Updated: 10th July 2026
Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder and CEO)
Top 5 Quality Management System Failures Every Medical Device Manufacturer Should Prevent
A Quality Management System (QMS) is the foundation of regulatory compliance, product quality and patient safety. However, even organisations with ISO 13485 certification can experience recurring quality issues if critical elements of their QMS are poorly implemented or allowed to deteriorate over time.
Many of the most significant non-conformities identified during certification audits and regulatory inspections stem from the same underlying weaknesses, including poor document control, ineffective corrective actions, weak supplier oversight and limited management engagement. Left unresolved, these issues can lead to product recalls, regulatory enforcement, certification delays and increased business risk.
This guide explores the five most common Quality Management System failures affecting medical device manufacturers, explains why they occur and provides practical guidance to help organisations strengthen their ISO 13485 Quality Management System and maintain long-term regulatory compliance.
Why Do Quality Management Systems Fail?
Quality Management Systems rarely fail because organisations lack procedures. More commonly, failures occur because documented processes are not consistently followed, monitored or continually improved.
Successful medical device manufacturers recognise that ISO 13485 is not simply about creating documentation—it is about embedding quality into everyday business activities. Leadership commitment, employee engagement, risk-based thinking and continual improvement all play an essential role in maintaining an effective Quality Management System.
By recognising common warning signs early, organisations can reduce quality issues, improve operational efficiency and avoid costly regulatory findings.
The infographic below summarises the five most common Quality Management System failures encountered during ISO 13485 certification audits and regulatory inspections. Understanding these common weaknesses can help medical device manufacturers strengthen their Quality Management System and reduce compliance risks before they become significant issues.
Failure #1 – Poor document control and record keeping
If you want to see a QMS fall over in slow motion, start with document control.
When procedures are outdated, signatures are missing, templates are duplicated, or records are stored across six different spreadsheets and someone’s inbox, risk multiplies quietly in the background.
Regulators know this. In a recent FDA warning letter case discussed by GMP Insiders, a medical device manufacturer was cited for continuing to use obsolete production procedures after process changes. The FDA noted failures in document control and inadequate investigation of nonconformities – textbook QMS failure leading directly to enforcement:
Typical symptoms:
- Multiple versions of SOPs in circulation
- Forms edited locally without approval
- Incomplete batch records or DHRs
- No clear ownership for key procedures
Impact:
- Inconsistent manufacturing outcomes
- Nonconforming products slipping through
- Inability to reconstruct history during investigations
- High risk of ISO 13485 nonconformities and surveillance-audit pain
Prevention strategies:
- Implement a centralised digital document control system with role-based access and audit trails.
- Define clear ownership for each procedure and record type.
- Link document changes to risk assessments and, where appropriate, to CAPA.
- Conduct quarterly document and record reviews, focusing on high-risk processes.
This is one of the most preventable quality management system failures – but only if document control is treated as a live process, not admin.
Strengthen the Foundations of Your Quality Management System
Many Quality Management System failures originate from weaknesses in the fundamental processes that support ISO 13485 compliance. Learn how the core elements of a Quality Management System work together, including leadership, document control, risk management, supplier management, validation, CAPA, internal audits and continual improvement.
Failure #2 – Inadequate CAPA system
If document control is the nervous system of your QMS, CAPA is the immune system. When it’s weak, everything else is at risk.
Regulators repeatedly highlight CAPA as a chronic failure area. Recent analyses of FDA warning-letter trends show that Corrective and Preventive Action deficiencies remain the most frequently cited QMS problem, appearing in over 60% of device warning letters and inspection findings, alongside design-control and complaint-handling failures. Complizen’s 2024–2025 review summarises exactly this pattern:
FDA’s own Quality System Regulation explainer reinforces that CAPA is one of the core elements inspectors evaluate:
How CAPA failures show up:
- The same issue appears in three audit cycles
- Complaints trend upwards with no clear action
- CAPAs closed without root-cause evidence
- No verification of effectiveness, just “action completed”
Notified Bodies are increasingly prepared to suspend certificates where CAPA is clearly ineffective. In 2023–2024, several manufacturers faced escalating findings because:
- The root-cause analysis consisted of guesswork instead of structured methods
- CAPAs focused on symptoms (“retrain staff”) rather than system causes
- There were no effectiveness checks, or they were purely superficial
Prevention strategies:
- Run formal CAPA review meetings with metrics like CAPA ageing, recurrence rate, and impact by process.
- Embed CAPA in management review under ISO 13485 Clause 5.6 – not as an afterthought, but as a core decision input.
- Train teams in structured problem-solving tools such as 5-Why, Ishikawa (Fishbone), and fault-tree analysis.
- Create a clear link between CAPA, complaints, nonconformities, internal audits, and risk management.
Strong CAPA is one of the most effective defences against QMS failures – and one of the first areas inspectors will test.
Prepare Your Quality Management System for Audit Success
Many Quality Management System failures only become visible during certification or surveillance audits. Discover how to prepare for success with our ISO 13485 Audit Readiness Guide, covering common non-conformities, documentation, auditor expectations and practical steps to help you pass your next audit with confidence.
Failure #3 – Weak management commitment and oversight
You can have the best procedures and software in the world, but if leadership treats the QMS as “the quality team’s job”, failure is only a matter of time.
In MHRA and Notified Body inspections, weak management commitment often shows up as:
- Management review minutes that simply restate KPIs with no decisions
- No follow-up on previous review actions
- No linkage to strategic planning or resource allocation
- Quality objectives that are vague, unmeasured, or ignored
When leadership isn’t visibly steering the QMS, the culture follows. Quality becomes something to “get through for the audit”, not a real business priority.
Consequences:
- Chronic under-resourcing of QA/RA
- Firefighting mentality around audits and inspections
- Slow or incomplete responses to CAPA and complaints
- Low staff engagement with quality initiatives
Prevention strategies:
- Tie QMS KPIs to executive and board reporting – including complaint trends, CAPA effectiveness, audit findings, and PMS outputs.
- Conduct regular management reviews aligned with ISO 13485 Clause 5.6, with documented decisions and follow-up responsibilities.
- Nominate Quality Champions in key functions (R&D, operations, supply chain, customer support) to keep quality visible in day-to-day decisions.
In short: a QMS without genuine management backing will eventually turn into one of your biggest ISO 13485 failures.
Build a Stronger Foundation with ISO 13485
Many common Quality Management System failures can be prevented by fully understanding the requirements of ISO 13485. Explore our Complete Guide to ISO 13485 to learn about Quality Management Systems, document control, risk management, supplier management, internal audits, validation and continual improvement for medical device manufacturers.
Failure #4 – Insufficient supplier and outsourced process control
In a globalised supply chain, many critical risks now sit outside your building – in sterilisation providers, contract manufacturers, software partners, and testing labs.
FDA warning-letter statistics for 2023, summarised by ECA Academy, highlight failures to control suppliers and purchasing processes as a persistent theme, including missing supplier evaluations, poor quality agreements, and limited monitoring of supplier performance:
The FDA Warning Letters database provides a steady stream of concrete examples:
Typical supplier-control failures:
- Suppliers added based solely on price or lead time
- No documented qualification or risk ranking
- No formal quality agreements or vague ones that cannot be enforced
- Little or no monitoring of supplier nonconformities or complaint trends
Why it matters:
- A single defective batch of components can trigger global recalls
- Sterilisation or test-lab failures can undermine entire product families
- Regulators increasingly expect end-to-end traceability, not just internal control
Prevention strategies:
- Maintain an Approved Supplier List (ASL) with risk-based qualification and periodic re-evaluation.
- Use quality agreements that clearly define responsibilities, documentation, change-notification expectations, and escalation paths.
- Audit high-risk suppliers and critical outsourced processes at planned intervals, with follow-up CAPAs where needed.
- Integrate supplier issues into your internal CAPA system – supplier failures are not “external problems”, they are part of your QMS.
Build a Lean Quality Management System That Prevents Compliance Failures
Many Quality Management System failures are caused by unnecessary complexity, inconsistent processes and reactive quality management. Learn how to build a lean ISO 13485 Quality Management System that improves efficiency, strengthens regulatory compliance, reduces bureaucracy and supports continual improvement throughout the medical device lifecycle.
Failure #5 – Ineffective internal audits and training
If CAPA is the immune system, internal audits are the early-warning radar. When done well, they catch problems before regulators and customers do. When done badly, they create a dangerous illusion of safety.
A classic pattern:
- Internal audits repeatedly report “no findings”
- Notified Body or FDA inspection, then uncovers major issues in design files, risk management, PMS, and training
- Regulators quickly conclude that your internal audit programme is superficial or incompetent
Common issues:
- Auditors lack regulatory and process understanding
- Audits simply tick compliance with procedures, not the effectiveness of the process
- Audit scopes are narrow, focusing on paperwork rather than practice
- Audit findings are not linked to CAPA or management review
Training is often the quiet co-conspirator here. Staff are expected to “follow the SOPs” but:
- Have not been properly trained on them
- Don’t understand the regulatory context
- They are not evaluated for competency, only attendance
Prevention strategies:
- Implement a risk-based internal audit programme covering all QMS processes and interfaces, including design and development, production, PMS, and supplier management.
- Train internal auditors on both ISO 13485 and relevant regulations (UK MDR, EU MDR, 21 CFR 820 / QMSR), and periodically calibrate audit techniques.
- Require CAPA for significant audit findings and track recurrence metrics.
- Use external independent audits occasionally to challenge internal blind spots.
Implement ISO 13485 the Right Way from the Start
Preventing Quality Management System failures begins with a structured implementation. Our ISO 13485:2016 Requirements & Implementation Guide provides a practical step-by-step approach to developing, implementing and maintaining a compliant Quality Management System, from gap analysis and documentation through to certification and continual improvement.
Early Warning Signs Your Quality Management System Is Beginning to Fail
Quality Management System failures rarely appear suddenly. Instead, they often develop gradually through repeated small issues that go unaddressed. Recognising these warning signs early allows organisations to take corrective action before they result in significant regulatory findings or product quality issues.
Common early warning signs include:
- Repeated audit findings across multiple audit cycles.
- CAPAs remaining open for extended periods.
- Increasing customer complaints.
- Poor document version control.
- Training records that are incomplete or outdated.
- Supplier performance deteriorating.
- Management Reviews being delayed or lacking meaningful actions.
- Risk Management Files not being updated following design changes or post-market feedback.
- Increasing numbers of production deviations.
- Employees following informal practices rather than documented procedures.
Addressing these issues proactively helps organisations maintain an effective Quality Management System while supporting continual improvement and regulatory compliance.
Case studies – lessons from recent regulatory actions
While specific company names are often confidential, the patterns in 2023–2025 regulatory actions are highly consistent. Three anonymised scenarios help illustrate how QMS failures play out in practice.
1. FDA Warning Letter – Software Device (2024)
A manufacturer of a software-driven diagnostic device received an FDA warning letter after:
- Multiple software failures in the field
- Inadequate design validation and verification evidence
- Incomplete CAPA responses with poor root-cause analysis
As highlighted in analyses such as Complizen’s review of top warning-letter violations, design-control and CAPA failures frequently appear together in software-based device enforcement:
KEY LESSON
2. EU / MHRA Inspection – Risk Management & PMS Gap (2023/2024)
A Class IIa manufacturer was flagged in an inspection because:
- Their risk management file had not been updated after field complaints
- PMS reports were formal but did not change risk evaluations
- There were no CAPAs linked to recurring complaint themes
The regulator required a comprehensive corrective-action plan and increased surveillance.
KEY LESSON
3. Notified Body Surveillance Audit – Certificate Suspension (2024)
During a routine surveillance audit, a Notified Body suspended a company’s ISO 13485 certificate after observing:
Incomplete CAPA records
Missing training documentation for key operators
Management review minutes with no decisions or follow-ups
The company had to undertake an extensive remediation plan just to get the certificate reinstated.
KEY LESSON
How to build a failure-proof QMS
No QMS is truly “failure-proof”, but you can get uncomfortably close with a structured, modern approach.
Here is a practical framework:
1. Establish accountability
- Assign process owners for each major QMS element
- Clearly define who owns risk management, CAPA, PMS, document control, and supplier management
- Ensure leadership is visibly accountable for quality performance
2. Digitise documentation
- Move away from fragmented spreadsheets and shared drives
- Implement a centralised eQMS or document-control system with proper versioning and audit trails
- Standardise forms and records across sites and teams
3. Adopt risk-based thinking
- Align your QMS with ISO 14971 where applicable
- Use risk levels to prioritise audits, CAPAs, and supplier monitoring
- Ensure risk controls are traceable into design, production, and PMS activities
4. Embed CAPA and PMS feedback
- Ensure complaints, nonconformities, audits, and PMS outputs all feed into a single CAPA system
- Review CAPA and PMS trends in the management review
- treat early warning signs seriously – don’t wait for a major incident
5. Conduct Mock Audits
- Run internal and external mock audits ahead of Notified Body/FDA/MHRA inspections
- Use them to test your QMS in real conditions and stress-test high-risk processes
- Treat findings as opportunities, not embarrassments
The regulatory and financial impact of QMS failures
QMS failures are not just procedural problems – they are direct business risks.
Under UK MDR, EU MDR, and FDA frameworks, serious failures can trigger:
- MHRA warning notices or enhanced surveillance
- Notified Body suspension or withdrawal of ISO 13485 certification
- FDA warning letters, import alerts, or consent decrees
- Mandatory recalls, import holds, or product withdrawals
Financially, the numbers speak for themselves:
- Device recalls cost the industry up to $5 billion annually, according to combined analyses referenced by Honeywell and quality-assurance studies
- Recall frequency in life-sciences has more than doubled since 2018, driven by complex supply chains and increased regulatory scrutiny
- ETQ’s 2024 survey reported that 73% of manufacturers experienced at least one recall in the previous five years, with many events costing $10–49.9 million in direct costs alone
Sources for further reading:
American Additive – quality and recall impact:
IN SHORT
Preventing Quality Management System Failures
An effective Quality Management System is not maintained through documentation alone. It requires active leadership, well-defined processes, competent personnel and a culture of continual improvement that extends throughout the organisation.
By strengthening document control, supplier management, CAPA, internal auditing and management oversight, medical device manufacturers can significantly reduce regulatory risk while improving product quality and operational performance.
Organisations that continually review and improve their Quality Management System are better positioned to achieve successful ISO 13485 certification, satisfy regulatory expectations and consistently deliver safe and effective medical devices throughout their lifecycle.
Frequently Asked Questions
Typically: poor document control, weak CAPA, low management engagement, insufficient supplier oversight, and superficial internal audits.
Start with a structured gap assessment, implement targeted CAPAs, link changes to risk management, and verify effectiveness through internal audits and management review.
Lack of true root-cause analysis, no effectiveness checks, closing CAPAs too quickly, and failing to link CAPA to complaints, nonconformities, and risk files.
At least annually across all processes, using a risk-based plan. High-risk or problematic processes may require more frequent audits.
Through warning letters, enforcement notices, enhanced surveillance, certificate suspension, import holds, or, in serious cases, recalls and legal actions.
Yes. Patient Guard supports full ISO 13485 gap assessments, internal audit programmes, CAPA system design, and remediation planning for MDR, UK MDR, and FDA expectations.
David Small BSc (Hons), MSc, MTOPRA
Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs, MDR/IVDR compliance and quality systems.
Patient Guards Recent Posts

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews
Preparing technical documentation for EU MDR or IVDR certification is only half the challenge. Successfully passing a Notified Body review depends on demonstrating consistency across your Quality Management System, Clinical Evaluation, Risk Management, Biological Evaluation, Performance Evaluation and Post-Market Surveillance activities. Discover ten of the most common technical documentation deficiencies identified during MDR and IVDR conformity assessments—and learn how to reduce the likelihood of costly review cycles and certification delays.

EU Authorised Representative Services for Medical Device & IVD Manufacturers
Selling medical devices or IVDs in Europe? If your company is based outside the EU, appointing an EU Authorised Representative (EC Rep) is a legal requirement under EU MDR 2017/745 and IVDR 2017/746. Patient Guard provides expert EU Authorised Representative services, EUDAMED support, regulatory guidance, and ongoing compliance management to help manufacturers access and maintain the European market with confidence.

Predetermined Change Control Plans (PCCPs): The Future of Agile Compliance for Medical Device Software
Learn how PCCPs help medical device software manufacturers manage updates, support AI systems, and enable agile compliance under evolving MDR and UKCA frameworks.
Patient Guards Related Services
Patient Guards Regulatory Tools
Need Training?
Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.