Device Compliance Official Flags Quality Gaps, Rising Enforcement
A senior CDRH device compliance official is warning industry that persistent shortcomings in complaint handling, corrective actions, and medical device reporting continue to dominate the Center’s enforcement findings, signaling deeper weaknesses in manufacturers’ risk-management systems as the FDA prepares to implement a sweeping update to device quality regulations next year. Speaking at the 12/4 Food and Drug Law Institute’s annual enforcement conference in Washington, DC, CDRH associate director for compliance and quality Keisha Thomas, outlined fiscal year 2025 compliance trends and previewed enforcement priorities for 2026.
Thomas told attendees that CDRH conducted roughly 2,300 device inspections in FY 2025, resulting in 97 Official Action Indicated (OAI) classifications and 45 Warning Letters. Nearly half of all firms inspected were cited for deficiencies in complaint handling, CAPA processes, or medical device reporting (MDR) — a longstanding pattern she said reflects underlying failures in manufacturers’ post-market surveillance and continuous-improvement systems.
“These are systemic signals,” Thomas said. “The information we get post-market is crucial because devices are in the hands of patients. When complaint handling and MDR systems aren’t operating optimally, that is a risk-management issue.”
Although overall device recalls have trended slightly downward, Thomas said device design problems continue to rank as the most common cause — a pattern she noted has been consistent across her two decades at the agency. Increasing device complexity and frequent product modifications, she added, amplify the importance of robust post-market systems and risk-based assessments.
Thomas also highlighted continued citations related to the Unique Device Identifier (UDI) system. Because UDI underpins traceability across the total product life cycle, deficiencies in labeling, data entry or tracking “are equally as problematic” as other violations, she said.
Looking ahead to 2026, Thomas said CDRH will continue to expand its risk-based enforcement approach, using analytics and signal trending across both product categories and corporate structures. CDRH will also intensify scrutiny of unapproved or unlawfully marketed devices, an area she said now accounts for the majority of Warning Letters. In FY 2025, about 61% of device Warning Letters cited unapproved or improperly marketed products, down from about 70% in FY 2024.
CDRH will further focus enforcement on data integrity and data quality in clinical trials and submissions, which Thomas described as a “significant safety issue” when compromised.
Thomas closed by underscoring the approaching implementation of the FDA’s long-anticipated Quality Management System Regulation (QMSR), which goes into effect 2/2/2026. QMSR harmonizes U.S. medical device GMPs with ISO 13485, adding explicit requirements for risk-management activities. While the agency does not plan new compliance programs or inspection protocols solely because of QMSR, Thomas stressed that FDA will place far greater emphasis on how firms make risk-based decisions across the total product life cycle.
“When you look at complaint handling, CAPA, and MDR issues — the underlying thread is a risk-management system that isn’t optimal,” she said. “That is going to be the focus under QMSR.”
Thomas encouraged firms to ensure they are prepared for risk-management expectations embedded in ISO 13485:2016, now incorporated directly into FDA’s quality-system requirements.