FDA / QMSR / 21 CFR 820
On 2 February 2026 the FDA formally withdrew the 1998 QSIT inspection manual and replaced it with Compliance Program 7382.850, built around the Quality Management System Regulation (QMSR) — the revised 21 CFR 820, now harmonized with ISO 13485:2016. The inspection is no longer a fixed subsystem checklist, and internal audit and management review records that were off-limits before are now fair game.
Last updated 16 August 2026
The revised 21 CFR 820 — now called the Quality Management System Regulation — took effect, and with it the FDA retired the QSIT manual that had governed device inspections since 1998. There's no "QSIT 2." Investigators now work from Compliance Program 7382.850, which replaces both QSIT and the older CP 7382.845, alongside CP 7383.001 for PMA inspections.
Source: The FDA Group, "QMSR Is Live, QSIT Is Gone"; FDA.gov QMSR page.
QSIT worked through a set list of subsystems — management controls, design controls, CAPA, production and process controls — in a predictable pattern manufacturers could prepare for directly. CP 7382.850 drops that structure: investigators select which parts of the quality management system to examine based on product-specific risk, complaint history, and a firm's prior compliance record. Two inspections at the same company can now legitimately look different.
Source: Ropes & Gray, "A QMSR State of Mind".
This is the change that catches manufacturers out. Under the old QSR, the FDA explicitly excluded internal audit reports, supplier audit reports, and management review records from inspection scope — it was written into the regulation. ISO 13485, which the QMSR now incorporates by reference, carries no such exclusion. Investigators can request management review records (Clause 5.6) and internal audit findings and corrective actions (Clause 8.2.4), typically once something else in the inspection gives them reason to ask.
Source: IntuitionLabs, "FDA QMSR: Internal Audit Reports No Longer Confidential".
The FDA formally withdrew the 1998 QSIT (Quality System Inspection Technique) manual, with no "QSIT 2" replacement. In its place, device inspections now run under Compliance Program 7382.850, aligned with the Quality Management System Regulation (QMSR) — the revised 21 CFR 820, now harmonized with ISO 13485:2016. Two older compliance programs, 7382.845 and 7383.001, were retired the same day.
QSIT sampled six fixed subsystems (management controls, design controls, CAPA, production/process controls, and so on) in a set pattern. CP 7382.850 is risk-based instead: investigators choose which QMS elements to examine based on the firm's product risk, complaint history, and prior compliance record, rather than working through a fixed checklist.
Yes, and this is the change manufacturers feel first. Under the old QSR, FDA explicitly excluded management review records and internal/supplier audit reports from inspection scope. ISO 13485 — which the QMSR now incorporates by reference — has no such exclusion. Investigators can request management review records (ISO 13485 Clause 5.6) and internal audit findings and corrective actions (Clause 8.2.4), typically once another finding gives them reason to look.
Being ISO 13485 certified is a strong starting position, but certification alone doesn't guarantee QMSR readiness — the gap is usually in what your internal audits and management reviews actually document, since those records are now inspectable in a way they weren't under the old QSR. Worth a documentation-level check before your next inspection, not after.
A QMSR inspection can now reach into documents your quality system never had to defend before. We review your internal audit and management review records against what CP 7382.850 investigators are trained to ask for, close the gaps before an inspection finds them, and coordinate the rest of your US market-access work alongside it.
Book a scoping call