Summary
“FDA isn’t asking whether you followed the procedure. They are asking whether your system can assure consistent outcomes in the real world.”
In this episode of the Let's Talk Risk Podcast, Priya Setty joins host Naveen Agarwal to unpack why QMSR represents more than a procedural update; it’s a mindset shift toward assurance, credibility, and risk-based decision making across the entire product lifecycle. Priya shares how the FDA’s alignment with ISO 13485 elevates expectations for design controls, risk integration, software assurance, and role-specific competence.
Drawing on her clinical roots, global regulatory experience, and work in regulatory intelligence, Priya discusses how RA/QA professionals can prepare for future expectations through deeper understanding of risk, building strong feedback loops, developing competence beyond training, and embracing leadership roles that shape culture, not just documentation.
Chapters
00:00 Why QMSR is a shift from compliance to assurance.
01:00 Priya’s unconventional journey from occupational therapy to regulatory affairs.
04:00 How FDA expects QMSR readiness to show up in pre-market submissions.
07:00 Compliance vs. assurance: Priya’s analogy for FDA’s mindset shift.
09:30 Software assurance, least burdensome validation, and risk-based thinking.
13:00 Why QMSR requires more than documentation—evidence of decision-making maturity.
17:00 The future of inspections: competence, culture, and systemic vulnerabilities.
22:00 Priya’s advice on preparing for QMSR and building a future-ready RA/QA career.
Suggested links:
* FDA: Draft Guidance - QMS Information for PMA Reviews.
* LTR: Megan Kane on Leading QMSR Readiness in a Startup.
* LTR: A 90-Day QMSR Readiness Action Plan for Leaders.
Key Takeaways
* QMSR represents a mindset shift: from proving compliance through procedures to demonstrating assurance through real-world performance and decision-making maturity.
* FDA now expects integrated, lifecycle risk management, not isolated risk files; risk thinking must visibly connect design, verification/validation, manufacturing, and post-market actions.
* Pre-market submissions will reflect QMSR readiness by showing how risk management drives design decisions, supplier oversight, and verification strategies.
* Software assurance is now explicitly risk-based, requiring validation proportional to intended use and potential impact, reflecting the “least burdensome” approach.
* Competence, not just training, will be scrutinized, and systemic gaps may escalate into management responsibility findings under QMSR.
* Culture becomes a quality system indicator, especially how organizations make decisions, close feedback loops, and connect signals to design controls.
* QMSR transition challenges differ by maturity: ISO 13485–certified companies refine and align; non-certified companies must build foundational structures.
* RA/QA professionals must evolve into cross-functional leaders, shaping risk-informed culture, strengthening feedback systems, and developing deeper expertise in standards and regulatory philosophy.
* Personal career growth principles - curiosity, networking, boldness, persistence - remain essential, especially as AI and digital technologies reshape regulatory practice.
Keywords
QMSR, Quality Management System Regulation, ISO 13485, Regulatory Affairs, Risk Management, Assurance Mindset, FDA Inspections, Software Assurance, Competence vs. Training, Regulatory Intelligence, Medical Devices, Digital Health.
About Priya Setty
Geethapriya (Priya) Setty is a regulatory affairs strategist and systems builder with over eight years in global regulatory affairs and more than twenty years in healthcare. Starting her career as a pediatric occupational therapist, Priya brings a unique blend of clinical insight and policy expertise to the evolving world of medical technology. She leads regulatory intelligence and digital transformation initiatives at a global medical device company, specializing in global regulatory strategy, regulatory intelligence, and digital health/AI compliance for high-risk devices. Priya is adept at navigating complex regulations such as the EU AI Act and FDA guidance, ensuring compliance is embedded in every innovation.
A certified PMP, RAC (Devices), and ISO 13485 lead auditor, Priya is known for demystifying complex regulations and building systems that keep teams ahead of industry changes. Guided by her mantra, “make a choice, and make it happen,” she is dedicated to leadership, mentorship, and simplifying healthcare through curiosity and purpose-driven action.
Disclaimer
Information and insights presented in this podcast are for educational purposes only. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards.
Let's Talk Risk! is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe