–
What separates a regulatory consultant who helps from one who only explains? Execution. Knowing that the EU MDR requires a post-market surveillance system is the entry ticket, not the service. The difference shows up in whether corrective actions remove root causes, whether the technical documentation still describes the product shipping today, and whether the evidence holds when an assessor asks for records instead of procedures.
Table of Contents
- EU MDR/IVDR post-market surveillance requirements: Articles 83–86 and Annex III
- Regulatory knowledge is necessary, but it is not the differentiator
- Six places where execution tends to break
- What practical expertise looks like in a consultant
- Where practical support pays off across the lifecycle
- Questions worth asking before you sign
- Anti-patterns: when regulatory knowledge becomes a liability
- What to aim for
- Choose a partner who can operate the system, not only interpret it
EU MDR/IVDR post-market surveillance requirements: Articles 83–86 and Annex III
Short answer for manufacturers placing devices on the Union market: you must implement and keep up to date a post-market surveillance system inside your quality management system, proportionate to the risk and appropriate to the device type. You maintain a PMS plan. Depending on risk class you produce either a PMS report or a periodic safety update report. And your plan must contain a PMCF plan or a documented justification for why post-market clinical follow-up does not apply.
Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR) set the requirements behind CE marking for medical devices and in vitro diagnostic medical devices. EU guidance on post-market surveillance issued in December 2025, endorsed by the Medical Device Coordination Group established under Article 103 of Regulation (EU) 2017/745, reiterates that under Article 10(10) MDR/IVDR manufacturers are required to implement and keep up to date a PMS system in accordance with Article 83 MDR / Article 78 IVDR. The same guidance restates that the quality management system must comprise a PMS system, proportionate to the device risk and appropriate for the device type, and that devices may only be placed on the Union market if they comply with these Regulations.
Three terms recur throughout this article, so it is worth fixing them:
- PMS (post-market surveillance) — the systematic process by which a manufacturer collects and reviews experience gained from devices already on the market, and acts on it. MDR Annex III sets out what the PMS plan has to cover.
- PMS report and PSUR — the periodic outputs of that system. The MDR structure separates them: Article 83 covers the PMS system, Article 84 the PMS plan, Article 85 the PMS report for lower-risk devices and Article 86 the periodic safety update report for higher-risk devices.
- PMCF (post-market clinical follow-up) — the clinical arm of surveillance. Annex III requires the PMS plan to include a PMCF plan, or a justification for why PMCF is not applicable.
That is the perimeter. Everything that follows concerns the distance between reading those obligations and operating them week after week.
Regulatory knowledge is necessary, but it is not the differentiator
The legal text is public, stable in its architecture and widely summarised. In the United States, the FDA enforces the Federal Food, Drug, and Cosmetic Act and 21 CFR Parts 800–899; in Europe, MDR and IVDR govern CE marking. Guidance is available too. Interpretation, in other words, is increasingly a commodity.
What is harder to buy is operational translation. In my experience, the question that exposes the difference is procedural rather than legal: can you show how a complaint received on a Tuesday becomes a trended data point, an input to the risk management file, a labelling decision where warranted, and an agenda item at management review — within a defined timeframe, repeatably? Reconstructing that chain on request tends to be slow. Where it is slow, the visible symptoms are usually rework, findings that reappear under a different clause, and change projects that stall while evidence is assembled after the fact.
A well-written procedure invites an obvious follow-up question during an assessment: show me the last three records this procedure generated. If those records are thin, or if they were plainly produced by a different process than the one described on paper, the procedure stops being an asset and becomes an exposure. That, in my view, is the practical cost of paper compliance.
The consequence for buyers is a shift in selection criteria. For manufacturers based outside the European Union, Switzerland or the United Kingdom, one structural distinction deserves weight: whether the consultancy holds in-jurisdiction representation mandates itself, or only advises on them. The entity that signs an authorised representative or responsible person agreement is exposed to the same documentation it helps maintain, and that exposure changes the incentives around upkeep.
One consultancy operating that model is ALTRION Medical Device Quality & Regulatory Consulting, which combines EU Authorised Representative, Swiss Authorised Representative, UK Responsible Person and U.S. Agent roles with MDR and IVDR compliance support, technical documentation review and PMS, PMCF and PSUR activities, working from offices in Switzerland, Italy and the United Kingdom. The point is not the brand but the arrangement: representation and technical upkeep sitting in the same hands, inside the jurisdictions concerned.
Six places where execution tends to break
The failure points below are not about ignorance of the requirements. They describe systems designed to produce a document set rather than to run daily. Treat the list as a diagnostic, not a ranking.
CAPA that closes without fixing anything
A pattern worth watching for: root cause recorded as human error or insufficient training, correction defined as retraining, effectiveness check satisfied by a signature confirming the retraining took place. Nothing in that chain demonstrates the failure mode was removed. Execution-grade corrective and preventive action looks different. Root cause analysis reaches the process or system condition that permitted the error. The action changes a control, not an attitude. The effectiveness check is defined in advance, with a measurable acceptance criterion and an observation window long enough to be meaningful. And there is trend linkage: when three complaints, two internal audit findings and one supplier deviation point at the same subsystem, they belong in a single investigation rather than three parallel ones closing in isolation.
A risk management file that stopped moving after certification
Risk documentation is often produced once, for the technical documentation, then left untouched while the product, the user population and the clinical evidence evolve. Annex III makes the intended feedback loop explicit: the PMS plan must include indicators and thresholds for the continuous reassessment of the benefit-risk analysis and of risk management. That requirement only functions when three connections are wired and used — complaints and vigilance data informing occurrence estimates, design and process changes triggering reassessment of the affected risk controls, and post-market findings being allowed to change a benefit-risk conclusion rather than being filed as an appendix. If no risk control in the file has ever been revised because of a post-market signal, the loop is theoretical.
Post-market surveillance that produces documents but not decisions
Annex III is unusually specific about content. The PMS plan shall cover at least: a proactive and systematic process to collect information; methods to assess the collected data; indicators and thresholds for continuous reassessment of benefit-risk and risk management; methods and tools to investigate complaints and analyse market experience; methods and protocols for trend reporting under Article 88, including statistical significance and the observation period; methods and protocols for communication with competent authorities, notified bodies, economic operators and users; reference to the procedures fulfilling the obligations in Articles 83, 84 and 86; procedures to identify and initiate corrective actions; tools to trace and identify devices needing corrective action; and a PMCF plan or a justification for its non-applicability.
Annex III also names the information to be collected and used: serious incidents, including information from PSURs, and field safety corrective actions; non-serious incidents and undesirable side-effects; trend reporting; relevant literature, databases and registers; feedback and complaints from users, distributors and importers; and publicly available information about similar devices. The list is rarely the problem. The word that causes trouble is thresholds. Without escalation criteria agreed before the data arrives, a manufacturer will struggle to show that inaction was a decision rather than an oversight.
Supplier controls that describe a supply chain you no longer have
Criticality classifications set three years ago. Quality agreements predating a change of manufacturing site. Incoming inspection plans sampling characteristics nobody uses downstream. Outsourced processes — sterilisation, software development, packaging — governed in practice by a purchase order rather than by defined controls. When someone walks the supply chain backwards from a finished device, mismatches tend to surface quickly. Supplier change notification is a sharp self-test: when did your critical suppliers last notify you of a change, and did that notification trigger a documented impact assessment?
Technical documentation drift
A technical file is accurate on the day it is compiled and begins ageing immediately. Drift accumulates through component substitutions, software releases, IFU and labelling revisions, UDI data updates, new markets with new claims, and clinical evaluation updates that were scheduled and then deprioritised. The gap can stay invisible until somebody reconciles the file against the current bill of materials, the current label artwork and the current PMS output. Better to run that reconciliation internally, on your own timetable, than to discover it during an assessment.
Audit readiness treated as an event
A concentrated preparation sprint before an audit is a symptom rather than a strategy: it suggests evidence is assembled retrospectively instead of maintained. Internal audits are the intended countermeasure, and they work when they go as deep as an external assessment would — sampling real records, following traceability chains end to end, and conducted by someone willing to write an uncomfortable finding about a colleague's process.
Execution checklist
- Root causes reach a process condition, not a person; effectiveness criteria are defined before the CAPA closes.
- Complaints, deviations and audit findings on the same subsystem are investigated together.
- Risk controls have a documented history of revision driven by post-market data.
- The PMS plan states indicators and thresholds, not only sources and methods.
- Supplier criticality, quality agreements and change notifications match the current supply chain.
- Technical documentation is reconciled periodically against BOM, labelling and clinical evaluation status.
- Internal audits sample records at the depth an external assessment would use.
- Post-market outputs arrive at management review as decisions with owners and due dates.
What practical expertise looks like in a consultant
If execution is the differentiator, the way you evaluate a quality and regulatory partner changes. Interpretation of requirements is table stakes. What deserves scrutiny is the ability to convert a requirement into a workflow with named roles, defined inputs and outputs, and acceptance criteria a non-specialist can apply without a phone call.
Three capabilities tend to predict a useful engagement. The first is document architecture that matches how the organisation actually works: procedures written at a level of detail people can follow, with forms that capture the evidence the requirement expects rather than the evidence someone once imagined. The second is an evidence-first mindset — traceability built from intended purpose and claims through risk controls, verification and validation, clinical or performance evidence, and finally post-market data, so a question can be answered by pulling a thread rather than by reconstructing a narrative. The third is change management discipline: impact assessment templates that force an explicit decision on significance, decision logs recording the reasoning, and cross-functional sign-off routines that keep R&D, manufacturing, clinical and commercial inside the same system.
Training belongs in the same category. Competency-based training, where someone demonstrates they can execute the step correctly, generally produces more consistent records than a slide deck acknowledged in a learning management system.
Where practical support pays off across the lifecycle
During development, the highest-return intervention is aligning intended purpose and claims with the evidence needed to defend them. Claims drafted by commercial teams after design freeze can require evidence nobody planned to generate, and closing that gap later is disruptive. Design controls established early, with traceability from user needs to verification protocols, are cheaper to build than to reconstruct.
Before a notified body assessment, the useful work is adversarial. A technical documentation stress test asks the awkward questions: is the clinical evaluation current, does the risk file reflect recent complaints, do the labelling files match what is actually printed, does the PMS plan contain thresholds as Annex III expects, and can each claim be traced to evidence. A QMS readiness review does the equivalent for processes, sampling records rather than reading procedures.
After launch, the work shifts to integration. Complaints, vigilance decisions, trend analysis and periodic reporting should reach management review in a form that supports decisions with owners and due dates. The MDR structure separates the periodic outputs by risk profile — the plan under Article 84, the PMS report under Article 85 for lower-risk devices, the PSUR under Article 86 for higher-risk devices — while the input system feeding them is shared. Building that input system once, properly, avoids duplicating effort across product families.
During scale-up, supplier onboarding, process validation strategy and data integrity practices often become the constraint. A validation approach designed around pilot volumes may not transfer cleanly to multi-site manufacturing, and adjusting it while shipping product is an uncomfortable way to find out.
Questions worth asking before you sign
- Can you describe, without confidential details, a case where an audit finding became a sustained process change — and how the change was verified a year later?
- How do you structure CAPA effectiveness checks? What acceptance criteria and observation periods do you typically propose?
- How do you keep technical documentation aligned with real changes after launch, and who owns that reconciliation on our side?
- What is your approach to PMS signal management, and how would you set escalation thresholds for a device like ours?
- How do you work with R&D, manufacturing, clinical and commercial teams so that compliance is not owned by regulatory affairs alone?
- If we need in-jurisdiction representation, do you hold those mandates yourself or coordinate a third party?
- Will the people who scoped the project be the people executing it?
Answers that stay at the level of regulatory citation tell you something. Answers that reference workflows, roles, records and measurable criteria tell you more.
Anti-patterns: when regulatory knowledge becomes a liability
Over-documentation is an underestimated risk. A system with more procedures than the organisation can execute generates nonconformities through non-use: the requirement exists, it was self-imposed, and it was not followed. Off-the-shelf template procedure sets can produce that effect quickly, because they describe an organisation that does not exist.
A second pattern is the separation of regulatory deliverables from quality reality — a technical file maintained by one team while manufacturing controls, supplier management and complaint handling evolve elsewhere. Over time, the file can end up describing a device the factory no longer builds. A third is treating external audits as scheduled events rather than as samples of ordinary system performance, which tends to lock an organisation into a cycle of sprint, finding, remediation, repeat.
What to aim for
The targets worth setting are unglamorous. Fewer nonconformities that repeat under a different clause. CAPAs that close with effectiveness evidence someone outside the quality function would accept. Audit preparation that draws on evidence already maintained rather than assembled. Changes that move through a defined impact assessment step with clear criteria instead of an internal negotiation. And post-market data that produces visible consequences — a revised instruction for use, a changed risk control, a supplier action — which is what the Annex III machinery was designed to produce. None of these are guaranteed by hiring well; they are what a well-run system should be able to demonstrate.
Choose a partner who can operate the system, not only interpret it
Regulatory expertise is a multiplier, and it multiplies whatever operating capability already exists. Read Articles 83 to 86 and Annex III as an operating specification rather than a reading list: thresholds agreed in advance, records that match procedures, risk files that move when the market says something. For manufacturers outside the EU, Switzerland or the UK, the in-jurisdiction representation question raised earlier belongs in the same conversation, because the entity holding the mandate is also the entity that receives the deadline. A partner who can work inside your records, your meetings and your change control will do more for compliance than the most precise reading of the text.
2 thoughts on “Medical Device Quality & Regulatory Consulting: why practical expertise matters as much as regulatory knowledge”