Complaint Handling

Complaint Handling is the regulated process a medical device manufacturer uses to receive, document, evaluate, and investigate any communication alleging a deficiency in a marketed device’s identity, quality, safety, or performance. It determines whether each complaint is reportable to regulators and drives corrective action, helping keep the device safe in the field.


What is Complaint Handling?

Complaint Handling, sometimes called complaint management, is a core post-market activity in the medical device lifecycle. A complaint is any written, electronic, or oral communication that alleges a deficiency related to the identity, quality, durability, reliability, usability, safety, or performance of a device after it has been released for distribution. ISO 13485:2016 Clause 8.2.2 sets the requirement, and the same definition carries into both US and EU frameworks.

The process sits at the front end of post-market surveillance. It captures real-world signals from clinicians, patients, distributors, and field staff, then routes them through evaluation, investigation, reportability assessment, and corrective and preventive action (CAPA). Complaint Handling is reactive by design, but a mature system also turns aggregated complaint data into trend signals that inform risk management.


Why Complaint Handling Matters in Medical Device Development

Complaints are often the first evidence that a device behaves differently in clinical use than it did in verification and validation. Missing or mishandling that signal has direct consequences: patient harm, delayed recalls, and regulatory enforcement.

In the United States, complaint records are a standing target for inspection. Under the Quality Management System Regulation (QMSR), which took effect on February 2, 2026, the FDA replaced the older Quality System Regulation and now incorporates ISO 13485:2016 by reference, with FDA-specific record content set forth in 21 CFR 820.35. Weak complaint files remain among the most frequently cited findings in device warning letters.

The cost scales with delay. A complaint caught and investigated early may close as a documented non-issue. The same signal ignored can become a field safety corrective action, a recall, or litigation. Auditors read the complaint system as a proxy for whether a manufacturer actually controls its product once it leaves the factory.


How Complaint Handling Works

A compliant process follows a closed loop from intake to closure. The specific steps vary by company, but the regulated backbone is consistent:

  • Intake and documentation. Capture every complaint regardless of source, with device identification, any Unique Device Identifier (UDI), dates, and the complainant’s details.
  • Triage and evaluation. Decide whether the communication constitutes a complaint and assess its potential impact on patient safety.
  • Investigation. Determine root cause, often pulling in design, manufacturing, and supplier records. Justify and document any decision not to investigate.
  • Reportability assessment. Decide whether the event must be reported to regulators, applying 21 CFR Part 803 in the US (Medical Device Reporting) and EU MDR Article 87 vigilance rules in Europe.
  • Corrective action and closure. Link confirmed the issues with CAPA, verified their effectiveness, and closed the record with a clear determination of whether the device met its specifications.

Several standards and regulations govern these steps. ISO 13485:2016 Clause 8.2.2 sets the complaint requirement, and Clause 8.2.3 covers regulatory reporting. ISO 14971 supplies the risk framework that drives reportability and CAPA decisions. In Europe, complaints that qualify as serious incidents are governed by Article 87 of the EU MDR 2017/745, with trend reporting under Article 88.


Common Challenges and Best Practices

The most common failure is not the investigation itself but the front door. Teams miss complaints because field communications are never logged, or because a sales or service note that clearly alleges a deficiency is never recognized as a complaint. Train every customer-facing function on what counts as a complaint.

Reportability is the second pressure point. US and EU timelines differ, and the language differs too: the EU MDR uses the terms “incident” and “serious incident,” not the US concept of “adverse event,” so a single global event can trigger different obligations in each market. Build a decision tree mapped to each jurisdiction, rather than a single generic rule.

Good systems treat complaints as data, not just cases. Aggregating and trending complaint signals against the risk file allows a team to detect drift before it becomes a serious incident. Tie that trending to Article 88 obligations in Europe and to ongoing risk management under ISO 14971, and the system starts preventing problems instead of only recording them.


How SJML Helps with Complaint Handling

SJML supports complaint handling and vigilance as part of its compliance-as-a-service offering. The QARA team handles complaint intake, evaluation, and adverse-event and serious-incident reporting, with root cause analysis fed into CAPA. The same team supports post-market surveillance planning, PSUR and PMSR preparation, vigilance, and field safety corrective actions, as well as maintenance of the ISO 13485 and ISO 14971 quality and risk files. For manufacturers scaling into US and EU markets, SJML can run these processes as a managed service with defined governance and on-demand capacity.

Talk to SJML’s QARA team →


Frequently Asked Questions

What is the difference between a complaint and an adverse event?

A complaint is any communication alleging a deficiency in a device’s identity, quality, safety, or performance. An adverse event is a specific outcome where a device may have caused or contributed to harm. Every adverse event starts as a complaint, but most complaints are not adverse events. The complaint process determines which communications constitute reportable events under FDA or EU rules.

Is complaint handling required by ISO 13485?

Yes. ISO 13485:2016 Clause 8.2.2 requires a documented procedure for receiving, evaluating, and investigating complaints, and Clause 8.2.3 covers reporting to regulatory authorities. Since the FDA QMSR took effect on February 2, 2026, US manufacturers have met this requirement by incorporating ISO 13485 by reference, with additional complaint record content specified in 21 CFR 820.35.

How fast must a medical device complaint be reported in the EU?

It depends on severity. Under EU MDR 2017/745 Article 87, a manufacturer must report a serious public health threat within two days, a death or unanticipated serious deterioration in health within ten days, and any other serious incident within fifteen days of becoming aware. Non-serious incidents may instead be captured through trend reporting under Article 88.

Does every complaint require an investigation?

No, but every complaint requires evaluation. If a similar complaint has already been investigated, a new investigation may not be necessary, provided the manufacturer documents the justification. Under the QMSR, that rationale must be recorded. The goal is a defensible, consistent decision, not an investigation of every case regardless of relevance.


Related Terms

  • Post-Market Surveillance
  • Adverse Event
  • CAPA (Corrective and Preventive Action)
  • ISO 13485
  • Medical Device Reporting (MDR)

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

```html ```