits, supplier audits, and management review records

Under QMSR, FDA inspectors may review internal audit reports, supplier audit outcomes, and management review records. Investigators evaluate whether quality processes function effectively in practice — not merely whether procedures formally exist. Records must clearly demonstrate identified issues, root cause analysis, corrective actions, and documented closure. Incomplete or draft audit records increase inspection risk.

2. Design controls and traceability (ISO 13485 clause 7.3)

Manufacturers must demonstrate full traceability across user needs, design inputs, design outputs, verification and validation, and residual risks. Traceability weaknesses frequently arise at the interfaces between risk management files, labeling claims, UDI triggers, and MDR criteria. For companion diagnostics, this alignment is especially critical because intended use, biomarker claims, and clinical evidence directly impact regulatory risk classification.

3. CAPA and effectiveness verification

CAPA remains one of the most enforcement-sensitive areas under QMSR. The most common weakness is the absence of documented effectiveness verification following corrective actions. Closing a CAPA administratively — marking it complete without objective evidence that the root cause was eliminated — is insufficient. Investigators expect evidence demonstrating that actions prevented recurrence.

Inspection Risk Indicators

Risk areaTypical vulnerability
CAPAProblemas repetidos sin verificación de eficacia documentada
Design controlsTrazabilidad incompleta entre el análisis de riesgos y las entradas de diseño
Management reviewActas sin decisiones, métricas o acciones de seguimiento documentadas
Supplier oversightNo risk-based justification for audit scope; missing quality requirements for suppliers
Post-market surveillanceTendencias de quejas no vinculadas a CAPA ni a actualizaciones de diseño
UDINot consistently recorded across complaints, servicing records, and device history records
MDR linkageComplaint handling procedures not explicitly connected to MDR reporting obligations

How to Conduct a QMSR Gap Analysis: Process and Timeline

ISO 13485 certification does not automatically confirm FDA QMSR compliance. A structured gap analysis identifies the regulatory overlays and inspection exposure points that ISO conformity alone leaves unaddressed.

What a QMSR gap analysis covers

A thorough assessment works through four stages:

  1. Clause mapping: Map ISO 13485 clauses to QMSR references. Confirm terminology alignment. Identify where the QMSR adds FDA-specific requirements beyond the ISO standard.
  2. FDA-specific overlay identification: Verify explicit incorporation of UDI requirements across all applicable record types, MDR reporting triggers and their linkage to complaint handling, labeling obligations under 21 CFR Part 801, and device listing and registration controls.
  3. Documentation exposure review: Assess internal audit completeness and whether records are inspection-ready, CAPA effectiveness evidence, management review decision traceability, and supplier risk classification and audit justification.
  4. Risk prioritisation and remediation planning: Each gap is assessed for potential impact on quality, business continuity, and regulatory standing. Higher-risk gaps — those most likely to generate Form 483 observations or warning letters — are prioritised for remediation with assigned ownership and timelines.

How long does it take?

A gap analysis typically takes 4–6 weeks, provided documentation is made available at the outset. Implementation of corrective actions depends on the number and severity of findings and on the responsiveness of the internal team.

For manufacturers with both QMSR and ISO 13485 gaps, implementation may take 4–5 months. Where gaps are limited to QMSR-specific requirements in an otherwise ISO-aligned system, the timeline is typically shorter.

The ISO 13485 certification gap — what ‘compliant’ actually means

A persistent scenario in QMSR readiness work: a manufacturer holds ISO 13485 certification, has documented procedures that appear robust, and believes ISO alignment is sufficient. Gaps emerge in missing FDA-required data fields in records, incomplete UDI implementation, and failure to link ISO processes to FDA regulatory requirements.

They are structurally compliant with ISO but not fully aligned with FDA expectations. The distinction matters: an FDA inspector is not evaluating conformity to a certification standard. The inspector is evaluating compliance with US law and assessing whether the quality system actually functions as an integrated framework.

Gestión de la calidad y proceso de inspección de productos sanitarios con formación de equipos, revisión basada en datos y narrativas de inspección para el cumplimiento con la FDA.

Practical Implications for Manufacturers

Inspection scope may be data-driven. FDA may use pre-inspection data reviews to target areas of concern, increasing scrutiny where trends or inconsistencies are identified.

FDA inspectors are evaluating how quality processes work together in practice — not whether each subsystem satisfies a checklist in isolation.

Previously internal records are now fair game. Internal audit reports, supplier audit outcomes, and management review records may be reviewed. These documents must reflect issues identified, decisions made, and actions taken.

Risk management must be continuous and demonstrable. FDA expects risk to be actively monitored and linked to CAPA, design changes, supplier controls, and post-market surveillance — not treated as a static exercise.

Post-market data is a primary inspection focus. Complaint trends, MDR, recalls, UDI, and tracking data are increasingly used to assess whether the quality system is effective and responsive.

Cómo MDx apoya la preparación para la FDA QMSR: visión experta

La transición de QSR a FDA QMSR requiere más que actualizar la terminología. Exige alineación estructural y preparación orientada a inspecciones.

Basándose en la experiencia de campo apoyando a fabricantes en la preparación para inspecciones y en proyectos de alineación regulatoria, Joana Martins, especialista en QA/RA en MDx, destaca que las vulnerabilidades más frecuentes no provienen de procedimientos ausentes, sino de una eficacia del sistema insuficientemente demostrada.

Según la experiencia de Joana en preparación para inspecciones, las organizaciones suelen subestimar tres puntos de exposición durante la preparación para inspecciones de la FDA:

  • La profundidad de la revisión de documentación ahora permitida bajo la QMSR
  • La necesidad de trazabilidad entre la gestión de riesgos, los controles de diseño y los datos poscomercialización
  • La importancia de la verificación documentada de la eficacia dentro de los sistemas CAPA

Para abordar estos puntos de exposición, MDx apoya a los fabricantes de productos sanitarios mediante:

  • Evaluaciones independientes de preparación alineadas con QMSR, centradas en la exposición durante inspecciones
  • Análisis estructurados de brechas de la QMSR que incorporan añadidos regulatorios específicos de la FDA
  • Inspecciones simuladas de la FDA alineadas con el Compliance Program 7382.850
  • Apoyo estratégico para empresas que desarrollan diagnósticos complementarios de la FDA, donde la trazabilidad del diseño, los controles de etiquetado y la integración de datos del ciclo de vida requieren una coherencia regulatoria reforzada

En lugar de abordar la FDA QMSR como una actualización documental, MDx trabaja con las organizaciones para garantizar que sus sistemas de calidad demuestren integridad operativa, toma de decisiones basada en riesgo y resiliencia ante inspecciones.

Las organizaciones que se preparan para una inspección de la FDA o evalúan su alineación con la QMSR pueden beneficiarse de una evaluación temprana y estructurada. La evaluación proactiva reduce los plazos de remediación, minimiza la interrupción por inspecciones y refuerza la confianza regulatoria.

Preguntas frecuentes sobre la FDA QMSR, MDSAP y las inspecciones

¿Cuál es la principal diferencia entre QSR y QMSR?

La principal diferencia es la alineación estructural. Bajo QSR, los requisitos de la FDA estaban redactados directamente en 21 CFR Part 820. Bajo QMSR, la FDA incorpora ISO 13485:2016 por referencia a la legislación estadounidense, manteniendo vigentes las obligaciones específicas de la FDA. En resumen, la QMSR armoniza la estructura con la ISO 13485. Sin embargo, no reduce la autoridad de aplicación de la FDA ni elimina requisitos específicos de EE. UU. como MDR, UDI o el registro/listado de dispositivos.

¿La certificación ISO 13485 garantiza el cumplimiento con la FDA bajo la QMSR?

No. Aunque la ISO 13485 constituye la base de la QMSR, los requisitos legales específicos de la FDA siguen aplicándose. Los fabricantes deben cumplir con MDR, correcciones y retiradas, UDI y otras obligaciones de EE. UU. Según la experiencia regulatoria, las empresas suelen asumir que la certificación ISO cierra todas las brechas. En la práctica, es necesaria una evaluación de brechas de la QMSR específica para confirmar la alineación completa con la FDA.

¿Qué sustituyó a QSIT en las inspecciones de la FDA?

La FDA sustituyó QSIT por el Compliance Program 7382.850, con efecto el 2 de febrero de 2026. Este nuevo programa alinea las inspecciones con el marco de la QMSR. En lugar de listas de verificación por subsistemas, la FDA ahora organiza las inspecciones en torno a seis áreas del QMS y cuatro Other Applicable FDA Requirements (OAFR). Como resultado, las inspecciones siguen un enfoque más integrado, basado en riesgo y centrado en el ciclo de vida.

¿Puede la FDA inspeccionar informes de auditoría interna bajo la QMSR?

Sí. Bajo la QMSR, los investigadores de la FDA pueden revisar informes de auditoría interna, auditorías de proveedores y registros de revisión por la dirección.
En la práctica, los inspectores ahora verifican si las incidencias se identificaron, documentaron y cerraron de forma efectiva. Ya no se centran solo en si existen procedimientos; evalúan si el sistema funciona según lo previsto.
Las acciones de auditoría incompletas o no verificadas pueden aumentar el riesgo de inspección.

¿Qué registros están recibiendo ahora mayor escrutinio durante las inspecciones de la FDA?

La FDA ahora pone mayor escrutinio en:
– Informes de auditoría interna y de proveedores
– Documentación de revisión por la dirección
– Registros de trazabilidad de controles de diseño
– Procedimientos CAPA y comprobaciones de eficacia
Según la experiencia en inspecciones, la verificación de eficacia de CAPA es un punto débil frecuente. Las empresas suelen implementar acciones correctivas, pero no documentan evidencia objetiva de que la acción resolvió la causa raíz.
Bajo la QMSR, la eficacia importa tanto como la documentación.

¿Por qué las empresas que superaron MDSAP siguen recibiendo observaciones FDA 483?

Porque MDSAP y las inspecciones de la FDA tienen finalidades distintas. MDSAP evalúa la conformidad. Las inspecciones de la FDA evalúan el cumplimiento legal y el riesgo para la salud pública. Los investigadores de la FDA no están sujetos a los métodos de muestreo ni al alcance de auditoría de MDSAP. Si los inspectores identifican CAPA ineficaz, trazabilidad débil o brechas entre los procedimientos y la práctica real, pueden emitir observaciones en el Formulario 483, incluso tras una auditoría MDSAP satisfactoria.

¿Cómo deberían prepararse los fabricantes para las inspecciones de la FDA bajo la QMSR?

Empiece pronto. La preparación suele llevar más tiempo del esperado. Después, realice una evaluación estructurada de brechas de la QMSR. El cumplimiento con ISO 13485 por sí solo no confirma la alineación completa con la FDA. Por último, forme a los equipos en el Compliance Program 7382.850. Las entrevistas simuladas y las simulaciones de inspección ayudan a identificar debilidades. Incluso una remediación documentada en curso demuestra control del sistema y reduce el riesgo de inspección.

¿Cuándo comienza la aplicación de la FDA QMSR?

La aplicación de la FDA QMSR comenzó el 2 de febrero de 2026, cuando la nueva Quality Management System Regulation sustituyó oficialmente a la anterior Quality System Regulation (21 CFR Part 820). A partir de esa fecha, las inspecciones de la FDA operan bajo el Compliance Program 7382.850.

¿Cuáles son los requisitos de armonización entre la FDA QMSR y la ISO 13485 para 2026?

Bajo la QMSR de 2026, la ISO 13485:2016 se incorpora por referencia a la legislación estadounidense. Esto significa que los fabricantes deben cumplir los requisitos de la ISO 13485 como parte del cumplimiento con la FDA. Sin embargo, la armonización no es una equivalencia completa: las obligaciones específicas de la FDA, como UDI, notificación MDR, registro/listado de dispositivos y controles de etiquetado, siguen siendo plenamente exigibles y no están cubiertas únicamente por la ISO 13485. Consulte la tabla comparativa QSR vs QMSR vs ISO 13485 anterior para un desglose detallado.

Escrito por:

Joana Martins

ISO 13485 Quality Management Systems (QMS) Regulatory Affairs

Joana Martins es especialista en control de calidad y asuntos regulatorios, con más de 10 años de experiencia en dispositivos médicos, gestión de la calidad y desarrollo de productos. Está especializada en sistemas de gestión de la calidad según la norma ISO 13485, requisitos regulatorios de la FDA, documentación técnica, gestión de riesgos y actividades… Leer más…

Ver el perfil del autor
Industry Insights & Regulatory Updates