I get this question every few months: "Can we ship tomorrow?" Usually it's asked with a sales deadline, a customer promise, or a production line breathing down everyone’s neck. My honest answer is almost always the one people do not want to hear: not until I spend three days checking five different systems.
To be fair, the question is reasonable. Leadership wants a single, reliable yes/no. The problem is that at too many small and mid‑size medtech firms that single number is not a single data point — it's a scavenger hunt.
What I actually have to check (and why it’s slow)
A compliant release isn't just "has the box been packed". In practice this means confirming a handful of gating items that live in different places:
- Design verification/validation artefacts (PLM or shared drive)
- Risk status and outstanding mitigation actions (risk register, sometimes a spreadsheet)
- Change control state affecting the batch or lot (eQMS change module or emails)
- Supplier nonconformances and material certificates (ERP / supplier portal)
- Batch records, test reports and the Device History Record (manufacturing system / lab LIMS)
- Regulatory status: CE certificate validity, notified body open actions, and EUDAMED/registration details
Each of those is a legitimate regulatory concern. Annex II of the MDR requires a complete technical file and traceability between design, risk and verification. The notified body will ask for the same things during audits. The trouble is, every one of those records can be in a different system and – worse – be represented differently.
Why this is a process problem, not an IT problem
People often propose "put everything in one system" as the panacea. Granted, single‑vendor solutions can help, but the root cause is operational:
- Missing release criteria: nobody has clearly documented what “ship” means for each device and each regulator.
- Data without links: the risk register references a change control number that lives only on a PDF; test reports reference a drawing revision that isn’t tagged in PLM.
- No release owner: there is no single accountable person who can say "I confirm these five things".
- Manual, brittle workflows: document reviews, CAPAs and supplier clears are often ad hoc emails or spreadsheets.
Those lead to the three‑day digging exercise. It’s not that the data doesn’t exist; it’s that it isn’t connected, reviewable and traceable at the moment of decision.
What to do when leadership asks “now” — a practical triage
You cannot conjure the perfect system overnight. You can, however stop lying and give leadership a reliable, actionable answer.
Step 1 — short, honest status in 10 minutes:
- "I cannot approve shipment right now. I need X hours to confirm items A, B and C. The likely blockers are supplier certificates and the pending change control."
Step 2 — a 3‑point, 72‑hour plan (what I actually do):
- Hour 0–4: Confirm owner and assign responsibilities for each gate (DHR, risk, change, supplier).
- Day 1: Pull the most recent test reports and the batch record; validate signatures and revision numbers.
- Day 2: Reconcile change control and supplier certificates; escalate any deviations as a hold and open CAPA if needed.
- Day 3: Final review and issue release or formal hold.
Step 3 — keep leadership informed with one canonical status update at the end of each workday.
This is not heroic. It’s disciplined. It also makes the decision auditable later.
Fixes that stop the three‑day scramble — practical, not theoretical
If you want to push the organisation to a point where “can we ship tomorrow?” is a quick, accurate question, start with these concrete items:
- Define release criteria per device and per regulatory market. Make these checklists official and bind them into change control and batch release workflows.
- Assign a release owner role for each product line (not "QA desk"). That person is accountable for the single number.
- Stop treating traceability matrices as static documents. Build living links between risk, design, verification and manufacturing records so a reviewer can follow the chain fast.
- Integrate risk management into project management. When RM lives in the same lifecycle view as design and change control, you get traceable history — less detective work when a shipment decision is due.
- Make the QMS usable: native workflow integration, connected workflow, and reviewability are what matters. Controlled assistance (e.g. AI‑assisted suggestions for CAPA categorisation) can help, but only where the decision path remains reviewable and auditable.
- Validate the tooling you rely on. If your eQMS is a device for decisions, it should be validated per appropriate guidance (for example, ISO/TR 80002‑2 for QMS software validation) so you can trust the automation and outputs.
Low‑hanging wins are often cultural: a brief daily stand‑up with the release owner, a standardized release checklist, and a guaranteed 24–72 hour “can we ship” SLA.
Auditability and business outcomes
Fixing this is not purely about speed. It reduces audit stress, lowers the risk of non‑conforming shipments, and makes notified body interactions far less stressful. The day you can hand an auditor a single release record that traces back to the risk register and the DHR is the day you stop doing forensic work for routine releases.
To be fair, implementing these changes requires investment and discipline. But the cost of continuing to treat one number per device per regulator as a research project is paid in delays, customer dissatisfaction, and ultimately regulatory risk.
What’s the single data point in your company that takes the longest to verify before a shipment — and why does it still live in three different places?
Top comments (0)