· MEDICAL DEVICE QUALITY

Complaint Handling & Device Vigilance

Once a device is on the market, the quality system’s centre of gravity shifts to the feedback loop: capturing what users report, deciding what must be told to regulators, and feeding both back into risk management and design. Complaint handling, vigilance reporting, and post-market surveillance are three linked but distinct obligations, and confusing them is a recurring source of inspection findings — most often under-reporting, where a real reportable event was mishandled as an ordinary complaint. This page separates the three decisions and the timelines that hang on them. The wider device quality system they serve is covered in the [Medical Device Quality System](/topics/medical-device-quality) explainer; ISO 13485, 21 CFR Part 803, and the EU MDR define the requirements.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 20 LINKS

A complaint, a reportable vigilance event, and a field action are three distinct decisions a device quality system must keep separate; under-reporting, where a reportable event is filed as an ordinary complaint, is the classic finding.

06 · QUALITY MATURITY — COMPLAINT HANDLING & DEVICE VIGILANCE, REACTIVE TO ADAPTIVE

L1
Reactive

Complaints are filtered at the front desk as 'user error'; reportability is decided ad hoc and under-reporting goes unnoticed.

L2
Defined

A complaint process captures and closes complaints, but they are never trended into CAPA and reportability rationales go unrecorded.

L3
Controlled

Every complaint is evaluated; the reportability decision is documented and defensible for each, including negatives, and the clocks are tracked.

L4
Predictive

Complaints, vigilance events, and field data trend into the ISO 14971 risk file and drive design changes before a regulator asks.

L5
Adaptive

Proactive planned post-market surveillance finds the signal ahead of complaints; the feedback loop genuinely re-enters risk management and design.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 3

Derived from the 3 standards SPEQ maps to this subject, across 3 regulatory bodies: ISO, EC, FDA.

RECORDS & OBJECTIVE EVIDENCE

  • A complaint file capturing every communication, with evaluation and investigation
  • Documented, defensible reportability decisions for each complaint, including negatives
  • Vigilance reports (MDR / serious-incident) filed within the statutory timelines
  • Field Safety Corrective Action and Field Safety Notice records where applicable
  • A post-market surveillance plan with PSUR/PMS reports feeding the risk file

COMMON INSPECTION FINDINGS

  • Reportable event mishandled as an ordinary complaint (under-reporting)
  • Reportability decisions with no recorded rationale
  • Complaints closed without evaluating reportability
  • Complaint trends never driving CAPA or design change
  • MDR 30-day or 5-day reporting timelines missed
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

Complaint handling: the closed loop that must not leak

A **complaint** in the regulatory sense is broad: any communication — written, electronic, or oral — alleging deficiencies in the identity, quality, durability, reliability, safety, effectiveness, or performance of a device after it has been released for distribution. That breadth is deliberate, because the complaint file is the manufacturer’s primary early-warning system for problems the design and testing did not anticipate. ISO 13485 requires a defined process to receive, record, evaluate, and investigate complaints, and the defining property of a good one is that nothing leaks: every complaint is captured and evaluated, not filtered out at the front desk as "user error" before it is assessed.

The loop runs capture → evaluate → investigate → act. Evaluation decides whether the complaint needs investigation and — critically — whether it is *reportable* to a regulator. Investigation establishes what happened and why, to a real root cause. Action feeds CAPA, where a pattern of complaints becomes a corrective or preventive change, and, where the design is implicated, a design change through change control. A complaint system that records and closes complaints but never trends them or drives CAPA is logging problems rather than learning from them — and for devices, complaint handling and CAPA are consistently among the most-cited inspection areas precisely because this loop is where quality systems visibly succeed or fail.

The reportability decision — where under-reporting is born

Not every complaint is reportable, and the decision about which ones are is the single most scrutinised judgement in device post-market. In the United States, **Medical Device Reporting (21 CFR Part 803)** requires manufacturers to report events where a device may have caused or contributed to a **death or serious injury**, and certain **malfunctions** that would be likely to cause or contribute to a death or serious injury if they recurred. The standard manufacturer report is due within **30 calendar days** of becoming aware of the event, with an expedited **5-working-day** report for events that require remedial action to prevent an unreasonable risk of substantial harm.

The European framework under the **EU MDR (Regulation 2017/745)** works on the same principle with its own vocabulary: manufacturers report **serious incidents** and **Field Safety Corrective Actions** to the competent authorities, on tiered timelines that shorten sharply for serious public-health threats and deaths, submitted through the EUDAMED system. The near-universal failure mode across both regimes is **under-reporting** — treating a reportable event as an ordinary complaint, or interpreting "serious injury" and "malfunction" too narrowly to avoid a report. Because the reportability decision is a judgement, regulators expect it to be *documented and defensible* for every complaint, including the ones judged not reportable: a decision with no recorded rationale is the finding waiting to happen.

Three different things: a complaint, a vigilance report, a field action

Keeping the vocabulary straight is not pedantry — the three describe escalating, distinct obligations. A **complaint** is customer-facing quality feedback the manufacturer must handle internally. A **vigilance report** (an MDR in the US, a serious-incident report under EU MDR) is an external regulatory notification triggered when a complaint meets the reportability threshold. A **field action** — a recall, a **Field Safety Corrective Action (FSCA)**, or a Field Safety Notice to users — is a step taken to reduce a risk presented by devices already distributed, such as a correction, a software update, or a removal from the market.

One event can travel the whole chain: a complaint is received, judged reportable and filed as a vigilance report, and — if the investigation shows a fleet-wide risk — triggers an FSCA communicated to every affected user. But the three are decided separately and on different criteria, and collapsing them causes real errors: assuming a reportable event automatically means a recall (paralysing the reporting decision), or assuming that because no field action is planned nothing needs reporting (the under-reporting trap again). The disciplined manufacturer runs each decision on its own merits and documents the basis for each.

From reactive complaints to proactive post-market surveillance

Complaint handling and vigilance are largely *reactive* — they respond to events that reach the manufacturer. The EU MDR’s most significant post-market change was to require surveillance that is also *proactive* and *planned*: a documented **post-market surveillance (PMS) plan** for every device, actively gathering and analysing real-world performance and safety data across the device’s life rather than waiting for complaints to arrive. Its outputs are structured reports — a **PSUR** (periodic safety update report) for higher-risk devices or a PMS report for lower-risk ones — and, where clinical evidence must be kept current, **post-market clinical follow-up (PMCF)**.

The point of making surveillance proactive is that it closes the loop back to where device safety is actually determined: the PMS findings feed the **ISO 14971 risk management** file — updating the real-world probability and severity of harms against the assumptions made at design — and, when the evidence warrants, drive design changes and updates to the clinical evaluation. A device quality system is ultimately judged on whether this loop is live: whether complaints, vigilance events, and surveillance data genuinely re-enter risk management and design, or merely accumulate in files. Reactive handling catches the events that come to you; proactive surveillance is how you find the signal before it becomes a vigilance report.

FREQUENTLY ASKED

What counts as a complaint for a medical device?

Any communication — written, electronic, or oral — alleging deficiencies in the identity, quality, durability, reliability, safety, effectiveness, or performance of a device after it has been released for distribution. The definition is deliberately broad because the complaint file is the manufacturer’s primary early-warning system, and ISO 13485 requires a defined process to receive, record, evaluate, and investigate every one — not to filter them out as "user error" before assessment.

Is every complaint reportable to a regulator?

No — and deciding which are is the most scrutinised judgement in device post-market. Under US Medical Device Reporting (21 CFR Part 803), reportable events are those where a device may have caused or contributed to a death or serious injury, plus certain malfunctions likely to do so if they recurred; the EU MDR works the same way for serious incidents. The reportability decision must be documented and defensible for every complaint, including those judged not reportable — under-reporting is the classic finding.

What are the US MDR reporting timelines?

Under 21 CFR Part 803, the standard manufacturer report is due within 30 calendar days of becoming aware of a reportable death, serious injury, or qualifying malfunction, with an expedited 5-working-day report for events that require remedial action to prevent an unreasonable risk of substantial harm. The EU MDR uses its own tiered timelines that shorten for deaths and serious public-health threats, submitted through EUDAMED.

What is the difference between a vigilance report and a field safety corrective action?

A vigilance report (an MDR in the US, a serious-incident report under EU MDR) is a regulatory notification triggered when a complaint meets the reportability threshold. A Field Safety Corrective Action (FSCA) — such as a recall, correction, software update, or Field Safety Notice — is a step taken to reduce risk from devices already distributed. One event can trigger both, but they are decided separately: a reportable event does not automatically mean a recall, and the absence of a field action does not remove the duty to report.

What did the EU MDR change about post-market surveillance?

It made surveillance proactive and planned rather than purely reactive. Every device needs a documented post-market surveillance (PMS) plan that actively gathers and analyses real-world performance and safety data, producing structured reports (a PSUR for higher-risk devices, a PMS report for lower-risk ones) and, where needed, post-market clinical follow-up. The findings feed back into the ISO 14971 risk file and, when warranted, drive design changes — closing the loop to where device safety is actually determined.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…