Compliance 13 min read

How FDA Structures a Device Inspection: Findings by QSIT Subsystem

J

Jared Clark

August 27, 2026

FDA doesn't inspect a medical device manufacturer the way most people picture an audit — someone with a clipboard wandering the floor asking questions. It inspects a system, and it does so through a specific, published methodology called the Quality System Inspection Technique, or QSIT. If you understand QSIT, you understand where the findings are going to cluster before the investigator ever walks in.

QSIT, issued by FDA in 1999 and still the operating framework for device inspections today, divides a quality system into four subsystems: Management Controls, Design Controls, Corrective and Preventive Action, and Production and Process Controls. Two additional areas, Purchasing Controls and complaint handling, get pulled into whichever subsystem the investigator is sampling, rather than standing as their own inspection track. That structure is not trivia. It's the actual decision tree FDA investigators use to choose which records to pull, and it's the reason a Form 483 tends to read like a checklist against these same four buckets, inspection after inspection, company after company.

This article walks through each subsystem, the specific 21 CFR 820 citation and ISO 13485:2016 clause that governs it, and the finding pattern that shows up most often when that subsystem breaks. I'll also cover what's different now that FDA's Quality Management System Regulation (QMSR) has replaced the old Quality System Regulation as the enforceable standard.

How FDA Structures a Device Inspection

Under QSIT, an investigator doesn't try to audit all four subsystems with equal depth every time. FDA's guidance directs a full inspection to sample at least two subsystems in depth, with Corrective and Preventive Action almost always one of them, because CAPA is the subsystem where failures in every other part of the quality system eventually surface. If a design control problem, a supplier problem, or a manufacturing drift never gets caught by CAPA, FDA reads that as a system that doesn't know about its own failures. That's a harder finding to walk back than almost any single technical deviation.

This is worth sitting with for a moment: the subsystem FDA weights heaviest isn't the one where the defect originates. It's the one that's supposed to catch it. A weak CAPA system doesn't just mean untracked problems — to an investigator, it means the entire system reports a false picture of itself, and everything else FDA sees during that inspection loses credibility to match.

Subsystem 1: Corrective and Preventive Action (CAPA)

21 CFR 820.100(a) requires each manufacturer to establish and maintain procedures for identifying, correcting, and preventing quality problems. The regulation lists seven specific elements the procedure has to address:

  • Analyzing quality data to identify existing and potential causes of nonconforming product
  • Investigating the cause of nonconformities
  • Identifying the corrective and preventive action(s) needed
  • Verifying or validating that the action is effective and doesn't introduce a new problem
  • Implementing and recording the resulting changes in methods and procedures
  • Communicating quality problems and corrective actions to those responsible for quality
  • Submitting relevant quality problems and corrective/preventive actions for management review

The most common way this breaks isn't a missing procedure. Almost every firm has a CAPA SOP. It's that the CAPA doesn't do what 820.100(a)(4) requires: verify or validate that the corrective action was effective and didn't introduce a new problem. Investigators pull closed CAPAs and ask a simple question — where's the evidence this fix actually worked? If the file shows a root cause, a containment action, and a closure signature but no effectiveness check tied back to real data, that's a citable gap under 820.100(a)(4) — in my experience, one of the subclauses that comes up most often in CAPA findings.

The second recurring pattern is root cause analysis that stops at the symptom. "Operator error" or "component failure" as a stated root cause, with no further investigation into why the operator made the error or why the component failed, doesn't satisfy 820.100(a)(2). Under the QMSR's incorporation of ISO 13485:2016, the equivalent expectation lives in clause 8.5.2 for corrective action and 8.5.3 for preventive action, and the standard is explicit that the action taken has to be appropriate to the effects of the nonconformities encountered — which presumes you've actually found the cause, not just labeled a symptom.

Subsystem 2: Design Controls

21 CFR 820.30 governs design controls for Class II and Class III devices and most Class I devices with software, and it maps closely to ISO 13485:2016 clause 7.3. The subsystem covers a defined set of design control elements:

  • Design planning
  • Design inputs
  • Design outputs
  • Design review
  • Design verification
  • Design validation
  • Design transfer
  • Design changes

Design history file assembly under 820.30(j) ties the whole record together.

The finding I see most often here is under 820.30(i), design changes. A device clears the design freeze, goes into production, and then something changes — a supplier substitution, a tolerance adjustment, a software patch — without running back through the design control loop to assess whether that change needs re-verification or re-validation. FDA's logic is straightforward: a change that isn't evaluated against the original design inputs is a change nobody actually controlled, regardless of what the document trail calls it.

The second pattern is a design history file that exists but doesn't connect. Verification protocols reference one version of the design inputs, validation reports reference a different one, and nothing in the DHF explains the discrepancy. 820.30(j) requires the DHF to contain or reference the records necessary to demonstrate the design was developed in accordance with the approved plan. The phrase "or reference" is doing real work — it lets records live in other systems as long as the DHF points to them. But a DHF that's a scavenger hunt across a dozen disconnected systems fails that test in practice, even when every underlying record technically exists somewhere.

Subsystem 3: Production and Process Controls

21 CFR 820.70 covers production and process controls, and it's a wide net: process validation, environmental controls, contamination control, equipment maintenance, and manufacturing material controls all live here, alongside ISO 13485:2016 clause 7.5.

The dominant finding pattern is under 820.70(a) and 820.75, process validation. Where a process's output can't be fully verified by subsequent inspection and test, the manufacturer has to validate the process with a high degree of assurance and establish procedures for monitoring and control. The recurring gap is validation that was performed once, at initial qualification, with no revalidation trigger tied to changes in equipment, materials, or personnel-driven process parameters. A process validated three product revisions ago, with no documented rationale for why revalidation wasn't needed, reads to an investigator as a control that existed on paper at one point and has since drifted loose.

Nonconforming product control under 820.90 shows up almost as often. The requirement is to establish procedures to control product that doesn't conform to specified requirements, including a documented review and disposition process. The typical break is inconsistent disposition — the same category of nonconformance gets scrapped one month and reworked without documented justification the next, with no criteria in the procedure that explains which disposition applies when.

Subsystem 4: Management Controls

21 CFR 820.20 is the shortest of the four subsystems on paper and the one most likely to get treated as a formality, which is exactly why it produces findings. It requires management with executive responsibility to establish a quality policy, define an organizational structure with the authority to ensure quality requirements are met, and conduct management reviews at defined intervals under 820.20(c), now aligned with the more detailed management review inputs and outputs specified in ISO 13485:2016 clause 5.6.

The common finding here is a management review that happens, and gets documented, but doesn't function as the standard intends. 820.20(c) requires the review to evaluate the suitability and effectiveness of the quality system — not just report metrics. A management review meeting that lists open CAPA counts and complaint volumes without any documented evaluation of what those numbers mean for system effectiveness, or without action items when the numbers are trending the wrong way, gets cited as a review in name only. Clause 5.6.2 of ISO 13485:2016 is more prescriptive than the old QSR language about what has to go into that review — customer feedback, audit results, process performance, status of corrective and preventive actions — and QMSR-era inspections increasingly check for that specific list.

Purchasing Controls and Complaint Handling: The Cross-Cutting Threads

Purchasing controls under 820.50 and complaint handling under 820.198 aren't standalone QSIT subsystems, but they get pulled into almost every inspection because they intersect all four. A supplier-caused nonconformance touches Production and Process Controls, CAPA, and Purchasing Controls at once; an unresolved complaint trend touches CAPA, Design Controls, and potentially Medical Device Reporting under 21 CFR 803.

The recurring 820.50 finding is inadequate supplier evaluation: a firm approves a supplier based on a certificate of conformance or a one-time audit, with no ongoing monitoring tied to the risk the supplier's component or service represents to the finished device. Under 820.198, the common gap is a complaint file that doesn't document whether the complaint was investigated, and when it wasn't, doesn't state the documented reason why — 820.198(b) requires that reasoning to be recorded, not just implied by silence.

Where the Citations Land: A Subsystem Comparison

QSIT Subsystem Key 21 CFR 820 Citation ISO 13485:2016 Clause Most Common Finding Pattern
Corrective and Preventive Action 820.100(a)(2), 820.100(a)(4) 8.5.2, 8.5.3 Root cause stops at symptom; no documented effectiveness check
Design Controls 820.30(i), 820.30(j) 7.3.9, 7.3.10 Design changes made without re-verification; disconnected DHF
Production and Process Controls 820.75, 820.90(a) 7.5.6, 8.3 Validation not revalidated after change; inconsistent nonconformance disposition
Management Controls 820.20(c) 5.6.2 Management review reports metrics without evaluating effectiveness
Purchasing Controls (cross-cutting) 820.50(a) 7.4.1 Supplier approved once, never re-evaluated against risk
Complaint Handling (cross-cutting) 820.198(b) 8.2.2 No documented rationale when a complaint isn't investigated

What Changed With QMSR

FDA published the Quality Management System Regulation final rule in the Federal Register on February 2, 2024 (89 FR 7496), amending 21 CFR Part 820 to incorporate ISO 13485:2016 by reference in place of the standalone Quality System Regulation. The compliance date was February 2, 2026, which means every device inspection happening now is being conducted against the QMSR framework, not the legacy QSR language many firms built their procedures around a decade or more ago.

The subsystems themselves didn't change — QSIT's four-part structure still governs how investigators approach an inspection, because QSIT is an inspection technique, not a regulatory text, and FDA hasn't reissued it to match QMSR's clause numbering. What changed is the vocabulary and the level of prescriptive detail underneath each subsystem. ISO 13485:2016 is more specific than the old 820 language in several places — management review inputs under clause 5.6.2, for instance, or the risk management tie-in required throughout clause 7 — and firms whose procedures still cite only the old 820 subclause numbers without mapping them to the corresponding ISO clause are the ones most likely to get a documentation-gap finding that has nothing to do with their actual practices and everything to do with an unrevised procedure manual.

If your quality manual, your CAPA SOP, and your design control SOP still reference "the Quality System Regulation" without any cross-reference to ISO 13485:2016, that's worth fixing before an investigator asks which standard you think you're operating under.

How to Read Your Own Risk Profile Before FDA Does

The pattern across all four subsystems is the same: the citation rarely comes from a missing procedure. It comes from a procedure that exists, gets followed partway, and stops short of the step that actually closes the loop — the effectiveness check, the re-verification, the ongoing supplier evaluation, the documented rationale. An internal audit that only confirms procedures exist will miss almost everything on this list. An internal audit that pulls closed records and asks "does this file prove the loop actually closed" will find the same gaps FDA finds, on your schedule instead of theirs.

That's the honest reason mock inspections and gap assessments earn their keep: not because they catch something exotic, but because they ask the same boring, specific question an investigator asks — show me the evidence — before someone with statutory authority asks it first.

For manufacturers navigating the QMSR transition or preparing for their first inspection under the new framework, Certify Consulting's ISO 13485 team works through exactly this subsystem-by-subsystem gap analysis. If you want a second set of eyes on where your own quality system is likely to draw a finding, reach out through Certify Consulting.

FAQ

What is QSIT and why does it matter for FDA device inspections? QSIT, the Quality System Inspection Technique, is FDA's 1999 guidance that structures device inspections around four subsystems: Management Controls, Design Controls, CAPA, and Production and Process Controls. It's still the operating framework investigators use to decide what to sample, even after the shift to QMSR.

Which subsystem gets the most FDA 483 citations? Corrective and Preventive Action, governed by 21 CFR 820.100, is the subsystem FDA investigators sample most heavily. In our experience, effectiveness-check gaps under 820.100(a)(4) are among the findings that come up most often in device inspections.

Did the QMSR change what FDA inspects? The QMSR, effective February 2, 2026, replaced the standalone Quality System Regulation by incorporating ISO 13485:2016 into 21 CFR Part 820. The four QSIT subsystems still structure inspections, but the underlying clause language and level of detail — especially for management review and risk management — now follows the ISO standard.

Is Purchasing Controls its own QSIT subsystem? No. Purchasing Controls under 21 CFR 820.50 and complaint handling under 820.198 aren't standalone QSIT subsystems — they're cross-cutting areas that investigators pull into whichever of the four main subsystems they're sampling.

What's the most common Design Controls finding? Design changes made after design freeze, such as a supplier substitution or tolerance adjustment, without documented re-verification or re-validation under 21 CFR 820.30(i). A disconnected design history file that doesn't tie verification and validation records back to the approved design inputs is a close second.

Last updated: 2026-08-27

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.