United States (MoCRA)

Setting Up a MoCRA Adverse Event Log That Works

The fields and workflow for a compliant complaint and adverse event log under MoCRA, buildable in a spreadsheet.

Diane R.4 min read

You don't need software to do this right. A well-built spreadsheet, used consistently, satisfies the recordkeeping intent behind MoCRA's adverse event requirements better than an expensive system nobody actually updates. The trick is getting the fields right from the start so you're not restructuring the log after you already have entries in it.

What MoCRA actually asks of you here

MoCRA, the Modernization of Cosmetics Regulation Act, requires a named responsible person, safety substantiation for your products, and adverse event recordkeeping, alongside facility registration and product listing with the FDA (some small businesses are exempt from the registration and listing pieces, though the responsible person and recordkeeping expectations still matter). The recordkeeping side means that when someone reports a bad reaction to your product, you need a documented process for capturing it, evaluating it, and keeping the record.

This isn't about proving your product is guilty of anything. It's about being able to show, if ever asked, that you take reports seriously and handle them consistently.

The fields your log actually needs

Field Why it matters
Date received Establishes your response timeline
Reporter name and contact info Lets you follow up for more detail if needed
Product name and lot/batch number Ties the report to a specific manufacturing run
Description of the event in the reporter's own words Avoid summarizing or softening at intake, capture what they actually said
Date of the event (if different from report date) Some reports come in weeks after the reaction occurred
Body location and symptoms Rash, swelling, breathing difficulty, and so on
Whether medical attention was sought Relevant to how the event gets classified
Your response and any follow-up What you told the reporter, whether you asked for a photo or more detail
Internal evaluation notes Did you check the batch record, did you review the formula against the complaint
Resolution and date closed Keep the loop visibly closed, not just abandoned

Keep the reporter's original words in a dedicated column, even if you also write a cleaned-up internal summary elsewhere. Rephrasing at intake risks losing detail that matters later.

The workflow, not just the spreadsheet

A log with empty rows waiting to be filled in isn't a process, it's a hope. The workflow around it matters just as much:

  1. Every channel funnels to one place. Website contact form, email, social media DM, a note passed along by a retailer, all of it needs to land in the same log, not scattered across whoever happened to see the message first.

  2. Someone owns intake. Even in a one-person operation, decide explicitly that you check for new reports on a set cadence, not "whenever I remember."

  3. Severity gets a quick first pass. A comment about scent fading over time is not the same as a report of a burning sensation or swelling. You don't need a formal severity scale to start, but a serious event should prompt faster follow-up than a mild one.

  4. Batch records get pulled for anything serious. If your batch documentation is solid, this step takes minutes. This is one of the clearest places where good manufacturing habits like the ones under general GMP guidance for cosmetics pay off directly.

  5. Keep it, don't purge it. Old entries are the record. Resist the urge to delete resolved complaints once they're closed. Archive them, but keep them.

What "serious" changes about the process

A report involving something like a significant or persistent health effect deserves a faster, more careful path than a report of mild dryness. That doesn't mean building two separate systems. It means your intake step should flag serious events for immediate attention rather than letting them sit in a queue with routine ones. A simple flag column, marked at intake, does this without adding complexity.

Where this fits with everything else

An adverse event log isn't a replacement for safety substantiation, which is a separate piece of what a responsible person needs to have in place, and it isn't a replacement for facility registration and product listing where those apply to your business. It's one piece of a small set of obligations that work together. But it's the piece most likely to get skipped by a small brand because it feels like paperwork for a problem that hasn't happened yet.

If you're also managing Canadian filings alongside your US obligations, it's worth knowing that Cosmetic Comply's Canada filing flow already asks for the ingredient and concentration detail that overlaps with what you'd want on hand for any US safety substantiation file, so building one clean internal record set tends to serve both markets rather than needing entirely separate systems. For the specifics of what MoCRA currently requires for your business size and product type, the FDA's own MoCRA guidance is the right place to confirm the exact obligations that apply to you.

READY TO FILE?

Send your ingredients and we take it from here

A short intake form is all it takes to start. Every ingredient gets checked against your market's prohibited and restricted lists, then we file your notification and hand you a number you can track.

Start a filing

Keep reading