Design Is Still the Leading Cause of Class I Recalls. The Failure Almost Always Starts at Design Inputs.
- Author
- Karthik Raghavan
Principal Design Engineer - Expertise
- Product Design and Development
- Service
- Medical Device Design & Development
- Sector
- Diagnostic Devices
Therapeutic Devices
Drug Delivery - Topic
- Development Strategy & Process
Risk Management - Published
7 min read
TL;DR
- In an analysis of 189 FDA Class I recalls of moderate- and high-risk devices between January 2018 and June 2022, device design was the single most frequent root cause at roughly 55%, ahead of manufacturing and processing at about 25% and software at 11%.
- Design failures are rarely failures of engineering skill. They are failures of design inputs — the requirements were incomplete, unverifiable, or written against an idealised patient who does not exist in the field.
- The clinical use environment, not the bench, defines the requirement set. Motion, perspiration, electrode drying, ambient EMI, and untrained users are design inputs, not deployment problems.
- Verification proves you built the device right against your specification. Validation proves the specification was right. Teams that conflate the two ship devices that pass every test and still fail in service.
- The economics are asymmetric: a requirement corrected during design input definition costs a review meeting. The same requirement corrected after design freeze costs re-verification, re-validation, potential re-submission, and tooling rework.
Recall data is one of the few honest, longitudinal datasets the medical device industry has about its own failures. It is worth reading carefully, because it says something uncomfortable.
A structured review of 189 FDA Class I recalls issued between January 2018 and June 2022 for moderate- and high-risk devices found that device design was the most frequent cause, accounting for approximately 55% of recalls. Manufacturing and processing issues followed at roughly 25%, and software at 11%. The same analysis found that cardiovascular devices accounted for 34% of Class I recalls, more than any other specialty, followed by anaesthesiology at 21% and general hospital devices at 17%. Around 19% involved implanted devices.
The scale is not trivial. The median recall notice covered 4,620 units, and roughly 6% of recalls involved more than a million units. Two-thirds of recalled devices had been subject to multiple recalls, with a median of four recalls per device.
The broader trend has not improved. Sedgwick's 2025 US State of the Nation Recall Index recorded 1,059 US medical device recall events in 2024 — a four-year high — with Class I recalls at their highest level in fifteen years, and device failure overtaking process control as the leading cause for the first time in over five years.
Read that back: the majority of the most serious recalls in the industry are not caused by a supplier shipping the wrong resin, or a technician missing a torque spec. They are caused by decisions made in the first ten percent of the programme, before any hardware existed.
The Real Failure Point Is Design Inputs, Not Design Outputs
21 CFR 820.30(c) and ISO 13485:2016 clause 7.3.3 both require design inputs to be appropriate, complete, unambiguous, and verifiable. In practice, most teams treat design inputs as an administrative gate — a document to be produced so the phase review can close — rather than as the single highest-leverage artefact in the programme.
The consequence is a specific and repeating pattern. The device is designed correctly against a requirement set that was wrong. Every subsequent activity — verification, validation, design transfer, submission — then faithfully confirms the wrong thing.
Three input failures show up most often:
Requirements that describe a function, not a performance limit. "The device shall acquire an ECG signal" is not a design input. "The device shall acquire a single-lead ECG at a sampling rate of ≥250 Hz with a bandwidth of 0.05–40 Hz for diagnostic mode, maintaining CMRR ≥ 100 dB, verified per IEC 60601-2-47" is. The first is untestable. The second constrains the analogue front end, the ADC, the electrode interface, and the firmware filter chain simultaneously.
Requirements written against a nominal patient. Physiology has a distribution, not a value. Skin impedance at the electrode interface varies by more than an order of magnitude across subjects, hydration states, and preparation quality. Chest circumference, adipose thickness, arm circumference, and skin condition all shift the signal you receive. A design centred on the median subject silently accepts failure at the tails, and the tails are where the harm concentrates.
Requirements that omit the use environment entirely. A device validated in a clinic and used at home is a different device. IEC 60601-1-11 exists precisely because the home environment introduces variables — no trained operator, uncontrolled temperature and humidity, mains supply quality, pets, children, no biomedical engineering department — that the clinical requirement set never contemplated.
Use-Related Risk Is Design Risk, and It Has to Be Analysed Before the Design Exists
ISO 14971:2019 requires risk management across the full lifecycle, and IEC 62366-1:2015+A1:2020 requires a use specification and a use-related risk analysis as inputs to design, not as a post-hoc usability study.
This ordering matters. A summative usability evaluation conducted after design freeze can only tell you that the design has a use problem. It cannot economically fix it. By that point the enclosure is tooled, the graphical interface is coded, and the labelling is at the printer.
The productive sequence is: define the user profiles and use environments, walk the task sequence, identify the hazard-related use scenarios, and then let those scenarios generate design inputs. A device where an electrode can be applied in reverse orientation is a design input problem — the connector should be keyed — not a training problem to be solved in the IFU.
Verification and Validation Answer Different Questions
The distinction is old and still routinely collapsed in practice.
Verification asks: does the output meet the input? It is a specification-conformance activity. Bench testing, EMC per IEC 60601-1-2 Ed. 4.1, electrical safety per IEC 60601-1, biocompatibility per ISO 10993-1:2018, software unit and integration testing per IEC 62304 — these are verification.
Validation asks: does the device meet the user's needs in the intended use environment? It requires initial production units or their equivalents, real users, and realistic conditions. A clinical validation on engineering prototypes built by the R&D team is not validation; it is an expensive rehearsal.
When teams treat validation as "more verification with patients," they generate evidence that satisfies no regulator and predicts no field behaviour. A device can pass 100% of its verification protocols and still be recalled, because the protocols only ever tested the assumptions that were wrong in the first place.
Design Freeze Is an Economic Decision, Not an Engineering One
The cost of a change is a function of how much downstream work depends on it. Before design freeze, a requirement change costs a discussion. After design freeze, the same change may require:
- Re-verification of affected requirements and any requirement coupled to them through the traceability matrix
- Re-execution of biocompatibility or sterilisation validation if materials or processes shifted
- Tooling modification or replacement, which for a multi-cavity injection mould is a capital event with a lead time measured in months
- Regulatory impact assessment, and potentially a new submission if the change affects safety or effectiveness relative to the cleared device
None of this argues for freezing early. It argues for spending disproportionate effort on inputs, so that the freeze holds.
Where Design Programmes Commonly Break Down
Traceability built at the end. A traceability matrix assembled retrospectively to satisfy an auditor documents what happened; it does not control anything. Built forward, it tells you within minutes which verification protocols a proposed change invalidates. That single capability changes how a team makes decisions under schedule pressure.
Risk analysis kept separate from design. When the risk file lives in the quality department and the design lives in engineering, risk controls stop being design features and become labelling statements. Regulators have become notably less tolerant of this. Under the FDA's Quality Management System Regulation, effective 2 February 2026, early inspection data shows management oversight and risk management integration emerging as dominant citation areas.
Testing to pass rather than testing to learn. The most valuable early tests are the ones designed to break the device and reveal where the model of its behaviour is wrong. Protocols written to demonstrate success generate a clean report and no information.
Deferring manufacturability. A part prototyped by CNC machining may have geometry that cannot be injection moulded without redesign — draft angles, wall thickness transitions, undercuts, gate location driving weld lines through a sealing surface. Discovering this after design freeze converts a design decision into a tooling loss.
The Honest Framing
Design controls are frequently taught as a compliance framework. They are better understood as a structured argument that the device will work — inputs are the premises, outputs are the claims, verification checks the logic, validation checks the premises against reality, and the design history file is the written record of the argument.
Recall data suggests the industry is generally competent at the logic and weak at the premises. Fifty-five percent of the most serious recalls trace back to design not because engineers cannot engineer, but because the question they were engineering an answer to was framed incompletely, early, by people under time pressure, before anyone knew enough to frame it well.
The remedy is not more documentation. It is spending more of the programme's scarce early attention on the requirement set, and treating every subsequent change to it as information about how well that work was done.
RhythmRx develops Class II and Class III devices under ISO 13485 design controls, with requirement definition, use-related risk analysis, and verification planning treated as a single connected activity from the first phase gate.
Karthik Raghavan is a Principal Design Engineer at RhythmRx, working on design control architecture, requirements definition and verification planning for wearable cardiac monitoring devices.
Sources
- Characterization of US FDA Class I Recalls for Moderate- and High-Risk Medical Devices, Medical Devices: Evidence and Research (Dove Press) — analysis of 189 Class I recalls, January 2018–June 2022.
- Sedgwick, 2025 US State of the Nation Recall Index — 1,059 US device recall events in 2024.
- 21 CFR 820.30 (Design Controls); FDA Quality Management System Regulation, effective 2 February 2026.
- ISO 13485:2016 clause 7.3; ISO 14971:2019; IEC 62366-1:2015+A1:2020; IEC 62304; IEC 60601-1, 60601-1-2 Ed. 4.1, 60601-1-11, 60601-2-47; ISO 10993-1:2018.