FDA QMSR Warning Letters Focus on Risk and Design Changes
Two early FDA Warning Letters from post-effective QMSR inspections directly cite incorporated ISO 13485:2016 clauses. The cases connect risk management to design changes, intended use, suppliers, complaints, rework, CAPA, environmental controls, and software validation—and give manufacturers a concrete evidence map for inspection readiness.
The US Food and Drug Administration (FDA) has published two device Warning Letters based on inspections that began on or after the date the Quality Management System Regulation (QMSR) took effect on February 2, 2026. The letters to Linemaster Switch Corporation and Koven Technologies, Inc. identify QMSR violations and cite requirements in ISO 13485:2016, which QMSR incorporates by reference.
These are company-specific enforcement communications, not a new rule or a generally binding interpretation. They nevertheless provide early public evidence of how FDA is applying QMSR in inspections and Warning Letters. The clearest shared point is risk management: both letters cite ISO 13485:2016 Clause 7.1, but the alleged deficiencies reach different parts of the quality system—from process risk and post-market feedback to intended-use hazards and design changes.
Read the official FDA letters to Linemaster Switch Corporation and Koven Technologies, Inc..
What FDA issued—and what the letters do not change
FDA issued the Linemaster letter on May 27, 2026, after an inspection conducted from February 4, 2026, through March 6, 2026. It issued the Koven letter on July 21, 2026, after an inspection conducted from February 2, 2026, through February 6, 2026. Both letters use the heading Quality Management System Regulation Violation(s) and state that the inspected devices were adulterated because the manufacturing methods, facilities, or controls did not conform to QMSR current good manufacturing practice requirements.
A Warning Letter communicates FDA's position that it has identified significant violations and gives the recipient an opportunity to respond. The cited observations are not an adjudicated finding against every manufacturer, and later interaction or a close-out letter may change the status of an individual case. The two letters also create no new QMSR effective date, transition period, remediation deadline, or inspection checklist.
The practical delta is narrower and useful: quality teams can now compare their systems with public examples in which FDA directly applied the incorporated ISO clauses during post-effective QMSR inspections.
The two QMSR letters at a glance
| FDA letter | Product context | QMSR and FDA requirements cited | Main control connections |
|---|---|---|---|
| Linemaster, CMS 730215 | Foot-pedal accessories used with medical devices, including controls for Class IV medical lasers | ISO 13485:2016 Clauses 8.3.4, 7.1, 8.5.2, 6.4.1, and 7.6 | Rework, process risk, post-market feedback, corrective action, work environment, and software validation |
| Koven, CMS 734643 | Doppler devices, including fetal-use labeling and applications | ISO 13485:2016 Clauses 7.3.9, 7.1, and 7.4.1; 21 CFR 820.35(a) | Design changes, intended use, product risk, contract manufacturers, supplier evaluation, and complaint records |
The overlap is not evidence that Clause 7.1 will appear in every inspection. It does show that a risk-management procedure standing by itself is not enough when the product, process, design, supplier, complaint, and post-market records do not connect to it.
Linemaster: risk management had to connect process and post-market evidence
FDA's Linemaster letter cites an alleged failure to document risk-management processes for product realization under ISO 13485:2016 Clause 7.1. The letter says the firm lacked a process failure mode and effects analysis for a foot-pedal accessory used to control Class IV medical lasers. It also says the risk-management procedure did not define how activities were performed and documented, who approved them, when records were updated, or how complaints, adverse events, and recalls entered the risk-management process.
The other cited findings show why that connection matters. FDA described undocumented rework, a customer corrective-action request with no recorded root cause or corrective action, inadequate environmental controls for temperature-related calibration effects, and software-validation records missing raw data, acceptance results, statistical or sample-size rationale, and verification of reliable measurement and nonconformance detection.
The lesson is not that every manufacturer needs the same document names or analysis method. Pure Global's reading is that the evidence chain must remain traceable: a known process or field signal should reach the relevant risk assessment, investigation, disposition, corrective action, validation, and effectiveness evidence. A procedure that promises this flow but cannot demonstrate it in records leaves the system exposed.
Koven: intended-use changes crossed design, risk, supplier, and complaint controls
FDA's Koven letter cites an alleged failure under ISO 13485:2016 Clause 7.3.9 to document and assess design changes associated with adding a fetal application to a Doppler device. FDA said the firm did not provide documentation of the specific changes, supporting validation, an assessment of whether a new 510(k) was required, or the date distribution began for the fetal use.
The same product change reappears in the risk-management finding. FDA said the reviewed risk files did not address fetal-specific hazards even though the relevant devices were labeled or cleared for fetal use. The letter identifies risks including thermal and acoustic exposure, diagnostic accuracy, misinterpretation, delayed care, and false reassurance. This is a direct example of a change assessment and a risk file failing to remain aligned with the intended use.
Supplier control was part of the same chain. FDA said the contract manufacturer implemented the labeling or indication change without adequate supporting documentation, while the quality agreement did not adequately govern design changes beyond labeling. FDA also cited the absence of a documented site assessment for a supplier the firm's own procedure treated as highest or critical impact.
Finally, FDA cited 21 CFR 820.35(a) because returned products reporting performance or reliability failures were not evaluated as complaints. That finding connects the post-market intake boundary back to risk management: service, return, and commercial codes cannot be allowed to hide information that meets the complaint definition.
What manufacturers should test now
The letters do not prescribe a universal remediation plan. Based on the control failures FDA described, manufacturers can perform a focused evidence test across five interfaces:
- Risk file to live quality data. Select representative complaints, adverse events, recalls, nonconformities, rework records, supplier issues, and process deviations. Confirm that the risk file was reviewed when the signal could change probability, severity, detectability, controls, or residual-risk conclusions.
- Design change to regulatory assessment. For a recent hardware, software, labeling, indication, usability, or performance change, trace approval, verification or validation, risk analysis, affected technical records, and the documented decision on whether a new submission or notification was required.
- Contract manufacturer to legal manufacturer. Test whether quality agreements, change-notification rules, supplier classification, audits, and records give the responsible manufacturer timely control over product and labeling changes.
- Return and service data to complaints. Sample return authorizations, service tickets, distributor messages, and technical-support records. Confirm that potential deficiencies in identity, quality, durability, reliability, usability, safety, or performance are evaluated through the complaint process.
- Procedure to execution evidence. Choose one promised control—rework, CAPA, environmental monitoring, or production software validation—and verify that the underlying data, acceptance criteria, approvals, investigation, disposition, and effectiveness records exist and agree.
These are Pure Global implementation recommendations derived from the two letters, not a replacement for the FDA QMSR overview, the incorporated standard, or product-specific legal advice. Scope the review to the manufacturer's devices, sites, outsourced processes, and applicable requirements.
How this fits the current FDA inspection framework
QMSR remains the governing framework that became effective on February 2, 2026. FDA also began using Compliance Program 7382.850 on that date and stopped using the Quality System Inspection Technique.
The two Warning Letters do not revise that program. They add observable enforcement examples beneath it. Together, they support a practical conclusion: inspection readiness should be tested through connected records and actual execution, not through a clause cross-reference or revised procedures alone.
For help mapping those evidence chains across risk management, design controls, suppliers, complaints, CAPA, validation, and FDA-specific requirements, see Pure Global's US FDA QMSR consulting service.
Let's Talk,
Anywhere You Are.
Whether looking for more information or ready to partner with us, we're here to guide you through every step of the regulatory process.
Contact us










