BATCH-1844 · filed

Regulation & Compliance

FDA Draft Guidance Details MoCRA Records Access Powers

FDA draft guidance on MoCRA Sections 605 and 610 details records access for adverse events and SAHCOD threats, with comments open until March 23.

By Sophie Lindqvist · · 5 min read · 959 words

Composition

  1. MoCRA Sections 605 and 610 give the FDA authority to access and copy cosmetic records; draft guidance details the scope, with comments due March 23.
  2. Adverse event records must be retained six years (three for qualifying small businesses) and cover reporter communications, seriousness assessments, and follow-up reports.
  3. Refusing records access is a prohibited act under FDCA Section 301(e), exposing companies to injunctions, criminal prosecution, and import refusal.

The FDA has issued draft guidance spelling out how it will use its new MoCRA-given authority to access and copy cosmetic industry records — and comments close on March 23, giving formulators, responsible persons and facility operators a narrow window to push back before the agency finalizes its expectations.

The Modernization of Cosmetics Regulation Act (MoCRA) added Sections 605 and 610 and amended Section 704 of the federal Food, Drug, and Cosmetic Act (FDCA), creating new records access authorities for cosmetics. The draft guidance, now open for comment, addresses who is subject to record access requirements, when the FDA may act, retention periods, confidentiality protections, and what happens if a company refuses to hand over records.

Section 605: Adverse event records

Under FDCA Section 605 (21 U.S.C. § 364a), the FDA can access records related to cosmetic adverse event reports during an inspection. The authority applies to the "responsible person" — the manufacturer, packer, or distributor whose name appears on the product label.

Within the scope of a Section 704 inspection, records for each adverse event report received by a responsible person and associated with use of a cosmetic product in the United States must be available to the FDA. The types of records covered include communications between the responsible person and the individuals who reported the event, the responsible person's assessment of whether the event was serious or non-serious, and for serious events, the report submitted to the FDA along with attachments, new material medical information, and follow-up reports.

Retention rules are concrete: six years after creation in paper or electronic format, or three years for small businesses that do not manufacture or process certain cosmetic products under Section 612(b). Compliance teams should map these periods against current document management policies now.

Section 610: SAHCOD threats

Section 610 (21 U.S.C. § 364f) is the broader and more disruptive authority. If the FDA has a reasonable belief that a cosmetic product, an ingredient, or a product likely to be affected in a similar manner is adulterated such that use or exposure presents a threat of serious adverse health consequences or death (SAHCOD), the agency can access and copy all needed records. Unlike Section 605, this power reaches both responsible persons and cosmetic facilities.

Access requires appropriate credentials and written notice, and must occur at reasonable times, within reasonable limits, and in a reasonable manner. But the scope of records is wide: manufacturing records, raw materials receipt records, product distribution and inventory records, raw ingredient and finished product analytical results, recall records, customer distribution lists, complaint and adverse event records, and safety substantiation records. The FDA may request records in any format and at any location — a recognition that many companies store documentation off-site from where covered activities take place.

There are carve-outs. The authority does not extend to recipes or formulas for cosmetics, financial data, pricing data, personnel data (beyond qualifications of technical and professional personnel performing FDCA-subject functions), research data (other than safety substantiation data), and sales data (other than shipment data regarding sales).

When SAHCOD requests will trigger

The FDA says Section 610 requests are most likely after product recalls, adverse event reports, consumer complaints, or inspections and sampling revealing SAHCOD-threatening conditions. The draft guidance lists examples of vulnerabilities: microbial contamination with pathogens such as Burkholderia cepacia, Pseudomonas aeruginosa, Serratia marcescens, or Staphylococcus aureus; contaminated tattoo inks; unsafe levels of heavy metals such as lead or cadmium; Benzimidazole pigments that may cause allergic reactions; and nail products containing toxic solvents or contaminated applicators. Design-or-use vulnerabilities — cosmetic forms that cause unintended contact with eyes or allow systemic exposure — and improper storage, distribution, or labeling also make the list.

Critically for manufacturers, the FDA interprets "likely to be affected in a similar manner" expansively. A product may fall within scope if it was made at the same time, location, or on the same equipment without adequate controls; uses the same or similar ingredients, containers, or closures; was manufactured in proximity without proper separation; is affected by systemic deficiencies in sterilization, preservation, pH adjustment, microbial testing, or labeling controls; or uses raw materials, ingredients, or packaging from the same supplier that sourced contaminated or defective inputs. That last point means a single supplier failure can pull an entire portfolio into a records request.

Confidentiality and enforcement

The FDA states it will comply with all protections against unauthorized disclosure of non-public information, governed by the Trade Secrets Act, the FDCA, the Freedom of Information Act, and the agency's disclosure regulations at 21 C.F.R. Part 20. Agency officials may disclose certain non-public information to other federal, state, local, or foreign government officials, or FDA contractors, if conditions are met.

Refusal carries real teeth. Denying access to or copying of records under Sections 605 or 610 is a prohibited act under FDCA Section 301(e) (21 U.S.C. § 331(e)), as is failing to establish or maintain adverse event records or failing to file required reports. The FDA can bring civil actions in federal court to enjoin violators and criminal actions to prosecute them. For imports, the agency may refuse admission of cosmetic products if it has credible evidence the responsible person blocked records access or otherwise failed to comply with Section 605.

For industry, the operational to-do list is clear: review recordkeeping policies against the retention periods, verify that adverse event files — including reporter communications and seriousness assessments — are inspection-ready, and audit manufacturing and supply chain documentation so the company can respond quickly if a SAHCOD request lands. The comment deadline of March 23 is the next fixed date to watch; the finalized guidance, and the first enforcement actions under it, will follow.

via fda.gov (Original)

Filed under

  • mocra
  • fda
  • regulatory-compliance
  • adverse-events
  • records-access

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

Market editor covering marketplaces and e-commerce at INCI File.

78 articles

Cross-references · Related articles

« Previous articleNext article »

End of monograph · 5 min read