my $0.02 is that there is no 'correct' sample size, but the assurance level you select (which can then be used to set a sample size whether you use attribute or variables measures) must be risk based. So if you didn't establish that the assurance levels (i.e. sample sizes) you use are laid out in your QMS policy are risk based, you'll never get the thumbs up from the regulator. Another way to make this point is you could have tested a million parts and they FDA would still reject you if you don't demonstrate the assurance level necessary to pass was a risk-based decision.
A risk based decision means you've categorized the risk associated with non-compliance and then used that risk categorization as an input to your decision. This is normally reflected in a policy where the risks are categorized (typically in the dimensions of occurrence and severity) and then based on those categories a requisite assurance level is established.
If people want to demonstrate true understanding of this aspect of risk management they need to start using the words 'assurance level' where they typically use 'sample size', because what you really need is an assurance level, sample size can only be discussed once you establish a method of analysis, its can't be established before the method is defined. Your QMS should be method agnostic and thus should dictate assurance level not sample size.
A risk based decision means you've categorized the risk associated with non-compliance and then used that risk categorization as an input to your decision. This is normally reflected in a policy where the risks are categorized (typically in the dimensions of occurrence and severity) and then based on those categories a requisite assurance level is established.
If people want to demonstrate true understanding of this aspect of risk management they need to start using the words 'assurance level' where they typically use 'sample size', because what you really need is an assurance level, sample size can only be discussed once you establish a method of analysis, its can't be established before the method is defined. Your QMS should be method agnostic and thus should dictate assurance level not sample size.