Updated July 2026. Scope: U.S. FDA Quality Management System Regulation (QMSR), 21 CFR 820.35, effective 2 February 2026. For the wider QMSR transition, see the QMSR and 21 CFR Part 820 executive guide.

Key takeaways

  • Under the QMSR, 21 CFR 820.35 (Control of records) sits on top of ISO 13485 Clause 4.2.5. It does not replace the ISO clause. It adds specific FDA record content that ISO 13485 alone does not spell out.
  • The additions concentrate on three record types: complaint records, servicing records, and unique device identifier (UDI) records, plus a confidentiality-marking provision.
  • For reportable and investigated complaints, 820.35 lists seven data points that each complaint record must capture. Missing any of them is a records gap an FDA investigator can cite.
  • This is a documentation-and-evidence requirement. The controls only count if the records actually exist and are complete.

Where 820.35 fits in the QMSR

The QMSR incorporates ISO 13485 by reference and layers targeted U.S. requirements on top. 21 CFR 820.35 is one of those layers. It opens by pointing back to ISO 13485 Clause 4.2.5, Control of Records, and then states that the manufacturer “must include the following information in certain records.”

So the reading order is: meet ISO 13485 Clause 4.2.5 for record control generally, then add the specific content 820.35 requires for complaints, servicing, and UDI. If your quality system was built to the old Quality System Regulation, the record content is familiar, but the framing is now ISO-clause-plus-supplement, and the cross-references have changed.

Complaint records: the seven data points

Building on ISO 13485 Clause 8.2.2 (Complaint Handling), 820.35(a) requires manufacturers to maintain records of the review, evaluation, and investigation for any complaint involving the possible failure of a device, its labeling, or its packaging to meet specifications. If a similar complaint has already been investigated, a new investigation is not required, but the manufacturer must keep a record documenting the justification for not investigating.

For complaints that must be reported to FDA under 21 CFR Part 803, complaints the manufacturer determines must be investigated, and complaints it investigated anyway, the record must capture:

#Required data point
1The name of the device
2The date the complaint was received
3Any UDI or universal product code (UPC), and any other device identification
4The name, address, and phone number of the complainant
5The nature and details of the complaint
6Any correction or corrective action taken
7Any reply to the complainant

These seven are the ones an inspector can check line by line. A complaint file that resolves the issue but omits, say, the corrective action taken or the reply to the complainant is incomplete against 820.35(a).

Servicing records

Under 820.35(b), for servicing activities (aligned with ISO 13485 Clause 7.5.4), the record must include, at a minimum:

  • The name of the device serviced
  • Any UDI or UPC, and any other device identification
  • The date of service
  • The individual or individuals who serviced the device
  • The service performed
  • Any test and inspection data

Servicing records are a frequent gap because service events happen in the field, away from the document controls that govern production. If your servicing records cannot name who performed the service and on what date, they do not meet 820.35(b).

UDI records and confidentiality

Two further provisions round out the section:

  • UDI records (820.35(c)). In addition to the relevant ISO 13485 clauses, the UDI must be recorded for each medical device or batch of devices. UDI is not only a labeling requirement; it has to be captured in the records.
  • Confidentiality marking (820.35(d)). Records the manufacturer considers confidential may be marked, to help FDA decide whether the information can be disclosed under the public-information rules in 21 CFR Part 20. Marking is a mechanism to flag confidentiality, not an automatic bar to disclosure.

What to check in your quality system

Reading 820.35 against your records is a short, concrete exercise:

  1. Confirm complaint records capture all seven data points for reportable and investigated complaints, not just the resolution.
  2. Confirm the no-reinvestigation justification is documented when you rely on a prior similar-complaint investigation.
  3. Confirm servicing records name the individual and date, not just the outcome.
  4. Confirm UDI is recorded, not only printed on the label.
  5. Confirm the ISO 13485 Clause 4.2.5 record controls underneath all of this are in place, since 820.35 assumes them.

Frequently asked questions

Is 21 CFR 820.35 new under the QMSR?
The QMSR restructured Part 820 to incorporate ISO 13485 and add U.S.-specific requirements. 820.35 (Control of records) is the section that carries the FDA-specific record content, on top of ISO 13485 Clause 4.2.5, and it applies from 2 February 2026.

Does 820.35 replace ISO 13485 record requirements?
No. It supplements them. You meet ISO 13485 Clause 4.2.5 for record control, then add the specific complaint, servicing, and UDI record content that 820.35 requires.

What are the seven complaint data points?
Device name; date the complaint was received; UDI/UPC or other device identification; complainant name, address, and phone; nature and details of the complaint; any correction or corrective action; and any reply to the complainant.

Do servicing records really need the name of the individual?
Yes. 820.35(b) lists the individual or individuals who serviced the device as required record content, along with the device name, identification, date, service performed, and any test and inspection data.

What does the confidentiality provision do?
820.35(d) lets a manufacturer mark records it considers confidential, to aid FDA in deciding whether the information may be disclosed under 21 CFR Part 20. It is a marking mechanism, not an automatic bar to disclosure.

Related guides and services


This article is for general information only and is not legal or regulatory advice. Teams remain responsible for regulatory decisions and staying current with applicable regulations and guidance.

Talk to CENIT Consulting about QMSR record controls and inspection readiness: book a 30-minute consult.