FDA QMSR: Why Your Management Review Is No Longer Protected (And What FDA Will Expect)
In our previous guide, FDA QMSR 101, we broke down the transition from the old 21 CFR 820 to a system that incorporates ISO 13485:2016 by reference.
However, a dangerous misconception is circulating: the idea that ISO 13485 certification is a “get out of jail free” card for FDA compliance. It isn’t. For firms selling into the US market, “Alignment” does not mean “Identity.” The FDA has carefully “retained” specific, high-stakes requirements—and removed old protections—that change the rules of the game.
The Death of §820.180(c)
For decades, section §820.180(c) acted as a “Privacy Shield.” It restricted FDA investigators from seeing the detailed content of your management reviews and internal audits.
Under the new QMSR, that shield has been deleted. It isn’t that the FDA added a new “permission” to see your files; they simply removed the law that stopped them from asking. Because ISO 13485:2016 is now the “Law of the Land” in the US, your management review records are now treated as standard quality system documentation—fully inspectable from start to finish.
In this blog, we will cover:
- The Reality of Transparency: Why “vague” minutes are now a 483 risk.
- The Practical Risks: How investigators are trained to find the gap between your data and your leadership’s actions.
- What to do now: 4 steps to audit your records before the FDA does.
- The “Management Review Bridge”: How to ensure your ISO-certified process meets the FDA’s retained expectations.
Table of Contents
QMSR in Context: What Has Changed?
Before focusing specifically on management review, it’s important to understand the broader shift introduced by QMSR. While often described as an “alignment” with ISO 13485:2016, QMSR represents a fundamental change in how quality systems are structured, assessed, and—most importantly—inspected by the FDA.
As shown in Figure 1, this shift impacts multiple areas of the quality system—from structure and risk management to documentation and supplier controls. Importantly, it also includes a significant change in FDA inspection authority, with management review and internal audit records now accessible for review.
At a high level, the shift includes:
- Moving from a prescriptive FDA-specific structure to an ISO 13485-aligned framework
- Expanding risk-based thinking across the entire quality system
- Allowing more flexibility in implementation—but increasing expectations for objective evidence
- Introducing greater FDA visibility into key quality system records, including management review and internal audits
As highlighted in Figure 1, one of the most significant—and often overlooked—changes is not in what is required, but in what FDA can now see. It’s this shift in visibility—particularly around management review—that has important implications for how records must now be documented and how they will be assessed during inspection.
While QMSR introduces several changes across the quality system, one of the most immediate and impactful is the removal of restrictions around management review visibility.
Management Review - What is Changing
For decades, medical device manufacturers operating under 21 CFR 820 (the old FDA QSR) worked within what was often referred to as a “privacy shield.” Under §820.180(c), FDA investigators were generally prohibited from reviewing the detailed content of management reviews and internal audit reports. They could confirm that these activities were performed—but not routinely examine what was actually discussed or decided.
The ISO 13485 vs. QMSR Conflict
If your organisation also operates under ISO 13485:2016, this creates an important contrast. Under ISO:
- Notified Bodies do review management review outputs
- There is an expectation of transparency and linkage to decisions
However, many firms historically maintained:
- More detailed records for ISO audits
- More controlled or “sanitized” versions for FDA inspections
As of February 2, 2026, that distinction is gone. By incorporating ISO 13485 into the new QMSR, the FDA has effectively removed the old limitations. Management review records, internal audit reports, and supplier audit reports are now fully subject to FDA inspection. ISO 13485 requires management review—but in practice:
Certification audits often focus on:
- Whether the process exists
- Whether required inputs are covered
They do not always deeply assess:
- How decisions are made
- Whether actions are effective
- Whether leadership is truly engaged
Under QMSR, FDA investigators can now see everything. This means:
- Weak discussions
- Lack of follow-through
- Poor linkage to CAPA or risk
…are no longer hidden.
The QMSR Reality: As of February 2, 2026, that distinction is gone. By incorporating ISO 13485 into the new QMSR, the FDA has effectively removed the old limitations. Management review records, internal audit reports, and supplier audit reports are now fully subject to FDA inspection.
If your management review minutes are vague (“quality objectives were discussed”), lack evidence of resource decisions, or show no linkage between identified issues and subsequent action, you’ll face pointed questions. Worse, if CAPA trends appear in your data but never surface in management review—or surface but trigger no response—that’s a systemic failure investigators are trained to flag.
Inspectors are not just looking for evidence that reviews happened. They are looking for:
- Clear escalation of quality issues
- Evidence of decision-making and follow-through
- Links between management review, CAPA, complaints, and risk
- Demonstration that leadership is actively engaged in the effectiveness of the QMS
In other words, it’s not just what was reviewed—it’s what was done about it.
What to do now:
- Audit your last four quarters of management review records. Do they show genuine executive engagement or ritual compliance?
- Ensure review outputs explicitly address resource allocation, quality objective progress, and risk trends.
- Document the rationale when leadership decides not to act on a raised issue—silence looks like negligence under scrutiny.
- Prepare these records as inspection-ready documents, not internal memos.
This gap is not theoretical—it shows up clearly in how management reviews are documented.
For professionals seeking comprehensive QMSR understanding, The Learning Reservoir offers FDA QMSR Transition: Practical Guidance for Medical Device QMS Professionals. This live virtual training translates regulatory requirements into practical implementation strategies.
Example scenario (Before QSMR & After QSMR)
The example scenario A below shows how management review documentation often looked under the previous 21 CFR 820 approach—records that appear compliant, but rely heavily on summary-level reporting and limited evidence of decision-making.
When assessed against QMSR expectations, and the management review requirements of ISO 13485:2016, this approach exposes clear gaps. We then contrast this with how the same scenario should be documented to demonstrate compliance—showing what FDA inspectors will now expect to see in practice.
(A) Example Management Review Scenario – Before QMSR
MedFlow Devices — Management Review Minutes
Q1 2026 | March 15, 2026
Attendees:
J. Martinez (CEO), R. Chen (VP Quality), S. Patel (VP Operations), L. Williams (Regulatory)
Agenda Items Reviewed:
- Quality objectives status
- Audit results
- Customer feedback and complaints
- CAPA status
- Process performance
Discussion Summary:
Customer complaints were reviewed. The team noted an increase in battery-related complaints for the PulseFlow 3000 product line. Quality objectives are on track. No significant audit findings. CAPA items are progressing.
Actions:
Continue monitoring complaint trends.
Next Review:
June 2026
(A) BEFORE QMSR (Typical Documentation — Where Gaps Occur)
Why the Example Scenario (A) Fails Under FDA Inspection:
An FDA investigator reviewing this document would immediately ask:
- “You noted an increase—how many complaints? What’s the trend compared to previous quarters?”
- “What was the risk assessment of these battery failures? Could they harm patients?”
- “‘Continue monitoring’ isn’t a decision. What resources were allocated? What’s the timeline? Who’s responsible?”
- “Where’s the evidence this was actually escalated to the risk management process?”
This documentation shows awareness of a problem but zero evidence of leadership engagement, resource commitment, or systemic response. It’s exactly the kind of record that triggers Form 483 observations.
Contrast to example (B) below shows how the same scenario can be documented to meet QMSR expectations. Here, the focus shifts from summary-level reporting to clear, data-driven analysis, defined management decisions, and explicit linkage to risk and CAPA—providing the level of evidence FDA inspectors now expect to see.
(B) Example Management Review Scenario – QMSR Compliant
MedFlow Devices — Management Review Minutes
Q1 2026 | March 15, 2026
Attendees:
J. Martinez (CEO), R. Chen (VP Quality), S. Patel (VP Operations), L. Williams (Regulatory)
1. Complaint Trend Analysis:
PulseFlow 3000 Battery Drainage
Data Presented:
- Q3 complaints related to battery drainage: 12 (up from 3 in Q2, 2 in Q1)
- Complaint rate: 0.8% of units shipped (threshold for escalation: 0.5%)
- Product scope: PulseFlow 3000, firmware versions 2.1.3 and 2.1.4
- No patient injuries reported; 4 complaints involved therapy interruption
Risk Assessment Reference:
Risk file RF-PF3000 reviewed. Current battery failure mode rated as Severity 3 (moderate—therapy interruption), Occurrence 2 (remote). Given trending data, Quality recommends re-evaluating occurrence rating and initiating CAPA.
Management Decision:
Leadership approved the following actions:
Action Owner Deadline Resources Allocated Initiate CAPA-2025-047 to investigate root cause R. Chen Oct 30, 2025 Quality Engineering (40 hours) Engage battery supplier for technical review S. Patel Nov 15, 2025 Procurement + Supplier Quality Update risk file RF-PF3000 with Q3 occurrence data L. Williams Nov 1, 2025 Regulatory Affairs (8 hours) Evaluate field action necessity based on CAPA findings J. Martinez Dec 15, 2025 Cross-functional team
Rationale for Resource Allocation:
The 300% quarter-over-quarter increase in complaints, combined with therapy interruption events, justifies immediate investigation despite no injuries to date. Proactive action aligns with our risk-based approach and avoids potential escalation to reportable events.
If No Action Were Taken (Documented Rationale):
N/A—action approved.
Why example (B) meets FDA Expectations
An FDA investigator reviewing this record would see clear evidence of a controlled, risk-based decision-making process.
- Data-driven assessment: The complaint trend is quantified and compared across quarters, with a defined escalation threshold. This allows the investigator to clearly understand the scale and significance of the issue.
- Direct linkage to risk management:The discussion explicitly references the risk file and evaluates severity and occurrence. This demonstrates that risk management is actively used—not just documented.
- Defined management decisions: Actions are specific, approved by leadership, and clearly linked to the identified issue. This shows that management review is driving real outcomes.
- Clear ownership and accountability: Each action has an assigned owner, deadline, and allocated resources. This provides evidence that decisions are not only made—but are expected to be executed.
- Justification of decisions: The rationale for action is documented and tied to data and risk. This shows that decisions are deliberate, justified, and aligned with a risk-based approach.
Even in the absence of injuries, action is taken based on trend analysis. This demonstrates a proactive system designed to prevent escalation. This is what FDA expects to see: not just awareness of issues, but clear evidence of analysis, decision-making, and follow-through. The difference is not in how the issue is described—it’s in how the organisation responds to it.
To ensure your management review process meets QMSR requirements, build these checkpoints into your procedure:
Before the meeting:
- Quality prepares trend analysis with actual numbers, not summaries
- Risk management provides current severity/occurrence ratings for any escalated issues
- Proposed actions come with resource estimates
During the meeting:
- Every escalated issue gets a documented decision: act, defer with rationale, or close with rationale
- Decisions include owner, deadline, and resources
- Leadership signatures confirm engagement, not just attendance
After the meeting:
- Action items feed directly into CAPA system or project tracking
- Risk files are updated within 30 days if occurrence/severity data changed
- Next management review includes effectiveness check on prior actions
What to do now:
- Audit your last four quarters of management review records. Do they show genuine executive engagement or ritual compliance?
- Ensure review outputs explicitly address resource allocation, quality objective progress, and risk trends.
- Document the rationale when leadership decides not to act on a raised issue—silence looks like negligence under scrutiny.
- Prepare these records as inspection-ready documents, not internal memos.
The QMSR Reality: As of February 2, 2026, that distinction is gone. By incorporating ISO 13485 into the new QMSR, the FDA has effectively removed the old limitations. Management review records, internal audit reports, and supplier audit reports are now fully subject to FDA inspection.
Is Your Management Review Inspection-Ready?
We review your recent management review records and identify gaps against FDA QMSR expectations—so you know exactly where you stand before inspection.
Common Questions About QMSR and Management Review
As organisations prepare for QMSR, a number of practical questions are emerging—especially around how management review will be assessed during FDA inspections. These are the questions we’re hearing most often from quality and regulatory teams right now.
Q1: What exactly was the “Privacy Shield” and why is it gone?
A: Under the old 21 CFR 820.180(c), the FDA generally agreed not to inspect the actual content of your management reviews or internal audits. This was meant to encourage companies to be honest about their own failures. As of February 2, 2026, the FDA has officially retired this exemption. By adopting ISO 13485:2016 into the QMSR, the FDA now has full authority to review the substance of these records.
Q2: If QMSR came into effect in February 2026 and I have an inspection in June 2026, which management reviews need to comply?
A:Any management review conducted after February 2, 2026 must be fully compliant with QMSR.
Management reviews conducted before that date will generally be assessed under the old 21 CFR 820 requirements. However, FDA investigators will focus most heavily on your most recent management reviews, particularly those conducted after QMSR came into force.
Q3: Does this mean an investigator can read my meeting minutes word-for-word?
A: Yes. Previously, you only had to prove that a review happened (a “Certificate of Attendance” style proof). Now, an investigator can—and will—read what was discussed, who was assigned actions, and whether those actions were actually funded and completed.
Q4: What is the single biggest “Red Flag” an investigator looks for in these minutes?
A: Silence. If your CAPA data shows a spike in product failures, but your Management Review minutes show “No issues discussed” or “Business as usual,” that is a massive red flag. It suggests that Top Management is either uniformed or indifferent—both of which lead to Warning Letters.
Q5: We are ISO 13485 certified, so we already show these to our Auditor. Is an FDA inspection any different?
A: Yes, the “Lens” is different. A Notified Body auditor looks for conformity to a standard. An FDA investigator looks for evidence of “Management Responsibility” and “Executive Oversight.” They are trained to find “Silos”—situations where the Quality Department knows about a problem, but Top Management hasn’t been told or hasn’t provided the resources to fix it.
Q6: We are already ISO 13485:2016 certified. Does this mean we are automatically compliant with the new FDA QMSR?
A: No. While the FDA has aligned with ISO 13485, they have “retained” specific US-only requirements. Your ISO certificate is the foundation, but you must still build the “FDA Bridge” for areas like Medical Device Reporting (MDR), specific Labeling controls (21 CFR 801), and the new transparency rules for Management Reviews.
Q7: Will FDA investigators still look at management reviews from before February 2026?
A:Yes—but mainly for context and consistency.
Inspectors may review earlier records to understand:
- How your system operated previously
- Whether there has been a clear transition to QMSR expectations
Q8: Do we need to update or rewrite past management review records to meet QMSR?
A: No—do not rewrite historical records.
Records should reflect the requirements that were in place at the time.
Instead:
- Focus on ensuring all post-February 2026 reviews meet QMSR expectations
- Be prepared to explain how your process has evolved
A clear, honest transition is far more defensible than retroactive changes.
Learn more about ISO 13485:2016 by taking our e-Learning course – Introduction to ISO 13485:2016
Conclusion: From "Ritual" to "Evidence"
The transition to QMSR is the most significant shift in FDA medical device regulation in 30 years. For years, many firms treated Management Review as a “compliance ritual”—a closed-door meeting with protected minutes.
That era is over. Under the QMSR, your leadership’s decisions are no longer shielded; they are primary evidence of your company’s commitment to safety. Transitioning successfully isn’t just about changing your SOP titles from “QSR” to “QMSR”—it’s about ensuring your executive team is prepared for a new level of transparency.
Bottom Line: If your Management Review records don’t show active leadership, resource allocation, and a clear link to patient safety data, you are walking into your next FDA inspection with a target on your back.
What’s Next?
This is only the first gap in the “Harmonization Myth.” In Part 2, we will pull back the curtain on Labeling and Packaging Controls, exploring the specific “Hidden Retentions” the FDA kept from 21 CFR 801 that your ISO 13485 certificate doesn’t cover.
Next Steps: Stay tuned for our upcoming deep-dive articles on specific QMSR topics. For immediate comprehensive training, visit The Learning Reservoir.
Stay up to date with our latest news by subscribing to The Learning Reservoir’s newsletter! As a subscriber, you’ll receive exclusive access to our latest blog posts, expert insights, and updates on our latest courses and training programs. Plus, you’ll be the first to hear about our special offers and promotions. Don’t miss out on this valuable resource – sign up today!
SHARE THIS POST
Dr. Fiona Masterson
With over 25 years’ experience in quality management, operations management,
and higher education, Fiona combines technical expertise with highly engaging
training. She has worked in fast-paced manufacturing environments including
medical device companies, and lectures part-time in universities.
She has Bachelor and Master of Science degrees, and a Doctorate in
Mechanical Engineering. Fiona has published in peer reviewed journals on
topics such as medical device and pharmaceutical regulatory affairs, on-the job
training and innovative training technologies and strategies. .
