Complaints Handling

Complaint handling is the systematic process a medical device manufacturer uses to receive, record, evaluate, investigate, and respond to communications alleging that a device failed to meet its quality, safety, or performance claims after release. It links directly to risk management, corrective action, and regulatory reporting, and sits at the center of post-market surveillance.


What is Complaints Handling?

Complaint handling is the closed-loop system for managing feedback that alleges a deficiency in a marketed device. A complaint, under ISO 13485:2016, is any written, electronic, or oral communication claiming problems with the identity, quality, durability, reliability, usability, safety, or performance of a device already in distribution.

It sits in the post-market phase of the device lifecycle. Once a product ships, the manufacturer no longer controls how it is used, so the complaint file becomes a primary signal for real-world failures. Effective complaints handling connects intake to investigation, root cause analysis (RCA), corrective and preventive action (CAPA), and, where thresholds are met, regulatory reporting.


Why Complaints Handling matters in medical device development

A device complaint is often the first evidence that a design assumption, a manufacturing control, or a use-related risk was wrong. Miss it, and a low-frequency defect can grow into a recall or patient harm. Catch it early, and you contain the issue while it is small.

The regulatory stakes are direct. Under the FDA Quality Management System Regulation (QMSR), effective February 2, 2026, complaint records are inspected against ISO 13485:2016 plus FDA record requirements in 21 CFR 820.35. Complaints meeting the criteria in 21 CFR Part 803 must be filed as Medical Device Reports (MDRs). In the European Union, complaint data feeds the vigilance system under EU MDR 2017/745 Articles 87–92, with serious incidents reported to competent authorities and through EUDAMED.

Weak complaint handling shows up quickly during audits. Untimely investigations, missing device identification, and the absence of links to CAPA are among the most common findings during FDA inspections and Notified Body assessments.


How the Complaints Handling process works

A robust complaints handling process follows a structured sequence:

  • Intake and capture. Record every complaint regardless of source, including field service, distributors, clinicians, patients, or digital channels. Capture the device identification, including the Unique Device Identifier (UDI), lot or serial number, complaint date, and complainant information.
  • Triage and reportability assessment. Determine whether the complaint meets the criteria for regulatory reporting. FDA reporting follows 21 CFR Part 803, while EU serious incidents are evaluated under EU MDR Article 87. Reporting timelines begin when the manufacturer becomes aware of the event.
  • Investigation. Determine whether the device met specifications. Under 21 CFR 820.35, investigations must be documented, or the rationale for not investigating must be recorded if a similar complaint has already been fully investigated.
  • Root cause analysis (RCA). Identify the underlying cause of the issue using structured investigation methods and determine whether the problem originated in design, manufacturing, suppliers, labeling, or user interaction.
  • CAPA and risk review. Feed confirmed findings into the CAPA system and update the ISO 14971 risk management file. New hazards or increased occurrence rates may require a revised benefit-risk assessment.
  • Reporting and closure. Submit required MDR or vigilance reports within regulatory timelines, document corrective actions, and formally close the complaint with objective evidence.

The principal regulatory references include:

  • ISO 13485:2016 Clause 8.2.2 for complaint handling.
  • ISO 13485:2016 Clause 8.2.3 for reporting to regulatory authorities.
  • ISO 14971 for integration with risk management.
  • FDA QMSR and EU MDR for jurisdiction-specific complaint and vigilance requirements.

Additionally, EU MDR Article 88 introduces trend reporting, requiring manufacturers to report statistically significant increases in non-serious incidents when predefined thresholds in the PMS plan are exceeded.


Common challenges and best practices

One of the most common failures is treating complaints as an administrative inbox rather than a safety signal. Organizations may record complaints without linking them to CAPA, fail to document investigation decisions, or delay reportability decisions while waiting for root cause analysis.

Successful complaint management programs typically:

  • Define clearly what constitutes a complaint so all potential complaints are consistently captured.
  • Separate regulatory reportability decisions from technical investigations to avoid reporting delays.
  • Maintain complete complaint records with traceability to the affected UDI and production records.
  • Trend complaint data against predefined thresholds to detect emerging safety issues before they escalate into recalls.
  • Validate electronic complaint management software for its intended use, consistent with QMSR expectations.

How SJML helps with Complaints Handling

Syrma Johari MedTech (SJML) provides complaints handling and vigilance as part of its Compliance-as-a-Service offering. That covers complaint intake, adverse-event and serious-incident assessment, root cause analysis, and CAPA, aligned to ISO 13485 and FDA and EU MDR post-market obligations. SJML supports post-market surveillance planning, PSUR and PMSR preparation, vigilance and field safety corrective action workflows, and EUDAMED-related activities, with QARA services that scale from startups through large OEMs. Risk files under ISO 14971 sit in the same quality system, so complaint findings flow back into the product.

Talk to SJML’s QARA team →


Frequently asked questions

What is a complaint in medical device terms?

Under ISO 13485:2016, a complaint is any written, electronic, or oral communication alleging deficiencies in the identity, quality, durability, reliability, usability, safety, or performance of a medical device that has already been released for distribution. Complaints may come from clinicians, patients, distributors, service engineers, or other users and must be documented and evaluated.

Is every complaint a reportable adverse event?

No. Every complaint must be documented and assessed, but only complaints meeting regulatory reporting criteria become reportable adverse events. In the United States, reportability is determined under 21 CFR Part 803 Medical Device Reporting (MDR) requirements. In the European Union, serious incidents are reported under EU MDR Article 87. The rationale for reporting—or deciding not to report—must always be documented.

How does complaint handling differ under the FDA QMSR?

Since February 2, 2026, the FDA Quality Management System Regulation (QMSR) incorporates ISO 13485:2016 by reference, making Clause 8.2.2 the primary complaint handling requirement. FDA-specific recordkeeping requirements remain in 21 CFR 820.35, including complaint investigations, device identification, UDI information, and complainant details. The former 21 CFR 820.198 complaint file section has been replaced by the ISO-based framework with FDA-specific record requirements.

How do complaints connect to CAPA and risk management?

Complaints serve as critical inputs to both CAPA and ISO 14971 risk management. Confirmed issues trigger root cause analysis and corrective actions to eliminate underlying problems. Complaint trends may also reveal new hazards or increased occurrence rates, requiring updates to the risk management file and reassessment of the device’s overall benefit-risk profile. This continuous feedback loop drives ongoing product and process improvement.


Related terms

  • CAPA (Corrective and Preventive Action)
  • Post-Market Surveillance (PMS)
  • Vigilance Reporting
  • Medical Device Reporting (MDR)
  • ISO 14971 Risk Management

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

```html ```