Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

QMSR Internal Audit report marked as withdrawn with inspection update.

QMSR Internal Audit: Why FDA Can Now Read Your Reports

QMSR internal audit reports can now be read by an FDA investigator. Until 1 February 2026 they could not — section 820.180(c) of the old Quality System Regulation put them, along with supplier audit reports and management review reports, outside what FDA could review. That protection no longer exists, and a great many quality systems are still written as though it does.

This guide covers exactly what changed, what replaced the old certification route, how to write audit reports that survive being read, and what to do about a back catalogue produced under the old assumption.

What this guide covers

QMSR internal audit explained
The three record types that lost their exemption from FDA review.

What QMSR internal audit protection used to exist

The old provision was narrow and specific. The records-availability requirements did not apply to three things: the management review reports required by 820.20(c), the quality audit reports required by 820.22, and supplier audit reports used to meet the supplier evaluation requirement in 820.50(a). It did apply to the procedures establishing those activities.

Instead of the reports, an investigator could require a written certification from an employee in management with executive responsibility that the reviews and audits had been performed and documented, giving the dates, and confirming that any required corrective action had been undertaken.

The logic was that candour inside an audit programme is worth protecting. Firms would find and fix more if the finding itself could not be used against them.

What the QMSR internal audit position is now

21 CFR Part 820 as amended contains no section 820.180. The exemption went with the section, and no equivalent was written into the new part.

At the same time, FDA Compliance Program 7382.850 — the inspection program that replaced the Quality System Inspection Technique on the same day — lists Internal Audits (ISO 13485 Clause 8.2.4) as an element within the Measurement, Analysis and Improvement area, and Management Review (Clauses 5.6.1 to 5.6.3) as an element within Management Oversight. Supplier evaluation sits inside Outsourcing and Purchasing.

Record Former exemption Now an inspection element
Management review reports old 820.20(c) Management Oversight — Clauses 5.6.1–5.6.3
Internal quality audit reports old 820.22 Measurement, Analysis and Improvement — Clause 8.2.4
Supplier audit reports old 820.50(a) Outsourcing and Purchasing — Clauses 7.4.1–7.4.3

There is no certification route any more. An investigator may ask to read the reports themselves.

The wrong QMSR internal audit response, and why it fails

The instinctive reaction is to make reports thinner — fewer findings, softer language, less detail. It is the wrong move for two reasons.

First, it is visible. An audit programme that produces no findings across a full cycle does not read as a healthy quality system; it reads as an audit programme that is not being performed effectively. That is itself a finding, and it invites more scrutiny rather than less.

Second, it removes the value. The reason to run internal audits is to find problems before somebody else does. A programme optimised for how it looks stops doing the job it exists for, and the problems it would have caught surface in complaints and Form 483 observations instead.

How to write a QMSR internal audit report that survives being read

The standard to write to is straightforward: write it the way you would want it read back to you in two years, by someone with no context and no goodwill.

  • State the finding plainly. A vague finding cannot be shown to be closed. “Complaint records incomplete” is unhelpful; “four of twelve complaint records sampled lacked the complainant telephone number required by 820.35(a)(4)” is a finding you can close and evidence.
  • Record the evidence examined, not just the conclusion. Which records, which dates, what sample size. An investigator assessing whether your audit was effective is reading for this.
  • Name the corrective action, the owner and the date, then record closure with evidence of effectiveness.
  • Do not speculate about regulatory consequence. Commentary about how a finding might look to FDA, or what it might expose the company to, is not a quality record. It adds nothing to the corrective action and reads badly in the one context where it will now be read.
  • Close what you open. An open finding with a target date eighteen months past is worse than a finding raised last week.

The QMSR internal audit distinction that matters

Plain, specific, evidenced findings are not the same as damaging findings. A QMSR internal audit that documents a real gap, an owner, a date and a closure with effectiveness evidence demonstrates a functioning quality system. What reads badly is an unclosed finding, a vague finding nobody could act on, or an aside about how bad this would look if anyone found out.

Dealing with the QMSR internal audit back catalogue

QMSR internal audit reports written before February 2026 were produced under the old assumption, and some will contain informal commentary.

Do not alter them. Editing a historical quality record is a far more serious problem than anything the record is likely to contain, and it is the kind of thing that turns an inspection into an investigation. Instead:

  1. Review the last few years of internal audit reports, supplier audit reports and management review minutes.
  2. Identify open findings and close them properly, with evidence.
  3. Where a record would benefit from context, add a dated addendum rather than changing the original.
  4. Record the review itself, so the exercise reads as diligence rather than being discovered as a gap.

Handling a QMSR internal audit request during an inspection

A request for these records is now legitimate, and the back room should not refuse one reflexively. Two controls prevent an avoidable problem.

Name the authority. One person, with a deputy, holds the authority to decline to produce a record on the basis it is out of scope. Whoever receives the request is not that person, and should route it rather than decide it.

Log everything. Every document produced goes in a request log with a retained copy of exactly what was handed over. Reconstructing later which version an investigator saw is not possible without it.

Extending QMSR internal audit to the FDA layer

One more consequence: your QMSR internal audit programme should now test the FDA supplements, not only the ISO clauses. Organise the cycle on the six QMS Areas so findings map to what an investigator examines, and specifically test:

  • Complaint records carrying all seven data elements of 820.35(a), and the justification record where an investigation was declined.
  • Servicing records carrying all six elements of 820.35(b).
  • UDI recorded against devices or batches under 820.35(c), not merely printed on labels.
  • Labeling accuracy examinations recording all five checks of 820.45(a), including the not-applicable determinations.
  • The four 820.10(b) bridges having live, owned procedures with evidence they operate.
  • Design-control applicability determinations existing for every device.

Building the QMSR internal audit programme cycle

Plan the QMSR internal audit cycle so all six QMS Areas and all four OAFRs are covered over its length, weighting frequency by risk rather than spreading effort evenly. Design and Development is annual where it applies; Production and Service Provision is usually per site; Management Oversight is annual and carries the most elements of any area.

Independence still applies. Auditors do not audit their own work, and where the organisation is too small for full independence, record how independence was achieved — a second site, a contracted auditor, a defined separation of duties — rather than leaving the question unaddressed.

Measure the programme itself, not only the individual audits: coverage against plan, findings by area, time to closure, and repeat findings. A programme producing no findings is not working, and one producing the same finding every cycle is not closing them. Both are now visible to anyone reading the file.

Frequently asked questions

Can FDA really demand QMSR internal audit reports now?

The exemption that prevented it was in section 820.180(c), and the QMSR contains no section 820.180. Compliance Program 7382.850 names Internal Audits as an inspection element. There is no longer a provision to point at when declining, and the written executive certification route went with the section.

Should we stop documenting minor findings?

No. Minor findings closed promptly are evidence that the system works. What creates exposure is the unclosed finding and the vague one — not the small one. A programme that records and closes minor issues consistently is exactly what an effective quality system looks like.

Does this affect supplier audits we commission?

Yes. Supplier audit reports used to meet the supplier evaluation requirement were covered by the same exemption and are now within the Outsourcing and Purchasing area. Where a supplier provides you with an audit report, treat it as a record you may have to produce.

What about management review minutes?

Same position. Record what was considered, what was decided, who owns each action and by when. Where a resource request was declined, record that too with the reasoning — a documented management decision is legitimate, whereas a request that silently vanishes from the minutes is not.

Where to go next on QMSR internal audit

For how the inspection itself now runs, see QMSR inspection under Compliance Program 7382.850. For the regulation behind it, 21 CFR Part 820 section by section, and for the change in context, the FDA QMSR guide.

The current regulation text — including the absence of any section 820.180 — is on eCFR at 21 CFR Part 820.

Our FDA QMSR Toolkit includes a disclosure readiness procedure written specifically for this change, a briefing that records for management that the certification route is gone, a QMSR internal audit procedure organised on the six QMS Areas, and an audit checklist covering all 54 elements. Two of those documents exist solely because 820.180(c) was withdrawn — it is the single most common blind spot in a quality system built under the old rule.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.