Medical device complaint file audit readiness banner showing a complaint document, checklist, compliance icons, and quality review workflow.

Medical Device Complaint File Audit Checklist: What Reviewers Expect

A closed complaint does not always mean an audit-ready complaint file.

A medical device complaint record may show a completed workflow status while still containing gaps such as missing evidence, unsupported investigation conclusions, unclear reportability rationale, or weak connections to CAPA and risk-management activities.

In an audit or inspection, it is not just the completion of the complaint process that is analyzed. It is whether or not the complaint file presents a complete, logical, and defendable account of the complaint from receipt to resolution.

A complaint file ready for auditing should be able to exhibit:

⦿ What was reported.

⦿ What information was reviewed.

⦿ How the complaint was investigated.

⦿ Why decisions were made.

⦿ What actions were taken.

⦿ Who reviewed and approved the outcome.

Complaint-file readiness should not be considered only before an audit. Continuous review helps identify gaps before they become findings.

For support reviewing complaint records, investigation adequacy, reportability decisions and downstream actions, see Medical Device Complaint Handling and Vigilance Review Services.

What Does “Audit-Ready” Mean for a Complaint File?

An audit-ready complaint file is complete, traceable, internally consistent and supported by evidence.

The purpose is not to eliminate every uncertainty. In many real-world cases, complete information may not be available. For example:

⦿ The device may not be returned.

⦿ The failure may not be reproduced.

⦿ Root cause may remain inconclusive.

⦿ Additional information may still be pending.

However, the file should clearly exhibit:

⦿ What information was available.

⦿ What evidence was reviewed.

⦿ What limitations existed.

⦿ What follow-up activities were performed.

⦿ Why the final conclusion was reasonable.

A reviewer should be able to independently understand:

⦿ What happened.

⦿ Which device was involved.

⦿ What the patient or user outcome was.

⦿ How the investigation was performed.

⦿ How reportability was assessed.

⦿ Whether similar events were considered.

⦿ Whether CAPA, risk or other actions were required.

⦿ Why the complaint was closed.

An audit-ready complaint file does not require perfect certainty. It requires a documented and defensible decision-making process.

What Should Happen Before a Complaint Is Closed?

Before closing a complaint, the organization should confirm that the file contains sufficient information to support the final conclusion.

Complaint Information Should Be Complete

The complaint record should include relevant information such as:

⦿ Complaint reference number.

⦿ Reporter details.

⦿ Date the event occurred.

⦿ Date the complaint was received.

⦿ Awareness date.

⦿ Device name and identification.

⦿ Model or catalog number.

⦿ Lot, batch or serial number.

⦿ Software version, where applicable.

⦿ Market and device configuration.

⦿ Patient or user outcome.

⦿ Description of the reported issue.

⦿ Use environment.

Missing information does not automatically prevent closure. However, the file should show that reasonable attempts were made to obtain additional details.

Missing Information Should Be Followed Up

The complaint record should document:

⦿ Questions sent to the reporter.

⦿ Follow-up attempts.

⦿ Information received.

⦿ Information that remained unavailable.

⦿ Whether missing information affected reportability, investigation or closure.

A complaint audit may identify weaknesses when companies simply record “insufficient information” without showing what was done to obtain additional evidence.

Reportability Should Be Resolved

Before closure, the file should demonstrate that reportability was assessed appropriately.

This includes documenting:

⦿ Applicable markets.

⦿ Reporting criteria considered.

⦿ Awareness date.

⦿ Reporting deadline assessment.

⦿ Submission status, if applicable.

⦿ Rationale for reportable or non-reportable conclusions.

For more details on complaint reportability decisions, see Which Medical Device Complaints Are Reportable, and Which Authority Should Be Notified?.

Investigation Should Be Adequate

The investigation should address the actual complaint, not simply repeat the information received.

Depending on the type of the event, appropriate evidence would include:

⦿ Returned-device evaluation.

⦿ Functional testing.

⦿ Manufacturing records.

⦿ Supplier information.

⦿ Software or log review.

⦿ Service history.

⦿ Similar complaint review.

⦿ Technical analysis.

The conclusion should match the evidence available.

For example, a conclusion such as “no device issue identified” should explain what was reviewed and why the evidence supports that conclusion.

For additional guidance, see How Do You Know Whether a Medical Device Complaint Investigation Is Adequate?.

Medical device complaint file audit framework showing intake, identification, assessment, investigation, actions, and documented closure.

How Should Complaint Trends and Recurrence Be Considered?

A complaint should not be reviewed only as an isolated event.

One complaint can point to a wider problem because it shows:

⦿ A new failure mode.

⦿ A potential safety concern.

⦿ A supplier problem.

⦿ A design weakness.

⦿ An ineffective risk control.

Similarly, several small complaints may reveal a trend.

The review of the complaint should take into account:

⦿ Similar complaint history.

⦿ Complaint frequency.

⦿ Failure mode recurrence.

⦿ Product or lot concentration.

⦿ Supplier involvement.

⦿ Market impact.

⦿ Severity changes over time.

A complaint audit may examine whether organizations are identifying patterns or simply closing individual complaints without evaluating broader implications.

For more information, see When Do Repeated Medical Device Complaints Become a Trend?.

What Records Should Be Available in a Complaint File?

An audit-ready complaint file does not need to contain duplicate copies of every related document. However, it should provide clear traceability to controlled records.

Complaint Intake Records

Examples include:

⦿ Initial complaint communication.

⦿ Customer service records.

⦿ Distributor reports.

⦿ Service reports.

⦿ Emails.

⦿ Call notes.

⦿ Photographs or videos.

Device Identification Records

The file should allow reviewers to understand exactly which device was involved.

Relevant records may include:

⦿ Model.

⦿ Serial number.

⦿ Lot or batch.

⦿ Software version.

⦿ Manufacturing date.

⦿ Device configuration.

⦿ Market supplied.

Investigation Records

Depending on the complaint, records may include:

⦿ Investigation approach.

⦿ Technical evaluation.

⦿ Returned-device assessment.

⦿ Test results.

⦿ Manufacturing review.

⦿ Supplier review.

⦿ Root-cause assessment.

⦿ Investigation conclusion.

Regulatory and Quality Records

The complaint file should link, where applicable, to:

⦿ Reportability assessment.

⦿ Regulatory reports.

⦿ CAPA.

⦿ Risk-management updates.

⦿ Supplier actions.

⦿ Change controls.

⦿ PMS records.

The goal is traceability. A reviewer should be able to follow the complete path from complaint receipt to final action.

How Should Reportability Decisions Be Documented?

A strong complaint file should not only state the final reportability conclusion. It should demonstrate how the decision was reached.

A statement such as:

“Not reportable.”

does not provide enough justification for an auditor or inspector to understand the reasoning.

An appropriate reportability determination must include:

⦿ Event description.

⦿ Patient or user outcome.

⦿ Device involvement.

⦿ Malfunction or failure assessment.

⦿ Potential consequence if recurrence occurs.

⦿ Applicable regulatory criteria.

⦿ Markets assessed.

⦿ Final rationale.

⦿ Reviewer and approval.

The assessment should show that the organization considered the relevant facts before reaching the conclusion.

Avoid Unsupported Conclusions

Weak documentation:

“No injury occurred, therefore not reportable.”

A stronger assessment would explain:

⦿ Whether the device malfunctioned.

⦿ Whether the device contributed to the event.

⦿ Whether recurrence could result in serious harm.

⦿ Whether similar events exist.

⦿ Why reporting criteria were or were not met.

The conclusion should be supported by evidence, not assumptions.

Document Each Market Assessment

For globally distributed devices, one generic conclusion may not be sufficient.

The complaint file should identify the markets reviewed, such as:

⦿ United States.

⦿ European Union.

⦿ Canada.

⦿ Australia.

⦿ Other applicable regions.

Different markets may have different reporting criteria, timelines and responsible entities.

For details on reporting timelines across different regions, see Medical Device Incident Reporting Timelines: FDA, EU, Health Canada and TGA.

Record Awareness Date and Timeline Information

The complaint file should clearly identify:

⦿ When the event occurred.

⦿ When the complaint was received.

⦿ When the company became aware of relevant information.

⦿ When the reportability assessment started.

⦿ Applicable reporting deadline.

⦿ Submission date, if applicable.

Missing or inconsistent awareness dates are typical audit findings due to their impact on evaluating the timing of reporting.

Document Uncertainty Appropriately

Not every complaint investigation will have complete information.

Where information is unavailable, the file should document:

⦿ What information is missing.

⦿ Attempts made to obtain additional information.

⦿ Whether missing information affects the decision.

⦿ Any remaining uncertainty.

⦿ Required follow-up actions.

A documented limitation is more defensible than an unsupported assumption.

What Do Auditors Inspect in Complaint Files?

During a complaint audit, reviewers typically assess whether complaint records are complete, consistent and supported by evidence.

They may evaluate:

Timeliness

Auditors may compare:

⦿ Complaint receipt date.

⦿ Awareness date.

⦿ Investigation initiation date.

⦿ Reportability decision date.

⦿ Regulatory submission date.

⦿ Complaint closure date.

It can be determined if there was compliance with internal and regulatory deadlines.

Procedure Compliance

Reviewers may verify whether the company followed its own procedures, including:

⦿ Required escalation steps.

⦿ Reviewer involvement.

⦿ Approval requirements.

⦿ Investigation timelines.

⦿ Documentation expectations.

An organization may have an acceptable procedure in writing but still receive findings if the complaints are not reflecting that.

Investigation Adequacy

There can be evaluation of whether:

⦿ Evidence supports the conclusion.

⦿ The investigation addressed the actual complaint.

⦿ Similar events were reviewed.

⦿ Relevant manufacturing or supplier information was considered.

⦿ Investigation limitations were documented.

For example, a conclusion of “no fault found” should explain what testing was performed and why the conclusion is reasonable.

Complaint Trending

Auditors may review whether the company identifies recurring issues.

They may ask:

⦿ Were similar complaints grouped together?

⦿ Were complaint rates reviewed?

⦿ Were escalation thresholds defined?

⦿ Did recurring issues lead to further action?

The critical point is that the complaints process should be able to detect trends, not just the actual complaints.

CAPA and Risk Linkage

Reviewers may assess whether complaints are connected to broader quality processes.

They may look for evidence that complaint findings were evaluated for:

⦿ CAPA impact.

⦿ Risk-management updates.

⦿ Supplier action.

⦿ Product changes.

⦿ PMS implications.

Medical device complaint audit timeline showing receipt, awareness, investigation, reporting, actions, and closure evidence.

Common Complaint File Audit Weaknesses

Many complaint-related findings occur because the file contains information but does not clearly demonstrate the decision-making process.

Common weaknesses include:

Reportability Conclusion Without Rationale

The report gives a conclusion of reportability without providing any rationale regarding the criteria for it.

Missing or Incorrect Awareness Date

The timeline is impossible to verify due to unknown starting date of reporting obligation.

Investigation Does Not Address the Failure

The document contains the complaint description and repeats it but does not contain evaluation and evidence analysis.

“No Fault Found” Without Supporting Evidence

The conclusion is stated without any documentation of the testing, analysis or limits.

Complaint Closed Due to Missing Device Return

The non-return of the device doesn’t mean the absence of assessment.

Similar Complaints Not Reviewed

The company considers just one complaint and does not find possible trends.

CAPA Mentioned but Not Linked

The complaint mentions the corrective action but there is no traceable connection with the CAPA.

Risk File Not Reviewed

New field information does not trigger evaluation of existing risk controls.

Different Conclusions for Similar Events

There are similar complaints but different conclusions on their reportability or investigations.

Open Actions Not Controlled

Important follow-up actions remain in emails or notes instead of controlled quality records.

Comparison of a closed and audit-ready medical device complaint file showing differences in evidence, rationale, actions, and traceability.

How Should CAPA and Risk Actions Be Connected to Complaint Files?

A complaint file should not exist separately from the broader quality system.

When a complaint reveals a systemic issue, the record should demonstrate how the information moved into appropriate processes.

Complaint-to-CAPA Connection

The complaint file should show:

⦿ Whether CAPA was considered.

⦿ CAPA decision rationale.

⦿ CAPA reference number, if opened.

⦿ Failure mode addressed.

⦿ Related complaints included.

⦿ Effectiveness verification approach.

For more information, see When Should a Medical Device Complaint Trigger CAPA?.

Complaint-to-Risk Management Connection

Complaint information may influence:

⦿ Existing hazards.

⦿ Hazardous situations.

⦿ Severity evaluation.

⦿ Probability estimates.

⦿ Risk controls.

⦿ Residual risk.

⦿ Benefit-risk assessment.

For more information, see How Should Complaint Data Drive Risk, Product, Supplier and Maintenance Actions?.

Maintain Two-Way Traceability

The complaint file should link to:

⦿ CAPA records.

⦿ Risk-management records.

⦿ Supplier corrective actions.

⦿ Change controls.

⦿ PMS activities.

Related documents should refer to the complaint.

This is so that auditors will be able to trace the full flow:

Complaint → Investigation → Decision → Action → Effectiveness Review

Practical Example: Blood-Pressure Monitor Battery Failure

A manufacturing firm has received a customer complaint regarding loss of power in the battery-powered blood pressure monitor.

Weak Complaint File

The file contains:

⦿ Customer complaint.

⦿ Device not returned.

⦿ “Battery issue suspected.”

⦿ “Not reportable.”

⦿ Complaint closed.

Such files can be hard to justify since no record exists on the decision-making process.

Audit-Ready Complaint File

The file includes:

⦿ Complaint details and user outcome.

⦿ Device identification information.

⦿ Follow-up attempts documented.

⦿ Assessment of whether treatment was affected.

⦿ Review of similar battery complaints.

⦿ Supplier and component evaluation.

⦿ Reportability rationale.

⦿ Risk assessment.

⦿ CAPA evaluation.

⦿ Supplier action, if required.

⦿ Closure approval.

It’s not the quantity of documentation that makes the difference. It’s the traceability and logic of the process recorded in the document.

An audit-ready complaint file demonstrates why decisions were made, not simply what decisions were made.

Need Help Reviewing Your Complaint Files?

Elexes supports medical device manufacturers with complaint file reviews, audit readiness assessments, reportability evaluations, CAPA traceability reviews and post-market quality system improvements.

  • What makes a medical device complaint file audit-ready?

    An audit-ready complaint file is complete, traceable and supported by evidence. It should show what happened, how it was evaluated and why decisions were made.

  • What records should be maintained in a complaint file?

    Intake information, device information, investigation information, reportability decision, actions taken, and closure of the complaint need to be recorded.

  • Can a complaint close without a confirmed root cause?

    Yes. Limitations of the investigation, evidence gathered, and reasonableness of the conclusion need to be documented in the complaint file.

  • Can a complaint close without the device being returned?

    Yes. But efforts made for the retrieval of the device and other evidence used need to be documented in the complaint file.

  • Can a complaint close while CAPA remains open?

    Yes. The complaint can close when its investigation is complete, provided the CAPA is formally linked and controlled.

Share This: