Many complaint systems begin well: a clear form, a reference number and an acknowledgement. Then the process stops when the ticket closes. That is where regulatory value is lost. A complaint is not a customer-service record isolated from quality. It is information that may change what the manufacturer knows about device safety or performance. It may lead to incident reporting, field action, risk-file updates or CAPA—or to none of them after a documented investigation.

An official SFDA FAQ confirms that corrective action is not automatically required for every reported incident; the response depends on the specific case. A mature system therefore neither opens CAPA for every complaint nor closes difficult cases under a convenient category.

Seven connected decisions

StageCritical questionExpected output
IntakeCan the device and event be identified?Dated record, product identity, source and follow-up path
TriageIs the case serious or potentially reportable?Documented decision against current SFDA rules
ContainmentMust stock, shipment or use be controlled now?Immediate action proportionate to risk
InvestigationWhat happened, based on which evidence?Confirmed cause or tested hypotheses with stated gaps
Risk evaluationDoes the information change probability or severity?Risk-file update or justified no-change decision
ActionCorrection only, CAPA, change or FSCA?Approved decision, owner and due date
EffectivenessDid recurrence fall and was the action completed?Measured effectiveness and auditable closure

Correction is not CAPA

Replacing a customer's device corrects the immediate situation. Retraining a person may form part of an action. CAPA asks a deeper question: what condition allowed the problem to occur? The answer may sit in design, a supplier, production, instructions for use, transport and storage, or complaint triage itself. The action must remove or control that cause. Otherwise the case closes while the system remains unchanged.

To turn this analysis into a product-specific plan, review Technical File and Regulatory Readiness Review and the related regulatory insight.

Opening CAPA for every case creates the opposite failure: administrative noise that hides significant signals. Escalation criteria should consider severity, recurrence, trends, detectability, uncertainty and the possibility that the issue affects other devices or markets. The no-CAPA decision needs evidence just as the CAPA decision does.

Feed the complaint back into risk management

The lifecycle model in ISO 14971:2019 includes production and post-production information. Complaint investigation therefore should not stop at identifying a malfunction. The team compares the event with known hazards, checks whether probability and severity assumptions remain credible, and looks for new risks or use patterns that were not adequately represented.

Not every event changes the risk file, but every relevant event needs a decision path. A bare statement that there is 'no risk impact' is not an analysis. Record the reviewed evidence, related hazard, decision owner and trigger that would cause reassessment if the event recurs.

When action moves into the field

SFDA describes a Field Safety Corrective Action as action by a manufacturer to reduce or remove a risk of death or serious deterioration in health associated with a marketed device. Depending on the case, that can include inspection, repair, calibration, relabeling, destruction or user notification.

Field action is not owned by quality alone. The manufacturer normally holds the technical assessment and global decision, while the Saudi authorized representative, importer and distributor may have local responsibilities for communication, traceability, stock and customer reconciliation, execution and evidence. Ambiguous roles consume time when response speed matters most.

A small dashboard can expose the system

Management does not need dozens of metrics. Start with time to initial triage, overdue investigations, recurrence by family or lot, complaints that triggered risk review, overdue CAPAs and effectiveness-check results. Read them together. A falling complaint count may be positive—or it may mean that local channels are not feeding information back to the manufacturer.

For Saudi implementation, use the current version of MDS-REQ11 at the time of the case, including reporting and follow-up duties. Do not freeze portal mechanics or timelines inside an SOP without a control for regulatory updates.

How Basier closes the loop

Basier designs one controlled path from complaint intake to documented closure or regulatory escalation. We define decision points, role ownership, minimum data, and the links among complaints, risk management, CAPA and FSCA, then test the design with real scenarios. The purpose is not more forms. It is less time between a signal and the right decision.

References: [1] [2] [3] [4]

Official sources

Turn the requirements into a clear plan for your case

Start with an assessment of the device and available evidence before deciding on submission.

Technical File and Regulatory Readiness Review