Updated: 10th July 2026
Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder and CEO)
Top 5 Quality Management System Failures Every Medical Device Manufacturer Should Prevent
A Quality Management System (QMS) is the foundation of regulatory compliance, product quality and patient safety. However, even organisations with ISO 13485 certification can experience recurring quality issues if critical elements of their QMS are poorly implemented or allowed to deteriorate over time.
Many of the most significant non-conformities identified during certification audits and regulatory inspections stem from the same underlying weaknesses, including poor document control, ineffective corrective actions, weak supplier oversight and limited management engagement. Left unresolved, these issues can lead to product recalls, regulatory enforcement, certification delays and increased business risk.
This guide explores the five most common Quality Management System failures affecting medical device manufacturers, explains why they occur and provides practical guidance to help organisations strengthen their ISO 13485 Quality Management System and maintain long-term regulatory compliance.
Why Do Quality Management Systems Fail?
Quality Management Systems rarely fail because organisations lack procedures. More commonly, failures occur because documented processes are not consistently followed, monitored or continually improved.
Successful medical device manufacturers recognise that ISO 13485 is not simply about creating documentation—it is about embedding quality into everyday business activities. Leadership commitment, employee engagement, risk-based thinking and continual improvement all play an essential role in maintaining an effective Quality Management System.
By recognising common warning signs early, organisations can reduce quality issues, improve operational efficiency and avoid costly regulatory findings.
The infographic below summarises the five most common Quality Management System failures encountered during ISO 13485 certification audits and regulatory inspections. Understanding these common weaknesses can help medical device manufacturers strengthen their Quality Management System and reduce compliance risks before they become significant issues.
Failure #1 – Poor document control and record keeping
If you want to see a QMS fall over in slow motion, start with document control.
When procedures are outdated, signatures are missing, templates are duplicated, or records are stored across six different spreadsheets and someone’s inbox, risk multiplies quietly in the background.
Regulators know this. In a recent FDA warning letter case discussed by GMP Insiders, a medical device manufacturer was cited for continuing to use obsolete production procedures after process changes. The FDA noted failures in document control and inadequate investigation of nonconformities – textbook QMS failure leading directly to enforcement:
Typical symptoms:
- Multiple versions of SOPs in circulation
- Forms edited locally without approval
- Incomplete batch records or DHRs
- No clear ownership for key procedures
Impact:
- Inconsistent manufacturing outcomes
- Nonconforming products slipping through
- Inability to reconstruct history during investigations
- High risk of ISO 13485 nonconformities and surveillance-audit pain
Prevention strategies:
- Implement a centralised digital document control system with role-based access and audit trails.
- Define clear ownership for each procedure and record type.
- Link document changes to risk assessments and, where appropriate, to CAPA.
- Conduct quarterly document and record reviews, focusing on high-risk processes.
This is one of the most preventable quality management system failures – but only if document control is treated as a live process, not admin.
Strengthen the Foundations of Your Quality Management System
Many Quality Management System failures originate from weaknesses in the fundamental processes that support ISO 13485 compliance. Learn how the core elements of a Quality Management System work together, including leadership, document control, risk management, supplier management, validation, CAPA, internal audits and continual improvement.
Failure #2 – Inadequate CAPA system
If document control is the nervous system of your QMS, CAPA is the immune system. When it’s weak, everything else is at risk.
Regulators repeatedly highlight CAPA as a chronic failure area. Recent analyses of FDA warning-letter trends show that Corrective and Preventive Action deficiencies remain the most frequently cited QMS problem, appearing in over 60% of device warning letters and inspection findings, alongside design-control and complaint-handling failures. Complizen’s 2024–2025 review summarises exactly this pattern:
FDA’s own Quality System Regulation explainer reinforces that CAPA is one of the core elements inspectors evaluate:
How CAPA failures show up:
- The same issue appears in three audit cycles
- Complaints trend upwards with no clear action
- CAPAs closed without root-cause evidence
- No verification of effectiveness, just “action completed”
Notified Bodies are increasingly prepared to suspend certificates where CAPA is clearly ineffective. In 2023–2024, several manufacturers faced escalating findings because:
- The root-cause analysis consisted of guesswork instead of structured methods
- CAPAs focused on symptoms (“retrain staff”) rather than system causes
- There were no effectiveness checks, or they were purely superficial
Prevention strategies:
- Run formal CAPA review meetings with metrics like CAPA ageing, recurrence rate, and impact by process.
- Embed CAPA in management review under ISO 13485 Clause 5.6 – not as an afterthought, but as a core decision input.
- Train teams in structured problem-solving tools such as 5-Why, Ishikawa (Fishbone), and fault-tree analysis.
- Create a clear link between CAPA, complaints, nonconformities, internal audits, and risk management.
Strong CAPA is one of the most effective defences against QMS failures – and one of the first areas inspectors will test.
Prepare Your Quality Management System for Audit Success
Many Quality Management System failures only become visible during certification or surveillance audits. Discover how to prepare for success with our ISO 13485 Audit Readiness Guide, covering common non-conformities, documentation, auditor expectations and practical steps to help you pass your next audit with confidence.
Failure #3 – Weak management commitment and oversight
You can have the best procedures and software in the world, but if leadership treats the QMS as “the quality team’s job”, failure is only a matter of time.
In MHRA and Notified Body inspections, weak management commitment often shows up as:
- Management review minutes that simply restate KPIs with no decisions
- No follow-up on previous review actions
- No linkage to strategic planning or resource allocation
- Quality objectives that are vague, unmeasured, or ignored
When leadership isn’t visibly steering the QMS, the culture follows. Quality becomes something to “get through for the audit”, not a real business priority.
Consequences:
- Chronic under-resourcing of QA/RA
- Firefighting mentality around audits and inspections
- Slow or incomplete responses to CAPA and complaints
- Low staff engagement with quality initiatives
Prevention strategies:
- Tie QMS KPIs to executive and board reporting – including complaint trends, CAPA effectiveness, audit findings, and PMS outputs.
- Conduct regular management reviews aligned with ISO 13485 Clause 5.6, with documented decisions and follow-up responsibilities.
- Nominate Quality Champions in key functions (R&D, operations, supply chain, customer support) to keep quality visible in day-to-day decisions.
In short: a QMS without genuine management backing will eventually turn into one of your biggest ISO 13485 failures.
Build a Stronger Foundation with ISO 13485
Many common Quality Management System failures can be prevented by fully understanding the requirements of ISO 13485. Explore our Complete Guide to ISO 13485 to learn about Quality Management Systems, document control, risk management, supplier management, internal audits, validation and continual improvement for medical device manufacturers.
Failure #4 – Insufficient supplier and outsourced process control
In a globalised supply chain, many critical risks now sit outside your building – in sterilisation providers, contract manufacturers, software partners, and testing labs.
FDA warning-letter statistics for 2023, summarised by ECA Academy, highlight failures to control suppliers and purchasing processes as a persistent theme, including missing supplier evaluations, poor quality agreements, and limited monitoring of supplier performance:
The FDA Warning Letters database provides a steady stream of concrete examples:
Typical supplier-control failures:
- Suppliers added based solely on price or lead time
- No documented qualification or risk ranking
- No formal quality agreements or vague ones that cannot be enforced
- Little or no monitoring of supplier nonconformities or complaint trends
Why it matters:
- A single defective batch of components can trigger global recalls
- Sterilisation or test-lab failures can undermine entire product families
- Regulators increasingly expect end-to-end traceability, not just internal control
Prevention strategies:
- Maintain an Approved Supplier List (ASL) with risk-based qualification and periodic re-evaluation.
- Use quality agreements that clearly define responsibilities, documentation, change-notification expectations, and escalation paths.
- Audit high-risk suppliers and critical outsourced processes at planned intervals, with follow-up CAPAs where needed.
- Integrate supplier issues into your internal CAPA system – supplier failures are not “external problems”, they are part of your QMS.
Build a Lean Quality Management System That Prevents Compliance Failures
Many Quality Management System failures are caused by unnecessary complexity, inconsistent processes and reactive quality management. Learn how to build a lean ISO 13485 Quality Management System that improves efficiency, strengthens regulatory compliance, reduces bureaucracy and supports continual improvement throughout the medical device lifecycle.
Failure #5 – Ineffective internal audits and training
If CAPA is the immune system, internal audits are the early-warning radar. When done well, they catch problems before regulators and customers do. When done badly, they create a dangerous illusion of safety.
A classic pattern:
- Internal audits repeatedly report “no findings”
- Notified Body or FDA inspection, then uncovers major issues in design files, risk management, PMS, and training
- Regulators quickly conclude that your internal audit programme is superficial or incompetent
Common issues:
- Auditors lack regulatory and process understanding
- Audits simply tick compliance with procedures, not the effectiveness of the process
- Audit scopes are narrow, focusing on paperwork rather than practice
- Audit findings are not linked to CAPA or management review
Training is often the quiet co-conspirator here. Staff are expected to “follow the SOPs” but:
- Have not been properly trained on them
- Don’t understand the regulatory context
- They are not evaluated for competency, only attendance
Prevention strategies:
- Implement a risk-based internal audit programme covering all QMS processes and interfaces, including design and development, production, PMS, and supplier management.
- Train internal auditors on both ISO 13485 and relevant regulations (UK MDR, EU MDR, 21 CFR 820 / QMSR), and periodically calibrate audit techniques.
- Require CAPA for significant audit findings and track recurrence metrics.
- Use external independent audits occasionally to challenge internal blind spots.
Implement ISO 13485 the Right Way from the Start
Preventing Quality Management System failures begins with a structured implementation. Our ISO 13485:2016 Requirements & Implementation Guide provides a practical step-by-step approach to developing, implementing and maintaining a compliant Quality Management System, from gap analysis and documentation through to certification and continual improvement.
Early Warning Signs Your Quality Management System Is Beginning to Fail
Quality Management System failures rarely appear suddenly. Instead, they often develop gradually through repeated small issues that go unaddressed. Recognising these warning signs early allows organisations to take corrective action before they result in significant regulatory findings or product quality issues.
Common early warning signs include:
- Repeated audit findings across multiple audit cycles.
- CAPAs remaining open for extended periods.
- Increasing customer complaints.
- Poor document version control.
- Training records that are incomplete or outdated.
- Supplier performance deteriorating.
- Management Reviews being delayed or lacking meaningful actions.
- Risk Management Files not being updated following design changes or post-market feedback.
- Increasing numbers of production deviations.
- Employees following informal practices rather than documented procedures.
Addressing these issues proactively helps organisations maintain an effective Quality Management System while supporting continual improvement and regulatory compliance.
Case studies – lessons from recent regulatory actions
While specific company names are often confidential, the patterns in 2023–2025 regulatory actions are highly consistent. Three anonymised scenarios help illustrate how QMS failures play out in practice.
1. FDA Warning Letter – Software Device (2024)
A manufacturer of a software-driven diagnostic device received an FDA warning letter after:
- Multiple software failures in the field
- Inadequate design validation and verification evidence
- Incomplete CAPA responses with poor root-cause analysis
As highlighted in analyses such as Complizen’s review of top warning-letter violations, design-control and CAPA failures frequently appear together in software-based device enforcement:
KEY LESSON
2. EU / MHRA Inspection – Risk Management & PMS Gap (2023/2024)
A Class IIa manufacturer was flagged in an inspection because:
- Their risk management file had not been updated after field complaints
- PMS reports were formal but did not change risk evaluations
- There were no CAPAs linked to recurring complaint themes
The regulator required a comprehensive corrective-action plan and increased surveillance.
KEY LESSON
3. Notified Body Surveillance Audit – Certificate Suspension (2024)
During a routine surveillance audit, a Notified Body suspended a company’s ISO 13485 certificate after observing:
Incomplete CAPA records
Missing training documentation for key operators
Management review minutes with no decisions or follow-ups
The company had to undertake an extensive remediation plan just to get the certificate reinstated.
KEY LESSON
How to build a failure-proof QMS
No QMS is truly “failure-proof”, but you can get uncomfortably close with a structured, modern approach.
Here is a practical framework:
1. Establish accountability
- Assign process owners for each major QMS element
- Clearly define who owns risk management, CAPA, PMS, document control, and supplier management
- Ensure leadership is visibly accountable for quality performance
2. Digitise documentation
- Move away from fragmented spreadsheets and shared drives
- Implement a centralised eQMS or document-control system with proper versioning and audit trails
- Standardise forms and records across sites and teams
3. Adopt risk-based thinking
- Align your QMS with ISO 14971 where applicable
- Use risk levels to prioritise audits, CAPAs, and supplier monitoring
- Ensure risk controls are traceable into design, production, and PMS activities
4. Embed CAPA and PMS feedback
- Ensure complaints, nonconformities, audits, and PMS outputs all feed into a single CAPA system
- Review CAPA and PMS trends in the management review
- treat early warning signs seriously – don’t wait for a major incident
5. Conduct Mock Audits
- Run internal and external mock audits ahead of Notified Body/FDA/MHRA inspections
- Use them to test your QMS in real conditions and stress-test high-risk processes
- Treat findings as opportunities, not embarrassments
The regulatory and financial impact of QMS failures
QMS failures are not just procedural problems – they are direct business risks.
Under UK MDR, EU MDR, and FDA frameworks, serious failures can trigger:
- MHRA warning notices or enhanced surveillance
- Notified Body suspension or withdrawal of ISO 13485 certification
- FDA warning letters, import alerts, or consent decrees
- Mandatory recalls, import holds, or product withdrawals
Financially, the numbers speak for themselves:
- Device recalls cost the industry up to $5 billion annually, according to combined analyses referenced by Honeywell and quality-assurance studies
- Recall frequency in life-sciences has more than doubled since 2018, driven by complex supply chains and increased regulatory scrutiny
- ETQ’s 2024 survey reported that 73% of manufacturers experienced at least one recall in the previous five years, with many events costing $10–49.9 million in direct costs alone
Sources for further reading:
American Additive – quality and recall impact:
IN SHORT
Preventing Quality Management System Failures
An effective Quality Management System is not maintained through documentation alone. It requires active leadership, well-defined processes, competent personnel and a culture of continual improvement that extends throughout the organisation.
By strengthening document control, supplier management, CAPA, internal auditing and management oversight, medical device manufacturers can significantly reduce regulatory risk while improving product quality and operational performance.
Organisations that continually review and improve their Quality Management System are better positioned to achieve successful ISO 13485 certification, satisfy regulatory expectations and consistently deliver safe and effective medical devices throughout their lifecycle.
Frequently Asked Questions
Typically: poor document control, weak CAPA, low management engagement, insufficient supplier oversight, and superficial internal audits.
Start with a structured gap assessment, implement targeted CAPAs, link changes to risk management, and verify effectiveness through internal audits and management review.
Lack of true root-cause analysis, no effectiveness checks, closing CAPAs too quickly, and failing to link CAPA to complaints, nonconformities, and risk files.
At least annually across all processes, using a risk-based plan. High-risk or problematic processes may require more frequent audits.
Through warning letters, enforcement notices, enhanced surveillance, certificate suspension, import holds, or, in serious cases, recalls and legal actions.
Yes. Patient Guard supports full ISO 13485 gap assessments, internal audit programmes, CAPA system design, and remediation planning for MDR, UK MDR, and FDA expectations.
References
This guide is based on the following international standards, legislation and official regulatory guidance relating to Quality Management Systems (QMS), ISO 13485 compliance and common regulatory findings affecting medical device manufacturers.
| Organisation | Reference | Why it's relevant |
|---|---|---|
| International Organization for Standardization (ISO) | ISO 13485:2016 – Medical Devices – Quality Management Systems – Requirements for Regulatory Purposes | Defines the internationally recognised Quality Management System requirements that underpin effective document control, CAPA, supplier management, internal audits and management responsibility. |
| European Union | Regulation (EU) 2017/745 on Medical Devices (MDR) | Requires manufacturers to establish, implement and maintain an effective Quality Management System throughout the medical device lifecycle, supporting the regulatory expectations discussed throughout this guide. |
| International Organization for Standardization (ISO) | ISO 14971:2019 – Medical Devices – Application of Risk Management to Medical Devices | Provides the internationally recognised framework for integrating risk management into Quality Management Systems, CAPA, post-market surveillance and continual improvement. |
| U.S. Food and Drug Administration (FDA) | Quality Management System Regulation (QMSR) | Explains the FDA's Quality Management System Regulation and its alignment with ISO 13485, supporting the quality management principles described throughout the article. |
| U.S. Food and Drug Administration (FDA) | Medical Devices; Quality System Regulation Amendments (Final Rule) | Publishes the FDA's final rule establishing the Quality Management System Regulation (QMSR) and aligning U.S. quality system requirements more closely with ISO 13485. |
| U.S. Food and Drug Administration (FDA) | FDA Warning Letters | Provides access to FDA Warning Letters, illustrating real regulatory enforcement actions and the recurring Quality Management System failures discussed throughout this article. |
Quality management standards, regulatory expectations and enforcement priorities continue to evolve. Organisations should always consult the latest published standards, legislation and official regulatory guidance when developing, maintaining and continually improving Quality Management Systems for medical devices.
David Small BSc (Hons), MSc, MTOPRA
Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs, MDR/IVDR compliance and quality systems.
Patient Guards Recent Posts

DCB0129 and Clinical Safety: What Digital Health Manufacturers Need for NHS DTAC
For digital health manufacturers preparing to enter the NHS, clinical safety can be one of the most important—and sometimes misunderstood—parts of DTAC.
It is not enough to demonstrate that your software works.
Manufacturers need to consider what could happen if the technology fails, produces incorrect information, presents information incorrectly, contributes to a workflow error or is used in circumstances that could expose patients to harm.
This is where clinical risk management and DCB0129 become particularly important.
NHS England identifies DCB0129 as the clinical risk management standard for manufacturers of health IT systems. Its counterpart, DCB0160, applies to health organisations deploying and using health IT systems. NHS England states that compliance with these standards is required under the Health and Social Care Act 2012.
For manufacturers working towards NHS DTAC readiness, understanding the distinction—and having the right clinical safety evidence—is essential.

DTAC Requirements Explained: The 5 Areas Digital Health Manufacturers Need to Get Right
If your digital health technology is heading towards the NHS, understanding the Digital Technology Assessment Criteria (DTAC) should be part of your market-access planning.
But one of the biggest mistakes manufacturers can make is treating DTAC as simply another questionnaire to complete.
The questions are only part of the process.
Behind your answers needs to be evidence showing that your technology and organisation have appropriate arrangements for clinical safety, data protection, technical security, interoperability, and usability and accessibility.
These five areas form the core of NHS DTAC. NHS England describes DTAC as national baseline criteria for digital health technologies entering NHS and social care.
For digital health manufacturers, the practical question is therefore not simply:
“Can we complete the DTAC assessment?”
It is:
“Can we demonstrate that our product meets the requirements?”
This guide looks at each of the five DTAC areas, the types of evidence manufacturers should consider and some of the common gaps that can delay NHS readiness.

The Complete Guide to NHS DTAC Compliance for Digital Health Manufacturers
A complete guide to NHS DTAC compliance for digital health manufacturers, covering the five DTAC assessment areas, required evidence, clinical safety, data protection, technical security, interoperability and usability, and how to prepare your digital health technology for NHS procurement.
Patient Guards Related Services
Patient Guards Regulatory Tools
Need Training?
Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.
Posted on Google![]()
Jay Verma15 days agoTrustindex verifies that the original source of the review is Google.
I found Patient Guard Ltd to be an exceptional partner. Their assessment was thorough, their guidance clear, and their support instrumental in helping us achieve our objectives. Steve and Ellie, in particular, were outstanding in steering us through the MHRA Class I medical device registration process.Posted on Google![]()
Munna P68 days agoTrustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.Posted on Google![]()
Peter Reeve94 days agoTrustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.Posted on Google![]()
Derek Timm95 days agoTrustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South LımıtedPosted on Google![]()
BMSCriticalCare132 days agoTrustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,Posted on Google![]()
Thomson Software803 days agoTrustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.Posted on Google![]()
Hannah Maddison906 days agoTrustindex verifies that the original source of the review is Google.
Fantastic, knowledgeable team that are always there to help. My appointments have always been booked in very promptly and have always ended with all my queries resolved. I have found the team very flexible and their breadth of knowledge is second to none. Patient Guard are without doubt my go-to for all the regulatory aspects of my medical device role.Posted on Google![]()
Richard Crow941 days agoTrustindex verifies that the original source of the review is Google.
Patientguard are an excellent source of Medical regulatory compliance advice, we have taken advantage of their various services from their EU Rep service, to helping with Technical Files all the way through to using their ISO Templates to implement our ISO 13485 system.Posted on Google![]()
George Kitching944 days agoTrustindex verifies that the original source of the review is Google.
David Small and PatientGuard have been extremely helpful and supportive in assisting us with producing and updating our Technical File and Appendices for MDR certification.Posted on Google![]()
Tracey Slater944 days agoTrustindex verifies that the original source of the review is Google.
Patient Guard have been a great support service to Cormed, providing help and advice promptly when ever requested. They have become a virtual department within Cormed enabling us to keep up to date and comply with the regulatory requirements whilst ensuring our QMS works for us at the same time.Verified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more