Blog Article

QMSR Transition Gap Assessment: How to Run One

How a device site scopes, runs, records and signs a QMSR gap assessment against ISO 13485:2016 as incorporated, and how the gaps flow into change control.

A matrix grid of clause rows against three columns, documented, implemented and evidenced, with most cells ticked and a single amber cell in the evidenced column marking a requirement that was self-declared rather than sampled, under the line 'A verdict without a sampled record is an opinion.'

A gap assessment is a comparison, and both sides have to be written down

A gap assessment is a documented comparison between a set of requirements as currently written and a quality system as it currently operates, producing a list of the differences, each supported by evidence. Two conditions follow, and transition projects tend to skip both. The requirements side has to be the text in force, not a summary of it. The operations side has to be observed, not described by the people who run it.

Since 2 February 2026 the requirements side for a device manufacturer is 21 CFR Part 820 as amended by the Quality Management System Regulation: six short sections, §820.1 to §820.45, of which §820.7 incorporates ISO 13485:2016 by reference. Everything else is the standard's own clause text, which the eCFR does not reproduce. What FDA kept, added and removed is set out in QMSR vs ISO 13485; what each clause asks of the eQMS is in the 12-clause map. This post covers the assessment that sits between them.

A note on scope. The QMSR is a device regulation: §820.1 applies it to finished devices intended for human use, and a pharmaceutical site under Part 211 is not subject to it. The method transfers to any requirement set; the rule does not.

Assessment, internal audit, certification audit: three different readers

The word "assessment" is used loosely, and the loose use causes problems when a site presents its gap assessment as the year's internal audit, or a registrar's certificate as its assessment.

Gap assessment Internal audit (clause 8.2.4) Certification audit
Run by The site, often the process owners The site, by people independent of the process A registrar
Question Where does the system not yet meet the text? Is the system effectively implemented and maintained? Does the system conform, on this sample?
Standing with FDA A record under 4.2.5, inspectable Inspectable; the former §820.180(c) exception was not carried forward Per FDA's QMSR FAQ: not required, not issued, no exemption from inspection

The assessment may be run by non-independent people and may find the system wanting, because its purpose is to produce the list, not to certify. Its report is nonetheless a record: dated, attributed, retained, and readable by an investigator who may ask why a gap found in March was still open in September.

Scoping: which processes, which records, which systems

Scope is recorded before the first clause is opened, because a scope decided during the assessment shrinks toward what was easy to reach. Three lists are written down.

Processes. Every ISO 13485:2016 clause the site's operations engage, plus the FDA layer as its own rows. A site that does not service devices records clause 7.5.4 and §820.35(b) as not applicable, with the justification, rather than leaving the rows out.

Records. For each requirement, the record types that would demonstrate it and a named sample. Three need explicit inclusion because they were outside FDA's reach under the former §820.180(c) and are not now: management review records under clause 5.6, internal audit records under 8.2.4 and supplier evaluation records under 7.4. The assessment is the first time anyone reads them as an investigator would.

Systems. The eQMS and every other piece of software the quality system runs on, down to the spreadsheets that hold supplier scores. Clause 4.1.6 requires software used in the QMS to be validated for its intended use, so a system without a validation record is a gap before a clause is read.

Two inputs decide scope: a licensed copy of ISO 13485:2016, because a summary cannot be referenced in the requirement column, and the device classification of every product, because §820.10(c) applies clause 7.3 design controls to class II, class III and listed class I devices, including any class I device automated with computer software.

The method: one requirement, three questions, sampled evidence

The unit of assessment is the requirement, not the clause. A clause may contain several "shall" statements, and each one is a row. For every row the assessor answers three questions in order and records the basis for each answer.

Is it documented? Which procedure, which revision, which paragraph. An unapproved procedure does not count; one in QSR vocabulary counts, with a terminology note.

Is it implemented? Observed, not asserted. The assessor watches the process or interviews the operator against the procedure. A process owner's "we do that" is recorded as a statement, not as implementation.

Is it evidenced? The sampled records, by identifier: three complaint files, named; the last two management review minutes, dated. The row records what was sampled and what it showed.

The verdict vocabulary is fixed in advance: conforms, partial, gap, not applicable with justification. A row that reads "reviewed, conforms" with no record identifier behind it is a self-declaration, and a self-declaration is the finding an investigator will make on the site's behalf. Rows are worked in the standard's clause order, not in the four QSIT subsystems; the inspection that follows will not use QSIT either.

The FDA layer gets its own rows

The FDA sections are where a certified site is most likely to have thin evidence, because no registrar audit covers them.

  • §820.10(b): four cross-references. UDI under Part 830 against clause 7.5.8; traceability under Part 821 against 7.5.9.1; reporting under Part 803 against 8.2.3; advisory notices under Part 806 against 7.2.3, 8.2.3 and 8.3.3. Does the procedure cite the FDA part, and does a sampled record show it met?
  • §820.35: seven required items in complaint records, six in servicing records, the UDI recorded per device or batch. Sample field by field; a complaint form that dropped fields when the site "went ISO" surfaces here.
  • §820.45: labelling examined for accuracy before release, including UDI or UPC, expiration date and storage and handling instructions, with the results documented under clause 4.2.5. Sample lot records for the result, not the procedure for the promise.
  • §820.3: a terminology row. "Safety and performance" reads as safety and effectiveness, "organization" as manufacturer, and the FD&C Act definitions of device and labeling supersede the standard's.

The worksheet the assessment fills in

The list needs a home that outlives the assessor's notebook. The FDA QMSR transition checklist opens with the gap assessment as its first phase: four tasks, from mapping each legacy procedure to its ISO 13485:2016 clause and the FDA additions to recording the gap list as the transition backlog with priorities. Each task carries an owner, a status, an evidence reference and a notes column, and the same columns run through the document update, internal audit, training and readiness phases the gap list feeds.

What a gap looks like when it is written down properly

A gap that says "management review needs work" cannot be assigned, scheduled or closed. A gap record has fields, whether it lives in a workbook or in a quality system.

A gap record card with Gap, Clause and Owner filled, and an empty Evidence lineOne cream record card. Three fields end in a navy line. The Evidence field is an empty amber box.GapClauseOwnerEvidence
Field What it holds
Identifier, clause, requirement as written A stable reference the change record will cite; one clause or Part 820 section per row; the "shall" statement quoted or referenced
Observation and evidence sampled Where the documented, implemented or evidenced answer fell short, and the record identifiers behind that
Severity Graded by consequence for safety and effectiveness; under §820.10(e) any failure to comply renders the device adulterated
Owner, target date, remediation route A named person; a date set by severity; document change, process change, system configuration, training, or no action with justification
Closure evidence and verifier The approved change, the effective revision, the training record, the verification; who confirmed closure, and when

Severity is graded by consequence, not by effort. A risk file that never mentions effectiveness is quick to fix and still a partial against §820.3, possibly a gap against clause 7.1. Effort belongs in the target date.

Who reviews the assessment, and who signs it

The assessment is a record under clause 4.2.5, so it has an author, a reviewer and an approver, each named and dated.

Assessors should not assess their own process where the site can avoid it. Clause 8.2.4 attaches that independence expectation to internal audits; a gap assessment is not bound by it, but one in which every process owner graded their own process is the one an investigator discounts first. The quality function then reviews the list for consistency, because two assessors working the same clause will grade it differently unless someone reconciles them.

Top management receives the list. Clause 5.6.2 names applicable new or revised regulatory requirements among the inputs to management review, and the QMSR is exactly that; the minutes that record the decision are now a record FDA can read.

The signature closes the assessment as a snapshot with a date. It does not close the gaps.

From the gap list into change control and document control

A gap is closed by the quality system's own controls, not by the assessment that found it.

The gap becomes a change record under change control: an impact assessment covering the procedures, forms, training and validated systems it touches; an approval before implementation; a verification that the change had the intended effect. Citing the gap identifier on the change keeps the trail from finding to fix intact.

The document changes run under clause 4.2.4: the revised procedure is approved before issue, its revision status and changes are identified, it is available at the point of use, and the superseded revision is prevented from unintended use. Training on the revision is completed before the old revision retires, with the record tied to the revision, not the topic; where the change touches QMS software, the validation under clause 4.1.6 is reassessed.

Then the gap row is closed by reference: the change identifier, the effective revision, the training completion and the verification are written into the closure field, and a named person confirms closure against them. A re-pointed internal audit under 8.2.4 later confirms the closed gaps stayed closed; its report is the first independent reading of the transition, and it is inspectable.

What a gap assessment cannot substitute for

An assessment done well is still one activity. It is not an internal audit under clause 8.2.4 unless it was planned, staffed and recorded as one. It is not a management review; it is an input to one. It is not validation of QMS software under clause 4.1.6; finding the validation out of date is a gap, not a validation. It is not a certificate, and per FDA's QMSR FAQ a certificate is not compliance either. And it is not inspection readiness: every record can exist and the site can still be unable to produce a management review minute in the time an investigator is prepared to wait, which is why the transition checklist ends in a retrieval drill. It is also dated: a list signed in one quarter describes the system in that quarter, and the clause 8.2.4 programme, not a repeat assessment, keeps reading the system against the text.

The assessment sequence, as a protocol

  1. Record the scope: clause set, FDA sections, not-applicable rows with justification, record sample per requirement, software inventory.
  2. Confirm the standard's text and the dated eCFR text are in force; assign assessors, avoiding self-assessment where possible.
  3. Work each requirement in clause order, documented, implemented, evidenced, with identifiers; then the FDA layer as its own rows.
  4. Reconcile verdicts and severities across assessors; write each gap with its full field set.
  5. Present the summary to management review; sign the assessment as a dated record.
  6. Open the change records, close each gap by reference to evidence, and plan the internal audit that reads the closed gaps independently.

Where Complere closes the gaps the assessment finds

Every gap becomes a change with a history. The change that closes a gap carries its impact assessment, approval and verification, with the gap it answers cited on the record, so the trail from finding to fix runs in both directions.

The revised procedure is the only one in use. When the new revision takes effect the superseded one retires at the same moment, and the version in front of the operator is the one the approval was given for.

Training is tied to the revision. Completion is recorded against the specific revision of the procedure, which is the question an investigator asks after any documentation change.

The gap list and its closure evidence sit together. The change, the revision, the training record and the verification stay linked to the row they close, so "how was this closed, and who confirmed it" is answered by retrieval.

The verdict on each clause, the severity assigned and the decision that a gap is closed remain the site's determinations. The system's part is that each determination is recorded, dated and retrievable when someone who did not make it asks who did.

Frequently asked questions

Questions readers commonly ask about QMSR Transition Gap Assessment: How to Run One.

Is a QMSR gap assessment the same as an internal audit?

Not unless it is planned and recorded as one. ISO 13485:2016 clause 8.2.4 asks for internal audits at planned intervals, conducted by people who do not audit their own work, with records of the audit and its follow-up. A gap assessment is usually a one-off comparison run by the people who own the processes, often before the procedures have been revised, and it is allowed to be. It can be structured to satisfy clause 8.2.4 if the site plans it into the audit programme, assigns independent assessors and keeps the records the clause asks for, but the site has to decide that in advance and write it down. A gap assessment that is later relabelled as the year's internal audit will not read as one.

Do we need a copy of ISO 13485:2016 to run the assessment?

Yes. 21 CFR §820.7 incorporates ISO 13485:2016 by reference and names ISO as the source from which the text may be obtained; the eCFR reproduces the FDA sections but not the standard's clauses. A gap assessment compares operations against the requirement as written, so the assessor needs the clause text in front of them, not a summary of it. Secondary summaries, including the ones on this site, are for orientation. The requirement column of the assessment quotes or references the standard itself.

What happens to a gap once the assessment is signed?

It leaves the assessment and enters the quality system's own controls. A gap that needs a revised procedure becomes a change under change control, with an impact assessment, an approval, the document revision under clause 4.2.4, training on the revision and a verification that the change had the intended effect. A gap that needs a configuration change in software follows the same route and may also reopen part of the software validation under clause 4.1.6. The gap row is closed when it points at that evidence, not when the change is approved. The assessment report itself stays as it was signed; the closure is recorded against it, not by editing it.

Disclaimer: This article interprets 21 CFR Part 820 as amended by the Quality Management System Regulation final rule (89 FR 7496, effective 2 February 2026) and ISO 13485:2016 as incorporated by reference at §820.7. Clause numbers refer to ISO 13485:2016. The QMSR applies to manufacturers of finished medical devices; the method described transfers to other GxP settings but the rule does not. It is not legal advice. Confirm obligations against the regulation, your device classification and your own quality system.

About the author

Co-founder, Validation & Engineering, DevOps Lead

Compliance and quality-systems specialist writing for regulated SaaS buyers in pharma, medical device, biotech, and CDMO. All posts reviewed against current FDA, MHRA, EMA, ICH, and PIC/S guidance before publication.

Continue Exploring

Explore related topics, modules, and compliance resources for a deeper understanding of your quality system.

QMSR 12-clause map companion post
Related

QMSR Is Live — The 12-Clause Map to Your eQMS

Explore
QMSR versus ISO 13485 companion post
Related

QMSR vs ISO 13485: What Changes for Quality Systems

Explore
QMSR transition checklist workbook
Related

FDA QMSR transition checklist

Explore

Related from the blog

More from the Complere editorial team on quality, validation, and inspection readiness.

Regulatory & Inspection

QMSR vs ISO 13485: What Actually Changes for Quality Systems

QMSR incorporates ISO 13485:2016, but a certificate isn't compliance. What FDA kept, what it added in §820.3, §820.10, §820.35 and §820.45, what it removed.

Read the article
Regulatory & Inspection

What You Can and Cannot Automate in GxP Validation Evidence

FDA's CSA guidance widens how you may test. It does not endorse an unattended validation pipeline. Where the automation ceiling actually sits, and why.

Read the article
Regulatory & Inspection

CSV vs CSA in Pharma: What Software Assurance Actually Means Under Inspection

CSV and CSA pursue the same confidence by different routes. FDA's final guidance: the four CSA steps, process risk, and the record an inspection asks for.

Read the article

See the gap list close under change control

Walk through how a revised procedure, its approval, the training on it and the closure evidence stay attached to the gap that required them.