What changes for IVD developers and manufacturers now that the FDA Quality Management System Regulation is in force, and where the gap work tends to land.
FDA’s Quality Management System Regulation (QMSR) took effect on February 2, 2026, incorporating ISO 13485:2016 by reference into 21 CFR Part 820 and replacing the legacy Quality System Regulation. For IVD developers and manufacturers, the change is more than a paperwork exercise. The updated inspection approach expands what FDA investigators can request, and certain records that were previously out of scope are now reviewable.
In this episode of Expert Insights, Emily Friedland, VP of Clinical Research at DCN Dx, talks with two guests who come at QMSR from different sides of the same problem. Dan Simpson, RAC, Director of Regulatory Affairs at DCN Dx, walks through the regulatory framing: what changed with the transition, how to map an ISO 13485-based QMS against QMSR’s U.S.-specific requirements, and what FDA’s updated inspection approach means for how teams document and maintain QMS records. Kevin Gunning, Principal Consultant at Gunning Quality Systems LLC, brings the quality systems implementation perspective from more than 25 years of building and maintaining QMS programs at IVD and medical device companies. Together, Dan and Kevin cover the four gap areas that matter most for IVD manufacturers, what FDA can now review that was previously off-limits, and how to scope a proportional remediation effort without overbuilding the QMS.
For more detail, read Dan’s companion article: [QMSR Readiness for IVD Manufacturers: Where Well-Maintained ISO 13485 Systems Still Have Gaps]
Listen below, or find us on your favorite podcast platform.
What You’ll Hear in This Episode
1. What QMSR changed from the legacy Quality System Regulation, and what it means for IVD teams day-to-day
2. Why a documented QMSR gap assessment still matters even for organizations already certified to ISO 13485
3. How to put together a Quality Plan that management will sign and that demonstrates readiness to outside auditors and FDA investigators
4. The four gap areas where well-maintained ISO 13485 systems most often fall short under QMSR: applicable regulatory requirements (UDI, MDR, corrections and removals); complaint handling records; labeling and packaging controls, including conformance to 21 CFR Part 809 for IVDs; and definitions and terminology
5. What FDA’s updated inspection approach under CP 7382.850 means for risk-based decision-making and how risk management files become a roadmap during inspection
6. Which records are now within FDA’s inspectional authority under QMSR that previously were not, including management review minutes, internal quality audits, and supplier audit reports
7. The most common misconceptions Dan and Kevin see from teams who assume the QMSR transition is “mostly handled” because they hold ISO 13485 certification
About the Guests
Emily Friedland | VP of Clinical Research, DCN Dx (Host)
Emily leads clinical research at DCN Dx and is a guest host of Expert Insights, the company’s podcast for diagnostics professionals.
Dan Simpson | Director of Regulatory Affairs, DCN Dx
Dan works with IVD developers and manufacturers on FDA and global regulatory strategy and inspection preparation. He holds the Regulatory Affairs Certification (RAC) from the Regulatory Affairs Professionals Society (RAPS) and is the author of DCN Dx’s article on QMSR readiness for IVD manufacturers.
Kevin Gunning | Principal Consultant, Gunning Quality Systems LLC
Kevin is a quality systems executive with more than 25 years of experience in IVD, medical device, and pharmaceutical industries. He has built quality management systems from the ground up at multiple organizations under ISO 13485 and 21 CFR Part 820, and has extensive experience both hosting and conducting FDA and ISO inspections and audits. He holds the Certified Quality Auditor (CQA) credential from the American Society for Quality (ASQ) and previously served as Vice President of Quality Assurance at Alveo Technologies, an IVD company, before founding Gunning Quality Systems LLC.
Emily Friedland: I'm Emily Friedland, Vice President of Clinical Research at DCN Dx, and this is Expert Insights. Today we're talking about FDA's Quality Management System Regulation, or QMSR, and what it means if you develop or manufacture IVDs. As of February 2nd, 2026, QMSR is in effect. It incorporates ISO 13485:2016 by reference into 21 CFR part 820. And among other changes, it comes with an updated inspection approach that changes what FDA investigators can request and review during the facility visit. I have two guests with me today. One comes from the regulatory strategy side and one from the quality systems implementation side. First, Dan Simpson, Director of Regulatory Affairs at DCN Dx. Dan works with IVD developers and manufacturers on FDA regulatory strategy and quality system readiness. He recently published an article on QMSR readiness that we'll be drawing on throughout this episode. And joining us on the pod for the first time, Kevin Gunning, Principal Consultant at Gunning Quality Systems, LLC. Kevin has spent over 25 years building and managing quality systems at IVD and medical device companies. He's an ASQ-certified Quality Auditor and has extensive firsthand experience on both sides of FDA and ISO audits and inspections. Dan, Kevin, welcome.
Dan Simpson: Thanks, Emily. As always, nice to chat with you.
Kevin Gunning: Great to be here. Thanks, Emily.
Emily: Let's get started. Dan, let's start with a clean definition for anyone still getting oriented. What is QMSR? What did it change from legacy Quality System Regulation, and what does it mean for an IVD manufacturer day to day?
Dan: The QMSR is the Quality Management System Regulation, which replaces the previous Quality System Regulation. It is still codified under 21 CFR part 820. But what the difference is, is that it incorporates by reference the majority of ISO 13485, which is the Quality Management System standard internationally for medical devices. What it means for IVD manufacturers day to day is that, if you currently operate under 13485, it's not going to be a big operational change. But there are some key differences that manufacturers have to pay attention to, and some traps that could potentially occur if you don't really go through a gap assessment and make sure you're transitioning properly. If you don't operate under 13485, there's going to be more substantive changes, especially around risk management.
Emily: Great. Thanks, Dan. Kevin, from a quality systems implementation standpoint, how does this land for a team that's been running a well-maintained ISO 13485 system? What's the practical difference they're going to feel?
Kevin: So for a company that has a well-maintained ISO 13485 system, the transition should be fairly painless, more of an evolution than a revolution or a big change. But it's not automatic, and there needs to be some work done to demonstrate. You know, within ISO 13485 you're required during your management review to assess how changes like this to the regulatory environment impact the business and make plans. And you should be able to demonstrate that management is aware of the transition, that you've done a gap analysis, and that you've mapped the FDA-specific portions of oversight into your 13485-based system. Most companies operating in the US have already done that because it's part of the regulatory landscape that they work in. So again, it should be — if you're running things the way you should be running things — you should have already been planning for this. Seeing that this transition was coming and putting together a plan to make sure that you are compliant with the new FDA expectations.
Emily: It sounds like it should be pretty painless for people who are already working under 13485, but what's the most common mistake or assumption that you see teams making about the QMSR that could be just completely wrong?
Kevin: Well, I think the most common assumption is, we're 13485 certified, so we're fine. I mean, not all ISO certifications are created equal to begin with, depending on how you certified or how you claim to be compliant. But the difference is that there's real teeth to people coming in and inspecting you now. And so whereas ISO 13485 for a lot of companies was almost something to put on the website or a certification for satisfying people doing supplier qualifications on them, now it's part of the actual FDA requirements and inspection practice. So the old QSIT inspection quality system inspection techniques are out the window, and it's more of an ISO 13485-based inspection. Some of the things that were off limits in previous inspections — like your internal audits, management reviews, complaints — the responses to those things are now reviewable by FDA. And in practice, that shouldn't change how you document those things. But in reality, it does change how you would approach that in certain ways. And there are strategies that can help you make sure that you don't write yourself into a corner or that you're following your own procedures. So the scoping of those types of internal records that used to be off limits to FDA now need to be looked at and written up with the lens that FDA may be looking at these.
Emily: Dan, in your article you lay out three practical realities that matter right now for IVD manufacturers under QMSR. Can you walk us through them?
Dan: Yeah, sure. And there are things that Kevin has already mentioned, aptly. The quality plan is one thing that Kevin already mentioned. And really, the point I think that he said really well is that you should be treating this like all changes to your quality system, and you should show the regulators and the auditors that just because there's a perceived sameness here between 13485 and the QMSR, you should treat it like it's a change — which it is. And so you do that by doing a quality plan, and then conducting that gap assessment. And then finally, getting that approval by your management review team that you're ready to go. And then again, as Kevin mentioned as well, one of the points I made was that now there are certain records — management review minutes, audit reports — that are now available for FDA review. If you weren't already writing those documents to be viewed by auditors or regulators, you probably should have been. And now there's no hiding from it.
Emily: Kevin, on the point of the quality plan being signed by management — you've built systems from the ground up at several organizations. What does it look like to put together a quality plan that management will sign with confidence, and that provides evidence of readiness to an outside investigator?
Kevin: It should be very practical. We're not looking for a 100-page theoretical assessment. It should be kind of four points: What did we assess? What gaps did we find? What did we do about those gaps, and how do we know that the system is now working? So a follow-up, an effectiveness check at the end of the plan. I think where people run into problems is if you're doing a management review — and I see this there in the field — where it's sort of a check-the-box management review, a standing agenda, there's not a lot of updates to the quality objectives or action items. So if your quality system is working and the management review process is working, you should see that this change was identified, a plan was put together, objectives maybe were updated to say we're going to add this to our quality objectives for the year to make sure that we've updated our QMS for this change — the gaps and the assignments — and then within the plan itself, a general schedule, just like any other project. What were the gaps? Assign the tasks to fill those gaps. Follow up to make sure that they are filled, and then maybe build it into your audit plan to demonstrate that you're following up, to make sure that each one of those identified gaps has been filled and is functioning correctly at the end of the plan execution.
Emily: Regarding the QMSR-specific content for that quality plan, can you describe what's new compared to the 13485 management review package? And what does the US regulatory overlay add?
Dan: You know, I think it's just important to think about the FDA regulatory requirements. The FDA has really pulled out of ISO and said what's important to them in the new final rule for QMSR — that your systems for complaint handling, adverse event reporting, MDRs, and recalls, UDI — those kinds of things are really still defined very well within that ISO framework. And then really I think it's still just driven by your gap assessment. It's driven by the new definitions put forth by ISO compared to the QSR, and really just making sure your system is easy to maneuver for an auditor or an inspector as well.
Emily: Moving on to places where people may find gaps in their systems. Your article described four areas where those gaps tend to cluster, even for companies that have well-maintained 13485 systems. Let's go through them now. The first is applicable regulatory requirements — UDI, MDR obligations, corrections and removals. What does it mean to have those integrated into the QMS versus handled in a parallel regulatory workflow?
Dan: Well, first of all, there really shouldn't be parallel regulatory workflows, as Kevin would probably agree. Everything should go through the quality system. All regulatory requirements should be directed through SOPs, and governing SOPs should refer to the appropriate regulatory SOPs. So things like UDI and MDR and corrections and removals are requirements of ISO 13485, but they're very general. It says where UDIs are required by a regulatory body, you should follow them. What the QMSR does is say specifically where to reference these requirements, and that these requirements must be there to the detail that FDA wants. And same with MDR, corrections or removals that are under reporting to regulatory authorities. But then you just need to put in the specific requirements through part 803 and part 807, which is MDR and Corrections and Removals, respectively.
Emily: Kevin, adding to this, what does the integration look like procedurally when you're auditing or building a QMS? How do you tell whether MDR decision-making is genuinely embedded versus just referenced?
Kevin: So, ISO 13485 is an international standard. So you may be reporting to multiple agencies. And of course, the US FDA is mostly concerned that you report things to them. So what you want to see is specific instructions for how things are handled and reported to FDA — from any of the feeder systems that end up generating reportable events, so primarily complaints. And you want to see that the decision-making for reportability is built right into the complaint management procedure, and that the folks making those decisions are qualified to make them. The timing of requirements are controlled. So I want to see the links to the CAPA, the risk management, the corrections and removals processes. And typically I'd like to see a Regulatory Affairs personnel sign off on those procedures. We want to see that there's a mechanism for trending — especially for complaints — if multiple incidents of the same type of complaint come in. They may be small, but you need to be able to have a system in place where you're doing a management review or a roll-up or trending of those complaints so that you can recognize that, just by frequency, some of these things may become larger issues and get referred to CAPA or assessed for reportability. And then, especially for IVDs, this can get tricky. For maybe not a physical injury — there's not a lot of those types of risks — but false negatives, false positives, invalids that delay results, these things can impact patient safety just as much as something that physically touches the patient. So we want to see that those are being assessed and monitored for trending as well. A good test is to walk through some real complaints. Look at how the decisions are being made. Are they being bucketed? Are they being trended? Can you see when an issue is fed into a CAPA? Is there a connection between the two systems? These are the types of where-the-rubber-meets-the-road systematic implementations of complaints management into reportability that we want to see. The systems are designed to work together, and there are really good tools out there to make them work together these days. So we want to see that folks are exercising those systems and documenting clearly in the records that the correct decisions are being made, with rationale to back them up.
Emily: Great. Dan, Kevin just touched on the second point from your article around complaint handling records. Anything to add around what the QMSR requires in those records and anything that teams might be missing?
Dan: One of the biggest compliance issues FDA usually has — you see the most 483s off of the complaint system. And that just shows you how important, from an FDA perspective, complaint handling is. So I think this is the one area where FDA has really kept the verbiage of the original Quality System Regulation, because to them, this is the most important thing. And it really goes around properly identifying the complaint and the product that is associated with it, and doing an investigation or justifying when there is no investigation, why you didn't do one. And then, as Kevin also said, getting that into your data analysis, CAPA procedures, and then also connecting to MDRs and corrections and removals. So it really goes back to just their fundamental regulatory requirements. There's a lot of identification — I'm not going to go through all of it — but that's really the gist of it. They've really kept their compliance part of this because to them, ISO alone didn't really satisfy their needs.
Emily: The third area for gaps identified in your article is labeling and packaging controls. Dan, the article adds an IVD-specific element here that goes beyond the General Device Labeling Regulation — conformance to 21 CFR part 809. Can you explain what that adds for IVD manufacturers specifically?
Dan: I really put that in because I think a lot of my clients that are new to the IVD industry don't really understand that there are additional labeling requirements above normal medical devices. Because as we all know, IVDs are definitely nuanced medical devices, and they have their own requirements to the user that are identified in that labeling standard, which is 21 CFR part 809. And so this is just specifically for what's in the IFU and what's in the labels specific to IVD reagents — things like storage conditions and volumes and things you might not have in a normal medical device. So again, if you go back to ISO and then you compare it to the new QMSR, FDA has added additional labeling requirements. Mostly the UDI, but also some other things, because they feel that ISO alone isn't enough for compliance. And so again, you just have to take it as an IVD manufacturer a little bit further and say, because I'm an IVD designer, I have to follow 21 CFR part 809 as well. And it's just implied, because of where you are in the IVD space.
Emily: And Kevin, from an implementation standpoint, labeling and packaging controls are an area where quality and regulatory often split ownership. How do you structure that so it holds up under an inspection?
Kevin: So in addition to quality and regulatory, there may be other folks involved — operations or quality control. The process for approving a label or changing a label is complex. Regulatory certainly owns interpretation of the requirements and claims on the labels and instructions, then quality may own the document control portion and versioning and releasing that text. Operations or QC may have to check that those things went through the printing process and came out looking the way that they were supposed to. So all of these processes need to be tied together. Oftentimes I'll implement a separate change control process in the EQMS system just for labels, because there's an approval of a proof. And then it goes to the printer and then it comes back. And regulatory is involved with the earlier steps of that, and then there's a check on the operational or quality aspect at the end. So it's a pretty unique process and it needs to be implemented in a special way. You can't just sort of shoehorn it into the normal change process typically. So I would encourage everyone to take a hard look at the actual steps in your process, especially if you're using outsourced printing, and to make sure that you've got each step checked. It's a risk analysis — where can things go wrong process FMEA-wise — and then put in the correct controls around each of those steps. It's not complicated, but it's easy to have what you approved in regulatory not end up being what's on the printed label at the end, if you're not careful about the process checks.
Emily: Yeah, it seems like a lot of different hands involved in the process. Dan, the fourth gap area is definitions and terminology. This one sounds almost administrative, but you flag it as a meaningful source of gap pain. Why is that?
Dan: This could actually be one of the hidden traps that you could fall into if you really don't do that detailed gap assessment. And the reason why is because all of the terminology — or a lot of the terminology — of the old QSR has now disappeared. So I do know that a lot of companies that started off complying to the Quality System Regulation and then went 13485 still kept a lot of those FDA terms. Like, for example, a design history file doesn't exist anymore — now it's a medical device file. Design controls is design and development. Production and process controls is now production service provision. Instead of being able to reference — a lot of companies would have those terms but they would reference the ISO provision, which was fine. But now those terms don't exist anymore. So that's just one of the things — you really have to go through your procedures and make sure your terminology and your definitions are up to date.
Emily: Thanks, Dan. It's going to be hard for me to get DHF out of my lexicon as we transition over.
Dan: I know, it's hard for us old people, right? I do think that FDA is going to have the same problem, because it was their terminology too. So I think there'll be a transition period, and you certainly need to map them and understand crosswalk-wise what references what. But they'll be struggling too. And if you say DHF, unless it's a brand new inspector, it's going to mean something to them as well. And I'll also add that a lot of companies get around that by having glossaries. You can say a medical device file is the same as a design history file. You don't have to change everything, but you do address it. And you're right — FDA is going to be on that curve too. So it's not like they will not give you a free pass for a while. But I think part of just recognizing it's a change is the optics with that. So it's just something to look out for.
Emily: Dan, the inspection side of the QMSR is where a lot of teams are caught off guard. QSIT is gone. Walk us through what CP 7382.850 changes and why it matters.
Dan: QSIT was primarily built on the main subunits — we usually start around management responsibility and go out from there. What changes now is it's really risk-based inspection. And so really they'll start with your product risk documents, your risk management plans. And then also be looking at what the actual risk of the product is in the field — by looking right at your post-market data, your complaints, MDRs and things — to see really if your risk management is basically working as well in their mind. Because if you're having a lot of issues in the field, it isn't. So really it's driven now around the risk of the product, what you perceive as a risk, and how well you've identified the risk, what your actual risk profile is in the field with users. The other major change is records that were previously exempt under QSR 820.180(c) — management review records, quality audits, internal audits, and supplier audit reports — those are now within FDA's inspection authority.
Emily: Kevin, you've been on both sides of this, hosting audits and conducting them. What does that change in how you would advise teams to write and maintain those documents?
Kevin: So the biggest change is in mindset. I think folks used to sort of know that these were off limits, and use that to give them a little bit of freedom in these things. The records should be written assuming that FDA is going to look at them. So that doesn't mean hiding problems or writing things really vaguely so it's hard to tell what happened. I think exactly the opposite. You should write them very clearly, factually, and professionally. Certainly scoped tightly as you can. But if something's a systemic problem, you need to recognize that and deal with it within your QMS. Taking them sort of one at a time — for internal audits, that means making sure that your audit findings are evidence-based. So just the way that you would if you've been through auditor training — not a general assessment, but a very specific finding. In a batch record: 1, 2, 3, 4, 5 — there was no calculation shown for step 5.2. Don't write general things; be very specific to what exactly you found, supported by the evidence that you reviewed in the audit. That makes things — there certainly is going to be an investigation in response to those audit observations. And if it gets wider, it gets wider. But in terms of documenting the findings, just keep it very factual. Same with management reviews. What we're looking for, as we discussed earlier, is that management is involved in the review. So if you're used to just having a very static slide deck with a signature at the bottom that doesn't change from review to review, that's not going to demonstrate that your management is involved and making decisions and reacting to the contents of the review. So you want to see action items, meeting minutes, updates to quality objectives that are happening as a result of those reviews — that tells the inspector that the QMS is functioning, and it's these higher-order concerns that the inspector should be looking at. And then same with audit reports for suppliers. When you're looking at your supplier audits, are you really assessing them based on their risk, and not just filling out a checklist? Everybody gets all fives and gets approved with a rubber stamp. You should be looking at what issues did we have with this supplier, how are we tying in supplier corrective actions — really scoring them, especially for the ones that matter. And FDA knows who your critical suppliers are and which ones count. Apply the scrutiny to the ones that deserve it. Risk-based. That's the focus. That's how things are intended to work, and you just need to apply your effort to the highest-risk items and back it up with record keeping.
Emily: Dan, Kevin touched on how CP 7382.850 frames inspections around risk-based evidence decision-making. What should teams expect in how FDA will use risk management evidence during an inspection under the QMSR?
Dan: The primary goal of inspections now is really that the QMS meets FDA safety and effectiveness requirements, which has always been the case. But then next, they are basically doing it by looking at your risk management process — that it's in place and that the company is using it to make risk-based decisions. And Kevin had a great example of how you can do that on the supplier side. So really everything he was saying about that — your biggest concerns from a risk management perspective are really what you're spending your time on, are really what you're concerned about. And then where it is a lower-risk thing and where you can show that the issue is not going to affect safety and efficacy of your product, you're able to justify that through your risk management documentation. So really it just hinges off of your risk management procedures and risk management file. That you are operating under, really, these risk controls — FDA will look at things like your post-market data, but also your change control process. Because in your change control process, if it is a big change, you should be going back into your risk management documentation and really making sure that it was addressed, or if it wasn't addressed, to make sure that you're always updating the risk profile of your device.
Emily: Kevin, you've built and audited quality systems at IVD companies of different sizes. When you engage with a company and start looking at their QMS against US regulatory requirements, what are the signs that there's more gap work ahead than they expect?
Kevin: In general, it's a lack of clear integration of the US regulatory oversight into the SOPs. So the SOP has been updated to include a statement something like "notify regulatory for review," as opposed to the form actually having checkboxes for MDR assessment rationale — things where the process has been updated to really guide you through compliance with the regulations, which is how you want to do it. You want to have the process lead to compliance in a very natural way. If you're following your process, you're meeting the regulatory compliance, instead of bolting it on with a couple of regulatory people who, if they're not involved in the day-to-day process and folks aren't trained appropriately, then there's going to be misses. So what I want to see is a tight integration of these specific FDA requirements into the SOPs. And then, from a supplier control standpoint, it's a red flag if all suppliers are treated equally. I think people used to get away with a supplier controls process that was a form of checkboxes with a score sheet that got filled in. And similar to management review, a very generic presentation with the right people in the room and signing off on some minutes — those things are transparent to an auditor who's actually reading the review and seeing if you're making decisions. I always advocate at least quarterly management reviews, or a lot of subsystem reviews that roll up to the management review. You can't tell an FDA auditor that you're looking at trends once a year and expect them to be satisfied. It could be 11 months before you recognize a very serious problem. So there needs to be subsystems or sub-teams that are looking at these metrics and escalating them if they're not looked at regularly by the management team. And this can vary significantly from different-sized companies. But that's the general idea — integration, and real functioning processes as opposed to checkboxes or SOPs having a minor update.
Emily: Great. Dan, where do you see IVD manufacturers getting the QMSR transition wrong or oversimplifying it? What misconceptions come up most often?
Dan: I think we're just going to come full circle here. It basically is again — because I'm ISO 13485, I don't need to do anything. And I think we've had enough points here today to say that there are nuances you have to be careful of. And what I encourage most people to do — and granted, this might be an insomnia cure for some people — but it's really reading the preamble of the new QMSR. Just to be able to really understand — I think with any new regulation, it's a good practice — because then you really understand what FDA is concerned about. In any new regulation, in this case the transition to an industry standard, it really comes down to what Kevin was saying: the integration of all the regulatory processes of the FDA into your quality system, but also just really making sure that you are giving FDA their share of acknowledgement in your international standards, right? As Kevin said, you might be selling to a lot of different spaces. If you're under MDSAP, you have to have all these different regulatory requirements in there, but you always have to give FDA its due and really pay attention to what they see as important on the compliance side. I definitely always try and pay attention to what FDA wants. That's for sure.
Emily: Dan and Kevin, thank you both. I think listeners at different points in the QMSR transition will each find something useful here. For listeners who want more detail, Dan's article on QMSR readiness for IVD manufacturers is available at DCNDx.com. If you need support with a QMSR gap assessment, independent auditing, remediation planning, or inspection readiness, you can reach DCN Dx's Regulatory Affairs team at DCNDx.com/contact. Thanks for joining us for Expert Insights.






