I work on CE marking submissions and Technical Files for Class IIa/IIb devices. For the last few years my inbox has been full of audit findings that boil down to the same basic issue: the manufacturer "had control" on paper, but the organisation didn't use it. Control is necessary — Article 10 and Annex II of the MDR make that clear — but control is not an end state. The real win is turning control into reliable day-to-day practice.
What I mean by "control"
Control starts with the fundamentals people expect:
- A defensible QMS (ISO 13485-aligned, per Article 10 obligations).
- Versioned Technical Files and traceable design history.
- Formal change control and CAPA processes.
- Defined roles and responsibilities for release, post-market surveillance and clinical follow-up.
To be fair, most small and mid-size teams get those boxes ticked. They have SOPs, a labelled folder structure, and a change form template. Auditors see those documents and say "good" — until they start sampling records.
Where "control" fails in practice
Here are the common failure modes I see in audits and internal reviews:
- Documents exist but are not followed. The procedure for change control is clear — the engineering team simply ignores the change impact step because "it's a minor tweak."
- Traceability is fragmented. Design files, supplier records, and risk assessments live in different systems with no reliable links. Annex II expects coherent documentation; fragmented data fails the intent.
- CAPAs are reactive and siloed. CAPA owners write a corrective action but don't map it back to the risk register or the Technical File. The action closes; the root cause wasn't addressed.
- Post-market data doesn't feed the design process. PMCF and vigilance reports sit with RA; engineers never see the trends that should trigger a risk control change.
Put bluntly: control on paper but not in daily workflows equals systemic risk. Notified bodies pick this up quickly, and so will competent authorities if a safety issue emerges.
How I translate control into daily practice
Turning control into habit is a programme, not a project. Here are the practical steps I've used that actually move the needle.
-
Make traceability a working feature, not a checkbox
- Establish a single source for device identifiers, risk items, and requirements. Link design outputs directly to risk controls and verification records.
- Use the links during design reviews and change assessments — if a change touches a linked item, the workflow must escalate.
-
Design change control as governance, not overhead
- Require a structured impact assessment for every change. Keep it short, focused, and mandatory.
- Train engineering to treat the impact assessment as a tool that reduces rework, not as paperwork. Show examples where impact mapping saved effort downstream.
-
Push CAPAs into daily workflows with connected workflow
- CAPA owners should get automated prompts, evidence requests, and reviewer assignments in the same system where the issue was raised.
- Automate low-risk CAPA routing and visibility; escalate higher-risk CAPAs to multi-disciplinary review automatically.
- Use traceable links so every CAPA references the affected design outputs, suppliers, and vigilance records.
-
Close the loop between post-market and design
- Embed PMCF outputs and complaint trends into sprint planning and backlog grooming.
- Require every design change triggered by post-market data to reference the original report and the risk assessment update.
-
Keep reviewability and audit trails simple and honest
- Ensure every decision, signature, and review has a clear rationale attached. Reviewability is not merely for auditors — it protects teams during product investigations.
- Prefer controlled assistance (templated language, guided forms) over free-text fields that produce opaque notes.
-
Use automation wisely — not as a substitute for judgment
- Automated CAPAs and AI-assisted triage can reduce manual triage time. Use them to surface likely root causes and recommended evidence, but keep human review as the control point.
- Automation must be configured so evidence and rationale are captured, not hidden.
Culture and governance
You can implement every workflow, but if culture resists, it will fail. Practical moves that help:
- Make compliance decisions visible in team forums.
- Recognise and reward engineers who close the loop on feedback from PMCF or complaints.
- Run "what-if" exercises where a minor change is traced end-to-end to show how control prevents surprises.
Granted, smaller teams have limited bandwidth. Prioritise: start with the processes that touch patient safety and regulatory obligations first (design change, CAPA, complaints, post-market surveillance). Deliver quick wins to build credibility.
Final thought
Control is the foundation; daily practice is the building. Annex II and Article 10 demand evidence of control, but auditors and patients both benefit when control becomes the way people work. Practically, that means shifting from document-centric compliance to workflow-centric quality: traceability that is used, CAPAs that are connected, change control that actually changes behaviour.
How have you successfully moved a paper procedure into daily practice in your organisation — what practical change made the biggest difference?
Top comments (0)