Risk, Risk, Risk, Risk: What FDA’s First 100 QMSR Inspections Are Telling You

In April, FDA held a town hall on how the first months of QMSR enforcement are going, and Keisha Thomas — associate director in CDRH’s Office of Product Evaluation and Quality — was asked what the agency is finding in its first hundred-plus inspections under the new regulation.

Her answer: “Risk, risk, risk, risk. That is the fundamental change to QMSR.”

She said it four times. When a regulator repeats a word four times into a microphone, I take that as a courtesy. They are telling you the answers to the test.

The list, while we’re at it

Per RAPS’s coverage of the town hall, FDA completed just over 100 QMSR inspections between February 2 and mid-April, and the top five observation areas were, in order: risk management, outsourcing and purchasing, complaint handling and feedback, UDI, and corrective action.

If that list looks suspiciously like the greatest hits of the old QSR era, you’re not wrong — Thomas herself noted the agency is seeing largely the same citation categories as before, “only in a different order.” But that reordering is the story. Risk didn’t climb to number one because manufacturers suddenly forgot how to fill out a risk matrix. It climbed because the inspection itself changed shape.

Why risk is #1 (hint: there’s no risk section)

Here’s the thing that trips people up: you can read the QMSR cover to cover and you will not find a section titled “Risk Management.” There’s no §820-something to point your procedure at. That’s because risk isn’t a section under the QMSR — it’s the connective tissue of the whole standard the QMSR incorporated into law.

ISO 13485 threads risk everywhere: clause 4.1.2 wants a risk-based approach to your QMS processes themselves. Clause 7.1 pulls risk management into product realization planning. Clause 7.3 runs it through every step of design. Clause 7.4 wants supplier controls proportionate to risk. Clause 8.2.1 expects customer feedback to feed back into it.

The old QSR, for the record, mentioned risk analysis essentially once — tucked into design validation in §820.30(g). One mention, one deliverable, one binder. Which is exactly how most quality systems still treat it.

The framed-diploma problem

The pattern showing up in early inspections, echoed by everyone watching this space closely, is that companies treat the risk file as a design deliverable. You finished design transfer, the risk file got signed, and it now hangs on the wall of your QMS like a framed diploma. Impressive. Laminated, possibly. Untouched since 2023.

The QMSR inspection doesn’t audit the diploma. It’s organized around product risk across the whole lifecycle, which means the investigator’s questions run like this: You had forty-one complaints on this device last year — show me where your risk analysis changed. Your supplier had three nonconforming lots — show me the risk file entry that reconsidered their controls. Your sampling plan inspects one unit in a hundred — show me the risk rationale for that number.

If the honest answer is “the risk file hasn’t materially changed since design transfer,” that’s not a documentation gap. That’s the number-one observation area in the country, sitting in your quality system with your signature on it.

What a living risk system actually looks like

Three practical moves, none of which require new software:

Give your risk file triggers, not just birthdays. An annual review is a birthday. A trigger is: complaint trends, nonconformances, CAPAs, and supplier issues each have a defined step that asks “does this change our risk analysis?” — and records the answer, including when the answer is no.

Make the trace visible in both directions. An investigator should be able to pick up a complaint and follow it into the risk file, or pick up a risk control and follow it out to the production evidence that it’s working. If that path currently runs through one employee’s memory, write it down while that employee still works for you.

Put risk rationale on the controls you already have. Your inspection levels, your supplier classifications, your audit schedule — they all exist. What’s usually missing is the documented sentence explaining why that rigor matches that risk. And remember: FDA can now read the records where that reasoning lives.

Find out where you stand — in about two minutes

Since FDA was kind enough to publish what its investigators are finding, we built something with it: a free QMSR Exposure Score self-assessment. Fifteen questions, scored and weighted to match FDA’s top five observation areas from those first hundred inspections — risk heaviest, because that’s how the agency is citing. You get your score instantly, no signup required to see it.

Two minutes. Fewer questions than an investigator will ask, and considerably lower stakes. I’d take that trade.

And if you’d rather hear it from a friendly face than a federal one: an independent internal audit against the QMSR’s risk expectations — or Candor, our managed internal-audit program that keeps risk-based auditing on a real schedule all year — is a considerably gentler way to learn where you stand.

Leave a Comment

Scroll to Top