Skip to content

Review log

A record of every post-publication content review and correction. See our editorial policy for how content is sourced and reviewed before this log begins.

2026-005 · Quarterly spot-check · August 20, 2026

First paraphrase audit — 21 CFR Part 809 (IVD) and postmarket-CFR (803/806/810/822) atoms

Trigger
Coverage-gap audit, not the routine quarterly sample (#3300). Every other requirement family had both a full paraphrase audit and a recent quarterly sample; ivd-cfr809 and postmarket-cfr had neither. This event closes that gap with a full audit of both families rather than a sample.
Scope
29 of 29 published requirements in the ivd-cfr809 (11) and postmarket-cfr (18) families — full coverage of both, not a sample. See docs/audits/2026-08-20-3300-ivd809-postmarket-cfr-paraphrase.md for the full report.
Method
Each requirement's requirement_text and atomic_constraints were compared against the current eCFR text of every cited section, fetched live via scripts/standards/standards-corpus fetch (all five CFR parts involved are source: live in the manifest, not stored PDFs). The audit report also includes a bounded check on why the six already-audited families' atom count grew from 123 to 166 since April, and corrects the issue's premise that this was caused by #1706's atom-ID rewrite (it was not — #1706 explicitly kept atom IDs frozen).
Findings
5 scored findings in postmarket-cfr, 0 in ivd-cfr809 (plus 1 informational note not scored, per the zero-false-positive-bias discipline). 1 medium: REQ-21CFR810-10's requirement_text states a strategy-development duty as unconditional when the atom's own atomic_constraints correctly scope it as conditional on order modification or escalation to mandatory recall. 4 low: three citation-misattribution/duplication findings (REQ-21CFR803-50, REQ-21CFR822-10, REQ-21CFR822-31 each attribute content to the wrong clause within Part 803/822, two of them duplicating a correctly-cited sibling atom) and one scope-broadening finding (REQ-21CFR806-20 states its recordkeeping duty applies to all corrections/removals when the cited clause scopes it to the non-reportable subset only).
Disposition
A second, independent auditor ran the same 29-requirement scope concurrently; a third pass adjudicated both classifiers' findings against live eCFR text. All 16 adjudicated corrections (8 citation-scope fixes to regime_keys, 7 substantive paraphrase-drift fixes, 1 intra-scope misattribution fix) were applied to the ivd-cfr809 and postmarket-cfr atom files on 2026-08-20.

2026-003 · Quarterly spot-check · August 12, 2026

Quarterly spot-check — Q3 2026

Trigger
Scheduled quarterly review (see How content is reviewed). This is the first quarterly spot-check, the one the editorial policy commits to completing in the third quarter of 2026.
Scope
30 of the 167 published requirements, sampled across all six published regimes. Selection basis: within each regime the requirements were sorted by identifier and sampled at even intervals, so the sample spans each standard's clause range rather than clustering; per-regime counts were set in proportion to regime size — ISO 13485 9, IEC 81001-5-1 8, IEC 62304 5, FDA cybersecurity guidance 4, IEC 62366-1 2, ISO 14971 2. The sample is recorded in full below and the selection is reproducible.
Method
Each sampled requirement was compared against the current text of its source standard or regulation, retrieved at review time. 21 CFR Part 820 was fetched live from the eCFR. The consensus standards and the FDA cybersecurity guidance were read from our licensed corpus copies, which are the authoritative text for sources that publish no machine-readable current version. Each check asked three questions: does every cited clause number exist in the current edition, does our wording carry the same obligation level and scope as the clause, and does the clause say what we claim it says. Working papers for all three review partitions are at data/review-ledger-evidence/2026-Q3/.
Findings
10 of the 30 sampled requirements carried a finding; 20 required no change. 1 was critical: our coordinated vulnerability disclosure requirement described a plan that §524B(b)(1) of the FD&C Act obliges manufacturers of cyber devices to submit as though it were a discretionary FDA recommendation. 2 were high: our internal-audit requirement narrowed ISO 13485 §8.2.4 from four conformance targets to one, and our security-update requirement extended a manufacturer-only verification duty to suppliers. 5 were medium and 2 were low, all of them dropped qualifiers, omitted a second required element, or attributed a passage to the wrong section of the FDA guidance. No sampled requirement cited a clause number that does not exist, and none was left unverified. The IEC 62304, IEC 62366-1 and ISO 14971 requirements were clean throughout.
Disposition
the critical finding was corrected on 2026-08-12; the remaining 9 were corrected on 2026-08-14.

2026-004 · Content review · August 12, 2026

Scheduled content review — guide library

Trigger
The guides reached 133 days since their last recorded review, past the one-quarter mark at which our staleness clock calls for a re-review.
Scope
All seven published guides.
Method
Each guide's prose was checked against the sources it cites and against the requirements we publish: every clause and section reference resolved against the current source text, every restatement of a requirement compared with the corresponding published requirement, every named standard edition confirmed to be the current one, and every dated or countable claim checked against the position today. 21 CFR Part 820 was fetched live from the eCFR; the consensus standards and FDA guidance were read from our licensed corpus copies. Working papers are at data/review-ledger-evidence/2026-Q3/.
Findings
18 findings across 6 guides; qmsr-google-drive required no change. 6 were high. Two were live citation errors on the QMSR transition guide: it pointed readers to §820.198 for complaint handling, a section that no longer exists in Part 820, and it claimed some records must be kept longer than ISO 13485 requires, which the current regulation does not say anywhere. The remaining four were on the standards guides, the clearest being a clause cited under the wrong number and a set of provisions attributed to a standard's base edition rather than the amendment that introduced them. The most widespread single defect was cosmetic but repeated: a superseded 2023 edition label for the FDA cybersecurity guidance survives in five places across three guides, even though the sections those guides cite are the current February 2026 ones.
Disposition
the two live citation errors on the QMSR transition guide were corrected on 2026-08-12; of the remaining 16, 15 were corrected on 2026-08-14 and one required no change, because the claim it flagged had already been revised at source.

2026-002 · Source-change re-verification · July 23, 2026

Source-change re-verification — ISO 19011:2018 withdrawn

Trigger
ISO withdrew ISO 19011:2018 (management system auditing guidelines) on 2026-05-27.
Scope
all published requirements and guide content citing ISO 19011.
Method
each citing page checked against the withdrawal notice and our library records.
Findings
0 published requirements presented the withdrawn edition as a current obligation. Two internal library records still marked the edition current; both were updated on 2026-07-23 to record the withdrawal.
Disposition
no published content required correction.
Elapsed
57 days from source event to completed re-verification, against our 30-day target. The internal alert that should have flagged this withdrawal did not fire; we have since fixed that alert, and elapsed time is now recorded on every entry of this type.