DEV Community

Rajiv Iyer
Rajiv Iyer

Posted on

The change takes 30 minutes, the impact analysis takes 3 days — that's the part AI actually helps

A change request landed on my desk last Tuesday from one of our OEM customers. They wanted to swap a polymer supplier in their bill of materials for a Class IIb device we assemble. The actual change to our incoming inspection procedure? Thirty minutes, maybe forty. Rewriting the sampling tables, updating the inspection plan, briefing the line inspector.

Three days. That's how long the impact analysis took. Three days of me cross-referencing:

  • Which other SKUs from the same OEM use that polymer
  • Which of our other 40+ suppliers make parts that share a sub-component affected by the change
  • Which open CAPAs currently reference incoming inspection for that material
  • Which validation protocols would need re-running
  • Whether the supplier's COA format still maps cleanly to our records

Two weeks. That's how long the documentation took after that — compiling the change record, getting it reviewed, routing it through e-signatures, archiving the supporting evidence, updating the affected controlled documents.

Thirty minutes of technical work. Three days of impact analysis. Two weeks of documentation.

The middle part is where CMOs bleed time

If you've worked at a device OEM, your change control probably looks different. Smaller supplier base, more contained scope, fewer interfaces between changes. The bottleneck tends to be the review cycle, not the impact analysis.

At a CMO, the bottleneck is impact analysis. Every change ripples. A polymer swap from one OEM affects nothing for another OEM — except when they share a sub-tier supplier, which happens more often than you'd think. We have two OEMs using parts from the same injection moulding shop in Coimbatore. When that shop changes their tool steel, we have to reason across both customer programmes at the same time.

The 3-day impact analysis isn't laziness. It's the work of holding the right facts in your head at once: device classification under MDR, ISO 13485 clauses affected, validation status, the current state of every affected document, every related CAPA, every supplier qualification that touches the changed item.

What AI impact mapping actually does

I'm sceptical of AI-in-QMS marketing generally. Most of it is autocomplete dressed up as intelligence. But there is a narrow, defensible use case for controlled assistance in change control: mapping the impact surface.

When a change lands, the AI can pull every related document, CAPA, validation, and supplier record in seconds. It does this because those records already exist in your eQMS — the AI just makes the cross-reference query practical for a human to run.

The 3-day impact analysis becomes:

  • 5 minutes: AI generates a candidate impact map
  • 30 minutes: I review the map, reject the false positives, add the ones the AI missed
  • Total: 35 minutes

This is honest. The AI isn't doing the impact analysis — it's doing the lookup. The analysis is still mine, with my name on it, defensible at audit.

Where this gets CMO-specific

At an OEM, the impact surface is mostly internal. At a CMO, half the impact surface lives in other companies: the OEM's design history file, the supplier's process FMEA, the third-party steriliser's validation. AI mapping across organisational boundaries is harder. We can map what we control; we still need customer and supplier confirmation for the rest.

qmsWrapper, for instance, has automatic change impact analysis that fits a single device maker's eQMS — that's where it's built and marketed. For a CMO, the same feature gets you perhaps 60% of the way. The remaining 40% is the cross-organisational impact that lives in your customer's DHF and your suppliers' PFMEAs. Useful, but not the whole answer.

This is why framing matters. AI-assisted impact analysis is a connected workflow tool when it lives inside your eQMS and pulls from your records. It stops being useful when it tries to cross boundaries it has no permission to see in.

What I won't claim

It won't eliminate the documentation. ISO 13485 §8.5.6 still requires impact evaluation of changes, and §4.2.4 still requires review and approval of the resulting document updates. 21 CFR 820.70 still covers supplier change management under purchasing controls. The documentation timeline doesn't compress just because the AI made the impact analysis faster — it compresses because you now have defensible content to document.

It won't replace human review. I sign my name to the impact assessment. The AI suggests. I decide. The audit trail has to show that distinction clearly.

It won't fix a broken change control process. If your impact analysis was 3 days partly because nobody could find the records, AI mapping helps. If your impact analysis was 3 days because nobody knew who was responsible for assessing supplier-side impact, no AI fixes that.

What I want to know

I'm writing this from a CMO in Bangalore with three OEM customers and 40+ suppliers. The numbers above are real for us. I'd be curious what the same breakdown looks like at a single-OEM device maker with a tighter supply chain.

How long does the impact analysis actually take at your shop — and what's the slowest part?

I work on qmsWrapper; this is my honest read of where it helps at an OEM and where the CMO reality still needs more.

Top comments (0)