> ## Content Index
> Fetch the complete content index at: https://www.fdaweb.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Attorneys Review FDA’s New Inspection Approach for Devices
- URL: https://www.fdaweb.com/attorneys-review-fdas-new-inspection-approach-for-devices/
- Published: 2026-03-05T12:00:00.000Z
- Updated: 2026-09-14T13:34:58.000Z
- Author: David McFarland
- Tags: Devices, #legacy-id-D5160766

Ropes & Gray attorneys **Joshua Oyster** and **Austin Laroche** review in a *WestLaw Today* [article](https://today.westlaw.com/Document/Ia3d2958517e611f1986ef39f1b68dca5/View/FullText.html?transitionType=Default&contextData=%28sc.Default%29&VR=3.0&RS=cblt1.0&firstPage=true&ref=fdaweb.com) FDA’s new inspection approach for medical device manufacturers under the Quality Management System Regulation and discuss key changes from prior inspection methods. The attorneys note that the updated regulatory framework signals a shift toward risk-based oversight and broader scrutiny of quality management practices across a product’s lifecycle.

Under the prior system, inspections were structured around four “subsystems” within the quality regulation, including management controls and production processes. The new compliance program replaces that structure with a risk-based inspection strategy that organizes requirements into six quality management system areas and four additional regulatory requirements. Investigators are instructed to focus on elements posing the greatest risk to patients or device users, according to the attorneys.

The six quality areas include change control, design and development, management oversight, measurement and improvement, outsourcing and purchasing, and production and service provision. Additional areas reviewed during inspections include medical device reporting, corrections and removals reporting, device tracking and unique device identification.

Oyster and Laroche point out thay FDA has replaced the previous tiered inspection levels with two inspection models. Most routine inspections will follow a flexible model in which investigators review at least one element in each quality system area but can select specific elements based on potential patient risk. A second model applies to baseline inspections of facilities with no prior FDA inspection or participation in the Medical Device Single Audit Program, as well as preapproval inspections for products seeking marketing authorization. Those inspections require review of specific elements in each regulatory area. Investigators will also examine standard compliance information, including facility registration, device listings, prior enforcement observations and relevant marketing authorizations.

A central feature of the new approach is a stronger emphasis on risk management across the entire product lifecycle, they note. Investigators are instructed to review documentation such as adverse event reports, product corrections and removals, complaints, postmarket surveillance data and servicing records to evaluate whether manufacturers are effectively identifying and mitigating risks. The compliance program also highlights several risk-management failures that could trigger an “official action indicated” classification, potentially leading to regulatory enforcement.

The new framework also expands the types of quality system records FDA may review during inspections, according to Oyster and Laroche. Under the previous regulation, management reviews, internal quality audit reports and supplier audit reports were generally excluded from routine inspection review. Under the new system, those records may now be examined by investigators because they are elements of the quality management system under ISO 13485.

Additionally, the new inspection framework calls for greater scrutiny of software-enabled and connected medical devices to ensure compliance with cybersecurity requirements enacted through the Food and Drug Omnibus Reform Act of 2022.

The attorneys say the new framework represents a significant shift in how the FDA evaluates device manufacturers and will require companies to adjust their compliance programs. Manufacturers may need to update internal procedures, strengthen risk management processes and ensure employees are trained on the expanded scope of FDA inspections, including the potential review of additional quality records.