Direct Answer. A customer satisfaction procedure is the documented process by which an organization decides what customer perception it will measure, against what promise, from whom, how often, and what happens to the result. ISO 9001 Clause 9.1.2 requires the monitoring of customer perception of the degree to which needs and expectations have been fulfilled — which means a customer satisfaction procedure has to name the comparison basis. ISO 13485 asks a different question entirely, and under the FDA Quality Management System Regulation a device organization carries record and reporting obligations that no clause checklist derived from the standard alone will surface.
The customer satisfaction procedure is one of the few documented processes in a quality management system that almost never produces a finding and almost never produces a surprise. The survey goes out. The score comes back somewhere between four and four and a half out of five. It gets a slide in management review, the slide says the number held, and the meeting moves on. Nothing is wrong. Nothing is learned either. A customer satisfaction procedure can run for years in exactly that state.
Then the complaint log comes up two agenda items later, from a different owner, and it does not agree. The complaints are about delivery dates. The survey never asked about delivery dates. Both documents are accurate, both were produced by people doing their jobs properly, and the organization has no mechanism for noticing that they describe different companies.
That gap is not carelessness, and it is not a failure of the customer satisfaction procedure as written. It is structural, and it is the subject of this article. Across 200+ audits attended in 28 years, MSI consistently sees satisfaction measurement land among the areas where a system is technically conforming and practically inert — a first-party observation from MSI's own audit-attended history rather than a published industry statistic, and worth stating plainly because the pattern is so stable. What follows is what ISO 9001 actually asks, what ISO 13485 asks instead, what the regulation adds on top of both, and what a customer satisfaction procedure has to contain to be worth the effort of writing it.
Section 1 · The clause itself
What ISO 9001 Clause 9.1.2 Actually Asks of a Customer Satisfaction Procedure
Define. Measure. Act.
Clause 9.1.2 of ISO 9001:2015 — the clause a customer satisfaction procedure exists to discharge — is three sentences long. It requires the organization to monitor customers' perception of the degree to which their needs and expectations have been fulfilled, to determine the methods for obtaining, monitoring and reviewing that information, and it offers examples of what those methods might be — surveys, delivery performance data, market share analysis, warranty claims, dealer reports, compliments and complaints.
Three words in that clause do most of the work, and a customer satisfaction procedure that skips any of them will produce a number that cannot be used.
Perception. Not performance. The clause asks what the customer believes, which is why a customer satisfaction procedure resting on on-time delivery data alone does not satisfy it. An organization can ship every order on the promised date and still have a customer who believes delivery is unreliable, because the promised date was renegotiated four times before it was met.
Degree. Not a binary. A degree implies a scale, and a scale implies endpoints. What does full fulfillment look like, and what does zero look like? A customer satisfaction procedure that leaves the endpoints unstated produces a number nobody can interpret.
Fulfilled. This is the load-bearing word, and it is the one that gets skipped. Fulfillment is always relative to something. The standard does not say what that something is, because it cannot — the comparison basis is specific to the organization. So the organization has to decide, and that decision is the single most consequential thing a customer satisfaction procedure does.
Direct Answer. ISO 9001 Clause 9.1.2 requires a customer satisfaction procedure to monitor customer perception of the degree to which needs and expectations have been fulfilled, and to define the methods for obtaining, monitoring and reviewing that information. The clause does not prescribe a survey, a score, or a frequency. It does require the organization to determine the methods — and determining a method means stating what perception is being compared against.
Worth naming the flexibility here, because organizations routinely overbuild. Nothing in Clause 9.1.2 requires an annual survey instrument. Complaint volume by category, warranty claim rate, repeat order rate, and structured account-review notes are all listed methods, and a customer satisfaction procedure built entirely from those is fully conforming. The survey is a convention, not a requirement. MSI's related work on continual improvement under ISO 9001 covers how Clause 9.1 evidence feeds the improvement chain, and the wider view of what a quality director does with customer signal sets out why weekly flow beats an annual snapshot.
Section 2 · The requirement almost nobody implements
The Comparison Basis: The Decision Almost No Customer Satisfaction Procedure Makes
Against. What. Exactly.
Fulfillment is relative. Relative to what? Every customer satisfaction procedure answers that question, and most answer it by accident. There are at least four defensible answers, and they produce different numbers from the same customers in the same quarter.
- The contract. Did we deliver what we agreed to deliver, on the terms we agreed? Objective, auditable, and often the least interesting answer, because contractual conformity is table stakes.
- The promise we made in the sale. Not the contract — the thing the salesperson said that made the customer choose us. Lead time. Responsiveness. A named contact. This is frequently where dissatisfaction actually lives.
- The alternative they could have bought. Satisfaction relative to the competitor they did not choose. Hard to measure, extremely predictive of retention.
- Their own prior experience of us. A four-out-of-five from a customer who used to give five is a different event from a four-out-of-five from a new customer, and an aggregate score erases the distinction.
Very few organizations choose, and very few customer satisfaction procedure documents record the choice. Not because they are careless, but because the question is never put in front of them. The sequence runs like this, and it is worth tracing because every step is reasonable on its own.
The clause asks for perception, so the organization reaches for a perception instrument — a survey. That is a sound first move. Survey platforms ship with default question sets built around delivery and responsiveness, because those are easy to ask about and easy to score. Nothing in the purchase, the configuration, or the annual run of that tool ever asks against what. The question is not on any screen. So the survey measures whatever it happens to ask, the score is stable, and it is stable precisely because it is asking about the thing the organization is already good at. None of that is visible from inside the customer satisfaction procedure itself.
Meanwhile the complaints are about something else, and they sit with a different function, reported into a different section of a different meeting. The tell is simple and diagnostic: the complaint log and the satisfaction score have never appeared on the same page. Where an organization does put them side by side, the two frequently disagree — and the disagreement is the most useful finding available anywhere in the performance evaluation clause.
Naming the comparison basis costs one paragraph in the customer satisfaction procedure and changes what every subsequent question is for. It also makes the instrument arguable, which is the point — a basis someone can disagree with is a basis someone can improve. MSI's work on multi-site procedure standardization makes the same argument about definitional questions generally: when the clock starts, what counts, and against what are decisions that have to be made once, centrally, or they get improvised differently everywhere.
The decisions, already made
Twenty-eight years of judgment calls, written down and editable
Most procedure templates restate the clause and stop — which leaves you making every hard decision yourself, which is the reason you wanted a template. MSI's ISO Procedure Templates and Guides library does the opposite: the comparison basis is named, the response-rate floor is set, the escalation criteria are written, and every bracketed placeholder marks a value that is genuinely yours to choose. Editable Word, worked examples, registers, and a four-level maturity ladder you can score yourself against.
Section 3 · Who answered
Response Rate and the Quiet Middle
Count. Compare. Correct.
A satisfaction score is a statement about the people who answered. Whether it is also a statement about the customer base depends entirely on whether those two populations look alike, and almost nothing in a standard survey workflow tests that. A customer satisfaction procedure has to test it deliberately or not at all.
Response is not random. It is bimodal by temperament: the delighted answer and the furious answer. The quiet middle — the accounts that are mildly dissatisfied, not enough to complain, entirely capable of leaving — is the group least likely to respond and most likely to matter commercially. A customer satisfaction procedure that reports only the aggregate has systematically excluded the population whose behavior it most needs to predict.
Three controls fix most of this, they belong in the customer satisfaction procedure rather than in the survey tool, and none of them requires new software.
- Report the response rate alongside the score, always. A score without a denominator is not a measurement. Put them in the same cell if necessary.
- Compare the responding population to the served population on whatever segmentation actually drives your business — revenue band, product line, region, account age. If the top decile of revenue is under-represented, the number is describing someone else.
- Define a second route for non-responders before you need it. A structured five-minute call from someone who is not the account owner reaches a different population than an email link, and it is the only practical way to hear the quiet middle.
Set the floor in the customer satisfaction procedure, not in the moment. A rule that reads “below a thirty percent response rate, or below fifty percent coverage of the top revenue decile, the result is reported with a stated limitation and the secondary route is deployed” converts a judgment call under time pressure into a decision made once, in calm conditions, by the people best placed to make it.
Section 4 · The device side
What ISO 13485 Asks Instead — and Why It Is Different
Met. Not liked.
This is the section that saves device organizations the most money, and it is a single sentence: ISO 13485 does not require customer satisfaction measurement.
Clause 8.2.1, Feedback, requires the organization to gather and monitor information on whether it has met customer requirements. Met. That is an objective conformity question, answerable from complaint records, servicing records, returns, nonconformity data, and post-market surveillance. There is no clause requiring a survey. There is no clause requiring a score. An assessor will not ask for either, and a device organization that has built one has bought something real but has not bought compliance with anything.
Direct Answer. No — ISO 13485 does not require a customer satisfaction procedure in the ISO 9001 sense. Clause 8.2.1 requires a documented feedback process that gathers information on whether customer requirements have been met, and Clause 8.2.2 requires a documented complaint-handling process. Measuring satisfaction for commercial reasons is entirely legitimate; presenting a satisfaction score as evidence of Clause 8.2.1 conformity is not, because the clause asks a conformity question rather than a perception question.
This matters most in organizations running both standards. The assumption that the requirement carries across is intuitive and wrong, and it results in a satisfaction program on the device side that costs real money, consumes real quality resource, and buys no regulatory or certification benefit at all. Keep it if the commercial case stands on its own. Do not defend it on clause grounds, and do not let it displace the feedback process the customer satisfaction procedure actually has to describe.
One further point of structure, because it is regularly misstated. ISO 13485 predates the harmonized ten-clause structure and does not share it with ISO 9001, ISO 14001 or ISO 45001. Its numbering is its own, its clause logic is its own, and a mapping table that assumes alignment will lose requirements. Relatedly: ISO 13485:2016 was not covered by the February 2024 climate change amendment that added text to Clauses 4.1 and 4.2 of ISO 9001, ISO 14001 and ISO 45001. If someone has told you every standard received the same insertion, that is not correct for this one. MSI's ISO 13485 gap analysis guidance walks the clause-by-clause scoring, and the ISO procedure order article covers which documents to write first so the set interlocks rather than cross-references.
Section 5 · The missing connection
Feedback Into Risk Management: The Sentence Everyone Reads and Nobody Wires
Rate. Not record.
ISO 13485 Clause 8.2.1 also requires that the information gathered serve as a potential input into risk management. One sentence — and in MSI's experience it is the most commonly missing connection in a device quality system and the most commonly missing paragraph in a device customer satisfaction procedure.
Again, the reason is structural rather than negligent, and the shape of it is worth setting out precisely.
- The complaint file and the ISO 14971 risk management file are both maintained, both accurate, and read by different people for different reasons on different cycles.
- Each individual complaint is investigated properly and closed on time. No single complaint is alarming, and none of them should be.
- The signal is in the rate, not in any one record. An occurrence estimate in the risk file was set at design time; the complaint log is the only place the real-world occurrence rate exists. Only a scheduled comparison surfaces a divergence.
- The two documents frequently have no common key. The complaint log uses one vocabulary for failure modes and the risk file uses another, so the comparison cannot be performed even by someone who genuinely wants to perform it.
The fix is two lines in the customer satisfaction procedure and one column of data. Give the complaint log a failure-mode field whose picklist is drawn from the risk file's hazard list. Schedule the comparison — quarterly is typical, and it belongs on a named calendar with a named owner rather than in an intention. Then state the trigger: what divergence between estimated and observed occurrence causes the risk file to be revisited, and who has authority to open it. MSI's risk management procedure guidance for ISO 9001 and ISO 13485 covers how that register is structured, and the medical device cybersecurity pillar shows the same routing applied to vulnerability reports arriving through the feedback channel.
Every complaint closed correctly, every record accurate, every deadline met — and the occurrence estimate that justified the residual risk has not been checked against reality in four years. That is a compliant system producing an uninformed decision.
Section 6 · The regulatory clock
Reportability Runs on Its Own Clock
Aware. Assess. Report.
This is the most consequential structural error in device complaint handling, and an organization can commit it while following its own customer satisfaction procedure exactly.
Under 21 CFR 803.50(a), a manufacturer must report no later than thirty calendar days after the day it receives or otherwise becomes aware of information, from any source, reasonably suggesting that a marketed device may have caused or contributed to a death or serious injury, or has malfunctioned in a way that would be likely to do so if the malfunction recurred. Five working days applies where a reportable event necessitates remedial action to prevent an unreasonable risk of substantial harm to public health, or where FDA has made a written request.
Read the trigger carefully. The clock starts at awareness of information that reasonably suggests — not at the conclusion of the investigation, not at the point the root cause is confirmed, not when the complaint is closed. And Part 803 defines that awareness broadly: a manufacturer is considered aware when any of its employees becomes aware of a reportable event. Not the complaint handler. Not the regulatory affairs lead. Any employee — including the field service technician who heard it on site and the sales representative who was copied on the email.
Now consider the ordinary, well-intentioned customer satisfaction procedure: receive, log, investigate, determine root cause, then assess reportability against the findings. It reads as diligence. It is also a design in which the reporting decision is made downstream of an investigation that routinely takes longer than thirty days — and it will file late on exactly the complaints that mattered most, because the serious ones take longest to investigate.
The reportability assessment is not a conclusion of the investigation. It is a parallel process that starts at intake, runs on its own clock, and is documented whichever way it comes out. A decision recorded as “not reportable, and here is why” is as much a required record as the report itself.
Four provisions belong in the customer satisfaction procedure to make that real. A day-zero definition that ties to first employee awareness rather than to the log entry, with the log capturing both dates so the interval between them is visible. A named decision-maker and a named alternate, because a single point of failure on a thirty-day clock is not a control. A documented not-reportable determination with its rationale. And an explicit reassessment trigger, since information arriving later can make a previously non-reportable event reportable.
The training implication follows directly, and it reaches well beyond the people who own the customer satisfaction procedure. If any employee's awareness starts the clock, then every employee who touches a customer needs to be able to recognize the trigger and knows where to send it within one working day. That is an awareness obligation, not a complaint-handling one, and it is the reason field service and sales belong in the training matrix for this procedure. This is exactly the sort of pattern MSI's QMS interviews course prepares people to describe in their own words — and being able to describe it is the practical test of whether it is embedded.
Advisory notices sit in a separate lane again. 21 CFR 820.10(b)(4) requires advisory notices to be handled in accordance with Part 806, whose criteria are different from those of Part 803. An event can be reportable under one and not the other, or under both. A customer satisfaction procedure for a device organization that treats these as a single question will get one of them wrong.
Section 7 · What the regulation adds
The Records the QMSR Requires That the Standard Does Not
Seven. Fields. Exactly.
Since February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference and is titled the Quality Management System Regulation. The consequence for any device customer satisfaction procedure is that three obligations attach which appear on no clause checklist derived from the standard alone. MSI covered the transition in detail in its analysis of the QMSR and ISO 13485 alignment; the summary below is the complaint-specific slice, verified against the current eCFR text.
| Obligation | Source |
|---|---|
| Seven specified fields on qualifying complaint records, plus records of review, evaluation and investigation, plus a documented justification where a similar complaint means no new investigation is performed | 21 CFR 820.35(a) |
| Notify FDA of complaints meeting the reporting criteria of Part 803 | 21 CFR 820.10(b)(3) |
| Advisory notices handled in accordance with Part 806 — a separate question from Part 803, with different criteria | 21 CFR 820.10(b)(4) |
The seven fields a customer satisfaction procedure has to produce, taken directly from 820.35(a), are the device name; the date the complaint was received; any unique device identifier or universal product code and any other device identification; the complainant's name, address and phone number; the nature and details of the complaint; any correction or corrective action taken; and any reply to the complainant. They apply to complaints reportable under Part 803, complaints the manufacturer determines must be investigated, and complaints investigated regardless of either requirement.
Direct Answer. Under the QMSR, a device organization's customer satisfaction procedure and its complaint process must together produce seven specified fields on qualifying complaint records under 21 CFR 820.35(a), records of the review, evaluation and investigation, a documented justification wherever a similar prior complaint means no new investigation is performed, and evidence that reportability was assessed against Part 803 and Part 806. The unique device identifier is the field most often captured too late to capture at all.
Two of those seven repay attention in the design of the customer satisfaction procedure. The unique device identifier is perishable — the complainant frequently has the device or its carton in front of them at the moment of first contact and will not have it a day later, so the intake script has to ask for it first rather than last. And the documented justification for not investigating is the one organizations discover they lack: the practice of closing a complaint because “we already looked at this” is expressly permitted by the regulation, but only where the justification is recorded. The habit without the record is the exposure. FDA's QMSR resource page also confirms that CGMP-exempt device manufacturers are not thereby exempt from complaint files or from 820.35 records, which is a distinction some exempt Class I manufacturers read too broadly.
Score your own process first
Find out which of these eight elements your process actually holds
The Customer Satisfaction and Feedback Maturity Check scores your current customer satisfaction procedure across eight elements on a four-level ladder — comparison basis, coverage, routing criteria, reportability timing, risk-file linkage, records, review cadence and ownership. It takes a few minutes, it tells you where you actually sit rather than where you assume you sit, and it names the two moves that would raise you a level.
Section 8 · Worked example A
The Thirty-Dollar Complaint That Carried the Exposure
Value. Versus. Exposure.
A hospital biomedical technician mentions during a routine service visit that the outer carton of a thirty-dollar single-use accessory shows the wrong catalog number. The item inside is correct. Nobody was harmed. Nothing was requested. The technician is not annoyed and does not consider themselves to be complaining.
A customer satisfaction procedure whose triage rule routes on value closes this at receipt. Thirty dollars, no harm, no request — log it, thank them, move on. That rule is defensible, common, and wrong.
A rule that routes on criteria asks a different question: does this concern the possible failure of a device, its labeling, or its packaging to meet a specification? It does. The investigation that follows finds a labeling revision that shipped 2,400 cartons to 78 customers — a mislabeled accessory sitting in customer stores under the wrong identity, in a category where the wrong identity is exactly how the wrong item reaches a patient. The escalation fired on fitness for use, not on value.
Value and exposure are uncorrelated. That is the whole lesson, and it is the reason the routing criterion in a customer satisfaction procedure has to be written as a question about the device rather than a question about the money. MSI makes the same argument about supplier selection in its risk management procedure guidance: a two-dollar connector in a fluid path carries exposure no financial threshold can detect.
There is a secondary point in this example that is easy to miss. The unique device identifier was captured because the technician had the carton in front of them when they mentioned it. Two days later it would have been unobtainable, the record would have been incomplete against 820.35(a)(3), and the 2,400-carton scope question could not have been answered at all. The intake script inside the customer satisfaction procedure did that, not the investigator.
Section 9 · Worked example B
The Score That Disagreed With the Complaints
Who. Answered. Which.
An annual survey returns 4.4 out of 5 from a 34 percent response rate — the best result in three years, and reported as such. In the same period, complaints arriving through informal channels rise from 3 to 19 per quarter.
The instinct is to decide which instrument is lying, and a customer satisfaction procedure that forces that choice has framed the question wrongly. Neither is. Both were working correctly and answering different questions.
The 66 percent who did not respond held 71 percent of the open complaints and 80 percent of the late deliveries. The score was an accurate description of the satisfied minority and said nothing at all about the customer base, because nothing in the workflow ever compared the responding population to the served one. And the rise in informal complaints tracked the rollout of channel training — more complaints were being captured, not more problems being created. A rising complaint count following a capture improvement is a system working, and reading it as deterioration is how good initiatives get cancelled.
Underneath both sat the comparison basis. The survey asked about responsiveness, and responsiveness was strong. The promise customers had actually bought on was delivery to the promised date. The instrument was measuring the thing the organization was already good at, which is what an unexamined default question set does. MSI's article on declining customer satisfaction and internal dysfunction traces how the coordination failure behind that pattern reaches the customer, and the companion piece on dysfunctional company symptoms covers the internal signals that precede it.
Note the difference in shape between the two examples. A is a single event with a hidden consequence. B is an aggregate that concealed its own composition. Both failures are invisible to a well-run customer satisfaction procedure that never asks the second question.
Section 10 · The document itself
What a Complete Customer Satisfaction Procedure Contains
Decide. Document. Deploy.
Sections one through six of any procedure are boilerplate — purpose, scope, references, definitions, responsibilities, records. What separates a customer satisfaction procedure that works from one that merely exists is whether the following decisions have been made in writing rather than left to whoever is running the process this year.
The general-product side
- The comparison basis, named. One paragraph stating what fulfillment is measured against and why, with a date and an owner so it can be revisited rather than inherited.
- The methods, plural. Clause 9.1.2 lists several. A procedure naming exactly one has narrowed itself unnecessarily.
- The response-rate floor and the coverage test, with the secondary route that deploys when either is missed.
- The scheduled comparison against the complaint log, with a stated frequency and a stated owner. This is the single highest-yield line in the document.
- What happens to the result. Which meeting, which agenda item, what threshold triggers action rather than discussion, and who owns the action.
- The review trigger for the instrument itself, so the question set is examined on named events rather than only on the calendar.
The device side, in addition
- The feedback-versus-complaint definition, written so an intake clerk can apply it without escalating, since the boundary decides which regulatory obligations attach.
- Routing criteria expressed as questions about the device, never as a value threshold.
- Day zero defined at first employee awareness, with both dates captured on the record.
- Reportability as a parallel process, with named decision-maker, named alternate, documented not-reportable determinations, and a reassessment trigger.
- Part 806 assessed separately from Part 803.
- The seven 820.35(a) fields present on the intake form, with the unique device identifier asked first.
- The failure-mode picklist drawn from the risk file, plus the scheduled rate comparison and its divergence trigger.
Direct Answer. The customer satisfaction procedure should be owned by the process owner accountable for acting on the result — ordinarily quality, working with commercial — and never by the survey vendor or by whoever happens to hold the platform license. Ownership means authority to change the instrument, not merely responsibility for running it. In a device organization, the reportability decision inside the same process needs its own named owner and a named alternate, because a thirty-day regulatory clock cannot depend on one person's availability.
One structural question that comes up constantly: one customer satisfaction procedure or two, where an organization makes both devices and general product? Two, in most cases — the obligations diverge sharply enough that a single document either buries the regulatory requirements in caveats or applies them to product that does not need them. A shared intake and a shared definitions section, then separate routing. MSI's guidance on procedure-first compliance automation covers why the document has to settle these questions before any software is selected, not after.
Where the result has to land
The agenda, the inputs, and the minutes that prove a decision was made
Satisfaction data is a named management review input under ISO 9001 Clause 9.3.2, and feedback and complaint handling are two of the twelve inputs ISO 13485 Clause 5.6.2 names individually. A review that presents the score and adjourns has met the input half of the requirement and failed the output half. MSI's ISO Management Review Toolkits give you the agenda, the input templates, the decision worksheet, and a minutes format that records decisions rather than attendance — for ISO 9001, ISO 13485, ISO 14001, ISO 45001 and ISO 7101.
Section 11 · Knowing when to stop
Where Organizations Should Stop
Enough. Is. Enough.
Maturity ladders invite a particular mistake, which is treating the top rung as the target, and a customer satisfaction procedure is a common place to make it. It is not, and saying so is the most useful thing in this article for most readers.
Level 2 is a legitimate place to stop. A well-implemented certified process sits somewhere around Level 2 to Level 3 and satisfies the clauses completely. The comparison basis is named, the response rate is reported, the complaint comparison happens on schedule, the result reaches a meeting where decisions get made. That is a conforming, useful, defensible customer satisfaction procedure, and an organization that stops there has not cut a corner. Treating Level 4 as the destination is how improvement programs lose credibility — the effort goes into instrumentation that nobody reads while the basics quietly decay.
There is exactly one exception. Reportability is not a maturity question. Level 1 on the comparison basis is a missed opportunity. Level 1 on reportability timing is a regulatory exposure, and it does not become acceptable because the rest of the system is strong. If the day-zero definition, the named decision-maker, and the documented not-reportable determination are not in place, that is the work — before anything else on the ladder.
The wider principle applies across the whole document set. MSI's calibration maturity model and its guidance on control of monitoring and measuring equipment both make the same case: know which rung you are on, know which rung is enough, and spend the difference somewhere it matters more.
Section 12 · Questions and answers
Customer Satisfaction Procedure FAQ
Ask. Answer. Apply.
What is a customer satisfaction procedure?
A customer satisfaction procedure is the documented process defining what customer perception the organization measures, against what comparison basis, from which customers, how often, and what happens to the result. Under ISO 9001 it discharges Clause 9.1.2. In a device organization it also carries the feedback and complaint obligations of ISO 13485 Clauses 8.2.1 and 8.2.2 and, in the United States, the supplemental record and reporting obligations of the Quality Management System Regulation.
Does ISO 13485 require customer satisfaction measurement?
No. Clause 8.2.1 requires a documented process for gathering and monitoring information on whether customer requirements have been met — an objective conformity question, answerable from complaint, servicing and nonconformity data. No clause requires a survey or a score. Measuring satisfaction for commercial reasons is legitimate; presenting the score as evidence of Clause 8.2.1 conformity is not. Build the customer satisfaction procedure around the conformity question and the score becomes optional.
What is the difference between feedback and a complaint?
Feedback is any information about whether requirements were met, from any source, including praise. A complaint is a communication alleging a deficiency in the identity, quality, durability, reliability, usability, safety or performance of a device after release. The boundary decides which regulatory obligations attach, which is why it belongs in the customer satisfaction procedure written plainly enough for an intake clerk to apply without escalating.
When does the reporting clock start under Part 803?
On the day the manufacturer becomes aware of information reasonably suggesting a reportable event — not when the investigation concludes. Part 803 treats awareness by any employee as awareness by the manufacturer. Thirty calendar days applies to standard reports; five working days applies where remedial action is needed to prevent an unreasonable risk of substantial harm to public health, or where FDA has made a written request.
Do we need one procedure or two if we make both devices and general product?
Usually two customer satisfaction procedure documents, with a shared intake and shared definitions. The obligations diverge far enough that a single document either buries the device requirements in conditional language or applies them to product that does not carry them. Two documents with one front door is generally cleaner than one document with two personalities.
How do we measure satisfaction if our response rate is low?
Stop treating the survey as the primary instrument of the customer satisfaction procedure. Clause 9.1.2 lists complaint data, warranty claims, delivery performance, dealer reports and compliments as legitimate methods, and none of them depends on anyone choosing to respond. Then add one deliberate route for non-responders — a short structured call from someone other than the account owner — and report response rate beside every score you publish.
Does ISO 7101 have an equivalent requirement?
It has a stronger one. ISO 7101, the healthcare quality management standard, requires experience assessment using a validated methodology with a representative sample in which all groups are equitably included, disaggregated analysis across named characteristics, coverage of administrative as well as clinical services, and the sharing of results with external as well as internal stakeholders. None of those has an ISO 9001 equivalent. MSI's overview of the ISO 7101 healthcare quality standard covers the wider structure.
Related reading and matching templates
- ISO 9001 Customer Satisfaction Procedure Template and Guide — the comparison basis, coverage tests and review wiring, already decided and editable.
- ISO 13485 Complaint Handling Procedure Template and Guide — intake fields, routing criteria, reportability timing and the risk-file linkage.
- Combined ISO 9001 and ISO 13485 Customer Feedback and Complaint Handling Template — one intake, two routings, with the divergences identified.
- ISO 13485 management review: the first-time playbook — where feedback and complaint data have to land.
- Management review procedure: why the record must prove it and the step-by-step management review guide.
- ISO 9001 gap analysis and MSI's FDA Voluntary Improvement Program overview.
Talk it through
One call, and you will know which two changes are worth making first
A planning session is a working conversation about your actual process — what you measure, against what, who answers, and where the result goes. No presentation, no pitch. MSI has attended 200+ certification and surveillance audits across 28 years and supported 80+ certifications, and most of what is worth changing in a customer satisfaction procedure turns out to be two or three specific decisions.
Call 760-434-9141
Prefer to start at leadership level? Watch the ISO Executive Decision Briefs — short leadership training videos on what a management system decision actually commits you to. Already certified and want the system maintained year-round? See SureResults. And if you want an experienced pair of eyes on the whole document set, MSI's ISO consulting practice does exactly that.
References and primary sources
- ISO 9001:2015, Quality management systems — Requirements (Clauses 9.1.2, 9.3.2)
- ISO 13485:2016, Medical devices — Quality management systems (Clauses 8.2.1, 8.2.2, 5.6.2)
- ISO 14971:2019, Application of risk management to medical devices
- ISO 10002:2018, Guidelines for complaints handling in organizations
- ISO 10004:2018, Guidelines for monitoring and measuring customer satisfaction
- ISO 7101:2023, Healthcare organization management
- 21 CFR Part 820, Quality Management System Regulation (eCFR)
- 21 CFR 820.35, Control of records — complaint record fields
- 21 CFR 820.10, Requirements for a quality management system — Part 803 and Part 806 links
- 21 CFR 803.50, Manufacturer reporting requirements
- 21 CFR Part 803, Medical Device Reporting — definition of awareness
- 21 CFR Part 806, Reports of corrections and removals
- 21 CFR Part 830, Unique Device Identification
- FDA, Quality Management System Regulation (QMSR)
- 89 FR 7523, Medical Devices; Quality Management System Regulation (final rule)
- ASQ, Customer satisfaction resources
- Global ACI — international accreditation arrangement, effective January 1, 2026
Regulatory citations verified against the current eCFR text on August 7, 2026. Clause references are provided so readers can locate each requirement in their own licensed copy of the relevant standard; the standards themselves are not reproduced. This article is guidance, not legal or regulatory advice.
About the author
Diana Lynn · Management Systems International (MSI)
Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.
msi-international.com · 760-434-9141 · Veteran-owned and female-owned.