top of page
Search

Would your QMS tell a coherent story if FDA analyzed the entire population of records instead of a small sample?

Aug 10
9 min read

The FDA investigator arrives at your facility and requests two years of complaint records.


Not merely a complaint log or summary spreadsheet. The investigator asks for the complete complaint records along with your CAPAs, nonconformances, supplier files, calibration records, audit reports, training records, and applicable risk-management documentation.


Then the investigator asks you to place everything on a thumb drive, takes it back to the office, and begins reviewing it with AI-assisted tools.


Within hours, you receive detailed questions:

  • Why were similar complaints classified differently for MDR reportability?

  • Why does the complaint investigation identify a hazardous situation that is not addressed in the product risk analysis?

  • Why did repeated nonconformances involving the same supplier and failure mode not trigger a CAPA or supplier corrective action?

  • Why do multiple CAPAs attribute the root cause to operator error without identifying a broader system failure?

  • Why was no product-impact assessment documented after this instrument failed calibration?

  • Why was the occurrence estimate in the risk file not updated after receiving 17 similar complaints?

  • Why was a CAPA closed without evaluating whether its findings affected the risk-management file?

  • Why is this supplier classified as low risk despite repeated nonconformances involving an essential component?

  • Why did the company conclude that no risk-control changes were necessary after identifying a new failure mode?

  • Where is the objective evidence supporting this CAPA effectiveness check?


There are already anecdotal reports within the medical-device industry of FDA investigators asking unusually detailed questions that appear to reflect analysis across large populations of records - questions that would be difficult to surface through human manual review alone.


Those reports are not proof that FDA routinely uploads complete quality system datasets into an AI platform. FDA has not publicly confirmed that practice.

However, FDA has confirmed enough about both its AI capabilities and its new risk-based inspection model to make this scenario credible, likely, and something that the industry needs to prepare for.


QMSR Changes the Inspection Focus

The Quality Management System Regulation, or QMSR, became effective on February 2, 2026. On that date, FDA discontinued the Quality System Inspection Technique and implemented the risk-based inspection process described in Compliance Program 7382.850.

FDA states that the goals of a medical-device inspection include evaluating whether:

  • The manufacturer’s QMS meets FDA requirements and provides reasonable assurance that its devices will be safe and effective.

  • Risk management and risk-based decision-making are effectively used throughout the QMS.


This is an important shift in inspection perspective.

Risk is not confined to the design risk-management file. FDA describes risk management as a framework that should identify, assess, control, communicate, and continually review device risks throughout the quality system and total product lifecycle. Postmarket information should continually feed back into that process.


An investigator may therefore follow a risk signal across multiple QMS processes:

Complaint → investigation → MDR decision → risk evaluation → CAPA → design change → supplier control → effectiveness monitoring


The individual records may each look acceptable when reviewed alone. The problem may emerge only when FDA examines whether they are connected.


For example, a company may document repeated complaints, close each investigation, and make defensible individual MDR decisions. But did it recognize the increasing occurrence rate? Did it reassess the hazardous situation? Did it update the risk analysis? Did it evaluate whether existing risk controls remained effective? Did it escalate the issue into CAPA or design change?


Under QMSR, those connections matter.  And AI is particularly well suited to finding where the connections are missing.


What Has Changed Since 2025?

In June 2025, FDA launched Elsa, its agency-wide generative-AI platform. FDA described Elsa as a secure, large-language-model-powered tool available to employees ranging from scientific reviewers to investigators. FDA also stated that Elsa was already being used to help identify high-priority inspection targets.


In December 2025, FDA announced agentic-AI capabilities across the agency and specifically identified inspections and compliance as intended use cases.

Agentic AI goes beyond answering individual questions. It can support multistep workflows such as searching information sources, comparing records, performing calculations, identifying anomalies, and refining an analysis under human oversight.


Then, in May 2026, FDA released Elsa 4.0 with capabilities that include:

  • Custom AI agents

  • Quantitative data analysis

  • Charts and data visualization

  • Optical character recognition for scanned records

  • Document generation

  • Optimized searching across large document repositories

  • Improved access to FDA data systems


FDA also introduced HALO (Harmonized AI & Lifecycle Operations for Data) which consolidates more than 40 agency data sources and systems. FDA has begun integrating HALO with Elsa so employees can query information and build workflows across a broader regulatory data environment.


Together, these systems give FDA the technical foundation to connect inspection history, adverse-event data, recalls, submissions, compliance records, and other agency-held information more efficiently than before.


FDA Has Already Piloted AI on Inspection Records

FDA’s Office of Regulatory Affairs has participated in a pilot involving an AI-assisted document-conformance tool for Establishment Inspection Reports, or EIRs. (https://www.fda.gov/media/182802/download)


The tool extracted information from EIRs and compared it against selected criteria in FDA’s Investigations Operations Manual. Its objective was to reduce repetitive manual review and allow FDA personnel to focus on higher-value analysis. The pilot was provided to FDA field-office reviewers for testing, and FDA reported positive feedback.


This was not an autonomous system making compliance decisions. Human reviewers remained responsible for the final conclusion. Nevertheless, it is concrete evidence that FDA has tested AI-assisted analysis within an inspection-related workflow.


What FDA Has (and Has Not) Confirmed

FDA has publicly confirmed that:

  • Elsa is available to FDA investigators.

  • AI is being used to identify high-priority inspection targets.

  • Agentic AI is intended to support inspections and compliance.

  • FDA has piloted AI-assisted analysis of Establishment Inspection Reports.

  • Elsa can process scanned documents, analyze data, and search large document repositories.

  • FDA is integrating AI with a consolidated environment covering dozens of agency systems.

  • QMSR inspections evaluate the effective use of risk management and risk-based decisions across the QMS.


FDA has not publicly stated that investigators routinely upload an establishment’s complete complaint, CAPA, nonconformance, calibration, supplier, and risk-management files into Elsa during an inspection.


It has also not published detailed procedures explaining what company records may be entered, what prompts are used, or how AI-generated findings must be verified.

The most supportable conclusion is not that fully AI-driven inspections have become standard practice.


It is that FDA now has, and is actively expanding, the capabilities needed to conduct more data-intensive, interconnected, risk-focused inspections.  It would be wise for the industry to take a conservative approach and assume that inspections will be AI-guided going forward.

 

How AI Could Change an Inspection


Before the Inspection

FDA could analyze information already in its possession, including:

  • Previous inspection findings

  • Establishment Inspection Reports

  • Form FDA 483 observations

  • Warning letters

  • Recalls and corrections

  • Medical Device Reports

  • Registration and listing data

  • Premarket submissions

  • Import and compliance information


The investigator could arrive with higher-risk products, processes, failure modes, and inconsistencies already identified.


During the Inspection

AI could help an investigator:

  • Summarize lengthy records.

  • Extract dates, products, failure modes, hazardous situations, harms, root causes, and dispositions.

  • Compare similar complaints and MDR decisions.

  • Identify recurring issues across complaints, service records, nonconformances, and CAPAs.

  • Compare actual field occurrence rates against estimates in the risk analysis.

  • Determine whether new hazards or failure modes were added to the risk file.

  • Identify CAPAs and design changes that did not trigger documented risk reviews.

  • Compare supplier classifications against the actual severity and frequency of supplier issues.

  • Identify risk controls that lack verification or effectiveness evidence.

  • Search scanned records using OCR.

  • Generate targeted follow-up questions.


After the Inspection

AI could assist with organizing evidence, comparing findings against inspection criteria, reviewing the EIR, connecting observations to prior compliance history, and prioritizing follow-up actions.

The investigator would still need to verify the evidence and exercise regulatory judgment. But AI could allow the investigator to examine far more information, and trace risk across more QMS processes, than was practical under a manual-review model.


Sampling Is Becoming a Dangerous Compliance Strategy

Many quality systems operate on an unstated assumption: an investigator will review only a small sample.


If five complaints, three CAPAs, and two supplier files look acceptable, the inspection may go well, even if the broader system contains serious inconsistencies.


AI blows up that assumption.


One complaint may not justify a change to the risk analysis. Twenty similar complaints may show that the estimated occurrence is no longer supportable.

One operator-error CAPA may appear reasonable. Twenty similar CAPAs may reveal a systemic failure in root-cause analysis and risk control.

One supplier deviation may appear isolated. When connected with complaints, incoming inspection failures, and production nonconformances, it may reveal that the supplier’s risk classification and controls are inadequate.

One design change may appear minor. When compared with the risk file, it may become clear that the change altered an existing risk control without appropriate verification.

One CAPA may be properly closed. A population-level review may reveal that CAPA conclusions are routinely not fed back into risk management.


AI does not need to independently prove a violation. It only needs to direct the investigator toward the records and disconnected decisions that deserve closer scrutiny.


Traditional Compliance Methods Cannot Keep Up

Manual audits, spreadsheet trackers, and small-sample reviews remain useful, but they cannot consistently evaluate thousands of interconnected records.


The same issue may be described differently across systems:

  • A complaint calls it a “failure to activate.”

  • A service record calls it “intermittent power.”

  • A nonconformance calls it a “connector-seating defect.”

  • A supplier record identifies “insufficient terminal retention.”

  • The risk file identifies “loss of therapy due to power interruption.”


A human reviewer may treat these as separate issues. AI may recognize them as the same risk signal.

Inspection readiness can no longer mean ensuring that a few individual records look acceptable.

The entire QMS must tell a coherent and defensible story about how risks are identified, evaluated, controlled, monitored, and updated.


How myQMS.ai Can Help You Prepare

The appropriate response is not to fear FDA’s use of AI. It is to use similar capabilities before the investigator arrives.


Automated Record Assessments

AI can assess complaints, CAPAs, nonconformances, audit reports, supplier records, calibration events, and risk documentation for completeness, compliance, and documentation quality.


Complaint, MDR, and Risk Consistency

myQMS.ai can compare similar complaints and flag inconsistent:

  • MDR decisions

  • Event codes

  • Failure descriptions

  • Investigation depth

  • Harm and hazardous-situation evaluations

  • Risk conclusions

  • Product-impact assessments

  • Regulatory rationales


It can also identify complaints involving failure modes or hazardous situations that do not appear to be adequately addressed in the risk-management file.


Risk-Management Feedback Checks

AI can evaluate whether quality data is properly feeding back into risk management, including whether:

  • New complaint trends triggered risk review.

  • Actual occurrence rates remain consistent with risk estimates.

  • New failure modes were added to the risk analysis.

  • CAPA investigations prompted appropriate risk-file updates.

  • Design or process changes were evaluated for risk impact.

  • New or modified risk controls were verified for effectiveness.

  • Postmarket data affected the overall residual-risk determination.

  • Risk-management conclusions are consistent across products and records.


CAPA Quality Review

myQMS.ai can identify:

  • Weak problem statements

  • Unsupported root causes

  • Overuse of operator error

  • Corrective actions that do not address the root cause

  • Missing implementation evidence

  • Weak effectiveness criteria

  • CAPAs that lack documented risk evaluation

  • CAPAs closed without updating affected risk documents

  • Effectiveness checks unsupported by objective evidence


Supplier Risk Analysis

AI can compare supplier classifications and controls against actual supplier performance, including:

  • Supplier nonconformances

  • Incoming inspection failures

  • Complaint involvement

  • Component criticality

  • SCAR history

  • Audit results

  • Delivery or quality trends

  • Effectiveness of supplier corrective actions


This can identify suppliers whose documented risk classification is inconsistent with their actual impact on device safety and performance.


Cross-System Risk Signal Detection

AI can identify relationships across:

  • Complaints

  • Service records

  • MDRs

  • Nonconformances

  • CAPAs

  • Supplier issues

  • Calibration failures

  • Audit findings

  • Design changes

  • Production controls

  • Risk-management files

  • Training records


This is precisely where siloed systems and traditional sampling are weakest.


Timeliness and Trend Monitoring

AI can identify overdue investigations, CAPAs, nonconformances, supplier actions, audit responses, calibration assessments, and recurring failure patterns.

It can also distinguish between a high volume of low-risk administrative issues and a smaller number of issues that could materially affect device safety or performance.


Risk-Based Inspection-Readiness Dashboards

Instead of scrambling after FDA arrives, manufacturers can maintain a current view of:

  • High-risk records

  • Emerging complaint signals

  • Recurring failure modes

  • Inconsistent MDR and risk decisions

  • Risk files that may not reflect current field data

  • CAPAs lacking risk-management linkage

  • Supplier risks unsupported by actual performance

  • Unverified or ineffective risk controls

  • Overdue investigations

  • Weak root causes

  • Documentation gaps


The Bottom Line

In 2025, an AI-assisted FDA inspection was a credible prediction. In 2026, FDA has confirmed that AI is available to investigators, is being used to prioritize inspection targets, is intended for inspections and compliance, and has already been piloted on Establishment Inspection Reports.


At the same time, FDA’s QMSR inspection model now expressly evaluates whether risk management and risk-based decision-making are effectively integrated throughout the QMS. FDA has emphasized that risk management should support decision-making throughout the device lifecycle and not remain isolated in a design-history or risk-management file.


That does not mean every inspection is currently an “AI inspection.”

It means the practical limitations that once restricted inspection depth are disappearing just as FDA is increasing its focus on connections across the quality system.

The investigator may not be limited to a handful of randomly selected records. The investigator may arrive with risks already identified and use AI to trace those risks through complaints, MDRs, nonconformances, CAPAs, suppliers, design changes, and the risk-management file.


Manufacturers should ask:

  • Does our risk file reflect what is actually occurring in the field?

  • Can we explain inconsistent risk and MDR decisions across similar events?

  • Do CAPA and nonconformance conclusions consistently feed back into risk management?

  • Are our supplier controls proportional to actual supplier and component risk?

  • Can we demonstrate that risk controls remain effective?

  • Would our risk conclusions withstand population-level analysis?

  • Do we know what an AI-assisted investigator would find before FDA does?


Inspection readiness should no longer mean preparing a polished sample.

It should mean continuously evaluating whether the entire QMS presents a coherent, current, and defensible picture of product risk.

 

Want to see how myQMS.ai can help you identify these risks before the FDA?  Schedule a demo today 

 

 

 
 
 

Recent Posts

See All

1 Comment

Rated 0 out of 5 stars.
No ratings yet

Add a rating
Dan Popovici
Aug 15
Rated 5 out of 5 stars.

Clever and timely insights with big, but preventable, impact to all FDA-inspectable QMS. I especially like the listed questions to ask ourselves and leverage to prioritize actions that will mitigate those inspections risks, and more importantly, the patient/customer outcomes these QMS elements are meant to protect. This is a way to accelerate change for the better...although we must remain aware of the potential misuse or inherent biases the AI "tools" can generate. Hopefully, it leads to less ambiguity in inspection findings, and findings mostly focused on high-impact nonconformities that generate higher value from associated corrective actions.

Edited
Like
bottom of page