top of page

FDA Just Retired the Inspection Technique It Used for Nearly 30 Years

  • Writer: Sharmila Bhatt
    Sharmila Bhatt
  • Aug 3
  • 8 min read

For almost three decades, walking into an FDA device inspection meant walking into a known structure. Investigators worked through the Quality System Inspection Technique — QSIT — a framework built around a handful of core subsystems: management controls, design controls, CAPA, production and process controls, and records/documents/change controls. Quality teams built their internal audit programs around those same subsystems. Consultants sold QSIT-readiness assessments. An entire generation of regulatory affairs and quality professionals learned to think about inspection readiness in QSIT's own vocabulary. As of February 2, 2026, none of that structure is how FDA actually inspects a device manufacturer anymore.

FDA stopped using QSIT that day, replacing it with an updated Inspection of Medical Device Manufacturers Compliance Program — CP 7382.850 — built to align with the new Quality Management System Regulation rather than the standalone framework QSIT represented. Two older compliance documents, 7382.845 and 7383.001, are retired along with it. FDA has held multiple town halls to walk industry through the change, most recently on April 1, and published a new CDRH Learn training module on the topic on April 14. The transition period that gave companies room to adjust has already closed — FDA said so explicitly in the April town hall, in response to a direct question about how manufacturers should prepare for a transition period that, by that point, was already over.


Why this is a bigger deal than a document swap

It would be easy to read this as bureaucratic housekeeping — new document number, same fundamental inspection. That's not quite right, and the reason is structural. QSIT organized an inspection around FDA's own historical subsystem categories, which mapped reasonably well onto the old Quality System Regulation but were always a somewhat FDA-specific way of carving up a quality system. QMSR, by incorporating ISO 13485 by reference, restructures the underlying regulatory expectation around the standard's own clause structure — and the new compliance program follows that same logic rather than preserving QSIT's subsystem framework as a wrapper around the new rule. An inspection built around ISO 13485's clauses doesn't ask the same sequence of questions, in the same order, looking for the same categories of evidence, as one built around QSIT's six subsystems. For a quality organization whose internal audit program, document hierarchy, and inspection-readiness training were all built around QSIT's specific vocabulary and structure, that's a more consequential shift than a compliance program number changing.

This lands on top of a change that already reshaped enforcement priorities this year. Since QMSR took effect, supplier audit records — previously outside inspection scope entirely — are now something an investigator can review directly. When an FDA official walked through the top QMSR-era inspection findings in a separate May presentation, risk management integration and outsourcing/purchasing controls topped the list — categories that map cleanly onto ISO 13485's clause structure but don't correspond to a single QSIT subsystem in the way quality teams are used to thinking about them.


What QSIT actually asked for, and what replaces it

It's worth being concrete about what's changing, because "risk-based" and "ISO 13485-aligned" can sound abstract until you see them next to what they're replacing. QSIT organized every device inspection around six subsystems, and investigators worked through them in a fairly predictable sequence: management controls (leadership's role in the quality system), design controls (a subsystem so central that QSIT guidance directed investigators to always cover it), corrective and preventive action, production and process controls, and records/documents/change controls, with a sixth "other" category picking up anything that didn't fit neatly elsewhere. A quality team preparing for inspection could reasonably organize their entire internal audit calendar around exactly those categories, because that's what QSIT told them to expect.

ISO 13485's clause structure — now the organizing logic behind CP 7382.850 — carves up a quality system differently. Clause 6 covers resource management, clause 7 covers product realization (which folds in design and development, purchasing, and production together rather than treating design controls as a freestanding subsystem the way QSIT did), and clause 8 covers measurement, analysis, and improvement, which is where CAPA now sits alongside complaint handling and internal audit rather than standing alone as its own subsystem. Purchasing controls — QSIT touched on these only glancingly within production and process controls — get their own dedicated clause (7.4) under the new structure, which lines up with what's already showing up in enforcement data: outsourcing and purchasing controls ranked as the second most common QMSR-era inspection finding in FDA's own May 2026 presentation on the subject, right behind risk management integration. That's not a coincidence. It's what happens when the inspection framework itself elevates a topic that used to be a subordinate line item inside a bigger subsystem.


Part of a wider pattern, not an isolated device-side change

Device manufacturers watching this shift shouldn't assume it's confined to CDRH. On the drug side, CDER has been running its own parallel modernization: a new Pre-License Inspection compliance program (7346.832M) published April 14 — the same week CDRH's new CDRH Learn module went live — and a revised Pre-Approval Inspection compliance program (7346.832) published June 29, both explicitly framed around risk-based inspection approaches rather than the older, more uniform models they replace. Across both centers, FDA is moving in the same direction at roughly the same time: away from fixed, checklist-style inspection techniques that treat every facility the same way, and toward frameworks that flex based on a manufacturer's actual risk profile, history, and the maturity of its quality system. A company that only tracks device-side changes, or only tracks drug-side changes, is likely to miss that this is a single agency-wide shift showing up on parallel tracks — which matters if your organization operates across both device and drug/combination product lines, since the underlying philosophy driving both changes is the same even though the specific compliance program numbers differ.


What actually changes in practice

The new compliance program describes updated inspection models and a post-inspection regulatory strategy that's explicitly framed as risk-based — meaning the scope and depth of an inspection is more directly tied to a manufacturer's risk profile and history than the older, more uniform QSIT approach. For a company with a strong compliance history, that can mean a narrower, more targeted inspection. For a company with prior findings, an unusual product risk profile, or gaps in recent post-market data, it likely means the opposite: a deeper, more comprehensive review than QSIT would have triggered under similar circumstances.

The practical consequence for quality teams is that internal audit programs modeled directly on QSIT's subsystem checklist need to be re-mapped, not just relabeled. A CAPA-subsystem audit checklist built for QSIT doesn't automatically produce evidence in the shape an investigator following CP 7382.850's ISO 13485-aligned structure is looking for, even if the underlying quality activities are identical. The gap isn't in what companies are doing — it's in whether their internal readiness materials speak the same structural language as the inspection they're actually going to face.


What the town hall revealed about where confusion still lives

FDA's April 1 town hall included a live Q&A, and the questions industry actually asked are as informative as the presentation itself. One attendee asked how manufacturers should prepare for the transition period leading up to the February 2026 effective date — a question that, on its face, assumed there was still time to prepare. CAPT Kimberly Lewandowski-Walker's answer was direct: the transition period had already ended, and this had been addressed in prior webinars. That exchange is worth sitting with, because it suggests a meaningful share of industry either missed the earlier webinars or assumed the compliance program change would follow the kind of extended, forgiving runway that some other major regulatory transitions have gotten. It didn't.

A second question asked whether FDA had training or educational material specifically addressing QMSR requirements and inspections. Keisha Thomas, Associate Director for Compliance & Quality, confirmed that CDRH Learn's Device Advice webpage hosts modules built specifically for this purpose — meaning the resource already exists, and any quality team still operating on outdated internal materials has a direct, agency-published alternative available rather than needing to reconstruct the new framework from inference alone.


Why the timing compounds the risk

The QSIT retirement doesn't land in isolation — it arrives on top of a full year of QMSR-related change that's already stretched a lot of quality teams thin. Supplier audit records entered inspection scope for the first time under QMSR. Purchasing controls and risk management integration are already the top two QMSR-era inspection findings FDA is citing. And now the inspection technique itself — the actual sequence and structure an investigator follows when walking through a facility — has changed underneath all of it. A quality team that spent the first half of 2026 updating its purchasing-controls documentation and supplier qualification records to meet the new substantive requirements, but hasn't yet revisited how its internal audit program is structured, has done real work that's still incomplete: the content may be QMSR-compliant while the readiness process built to demonstrate that content is still organized around a framework FDA stopped using in February.


Turning this into practice

The near-term items are straightforward and worth doing before your next scheduled internal audit, not after:

  • Pull your current internal audit checklist and confirm whether it's still organized around QSIT's six subsystems. If it is, remap it against ISO 13485's clause structure (particularly clause 7.4 for purchasing, and clause 8 for CAPA, complaint handling, and internal audit) rather than simply relabeling the existing categories.

  • Confirm whoever hosts or supports FDA inspections at your facility has been briefed on the actual structural change, not just the effective date. Muscle memory built over years of QSIT-structured mock inspections doesn't update itself.

  • Walk through CDRH Learn's dedicated QMSR inspection module directly, rather than relying on a consultant's summary or an internal training deck that may predate the April 14 release.

  • If your organization spans both device and drug/combination products, loop in whoever tracks CDER's parallel PLI and PAI compliance program updates — the underlying risk-based philosophy is shared, even though the specific programs and effective dates differ by center.


The longer-term shift is less about any single checklist and more about how quality organizations think about inspection readiness going forward. QSIT gave the industry three decades of a stable, predictable, FDA-specific vocabulary to organize around. That stability is gone, replaced by a framework tied directly to an international standard that FDA doesn't control the wording of and that gets its own periodic revisions independent of FDA's own regulatory calendar. Quality organizations that build their inspection-readiness programs around genuinely understanding ISO 13485's structure — rather than around whatever FDA-specific interpretation layer happens to sit on top of it this year — are better positioned for whatever the next structural shift looks like, because the standard itself is now the stable reference point, not FDA's inspection technique du jour.


None of this means the underlying quality expectations changed overnight — a company running a genuinely mature, ISO 13485-aligned quality system under QMSR should find the substance of what it's already doing largely unchanged. What changed is the lens FDA uses to examine that system, and a quality organization whose internal readiness materials are still speaking QSIT's language is preparing for an inspection that, as of February 2, no longer happens.


Sources: U.S. Food and Drug Administration, Inspection of Medical Device Manufacturers Compliance Program (CP 7382.850); FDA Town Hall, Medical Device Risk-Based Inspections, April 1, 2026; CDRH Learn, QSMR: Medical Device Risk-Based Inspections module, April 14, 2026; FDA Overview of Device Regulation.

Comments


bottom of page