This is a deep-dive exploration from: FDA Replaced QSIT: How Risk Management Files Now Drive Device Inspections
For a Quality Assurance VP, FDA's transition from QSIT to the risk-based QMSR inspection model is not merely a procedural update; it is a strategic inflection point that places the risk management file at the center of every inspection. Within that file, clinical evidence strategy is the bridge between hazard analysis and verifiable claims of safety and effectiveness. This deep dive provides an implementation-ready examination of how clinical study designs, endpoint selection, and equivalence arguments must be structured, maintained, and presented so that an FDA investigator can trace every identified risk to a valid scientific evidence base. The guidance integrates the QMSR final rule, Compliance Program 7382.850, ISO 13485:2016, ISO 14971, ISO 14155:2026, FDA's pivotal clinical investigation guidance, and the least burdensome provisions into a single operational framework for inspection readiness.
Under the Quality System Regulation (QMSR), which became effective on February 2, 2026, FDA amended 21 CFR Part 820 to incorporate by reference ISO 13485:2016 and to retire the Quality System Inspection Technique (QSIT). The new inspection methodology is described in Compliance Program 7382.850, "Inspection of Medical Device Manufacturers." The most consequential operational change for QA leadership is that investigators now begin inspections by reviewing the manufacturer's risk management file and use product-specific risks to determine which QMS areas to examine, which records to sample, and how deeply to evaluate controls.
Clinical evidence is no longer the exclusive domain of regulatory affairs or clinical affairs. It is an input to, and an output of, the quality management system. Under ISO 13485:2016 Clause 7.3.7, clinical evaluation may be required as part of design validation. Under ISO 14971, clinical data informs the estimation of risk, the evaluation of residual risk, and the post-market surveillance loop. Under CP 7382.850, investigators explicitly review post-market surveillance data, complaint trends, medical device reports, corrections and removals, and servicing records to understand product risk. Any disconnect between the risk file and the clinical evidence strategy becomes an inspection finding almost by definition.
The QA VP therefore needs a clinical evidence strategy that is:
The QMSR final rule (89 FR 7496, February 2, 2024) incorporates ISO 13485:2016 by reference into 21 CFR Part 820. This means the ISO 13485 standard text has the force and effect of U.S. federal law. For clinical evidence strategy, the most relevant clauses are:
When FDA investigators review design controls under the new model, they will not simply check that a design validation report exists. They will ask how the validation evidence addresses the risks in the risk management file, whether the clinical evidence is current, and whether post-market data have caused the organization to revisit prior conclusions.
ISO 14971 requires a risk management file for each device. The file must include:
Clinical evidence enters this lifecycle in three ways. First, clinical data may be used to estimate the probability or severity of harm for a given hazardous situation. Second, clinical data may be required to validate the effectiveness of a risk control measure, particularly when the control's performance can only be demonstrated in human use. Third, post-market clinical data must be used to update the risk management file when new safety or performance information becomes available. Under CP 7382.850, an investigator who finds that post-market data has not been used to update risk estimates has a direct path to an Official Action Indicated (OAI) classification, because the failure reflects a breakdown in the risk-based decision-making that QMSR demands.
The risk management file should also document the risk acceptability criteria. These criteria must be defined before risks are evaluated, not adjusted afterward to justify a predetermined conclusion. Clinical evidence must support the criteria: for example, if a residual risk is deemed acceptable because it is comparable to the risk of the standard of care, the file should cite the clinical data that establish that benchmark.
ISO 14155:2026 is the international Good Clinical Practice standard for medical device clinical investigations. It specifies requirements for the design, conduct, recording, and reporting of clinical investigations in human subjects. The 2026 edition introduces mandatory risk management integration, Clinical Events Committees (CECs), Data Monitoring Committees (DMCs), and an estimand framework aligned with ICH E9(R1). For FDA submissions, clinical investigations are also governed by 21 CFR Part 812 (Investigational Device Exemptions) for significant risk devices and by the informed consent and IRB requirements of 21 CFR Parts 50 and 56.
The convergence of ISO 14155:2026 and FDA IDE requirements means that a well-designed clinical investigation plan can satisfy both sets of expectations. The QA VP should ensure that the clinical evidence strategy explicitly addresses both frameworks and that any deviations are justified and documented. For example, if a clinical investigation is conducted outside the United States, 21 CFR 812.28 sets forth acceptance criteria, while ISO 14155:2026 provides the GCP baseline. The strategy should document how both are met.
For QA leadership, a clinical evidence strategy is the documented plan that defines what clinical data are needed, why they are needed, how they will be generated or sourced, how they connect to the risk management file and design validation, and how they will be maintained and updated throughout the device lifecycle. It is not a regulatory submission artifact; it is a living QMS record.
The strategy should answer the following questions for every device or device family:
A robust strategy is not a one-time document created at the start of a submission. It is updated when design changes occur, when new post-market data emerge, when predicates are modified, and when regulatory guidance changes. The update history itself is an inspection artifact that demonstrates the organization's commitment to lifecycle management.
For high-risk devices or novel technologies, a randomized controlled trial (RCT) remains the strongest design for establishing causal effects. FDA's "Design Considerations for Pivotal Clinical Investigations for Medical Devices" guidance emphasizes that randomization reduces selection bias and supports valid statistical inference. However, RCTs are not always feasible or ethically justified. In such cases, FDA may accept non-randomized concurrent comparisons, historical controls, or subject-as-own-control designs, provided the bias risks are addressed.
For a QA VP, the critical question is not whether the design is ideal but whether the design is justified in the clinical evidence strategy. The strategy document should explain why a particular design was chosen, what biases were considered, and how the design connects to the risks identified in the risk management file. For example, if a device introduces a new energy source, an RCT comparing the new device to the standard of care may be the only acceptable way to estimate the probability of serious adverse events. Conversely, if the device is a mechanical iteration of an established design with a well-understood safety profile, a single-arm study with an OPC may be the least burdensome path.
Single-arm studies compare the device to a pre-specified performance goal or objective performance criterion (OPC), rather than to a concurrent control group. OPCs are particularly common in areas where the clinical standard is well established, such as heart valves, endometrial ablation, and certain orthopedic and cardiovascular devices. The advantage is efficiency: fewer subjects, shorter timelines, and lower cost. The risk is that the OPC may not reflect current clinical practice or the specific patient population being studied.
Under the least burdensome provisions, FDA encourages the use of OPCs and historical controls when they provide valid scientific evidence. The clinical evidence strategy must document how the OPC was derived, what studies or registries support it, and why it is applicable to the subject device. An investigator reviewing the strategy should be able to verify that the OPC is not an arbitrary target but a clinically meaningful benchmark grounded in real-world data. The strategy should also address how the OPC will be maintained over time as clinical practice evolves.
Adaptive designs allow pre-specified modifications to the trial based on accumulating data without undermining the trial's validity. Bayesian designs incorporate prior information, such as predicate data or historical controls, into the analysis. Both are explicitly recognized by FDA as potentially least burdensome approaches when properly pre-specified and controlled for Type I error.
For QA leadership, the governance challenge is ensuring that the adaptive or Bayesian design is locked in the clinical investigation plan before the first subject is enrolled. Post-hoc modifications, even if statistically defensible, create inspection risk because they undermine the pre-specification requirement that FDA relies on for evidentiary integrity. The strategy should also define the stopping rules, the independent oversight committee (DMC or CEC) responsibilities, and the process for communicating interim results without unblinding the study.
FDA's guidance on the use of real-world evidence (RWE) to support regulatory decision-making recognizes that data from electronic health records, registries, claims databases, and other sources can constitute valid scientific evidence when the data are relevant, reliable, and of sufficient quality. For post-market surveillance, registries are a primary mechanism for collecting long-term safety and performance data.
The clinical evidence strategy must define how RWE fits into the evidentiary hierarchy. Is it primary evidence for a labeling expansion? Is it confirmatory safety data for a PMA post-approval study? Is it a source of post-market surveillance inputs for the risk management file? Each role requires different data quality controls, endpoint definitions, and analytical methods. The strategy should also document how RWE sources are validated, how data provenance is maintained, and how confounding and selection bias are addressed.
Early feasibility studies (EFS) are small clinical investigations designed to evaluate device design concepts, refine the device or procedure, and gather initial safety and performance information before a larger pivotal study. FDA's EFS program is intended to accelerate device development by allowing earlier human evaluation. The clinical evidence strategy should define the role of EFS data in the overall evidentiary package and how EFS findings inform the pivotal study design, endpoints, and patient selection criteria.
Clinical outcome endpoints measure how a patient feels, functions, or survives. They are the most persuasive endpoints because they directly address the device's intended use. Examples include mortality, myocardial infarction, stroke, amputation-free survival, pain scores, functional status, and quality-of-life measures.
The challenge with clinical outcome endpoints is that they often require larger, longer, and more expensive studies. For a QA VP, the strategic question is whether the endpoint is clinically meaningful to patients and regulators, and whether it is measured with a validated instrument. An endpoint that is clinically meaningful but poorly measured will not withstand inspectional scrutiny. The strategy should specify the endpoint definition, the measurement instrument, the timing of assessment, the handling of missing data, and the clinical significance threshold.
Surrogate endpoints are biomarkers or intermediate outcomes that are expected to predict clinical benefit. They are acceptable when the relationship between the surrogate and the clinical outcome is well established. FDA may accept surrogate endpoints under the least burdensome provisions when a clinical outcome study would be impractical.
The clinical evidence strategy must provide the scientific rationale for any surrogate endpoint. This rationale should include evidence from prior studies or mechanistic understanding that the surrogate predicts clinical benefit; the strength of the surrogate-disease relationship; the proposed analytical plan for demonstrating that the surrogate effect translates into clinical benefit; and a plan for post-market verification, if required.
Performance endpoints measure whether the device performs as intended under clinical conditions. They are common in diagnostic devices, surgical instruments, and devices where the mechanism of action is mechanical or electrical. Examples include accuracy, sensitivity, specificity, delivery precision, deployment success, and procedural time.
For diagnostic devices, FDA's "Study Designs for Diagnostic Clinical Trials" framework distinguishes between clinical validity endpoints (does the test detect the target condition?) and clinical utility endpoints (does use of the test improve patient outcomes?). The clinical evidence strategy must specify which type of endpoint is being used and why. A strategy that relies on analytical performance alone for a diagnostic device may be insufficient if the device makes claims about clinical management.
Composite endpoints combine multiple clinical events into a single endpoint. They can increase statistical power and capture the totality of device effect, but they can also obscure the effect on individual components. FDA recommends that composite endpoints be composed of components that are clinically similar in importance and that the analytical plan include component-specific analyses.
Multi-domain assessments, such as patient-reported outcome measures (PROMs), may combine symptoms, function, and quality of life into a single score. The clinical evidence strategy must document the psychometric validation of any instrument used, including evidence of reliability, validity, responsiveness, and interpretability in the target population. Instruments must be linguistically validated if used in multinational studies.
ISO 14155:2026 incorporates the estimand framework from ICH E9(R1). An estimand is a precise description of the treatment effect reflecting the clinical question of interest. It includes the population, the treatment variable of interest, the clinical outcome, the handling of intercurrent events, and the population-level summary. For device trials, common intercurrent events include device malfunction, crossover to rescue therapy, and discontinuation due to adverse events.
The QA VP should ensure that the clinical evidence strategy defines the estimand for each primary endpoint and that the statistical analysis plan is aligned with the estimand. Pre-specification is critical: an investigator who finds that the estimand was defined after database lock will question the integrity of the analysis.
The 510(k) pathway requires a demonstration that a new device is substantially equivalent (SE) to a legally marketed predicate device. Substantial equivalence is defined in section 513(i) of the FD&C Act: the new device must have the same intended use as the predicate and either the same technological characteristics or different technological characteristics that do not raise different questions of safety and effectiveness and for which the device is shown to be as safe and as effective as the predicate.
FDA's "The 510(k) Program: Evaluating Substantial Equivalence in Premarket Notifications" guidance describes a decision-making flowchart that investigators and reviewers use. The QA VP should ensure that the clinical evidence strategy includes a structured substantial equivalence discussion that addresses predicate identification and justification; comparison of intended use and indications for use; comparison of technological characteristics (materials, design, energy source, software, manufacturing); performance data supporting equivalence (bench, animal, clinical); and discussion of any differences and why they do not affect safety or effectiveness.
FDA's "Recommendations for the Use of Clinical Data in 510(k) Submissions" guidance identifies situations where clinical data may be needed to demonstrate substantial equivalence, including new indications for use; different technological characteristics that raise new questions of safety or effectiveness; changes to a marketed device that affect clinical performance; and predicates for which clinical performance is the primary basis of equivalence.
The clinical evidence strategy must identify any situation that triggers the need for clinical data and document the rationale for the chosen evidence source. If a 510(k) relies on a split predicate, the strategy must explain how data from multiple predicates are integrated to support equivalence. The strategy should also address the "necessary" standard in section 513(i)(1)(D) of the FD&C Act, which requires FDA to request only the minimum information necessary to make a substantial equivalence determination.
For devices that are low to moderate risk but have no predicate, the De Novo pathway allows FDA to establish a new classification regulation. De Novo submissions require sufficient evidence to establish that the device is safe and effective for its intended use and that general controls are adequate to assure safety and effectiveness. The clinical evidence strategy for a De Novo device must demonstrate that the general controls, including performance standards and special controls, are sufficient and that the clinical data support the proposed indications and labeling.
PMA submissions require a demonstration of reasonable assurance of safety and effectiveness based on valid scientific evidence. Under 21 CFR 814.20, the PMA application must include the results of clinical investigations, unless FDA permits a waiver. The clinical evidence strategy for a PMA must address the totality of the evidence, including non-clinical testing, clinical trials, and any real-world data, and must demonstrate that the benefits outweigh the risks for the target population.
CP 7382.850 organizes inspections into six QMS areas. Clinical evidence strategy intersects with each:
The risk management file should contain, or reference, the clinical evidence strategy and the specific evidence that supports each risk control. A best-practice approach is to create a traceability matrix with the following columns:
This matrix allows an investigator to start with a risk, follow the thread through the QMS, and arrive at the evidence supporting the claim. It should be a controlled document with version history and approval signatures.
Under QMSR, FDA investigators may now review internal audit reports, management review records, and supplier audit reports. This means that candid findings in internal audits about clinical data quality, protocol deviations, or CRO oversight must be closed with documented effectiveness checks. A QA VP should ensure that the internal audit program includes audits of clinical investigation processes, data management, and the integration of clinical evidence into the risk management file.
Data integrity is the foundation of any clinical evidence strategy. FDA expects clinical investigation data to adhere to ALCOA+ principles: attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available. These principles apply to electronic data capture systems, source documents, case report forms, and the audit trails that link them.
The clinical evidence strategy should define the data governance framework, including:
Device accountability is a device-specific data integrity requirement. Unlike pharmaceuticals, medical devices must be tracked by serial number, lot number, and physical condition. The strategy should specify how investigational devices are received, stored, used, returned, and reconciled at each site, and how device deficiencies are documented and reported.
Under the QMSR lifecycle orientation, clinical evidence does not end at market authorization. The clinical evidence strategy must include a plan for post-market clinical follow-up (PMCF), particularly for devices with long-term risks, novel technologies, or limited pre-market clinical data. PMCF activities may include registry studies, surveys, chart reviews, and targeted clinical investigations.
The strategy should define how PMCF data will be evaluated for impact on the risk management file, labeling, and instructions for use. It should also define thresholds that trigger escalation, such as a statistically significant increase in adverse event rates, new signals not identified in pre-market studies, or emerging comparator data that affect the benefit-risk profile.
Based on FDA inspection observations, warning letters, and the OAI criteria in CP 7382.850, the following pitfalls are most likely to generate findings:
To operationalize this deep dive, the QA VP should lead the following initiatives:
A clinical evidence strategy that is current on the day of submission can become outdated within months. New FDA guidance documents, updated consensus standards, predicate modifications, competitor product recalls, and emerging clinical literature can all change the risk landscape. The QA VP should establish a regulatory intelligence process that monitors these inputs and triggers updates to the clinical evidence strategy when warranted.
Key intelligence sources include the Federal Register for final rules and proposed rules; FDA guidance documents and draft guidances; FDA advisory panel meeting materials; ISO/TC 194 and ISO/TC 210 updates for risk management and QMS standards; ISO/TC 215 and ICH updates for clinical investigation methodology; MDCG guidance for EU MDR-aligned clinical investigation practices; FDA warning letters and inspection observations; and peer-reviewed clinical literature in the device's therapeutic area.
The regulatory intelligence process should produce a periodic summary for management review. When a new guidance or standard affects the clinical evidence strategy, the summary should identify the specific sections of the strategy that need revision, the responsible owner, and the deadline for completion. This creates a defensible record that the organization proactively monitors and adapts its evidence base.
For combination products, the intelligence process must cover both device and drug or biologic regulatory developments. A device constituent that incorporates a drug delivery mechanism may require evidence strategies that satisfy both ISO 14155 and ICH E6(R3), and changes to either standard can affect the clinical investigation plan.
Finally, the QA VP should ensure that the regulatory intelligence process is itself audited. An intelligence process that exists only in email threads or ad-hoc meetings will not survive an inspection. Documented procedures, scheduled reviews, and action logs transform regulatory awareness into a QMS process.
The convergence of QMSR, ISO 13485:2016, and risk-based inspections will continue to elevate the importance of clinical evidence strategy. Emerging trends include the use of artificial intelligence and machine learning for clinical data analysis, decentralized clinical trials, digital health technologies as endpoints, and patient-generated health data. The QA VP should ensure that the QMS is agile enough to incorporate these evidence sources while maintaining the traceability, risk-anchoring, and inspection-readiness principles described in this deep dive. Organizations that treat clinical evidence strategy as a core QMS function, rather than a regulatory submission chore, will be best positioned to succeed in the QMSR era.
A manufacturer of a Class II powered surgical instrument planned a 510(k) submission using a predicate device that had been on the market for eight years. During the design phase, the engineering team changed the battery chemistry to improve run time. The change was considered minor from a design perspective, but it altered the energy source — a technological characteristic that can raise different questions of safety and effectiveness under the 510(k) decision framework.
The clinical evidence strategy initially relied solely on bench testing and predicate equivalence. A cross-functional review identified that the battery change introduced new thermal hazard and electrical failure modes. The strategy was revised to include a clinical performance study measuring device activation time, tissue effect consistency, and adverse event rates in a simulated-use cohort. The study endpoints were mapped to the updated risk management file. The 510(k) was cleared because the clinical data directly addressed the new risk questions raised by the technological change.
A manufacturer of a novel Class III implant submitted a PMA based on a pivotal RCT with a one-year primary endpoint. FDA approved the device with a post-approval study requirement to evaluate five-year durability. The manufacturer's clinical evidence strategy included a registry to collect long-term data. However, the registry was managed by marketing as a commercial support tool, not by QA as a post-market surveillance input.
During a QMSR inspection, the investigator traced a durability-related complaint trend to the registry data and asked why the data had not been used to update the risk management file. The manufacturer could not demonstrate a closed-loop process. The finding was classified as a Situation 1 risk management failure because the post-market data had not been used as an input into risk management for monitoring and maintaining product realization. The remediation required restructuring the registry under QMS controls, formalizing data review procedures, and updating the risk file.
A Software as a Medical Device (SaMD) developer sought De Novo classification for an algorithm that analyzed electronic health record data to predict patient deterioration. The clinical evidence strategy combined a retrospective validation study using real-world data and a prospective clinical utility study. The retrospective study established analytical validity, while the prospective study measured whether clinicians acted on the algorithm's alerts and whether patient outcomes improved.
The strategy explicitly defined the data provenance, inclusion and exclusion criteria, and confounding adjustment methods for the real-world data component. It also pre-specified the estimand for the clinical utility endpoint. The De Novo request was granted, and the QMSR inspection focused on whether the post-market monitoring plan continued to validate algorithm performance against the real-world data baseline.
The QA VP is uniquely positioned to ensure that clinical evidence strategy is inspection-ready. This requires:
Under CP 7382.850, investigators are trained to use critical thinking and follow risk signals, not to work through standardized checklists. A QA VP who can articulate the clinical evidence strategy in risk-based terms will reduce inspection friction and demonstrate that the organization operates as an integrated quality system.
Our consulting engagements provide personalized, exhaustive analysis tailored to your specific challenges.
Get in Touch