Medical Device QSR (21 CFR 820) Compliance: OEM Audit Checklist for Wearable Buyers






Medical Device QSR (21 CFR 820) Compliance: OEM Audit Checklist for Wearable Buyers

On February 2, 2026, the FDA’s Quality Management System Regulation (QMSR) took effect, officially replacing the old Quality System Regulation (21 CFR 820). This new QMSR aligns directly with ISO 13485:2016, marking the most significant structural change to medical device quality regulation in three decades. If your OEM manufacturer hasn’t fully updated their quality system to reflect this transition, you are actively buying into severe regulatory risk.

Why does this matter so much for wearable buyers? Medical wearables are no longer just fitness trackers. Devices measuring continuous glucose, blood pressure, and ECG are classified as Class II medical devices. They integrate complex software, wireless telemetry, and biometric sensors. A failure in the manufacturing quality system doesn’t just mean a defective gadget; it means inaccurate clinical data, potential patient harm, and a sudden FDA recall that could bankrupt your brand. Grand View Research projects the medical wearables market will surpass $60 billion by 2028. Capturing that market requires absolute confidence in your supply chain.

Having spent the last 15 years building Geyan Technology Innovation since 2011, I have sat on both sides of the audit table. I have watched buyers waste $15,000-$45,000 on FDA 510(k) submissions only to have them delayed because their OEM’s design history file was a mess. This guide breaks down the legacy 15 subparts of the QSR, how they map to the new QMSR, and provides a 50-item checklist to ensure your manufacturing partner is actually compliant, not just claiming to be.

Understanding the QSR → QMSR Transition: What Changed

To audit a factory effectively, you must understand the rules they are playing by. The old QSR was highly prescriptive. It told manufacturers exactly “how” to do things across 15 distinct subparts. The new QMSR takes a different approach. By incorporating ISO 13485:2016 by reference, it focuses on “what” outcomes the quality system must achieve. This shift offers more flexibility and aligns US requirements with international standards, simplifying life for manufacturers using the Medical Device Single Audit Program (MDSAP).

However, do not mistake flexibility for leniency. The FDA still expects rigorous adherence to specific US-only regulations that ISO 13485 does not cover. Design controls now explicitly reference ISO 13485:2016 Section 7.3, but risk management must strictly follow ISO 14971. Purchasing controls require supplier evaluation per ISO 13485, yet new requirements for software validation under IEC 62304 remain heavily scrutinized. Management responsibility has also expanded, requiring top leadership to demonstrate direct involvement in quality outcomes.

What stayed the same? The FDA did not abandon its core safety nets. Complaint handling under 21 CFR 820.198, Medical Device Reporting (MDR) under 21 CFR 803, Unique Device Identification (UDI) under 21 CFR 830, and specific labeling requirements remain fully intact. The transition timeline was strict: compliance was required by February 2, 2026, with no grace period.

Old QSR Subpart New QMSR Reference Key Changes Impact on Wearable OEMs
Subpart C: Design Controls (820.30) ISO 13485:2016 Sec 7.3 Shifts from prescriptive steps to outcome-based design validation. DHF must still be robust, but OEMs can use risk-based approaches for design changes in software (IEC 62304).
Subpart B: Quality System (820.20) ISO 13485:2016 Sec 5 Management responsibility expanded; requires management review inputs/outputs. Factory leadership must actively review quality metrics, not just delegate to a QA manager.
Subpart E: Purchasing Controls (820.50) ISO 13485:2016 Sec 7.4 Supplier evaluation based on risk and ability to meet requirements. OEMs must rigorously audit suppliers of critical components like PPG sensors and BLE modules.
Subpart G: Production Controls (820.70) ISO 13485:2016 Sec 7.5 Focus on production environment and process validation outcomes. ESD and cleanroom controls must be validated and continuously monitored.
Subpart J: CAPA (820.90) ISO 13485:2016 Sec 8.5.2 Integrates CAPA with broader risk management and post-market surveillance. CAPAs must link back to ISO 14971 risk files; “retrain operator” is no longer an acceptable root cause.

The 15 Subparts Legacy Checklist — What Buyers Should Audit

Even though the QMSR references ISO 13485, the FDA’s inspection model still heavily relies on the structural logic of the original 15 subparts. When I walk through a facility, I use these subparts to structure my audit. Here is how you should evaluate your OEM.

Subpart A: General Provisions

Start at the foundation. Ask to see their quality policy and quality manual. Specifically, ask when it was last updated to reflect the QMSR transition. A passing answer involves showing a manual updated in late 2025 or early 2026 that explicitly maps ISO 13485 clauses to US-specific CFR requirements. A major red flag is a quality manual that hasn’t been touched since 2023. If they haven’t updated their core document, their entire system is likely outdated.

Subpart B: Quality System

Request the organizational chart highlighting quality responsibilities. Identify the Management Representative. What is their direct reporting line? In a compliant facility, the quality manager reports directly to the CEO or Plant Manager. If the quality manager reports to the production manager, you have a fundamental conflict of interest. Production will always prioritize speed over quality when push comes to shove. I once audited a factory where the QA lead reported to the assembly supervisor; their CAPA log was completely empty.

Subpart C: Design Controls

This is where most wearable OEMs fail. Ask for their design control procedure and walk through a recent Design History File (DHF) for a device like a continuous glucose monitor or a smart ring. You need to see design inputs, outputs, review records, verification, and validation. Traceability is key. If the DHF is incomplete or fails to show clear traceability from clinical inputs to software verification, reject the facility. For devices with software, ensure their processes support IEC 62304 compliance.

Subpart D: Document Controls

How do they ensure only the latest revision of a work instruction is used on the production floor? Ask to see their document control procedure and how obsolete documents are destroyed. A massive red flag is a purely paper-based document control system. In modern medical manufacturing, an electronic Quality Management System (eQMS) is practically mandatory to prevent version-control errors on the floor.

Subpart E: Purchasing Controls

Show me the Approved Vendor List (AVL). How do they evaluate and re-evaluate suppliers? More importantly, ask for incoming inspection records for critical components like optical sensors, batteries, and integrated circuits. If they have no formal supplier audit program or lack incoming inspection records for critical electronic components, your device’s reliability is a gamble. AAMI TIR57 and NIST SP 800-53 guidelines should also influence how they evaluate software component suppliers.

Subpart F: Identification and Traceability

Pick a finished device serial number from the floor. Ask them to trace it back to its specific component batches. For wearables, this includes the specific lot of the ECG electrodes or the BLE chip. If they cannot trace a single device to its component batch within 10 minutes, their recall strategy is broken. UDI requirements under 21 CFR 830 must be seamlessly integrated into this traceability matrix.

Subpart G: Production and Process Controls

Review the production work instructions. Ask for process validation records (IQ/OQ/PQ) for critical processes like ultrasonic welding or potting. Check environmental monitoring records for Electrostatic Discharge (ESD), temperature, and humidity. A critical red flag is the absence of process validation for automated optical inspection (AOI) or no environmental controls for electronics assembly. Micro-components in devices like the TK67 Smartwatch require strict ESD flooring and wristband protocols.

Subpart H: Acceptance Activities

Examine receiving, in-process, and final acceptance procedures. Ask for acceptance records from the last three production batches. What is their defined Acceptable Quality Level (AQL) for cosmetic versus functional defects? If the AQL is not defined, or if acceptance records show inconsistent pass/fail criteria between shifts, their quality output is entirely dependent on the mood of the inspector.

Subpart I: Nonconforming Product

Ask for the nonconforming product procedure and the Nonconformance Report (NCR) log for the last six months. How do they disposition nonconforming products? A major red flag is an empty NCR log, or a log where every single nonconformance is dispositioned as “use as is” without a formal engineering investigation. Every factory has defects; a factory that claims it doesn’t is hiding them.

Subpart J: Corrective and Preventive Action (CAPA)

Review the CAPA procedure and the last three closed CAPAs. What was the root cause? What was the corrective action? How was effectiveness verified? If all the CAPAs simply state “retrain operator” as the corrective action without a deep root cause analysis (like 5 Whys or Fishbone), the system is ineffective. True prevention requires engineering or process changes, not just blaming the worker.

Subpart K: Labeling and Packaging Control

How do they ensure the correct label is applied to the correct device? Ask for label verification records and how they handle label storage. A red flag is finding mixed label reels at a packing station or no environmental controls for label adhesives. For wearables, incorrect labeling regarding software versions or UDI can trigger an FDA enforcement action.

Subpart L: Handling, Storage, Distribution, and Installation

Check the warehouse storage conditions. What is the temperature and humidity range for finished devices and sensitive components like lithium batteries? Ask for distribution records with traceability. If there are no environmental controls in the warehouse or no digital distribution records, your products are degrading before they reach the customer.

Subpart M: Records

Review the record retention procedure. How long are records kept? How are electronic records backed up? Are records legible, identifiable, and retrievable? Under 21 CFR 11, electronic records must be secure. A red flag is having no backup procedure for the eQMS, or storing physical batch records in a standard filing cabinet without fire protection or climate control.

Subpart N: Servicing

Do they provide servicing or repair for the devices? If yes, show me the servicing procedure and records. For most wearable OEMs, this is Not Applicable (N/A) because devices are replaced, not repaired. However, if the OEM provides refurbishment or repair services, this subpart becomes critical to ensure repaired devices meet original specifications.

Subpart O: Statistical Techniques

Ask for their statistical techniques procedure. What statistical methods do they use for process control, acceptance sampling, and data analysis? If they have no Statistical Process Control (SPC) charts for critical dimensions, or if acceptance sampling is done by “gut feel” rather than ANSI/ASQ Z1.4 standards, their quality data is meaningless.

50-Item Audit Checklist (Summary Table)

To make this actionable, I have compiled the core audit questions into a 50-item checklist. You can print this table and take it directly onto the factory floor. Score each item as Pass, Minor Observation, or Major Observation. Any Major Observation in Subparts C, G, or J should halt production until resolved.

# Subpart Audit Question Passing Criteria Red Flag
1 A Is the Quality Manual updated for QMSR? Updated post-2024, maps ISO 13485 to CFR. Last updated before 2024.
2 A Is the quality policy displayed and understood? Posted on floor, workers can explain it. Workers unaware of the policy.
3 B Does QA report to top management? QA reports to CEO/Plant Manager. QA reports to Production.
4 B Are management reviews documented? Minutes show resource allocation & metrics. No meetings in the last 12 months.
5 C Is the DHF complete for a recent device? Contains all inputs, outputs, and validations. Missing validation reports.
6 C Is there design traceability? Matrix links inputs to verification tests. No traceability matrix exists.
7 C Are design changes controlled? Change requests show impact analysis. Changes made without documentation.
8 D How are documents controlled? eQMS used, obsolete docs removed. Paper system, old docs on floor.
9 D Are foreign documents translated? Work instructions in local language. Instructions only in English/Chinese.
10 E Is there an Approved Vendor List (AVL)? AVL exists, updated annually. No formal AVL.
11 E Are suppliers audited? Audit reports on file for critical suppliers. No supplier audits conducted.
12 E Is incoming inspection performed? Records show inspection of sensors/ICs. No incoming inspection records.
13 F Can you trace a device to components? Traceability shown in < 10 mins. Cannot trace to component batch.
14 F Is UDI applied correctly? UDI matches database, scannable. Missing or incorrect UDI.
15 G Are work instructions available? Current rev available at every station. Missing or obsolete instructions.
16 G Are critical processes validated? IQ/OQ/PQ records exist for welding/potting. No validation for critical processes.
17 G Are environmental controls monitored? ESD, temp, humidity logged daily. No ESD or climate controls.
18 G Is equipment maintained? Preventative maintenance logs up to date. Equipment broken, no PM schedule.
19 H Are acceptance procedures defined? Procedures specify AQL and test methods. No defined AQL.
20 H Are acceptance records kept? Records match production batches. Missing acceptance records.
21 I Is nonconforming product segregated? Red bins used, physically locked. Bad parts mixed with good parts.
22 I Is there an NCR log? Log exists, shows disposition and approval. No NCR log, or all “use as is”.
23 J Is there a CAPA procedure? Procedure defines triggers and timelines. No formal CAPA procedure.
24 J Are CAPAs effective? Effectiveness verified after 3 months. No effectiveness verification.
25 J Is root cause analysis used? 5 Whys or Fishbone diagrams on file. Root cause is always “operator error”.
26 K Are labels verified? First article inspection for labels. No label verification process.
27 K Is label storage controlled? Labels stored in secure, climate-controlled area. Labels left on open shelves.
28 L Are storage conditions monitored? Warehouse temp/humidity logged. No environmental monitoring.
29 L Is FIFO used? First-In-First-Out clearly marked and used. Old stock buried in back.
30 L Are distribution records kept? Records link ship date to device serials. No distribution traceability.
31 M Are records legible and retrievable? Records can be pulled in < 5 mins. Records disorganized, hard to read.
32 M Are electronic records backed up? Daily automated backups, tested quarterly. No backup procedure for eQMS.
33 M Is record retention defined? Procedure matches device lifetime + 2 years. No retention policy.
34 N Are servicing procedures defined? N/A or procedures exist for repairs. Repairs done without documentation.
35 O Are statistical techniques used? SPC charts used for critical dimensions. No statistical process control.
36 O Is acceptance sampling statistical? Uses ANSI/ASQ Z1.4 or ISO 2859-1. Sampling done by “gut feel”.
37 A Is the facility registered with FDA? FDA registration certificate current. Registration expired or missing.
B B Are quality objectives set? Measurable goals set annually. No quality objectives defined.
39 C Are clinical evaluations done? CER or 510(k) equivalence documented. No clinical data review.
40 D Are records of document changes kept? Revision history shows who changed what. No revision history.
41 E Are purchasing documents clear? POs specify exact part numbers and revs. POs lack revision levels.
42 F Is software version traceable? Device serial links to specific SW build. Cannot trace SW version to device.
43 G Are calibration records kept? All gauges calibrated, stickers current. Expired calibration stickers.
44 H Are inspection statuses identified? Pass/Fail/Hold tags used on bins. No status identification.
45 I Is rework controlled? Rework instructions exist and are validated. Rework done ad-hoc.
46 J Are complaints fed into CAPA? Trend analysis triggers CAPAs. Complaints handled in isolation.
47 K Are labeling machines validated? Label applicators have IQ/OQ. Manual labeling without poka-yoke.
48 L Are hazardous materials stored safely? Batteries/chemicals in fire cabinets. Lithium batteries stored improperly.
49 M Are training records maintained? Matrix shows who is trained on what. Training records signed same day.
50 O Is data analyzed for trends? Monthly quality review analyzes defect trends. Data collected but never analyzed.

How to Conduct a Remote Factory Audit

Travel budgets are tight, and global supply chains are complex. Remote audits are highly effective if structured correctly. I recommend a hybrid approach. Use the pre-audit phase to send this 50-item checklist and request all core documents (Quality Manual, DHF, CAPA log, AVL) via a secure shared folder. Review these documents thoroughly before the live session.

During the audit, use Zoom or Teams for live video. Request a screen-sharing session to see their eQMS in action. Have the quality manager navigate to a specific CAPA and show you the audit trail to verify 21 CFR 11 compliance. Then, put on a hard hat and do a live video walkthrough of the production floor. Ask them to pan the camera to specific workstations, check ESD wristband straps, and read calibration stickers on the spot. For data privacy, ensure any live demonstrations involving patient data or proprietary HL7 FHIR R4 integrations are masked or simulated.

Post-audit, issue a formal report within 48 hours. Categorize findings as Major, Minor, or Observation. Require a corrective action plan for all Major findings within 14 days. A remote audit saves money, but it requires the OEM to be highly organized and transparent. If they resist screen sharing or camera walkthroughs, treat it as a major red flag.

Red Flags Checklist: 10 Signs Your OEM Isn’t QSR-Compliant

After 15 years in this industry, you learn to spot the signs of a failing quality system before you even open a document. Here are 10 red flags that should make you walk out of the factory immediately.

  1. The quality manual is more than 3 years old. If it hasn’t been updated for the QMSR transition, they are operating on expired regulatory assumptions.
  2. No management review meetings in the last 12 months. This proves top management views quality as solely the QA department’s problem, not a business imperative.
  3. The CAPA system has fewer than 5 entries in the last year. Every manufacturing floor has issues. An empty or sparse CAPA log means they are hiding defects or lack the maturity to identify systemic problems.
  4. The Design History File is “in the engineer’s head.” If they cannot produce a physical or digital DHF with clear traceability, they do not have design controls; they have a hobby.
  5. No incoming inspection for critical components. If they just plug optical sensors and BLE modules straight onto the line without checking them, your yield will be a disaster.
  6. Calibration stickers on equipment are expired. This shows a breakdown in basic preventative maintenance and document control.
  7. Training records are all signed on the same day. I have seen factories pre-fill training logs the night before an audit. It is fraudulent and invalidates their competency claims.
  8. No environmental monitoring in the production area. Electronics assembly for medical wearables requires strict ESD and humidity controls. Ignoring this guarantees latent failures in the field.
  9. The complaint handling procedure doesn’t exist or is never used. If they don’t have a system to capture and investigate field complaints, they are flying blind regarding post-market surveillance.
  10. “We’ve never had an FDA inspection.” For US-bound Class II devices, this is not a badge of honor. It usually means they are not properly registered, or their facility is so small they’ve flown under the radar. Either way, it’s a risk you don’t want to inherit.

How Geyan Technology Innovation Maintains QSR/QMSR Compliance

At Geyan Technology Innovation, we understand that our quality system is the foundation of your regulatory success. Since 2011, we have built our manufacturing processes to support strict compliance with ISO 13485:2016 and the new FDA QMSR. We utilize a fully validated electronic QMS (eQMS) that manages document control, CAPA, training matrices, and Nonconformance Reports (NCR) with full 21 CFR 11 audit trails.

Our commitment goes beyond paperwork. We conduct monthly management review meetings where top leadership analyzes quality metrics, customer complaints, and supplier performance. We maintain an active supplier qualification program with over 50 approved suppliers for critical components like the sensors used in our TK67 Smartwatch and the TK30 Smart Ring. We undergo annual surveillance audits to ensure our systems remain robust and aligned with international standards. For buyers navigating the complex medical device certification roadmap, our engineering team ensures that our TK35Pro and GE54 platforms are designed with IEC 62304 software lifecycle and ISO 14971 risk management baked into the DHF from day one.

We welcome customer audits, both on-site and remote. Transparency is how we build trust. Last year, a US client’s quality team spent three days auditing our facility. They found two minor observations regarding warehouse labeling formats. Both were closed within 30 days with updated visual management boards. They have been ordering from us for four years now because they know our quality system is real, not just a binder on a shelf.

If you are looking for a manufacturing partner to build your next remote patient monitoring device or clinical wearable, you need a team that speaks the language of regulatory compliance fluently. Check out our RPM wearables guide to see how our hardware integrates with clinical workflows, and review our FDA 510(k) guide to understand how our documentation supports your submission.

Want to audit our quality system? We welcome on-site and remote audits. Request our QMS overview and audit schedule.

→ Request Factory Audit: jine@xdunmedical.com

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top