The 483 that doesn't look like the one you rehearsed for
A device manufacturer closes out its first inspection under the new rules. The investigator hands over a Form 483 — seven observations on the familiar form. But the top citation doesn't read the way the QA team's response template expects. It says "failure to establish and maintain procedures for corrective action per ISO 13485:2016 clause 8.5.2," not the §820.100 language every SOP on file is written against.
The 15-working-day clock starts on receipt, the same as it always has. What's different is nearly everything the response has to contain:
- the citation points at an ISO 13485 clause, so the response template's §820 header fields are already wrong;
- the investigator has asked to read the internal audit that surfaced the gap — a record FDA couldn't compel a year ago;
- a narrative letter promising to "implement corrective actions" won't clear the bar — the reviewer expects the CAPA record itself, attached.
That's the shift this post is about: not the deadline, but what a defensible 483 response now has to produce — and the CAPA workflow that has to produce it inside the window.
What changed on February 2, 2026
The QMSR Final Rule replaced the operational requirements of the 1996 21 CFR Part 820 with ISO 13485:2016, incorporated by reference, plus a thin layer of FDA-specific retained clauses. Effective date February 2, 2026. On the same day, FDA Compliance Program 7382.850 replaced the Quality System Inspection Technique (QSIT) as the inspection manual investigators work from.
QSIT had been the inspection framework for medical devices since 1999. It structured inspections around six subsystems (Management, Design Controls, CAPA, Production and Process Controls, Material Controls, Records/Documents/Change Controls) and gave investigators a known progression through a manufacturer's QMS. Sponsors prepared for QSIT inspections for two and a half decades.
CP 7382.850 keeps the subsystem framing but updates how investigators move through it: ISO 13485 vocabulary, the new Medical Device File construct, and access to records that the old §820.180(c) exemption used to shield. The first post-QMSR inspections began Feb 2; by mid-2026 the pattern in 483 citations had become clear enough for response procedures to need updating.
This article is about what's actually different in the 483 response process under CP 7382.850, where the response templates most companies have on file fall short, and what your CAPA workflow has to produce inside the 15-working-day window to make the response defensible. In one table:
| In your 483 response | Pre-QMSR (Part 820 / QSIT) | Post-QMSR (ISO 13485 / CP 7382.850) |
|---|---|---|
| Citation language | "…per 21 CFR §820.100(a)" | "…per ISO 13485:2016 clause 8.5.2, as incorporated by reference" |
| Records FDA can request | Management review, internal audit, supplier audit shielded by §820.180(c) | All three fully inspectable |
| Acceptable response | Narrative letter + commitments; evidence to follow | Structured, per-citation, with the CAPA records attached |
| Evidence expectation | Summary of intended actions | Root cause + CAPA + effectiveness plan as linked records |
| Response window | 15 working days | 15 working days (unchanged) |
The new citation language in 483s
Pre-QMSR 483 citations read in a familiar shape: "Failure to establish and maintain procedures for corrective and preventive action per 21 CFR §820.100(a)." The structure was a regulatory citation with a brief description of the observed gap, written against the Part 820 framework that had been the operational reference since 1996.
Post-QMSR 483 citations read differently: "Failure to establish and maintain procedures for corrective action per ISO 13485:2016 clause 8.5.2, as incorporated by reference under 21 CFR Part 820." The citation now names the ISO 13485 clause directly, references QMSR's incorporation by reference, and (where applicable) cites the FDA-retained §820 clauses alongside the ISO clause.
The shift sounds cosmetic. It isn't, for three operational reasons:
- Response procedures need updating. Any pre-2024 SOP that says "the response shall address each cited §820 clause" no longer describes the response your team has to produce. Update the language to "each cited ISO 13485:2016 clause and the corresponding retained §820 clauses where applicable."
- Response templates need updating. Form templates with §820.X header fields have to become ISO 13485 clause fields — same structure, different labels. A template still on §820 vocabulary reads to a CDER or CDRH reviewer as a sponsor who hasn't updated their post-QMSR practices.
- Cross-reference tables matter again. The §820-to-ISO-13485 mapping tables many QA teams built during 2024–2025 transition planning are now operational reference documents, not transition artefacts. Cite the cross-reference when you cite a legacy §820 clause — it proves the response is coherent across both citation systems.
Records FDA can now request during inspection
The §820.180(c) exemption under the old Part 820 protected three categories of records from FDA review: management review minutes, internal audit reports, and supplier audit records. The exemption was specific — the records had to exist (they were required by §820.20, §820.22, and §820.50) but FDA couldn't compel their production during an inspection.
QMSR removes the exemption. The three record types now sit in the same inspection-accessible category as every other QMS record, and CP 7382.850 tells investigators exactly when to ask for each:
- Management review records — requested during the Management subsystem portion of the inspection.
- Internal audit reports — requested during the Records subsystem portion.
- Supplier audit records — requested during the Material Controls subsystem portion.
The practical implication for your 483 response: if your response cites a management review where the issue was discussed, or an internal audit where the gap was identified, or a supplier audit where the deficiency was flagged, FDA can now request the underlying record. Citing the record means producing the record. The response procedure has to anticipate this.
It also changes how your CAPA workflow runs. Pre-QMSR, a finding from internal audit could be addressed through a focused CAPA without the internal audit report itself becoming part of the inspection record. Post-QMSR, the internal audit that found the gap, the CAPA that addressed it, and the management review that surfaced the trend are all linked records FDA can request together. The CAPA workflow has to keep those linkages clean.
The 15-working-day window hasn't moved
FDA's expectation that the response arrive within 15 working days of receipt of the 483 hasn't changed. What changed is what the response has to contain.
Pre-QMSR, a strong response sent to the FDA district office within 15 days could be a narrative letter committing to corrective actions, with implementation evidence to follow over the next 30-60 days. The narrative format was acceptable as long as the commitments were specific and the timeline was reasonable.
Post-QMSR, the strong response is more structured. Each citation needs a numbered response section containing: the root cause analysis with documented data behind it, the corrective action with implementation evidence (where the implementation has happened in the 15-day window), the preventive action with the risk-based justification, and the effectiveness verification plan with the monitoring metrics that will close the loop. Where implementation evidence isn't yet available, the response cites the implementation plan with named owners and dates.
The pattern is essentially what a strong response always was, expressed in CAPA-system terms. The difference is that CP 7382.850 investigators expect to see the CAPA records themselves attached to the response, not just summarised in narrative. A response that says "we have opened CAPA #198 to address this finding" without producing CAPA #198 reads as incomplete to the post-QMSR reviewer.
What an acceptable response looks like under CP 7382.850
The post-QMSR acceptable 483 response has a structural shape that pre-QMSR responses didn't always have. Each citation gets its own response section. Each response section contains:
Root cause analysis with documented data. Not "the team failed to follow the procedure." The specific failure mode, traced through process data, deviation history, and supporting investigation records. Where the root cause analysis used a structured methodology (5-Why, fishbone, fault tree), the methodology is named and the analysis attached.
Corrective action with implementation evidence. The action taken or planned to address the immediate failure. Where implementation has happened within the response window, the implementation evidence is attached (updated procedure version, training-completion records, equipment qualification record, etc.). Where implementation hasn't happened yet, the implementation plan is named with owners and dates.
Preventive action with risk basis. The systemic action to prevent recurrence, with the risk-based justification for why this action addresses the cause rather than the symptom. ICH Q9(R1) risk methodology is acceptable framing; ISO 14971 framing is acceptable for device-specific risk; the framework named doesn't matter as long as the justification is documented.
Effectiveness verification plan with monitoring metrics. The specific data the firm will collect to demonstrate the action worked. Frequency, owner, threshold for escalation if the data shows the action didn't close the gap. The effectiveness verification record gets linked to the CAPA so the closure of the verification feeds back to the CAPA closure.
Linked records. The CAPA record, the change-control record (where applicable), the training assignment record (where applicable), the procedure revision record. All attached or referenced with retrievable identifiers.
This is the format CP 7382.850 reviewers are looking for. It's also exactly what a working CAPA workflow produces as a matter of routine. The response is the CAPA record set, formatted for FDA submission.
The CAPA workflow your response depends on
The 15-working-day response window forces a particular operational discipline on the CAPA system. The CAPA has to be opened within 24 hours of the 483, the root cause analysis has to be substantive within 5-7 working days, the corrective and preventive actions have to be defined within 10 working days, and the response package has to be assembled and reviewed by 15. None of that scales without a CAPA workflow that runs as one connected record set rather than as separate documents.
The connected record set is:
- the originating 483 citation, and the CAPA opened against it;
- the root cause analysis with its linked investigation evidence;
- the action plan, with linked change-control records where the action is a procedure or process change;
- the linked training where the action is a competency change;
- the linked effectiveness verification plan with its monitoring schedule;
- and the response cover letter your QA team assembles from those records for submission.
The architectural discipline is the same one a strong CAPA workflow always needs: a workflow that owns the state of the CAPA end to end, clean links between the records an action touches — the change-control record a procedure fix drives, the training a competency action depends on, the effectiveness verification that has to close before the CAPA does — and an audit trail, kept separate for each customer, that captures every change with a timestamp and the sign-off recorded at each gate. See the slow-CAPA architecture post for why these primitives matter outside the 483 response context too.
The firms that handle 483 responses smoothly under CP 7382.850 aren't doing anything novel. They're running CAPA workflows that produce the structured records as a matter of routine, then assembling those records into the response inside the 15-day window. Firms still running on form-and-email CAPAs spend the 15 days reconstructing what a connected workflow would already have captured.
Common 483 response mistakes that surface as repeat findings
Post-QMSR inspection pattern is showing a small number of recurring response mistakes that produce repeat findings in the next inspection cycle.
Symptom-level corrective action without preventive action. The response addresses the immediate failure (retrain the operator, revise the procedure) without addressing why the gap existed in the first place (the SOP was outdated, the training programme didn't catch it, the management review didn't surface it). The next inspection finds the same gap because the cause wasn't addressed.
Effectiveness verification that's a date in the future without a metric. "Effectiveness will be verified at the next quarterly management review." A management review without a defined metric isn't effectiveness verification — it's a calendar reminder. The post-QMSR expectation is a named metric with a numeric threshold and a documented data source.
Response that doesn't address all citations on the form. A 483 with seven citations needs seven response sections. Responses that cluster citations under common themes ("citations 1-3 all relate to documentation gaps...") leave specific citations without explicit response and produce follow-up correspondence asking for the missing pieces.
Implementation evidence that doesn't actually demonstrate implementation. A response that says "the procedure has been revised" needs to attach the new revision with the approval signature timestamps, the training records for everyone trained on the new revision, and the date the old revision was retired. The narrative "we've updated the procedure" without the supporting evidence reads as a commitment, not a closure.
Cross-citation linkages missed. When multiple citations share a root cause (e.g., several findings tracing back to a single training-management gap), the response should explicitly note the linkage and address the shared root cause once with cross-references. Responses that address each citation separately as if it had a unique cause read as superficial and risk repeat findings on the linked items.
How Complere supports a defensible 483 response
A post-QMSR 483 response runs on the same corrective-action work your team does every day: the response is that record, put together by your QA team for submission. Complere keeps its pieces connected from the moment you open it.
- Each citation gets its own thread. You can open a separate corrective-action record for every item on the 483, and everything that item needs stays attached to it as it moves.
- It can't close before it's actually done. The record walks from root cause, through the corrective and preventive actions, to a check that the fix worked, and it isn't allowed to close until it gets there, so the analysis, the actions, and the proof sit in one place instead of scattered across documents.
- Actions stay tied to what they set in motion. When an action is a procedure change, it stays linked to that change; when it's a training need, the training is assigned and its completion tracked.
- Nothing changes without leaving a mark. Every step keeps its own history, who did what and when, so a change becomes part of the record. Your files sit in a space of your own, apart from every other customer's.
The quality judgement stays yours: the root cause analysis, the action plan, the effectiveness criteria, and the review of what you send. What Complere gives it is a connected place to live, so producing the response inside the 15-working-day window isn't a hunt for last quarter's template or last year's training records.



