Design Control Under the FDA Device Quality System: Requirements and Common Inspection Citations
Design control is among the most scrutinized elements of FDA's device quality system regulation. For regulatory, quality, and engineering teams, gaps in design control documentation carry real consequences: repeated 483 observations, warning letters, and, in severe cases, consent decrees that can halt product development and commercialization.
The analysis below examines what design control requires under 21 CFR Part 820 and the incorporated ISO 13485 framework, how the requirement applies across device classes, and which specific deficiencies FDA investigators most frequently cite during inspections of design and development activities.
Want to ask Rhizome your own regulatory questions? Try it for free.
Design control under the FDA device quality system: what it is, and what inspections actually cite
Design control is the part of a medical device manufacturer's quality system that governs how a device is designed and developed, so that the finished product provably meets defined user needs and intended uses. It is where a firm turns clinical and user requirements into engineering specifications, proves the resulting design does what the requirements demand, and preserves the evidence trail. For most device makers it is also one of the most frequently cited areas in FDA inspections, because the requirement is documentation-heavy and unforgiving: if an activity was not written down, reviewed, and approved, FDA treats it as not done.
Where design control sits in the quality system
Design control lives inside 21 CFR Part 820. As of the amended Part 820 (the Quality Management System Regulation, or QMSR), a manufacturer must document a quality management system that complies with ISO 13485 together with the remaining FDA-specific requirements of Part 820 213. Part 820 applies to all finished devices intended for human use that are manufactured in the United States or imported into it, and to certain HCT/Ps that are devices; it does not reach makers of components or of blood and blood components 227. ISO 13485 is expressly incorporated by reference 227.
Design and development is not optional for most products. Section 820.10(c) requires manufacturers of class II devices, class III devices, and certain class I devices to comply with ISO 13485 clause 7.3 (design and development) and its subclauses 213. Under the predecessor Quality System Regulation, the same discipline was codified as the standalone design controls section at 21 CFR 820.30, and that is the framing that appears throughout the enforcement record: the warning letters and Form 483 observations reviewed here cite the 820.30 design control elements directly 74798328. The two frameworks describe the same activities, and a firm that satisfied 820.30 is substantially aligned with the design and development expectations FDA now reads through ISO 13485.
The elements of design control
Whether expressed as the 820.30 subparts or as ISO 13485 clause 7.3, design control breaks into a consistent set of linked activities. Each one is a distinct, separately citable requirement.
Design and development planning. A written plan that describes the design activities, defines responsibilities, and identifies the interfaces between the groups that contribute to the design. Firms are cited when no plan exists or when the design cannot be shown to have been developed under an approved plan 791487.
Design input. The physical, performance, safety, and user requirements the device must meet, documented and approved, with a mechanism to resolve incomplete, ambiguous, or conflicting requirements. Inputs must be defined specifically enough to be objectively verified later 945052.
Design output. The design results at each phase, including drawings, specifications, labeling, and work instructions, expressed against acceptance criteria so they can be checked against the inputs. Outputs must identify the records essential to the device's proper functioning 98109.
Design review. Formal, documented reviews at appropriate stages, with participants that include representatives of all functions concerned with the stage being reviewed plus at least one individual without direct responsibility for that stage. Results, the design reviewed, the date, and the reviewers must be recorded 74102.
Design verification. Objective evidence, generated against a pre-established protocol and acceptance criteria, that the design output meets the design input. This is the "did we build the device right" check 1127.
Design validation. Evidence, produced on initial production units, lots, or batches under actual or simulated use conditions, that the device conforms to defined user needs and intended uses. Validation must include risk analysis. This is the "did we build the right device" check 1122536.
Design transfer. Procedures ensuring the design is correctly translated into production specifications, so that what is manufactured matches the approved, validated design 92.
Design changes. Identification, documentation, verification or validation as appropriate, review, and approval of design changes before they are implemented 764043.
Design history file (DHF). The compilation of records demonstrating the design was developed in accordance with the approved plan and the design control requirements 808710.
What FDA inspections actually cite
Across warning letters and Form 483 observations, the deficiencies cluster into a recognizable set of failure modes. The pattern holds from very small firms with no design system at all to large, sophisticated manufacturers whose individual activities were technically deficient.
No design control system, or procedures that only restate the rule
The most basic citation is the absence of any design control procedures. Staff at William C. Domb told investigators the firm had no design control procedures and had not established any design control activities 93. Quantum Skincare had no written design control procedures for its device and no DHF 85. Jade & Pearl had no procedures for inputs, outputs, reviews, verification, validation, transfer, or changes, and no DHFs 84. Spinal Solutions had not defined or implemented the core elements at all, including the plan, DHF, inputs and outputs, review, verification, validation, risk analysis, and transfer 28.
A related, subtler citation targets procedures that exist on paper but carry no content. FDA criticized Biosafe's design procedure as merely a reproduction of 21 CFR 820.30, lacking any detail or specificity to the firm's own operations 92.
Design inputs that are incomplete, ambiguous, or unverifiable
Firms are repeatedly cited for inputs that cannot be objectively verified. At Zimmer Biomet, requirements such as "must be able to withstand anticipated loads" and "adequate femoral strength" were not defined in a verifiable way, and the DHF lacked objective evidence that updated inputs were approved before commercial release 5052. Bausch and Lomb had incomplete design input requirements that were not addressed, with several inputs still open when the product was brought to market 59. At St. Jude Medical, cybersecurity risk assessments did not capture all known risks, so appropriate design inputs for the system were never implemented 53. Other firms failed to document the initial design input and its approval at all 94, or omitted input requirements for entire products 105.
Design outputs and design review not documented
Output failures typically show up as a DHF that does not identify the essential outputs. One firm's DHF did not identify complete labeling, work instructions, drawings, or material specifications as outputs 98; another listed parts on a bill of materials without documenting outputs that met predetermined acceptance criteria 109.
Design review is cited both for not happening and for happening wrong. Levitronix was cited because its design review did not ensure participants included all concerned functions plus an individual not directly responsible for the stage being reviewed 74. At Zimmer Biomet, the first design review occurred before the design inputs had been fully established, so it could not serve as an adequate basis for approval, and there was no evidence that implants other than the PS femoral components were reviewed and approved at that review 4952. Bausch and Lomb did not perform reviews at the scheduled times 59. Torbot never conducted or documented a formal design review 79.
Verification and validation: the largest cluster
Verification and validation deficiencies dominate the enforcement record, and the citations are specific.
On verification, FDA cites firms for testing without a pre-established protocol. Sometech's only verification "activity" for the LVT100 was a document dated after the work was done, and FDA noted no protocol had been established before verification began 112. Gynetics' procedure did not ensure acceptance criteria were set before verification 114. Medart's verification report contained no actual results or conclusion 115. Optovue's records had sections not performed, unsigned entries, missing raw data, and pass results with no supporting data 119. In one striking case at Hill-Rom, a verification script was not executed as written, and there was no documentation that management evaluated the deviation or its effect on whether outputs met inputs 23. Advanced Medical Optics ran verification under best-case conditions, using lots with preservative at the top of the specification, which undercut the test's ability to challenge the design 29.
On validation, the recurring themes are testing on the wrong units and failing to demonstrate conformance to user needs. Terumo validated a design using recalled devices in simulated perfusion cases rather than production units or equivalents 27. Bedfont validated its ToxCO on units that were not initial production units and on a firmware version prior to the one actually implemented 120. Meridian Medical Technologies performed no validation on initial production units, did not validate the user interface, and did not update the risk analysis for the EpiPen product line 32. Utah Medical Products lacked real-time shelf-life testing to confirm accelerated-aging results supporting a five-year expiration claim 41. Philips Respironics' design validation, health hazard evaluation, and biological risk assessment did not ensure the Trilogy devices conformed to defined user needs and intended uses 36. Zimmer Biomet's DHF held validation items that did not provide objective evidence the device conformed to user needs and intended uses 25. Allez Spine's sterilization parameters in the instructions for use were never validated during design or before commercial distribution, and later post-market work recommended different parameters 122.
Design change control
Changes made without verification, validation, or review recur across firms of every size. Stryker Medical released a design change into production without verification testing 30. PhotoMedex changed its liquid light guide assemblies without validation or verification and offered no justification for concluding they were unnecessary 31. Magellan Diagnostics changed the LeadCare II labeling and incubation time but documented that the change required no validation or verification and did not consider whether the risk documentation needed updating, despite the change affecting form, fit, and function 40. Philips Respironics changed preventive maintenance schedules and servicing procedures for Trilogy ventilators without adequately verifying, reviewing, or validating them first 36. Agile Radiological Technologies pushed four version updates and five service packs to its software without documenting development, verification, validation, or approval 83. Light-Tech switched from halogen bulbs to LED illuminators with no design change procedure covering the change, its labeling, or its risk analysis 88.
Design transfer
Transfer citations turn on a mismatch between the approved design and what is actually built. One firm's Device Master Record still held the old base-frame specifications after the design had been changed 3. Another company distributed its Tango3 system without ever transferring it from design to production 9. A third could not show that production assembly drawings for a redesigned device matched the approved outputs, and the drawings lacked revision dates and approval signatures 2.
Risk analysis as part of validation
Because validation must incorporate risk analysis, weak or absent risk analysis is a frequent companion citation. Water and Power Technologies had no method to identify, analyze, control, and document risks for its water purification systems 14. A knee implant system's risk analysis did not identify all hazards, did not quantify severity or probability, and did not address controls for manufacturing steps such as laser etching, polishing, and sterilization 6. A face mask firm's risk analysis incorrectly treated a non-sterile device as sterile and credited sterilization as a risk-reduction measure 7. A multi-drug cup test's risk analysis failed to consider cross-interference and lacked author and approval signatures and a date 15.
Design history file
DHF citations are the connective tissue of the enforcement record, because a missing or incomplete DHF is how most of the above deficiencies become visible. Firms are cited for having no DHF at all 808519, for DHFs that do not show the device was developed under the approved plan 1187, and for DHFs missing specific records such as design review results, transfer records, or verification evidence 1097. Teamedics told investigators it discarded documents after two years, leaving the investigator no design documentation to review 80.
The through-line
The consistent lesson from the enforcement record is procedural, not scientific. FDA rarely argues that a device is unsafe on its face; it argues that the manufacturer cannot prove the device was designed under control. The most common failures are not exotic: no protocol established before testing 112, acceptance criteria set after the fact or not at all 114115, validation run on the wrong units 27120, changes implemented without verification 3031, and a DHF that cannot demonstrate the design was developed as planned 1180. Under the QMSR's ISO 13485 clause 7.3 framing, these obligations carry forward essentially unchanged, so the same discipline that satisfied 820.30 is what will satisfy an inspection today.