Skip to main content
v2026.11,610 entries · CC-BY 4.0

Complaint Handling for Medical Devices: Intake, Reportability, and the Complaint File

A walkthrough of medical device complaint handling: what counts as a complaint, controlled intake, the MDR/EU MDR vigilance reportability decision, 820.198/ISO 13485 8.2.2 investigation requirements, complaint file record content, and the link into CAPA and trending.

Ask about Complaint Handling for Medical Devices: Intake, Reportability, and the Complaint File

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

A medical device complaint is a specific, defined regulatory record — not just customer feedback. Under both the US Quality Management System Regulation (QMSR, 21 CFR Part 820) and ISO 13485:2016, a complaint handling process has to do four things reliably: intake every complaint through a controlled channel, decide whether it triggers regulatory reporting, investigate it to a documented standard, and roll the results into trending and CAPA. Getting any one of those four wrong is a recurring FDA inspection and notified-body audit finding. This guide walks through each stage and what a compliant complaint file actually has to contain.

What counts as a complaint

The legacy 21 CFR 820.3(b) definition — carried forward in substance under the QMSR — defines a complaint as any written, electronic, or oral communication that alleges deficiencies related to the identity, quality, durability, reliability, safety, effectiveness, or performance of a device after it has been released for distribution. That “after release for distribution” boundary matters: a defect caught internally before a device ships is a nonconformance under 21 CFR 820 §820.90, not a complaint. Once the device has left the manufacturer’s control, an allegation of a problem with it is a complaint, regardless of whether it arrived by phone, email, a field service report, a distributor, or social media.

ISO 13485:2016 Clause 8.2 groups this under “Feedback”: Clause 8.2.1 is the general feedback-gathering obligation (a broader input to the quality system, not automatically a complaint), and Clause 8.2.2 is the complaint-handling procedure specifically — timely handling per applicable regulatory requirements, and a documented determination of whether an event needs to be reported to a regulatory authority. Clause 8.2.3 covers reporting to regulatory authorities itself. Treat 8.2.1 and 8.2.2 as different obligations: not every piece of feedback is a complaint, but every complaint has to run through the 8.2.2 procedure, including a documented reportability decision, even if the eventual answer is no.

Complaint intake: what has to be captured at the door

The intake step is where most complaint-handling programs actually fail — not in the investigation, but in never logging the complaint as a complaint in the first place because it arrived through an unmonitored channel (a sales rep’s inbox, a support chat, a conference conversation). A controlled intake process needs to:

  • Route every possible complaint — regardless of source or channel — into a single logging system with a unique complaint number.
  • Capture the minimum record content 820.198(e) requires once a complaint is logged: the device name and control number(s) (lot, batch, serial), the complainant’s name/address/phone, the nature and details of the complaint, the dates and results of any investigation, corrective action taken, and any reply to the complainant.
  • Make an initial, documented triage decision on every complaint: does it require a formal investigation, and does it require a regulatory reportability assessment. Under 820.198(b)-(c), if an investigation is not conducted, the manufacturer must document the reason and the name of the person responsible for that decision — “we decided not to investigate” is only compliant if it’s written down and attributed.

A common design mistake: building the complaint form to just capture “what happened” as free text. Structured fields for device identification, event date, and initial MDR/vigilance screening question turn intake into usable trending data later — free text alone has to be manually re-coded before it’s analyzable, which is exactly the kind of gap an FDA 483 observation calls out.

The reportability decision: does this trigger MDR or EU vigilance reporting

Every complaint needs an explicit, documented reportability determination — not a default assumption either way. The US and EU frameworks ask a similar underlying question but run on different clocks and thresholds.

US: 21 CFR Part 803 Medical Device Reporting (MDR)

Under Part 803, a manufacturer must report to FDA if it becomes aware of information that reasonably suggests a device (1) may have caused or contributed to a death or serious injury, or (2) malfunctioned, and the device or a similar device the manufacturer markets would be likely to cause or contribute to a death or serious injury if the malfunction were to recur. Two timelines apply once that threshold is met:

  • 30-day report — the baseline: 30 calendar days from becoming aware of a reportable event, filed via MedWatch Form 3500A or its electronic eMDR equivalent (now mandatory for most manufacturers).
  • 5-day report — where remedial action is needed to prevent an unreasonable risk of substantial harm to public health, or FDA specifically requests it.

EU: MDR Article 87 vigilance reporting

Under Regulation (EU) 2017/745, a “serious incident” (Art. 2(65)) triggers a reporting duty under Article 87(1)(a), and the deadline is conditional on severity, not a flat number — each is an outer limit on an underlying “immediately” obligation:

  • Serious incident not involving death or an unanticipated serious deterioration in health — no later than 15 days from the awareness date (Art. 87(3)).
  • Death or unanticipated serious deterioration in a person’s state of health — no later than 10 days (Art. 87(5)).
  • Serious public health threat — no later than 2 days (Art. 87(4)).

The clock tightens as facts develop, and it does not restart: if an incident is first assessed on the 15-day track and the patient later dies, it becomes a 10-day case measured from the earliest date the manufacturer could have reported. Article 87(7) closes the obvious loophole: where it’s uncertain whether an event is reportable, the manufacturer must report anyway within the applicable timeframe rather than wait for certainty. A field safety corrective action (FSCA) arising from the same event is a separate reporting duty under Art. 87(1)(b) — see Field Safety Corrective Action (FSCA) for how FSCA, recall, and field safety notice relate to each other.

Both frameworks land on the same practical rule: reportability is assessed at first awareness, on the facts known at that moment, and the decision — including a “not reportable” conclusion — has to be documented in the complaint record, not just implied by the absence of a filed report.

Investigation: what 820.198 and Clause 8.2.2 actually require

Once a complaint is logged, 820.198(a)-(d) sets the investigation baseline: review and evaluate every complaint to determine whether it represents an event that must be reported under MDR requirements, and investigate unless the exact same complaint has already been investigated for a similar device and a new investigation isn’t needed. Where an investigation is conducted, it has to examine the device itself where practical (not just the complainant’s account) and establish its relationship, if any, to the reported event or nonconformance. Investigations spanning multiple sites — the manufacturing site and a separate complaint-receiving unit, for instance — must be accessible to both.

What belongs in the complaint file record

Complaint files sit alongside the device master record (DMR), device history record (DHR), and quality system record in the QMSR’s records subpart — see Design History File (DHF) for how complaint files differ from the DHF/DMR/DHR trio; a complaint file documents what happened to units already in the field, not how the device was designed or built. A defensible complaint file, per 820.198(e) and ISO 13485 8.2.2, should contain, at minimum:

  • Device name and control number(s) — lot, batch, or serial number of the specific unit(s) involved.
  • Complainant’s name, address, and phone number.
  • The nature and details of the complaint as reported, in the complainant’s own terms where possible.
  • Dates and results of the investigation, including whether the device was examined and what was found.
  • Any corrective action taken, including a CAPA reference if one was opened.
  • Any reply provided to the complainant.
  • The documented reportability determination (MDR and/or EU vigilance) and its rationale, even when the conclusion is “not reportable.”

Two carve-outs worth knowing: a device classification’s CGMP exemption (granted under 21 CFR 862-892) does not exempt a manufacturer from maintaining complaint files, and a device manufactured under an Investigational Device Exemption is not exempt either — both obligations run independently of premarket exemption status.

Linking complaints to trending and CAPA

A single complaint file is a record; a complaint-handling program is what turns a stream of individual records into a signal. Two mechanisms formalize that:

  • Trend reporting — under EU MDR Article 88, manufacturers must report to competent authorities any statistically significant increase in the frequency or severity of incidents that don’t individually meet the serious-incident threshold but, in aggregate, represent a change to the established benefit-risk profile. This is why a complaint intake system needs structured, codeable fields from day one — trend analysis on unstructured free text is unreliable at best.
  • CAPA — a complaint investigation that identifies a root cause feeds directly into the CAPA (Corrective and Preventive Action) system under ISO 13485 Clauses 8.5.2-8.5.3. The complaint record and the CAPA record should cross-reference each other by number; an auditor tracing a CAPA back to its trigger, or a complaint forward to its resolution, should be able to follow the paper trail in either direction without a gap.

Complaint trends showing up as a use-error pattern are also a signal to revisit the usability engineering file — see IEC 62366-1: The Usability Engineering Process — since a recurring “device is hard to use correctly” complaint theme often means the original use-related risk analysis under-scoped a real-world use scenario, not that the device itself is defective.

How this fits the QMSR / ISO 13485 transition

FDA’s Quality Management System Regulation, effective February 2, 2026, incorporates ISO 13485:2016 by reference and retired most of the standalone Part 820 text — but the Subpart M records structure, including §820.198 complaint files, was explicitly retained rather than folded entirely into the ISO clause structure. In practice, a US device manufacturer now runs its complaint-handling procedure to ISO 13485 Clause 8.2.2 (and 8.2.3 for regulatory reporting) as the operative process standard, while still maintaining a complaint file that satisfies the specific §820.198(e) record-content list FDA retained. See 21 CFR Part 820 after the QMSR transition and ISO 13485 for the full clause-by-clause detail of how the two frameworks now interlock.

Frequently asked questions

Is every complaint MDR-reportable?

No. Reportability under 21 CFR Part 803 depends on whether the complaint reasonably suggests the device may have caused or contributed to a death or serious injury, or malfunctioned in a way that would likely cause death or serious injury if it recurred. Many complaints — a labeling question, a cosmetic defect with no safety implication — are legitimately not reportable, but that conclusion still has to be documented in the complaint record, not simply assumed.

What’s the difference between “feedback” and a “complaint” under ISO 13485?

Clause 8.2.1 feedback is the broader obligation to actively gather information on device performance, including from sources like surveys or service reports. A complaint under Clause 8.2.2 is a specific allegation of deficiency in an already-distributed device. All complaints are feedback, but not all feedback rises to the level of a complaint requiring the 8.2.2 procedure, reportability determination, and complaint-file documentation.

How long does a manufacturer have to investigate a complaint?

Neither 820.198 nor ISO 13485 8.2.2 sets a fixed investigation deadline in days — the requirement is that review, evaluation, and (where warranted) investigation happen in a timely manner appropriate to the risk, and that the decision not to investigate is documented with a named responsible individual. In practice, the applicable MDR/vigilance reporting clock (5, 15, 10, or 2 days depending on severity) is what actually forces speed on any complaint where reportability is even plausible.

Does a distributor or importer have its own complaint-handling obligation?

Under the US framework, importers report deaths and serious injuries to both FDA and the manufacturer, and report malfunctions to the manufacturer only — they are mandatory MDR reporters in their own right, not just a pass-through. Manufacturers still need a contractual mechanism ensuring distributor-received complaints reach the manufacturer’s own complaint-handling system promptly, since the manufacturer’s regulatory reporting clock starts on awareness, which can run through a distributor first.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.