
QMSR INSPECTABLE RECORDS · IN FORCE SINCE FEBRUARY 2, 2026
Producible. Evidentiary. Permanent.
Direct Answer
QMSR inspectable records are the three document types FDA gained the authority to demand on February 2, 2026: management review records, internal quality audit reports, and supplier audit reports. All three were shielded for thirty years by the § 820.180(c) confidentiality exemption, which the Quality Management System Regulation did not carry forward. Nothing about how you write these records changed. Everything about who reads them did.
For thirty years, a medical device quality manager could hand an FDA investigator a great deal and still, lawfully and politely, decline three specific requests. Those three requests are now the QMSR inspectable records, and declining is no longer an option. The management review minutes, the internal audit reports, and the supplier audit reports are producible on demand — including the ones your team wrote last quarter, under the old assumption of privacy.
Most coverage of the Quality Management System Regulation, written before it took effect, framed it as a harmonization story: the United States finally adopting the international standard everyone else already used. True, pleasant, and incomplete. Harmonization is what the rule is. The QMSR inspectable records are what it does, and they are the part almost nobody rehearsed for.
This guide covers exactly which records became producible and why, what the regulation preserved untouched, how FDA now runs an inspection under a brand-new compliance program, and the six areas a manufacturer should verify to confirm its transition landed in practice rather than on paper. It is written for the people who own the answer when an investigator asks — and it draws on what Management Systems International (MSI) has observed across 200+ certification and regulatory audits attended alongside clients.
Key Takeaways on QMSR Inspectable Records
- The § 820.180(c) confidentiality exemption was eliminated. That single deletion created the category of QMSR inspectable records.
- Three record types are affected: management review records, internal quality audit reports, and supplier audit reports.
- The regulation took effect February 2, 2026, replacing the legacy Quality System Regulation under 21 CFR Part 820.
- ISO 13485:2016 is incorporated by reference — the international standard now carries the force of U.S. federal law for finished-device manufacturers.
- QSIT is retired. Compliance Program 7382.850 replaced it, restructuring inspections around a Total Product Life Cycle model rather than four subsystems.
- FDA-specific requirements survive on top of ISO 13485: UDI, MDR reporting, traceability, recall reporting, labeling, and complaint files.
- The instinct to write softer minutes is the wrong response. Sanitized QMSR inspectable records read worse to an investigator than honest ones.
- The most common shortfall MSI sees is not systemic — it is procedural language. The system is compliant; the documentation still speaks QSR.
SECTION 1 · THE CHANGE
What Made These Records Inspectable
Deleted. Disclosed. Done.
Under the prior Quality System Regulation, 21 CFR § 820.180(c) carved out a narrow but consequential confidentiality exemption. Management review records, internal quality audit reports, and supplier audit reports did not have to be produced during an FDA inspection. A manufacturer could decline, and many did as a matter of standing policy. The QMSR did not rewrite that provision, narrow it, or add conditions to it. It removed it. That deletion is the entire origin of the QMSR inspectable records question.
From FDA's Own QMSR FAQ
FDA states plainly that the regulation gives the agency authority to inspect management review, quality audit, and supplier audit reports, and that the § 820.180(c) exceptions are not carried forward.
FDA's reasoning is disarmingly reasonable. Manufacturers already hand these same reports to notified bodies, to Medical Device Single Audit Program auditors, and to other national regulators. Producing them for FDA formalizes a reality that already exists in every other jurisdiction. But the effect inside the room changes completely. Every management review held from February 2026 onward produces one of the QMSR inspectable records, and it is written knowing a federal investigator may read it.
The instinct this provokes is precisely the wrong one. The temptation is to write softer minutes — to record fewer findings, to blur an unresolved action, to describe a serious escalation as “under discussion.” That instinct produces a worse outcome than the honest record ever could. An investigator who reads a management review surfacing three real problems, with three assigned owners and three due dates, sees a system that detects and responds. An investigator who reads a review in which nothing was ever wrong sees a system that detects nothing. Among the QMSR inspectable records, sanitized minutes are not protection.
“Every organization that treated this as a vocabulary swap is going to discover, at its next inspection, that it was actually a change in what counts as evidence.”
Worth being precise about scope: the change is evidentiary, not substantive. No new record was invented. ISO 13485 already required all three. What the QMSR altered is the audience. The QMSR inspectable records are the same documents your quality system was already producing — now readable by a party who previously could not ask.
SECTION 2 · THE THREE
The Three QMSR Inspectable Records, One at a Time
Review. Audit. Supplier.
Each of the three carries a different kind of exposure, and treating them as one undifferentiated pile is the fastest way to miss which one is actually weak. The QMSR inspectable records break down as follows.
1. Management Review Records — ISO 13485 Clause 5.6.3
ISO 13485 places management review at Clause 5.6, inside Management Responsibility, rather than at Clause 9.3 where the harmonized standards put it. Clause 5.6.2 names twelve required inputs; Clause 5.6.3 requires the decisions and actions that come out. Of the three QMSR inspectable records, this is the one that tells an investigator the most in the least time, because it shows in a single document whether leadership sees the system, judges it, and acts on it.
The common defects are structural rather than dramatic. A review chaired by the management representative with the chief executive logged as “absent, reviewed minutes.” Ten of the twelve inputs addressed and two silently skipped. Decisions recorded as sentiments rather than as assigned actions with owners and dates. Each was survivable when the document was private. Each is now visible.
2. Internal Quality Audit Reports — ISO 13485 Clause 8.2.4
The second of the QMSR inspectable records creates a comparison that did not previously exist. An investigator can now read what your own auditors found, then read what your corrective action system did about it. The distance between those two documents is the single most revealing artifact in a device quality system, and no amount of procedural polish conceals it.
This raises the stakes on auditor competence considerably. An internal audit program that generates findings nobody acts on now documents its own inertia. One that generates no findings at all documents something worse. MSI's guidance on internal audit planning works through building a schedule that follows the product rather than the org chart, and the ISO 19011:2026 revision pushes in the same direction by requiring a defined objective for every audit, not merely a scope and criteria.
3. Supplier Audit Reports — ISO 13485 Clause 7.4
The third of the QMSR inspectable records is the one organizations forget they own. If a supplier audit flagged a nonconformity in 2025, and that supplier remains on the approved list with no documented follow-up, the file now says so out loud. Purchasing controls under Clause 7.4 require evaluation proportionate to the risk the purchased product carries — and the evidence behind that evaluation is producible along with everything else.
Direct Answer
Which records are the QMSR inspectable records? Exactly three: management review records under Clause 5.6.3, internal quality audit reports under Clause 8.2.4, and supplier audit reports under Clause 7.4. All three were shielded by the § 820.180(c) confidentiality exemption under the old Quality System Regulation. That exemption was not carried forward, so all three are producible during an FDA inspection.
Make the Record Work For You
Run a Management Review an Investigator Would Respect
Of the three QMSR inspectable records, the management review is the one you control most directly — and the one an agenda built from last year's agenda will quietly fail. MSI's ISO Management Review Toolkits give you a presentation deck and a matching Word minutes form, generated from the same numbered section list, with the clause reference printed under every section title. Nothing gets left out because nobody knew it was required.
For device manufacturers, the Medical Device ISO 13485 Management Review Tool Kit runs 23 numbered sections built from Clause 5.6. Already certified to ISO 9001 as well? The combined ISO 13485 and ISO 9001 edition runs 32 sections and resolves every point where the two standards diverge — a device organization building from ISO 13485 alone misses three ISO 9001 inputs, and one building from ISO 9001 alone misses six ISO 13485 requirements.
Not sure which fits your certification scope? Call 760-434-9141 and describe it — a short conversation beats guessing.
SECTION 3 · MECHANISM
What the Regulation Actually Says
Reference. Overlay. Layer.
The QMSR rewrote 21 CFR Part 820 by incorporating ISO 13485:2016 — and Clause 3 of ISO 9000:2015 for terminology — by reference. In administrative law, incorporation by reference means a second document is treated as though it were written into the first in full. ISO 13485 now carries the same legal force as the regulation citing it.
There is a practical consequence worth pausing on: the standard is copyrighted, and the regulation does not reprint it. A manufacturer subject to Part 820 must hold a legitimate copy of ISO 13485:2016 in order to read its own governing law. That is unusual, and it catches smaller manufacturers off guard.
Most of Part 820 is now either a pointer to a specific ISO 13485 clause or marked “Reserved.” The sections retaining unique FDA wording are the ones where the international standard was not sufficient on its own under U.S. statute. FDA's official QMSR overview sets out the mechanism, and the agency's economic analysis, published with the February 2024 final rule, projects $532 million to $554 million in annual industry savings from removing the duplicate compliance burden.
Core Changes Beyond the Inspectable Records
- ISO 13485:2016 incorporated by reference. The international standard is now the primary body of quality system requirements inside Part 820.
- ISO 9000:2015 Clause 3 incorporated for terminology. The definitions ISO 13485 depends on come with it.
- Risk-based thinking runs throughout. ISO 13485 threads risk through the whole system, not only design — a meaningful departure from the QSR's more prescriptive shape.
- Legacy terminology retired. Design History File, Device Master Record, and Device History Record are no longer defined terms. The underlying records survive under ISO 13485 vocabulary.
- “Design controls” becomes “design and development.” The discipline is preserved; the name aligns with the standard. MSI covers the practical consequences in its guide to ISO 13485 design and development.
- The FDA-specific overlay is retained. UDI, traceability, MDR vigilance reporting, recall reporting, and labeling controls remain layered on top.
Direct Answer
Does the QMSR require a new quality system? No. For an organization already certified to ISO 13485:2016, almost no structural change is required — the system is already the right shape. What it requires is a documentation and terminology reconciliation, explicit coverage of the FDA overlay requirements ISO 13485 does not address on its own, and a hard look at the three QMSR inspectable records that are now producible on request.
SECTION 4 · CROSSWALK
The QSR-to-ISO 13485 Crosswalk Every Procedure Needs
Map. Rewrite. Retrain.
The documentation work created by the QMSR is unglamorous and unavoidable. Every quality manual, SOP, work instruction, form, and audit checklist citing a QSR section number is now citing a regulation that no longer reads the way it is quoted. The table below is the reconciliation map MSI walks clients through during a planning session — and the three rows shaded by the QMSR inspectable records change are the ones to read twice.
| Old QSR Concept | Where It Lives Now | What Changes in Practice |
|---|---|---|
| Design Controls (§ 820.30) | ISO 13485 Clause 7.3 — Design and Development | Same discipline; add explicit design transfer and design file requirements. |
| Design History File (DHF) | Design and development file, Clause 7.3.10 | Term retired. The file still exists — rename it, do not delete it. |
| Device Master Record (DMR) | Medical Device File, Clause 4.2.3 | Broader scope. Clause 4.2.3 asks for one file per device type or family. |
| Device History Record (DHR) | Records of production and service provision, Clause 7.5.1 | Term retired; batch and lot traceability requirement is unchanged. |
| Management Review (§ 820.20(c)) | ISO 13485 Clause 5.6 | Twelve defined inputs under 5.6.2. Now one of the QMSR inspectable records. |
| Internal Quality Audit (§ 820.22) | ISO 13485 Clause 8.2.4 | Auditor independence still required. Now one of the QMSR inspectable records. |
| Purchasing Controls (§ 820.50) | ISO 13485 Clause 7.4 | Evaluation proportionate to risk. Supplier audit reports now inspectable. |
| CAPA (§ 820.100) | Clauses 8.5.2 and 8.5.3 | Corrective and preventive action split into separate clauses. |
| Complaint Files (§ 820.198) | Clause 8.2.2 plus retained FDA wording | FDA kept specific complaint provisions. Both apply. |
MSI client experience suggests this crosswalk is where transitions quietly fail. The system is fine. The engineers are doing the right work. But an audit checklist still asks “is the DHF complete?” and an investigator working from the current regulation hears a company describing its own quality system in a language the regulation retired. The finding that follows is not about capability. It is about control of documents — a discipline MSI covers in its guide to document control that actually holds up, and one that a structured ISO 13485 gap analysis surfaces early.
SECTION 5 · INSPECTION MODEL
How FDA Reads QMSR Inspectable Records During an Inspection
Lifecycle. Risk. Integration.
The Quality System Inspection Technique — the four-subsystem method FDA investigators used from 1999 onward — was withdrawn when the QMSR took effect. In its place FDA issued Compliance Program 7382.850, Inspection of Medical Device Manufacturers, with an implementation date of February 2, 2026. It supersedes both CP 7382.845 and CP 7383.001, the PMA pre- and postmarket inspection program.
This is the part most organizations have not rehearsed. If your internal audit program, your mock-inspection drills, and your front-room binder were all organized around the QSIT subsystems — Management, Design, Production and Process Controls, and Corrective and Preventive Actions — you are rehearsing for an inspection that no longer happens that way. And the QMSR inspectable records now sit inside that new model rather than outside it.
What Changed in the Inspection Itself
- Total Product Life Cycle assessment. CP 7382.850 structures the inspection around the device's full lifecycle rather than four discrete subsystems, with benefit-risk-informed compliance decisions.
- Other Applicable FDA Requirements. The program explicitly directs investigators to assess UDI, device tracking, corrections and removals, and MDR practices alongside the quality system itself. These carry their own reporting codes.
- Defined inspection types. Baseline surveillance, non-baseline surveillance, compliance follow-up, for-cause, and specific-product-risk assignments each carry distinct scope and triggers.
- System function over system existence. The practical shift most quality leaders report: investigators are less interested in whether a procedure exists and more interested in whether the system behaves as an integrated, risk-driven whole. The QMSR inspectable records are the fastest way to see that.
Organizations that want their internal audit program to actually predict an FDA outcome need to restructure it around this model rather than the retired one. The audit report is no longer an internal artifact; it is an exhibit.
Build Auditors Who Can See It Coming
Train Your Internal Auditors to the Standard FDA Now Enforces
Your internal audit reports are federal evidence now. That makes auditor competence a regulatory asset rather than a training line item. MSI's ISO 13485 2-Day Internal Auditor Training ($1,137) qualifies your team to audit against the clauses the regulation enforces. Running one system against both standards? The ISO 9001 & ISO 13485 2-Day Internal Auditor Training ($1,137) covers quality and device requirements in a single cohort.
Need the whole team fluent first? Start with the ISO 13485 Overview ($497) — roughly four hours of video across nine modules, with lifetime access. MSI's internal auditor training overview maps the full pathway.
SECTION 6 · THE OVERLAY
What the QMSR Did Not Change
Retained. Layered. Mandatory.
A dangerous simplification circulating since February is that the regulation means “ISO 13485 certification equals FDA compliance.” It does not. ISO 13485 is now the quality system backbone, but a set of uniquely American obligations sits on top of it, and they are exactly the requirements a certified-but-complacent manufacturer forgets to demonstrate. None of them are part of the QMSR inspectable records question — they are a separate exposure entirely.
The FDA Overlay Requirements That Survived
- Unique Device Identification — 21 CFR Part 830, plus FDA's UDI system requirements. ISO 13485 does not require a UDI. U.S. law does.
- Medical Device Reporting — 21 CFR Part 803. Vigilance timelines and reportability decisions remain FDA-specific.
- Device tracking — 21 CFR Part 821.
- Corrections and removals — 21 CFR Part 806.
- Labeling and packaging controls — Part 820 §§ 820.35 and 820.45, retained with unique FDA wording.
- Combination products — 21 CFR Part 4, whose cross-references were amended to point at the current regulation. A device-led combination product must satisfy it alongside the applicable drug cGMP provisions.
Device classification also survives unchanged. Whether a given provision applies to your product still depends on where the device sits in FDA's classification scheme — certain Class I devices retain partial exemptions, and the classification regulation for your specific product remains the authority. Cybersecurity evidence follows the same logic, as MSI sets out in its analysis of medical device cybersecurity as quality system evidence.
SECTION 7 · RISK
Risk Management and the Records That Prove It
Embedded. Continuous. Provable.
The QSR treated risk analysis largely as a design-phase activity. ISO 13485 — and therefore the current regulation — treats it as a property of the whole management system. Risk-based thinking is expected to appear in supplier qualification, in process validation decisions, in change control, in the sampling plans behind acceptance activities, and in how corrective action is prioritized.
ISO 13485 points to ISO 14971 as the risk management method, and FDA maintains it among the recognized consensus standards a manufacturer can declare conformity to. The practical implication is that a risk file existing only as a design-era artifact — written once, filed, never revisited against post-market data — is now visibly out of step. And because two of the three QMSR inspectable records report on exactly this loop, the mismatch is discoverable in a way it previously was not.
This is where CAPA under ISO 13485 becomes the connective tissue. Complaint data feeds risk. Risk reprioritizes corrective action. Corrective action feeds design change. Design change feeds validation. Organizations whose change control still runs on email and shared drives struggle to demonstrate that loop — a failure mode MSI examines in its analysis of change management automation, where design changes under Clause 7.3.9 now sit squarely inside federal regulation. Software-connected devices carry a further layer, addressed in MSI's work on medical device threat modeling.
Direct Answer
How does the regulation change risk management? It moves risk from a design deliverable to a system-wide expectation. Risk-based thinking must be demonstrable in supplier qualification, process validation, change control, acceptance activities, and corrective action prioritization — and because the QMSR inspectable records report on that work, the evidence is now producible rather than internal.
SECTION 8 · SUPPLIERS
Supplier Files: The Quietest of the QMSR Inspectable Records
Evaluate. Monitor. Evidence.
Clause 7.4 asks a manufacturer to evaluate and select suppliers based on their ability to meet requirements, to apply controls proportionate to the risk the purchased product carries, and to keep records of the evaluation. Straightforward on paper. The exposure is that the supplier audit reports behind those records are the third of the QMSR inspectable records, and they are the ones nobody rehearses.
Organizations typically report that supplier files are the least-maintained corner of a device quality system. The approved supplier list is current. The supplier evidence often is not: an audit from three years ago, a certificate that expired in the interval, a corrective action request the supplier never closed. Under the old regulation the manufacturer could keep that quietly to itself. It is now on the table with the rest of the QMSR inspectable records.
The remedy is unglamorous: reconcile the approved supplier list against the actual evidence file, close what is open, and set a monitoring cadence proportionate to risk. The mechanics of that reconciliation belong in a written purchasing procedure rather than in someone's memory — which is why the purchasing and supplier control procedures sit in MSI's ISO procedure template library alongside the leadership and commitment procedure the management review record depends on.
Direct Answer
Are supplier audit reports part of the QMSR inspectable records? Yes. Supplier audit reports under ISO 13485 Clause 7.4 are the third of the three record types the § 820.180(c) exemption previously shielded. Reconciling the approved supplier list against the evidence behind it is the single most productive hour a purchasing owner can spend.
Manufacturers whose supply chain spans additive manufacturing, sterilization, or contract testing carry more of this exposure than most — MSI covers those cases in its work on ISO for additive manufacturing and ISO for scientific service providers. The commitment point where supply obligations become binding is worked through in MSI's guide to the sales management procedure.
SECTION 9 · VERIFICATION
Six Areas to Verify Now
Review. Reconcile. Refine.
Most U.S. manufacturers planned their transition during 2024 and 2025. Now that the regulation is in force and inspections are running under the new compliance program, the useful question is no longer “did we plan?” but “did the plan land?” A structured planning session covers six areas, and three of them are the QMSR inspectable records themselves.
- Procedure mapping. Every procedure citing a QSR clause should now cite the corresponding ISO 13485 clause, with the Part 820 overlay named where it applies. Confirm the cross-references are current and that staff have been retrained on the vocabulary. A procedure that says the right thing while the operator says “DHF” out loud in an interview is only half-transitioned.
- Management review records. Read the most recent minutes against Clauses 5.6.2 and 5.6.3. All twelve inputs addressed, decisions documented, owners and dates assigned. This is the first of the QMSR inspectable records an investigator is likely to ask for.
- Internal audit program. Confirm the schedule covers all applicable ISO 13485 clauses on a planned basis, that reports are retrievable, and that the program is structured for the lifecycle model rather than the retired QSIT subsystems.
- Supplier audit documentation. Reconcile the approved supplier list against the evidence behind it. Everything true of the other QMSR inspectable records applies equally here.
- Risk management integration. Demonstrate risk-based thinking in design, supplier qualification, corrective action, validation, and monitoring — not only in a design-era risk file.
- FDA overlay coverage. UDI, MDR, tracking, corrections and removals, labeling, and complaint specifics addressed explicitly — not assumed to be covered by the ISO 13485 reference.
MSI client experience suggests the most common shortfall is not a broken process. It is procedural language: quality manuals and SOPs still referencing QSR section numbers, “Design History File,” “Device Master Record,” or QSIT subsystems in audit checklists. The substance of the system is often current. The documentation lags — and the documentation is what an investigator reads first.
Smaller manufacturers carry the most of this exposure, because the original quality system was frequently assembled from QSR-era templates. MSI's caution to medical device startups that misread ISO 13485 and its guide to what ISO 13485 does to a device launch both walk through where those templates break, and MSI's overview of building a medical device QMS covers the rebuild sequence.
Procedures That Produce the Evidence
The Written Procedures Behind Every Record You Now Hand Over
The QMSR inspectable records are outputs. Something has to produce them, on a defined cadence, in a defined format — and ISO 13485 Clause 5.6.1 requires a documented procedure as well as a record. MSI's ISO Procedure Templates and Guides cover thirteen procedure families and 100+ editable Word templates across ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101, written to a single architecture so the set interlocks rather than contradicting itself at the seams.
Twenty-eight years of practice, written down — with the judgment calls already made. Browse the template library, or see the ISO manual templates if the quality manual itself is what needs rebuilding.
SECTION 10 · CROSS-REFERENCES
The 179-Section Cleanup the Rule Triggered
Editorial. Sweeping. Consequential.
In December 2025 FDA issued technical amendments updating 179 sections across 18 parts of Title 21 to conform existing references to the new regulation. The amendments are editorial in character — but the reach (parts 801, 803, 812, 860, 862, 864, 866, 868, 872, 874, 876, 878, 880, 882, 886, 888, 890 and 892) shows how deeply Part 820 is woven into the wider device framework.
For documentation owners the implication is concrete: any internal procedure, work instruction, quality manual, or regulatory submission template citing 21 CFR sections needs a cross-reference sweep. References to § 820.30, § 820.180 and § 820.198 under the old regulation now resolve differently — and § 820.180 is the specific citation that created the QMSR inspectable records in the first place, so any procedure quoting it is quoting a protection that no longer exists. This is exactly the kind of change a well-run first management review should catch and assign.
SECTION 11 · UPSIDE
The Real Benefits Behind the Exposure
Cost. Speed. Confidence.
For all the exposure created by the QMSR inspectable records, the regulation is a net reduction in regulatory friction — particularly for manufacturers selling outside the United States.
One System Instead of Two
FDA's economic analysis projects $532 million to $554 million in annual industry savings, driven by the elimination of duplicate quality documentation, reduced audit overhead under MDSAP, and training consolidated around a single standard. Organizations typically report that the savings surface as reduced audit-preparation and consulting hours rather than as a visible line item.
Faster Market Access
A quality system satisfying Part 820 now simultaneously satisfies the ISO 13485 certification requirements used by EU notified bodies, Health Canada, ANVISA, the TGA and the PMDA. For an organization expanding internationally, the distance between U.S. clearance and a second-jurisdiction filing has genuinely compressed. The wider 2026 ISO revisions reinforce the point: ISO 13485 was reaffirmed at its 2016 edition rather than rewritten, precisely because so much regulatory machinery — now including FDA's — depends on its stability. Organizations running device and quality systems together should note that ISO 9001 publishes its next edition on September 16, 2026, which will move the ISO 9001 half of a combined system while the device half stays put.
A More Honest System
This is the benefit nobody puts in a press release. When management review minutes and internal audit reports become visible to a regulator, the incentive to run those meetings seriously goes up. Organizations that had drifted into ceremonial management reviews — a slide deck, a nod, an adjournment — tend to rebuild them into real ones. The QMSR inspectable records made a governance practice consequential, and consequential practices improve.
For manufacturers who want to prove maturity rather than merely assert it, the FDA Voluntary Improvement Program measures the same system the regulation enforces — improving one improves both. Sustained performance is what continuous improvement under ISO 13485 is built to deliver, and what MSI's SureResults maintenance program keeps running between audits.
SECTION 12 · WHERE EXPERTISE FITS
What ISO Consulting Adds to a QMSR Transition
Pattern. Precision. Proof.
The value of experienced ISO consulting on a QMSR transition is not that a consultant knows the regulation. The text is public; anyone can read it. The value is pattern recognition — knowing, before you open a single binder, which three places a QSR-era system almost always fails to translate.
That is measurable, not rhetorical. Across 28 years, Management Systems International (MSI) has supported 80+ certifications, attended 200+ audits alongside clients, and counts 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Sitting on the client's side of the table through 200+ audits is a specific education: you learn what an auditor reaches for second, after the procedure checks out. Under the current regulation, what they reach for second is the first of the QMSR inspectable records — the management review file.
ISO 13485 is also the deliberate exception in the standards family. Unlike ISO 9001, ISO 14001, ISO 45001 and ISO 7101, it does not use the harmonized ten-clause structure — it keeps its own architecture, with the medical device file at Clause 4.2.3 and competence tied to defined roles at Clause 6.2. Knowing precisely where ISO 13485 converges with and diverges from the rest is the kind of precision good ISO consulting exists to supply, and MSI lays that map out in its ISO consulting decoder ring and in its overview of integrated management systems.
MSI builds ISO 13485 quality systems around how a team actually designs, manufactures, validates and ships product — engineered to satisfy Part 820, MDSAP and EU MDR at once, without bloating documentation or grinding operations to a halt. For organizations starting from a blank page, SurePath carries the build through to first-pass certification, SureFinish compresses advising into six weeks, and MSI's clients span the regulated industries where getting this wrong is expensive. Background on the standard itself sits in MSI's explainer on what the ISO 13485 standard covers.
The 30-Minute Answer
Would Your Last Three Records Hold Up? Find Out in One Call.
Most organizations that believe they finished the transition finished 80% of it. The remaining 20% is almost always the same 20%: procedural language, supplier evidence, and a management review file that was never written to be read by a regulator. A planning session with MSI puts a name to what is left — in days, not during an inspection.
Call 760-434-9141 and ask for a verification planning session. Bring your last management review minutes and your approved supplier list — two of the three QMSR inspectable records tell us most of what we need to know.
Building from zero instead? Start with ISO 13485 Launch Mastery ($397), or the Executive ISO Launch — Quality & MedDevice Program ($397) if you are running ISO 9001 and ISO 13485 together.
SECTION 13 · FREQUENTLY ASKED
QMSR Inspectable Records — Common Questions
Direct. Practical. Current.
Which records are the QMSR inspectable records?
Three. The QMSR inspectable records are management review records under ISO 13485 Clause 5.6.3, internal quality audit reports under Clause 8.2.4, and supplier audit reports under Clause 7.4. All three were protected by the § 820.180(c) confidentiality exemption under the old Quality System Regulation, which was not carried forward when the current regulation took effect on February 2, 2026.
When did records become inspectable under the QMSR?
February 2, 2026. The final rule published on February 2, 2024 with a two-year implementation window, and the QMSR inspectable records became producible on the effective date. There was no phase-in period and no grandfathering of records created before that date — a management review held in 2025 is producible now.
Should we write more cautious minutes now that records are inspectable?
No. Softening the record is the most common wrong response to the QMSR inspectable records change. An investigator reading a management review that surfaces three real problems with three assigned owners sees a system that detects and corrects. An investigator reading a review in which nothing was ever wrong sees a system that detects nothing. Write the honest record and document the response to it rigorously.
Does ISO 13485 certification mean we comply with the QMSR?
No. Certification is a strong foundation but not compliance on its own. FDA-specific requirements sit on top of ISO 13485 — UDI, MDR reporting, device tracking, corrections and removals, labeling, and complaint file specifics. Certification by a registrar and FDA inspection also remain separate regimes that now happen to use the same standard, though the QMSR inspectable records are producible to both.
What replaced QSIT for inspections?
Compliance Program 7382.850, Inspection of Medical Device Manufacturers, replaced QSIT on February 2, 2026. It also supersedes CP 7382.845 and the PMA inspection program CP 7383.001. Inspections are structured around a Total Product Life Cycle assessment rather than the four QSIT subsystems, and the QMSR inspectable records are read inside that lifecycle framing.
Do we still need a Design History File?
The term is retired, but the records are not. The design and development file at ISO 13485 Clause 7.3.10 carries what the DHF carried. Device Master Record maps to the Medical Device File at Clause 4.2.3, and Device History Record to production and service records at Clause 7.5.1. Rename and re-map the documentation — do not delete anything.
Are supplier audit reports really producible to FDA?
Yes. Supplier audit reports are the third of the QMSR inspectable records and the one most organizations overlook, because the exposure lives in a purchasing file rather than a quality file. If a supplier audit flagged a nonconformity and that supplier remains approved with no documented follow-up, the file now says so to anyone who asks for it.
What should a manufacturer verify first?
Start with the three QMSR inspectable records, because they carry the highest exposure and take the least time to check. Read the most recent management review minutes against Clauses 5.6.2 and 5.6.3, confirm internal audit reports are retrievable and their findings closed, and reconcile the approved supplier list against the evidence behind it. Then move to procedure cross-references, risk integration, and FDA overlay coverage. A planning session covers all six in days — call 760-434-9141.
Present. Decide. Record.
Build the One Record an Investigator Reads First
Of the three QMSR inspectable records, the management review is the one you can rebuild this quarter. MSI's toolkits give you a deck to present from and a Word minutes form to record into, generated from the same numbered section list, with every section anchored to the clause it satisfies — including the device edition built from ISO 13485 Clause 5.6 and the combined edition for organizations certified to ISO 9001 as well.
See the Management Review Toolkits →
Need the procedures underneath them too? Browse the ISO Procedure Templates and Guides, or call 760-434-9141 for a planning session.
Related Reading on QMSR Inspectable Records and ISO 13485
- ISO 13485 Medical Device Consulting — MSI
- ISO 13485 Management Review: The Proven First-Time Playbook
- ISO Management Review Toolkits — Clause by Clause
- ISO Procedure Templates and Guides
- ISO 13485 Gap Analysis: The Proven Path to QMSR Ready
- Navigating the Transition from QSIT to ISO 13485:2016
- How CAPA Works Under ISO 13485
- Design and Development in Practice — Clause 8.3 Tactics
- Internal Audits — Building an Inspection-Ready QMS
- ISO Consulting — How MSI Works
References & Authoritative Sources
- FDA — Quality Management System Regulation (QMSR) Overview
- FDA — QMSR Frequently Asked Questions
- FDA — Compliance Program 7382.850, Inspection of Medical Device Manufacturers
- FDA — Medical Device Single Audit Program (MDSAP)
- FDA — Unique Device Identification (UDI) System
- FDA — Classify Your Medical Device
- FDA — Recognized Consensus Standards Database
- FDA — FDA Form 483 Frequently Asked Questions
- Federal Register — Quality System Regulation Amendments, Final Rule (Feb 2024)
- Federal Register — QMSR Technical Amendments (Dec 2025)
- eCFR — 21 CFR Part 820 (current text)
- eCFR — 21 CFR Part 830 (UDI)
- eCFR — 21 CFR Part 803 (Medical Device Reporting)
- eCFR — 21 CFR Part 821 (Device Tracking)
- eCFR — 21 CFR Part 806 (Corrections and Removals)
- eCFR — 21 CFR Part 4 (Combination Products)
- ISO — ISO 13485:2016, Medical devices — Quality management systems
- ISO — ISO 13485 standard landing page
- AAMI — QMSR and Global Harmonization
- IMDRF — International Medical Device Regulators Forum
- Global ACI — Global Accreditation Cooperation Incorporated (assumed accreditation oversight from IAF and ILAC on January 1, 2026)
- ANAB — ANSI National Accreditation Board
- ASQ — American Society for Quality
About Management Systems International (MSI)
Management Systems International (MSI) is a veteran-owned, female-owned ISO consulting firm founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.
msi-international.com · 760-434-9141