Medical Device Quality, Regulatory and Product Development Blog | Greenlight Guru

Behind the QMSR Audits: The Top 5 FDA Citations & Risk Management Pitfalls

Written by Etienne Nichols | September 21, 2026

In this episode of the Global Medical Device Podcast, host Etienne Nichols sits down with Nikhil Mangale, Vice President of Quality at Kapstone Medical, to discuss the real-world impact of the FDA's Quality Management System Regulation (QMSR). Seven months post-implementation, the industry is seeing actual inspection data that shifts the focus away from superficial documentation updates and directly onto core quality system operations.

Nikhil breaks down the top five areas where the FDA is issuing citations under the new regulation: risk management, supplier controls, complaint handling, Unique Device Identification (UDI), and corrective actions. The discussion highlights how the industry spent years worrying about renaming documents like Design History Files (DHFs) to Design and Development Files (DDFs), yet inspectors are bypassing mere translation projects to evaluate how information flows across living quality processes.

The conversation offers actionable guidance on conducting thorough, multi-layered gap assessments for both active and legacy products. Nikhil provides strategic advice for small companies and startups on prioritizing risk management, handling supplier audit visibility, navigating ISO 13485 alignment, and weighing the benefits of participating in programs like MDSAP.

Watch the Video:

Listen now:

Love this episode? Leave a review on iTunes!

Have suggestions or topics you’d like to hear about? Email us at podcast@greenlight.guru.

Key Timestamps

  • 00:33 - Introduction of guest Nikhil Mangale and overview of QMSR inspection insights.
  • 01:39 - Nikhil’s background across large enterprises and mid-size to small medical device organizations.
  • 03:03 - What surprised the industry most: FDA focusing on operating models rather than terminology translation.
  • 04:25 - Detailed breakdown of the top 5 FDA citation areas under QMSR.
  • 07:57 - Why risk management process failures lead current inspection citations over static files.
  • 10:12 - How FDA’s new compliance program (CP 7382) replaces QSIT with a risk-driven approach.
  • 12:14 - Increased scrutiny on supplier controls and the newly unmasked visibility of internal supplier audit reports.
  • 16:28 - DHF vs. DDF: Shift from a closed design record at launch to an active lifecycle file.
  • 18:50 - Regulatory expectations for legacy products and conducting proper gap analysis.
  • 20:09 - The 3 layers of QMS mapping: Terminology, clause conformity, and operational evidence.
  • 22:27 - Execution framework for a 4-pass QMSR gap assessment and building a defensible quality plan.
  • 25:16 - Pragmatic QMSR implementation order for small companies and startups.
  • 27:42 - Status of ISO 13485 revisions and rule-making implications.
  • 28:51 - Clarifying ISO 13485 certification vs. FDA inspection exemptions and MDSAP benefits.

Top takeaways from this episode

  • Prioritize Risk as a Living Process: Risk management must continuously integrate post-market feedback, complaint data, and nonconformances rather than remaining a static file archived after design release.
  • Re-evaluate Supplier Audits for External Scrutiny: Routine supplier audit records are now accessible to FDA inspectors; ensure reports are well-documented, audit schedules are risk-proportionate, and findings are formally resolved.
  • Implement a Three-Layer Mapping Strategy: Move beyond surface-level terminology updates (Layer 1) to establish subclause conformity (Layer 2) and verify operational evidence across interrelated processes (Layer 3).
  • Maintain Open Design and Development Files (DDF): Unlike legacy DHFs that were closed at commercial launch, DDFs must remain active throughout the product lifecycle to evaluate ongoing design changes.
  • Formulate a Defensible Quality Plan: When addressing gaps, document a risk-prioritized, sequential quality plan to show objective evidence of a structured compliance roadmap during an inspection.

References:

  • FDA Compliance Program CP 7382.045: The FDA inspection guidance replacing QSIT, organizing surveillance around core QMS areas and specific regulations.
  • ISO 13485:2016: The international standard for medical device quality management systems incorporated by reference into the FDA's QMSR.
  • Etienne Nichols LinkedIn Profile
MedTech 101 Section

Design History File (DHF) vs. Design and Development File (DDF)

Think of a Design History File (DHF) like a house's original architectural blueprint and construction binder—it details how the house was designed and built up to the day you moved in, after which the binder is filed away. Under the QMSR, the Design and Development File (DDF) Etienne Nichols: acts like a living home maintenance log. It includes those initial blueprints, but it must be updated every time you renovate, repair, or upgrade the home throughout its entire lifespan to ensure structural safety.

Memorable quotes from this episode

"The industry spent two years on a translation project, and FDA showed up to inspect an operating model." - Nikhil Mangale

"A stale risk file is worse than an incomplete one. An incomplete file is a gap, but a stale file actually points them at the wrong things." - Nikhil Mangale

Feedback Call-to-Action

We want to hear from you! What challenges are you experiencing with your QMSR implementation or risk management files? Send your feedback, reviews, or topic suggestions directly to podcast@greenlight.guru. We personally review and respond to every message from our listeners!

Sponsors

This episode is brought to you by Greenlight Guru. Navigating the shift to QMSR requires a quality system designed specifically for the medical device industry. Greenlight Guru provides dedicated QMS (Quality Management System) and EDC (Electronic Data Capture) software solutions that connect your risk management directly to post-market surveillance, complaint handling, and design control workflows. Keep your quality system inspection-ready and maintain seamless data visibility across your entire product lifecycle by visiting Greenlight Guru.

 

Transcript

Etienne Nichols: Hey everyone, welcome back to the Global Medical Device Podcast. My name is Etienne Nichols. Today I'd like to talk a little bit more about QMSR. We've covered this a couple times in the past, but it's been it's been some time. And now it's we're to the point where we have real world data. We have some actual the ability to look and see how the investigations have gone from the from the FDA side and the inspections there. So, with us today to talk about this is Nikhil Mangale.

Who is the vice president of quality at Kapstone Medical? It's a role he's held since July 2024 after previously serving as the company's senior director of quality. He brings nearly two decades of medical device quality leadership experience, having risen through progressively senior roles at LinkBio Corp., Stryker Orthopedics, and Boston Scientific. I so he has deep expertise in FD and EUMDR compliance, GMP, change management.

Along with the track record of driving supplier quality improvements and leading cross-functional teams through complex regulatory challenges. So, I think he's the right man for the job today. We want to talk a little bit about QMSR, and you know, whatever advice you have for us in the industry. So, I'm curious, well, first of all, how are you doing? Welcome to the show.

Nikhil Mangale: Thanks, Etienne. Glad to be here. Looking forward to having this great discussion. And thanks for the introduction, really. I mean, it's really been an exciting journey so far. I mean, in I started my career with Boston Scientific. I was lucky enough to get trained in Boston Scientific and Stryker. And then I got to use my knowledge to apply in mid-sized companies. And now I'm helping small companies, which means I'm not living inside one system.

I'm inside a different one every few weeks. So, for a typical party professional, if you're inside of one company, you have one data point, I get to see the pattern. That's and that's why I'm here today to just share my thoughts about QMSR. for the last two years, people have been thinking about this change and have been thinking about this change. And now that QMSR is here, a few things that have surprised me and I felt like people it will help people learn about this so that it helps them clear their perspective towards KMSR.

Etienne Nichols: Great. Well, appreciate you willing to share your knowledge. I think it was, was it three and a half years ago when the FDA first came out with the proposed rule? I can't remember. I joined that FDA town hall, and it was interesting just the thought. Everybody was just all in an uproar. And here it is now, seven months past, and you like you said, you've seen a lot of different things and seen a lot of different QMS. At this point, seven months past, what surprised you most about what's actually happening in the industry?

Nikhil Mangale: Honestly, what surprised me was what didn't happen. So, everyone spent two years worrying about the terminology, right? Like do I rename my DHF? What do I call my device master record? Do I have to rebuild my file structure? And then the inspection started. And terminology is basically not on FDA's citation list.

So, from FDA's own ranking, the top five are basically risk management suppliers, complaint handling, UDI, and corrective actions. And not one of those five is about what you call device history record. So, the industry spent two years on translation project and FDA showed up to inspect an operating model. So, this was most surprising to me. Like none of the top five citations are about documentation, but they are really about how your quality management system is operating.

Etienne Nichols: Hmm. Yeah. And I remember the DHF, DMR, DHR. That's my favorite article. You know, I had a change point to the DDP and several MDF and so on, but you're right. That two-year exercise really should have been a two-week exercise if your human is healthy. but the more realistic things, the more the more impactful things, like you said, risk management, corrective action. So, you've looked at the early inspection data now. What are companies like you mentioned a few.

What can you get into a little bit more specifics about what they're actually being cited for?

Nikhil Mangale: Absolutely. So, the five areas that I mentioned, right? And this is based on India's order. So, the first one is risk management. So almost all companies have risk file. What they don't have is risk passes, right? So, the risk file is built at design release and it's never touched since. So that is lining that is landing as a location for most companies. Second is suppliers. Many supplier controls that are uniform and they should be proportionate.

So, which doesn't align with the new requirement. Yeah. And supplier audit records that nobody outside the company had ever read before, now they are available for FDA to review. So that is one area where the reports were written in such a fashion that nobody ever thought for the last 30 years that anyone else would be looking at them other than the company itself. So now it is revealing all the secrets and all the issues.

So that's another area where citations are landing. Third is complaint. This is usually an interface problem. What I mean by that is something that's functionally a complaint coming in through a channel that was never wired into the complaint system. And returns are the classic ones. Like you know, returns come in, people process those returns, and since they are not wired into their complaint system.

Some of those returns they never make into the complaint systems. And I'm seeing a lot of simulations being done. Fourth is UDI. This one is a little bit different. It's mainly around the data accuracy and laboring requirements rather than the rather than the system maturity itself. And fifth one is corrective actions. And the thread through four of those five is whether information actually moves between the system.

If you look at these systems, they each work fine on their own, but what MDA is looking for is how the information is flowing through these east systems. And these are the areas where most of the companies are exposed and they are experiencing some patients.

Etienne Nichols: And I think there was it's interesting because I think what was it 21 CFR, part eight twenty dot forty-five where they started referencing the UDI and the QMSR? The way I looked at that when it first came out was not really anything new. It's just ISO 1345 is not quite up to what the FDA had current expectations were.

So, they basically put that as a placeholder and say, okay, I said 1345 is not doing away with the UDI requirements. And so, UDI, it's almost like been a parallel thing. And I've been surprised that there haven't been more citations from that. I mean are the citations related to UDI are they really real are they does is QMSR any impact on that or is it kind of its own it just probably would have happened regardless. What are your thoughts there? I'm curious.

Nikhil Mangale: So basically, what they are looking at is the claims that you're making on UDI and were those checked before the product was released, right? Yeah. I have not looked at this particular topic in depth to give a very sensible answer, but that's what my discipline is. And I'm pretty sure we are gonna learn more as time goes and we have more and more information, published information available.

Etienne Nichols: Yeah. It is interesting how, you know, some of the inspection results and why they've changed. And I'm sure a lot of different things have changed, but maybe to that point, what maybe we talk about what has changed and why is it why is it coming down this way? So, any thought as to why risk management. I mean it's it seems kind of like an obvious, but why that would be the top citation area rather than documentation area, like you said, DHA D all the different acronyms that used to be FDA specific.

Nikhil Mangale: Absolutely. So, risk management because almost every company has a risk management file, but almost nobody has a risk management process. What I mean by that is the risk management file gets built during design, it gets approved, and then it goes in the drawer. Yeah. Then for five years, you collect companies are collecting complaints, they open nonconformances, they change suppliers, and none of this information is flowing back.

Into your risk file. So basically, your hazards are ones you imagined before launch, not the ones that the field taught you, right? So, under the old rule, you could survive that because risk essentially showed up basically at one place at design validation. But under ISO 1345, it runs through product realization as its own documented process.

If so, the citations that I'm seeing is not that your risk file is wrong, but they are saying that you don't have a process, if that makes sense. So, and like historically investigators would typically start with a checklist, but now then no one is using checklist anymore. They are the inspections are designed around the risk.

Because the risk runs throughout the product lifecycle. So that is one thing that investigators are going to first. And that's the whole intent of QMSR, right? I mean, as I mentioned before, it is not a translation project. It is not just limited to the terminologies. The new standard expects you to enforce risks throughout product realization. So, it's natural for any investigator or an auditor to start with response.

Etienne Nichols: Yeah, that makes sense. it's interesting because you mentioned the checklist mentality or the previous, which you know, if we look at QSIT, the quality system inspection technique, the fact that it's been done away with and replaced with CP 7382 is you know yeah. Yeah, so I mean, yeah, it's a different technique for sure, how they're approaching it.

So that being said, I'm curious, I mean the FDA's been kind of touting the risk-based approach to a lot of different things for a while now. What does that actually look like when they're in the building? They're actually looking at your files and so on. What does that look like in your mind?

Nikhil Mangale: Absolutely. So, as I mentioned, right? I mean, basically it means the investigator is not working from a checklist anymore. So, and as you said, QCIT was withdrawn on February 2nd, and it was replaced by compliance program. And the compliance program is basically organized, it organizes the inspection around six QMS areas, mainly quality management system, sorry, party management oversight.

Design and development, change controls, supplier controls, production and service provisions, measurement, analysis and improvements, plus four FDA-specific requirements, which are MDR, corrections and removals, device tracking and UDI. So, during inspection, you know, which record gets pulled inside those areas is purely a judgment call driven by the product risk.

FD is in clear there is no statistical sampling. Investigators basically review what they think they should. So, one might wonder like what tells them what's risky here, right? So, your own risk documentation tells you that. Your own file is now the navigation instrument for an investigator. So, which is why a stale risk file is worse than an incomplete one. an incomplete file is a gap.

But the stale file actually points them at the wrong things. What I mean by that is when there is a difference between what your file says is risky and what your complaint data says is risky, that becomes its own finding. If you have never touched your risk file, you have never gone back and updated your risk file based on your current complaint data, then the two are gonna say two different things. They're not gonna speak with each other. And that is becoming its own finding. Cause that shows that you're not you utilizing your risk management process as it is intended. That makes sense.

Etienne Nichols: Yeah, that makes sense. And you had you had mentioned a few others. I think outsourcing, so purchasing as some of the more the second highest citation area. Why is that? What in your mind? Why suppliers?

Nikhil Mangale: That's this this one is really interesting one. And this is because two things happened, right? once QMSR went into effect. First, the records became visible. supplier audit reports used to be exempt from routine FDA review. So, people wrote them from an internal audience perspective. Those reports were very candid, blunt, they had open issues, nobody closed because nobody outside was going to read them.

These are now real regulatory evidences, right? And secondly, most supplier programs are uniform when the standard really wants them to be proportionate, right? What I mean by that is you might have a supplier who is doing label printing, and you might have a supplier providing you implants. But most programs they will send them the same questionnaire, same three-year audit cycle.

And that's really not efficient because your supplier program should be proportionate to the risk that the supplier is providing to the product itself. So, if you don't have a program that is proportionate, it's an that is proportionate to your supplier, it's an evidence you haven't applied risk-based thinking to the purchasing.

Etienne Nichols: Yeah. Yeah. That makes sense. Yeah.

Nikhil Mangale: These the two areas I think most people they never worried about these things, but now since KMSR has got into effect, these are two areas investigators are honing on and issuing citations around.

Etienne Nichols: Yeah. That makes sense. When I think about like, okay, so if we move on from these are the real impacted areas, actual supplier quality, because that's it that's impacting your product quality, really. Because if you don't have good supplier consistent quality from there, your product itself will it it's gonna translate. And same with your risk management file. If you're not implementing risk management, that all makes sense. Some of the I mean we could argue about terminology.

Because like you mentioned, there were two years where people were just like, what are we gonna do with DHF? So, what how are they dealing with that? Is I know design and development plan or design and development file, we talk about the medical device file, we talk about all these different other maybe or batch record, lot record. What how are how are those differing? And are they just direct correlations? Do they say anything about them at all during an inspection?

Nikhil Mangale: Yes, so what I have been noticing is that whenever the requirement comes from a standard, FDA cites the ISO clause and where it's FDA's own addition, 20, they cite the CFR section. So, you will see in in the citations that it is they are no longer just referring to CFR section.

Which means if your SOP still map only to let's say eight twenty thirty and eight twenty hundred, you won't be able to trace your own warning letter back to your own quality systems. Your procedure and the enforcement documents will be written essentially two different languages. So yeah, I mean what have a good point. Like, you know, the citation is now equally important. Like you cannot just rely on CFR citations. You also want to make sure that you're including SO clauses in your SOPs so that when citations you can place it appropriately and fix the right areas.

Etienne Nichols: Yeah. Okay, it makes sense. And so, the ISO 1345 clause numbers, they're actually being they're being cited in in enforcement documents, is what you're saying. Yes.

Nikhil Mangale: Yes, they are directly being cited in the enforcement document for NFD is also citing CFRs for their own additions. Because remember, HMSR the backbone of HMSR is episode 1340, almost everything from ISO 1345 but it also has these conditions to it. Which means people sometimes…

Etienne Nichols: Right. Yeah. Do you ever see any definitions from like ISO 9000 reference? I haven't I haven't been paying attention for that. I don't know if those were referenced or not, just because some of the ISO 1345 definitions, I think some of those call back to nine thousand. Isn't that, right? Or…

Nikhil Mangale: You might be right. yeah. You have not honestly, I honestly have not compared the definition. Just…

Etienne Nichols: But not seen that.

Nikhil Mangale: Focusing on 3045.

Etienne Nichols: Yeah. Well, that being said, so do they do they use the terminology DHF and or at all or did is there any preference there?

Nikhil Mangale: Okay, so this is interesting, right? I mean, if you look at DHF, DHF is essentially the design history file, and the design history file was a record of what you did. Yeah. It basically documented inputs, outputs, verification, animation, design transfers, reviews. Basically, it's an historical record. And the design and development file, which is a new terminology for QMC.

It contains or references everything needed to show you met the design requirements. And FDA's own preamble calls it consistent with the former DHL. So, the content overlap is large. The difference that matters is emphasis. So, the design and development file carries traceability of design changes across the product's whole life, not just to the launch, right?

And the clause 739 really makes you evaluate the significance of rechange to the function, performance, usability, safety, and to the product quality ship. So basically, design and development file, DDF, it's a file sorry, I mean the design history file is a file that closed at the launch versus design and development file DDF is a file that stays open as long as the device is on the market. So, if your file is closed, that's essentially a gap.

Etienne Nichols: Yeah. So okay yeah. Yeah. So, the DHF's gone. And really, we need to be focusing on the ISO those the way things are built out there in seven point three. Yeah, that makes sense.

Nikhil Mangale: The way you call it is different, but the intent is the same and now it goes beyond the launch, right? historically DHS were closed at the launch, we're done with it. They were open during inspections. But now design and development needs to stay open because it constantly you constantly need to feed in all the information into DDF, late your DDF, based on what you're learning from the feedback.

Etienne Nichols: Okay. Well, so some of the things you mentioned, I mean, we talked a little bit about some of the inspection findings. what should companies even be doing this? I mean, I'm thinking about like I mean, it makes sense for future devices that are coming in the market. Okay, just get DHF out of your mind, focus on the ISO 34573, and develop your products under the DDF. But what about legacy products? Products that are on the market, been there for 15 years with the DHF, like you said, no one's ever opened. What about that? What do you think?

Or just what's you thinking?

Nikhil Mangale: Well, there is some relief there, and it's real, right? FDS said on the record it does not expect you to go back into pre-February files and add and add ISO references. And it does not expect you to scrub them for old terms like design history file. Nobody is getting saved for the word DHM. Yeah. But FDA also said investigators may review records created before the effective date, and they recommend you to conduct a gap analysis of legacy designs still being marketed. So, the file doesn't need rewriting, it's just need examining.

Put it in simpler words, right? Like you don't have to repaint values. You do have to check the wiring. And for a 12-year-old product, the wiring question is always the same. As anything the field taught you in the last 12 years made it back into the list form. If not, that's a legacy documentation problem. And that's likely.

Etienne Nichols: Okay. Well, I know capstone has established a guide on mapping the DHF to ISO 3025. Greenlight Guru also has a map your DHF DMR DHR terminology to ISO 1345 terminology. now that we've kind of been seven year seven months, not seven years, seven months in the yeah, on the market with QMSR, what does it look like in practice? Anything you change out of those ultimate guides?

Nikhil Mangale: So, what I've seen, like a real mapping has three layers, right? And most people stop after the first one. The layer one is which everyone knows, it's terminology. Like DHF maps to design and development file, DMR, the medical device file, DHR to production and service record. This is basically just a table. It takes an afternoon, you know, for you to update your SOPs. And most people kind of stop there.

It proves nothing but compliance. It tells you what to call things, not whether they are right. Layer two is clause level conformity. So, what I mean by that is for every subclause, can you point at the record that satisfies it? And if you think about design transfer, right? The design transfer is usually the first surprise. Like most people under 82030, 82030, most people treated design transfer as an event that involved a signature and then handoff. But if you look if you look at clause seven dot three. So that's a process, not a moment, right? And the third layer is operational evidence.

And almost nobody has done it. It is not just does a procedure exist, but when the device changed in 2023, did that change follow through change evaluation into the risk file, into the medical device file, into supplier controls? That's what an investigator traces. That's where the segmentation is available.

Etienne Nichols: Yeah. As a manufacturer an ex-manufacturing engineer moved to product development engineer and then and then a project manager when I got my PMP and I was develop leading a drug delivery accommodation product. I very much I think about, you know, my line item in Microsoft Project where it said design transfer. That was not one line item. I mean, we had the master validation plan activities, like you okay, PQs, all those different things.

There's a lot there that needs to be in your processes so that that handoff is more than just a signature because otherwise your product is going to fall flat for sure. So, I'm totally with you on that. so okay, when you when you are evaluating companies and talking to companies, because you talk to a lot of QMS’s, or a lot of lot you live in a lot of different QMSs from week to week for your clients and your and so on. What does a gap assessment look like for you? What does it consist of? What are you looking for in…

Nikhil Mangale: That's a great question. So, I would run it in four phases, right? Four passes basically. roughly in this order. The first is the risk assessment. because that's where FDA starts. Is risk documented as prices?

Cross-product realization is the file line. Can you show me a complaint from last quarter arriving in it? These are the things that I'll be looking at the at first. Second is the interfaces between different elements of QMS. So basically, making sure complaints are making to risk, non-conformances are making to CAPAs, service records into feedback, returns into complaints. Most party systems are healthy at the organs and broken at the connective tissues. That's where investigators are honing on, and that's where most of the organizations fail problems. So, we focus on that to help fix those kinds of issues, right? And third, the FDS-specific overlays, as I mentioned before.

Because these are the parts that ISO 1345 does not cover, and people genuinely forget. Things like UDI, device tracking, reporting, corrections and removals, plus the record content and labeling controls, right? And fourth, the records that just became visible. So basically, just go back and read your last three years of management reviews.

Internal audits and supplier audits. Because these are the records that investigators were not looking before, but now they will. If you have open findings with no closures, audits that never happen, actions with no effectiveness, evidence, these are going to be a real problem moving forward. These were all hidden before because these documents were exempt from FDA, but now they are no longer exempt.

So, these are real regulatory evidences, right? And once we go through all of these things, then it has to end in a prioritized plan, not a list of 140, 150 findings, right? Because a finding list is a liability and a sequence plan is a defense. So, if you have a plan, you can defend it.

So, I typically advise our customers. at Kapstone, we typically advise our customers to create a documented quality plan and prioritize it based on the risk and then focus on completing each task. So even if you find yourself in a situation where FDA shows up, and if you're not yet compliant, but you at least can demonstrate with objective evidence that you have a plan, you have a thought process, and you have a response approach. That's better than having nothing, I would say.

Etienne Nichols: Yeah, that makes sense. And if you're a small company, is there anything different you'd do or recommend if someone who doesn't have a full-time quality lead.

Nikhil Mangale: Absolutely. So, if you're a small company, you really don't need a complete quality system. You need a true one. What I mean by that is you need a system where every procedure describes something the company actually does, right? The failure I see consistently isn't missing procedure. It's inherited ones. What I mean by that is somebody bought a template pack, it describes a 200-person organization, right? And now a 15

People are non-compliant with their own SOPs. Because for a small startup, you really don't have that big resources, and you have very limited number of resources, and they are not able to keep up with the QMS that is really meant for 200 people organization. And investigators recognize the boilerplate immediately. And really, a procedure you don't follow is worse than one you don't have. So, the sequence for QMSR specifically is.

I'll focus on risk management first because it is the through line and it's the FDS top citation. Then the design and development, because that's where your product actually lives. Then document control and supply controls, and then the FDS specific overlays such as UDI, reporting, corrections, and removals, which to be honest, most startups have never touched because they weren't relevant pre-market, right?

And what else? Yeah, so that that's pretty much it. So, I'll as I just to reiterate, I'll just start with risk management first, then design development files, and then the document controls, supplier controls, and then every specific overlays.

Etienne Nichols: Yeah. And I guess just I guess clarify what you said, which I think I mean I know I think I know what you meant when you said a small company doesn't necessarily need a full QMS, that's pre-market. If you're if you're not on the market. Yes, yes. Yes, if you're on the market, you might be a small company. Yeah.

Nikhil Mangale: Thanks for bringing that up. That's a very important point. If you're pre-market, that's very important. Yeah.

Etienne Nichols: Right. Yeah. There’re those interesting milestones where different things start to make sense. And maybe that's a topic for a different day. But okay, so a couple other questions because ISO 1345 is now incorporated by reference in FDA's QMSR or yeah, QMSR Party twenty. So, there's some question in the industry, okay, well what about when ISO 1345's going to be revised. It's twenty sixteen right now. It was I think the previous version was two thousand three. So that's pretty get big gap, but things are changing pretty fast. any thought as to when it will be revised again?

Nikhil Mangale: Luckily not anytime soon. Yeah. Right. And that's a good news. I mean, if you just spent a year remediating, you don't want to go through this again, right? ISO 1345 2016 went through its systematic review and was confirmed in October last year. So, the standard stands. No new edition is in the pipeline as far as I know. And because FDA incorporated the 2016 edition specifically.

A future revision wouldn't automatically become US law. So, I don't think anyone has to worry about that. And FDA has said it would have to go through rulemaking again for future revisions.

Etienne Nichols: Yeah. Yeah. That is good and that's comforting for I'm sure for those and I I think the reconfirmation date for ISO 1345 is what is that, every five years so 2030 would probably be the next…

Nikhil Mangale: Twenty thirty would be the next one. Yeah.

Etienne Nichols: Okay, and a couple other questions because I know some people have asked this in the past. What about certification? I'm ISO 1345 certified. Why am I getting an FD inspection? Does ISO 1345 certification exempt you from an FD inspection? Or and maybe we can touch on MDSAP too. But let's start, let's answer the first question first.

Nikhil Mangale: Okay, so the way I would talk about this is I want our listeners to understand that do I need a certification? No. If you don't have an ISO 1345 certification, you don't need it. But if you do have it, that doesn't exempt you from FDA inspection. FDA's FAQ is unambiguous. The age the agency won't require certificates, they won't issue them, and a certificate doesn't exempt you.

From inspection. Basically, certification really tells you tells your system was designed correctly, and inspection asks whether you ran it correctly. So, these are two different things. So, to answer your question, no, certification is not a requirement. and having one doesn't exempt you from FD inspection.

Etienne Nichols: Yeah. What about MDSAP? Now that you know QMSR's adopted the standard…

Nikhil Mangale: Okay, so MDSAP that depends entirely on your markets, right? Like Health Canada requires an ISO 30 1345 certificate for Class II through Class IV products. And MDSAP is the route they accept. So, if you sell into Canada, the question is close. You don't have to worry about it; you don't want to have to think about it. But if you sell in the US and EU, the map changed when QMSR adopted the standard.

But before anyone drops it, FDA's own compliance program says surveillance inspection aren't conducted at sites actively enrolled in MDSAP. So that's a real benefit you would be giving up if you drop MDSAP. So, my recommendation would be if you are enrolled in MDSAP, I think there is a benefit to it.

Etienne Nichols: Yeah. To say that. Yeah. Yeah. If you if yeah, I don't think if you're in if you're in Brazil, Canada, Australia, what's the other one? Japan. yeah. So yeah. Neat so yeah, that's a good point. So, and what would you say to anyone listening who thinks they've, you know, well, you know, we're not worried about an FDA inspection now that QMSR is here. any pieces of advice you give that company.

Nikhil Mangale: Yes. So as a starter, I would say go open your risk management file and look at the revision date. If it hasn't changed since the design release, you're not done. doesn't matter how clean your terminology mapping is, right? Because that risk management file is now the first thing an investigator uses to decide what to look at. And you and your file describes a product.

That stop existing the day you started learning from the field. So yeah, go back to your risk management file. That's the start best starting point for you to look at. And remember, the cheapest gap is the one you find before an investigator master, right? Because I mean, do I really need to explain why? I think people under people understand what I mean when I say that.

Etienne Nichols: You know. Yeah, don't let the FDA be your internal audit system.

Nikhil Mangale: Exactly. Exactly.

Etienne Nichols: Awesome. Well, thank you so much. I really appreciate you coming on the show and talking through your experiences and what you've seen in the field. So yeah, like where can people find you to learn more about what you're doing and get a hold of you if they have more questions?

Nikhil Mangale: So, people can always visit or find us on LinkedIn, and they can visit us at medical.com. And you can find me on the LinkedIn as well. I will I will provide you with information. Hopefully you can just include in the podcast for people to see. And at the end, really, I just wanted to take some time to thank you for taking the time to have this discussion.

Dream the goals, doing breach.

Etienne Nichols: Absolutely.

Nikhil Mangale: The uses Green and Bureau as well and build the system. It's always interesting to learn about different topics and listen to different topics that you have with various other professions.

Etienne Nichols: Thank you so much. Really appreciate you coming on and like I said, just being willing to share your experiences and thank you for the for the kind words. Those you've been listening, really appreciate you hanging in there, listening with us on this topic. You know, QMSR, it feels like it should be over by now, but it's really just getting started because now, you know, the FDA inspections are happening. So, definitely you want to be ready for when they come for you.

So, get ready so you don't have to stay don't get ready and stay ready you don't have to get ready in the future or do remediation. I've done remediation for at fault FDA inspections and it's not fun. So, we'll have to talk about that some other time, I guess. But thank you so much for listening. And we'll put the links in the show notes so that you can get a hold of the team over at Kapstone. And if you have any more questions, they'd definitely love to hear from you. And they're a welcoming bunch over there. I they've always been really good to me at the different events that I've seen them at. So, all right.

Thank you so much for everybody being here. Take care.

Nikhil Mangale: That's again bye.

 

 

About the Global Medical Device Podcast:

The Global Medical Device Podcast powered by Greenlight Guru is where today's brightest minds in the medical device industry go to get their most useful and actionable insider knowledge, direct from some of the world's leading medical device experts and companies.

Like this episode? Subscribe today on iTunes or Spotify.