How Should Complaint Data Drive Medical Device Risk Management and Quality Actions?
A complaint can be correctly investigated, assessed as non-reportable and formally closed while the product, supplier, risk file or maintenance programme that contributed to the issue remains unchanged.
That is where medical device risk management becomes important. Complaint data is not only a record of individual customer experiences. It can provide important information about hazards, risk controls, product performance and real-world use.
A complaint may reveal a design weakness, underestimated risk, supplier problem, servicing gap, labeling issue or training need. It may also show that an existing risk control is not working as expected.
The key question is therefore not simply whether the complaint can be closed. It is what the investigation findings mean for the rest of the quality and regulatory system.
For manufacturers that need support connecting complaint findings with downstream actions, see Medical Device Complaint Handling and Vigilance Review Services.
What Should Happen After a Complaint Investigation?
Once the investigation is complete, first confirm what the evidence actually shows. This includes the failure mode, patient or user outcome, cause or level of uncertainty, recurrence, similar complaints and whether other products or markets could be affected.
The company will then have to examine the potential downstream actions. Depending on the results, there may be need to consider whether the complaint requires assessment by regulatory authorities, risk management, CAPA, engineering review, supplier actions, maintenance actions, labeling or training actions, or post-market surveillance.
The correct owner should also be assigned. Risk Management, Engineering, Supplier Quality, Service, Regulatory Affairs, Quality, Labeling or Training may each have a role.
A complaint should therefore not be considered fully resolved simply because its individual record can be closed. The organization should know whether its findings have been transferred to the functions responsible for addressing broader implications.
A complaint is not truly complete until the organization has decided what the investigation means for risk, product, supplier, maintenance, labeling, training and other applicable quality actions.
When Should the Risk-Management File Be Updated?
The risk-management file should be reviewed when complaint data changes, or may change, the manufacturer’s understanding of a hazard, hazardous situation, probability, severity, risk control or residual risk.
For anyone asking what is risk management in medical devices, the practical answer is that it is a structured process for identifying hazards, evaluating and controlling risks, and monitoring those controls throughout the device life cycle. ISO 14971:2019 remains the current international standard for this process and includes production and post-production information within the risk-management framework.
A new hazard or hazardous situation is identified
A complaint may reveal a failure mode, sequence of events or use condition that was not adequately considered in the original risk assessment.
The probability of a known harm may have changed
Repeated complaints may show that a failure occurs more often than estimated, affects a wider population or occurs under conditions not adequately represented in the original assessment.
The severity or consequence is different
Field experience may show that a malfunction delays treatment, affects a safety-critical function or produces a more serious consequence than originally anticipated.
A risk control may be ineffective
Examples include an alarm that does not reliably alert the user, a warning that is misunderstood, an inspection process that does not detect the defect or preventive maintenance that does not prevent a recurring failure.
A product or process change is being considered
Risk review is also important when complaint findings lead to a design, software, supplier, manufacturing, labeling or maintenance change. The change may introduce new hazards or alter existing risks.
The review may affect hazard analysis, probability estimates, severity justification, risk controls, residual-risk evaluation or benefit-risk assessment.
This is where When Should a Medical Device Complaint Trigger CAPA? should be considered alongside the risk review. CAPA and risk management for medical device products may operate through different processes, but their outputs often need to remain connected.
When Should Engineering Review the Product?
Engineering should review a complaint when evidence suggests that design, component selection, software, user interface or product performance may have contributed to the problem.
Failure of the product in recurrent cases is critical. When a particular problem is experienced in all lots and is not found to be in the manufacturing record, it may point to design issues.
Complaint data can also reveal differences between specified performance and real-world use. A battery may meet its specification but provide inadequate operating time in actual use. An alarm may meet a measured output requirement but still be difficult for users to hear.
An engineering review does not necessarily mean redesigning the product. Engineering review can result in further tests, enhanced surveillance, changes in specifications, replacement of some parts, software changes, labeling actions or confirmation that the existing design remains adequate.
Where a product or process change is being considered, the change should also undergo the appropriate change-impact assessment.
When Should Supplier Quality Become Involved?
Supplier quality should become involved when a supplied component, material, outsourced process or supplier change may have contributed to the complaint.
Useful indicators include complaints clustering around the same component, supplier lot or material, or a supplier change occurring before the problem appeared.
The review should consider incoming inspection results, supplier nonconformances, supplier CAPAs, deviations, change notifications, audit findings and relevant test records.
The part may also meet its current specification requirements yet exhibit poor field performance. This would suggest that the specification or acceptance requirement does not address the requirements of the finished medical device.
A supplier corrective-action request may be appropriate for supplier related issues that are recurring, affecting multiple lots or where there is a need for root cause analysis.
When Should Preventive Maintenance Be Changed?
Preventive maintenance should be reviewed when complaint data suggests that failures could be detected, prevented or reduced through better inspection, servicing, replacement or calibration controls.
Examples include battery degradation, sensor drift, seal deterioration, mechanical wear or recurring calibration problems.
Compare complaint data with service records, device age, operating hours, replacement history and maintenance intervals. If failures repeatedly occur before scheduled service, the existing interval or maintenance task may need review.
However, maintenance should not become a substitute for an unacceptable design solution. If the evidence points to a fundamental product weakness, engineering or design action may be more appropriate.
When Should Labeling or Training Be Reviewed?
Complaint data should prompt labeling or training review when users repeatedly misunderstand instructions, miss warnings, perform an incorrect procedure or cannot reliably complete a required task.
Examples include incorrect assembly, improper cleaning, incorrect storage, accessory confusion or failure to follow maintenance instructions.
The investigation should not automatically conclude “user error.” It should consider whether the instructions were clear, whether the error was foreseeable, whether the interface encouraged the behavior and whether a design-based control could be more effective.
Labeling or training may be appropriate, but repeated use errors can also indicate a usability or design problem.
Can One Complaint Require Several Downstream Actions?
Yes. A single complaint can have implications across several functions.
For example, suppose a blood-pressure monitor unexpectedly loses power during use. The complaint may require risk review if recurrence could delay treatment, engineering review if battery performance is inadequate, supplier review if a particular battery lot is involved, maintenance review if replacement intervals are unsuitable and labeling review if battery instructions are unclear.
If the event also reveals a systemic issue, CAPA may be appropriate.
The important point is that the complaint process should not force the organization to choose only one action category. Several controlled actions may need to remain linked to the same complaint.
How Should Downstream Actions Be Controlled?
Once an action is identified, it should have a clear owner, due date and controlled record. The complaint should remain traceably connected to the resulting CAPA, risk update, engineering change, supplier action, maintenance change or labeling revision.
The organization should also determine whether the action requires change control, regulatory assessment, verification or effectiveness review.
For post-market surveillance complaints, this traceability is particularly important because complaint information can contribute to broader PMS evaluation. ISO/TR 20416 describes post-market surveillance as a systematic process for collecting and analysing post-production information, with outputs that can feed into risk management, product realization and improvement.
EU PMS guidance likewise identifies complaints and feedback from users, distributors and importers as relevant post-market information.
Can a Complaint Close While Downstream Actions Remain Open?
Potentially, yes.
A complaint-specific investigation can be complete while a linked CAPA, supplier action, engineering change or other controlled activity remains open.
This is appropriate when the complaint conclusion and reportability assessment are complete, the downstream action is formally assigned, ownership and due dates are established, and the relationship remains traceable.
A complaint should not be closed simply because the action has been mentioned in free text. Conversely, the complaint should not remain open indefinitely when its investigation is complete and the remaining work is properly controlled elsewhere.
What Should Be Documented?
A defensible record should capture:
⦿ Complaint and failure mode.
⦿ Patient or user outcome.
⦿ Investigation conclusion and uncertainty.
⦿ Similar-event or trend assessment.
⦿ Risk-management decision.
⦿ Engineering decision.
⦿ Supplier-quality decision.
⦿ Maintenance decision.
⦿ Labeling or training decision.
⦿ CAPA decision.
⦿ Action owner and due date.
⦿ Linked controlled records.
⦿ Regulatory impact, where applicable.
⦿ Verification or effectiveness review.
⦿ Closure rationale and approval.
The record should make it possible for another reviewer to understand what was learned from the complaint and how that learning was translated into action.
The Key Question Is What the Complaint Changes
Complaint handling should not end with a reportable or non-reportable decision. The more important quality question is whether the information changes the organization’s understanding of risk, product performance, supplier performance, maintenance needs or user interaction.
Effective medical device risk management depends on feeding relevant production and post-production information back into the risk process. Complaint data can also support engineering, supplier quality, maintenance, labeling, training, CAPA and PMS decisions.
The objective is not to create an action for every complaint. It is to make sure that important information does not stop at complaint closure.
For manufacturers that need help evaluating complaint findings and connecting them to risk, quality and post-market actions, explore Medical Device Complaint Handling and Vigilance Review Services.
Need Help Turning Complaint Findings Into Action?
FAQs
What should happen after a medical device complaint is investigated?
The organization should assess the investigation findings for regulatory, risk, product, supplier, maintenance, labeling, training, CAPA and PMS implications, then assign and control any required actions.
When should complaint data update the risk-management file?
The risk file should be reviewed when complaint information may change the understanding of a hazard, hazardous situation, probability, severity, risk control or residual risk.
Can one complaint require multiple downstream actions?
Yes. A single complaint may require coordinated action from Risk Management, Engineering, Supplier Quality, Service, Regulatory Affairs, Labeling or other functions.



