FDA Inspections Under QMSR: What Program 7382.850 Changes
Since 2 February 2026 the FDA no longer inspects under QSIT but under Compliance Program 7382.850. More consequential than the new procedure, though, is a change in the regulatory text: the protection for management review, internal audits and supplier audit reports is gone.
Entourage Editorial
In brief
What changes for inspection readiness with Compliance Program 7382.850: the risk-based structure of six QMS Areas and four Other Applicable FDA Requirements, the removal of the former Section 820.180(c) exception for management reviews and audit reports, the risk link in Clauses 7.5 to 8.5, and the role of MDSAP as a substitute for routine inspections.
Most of the preparation material sitting in cupboards at MedTech companies trains a procedure that no longer exists. On 2 February 2026 the FDA stopped using the Quality System Inspection Technique (QSIT) for device inspections and moved to the updated Compliance Program 7382.850 (Inspection of Medical Device Manufacturers). Also withdrawn: the former program 7382.845 and 7383.001 for PMA preapproval and postmarket inspections, which are now covered by the same program.
The change of procedure is the visible one. The more consequential change sits in the regulatory text, and it gets far less attention.
The protection for management review and audits is gone
The former Quality System Regulation contained an exception in Section 820.180(c): a manufacturer did not have to make management reviews, quality audits and supplier audit reports available to an FDA investigator. That exception has not been carried over into the QMSR. The FDA states this expressly in its FAQ and points to comment 55 of the preamble to the final rule. The reasoning is matter-of-fact: manufacturers provide these documents to other regulators anyway, they arise in the ordinary course of business and should be readily available at inspection.
This turns material into an inspection subject that many organisations have deliberately kept open and self-critical. A management review minute noting that the CAPA system is overloaded and 47 cases are open now hands the agency the finding itself.
The wrong conclusion would be to document less. It would also be dangerous, because a thin management review breaches Clause 5.6 of ISO 13485 and thereby Section 820.10. The right conclusion is a different one: every finding carries its action with it. A record that names a problem and assigns it an owner, a date and later evidence of effectiveness is not a confession, it is proof of a working system. A record that only assesses is a template for the Form 483 observation.
The same applies to supplier audit reports. In practice these often sit with the auditor or with the supplier rather than with the manufacturer. When the FDA asks for them, the question is not whether you want to show them but whether you have them.
How the new procedure is built
The risk-based process organises the QMSR requirements into six QMS Areas and four Other Applicable FDA Requirements (OAFRs). Each is made up of one or more elements. The full tables with areas, elements and mapped requirements are in Attachment A of Program 7382.850, and that document is public. Anyone rebuilding their preparation should read it rather than have it summarised.
Two areas are worth naming because they show the cut: Management Oversight bundles top management's broad oversight of the QMS and draws on requirements from several places in ISO 13485 and Part 820. Outsourcing and Purchasing covers outsourced processes and procurement.
The difference in principle matters. QSIT worked with four subsystems, of which an inspection typically examined a selection in depth. Under the new approach the FDA evaluates, on every inspection, every main part of the quality management system to some extent, because ISO 13485 rests on a process approach and the areas are connected accordingly. Depth follows the risk to patient and user.
For preparation this means the thought "that subsystem came up last time, so it will be a different one now" no longer holds.
Risk is the sorting key, not a chapter of its own
Risk-based decisions are distributed across the processes in ISO 13485, among others in Clause 7.5 (production and service provision), Clause 7.6 (control of monitoring and measuring equipment), Clause 8.2 (monitoring and measurement), Clause 8.3 (control of nonconforming product) and Clause 8.5 (improvement).
This is precisely where an inspection is decided. Risk management that lives only in the product's ISO 14971 file and never surfaces in the processes is formally present and practically invisible. What is called for is the reverse proof: at which point did a risk consideration actually change a decision on an inspection frequency, a release or a rework.
MDSAP remains the most effective lever
Companies operating in several markets have an alternative to the unannounced routine inspection. CDRH accepts MDSAP audit reports as a substitute for routine FDA inspections, which by agency policy occur on a biennial cycle. MDSAP routine audits are announced and scheduled by the auditing organisation together with the manufacturer, with a pre-established duration, and the FDA reviews the reports with a level of scrutiny commensurate with the significance of the findings.
One limitation belongs here: establishments with activities under the Electronic Product Radiation Control (EPRC) provisions remain subject to FDA inspection for those activities.
That makes the calculation simpler than it is usually presented. MDSAP costs effort and audit fees and in exchange trades an unannounced inspection for a plannable audit. For a company with the US as its only market it rarely pays. For one with Canada, Europe and the US it almost always does.
What to do now
- Map Attachment A onto your own process landscape. The six QMS Areas and the four OAFRs, with their elements, are named there. That mapping is the preparation; everything else builds on it.
- Write the management review to be inspection-ready. Not shorter but more complete: finding, assessment, action, owner, date, evidence of effectiveness. An open finding without an action is the most expensive line in the minutes.
- Read through the internal audit reports. Are findings closed, and is closure evidenced? Last year's report will be read, not the one due after tomorrow.
- Collect supplier audit reports. Establish before the inspection which reports are actually held in house and which would have to be requested from the auditor or supplier.
- Evidence the risk link inside the processes. For Clauses 7.5, 7.6, 8.2, 8.3 and 8.5, one example each where a risk consideration changed a decision. That is the evidence the approach looks for.
- Rebuild the QSIT material, do not discard it. The technical content stays useful; the running order does not.
- Assess MDSAP where more than one market is involved. The question is a cost calculation, not a matter of belief.
Entourage prepares MedTech and IVD manufacturers for inspections under the current program: mapping your processes to the areas and elements of the program, reviewing management review and internal audit reports under the new duty to produce them, building the risk evidence inside the affected processes, and mock inspections that rehearse today's sequence rather than the one from 2025. The most uncomfortable and most useful entry point is usually the question of what the last management review says, and whether you would hand it to an investigator today.
Relevant for your project?
Similar questions in your current project?
In a first call we clarify what is specifically relevant for your situation, without obligation.
Request a call →Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Regulations & standards considered
- 21 CFR Part 820 (Quality Management System Regulation, QMSR, since 2 February 2026)
- 21 CFR Section 820.180(c) of the former version (exception for management reviews and audit reports, not carried over into the QMSR)
- FDA Compliance Program 7382.850 (Inspection of Medical Device Manufacturers)
- ISO 13485:2016 (QM system for medical devices)
- ISO 13485 Clause 5.6 (management review), Clause 8.2.4 (internal audit), Clause 7.4 (purchasing)
- Medical Device Single Audit Program (MDSAP)
- FD&C Act Sec. 704 (inspection authority)
Related expertise
Inspection Readiness →
Preparation for the current program instead of the four QSIT subsystems.
Mock Audits. →
A practice inspection following a withdrawn procedure trains the wrong sequence.
GxP Audits (GMP, GLP, GCP) →
Internal audit reports are inspection material now, no longer protected.
FDA Clearance & Approval →
PMA preapproval and postmarket inspections now run under the same program.
Supplier Development & Qualification →
Supplier audit reports have to be at hand when the FDA asks for them.
Related projects
All case studies →Sources
- FDA, Quality Management System Regulation (QMSR): https://www.fda.gov/medical-devices/postmarket-requirements-devices/quality-management-system-regulation-qmsr
- FDA, Quality Management System Regulation, Frequently Asked Questions (removal of the Section 820.180(c) exception, reference to preamble comment 55): https://www.fda.gov/medical-devices/quality-management-system-regulation-qmsr/quality-management-system-regulation-frequently-asked-questions
- FDA, Compliance Program 7382.850, Inspection of Medical Device Manufacturers: https://www.fda.gov/media/80195/download
- FDA, CDRH Compliance Programs (overview of programs in force): https://www.fda.gov/medical-devices/quality-and-compliance-medical-devices/center-devices-and-radiological-health-cdrh-compliance-programs
- FDA, Medical Device Risk-Based Inspections (town hall of 1 April 2026, six QMS Areas and four OAFRs): https://www.fda.gov/media/191961/download
- FDA, Medical Device Single Audit Program (MDSAP): https://www.fda.gov/medical-devices/cdrh-international-affairs/medical-device-single-audit-program-mdsap
- 21 CFR Part 820 (eCFR): https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-820
Related insights
All insights →Your project
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +39 02 8904 1000
info@theentourage.it
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences




