The Workbench · Craft
What a complaint record has to decide before it becomes a CAPA
A complaint arrives as a phone call, a returned unit, an email with a photo attached. Most complaint-handling procedures treat everything that follows as one continuous step: log it, investigate it, close it. ISO 13485:2016 Clause 8.2.2 splits that step into two separate decisions, and FDA's Quality Management System Regulation — in force since February 2, 2026 — made the record for the second one explicit rather than implied. Every complaint record has to answer two questions that don't have the same answer by default: does this communication actually meet the standard's definition of a complaint, and does it clear the separate, stricter bar for reporting to FDA under 21 CFR Part 803. A log built to answer only the first one is missing the question an inspector asks first.
The two questions get conflated because they arrive on the same intake form and often get answered by the same person in the same sitting. Treating them as one decision is how a log ends up either padded with non-complaints that dilute a trend review, or missing the reportability call that should have started a 30-day clock the day the information came in.
A complaint is not a service call
ISO 13485:2016 Clause 3.4 defines a complaint narrowly, on purpose: a written, electronic or oral communication that alleges deficiencies related to the identity, quality, durability, reliability, usability, safety or performance of a device already released from the organization's control, or related to a service that affects the performance of such a device. A call asking how to reorder a part, or reporting a shipment arrived a day late, doesn't clear that bar. A working intake process makes the complaint/not-complaint call explicitly, at the point of contact, instead of routing every inbound message into the complaint file because that looks like the safer default — a log padded with non-complaints buries the signal a trend review exists to find just as effectively as a log that under-captures.
The second question runs on its own clock
Once a communication clears the Clause 3.4 bar, it inherits an independent test under 21 CFR Part 803: does it describe an event where the device may have caused or contributed to a death or serious injury, or a malfunction that would be likely to cause or contribute to one if it recurred. A standard Medical Device Report is due no later than 30 calendar days after the manufacturer becomes aware of a reportable event (21 CFR 803.50); a narrower category requiring remedial action to prevent an unreasonable risk of substantial harm is due within 5 work days under 803.53. Both clocks start at awareness of the reportable information — not at the close of the investigation that eventually confirms it. A tracker whose only reportability check happens at closeout is dating the clock weeks late.
What the QMSR made explicit
Complaint handling has run through Clause 8.2.2 since the QMSR replaced most of Part 820 with a pointer to ISO 13485. FDA retained one section of the old regulation as a US-specific supplement on top of the standard: 21 CFR 820.35, control of records, now spells out content requirements for complaint records that Clause 8.2.2 leaves to the organization's own procedure — including a specific rule for when an investigation isn't required. If an investigation has already been performed for a similar complaint, another one isn't necessary, but the manufacturer has to maintain a record documenting the justification for not investigating. That justification is easy to skip and easy to audit for; a log with a run of entries reading closed, similar to prior complaint and no linked justification record is showing exactly the gap 820.35 was written to close.
Where the complaint record hands off
A complaint that clears the reportability test doesn't end its own life there — it typically opens a corrective action, and from that point forward it's the trigger event a CAPA tracker has to track, not a complaint record anymore. That handoff is one of the places a tracker's aging clock is most often set wrong, when teams start counting from the day the CAPA was opened instead of the date the complaint first surfaced the problem. It's also worth noting: the same QMSR renumbering that retired 21 CFR 820.100 moved the complaint-record content requirements out of their old home at 820.198. A procedure that still cites 820.198 by name is a small, checkable sign nobody has rebuilt it since before this February.
A complaint log built around these distinctions — the Clause 3.4 gate, the independent 803 reportability test, and the 820.35 investigation-justification field — is previewed in the launch catalog. If your team's version catches a failure mode this one doesn't, the shelf takes that kind of correction directly.
The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.