Resources  /  Checklists  /  EU MDR

EU MDR compliance checklist

Practising auditors wrote these 57 audit questions, covering the full standard. Each item names the objective evidence to request, the nonconformities most often raised against it, and what to sample. It is free to read, with no sign-up required.

Download the PDF

Includes all 57 items, formatted for a clipboard.

You will get one email with the file. We will not send anything else.

57 items24 hours estimated, end to end 12 sectionsEU MDR · updated 2026-03-27

What each item gives you

This is what an auditor needs at each item. You already hold the standard itself.

The question

Phrases it the way you would ask it in the room.

Objective evidence

Names the specific artefacts that satisfy the item, and how to tell a real one from a placeholder.

Common nonconformities

Lists the findings most often raised here, in the words they get written up in.

Auditor tips

Shows where the item usually goes wrong, and what a mature answer sounds like against a rehearsed one.

What to sample

Explains how many to take, how to choose them, and what to cross-reference them against.

Follow-up questions

Gives the second and third questions to ask when the first answer is too smooth.

All 57 items on this page

Questions below are grouped by section, and you can check items off as you go — this browser remembers your progress. Open any row for its evidence, common nonconformities and auditor tips.

§art10 General obligations of manufacturers (article 10) 8 items · ~180 min
Article 10(1) Has the manufacturer established a system to ensure that devices are designed and manufactured in accordance with EU MDR requirements? Is there documented evidence that devices placed on the market conform to the regulation?
Objective evidence
  • Declaration of Conformity per Article 19 and Annex IV — verify it references the correct EU MDR regulation number (2017/745), lists applicable conformity assessment procedures, and is signed by an authorized person with a recent date
  • Technical documentation per Annex II demonstrating design and manufacturing controls — confirm it exists as a structured file rather than a loose collection of documents
  • Evidence of conformity assessment route selection based on device classification — verify the selected Annex (IX, X, XI) matches the device risk class per Annex VIII
  • Notified Body certificate (for Class IIa/IIb/III) — confirm validity dates, scope coverage, and any restrictions or conditions noted on the certificate
Common nonconformities
  • Declaration of Conformity references the old Medical Device Directive (93/42/EEC) instead of EU MDR 2017/745 — the organization has not updated its declarations despite placing devices on the market under EU MDR (Major NC).
  • No documented system exists for ensuring ongoing conformity — the organization treats conformity as a one-time event at product launch rather than a continuous obligation (Major NC).
  • The conformity assessment route selected does not match the device classification — a Class IIb device is being assessed under a procedure intended for Class IIa, indicating a classification error or procedural gap (Major NC).
  • Technical documentation exists but has not been updated to reflect design changes made after initial market placement — Article 10(1) requires ongoing conformity, not just initial conformity (Minor NC).
Auditor tip

Start by asking for the Declaration of Conformity and work backwards. The DoC is the manufacturer's formal claim of compliance — if it references the wrong regulation, the wrong classification, or an expired Notified Body certificate, everything downstream is suspect. Check that the organization understands the difference between MDD and MDR declarations, especially during the transition period.

What to sample

Request the Declaration of Conformity for 2 devices of different risk classes. Cross-reference against Notified Body certificates and technical documentation to confirm alignment.

Follow-up questions
  • Walk me through how you determined the conformity assessment route for your highest-risk device — what analysis supported that decision?
  • When was the last time you updated your Declaration of Conformity, and what triggered the update?
  • If a design change is made to a device already on the market, what is your process for reassessing conformity?
Article 10(2) Has the manufacturer established, documented, implemented, and maintained a risk management system covering the entire product lifecycle? Does the risk management system address the general safety and performance requirements of Annex I?
Objective evidence
  • Risk management plan per ISO 14971 — verify it references EU MDR Annex I general safety and performance requirements (GSPRs) and covers the full product lifecycle including post-market phases
  • Risk management file containing hazard identification, risk analysis, risk evaluation, and risk control records — confirm completeness against the risk management plan
  • Benefit-risk analysis per Article 10(2) and Annex I Section 1 — verify it explicitly concludes that residual risks are acceptable when weighed against benefits under normal conditions of use
  • Evidence that risk management outputs feed into design controls, labeling, and post-market surveillance — trace at least one identified risk through to its control measure and monitoring plan
  • Post-production risk management activities — verify that complaint data, vigilance reports, and field safety actions feed back into the risk management file
Common nonconformities
  • Risk management file was created during product development but has never been updated with post-market data — no evidence that field complaints, PMCF data, or trend analyses have been incorporated (Major NC).
  • Benefit-risk determination is a single statement in the risk management report without supporting quantitative or qualitative analysis — the conclusion is unsupported (Minor NC).
  • Risk management plan does not reference EU MDR Annex I GSPRs — the plan is written to ISO 14971 alone without addressing regulation-specific requirements (Minor NC).
  • No documented link between identified risks and corresponding labeling warnings or instructions for use — risk controls that rely on information supplied with the device are not traceable to actual label content (Major NC).
Auditor tip

EU MDR explicitly requires that risk management cover the entire product lifecycle, which is a broader scope than many organizations practiced under MDD. Look specifically for post-market feedback loops — the risk management file should be a living document that gets updated with real-world data, not a static design-phase artifact. The benefit-risk analysis is an MDR-specific obligation that goes beyond ISO 14971 and must be documented explicitly.

What to sample

Select one device and trace a single hazard from identification through risk analysis, control implementation, verification of effectiveness, and post-market monitoring. Verify the chain is complete and documented.

Follow-up questions
  • Show me an example where post-market data led to a change in your risk management file — what was the data source and what action was taken?
  • How do you determine whether a residual risk is acceptable — what criteria do you use and who makes the final determination?
  • How does your risk management system address risks from foreseeable misuse?
Article 10(3) Has the manufacturer conducted a clinical evaluation in accordance with Article 61 and Annex XIV, including post-market clinical follow-up (PMCF)? Is the clinical evaluation and its documentation kept up to date with ongoing clinical data?
Objective evidence
  • Clinical evaluation report (CER) per Annex XIV Part A — verify it follows a systematic methodology (literature review, clinical investigation data, and/or equivalence analysis), includes defined search criteria, and reaches a documented conclusion on safety and performance
  • Clinical evaluation plan defining the scope, appraisal methodology, and update frequency — confirm it addresses both pre-market and post-market clinical data requirements
  • PMCF plan per Annex XIV Part B — verify it defines specific clinical questions to be addressed, data collection methods, and the rationale for chosen methods (surveys, registries, investigations)
  • PMCF evaluation report documenting results of post-market clinical data collection and any actions taken — confirm it references the PMCF plan and addresses each planned clinical question
  • Evidence of CER update within the organization's defined review cycle — for Class III and implantable devices, verify annual update per Article 61(11)
Common nonconformities
  • Clinical evaluation report is a literature review from three years ago that has not been updated to incorporate recent publications, adverse event data, or PMCF results — the CER does not reflect current clinical knowledge (Major NC).
  • PMCF plan exists as a template but no PMCF activities have been performed — the organization treats PMCF as a theoretical requirement rather than an operational obligation (Major NC).
  • CER relies on equivalence to a predicate device but does not demonstrate equivalence across all three dimensions required by Annex XIV (clinical, technical, and biological) — the equivalence claim is insufficiently supported (Major NC).
  • No documented process for triggering a CER update when new clinical data becomes available — updates are ad hoc rather than systematic (Minor NC).
Auditor tip

Clinical evaluation is one of the most scrutinized areas under EU MDR. Notified Bodies routinely raise findings on insufficient CERs, particularly around equivalence claims and PMCF execution. The bar for demonstrating equivalence has increased significantly under MDR compared to MDD — ask specifically how clinical, technical, and biological equivalence was established and whether a contractual access agreement exists for the equivalent device's technical documentation. For Class III and implantable devices, verify annual CER updates as a hard regulatory requirement.

What to sample

Request the CER and PMCF plan for one device. Verify the CER's literature search is reproducible (defined databases, search terms, date ranges). Check whether PMCF results have actually been collected and analyzed per the plan.

Follow-up questions
  • If you claim equivalence to another manufacturer's device, do you have a contractual agreement to access their technical documentation? If not, how do you demonstrate equivalence?
  • What triggered your most recent CER update, and what new data was incorporated?
  • How do you integrate PMCF findings back into your benefit-risk analysis and risk management file?
Article 10(4) Has the manufacturer drawn up and kept up to date the technical documentation referred to in Annexes II and III? Is the technical documentation available for Notified Body and competent authority inspection?
Objective evidence
  • Technical documentation index or table of contents showing coverage of all Annex II elements — device description, design and manufacturing information, GSPRs, benefit-risk analysis, product verification and validation, clinical evaluation
  • Post-market surveillance documentation per Annex III — PMS plan, PMS report or PSUR, PMCF plan and report
  • Evidence that technical documentation has been reviewed and updated following design changes, manufacturing changes, or new post-market data — verify revision history and approval records
  • Document control system showing how technical documentation is maintained, versioned, and retrievable — confirm the system supports Notified Body audit access
Common nonconformities
  • Technical documentation is incomplete — one or more Annex II sections are entirely missing or contain only placeholder text (Major NC).
  • Technical documentation was prepared for initial certification but has not been updated to reflect three subsequent design changes — the current documentation does not describe the device as manufactured and placed on the market (Major NC).
  • Post-market surveillance documentation per Annex III does not exist as a structured component — PMS data is scattered across complaint files with no consolidated PMS plan or report (Minor NC).
  • Technical documentation is stored across multiple systems with no master index — the manufacturer cannot readily present the complete file for inspection within a reasonable timeframe (Minor NC).
Auditor tip

Think of the technical documentation as the manufacturer's proof file — it must tell the complete story of the device from concept through post-market experience. Under MDR, the technical documentation requirements are more prescriptive than under MDD. Walk through the Annex II checklist systematically: device description and specification, information supplied by the manufacturer, design and manufacturing information, GSPRs, benefit-risk analysis, product verification and validation, and clinical evaluation. Each section should contain substantive content, not just references to other documents that may or may not exist.

What to sample

Select one device and walk through the Annex II table of contents. Open 3 random sections and verify they contain current, substantive content with approval signatures and revision dates.

Follow-up questions
  • If I asked your Notified Body auditor to produce your complete technical documentation for one device within 24 hours, could your team do it?
  • How do you decide when a change to a device triggers an update to the technical documentation versus when it does not?
  • Who is responsible for maintaining the technical documentation, and how do you ensure completeness when multiple departments contribute content?
Article 10(8) Does the manufacturer have procedures to keep available the Declaration of Conformity, the technical documentation, and — if applicable — Notified Body certificates, for a period of at least 10 years after the last device has been placed on the market? For implantable devices, is the retention period at least 15 years?
Objective evidence
  • Record retention policy or procedure specifying retention periods for EU MDR documentation — verify it explicitly states 10 years (or 15 years for implantable devices) from the date the last device covered by the DoC was placed on the market
  • Document management system configuration showing retention period settings for technical documentation, DoCs, and certificates — confirm settings match policy
  • Evidence that historical documentation is actually retrievable — request a DoC or technical documentation for a device placed on the market more than 2 years ago and verify it can be produced
  • Backup and disaster recovery procedures for regulatory documentation — confirm that electronic records are protected against loss
Common nonconformities
  • Record retention policy specifies 5 years, which is the ISO 13485 minimum but does not meet the EU MDR 10-year requirement — the policy was not updated for MDR transition (Minor NC).
  • No distinction in retention periods between standard devices (10 years) and implantable devices (15 years) — all documentation is subject to the same retention period regardless of device type (Minor NC).
  • The retention period is calculated from the date of document creation rather than from the date the last device was placed on the market — the calculation method does not comply with Article 10(8) (Minor NC).
  • Historical technical documentation from 4 years ago cannot be retrieved because the document management system was migrated and older records were not carried forward (Major NC).
Auditor tip

This is a straightforward compliance check but frequently missed during MDR transition. Organizations that had 5-year retention under MDD or ISO 13485 often fail to update their retention policies to the MDR minimum. Pay special attention to how the retention clock starts — it is not from document creation date but from the date the last device covered by the Declaration of Conformity was placed on the market, which could be many years after the document was first created.

What to sample

Check the record retention procedure. Then request documentation for the oldest device still on the market. Verify it is retrievable and complete.

Follow-up questions
  • How do you determine the date the last device was placed on the market for purposes of starting the retention clock?
  • If your document management system were to fail, how would you recover your regulatory documentation?
  • Do you have any implantable devices, and if so, are their retention periods set to 15 years?
Article 10(10) Has the manufacturer implemented and kept up to date a post-market surveillance system in accordance with Article 83? Does the system actively collect, record, and analyze relevant data on quality, performance, and safety throughout the device's entire lifetime?
Objective evidence
  • Post-market surveillance plan per Article 84 — verify it defines data sources (complaints, vigilance, literature, registries, PMCF), collection methods, analysis frequencies, and responsibilities
  • PMS report (Class I) or Periodic Safety Update Report (PSUR, Class IIa/IIb/III) — verify it is current within the required update cycle and contains actual data analysis, not just data summaries
  • Evidence that PMS data feeds back into risk management, clinical evaluation, and design — trace at least one PMS finding through to a corrective or preventive action
  • Trend analysis methodology and results — verify the manufacturer is actively looking for statistically significant increases in complaints, incidents, or adverse events
Common nonconformities
  • PMS plan exists but the manufacturer has not actually collected or analyzed post-market data — the plan is a paper exercise without operational implementation (Major NC).
  • No trend analysis is performed on complaint and incident data — individual events are investigated but no population-level trend analysis exists (Major NC).
  • PSUR has not been updated within the required cycle — for Class IIb and III devices the PSUR must be updated at least annually, and the most recent version is more than 18 months old (Minor NC).
  • PMS system does not include proactive data collection methods — the manufacturer waits for complaints rather than actively collecting data from literature, registries, or clinical follow-up (Minor NC).
Auditor tip

PMS under EU MDR is fundamentally different from the MDD approach. It is no longer sufficient to passively collect complaints — manufacturers must proactively seek out and analyze safety and performance data from multiple sources. The key test is whether PMS data actually flows back into the risk management file, clinical evaluation, and preventive actions. Ask to see the data flow, not just the plan.

What to sample

Request the PMS plan and the most recent PMS report or PSUR. Verify the report contains actual data analysis (not just summaries) and that at least one finding resulted in a documented action.

Follow-up questions
  • Show me an example where PMS data changed your risk assessment or triggered a CAPA — what was the data source and how long did it take from data collection to action?
  • How do you identify trends in your post-market data — what statistical methods or thresholds do you use?
  • What proactive data sources do you monitor beyond customer complaints?
Article 10(11) Does the manufacturer ensure that its devices are accompanied by the information required in Annex I Chapter III (labeling and instructions for use) in an official EU language determined by the Member State in which the device is made available?
Objective evidence
  • Label samples for each device variant — verify they include all elements required by Annex I Section 23 (manufacturer name and address, UDI carrier, device description, warnings, sterility status, lot/serial number, CE mark with Notified Body number where applicable)
  • Instructions for use (IFU) for each device — verify they include all elements required by Annex I Section 23.4 (intended purpose, user profile, contraindications, warnings and precautions, residual risks, performance characteristics, installation and maintenance instructions)
  • Language matrix showing which languages are provided per target market — verify compliance with Member State language requirements for each market where the device is placed
  • Label and IFU review records showing regulatory and quality review prior to release — confirm that label content is traceable to design outputs and risk management conclusions
Common nonconformities
  • Label does not include a UDI carrier in machine-readable format — the organization has not implemented UDI on labels despite the device being within the applicable timeline (Major NC).
  • Instructions for use do not address residual risks identified in the risk management file — there is a gap between risk management outputs and information supplied with the device (Major NC).
  • Device labels are provided only in English but the device is marketed in Member States that require national language labeling — no translated labels exist for France, Germany, or Italy (Major NC).
  • Warnings and precautions on the label do not match those specified in the risk management report — the label was not updated after the most recent risk management file revision (Minor NC).
Auditor tip

Labeling is a frequent finding area because it sits at the intersection of multiple requirements — risk management outputs must feed into labeling content, UDI must be implemented per the applicable timeline, and language requirements vary by Member State. Pull a physical device (or production label sample) and systematically check it against the Annex I Section 23 checklist. Then cross-reference against the risk management file to verify that residual risks requiring user information are actually addressed on the label or in the IFU.

What to sample

Pull a production label and IFU for one device. Check against Annex I Section 23 requirements point by point. Then open the risk management file and verify that residual risks identified as requiring user information are addressed in the IFU.

Follow-up questions
  • How do you ensure that label content stays synchronized with risk management file updates?
  • Walk me through your label change control process — when risk management identifies a new residual risk requiring user information, how does that become a label change?
  • How do you manage language translations — do you use validated translation processes?
Article 15 Has the manufacturer designated a Person Responsible for Regulatory Compliance (PRRC)? Does the PRRC possess the required qualifications (diploma in law, medicine, pharmacy, engineering, or another relevant scientific discipline, plus professional experience in regulatory affairs or QMS)?
Objective evidence
  • Documented designation of the PRRC including name, role, and reporting line — verify the designation is formal (appointment letter, job description, or quality manual reference) rather than informal
  • Evidence of PRRC qualifications — diploma or degree in a qualifying field plus at least one year of professional experience in regulatory affairs or quality management systems for medical devices, or four years of professional experience in those fields
  • Job description defining PRRC responsibilities per Article 15(3) — verify it covers technical documentation conformity, DoC preparation, PMS obligations, reporting obligations, and clinical investigation statement issuance where applicable
  • Evidence that the PRRC has operational access and authority to fulfill the role — meeting minutes, sign-off authority on regulatory submissions, or delegation records
Common nonconformities
  • No formal PRRC designation exists — the quality manager informally performs regulatory compliance tasks but has not been formally appointed as PRRC (Minor NC).
  • The designated PRRC does not meet the qualification requirements — the individual has relevant experience but no qualifying diploma and fewer than four years of professional experience (Major NC).
  • PRRC responsibilities are not documented — the individual has been designated by name but there is no documented scope of responsibilities matching Article 15(3) requirements (Minor NC).
  • The PRRC has been designated but has no operational authority — regulatory submissions and technical documentation approvals are made by other personnel without PRRC review or sign-off (Minor NC).
Auditor tip

PRRC is an EU MDR-specific requirement that did not exist under MDD. Many organizations have struggled with implementation, particularly micro and small enterprises that may use an external PRRC. Verify both the formal designation and the practical ability of the PRRC to fulfill the role. If the PRRC is external (e.g., a consultant), verify that a contractual agreement exists per Article 15(2) and that the arrangement allows the PRRC to genuinely fulfill responsibilities rather than being a paper exercise.

What to sample

Request the PRRC designation document and qualification evidence. Interview the PRRC about their role — ask them to describe their last interaction with a technical documentation review or vigilance reporting decision.

Follow-up questions
  • Can I speak with your PRRC directly? How do they stay informed about regulatory changes that affect your devices?
  • If the PRRC identifies a compliance concern, what authority do they have to halt a market release?
  • Is your PRRC an employee or an external consultant? If external, how do you ensure they have sufficient access to your QMS and technical documentation?
§annex2 Technical documentation (annex ii/iii) 7 items · ~200 min
Annex II Section 1 Does the technical documentation contain a complete device description and specification, including intended purpose, intended users, indications and contraindications, principles of operation, device classification and justification, and explanation of novel features?
Objective evidence
  • Device description document within the technical file — verify it includes product name, model/variant identifiers, intended purpose statement, indications, contraindications, target patient population, intended user profile, and conditions of use
  • Device classification justification per Annex VIII — verify the classification rule(s) applied, the rationale for the selected rule, and the resulting classification (I, IIa, IIb, III)
  • Description of novel features or technologies and how they differ from existing devices — if the device incorporates novel materials, software algorithms, or nanomaterials, verify they are identified and their safety implications discussed
  • Accessories and other devices intended to be used in combination — verify they are identified and their interaction described
  • Configuration and variant matrix — for devices with multiple variants, verify the rationale for grouping them under a single technical documentation set
Common nonconformities
  • Intended purpose statement is vague or overly broad — it does not specify the medical condition being addressed, the target patient population, or the clinical context of use (Major NC).
  • Device classification rule is cited without supporting rationale — the manufacturer states 'Rule 11' without explaining why that rule applies to the device's characteristics and intended purpose (Minor NC).
  • Novel features are not identified — the device incorporates a proprietary algorithm for diagnostic support but the technical documentation does not describe it as novel or address its specific safety implications (Major NC).
  • No variant or configuration matrix exists for a product family with 12 variants — it is unclear which technical documentation content applies to which variant (Minor NC).
Auditor tip

The device description is the foundation of the entire technical documentation file — if the intended purpose is wrong or imprecise, everything that follows (classification, risk analysis, clinical evaluation, labeling) will be misaligned. Read the intended purpose statement carefully and compare it against marketing materials, labeling, and clinical evaluation scope. Misalignments between the regulatory intended purpose and how the device is marketed are a common and serious finding.

What to sample

Compare the intended purpose in the technical documentation against the label, IFU, and any marketing materials. Verify the classification justification against Annex VIII rules.

Follow-up questions
  • Is the intended purpose in your technical documentation identical to what appears on your labeling and marketing materials? If there are differences, why?
  • How did you determine that your classification rule is correct — did you consider alternative rules that could apply?
  • Do any of your device variants have sufficiently different risk profiles that they should have separate technical documentation?
Annex II Section 2 Does the technical documentation include the information to be supplied by the manufacturer — specifically, the label texts, IFU, and packaging information — in all required languages?
Objective evidence
  • Current label artwork or proof for each device variant — verify all mandatory label elements per Annex I Section 23 are present
  • Current Instructions for Use — verify content completeness against Annex I Section 23.4 requirements
  • Language translation records — verify that translations exist for all Member States where the device is placed on the market
  • Label review and approval records — confirm that label content was reviewed against design outputs and risk management file before release
Common nonconformities
  • Technical documentation does not contain the actual label artwork — only a text specification exists, and the final printed label has never been verified against the specification (Minor NC).
  • IFU content is incomplete — mandatory sections such as contraindications, warnings related to residual risks, or maintenance requirements are missing (Major NC).
  • Translations have not been verified by a qualified reviewer — machine-translated labels are used without human review, risking inaccurate safety information in the target language (Minor NC).
Auditor tip

Compare what is in the technical file against a physical production label or finished product packaging. Discrepancies between the documented label design and the actual label on devices indicate a label control gap. Also check that information required by risk management (residual risk warnings) actually appears in the IFU.

What to sample

Pull a finished product unit and compare the label against the technical documentation artwork. Check the IFU for completeness against Annex I Section 23.4.

Follow-up questions
  • How do you ensure the printed label matches the approved artwork in the technical documentation?
  • When a risk assessment identifies a new residual risk requiring user information, how does it get into the IFU?
Annex II Section 3 Does the technical documentation contain design and manufacturing information, including a description of manufacturing processes, validated manufacturing processes, quality controls, and information on suppliers and subcontractors?
Objective evidence
  • Manufacturing process flow diagram showing all process steps from incoming materials through packaging and release — verify it includes in-process controls, hold points, and inspection points
  • Process validation records for special processes (sterilization, bonding, welding, sealing, software compilation) — verify validation protocols, execution records, and acceptance criteria are documented
  • Supplier qualification records for critical suppliers — verify approved supplier list, quality agreements, and incoming inspection procedures exist
  • Manufacturing site information — address, capabilities, GMP status, and whether manufacturing occurs at the manufacturer's own facility or at a subcontractor
  • Design transfer records — evidence that design outputs were translated into production specifications with verification that production outputs meet design requirements
Common nonconformities
  • Process validation records for sterilization do not exist or are incomplete — the sterilization process is treated as a standard process rather than a special process requiring validation (Major NC).
  • Subcontracted manufacturing processes are not described in the technical documentation — a critical assembly step is performed by a subcontractor but the technical documentation does not describe this arrangement or include the subcontractor's quality controls (Major NC).
  • Supplier qualification records show initial qualification but no ongoing monitoring — suppliers qualified 5 years ago have never been re-evaluated (Minor NC).
Auditor tip

This section must tell the story of how the device is actually made. Walk the manufacturing process flow and verify that each step described in the documentation matches what happens on the production floor (or at the subcontractor). Special processes — anything whose results cannot be fully verified by subsequent inspection — must be validated. Under EU MDR, subcontractors must be identified and their quality controls documented.

What to sample

Select one validated process and review the validation package (protocol, execution data, acceptance criteria, approval). Verify supplier qualification records for the top 2 critical suppliers.

Follow-up questions
  • Which of your manufacturing processes are classified as special processes, and how did you determine which processes require validation versus verification?
  • How do you qualify and monitor your critical suppliers and subcontractors?
  • When you make a manufacturing process change, what is the change control pathway?
Annex II Section 4 Does the technical documentation include a GSPR (General Safety and Performance Requirements) checklist per Annex I, showing how each applicable requirement is addressed and referencing the supporting evidence?
Objective evidence
  • GSPR checklist or compliance matrix — verify it lists every requirement from Annex I Chapters I, II, and III, identifies which are applicable and which are not (with justification for non-applicability), and references the specific document or evidence that demonstrates compliance
  • Cross-references from the GSPR checklist to supporting documentation — verify that at least 5 referenced documents exist and contain the claimed evidence
  • Evidence that the GSPR checklist is maintained as a living document — revision history showing updates when new evidence becomes available or requirements change applicability
  • Harmonized standards and common specifications applied — list of EN ISO standards used to demonstrate conformity with specific GSPRs, with applicability statements
Common nonconformities
  • GSPR checklist is incomplete — several applicable requirements are not addressed and no justification for exclusion is provided (Major NC).
  • GSPR checklist references documents that do not exist — the checklist cross-references a biocompatibility report and a software validation report, but neither document can be located in the technical documentation (Major NC).
  • GSPR checklist has not been updated since initial certification — new GSPRs added during design changes are not reflected in the current checklist (Minor NC).
  • No distinction between applicable and non-applicable GSPRs — the checklist lists all requirements as applicable without evaluating which ones genuinely apply to the specific device (Minor NC).
Auditor tip

The GSPR checklist is a powerful audit tool — it should function as a navigational map to the entire technical documentation. If the checklist is well-maintained, it accelerates the audit by directing you to evidence. If it is poorly maintained, that is itself a finding and also signals that the manufacturer may not understand which requirements apply to their device. Spot-check at least 5 cross-references to confirm the referenced evidence actually exists and supports the claimed compliance.

What to sample

Request the GSPR checklist. Select 5 entries at random and trace each to the referenced supporting evidence. Verify the evidence exists and supports the compliance claim.

Follow-up questions
  • For GSPRs you marked as not applicable, walk me through the justification for one of them — how did you determine it does not apply?
  • When you apply a harmonized standard to demonstrate conformity with a GSPR, how do you handle requirements in the GSPR that are not covered by the standard?
  • How frequently do you review the GSPR checklist for completeness and accuracy?
Annex II Section 5 Does the technical documentation include the benefit-risk analysis and risk management outputs? Does the benefit-risk determination demonstrate that residual risks are acceptable when weighed against the intended clinical benefits?
Objective evidence
  • Benefit-risk analysis document — verify it contains explicit identification of benefits (clinical outcomes, diagnostic accuracy, treatment efficacy), explicit identification of risks (from the risk management file), and a comparative analysis reaching a documented conclusion
  • Risk management report summarizing the overall residual risk and its acceptability — verify it references the benefit-risk analysis and is signed by an authorized individual
  • Risk-benefit ratio consideration for each identified residual risk — verify the analysis is not a generic statement but addresses specific risk-benefit trade-offs
  • State-of-the-art analysis — evidence that the manufacturer considered current medical knowledge and available alternatives when determining risk acceptability
Common nonconformities
  • Benefit-risk analysis is a single paragraph concluding that benefits outweigh risks without any structured analysis — the determination is unsupported by evidence or methodology (Major NC).
  • Benefits are described qualitatively but risks are described quantitatively, making meaningful comparison impossible — the analysis lacks methodological consistency (Minor NC).
  • No consideration of the state of the art — the manufacturer has not compared the risk profile of the device against available alternatives or current clinical practice (Minor NC).
Auditor tip

EU MDR places explicit emphasis on benefit-risk analysis in a way that MDD did not. The analysis must be substantive, not perfunctory. Look for actual clinical benefit data (from the CER or clinical investigations) being weighed against actual risk data (from the risk management file). A common shortcut is to state that benefits outweigh risks without demonstrating how that conclusion was reached. Challenge this — ask to see the methodology, the data inputs, and the decision criteria.

What to sample

Review the benefit-risk analysis document. Verify that benefits and risks are described with comparable rigor. Cross-reference benefits against clinical evaluation data and risks against the risk management file.

Follow-up questions
  • What clinical evidence supports the benefits you claim in your benefit-risk analysis?
  • How did you determine that the residual risks are acceptable — what threshold or criteria did you apply?
  • How does your benefit-risk analysis account for alternative treatments or devices available to the patient?
Annex II Section 6 Does the technical documentation include product verification and validation, covering design verification, design validation, pre-clinical testing (biocompatibility, electrical safety, EMC, software validation, sterility), and clinical evaluation references?
Objective evidence
  • Design verification test reports — verify they demonstrate that design outputs meet design inputs, with clear pass/fail criteria and actual results
  • Design validation records — verify the device was validated under actual or simulated use conditions with representative users
  • Biocompatibility evaluation per ISO 10993-1 — for devices contacting the body, verify a biological evaluation plan exists and appropriate testing has been completed
  • Electrical safety and EMC test reports (where applicable) — verify testing was performed to applicable harmonized standards and results are within acceptance criteria
  • Software verification and validation records (where applicable) — verify software lifecycle documentation per IEC 62304
  • Sterilization validation records (where applicable) — verify the sterilization process is validated per the applicable standard (ISO 11135, ISO 11137, ISO 17665)
Common nonconformities
  • Design verification testing was performed on a prototype that differs from the production device — there is no evidence that verification results are applicable to the device as manufactured (Major NC).
  • Biocompatibility evaluation consists of material data sheets only — no biological evaluation plan or testing per ISO 10993-1 has been performed (Major NC).
  • Software validation records do not exist — the device contains embedded software but no software lifecycle documentation per IEC 62304 is available (Major NC).
  • Design validation was performed by internal engineers rather than representative users — the validation does not reflect actual use conditions (Minor NC).
Auditor tip

This section is where the technical evidence lives. Do not accept summaries or test report titles — open the actual reports and verify they contain raw data, acceptance criteria, and conclusions. For pre-clinical testing, check that the test articles match the production device (same materials, manufacturing process, sterilization method). For software, look for IEC 62304 lifecycle documentation including software requirements, architecture, unit testing, and integration testing. Missing pre-clinical data is one of the most common reasons Notified Bodies reject or delay technical documentation review.

What to sample

Select one test report from each of 3 categories (mechanical/physical, biocompatibility, software/electrical). Verify that test articles match production specifications and that acceptance criteria were met.

Follow-up questions
  • Are the test articles used in verification and validation testing representative of production devices — same materials, same manufacturing process, same sterilization?
  • For your biocompatibility evaluation, what was the rationale for the tests selected — did you perform a biological evaluation plan per ISO 10993-1?
  • How do you handle software changes — does every software change trigger re-validation, or do you have criteria for when re-validation is required?
Annex III Does the post-market surveillance documentation per Annex III include a PMS plan, a PMS report (Class I) or PSUR (Class IIa/IIb/III), and a PMCF plan and PMCF evaluation report?
Objective evidence
  • PMS plan per Article 84 — verify it covers data sources, analysis methods, indicators and thresholds for action, update frequency, and responsibilities
  • PMS report (for Class I devices) or PSUR (for Class IIa/IIb/III devices) — verify the document is current within the required update cycle and contains data analysis conclusions and resulting actions
  • PMCF plan per Annex XIV Part B — verify it defines specific clinical questions, data collection methods (surveys, registries, studies), and timelines
  • PMCF evaluation report — verify it presents results from PMCF activities and any conclusions or actions resulting from the analysis
Common nonconformities
  • PSUR for a Class III device has not been updated annually as required — the most recent version is 20 months old (Major NC).
  • PMCF plan exists but no PMCF activities have been conducted — the plan references a registry study that was never initiated (Major NC).
  • PMS report for a Class I device exists but contains no actual data — it states 'no complaints received' without describing the complaint collection system or data sources monitored (Minor NC).
Auditor tip

Annex III is specifically about post-market documentation within the technical file. Check that all four documents (PMS plan, PMS report or PSUR, PMCF plan, PMCF evaluation report) exist and are current. For PSURs, verify the update frequency matches the device class requirement. The PMCF plan and report are often the weakest — many manufacturers have a plan but have not executed it.

What to sample

Request all four Annex III documents for one device. Verify currency and completeness. For the PSUR, confirm data analysis is substantive.

Follow-up questions
  • When is your next PSUR due, and what data will it incorporate that was not in the previous version?
  • What specific PMCF activities have you completed in the last 12 months?
§qms Quality management system (article 10(9)) 4 items · ~150 min
Article 10(9)(a) Does the QMS address a strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for managing modifications to devices covered by the system?
Objective evidence
  • Regulatory strategy document or procedure — verify it identifies applicable conformity assessment procedures (Annex IX, X, XI) for each device, defines the manufacturer's approach to maintaining conformity, and assigns responsibilities
  • Change management procedure for device modifications — verify it distinguishes between significant changes (requiring Notified Body notification per Article 10(9)(a)) and non-significant changes, with documented criteria for the distinction
  • Records of device modifications showing the change evaluation process was followed — verify at least 2 recent changes were assessed for significance and the assessment is documented
  • Procedure for notifying the Notified Body of planned significant changes — verify the procedure exists and has been followed for any significant changes since the last NB audit
Common nonconformities
  • No documented criteria for distinguishing significant from non-significant changes — all changes are treated equally, with no risk-based approach to determining NB notification requirements (Major NC).
  • Device modifications have been implemented without a documented change evaluation — changes were made to manufacturing processes and materials without assessing whether the Notified Body should be notified (Major NC).
  • Regulatory compliance strategy does not exist as a documented element of the QMS — the organization relies on informal knowledge of regulatory requirements without a systematic compliance framework (Minor NC).
Auditor tip

The MDR places significant emphasis on change management for devices — particularly the requirement to notify the Notified Body of 'planned substantial changes.' Ask to see the criteria the manufacturer uses to determine whether a change is substantial. Then review actual change records and verify the criteria were applied consistently. If the manufacturer has made changes since the last Notified Body audit, verify they were assessed and — if significant — the Notified Body was notified.

What to sample

Review the change management procedure and 3 recent device change records. Verify the significance assessment was performed and documented for each.

Follow-up questions
  • How do you determine whether a device modification is a 'significant change' requiring Notified Body notification?
  • Show me the last 3 device changes — how was each one evaluated for significance?
  • Has your Notified Body ever disagreed with your significance assessment? If so, what was the outcome?
Article 10(9)(b-d) Does the QMS include procedures for device design and development, production control, and purchasing/supplier management? Are these procedures implemented with documented evidence?
Objective evidence
  • Design and development procedure — verify it covers planning, inputs, outputs, review, verification, validation, transfer, and change control, with defined roles and responsibilities at each stage
  • Production control procedures — verify they address work instructions, equipment qualification, environmental controls, in-process inspection, and final release criteria
  • Purchasing and supplier management procedure — verify it includes supplier selection criteria, evaluation and re-evaluation processes, quality agreements, and incoming inspection requirements
  • Records demonstrating implementation — design history file for a recent device, production batch records, supplier audit reports or evaluation records
Common nonconformities
  • Design and development procedure exists but no design history file has been created for the most recent device — the procedure is not being followed (Major NC).
  • Supplier evaluation consists of a self-assessment questionnaire only — no on-site audits, performance monitoring, or quality agreements exist for critical suppliers (Minor NC).
  • Production control procedures do not include acceptance criteria for in-process inspections — operators perform inspections but there are no documented criteria for pass/fail determination (Minor NC).
Auditor tip

These are familiar QMS elements for organizations that have ISO 13485 certification. The key MDR-specific angle is ensuring these procedures also address MDR-specific requirements — for example, design and development must include clinical evaluation integration, and purchasing must address EU MDR economic operator obligations for importers and distributors in the supply chain.

What to sample

Review a recent design history file for completeness. Check supplier evaluation records for the top 3 critical suppliers. Review one production batch record.

Follow-up questions
  • How does your design and development process integrate clinical evaluation — at which stage does clinical data inform design decisions?
  • What triggers a supplier re-evaluation, and what actions do you take if a supplier fails re-evaluation?
  • How do you verify that your production process consistently produces devices that conform to the design specifications?
Article 10(9)(e-f) Does the QMS include processes for product traceability, complaint handling, and reporting obligations? Are vigilance reports and field safety corrective actions (FSCAs) managed through documented procedures?
Objective evidence
  • Traceability procedure — verify it describes how devices are traced from incoming materials through production, distribution, and final customer, using lot or serial numbers and UDI where applicable
  • Complaint handling procedure — verify it defines complaint intake, initial assessment for reportability (vigilance), investigation, root cause analysis, CAPA linkage, and closure criteria
  • Vigilance reporting procedure — verify it defines serious incident identification criteria, reporting timelines (per Article 87), and responsibilities for submitting reports through EUDAMED or national competent authority systems
  • FSCA procedure — verify it describes the process for initiating, planning, executing, and closing field safety corrective actions, including customer notification and competent authority communication
  • Records of complaint investigations and any vigilance reports submitted — verify at least 3 recent complaints were investigated and the reportability assessment was documented
Common nonconformities
  • Complaint handling procedure does not include a reportability assessment step — complaints are investigated for root cause but not evaluated against Article 87 serious incident criteria (Major NC).
  • No FSCA procedure exists — the manufacturer has never executed a field safety corrective action but also has no procedure for doing so if needed (Minor NC).
  • Traceability records are incomplete — distribution records do not identify the end customer or healthcare facility, making downstream traceability impossible (Major NC).
Auditor tip

Traceability and vigilance are areas where EU MDR is more demanding than many other regulatory frameworks. The traceability chain must extend to the end customer (hospital, clinic, or user) where possible. For complaints, verify that every complaint is assessed for reportability as a serious incident — even if the organization concludes it is not reportable, the assessment must be documented. Ask to see 3 complaints and trace each through the process from intake to closure.

What to sample

Select 3 complaints from the past 12 months. Verify each was assessed for reportability with a documented rationale. Check that traceability records can link a specific device lot to its distribution destination.

Follow-up questions
  • Walk me through a recent complaint — how did you determine whether it was reportable as a serious incident?
  • How far downstream does your traceability extend — can you identify which healthcare facilities received a specific lot of your device?
  • If you needed to execute a field safety corrective action tomorrow, what is your first step?
Article 10(9)(g-h) Does the QMS include procedures for management review, corrective and preventive action (CAPA), internal audits, and continual improvement? Is there documented evidence that these processes are executed at planned intervals?
Objective evidence
  • Management review procedure and records — verify reviews are conducted at planned intervals, include inputs required by the QMS procedure (audit results, complaints, CAPA status, regulatory changes, PMS data), and produce documented decisions and actions
  • CAPA procedure — verify it includes problem identification, root cause investigation methods, effectiveness verification, and escalation criteria
  • Internal audit program and records — verify audits cover all QMS processes within the defined audit cycle, auditors are independent of the areas audited, and findings are tracked to closure
  • Continual improvement evidence — verify that management review outputs, CAPA results, and audit findings are used to drive measurable improvements in the QMS
Common nonconformities
  • Management review records do not include PMS data as an input — post-market surveillance results are not presented to or considered by management (Minor NC).
  • CAPA effectiveness verification is not performed — CAPAs are implemented and closed without evidence that the corrective action actually prevented recurrence (Major NC).
  • Internal audit program has not been completed within the defined cycle — 4 of 12 planned audits were not conducted in the last 12 months and no justification exists for the gap (Minor NC).
  • No documented continual improvement objectives — management review minutes do not set improvement targets or track progress against previous targets (Minor NC).
Auditor tip

These are standard QMS management processes, but under EU MDR they must integrate MDR-specific elements. Management review must include PMS data and vigilance trends. CAPA must connect to vigilance investigations. Internal audits must cover MDR-specific requirements (UDI, PRRC, PMS). Look for these connections — if the management system processes exist but do not incorporate MDR-specific inputs, the QMS is not fully MDR-aligned.

What to sample

Review the last management review record and verify PMS data was included. Select one CAPA and verify effectiveness verification was performed with documented evidence. Review the internal audit schedule and confirm MDR-specific topics are covered.

Follow-up questions
  • How does your management review incorporate post-market surveillance findings — show me where PMS data appears in the last review record?
  • For your most recent CAPA, how did you verify that the corrective action was effective?
  • Do your internal auditors assess MDR-specific requirements such as UDI, PRRC, and clinical evaluation, or only ISO 13485 clause requirements?
§clinical Clinical evaluation (article 61, annex xiv) 5 items · ~180 min
Article 61(1) Has the manufacturer conducted a clinical evaluation based on a clinical evaluation plan, following a defined and methodologically sound procedure? Does the clinical evaluation confirm conformity with the relevant general safety and performance requirements of Annex I?
Objective evidence
  • Clinical evaluation plan (CEP) — verify it defines the scope of the evaluation, identifies the device and its intended purpose, defines the clinical data types to be considered, specifies the appraisal methodology for clinical data, and describes how clinical data gaps will be addressed
  • Clinical evaluation report (CER) — verify it follows the methodology defined in the CEP, includes systematic literature review results, equivalence analysis (if applicable), clinical investigation data (if applicable), and reaches documented conclusions on safety and clinical performance
  • Literature search protocol and results — verify search databases used, search terms, inclusion/exclusion criteria, date ranges, and that both favorable and unfavorable data were considered
  • Clinical data appraisal records — verify that each piece of clinical data was appraised for methodological quality, relevance, and contribution to the safety and performance conclusions
  • GSPR compliance mapping from the CER — verify the CER explicitly addresses Annex I GSPRs related to clinical performance and safety
Common nonconformities
  • No clinical evaluation plan exists — the manufacturer produced a CER without first defining the evaluation scope and methodology (Major NC).
  • Literature search is not systematic — the manufacturer identified supportive publications but did not follow a defined search protocol with reproducible search terms and databases (Major NC).
  • CER does not consider unfavorable data — adverse event reports, negative clinical outcomes, and device-related complications from literature or registries were excluded without documented justification (Major NC).
  • CER conclusions do not address specific GSPRs — the report concludes the device is 'safe and effective' generically without mapping conclusions to individual safety and performance requirements (Minor NC).
Auditor tip

The clinical evaluation plan is the roadmap and the CER is the deliverable. If the plan is poor, the report will be poor. Start by reviewing the CEP to understand the intended methodology, then verify the CER followed it. The most common failures are non-systematic literature searches (not reproducible), exclusion of unfavorable data, and generic safety conclusions that do not address specific GSPRs. For equivalence-based evaluations, scrutinize the three pillars of equivalence (clinical, technical, biological) — MDCG 2020-5 provides the criteria.

What to sample

Request the CEP and CER. Verify the literature search is reproducible. Check that unfavorable data is addressed. Trace 3 CER conclusions back to the supporting clinical data.

Follow-up questions
  • Can you reproduce your literature search today and get the same results — are the search terms, databases, and date ranges fully documented?
  • How did you handle unfavorable clinical data — were there any publications or reports that contradicted your safety conclusions?
  • Who performed the clinical data appraisal, and what were their qualifications?
Article 61(3-5) If the clinical evaluation is based on equivalence to another device, has the manufacturer demonstrated equivalence across clinical, technical, and biological characteristics? For Class III and implantable devices, does the manufacturer have access to the equivalent device's technical documentation?
Objective evidence
  • Equivalence analysis document — verify it systematically compares the subject device to the claimed equivalent device across all three dimensions: clinical (same clinical condition, same intended purpose, same user population), technical (same design, same materials, same specifications), and biological (same materials in contact with the same tissues for the same duration)
  • Contractual access agreement for the equivalent device's technical documentation (required for Class III and implantable devices per Article 61(5)) — verify the agreement is current and grants sufficient access to demonstrate equivalence
  • Justification for each claimed equivalence characteristic — verify that differences between devices are identified, assessed, and their impact on safety and performance is documented
  • If equivalence cannot be demonstrated, evidence of clinical investigation or other clinical data sufficient to support the evaluation
Common nonconformities
  • Equivalence analysis addresses technical and biological characteristics but does not systematically assess clinical equivalence — the same intended purpose is assumed without documented analysis (Major NC).
  • Manufacturer claims equivalence to a competitor's device but has no contractual access to the competitor's technical documentation — for a Class III device, this is a fundamental gap that invalidates the equivalence approach (Major NC).
  • Differences between the subject device and the equivalent device are identified but their clinical significance is not assessed — the analysis does not explain why the differences do not affect safety or performance conclusions (Minor NC).
Auditor tip

Equivalence is the most contentious area in EU MDR clinical evaluation. Under MDD, equivalence was relatively easy to claim. Under MDR, the three-pillar approach is strictly enforced, and for Class III and implantable devices, contractual access to the equivalent device's technical documentation is mandatory. If the equivalent device is from a competitor, this requirement is extremely difficult to satisfy. Many manufacturers need to transition from equivalence-based evaluations to generating their own clinical data through clinical investigations. Ask specifically about each pillar and probe for undocumented differences.

What to sample

Review the equivalence analysis. Verify all three dimensions are addressed systematically. If a contractual access agreement is required, verify it exists and is current.

Follow-up questions
  • Is the device you claim equivalence to manufactured by your organization or by a competitor?
  • For each difference identified between your device and the equivalent device, how did you determine the difference is not clinically significant?
  • If your equivalence claim were challenged, do you have a contingency plan — such as a clinical investigation — to generate sufficient clinical data?
Article 61(11) Is the clinical evaluation and its documentation updated throughout the device lifecycle with clinical data obtained from post-market surveillance, PMCF, and other sources? For Class III and implantable devices, is the CER updated at least annually?
Objective evidence
  • CER revision history — verify it shows updates at the required frequency (annually for Class III and implantable devices, at defined intervals for other classes) with documented reasons for each update
  • Evidence that post-market clinical data has been incorporated into the CER — verify that PMCF results, complaint trends, vigilance data, and new literature have been considered in the most recent CER update
  • Process or procedure for CER updates — verify it defines triggers for unscheduled updates (new safety signals, significant complaints, regulatory authority requests) in addition to scheduled periodic reviews
  • Clinical evaluation update assessment records — verify that the clinical data review performed during each update cycle is documented with conclusions on whether the existing evaluation remains valid
Common nonconformities
  • CER for a Class III device has not been updated in 18 months, exceeding the annual update requirement — no documented justification exists for the delay (Major NC).
  • CER updates consist of appending a note stating 'no new data' without demonstrating that a systematic review was actually performed — the update is a formality rather than a substantive evaluation (Minor NC).
  • Post-market clinical data (complaints, vigilance, PMCF) is not reflected in the CER — the most recent CER version does not reference any post-market data collected since the previous version (Major NC).
Auditor tip

The concept of clinical evaluation as a living, continuously updated process is central to EU MDR. Check the CER revision date first — for Class III and implantable devices, it must be no more than 12 months old. Then verify the update was substantive: did the manufacturer actually review new clinical data, or did they simply change the date and re-sign the document? Look for evidence that PMS findings, PMCF results, and new literature publications were actively searched for and considered.

What to sample

Check the CER revision date and verify compliance with update frequency requirements. Compare the current CER against the previous version to verify substantive changes were made. Cross-reference against PMS data collected during the update period.

Follow-up questions
  • Walk me through the most recent CER update — what new data was identified and how did it affect your conclusions?
  • What would trigger an unscheduled CER update outside of your normal review cycle?
  • How does your organization ensure that field safety data is available to the person performing the CER update?
Annex XIV Part B Has the manufacturer established a PMCF plan that specifies the methods for proactively collecting and evaluating clinical data from devices already placed on the market? Does the PMCF plan address specific clinical questions derived from the clinical evaluation?
Objective evidence
  • PMCF plan — verify it identifies specific clinical questions to be answered, defines data collection methods (PMCF studies, surveys, registries, literature monitoring), specifies timelines and milestones, and assigns responsibilities
  • Rationale for selected PMCF methods — verify the chosen methods are appropriate for the clinical questions being addressed and the device risk class
  • PMCF evaluation report — verify it presents results from completed PMCF activities, analyzes data against the clinical questions defined in the plan, and documents any actions taken based on findings
  • Evidence of PMCF activity execution — verify that planned activities are being conducted (enrollment data for studies, survey responses, literature search updates)
Common nonconformities
  • PMCF plan does not define specific clinical questions — it states generically that 'long-term safety and performance will be monitored' without identifying what specific aspects of safety and performance need further clinical evidence (Major NC).
  • PMCF plan specifies a registry study as the primary data collection method but the manufacturer has not enrolled any patients or initiated the registry — the plan exists but is not operational (Major NC).
  • PMCF evaluation report does not exist — PMCF activities have been conducted but the results have not been compiled into a report per Annex XIV Part B requirements (Minor NC).
  • PMCF plan has not been updated since the initial clinical evaluation — new clinical questions arising from post-market experience have not been incorporated (Minor NC).
Auditor tip

PMCF is not optional under EU MDR — every device requires a PMCF plan, even if the clinical evaluation conclusion is that the existing clinical evidence is sufficient. The plan must address specific clinical questions, not generic safety monitoring. The most common finding is a PMCF plan that exists on paper but has never been executed. Ask for evidence of actual PMCF activities — enrollment numbers, completed surveys, updated literature searches. If the manufacturer claims that literature monitoring is their PMCF method, verify they are actually performing systematic literature searches at defined intervals.

What to sample

Request the PMCF plan and evaluation report. Verify specific clinical questions are defined. Check evidence that planned PMCF activities have actually been conducted.

Follow-up questions
  • What are the top 3 clinical questions your PMCF plan is designed to answer, and why were those questions identified as priorities?
  • How many patients or data points have you collected through your PMCF activities to date?
  • If your PMCF data reveals a new safety concern, what is the pathway from data analysis to corrective action?
Article 62 If clinical investigations were conducted or are planned, were they performed in accordance with Article 62-82 requirements? Were they registered in EUDAMED and conducted under ethical committee approval?
Objective evidence
  • Clinical investigation plan (CIP) — verify it includes objectives, design, statistical methodology, endpoints, subject selection criteria, monitoring plan, and adverse event management procedures
  • Ethics committee approval documentation — verify approval was obtained before subject enrollment began
  • Evidence of EUDAMED registration (or national competent authority notification if EUDAMED module not yet operational) — verify the investigation was registered before enrollment began
  • Clinical investigation report (CIR) — if the investigation is complete, verify the report includes all data per Article 77 and Annex XV
  • Informed consent forms — verify they comply with Article 63 requirements and were signed before any study procedures were performed
Common nonconformities
  • Clinical investigation was initiated before ethics committee approval was obtained — subject enrollment occurred before the approval date on the ethics committee letter (Major NC).
  • Clinical investigation report does not include all device deficiencies and adverse events — the report presents only results supporting the device's safety and performance without disclosing all events (Major NC).
  • No clinical investigation plan exists — the manufacturer collected clinical data during routine clinical use and presented it as a clinical investigation without the required formal framework (Minor NC).
Auditor tip

Not all devices require clinical investigations — this item applies only when investigations were conducted or are planned. If the manufacturer claims their clinical evaluation is based solely on literature and equivalence, verify that claim is supportable (especially for Class III and implantable devices). If investigations were conducted, the regulatory requirements are extensive and closely aligned with international standards (ISO 14155). Check the ethical foundation first — ethics committee approval and informed consent — before reviewing the scientific content.

What to sample

If an investigation was conducted, request the CIP, ethics committee approval, and CIR. Verify timelines — ethics approval must precede enrollment. Check that adverse events are fully documented.

Follow-up questions
  • What prompted the decision to conduct a clinical investigation rather than relying on literature and equivalence alone?
  • How do you ensure that all adverse events during the investigation were reported and documented?
  • Were any subjects withdrawn from the investigation, and if so, were withdrawals documented with reasons?
§pms Post-market surveillance (articles 83-86) 4 items · ~120 min
Article 83 Has the manufacturer established a PMS system that is proportionate to the risk class and device type? Does the system actively collect and utilize data from multiple sources including complaints, vigilance, literature, and clinical experience?
Objective evidence
  • PMS system description or procedure — verify it defines data sources, collection methods, analysis methodologies, action triggers, and feedback loops to risk management, clinical evaluation, and design
  • Evidence of active data collection from multiple sources — complaint logs, literature search records, registry data pulls, healthcare professional feedback, competitor device safety data
  • Trend analysis records — verify the manufacturer performs systematic trend analysis on complaint data, field performance data, and incident data to identify emerging safety signals
  • Evidence of PMS data feeding back into other QMS processes — trace at least one PMS finding to a resulting action in risk management, clinical evaluation, or CAPA
Common nonconformities
  • PMS system is limited to complaint collection — the manufacturer does not actively monitor literature, registries, or other external data sources for safety and performance information (Major NC).
  • No trend analysis is performed — individual complaints are investigated but no population-level analysis exists to identify emerging patterns (Major NC).
  • PMS data does not feed back into risk management — the risk management file has not been updated with any post-market data since initial product launch (Major NC).
Auditor tip

The core question is whether PMS is a living, proactive system or a passive complaint repository. Under EU MDR, the manufacturer must demonstrate that PMS data flows into risk management, clinical evaluation, and corrective action. The feedback loops are mandatory — data in, analysis performed, conclusions reached, actions taken. Ask for concrete examples of the cycle completing. If the manufacturer cannot show a single example where PMS data triggered an action, the system is not functioning as required.

What to sample

Request PMS data collection evidence from the last 12 months. Verify multiple data sources were used. Check for at least one complete feedback loop from data collection through analysis to action.

Follow-up questions
  • What external data sources do you monitor beyond customer complaints?
  • Show me your most recent trend analysis — what data did it cover and what conclusions did you draw?
  • Give me an example where PMS data resulted in a concrete action — what was the data, the analysis, and the action?
Article 84 Does the manufacturer's PMS plan identify the data sources to be monitored, the methods for data collection and analysis, indicators and thresholds for initiating corrective or preventive actions, and methods for communicating with competent authorities, Notified Bodies, and economic operators?
Objective evidence
  • PMS plan per Article 84 — verify it explicitly lists data sources (complaints, vigilance databases, literature, registries, surveys, service records), defines analysis methods (statistical techniques, signal detection), and establishes indicators and thresholds for action
  • Communication procedures referenced in the PMS plan — verify they define how and when the manufacturer communicates PMS findings to competent authorities, the Notified Body, distributors, importers, and users
  • Evidence that the PMS plan is a living document — verify it has been reviewed and updated since initial creation to reflect lessons learned and new data sources
Common nonconformities
  • PMS plan does not define indicators or thresholds for action — there is no quantitative or qualitative criteria for when PMS data should trigger a CAPA, field safety corrective action, or NB notification (Minor NC).
  • PMS plan does not include all required communication pathways — procedures for communicating PMS findings to distributors and importers are missing (Minor NC).
  • PMS plan was created 3 years ago and has never been updated — it does not reflect current data sources, organizational changes, or lessons learned from PMS activities (Minor NC).
Auditor tip

The PMS plan is the control document for the entire PMS system. It should be specific and actionable — not generic. Check that thresholds are defined: at what point does a complaint trend become a safety signal? At what volume does an increase in a specific failure mode trigger investigation? Generic statements like 'significant trends will be investigated' are insufficient — the plan should define what 'significant' means.

What to sample

Review the PMS plan for specificity. Verify indicators and thresholds are defined with quantitative criteria. Check communication procedures are complete.

Follow-up questions
  • What specific thresholds have you set for complaint rates, failure modes, or adverse event frequencies that trigger a formal investigation?
  • How do you determine which PMS findings require communication to your Notified Body?
  • When was the last time you updated your PMS plan, and what prompted the update?
Article 85 For Class I devices, has the manufacturer prepared a PMS report summarizing the results and conclusions of the PMS data analysis, together with a rationale and description of any preventive and corrective actions taken?
Objective evidence
  • PMS report for each Class I device family — verify it covers the reporting period, summarizes data collected from all PMS sources, presents analysis conclusions, and describes any resulting corrective or preventive actions
  • Evidence of report updates — verify the PMS report is updated when necessary and is available to the competent authority upon request
  • Linkage to risk management and clinical evaluation — verify the PMS report conclusions are reflected in updates to the risk management file and clinical evaluation
Common nonconformities
  • No PMS report exists for a Class I device — the manufacturer assumed that Class I devices are exempt from PMS reporting requirements (Major NC).
  • PMS report states 'no complaints received' without providing evidence that the complaint collection system was operational and data sources were monitored — absence of data is presented as absence of issues without supporting evidence (Minor NC).
Auditor tip

Class I devices still require a PMS report under EU MDR — this is a change from MDD practice where many Class I manufacturers had minimal post-market obligations. The report need not be as extensive as a PSUR, but it must demonstrate that PMS data was collected, analyzed, and acted upon. If the manufacturer claims zero complaints, verify their complaint intake system was actually operational during the reporting period.

What to sample

Request PMS reports for Class I devices. Verify they contain actual data analysis, not just statements of no events. Confirm the complaint collection system was operational.

Follow-up questions
  • How do you collect complaints and feedback for your Class I devices — through what channels?
  • If your PMS report shows no safety concerns, how do you verify that conclusion reflects reality rather than gaps in your data collection?
Article 86 For Class IIa, IIb, and III devices, has the manufacturer prepared a Periodic Safety Update Report (PSUR) that includes a determination of the benefit-risk ratio, PMCF findings, and volumes of devices sold? Is the PSUR updated at the required frequency?
Objective evidence
  • PSUR for each Class IIa/IIb/III device — verify it includes all Article 86(1) elements: determination of benefit-risk ratio, PMCF main findings, volume of devices on the market, estimated usage, frequency and trend of incidents and FSCAs
  • PSUR update schedule — verify compliance with Article 86(2) frequency requirements: at least annually for Class IIa and IIb devices, at least annually for Class III devices (or more frequently if the NB requires it)
  • Evidence that the PSUR was provided to the Notified Body per Article 86(2) — verify submission records showing the PSUR was provided to the NB as part of the ongoing assessment
  • PSUR conclusions and actions — verify the PSUR reaches documented conclusions on whether corrective actions are needed and, if so, what actions were taken or planned
Common nonconformities
  • PSUR has not been updated at the required frequency — for a Class III device, the most recent PSUR is more than 14 months old, exceeding the annual requirement (Major NC).
  • PSUR does not include a benefit-risk determination — the report summarizes complaint data but does not reassess the benefit-risk ratio in light of the post-market data (Major NC).
  • PSUR does not include volume data — the number of devices on the market and estimated usage are not reported, making it impossible to calculate incident rates (Minor NC).
  • PSUR was not submitted to the Notified Body — the report was prepared internally but not provided to the NB per Article 86(2) (Minor NC).
Auditor tip

The PSUR is a regulatory submission — it must be prepared at the required frequency, contain all required elements, and be provided to the Notified Body. Check the date first — is it current? Then check the content — does it include all Article 86(1) elements? The benefit-risk determination is critical and frequently missing — the manufacturer must reassess whether the benefit-risk ratio remains favorable in light of all post-market data. Volume data enables rate-based analysis and is essential for meaningful trend assessment.

What to sample

Request the most recent PSUR. Verify it contains all Article 86(1) elements. Check the date against the required update frequency. Verify it was submitted to the Notified Body.

Follow-up questions
  • How many units of this device were on the market during the PSUR reporting period, and how did you estimate usage?
  • Based on your PSUR analysis, has the benefit-risk ratio changed since the original clinical evaluation?
  • How does your PSUR trend analysis compare current-period incident rates to previous periods?
§vigilance Vigilance (articles 87-89) 4 items · ~120 min
Article 87(1) Has the manufacturer established a procedure for identifying and reporting serious incidents to the competent authorities of the Member States in which the incident occurred? Does the procedure define the criteria for classifying an event as a serious incident?
Objective evidence
  • Vigilance reporting procedure — verify it defines serious incident criteria per Article 2(65) (death, serious deterioration of health, serious public health threat), reporting timelines, responsibilities, and the reporting pathway (national competent authority systems or EUDAMED when available)
  • Serious incident criteria decision tree or flowchart — verify the procedure provides clear guidance for determining whether an event meets the reporting threshold
  • Reporting timeline compliance — verify the procedure specifies reporting within the required timeframes: 15 days for serious incidents, 10 days for serious incidents involving death or unanticipated serious deterioration of health, and 2 days for serious public health threats
  • Records of serious incident evaluations — verify that complaints and field events are assessed against serious incident criteria, with documented rationale for both reportable and non-reportable determinations
Common nonconformities
  • No documented criteria for classifying serious incidents — the quality team makes reportability determinations on a case-by-case basis without a defined decision framework (Major NC).
  • Reporting timelines in the procedure do not match EU MDR requirements — the procedure specifies 30-day reporting for all incidents rather than the tiered timelines required by Article 87 (Major NC).
  • Serious incident evaluations are not documented for non-reportable events — when the manufacturer determines a complaint is not reportable, no written rationale exists for the decision (Minor NC).
  • The manufacturer is unaware of the 2-day reporting timeline for serious public health threats — the procedure does not address this category of reporting (Minor NC).
Auditor tip

Vigilance reporting is a hard regulatory obligation with specific timelines. Verify the procedure matches the actual MDR timelines — many organizations still use MDD timelines which are different. Then check actual practice: pull 5 complaints from the last 12 months and verify each was assessed for reportability. For any that were determined to be reportable, verify the report was submitted within the required timeframe. For any determined to be non-reportable, verify the rationale is documented. Missing reportability assessments are a systemic finding — one missing assessment suggests many may be missing.

What to sample

Pull 5 complaints from the last 12 months. Verify each has a documented reportability assessment. For any reported incidents, verify the report was submitted within the required timeframe.

Follow-up questions
  • Walk me through a recent complaint that was evaluated as non-reportable — how did you reach that conclusion?
  • Have you submitted any serious incident reports in the last 12 months? If so, were they within the required timeframes?
  • How do you handle reports from users that do not clearly meet the serious incident definition but raise safety concerns?
Article 87(2-4) Does the manufacturer report serious incidents within the required timelines — 15 days for general serious incidents, 10 days for death or unanticipated serious deterioration, and 2 days for serious public health threats? Are initial, follow-up, and final reports managed systematically?
Objective evidence
  • Incident reporting log — verify it tracks report dates against event awareness dates and confirms compliance with required timelines
  • Evidence of initial, follow-up, and final report submissions for each reported incident — verify the reporting lifecycle is managed through to conclusion
  • Template or form for vigilance reports — verify it captures all required information per Annex to Commission Implementing Regulation
  • Procedure for follow-up reports — verify it defines triggers for follow-up (investigation progress, root cause identified, FSCA initiated) and timelines for submission
Common nonconformities
  • Initial report was submitted after the required deadline — the manufacturer became aware of a death-related event on day 1 but the initial report was submitted on day 18, exceeding the 10-day requirement (Major NC).
  • Final reports have not been submitted for incidents reported more than 12 months ago — initial reports exist but no follow-up or final report has been filed, leaving multiple incidents without closure (Major NC).
  • No tracking system exists for vigilance report status — the manufacturer cannot demonstrate that all reported incidents have been followed through to final report submission (Minor NC).
Auditor tip

Timeline compliance is objectively measurable — compare the 'date of awareness' against the 'date of initial report submission.' If the gap exceeds the required timeframe, it is a clear nonconformity. Also check the back end — are final reports being submitted? Many manufacturers submit initial reports but fail to close the reporting lifecycle with final reports after the investigation is complete. An open, unresolved vigilance report is both a regulatory and a quality concern.

What to sample

Request the vigilance reporting log. Verify timeline compliance for all reports submitted in the last 12 months. Check for open reports awaiting final closure.

Follow-up questions
  • How do you define the 'date of awareness' for purposes of starting the reporting clock — is it the date the complaint is received, or the date the event is assessed as reportable?
  • How many open (unfinalized) vigilance reports do you currently have, and what is the oldest?
  • How do you ensure that follow-up information from the investigation reaches the regulatory team for timely submission?
Article 89 Does the manufacturer have a procedure for implementing field safety corrective actions (FSCAs)? When an FSCA is initiated, does the manufacturer issue a field safety notice (FSN) and coordinate the action across all affected Member States?
Objective evidence
  • FSCA procedure — verify it defines the process for evaluating the need for an FSCA, planning the corrective action, communicating with competent authorities and users (FSN), executing the action, and verifying effectiveness
  • Field safety notice template or example — verify it contains all required elements (device identification, description of the problem, advice to users, manufacturer contact information)
  • FSCA coordination records — if an FSCA has been executed, verify the manufacturer coordinated the action across all Member States where affected devices were distributed
  • FSCA effectiveness records — verify the manufacturer assessed whether the FSCA achieved its intended outcome
Common nonconformities
  • No FSCA procedure exists — the manufacturer has never conducted an FSCA and has not prepared a procedure for doing so (Minor NC).
  • FSCA was executed in one Member State but not in others where the affected device was distributed — the manufacturer did not coordinate the action across all affected markets (Major NC).
  • Field safety notice does not identify the specific devices affected — the notice is generic and does not include lot numbers, serial numbers, or date ranges to enable users to identify affected units (Minor NC).
Auditor tip

Even if the manufacturer has never executed an FSCA, the procedure must exist and the organization must be prepared to execute one. Ask the manufacturer to walk you through a hypothetical FSCA scenario to test their readiness. If an FSCA has been executed, verify it was coordinated across all affected Member States — incomplete geographic coverage of an FSCA is a serious compliance gap. Check that the field safety notice was adequate for users to identify and respond to affected devices.

What to sample

Review the FSCA procedure. If an FSCA was executed, review the FSN, coordination records across Member States, and effectiveness verification.

Follow-up questions
  • If you identified a safety issue tomorrow that required a field recall, what would be your first 3 actions?
  • How do you determine which Member States are affected when initiating an FSCA?
  • If you have executed an FSCA, how did you verify that the corrective action reached all affected users?
Article 88 Has the manufacturer established a trend reporting process for statistically significant increases in the frequency or severity of non-serious incidents or expected side-effects that could have a significant impact on the benefit-risk analysis?
Objective evidence
  • Trend reporting procedure — verify it defines the methodology for detecting statistically significant increases in non-serious incidents, the thresholds for triggering a trend report, and the reporting pathway to competent authorities
  • Statistical trend analysis records — verify the manufacturer performs regular (at least quarterly) trend analysis on complaint and incident data using defined statistical methods
  • Trend report submissions (if any) — verify any trend reports submitted to competent authorities include the period of concern, the observed increase, the expected baseline, and the manufacturer's assessment of impact on benefit-risk
Common nonconformities
  • No trend reporting process exists — the manufacturer monitors individual incidents but has no procedure for detecting population-level trends in non-serious events (Major NC).
  • Trend analysis is performed but uses no statistical methodology — the manufacturer manually reviews complaint logs without defined baselines, thresholds, or statistical methods (Minor NC).
  • The manufacturer is unaware of the Article 88 trend reporting obligation and has not considered it as part of their vigilance system (Major NC).
Auditor tip

Trend reporting is one of the most overlooked obligations under EU MDR. Unlike individual incident reporting, trend reporting requires the manufacturer to detect population-level signals — a gradual increase in a non-serious complaint type that, individually, would not be reportable but collectively may indicate a safety concern. Check that the manufacturer has a defined methodology for trend detection, including baseline rates, thresholds for significance, and a defined review frequency.

What to sample

Request the trend reporting procedure and the most recent trend analysis output. Verify the methodology includes defined baselines and statistical significance criteria.

Follow-up questions
  • What baseline rates do you use for your most common complaint types, and how were those baselines established?
  • What statistical methods do you use to determine whether an increase in complaint frequency is statistically significant?
  • Have you ever identified a trend that required reporting — if not, how do you know your trend detection method is sensitive enough?
§udi Udi and traceability (articles 27-29) 5 items · ~90 min
Article 27(1-3) Has the manufacturer assigned a UDI to each device and, where applicable, to all higher levels of packaging? Does the UDI comprise both a UDI-DI (device identifier) and a UDI-PI (production identifier)?
Objective evidence
  • UDI assignment records — verify a UDI-DI has been obtained from an EU-recognized issuing entity (GS1, HIBCC, ICCBBA, IFA) for each device variant and packaging level
  • UDI-PI generation methodology — verify the manufacturer has defined how the production identifier (lot number, serial number, manufacturing date, expiry date) is created and applied to each device unit
  • UDI database entries — verify the manufacturer's UDI data has been submitted to EUDAMED (or the applicable national database if EUDAMED is not yet fully operational for UDI)
  • Internal UDI management procedure — verify a documented process exists for UDI assignment, maintenance, and updates when device configurations change
Common nonconformities
  • No UDI has been assigned to the device despite the applicable implementation deadline having passed — the manufacturer has not engaged with any UDI issuing entity (Major NC).
  • UDI-DI has been assigned at the device level but not at higher packaging levels (box, carton, pallet) — only partial UDI assignment exists (Minor NC).
  • UDI data has not been submitted to EUDAMED or the applicable database — UDIs exist internally but are not registered in the required public database (Major NC).
  • UDI-PI does not include all required production identifiers — lot number is included but manufacturing date and expiry date are missing despite being required for the device type (Minor NC).
Auditor tip

Check the UDI implementation timeline first — different device classes have different deadlines. For Class III and implantable devices, UDI should already be fully implemented. For Class I devices, the timeline may still be in effect. Verify that UDI-DIs come from an EU-recognized issuing entity — using internal part numbers or arbitrary identifiers does not comply. Check all packaging levels — the UDI requirement extends beyond the device label to box, case, and shipping container levels.

What to sample

Request UDI records for 2 devices. Verify the UDI-DI is from a recognized issuing entity. Check that the UDI-PI includes all required production identifiers. Verify a label sample carries the UDI carrier.

Follow-up questions
  • Which UDI issuing entity do you use, and why did you select them?
  • When you create a new device variant, what is the process for obtaining a new UDI-DI?
  • How do you handle UDI assignment for devices with multiple configurations or accessories?
Article 27(4) Is the UDI carrier placed on the label of the device and on all higher levels of packaging in both human-readable (plain text) and machine-readable (barcode or RFID) formats? For reusable devices requiring reprocessing, is the UDI placed on the device itself?
Objective evidence
  • Label samples showing the UDI carrier in both human-readable and machine-readable formats — verify the barcode scans correctly and the human-readable text matches
  • Packaging samples at all levels (unit, box, case) showing UDI carriers — verify each packaging level carries the appropriate UDI
  • For reusable devices subject to reprocessing, evidence of direct marking on the device — verify the UDI is placed on the device itself in a way that remains legible through the expected number of reprocessing cycles
  • Barcode verification records — verify the manufacturer has validated that the machine-readable UDI carrier scans correctly and encodes the correct UDI
Common nonconformities
  • UDI carrier is in human-readable format only — no machine-readable barcode or RFID exists on the label (Minor NC).
  • UDI barcode does not scan correctly — the machine-readable carrier fails verification and does not encode the correct UDI-DI and UDI-PI (Major NC).
  • Reusable device subject to reprocessing does not have a direct-marked UDI — the UDI appears only on the outer packaging, which is discarded after first use (Major NC).
  • UDI carrier on outer packaging is missing or inconsistent with the device-level UDI — higher-level packaging carries an outdated UDI-DI (Minor NC).
Auditor tip

This is a verification activity — request physical label samples or production devices and check them directly. Scan the barcode with a verification scanner to confirm it encodes the correct data. Verify human-readable text matches. For reusable devices, check whether direct marking has been implemented and — critically — whether the marking remains legible after simulated reprocessing cycles. Direct marking is one of the most frequently delayed UDI obligations.

What to sample

Pull production labels and packaging for one device. Verify UDI carrier presence and scannability. For reusable devices, check direct marking.

Follow-up questions
  • Have you verified that your UDI barcodes scan correctly at typical reading distances and under typical conditions?
  • For your reusable devices, how many reprocessing cycles has the direct-marked UDI been validated to withstand?
  • How do you ensure UDI labels are updated when the UDI-DI or UDI-PI changes due to device or packaging modifications?
Article 28 Has the manufacturer submitted device information to EUDAMED in accordance with Article 28 and Annex VI Part B? Is the EUDAMED data kept up to date when device information changes?
Objective evidence
  • EUDAMED registration records — verify the manufacturer's basic UDI-DI data has been submitted per Annex VI Part B requirements (device description, classification, intended purpose, manufacturer information, Notified Body, certificates)
  • Evidence of data maintenance — verify EUDAMED entries are updated when device information changes (new variants, classification changes, certificate updates)
  • If EUDAMED UDI module is not yet fully operational, evidence of submission to the applicable alternative system
  • Internal procedure for EUDAMED data management — verify responsibilities are assigned for initial data submission and ongoing maintenance
Common nonconformities
  • Manufacturer has not registered any device data in EUDAMED despite the applicable modules being operational — no registration activity has occurred (Major NC).
  • EUDAMED entries are outdated — device variants added in the last year are not reflected in the database registration (Minor NC).
  • No internal procedure exists for EUDAMED data management — data submissions are ad hoc with no assigned responsibility or review cycle (Minor NC).
Auditor tip

EUDAMED implementation has been phased, with different modules becoming operational at different times. Verify which modules are currently operational and whether the manufacturer has met their obligations for each. The UDI database module and actor registration module are typically the first to become operational. If the manufacturer claims EUDAMED is not yet operational for their required submissions, verify that claim against the current EUDAMED deployment status.

What to sample

Request evidence of EUDAMED submissions. Cross-reference EUDAMED entries against the manufacturer's current device portfolio to identify any unregistered devices.

Follow-up questions
  • Which EUDAMED modules have you registered data in, and which are pending?
  • How do you ensure EUDAMED data stays current when device specifications or certificates change?
  • Who in your organization is responsible for EUDAMED data management?
Article 18 For implantable devices, does the manufacturer provide an implant card to the patient? Does the implant card contain the information required by Article 18(1), including the UDI, device identification, manufacturer details, warnings, and expected device lifetime?
Objective evidence
  • Implant card template or sample — verify it includes all Article 18(1) requirements: device identification, UDI, manufacturer name and address, any necessary warnings or precautions, expected device lifetime, and information needed to allow the patient to identify the device
  • Process for providing the implant card — verify the manufacturer supplies the implant card with the device so that the healthcare professional can give it to the patient after implantation
  • Implant card language versions — verify the card is available in the languages required by the Member States where the device is placed on the market
  • Content review records — verify the implant card content was reviewed against Article 18(1) and approved through the document control process
Common nonconformities
  • No implant card is provided with the device despite it being an implantable device — the manufacturer is unaware of the Article 18 requirement (Major NC).
  • Implant card does not include the UDI — the card identifies the device by product name and catalog number but does not include the UDI (Minor NC).
  • Implant card does not include expected device lifetime — this required element is missing, preventing the patient from understanding when follow-up or replacement may be needed (Minor NC).
  • Implant card is provided only in English but the device is marketed in non-English-speaking Member States — patients cannot read the safety information on the card (Major NC).
Auditor tip

The implant card is a patient-facing document — it must be understandable by a non-medical person and provided in the appropriate language. If the manufacturer makes implantable devices, request a sample implant card and check it against the Article 18(1) requirements point by point. The expected device lifetime is a frequently missing element because it requires the manufacturer to commit to a specific timeframe, which they may be reluctant to do without sufficient clinical data. This reluctance does not remove the requirement.

What to sample

Request a sample implant card. Check all Article 18(1) elements are present. Verify the language is appropriate for target markets.

Follow-up questions
  • How did you determine the expected device lifetime stated on the implant card — what data supports that claim?
  • How does the implant card reach the patient — through the surgeon, the hospital, or another pathway?
  • Is the implant card content reviewed and updated when new clinical data affects the expected device lifetime or safety warnings?
Article 25 Has the manufacturer established a traceability system that enables devices to be traced through the supply chain from the manufacturer to the end user? Can the manufacturer identify where a specific device lot or serial number was distributed?
Objective evidence
  • Traceability procedure — verify it describes the traceability system from incoming materials through manufacturing, packaging, distribution, and where possible to the end user (healthcare facility or patient for implantable devices)
  • Distribution records for a specific device lot — verify the manufacturer can identify which distributors, importers, or healthcare facilities received a specific lot number or serial number
  • Upstream traceability records — verify incoming materials and components can be traced to their suppliers and linked to finished device lots
  • Traceability exercise or drill records — verify the manufacturer has tested their traceability system's ability to identify all affected units in a recall scenario
Common nonconformities
  • Distribution records identify first-level distributors but not downstream customers — the manufacturer cannot identify which healthcare facilities ultimately received a specific device lot (Minor NC).
  • No traceability exercise has ever been performed — the manufacturer assumes the system works but has never tested it under simulated recall conditions (Minor NC).
  • Upstream traceability is incomplete — raw materials and components cannot be traced to finished device lots because lot documentation is not linked between incoming inspection and production batch records (Major NC).
Auditor tip

Traceability is only useful if it works when you need it — during a recall. Ask the manufacturer to trace a specific device lot from production through to distribution destinations. Time the exercise. If it takes hours to compile the information from multiple disconnected systems, the traceability system is not fit for purpose. Also test upstream traceability — can the manufacturer determine which component lots went into a finished device lot? This is critical for identifying scope when a supplier notifies of a component quality issue.

What to sample

Select a random device lot number. Ask the manufacturer to trace it forward to distribution and backward to component suppliers. Measure response time and completeness.

Follow-up questions
  • If you received a supplier notification that a component lot was defective, how quickly could you identify every finished device lot that contains that component?
  • Have you ever performed a mock recall — what was the outcome and what did you learn?
  • For your implantable devices, can you trace individual serial numbers to the healthcare facility where they were implanted?
§labeling Labeling and instructions for use (annex i chapter iii) 3 items · ~90 min
Annex I Section 23.2 Does the device label contain all required elements per Annex I Section 23.2, including manufacturer identification, device description, UDI carrier, CE marking, warnings, sterility status, lot or serial number, date of manufacture, and expiry date?
Objective evidence
  • Production label sample — verify against the Annex I Section 23.2 checklist, confirming presence of: manufacturer name and registered place of business, device description sufficient for user identification, lot number and/or serial number, UDI carrier in human-readable and machine-readable formats, CE marking with Notified Body number (for Class IIa/IIb/III), sterility status and sterilization method (if applicable), single-use designation (if applicable), date of manufacture, expiry date or use-by date (if applicable), storage and handling conditions, specific warnings or precautions
  • Label specification document — verify the design specification matches the production label and includes all mandatory elements
  • Label change control records — verify labels are controlled documents subject to change management, with evidence of review and approval prior to production release
Common nonconformities
  • CE marking appears on the label without the Notified Body number for a Class IIa device — the CE mark must include the NB identification number for devices that require NB involvement in conformity assessment (Major NC).
  • Manufacturer address on the label does not match the registered place of business — the label shows a marketing office address rather than the legal entity's registered address (Minor NC).
  • Single-use designation is missing from a device intended for single use — the label does not include the symbol per ISO 15223-1 indicating the device must not be reused (Major NC).
  • Expiry date format is inconsistent across product lines — some labels use YYYY-MM-DD while others use MM/YYYY, and the IFU does not explain the date format used (Minor NC).
Auditor tip

This is a checklist exercise — take a production label and work through Section 23.2 point by point. Every missing element is a finding. Pay special attention to the UDI carrier (newly required under MDR), the CE marking format (NB number must be included for devices requiring NB involvement), and single-use designations (missing single-use symbols on disposable devices is a common and serious finding because it affects reprocessing safety). Use ISO 15223-1 as the reference for symbols.

What to sample

Pull production labels for 3 devices of different risk classes. Check each against the Section 23.2 requirements point by point. Note any missing or incorrect elements.

Follow-up questions
  • Walk me through your label review process — who checks the label against Annex I Section 23.2 before it goes to production?
  • How do you ensure label consistency across product variants and packaging levels?
  • When did you last update your labels, and what triggered the change?
Annex I Section 23.4 Do the instructions for use (IFU) contain all required information per Annex I Section 23.4, including intended purpose, performance characteristics, residual risks, installation and maintenance information, sterilization instructions, warnings, and contraindications?
Objective evidence
  • Instructions for use document — verify against the Section 23.4 checklist, confirming presence of: intended purpose with indications and contraindications, user qualifications and training needs, performance characteristics, residual risks and side effects, information on combination with other devices, required accessories, warnings and precautions, installation and setup instructions, maintenance and calibration instructions, reprocessing instructions (for reusable devices), sterilization method and instructions (if applicable), disposal information
  • Traceability from risk management to IFU — verify that residual risks identified in the risk management file as requiring user information are addressed in the IFU
  • Usability study or IFU validation results — for high-risk devices, verify the IFU was tested with representative users to confirm comprehensibility
Common nonconformities
  • IFU does not list contraindications — the manufacturer has identified contraindications in the clinical evaluation but they do not appear in the IFU (Major NC).
  • Residual risks identified in the risk management file are not communicated in the IFU — the risk management report identifies residual risks requiring user information but the IFU does not address them (Major NC).
  • IFU does not specify the required qualifications of the intended user — the device requires specialized clinical training to use safely but the IFU does not state this (Minor NC).
  • Reprocessing instructions for a reusable device are incomplete — the IFU provides cleaning instructions but does not specify the validated sterilization method or cycle parameters (Major NC).
Auditor tip

The IFU is where risk management meets the end user. Open the risk management file and find every residual risk that was accepted on the basis of information supplied with the device. Then verify each one appears in the IFU. Any gap between the risk management file and the IFU is a finding — the manufacturer cannot claim a risk is controlled through user information if that information is not actually provided. Also check for completeness against the Section 23.4 list — missing contraindications and missing reprocessing instructions are particularly common findings.

What to sample

Compare the IFU against the risk management file. Verify every residual risk requiring user information appears in the IFU. Check the IFU against the Section 23.4 checklist for completeness.

Follow-up questions
  • How do you verify that every residual risk requiring user information is actually communicated in the IFU?
  • Have you tested the IFU with representative users to confirm they can understand and follow the instructions?
  • When the risk management file is updated with new residual risks, how does that trigger an IFU update?
Annex I Section 23.1 Has the manufacturer determined which information is necessary for safe use, verified it with representative users, and provided it in the appropriate form (label, IFU, or both)? Is the information provided in a language understood by the intended user, in plain terms where possible?
Objective evidence
  • Usability engineering file or human factors analysis — verify the manufacturer has assessed which information users need for safe operation and how that information should be presented
  • User comprehension testing results (where applicable) — for devices used by lay users or in safety-critical applications, verify the information was tested with representative users
  • Language availability matrix — verify IFUs and labels are available in all languages required by Member States where the device is marketed
  • Lay user information — for devices intended for lay users (patients, caregivers), verify the information is written in non-technical language understandable by the intended audience
Common nonconformities
  • No usability assessment has been performed for the information provided with the device — the manufacturer did not systematically determine what information users need for safe use (Minor NC).
  • IFU uses highly technical medical terminology but the device is intended for use by patients at home — the language is not appropriate for the intended user population (Major NC).
  • IFU is available only in English but the device is sold in Member States where English is not sufficient under national requirements (Major NC).
Auditor tip

EU MDR places more emphasis on usability and comprehensibility than MDD. For devices used by lay users (home-use diagnostics, patient-applied devices), the information must be in plain language. For all devices, the manufacturer should have considered what information is needed for safe use through a usability engineering process. Check that the language matches the intended user profile described in the technical documentation.

What to sample

Review the IFU for readability against the intended user profile. For lay-user devices, assess whether the language is truly comprehensible to non-medical users.

Follow-up questions
  • Who is the intended user of this device, and how did you determine what information they need for safe use?
  • Have you received any complaints or feedback indicating that users find the IFU difficult to understand?
  • How do you manage translation quality — do you use validated translation processes with back-translation verification?
§supply.chain Supply chain and economic operators (articles 11-16) 5 items · ~90 min
Article 11 If the manufacturer is established outside the EU, has it designated an authorized representative established within the EU? Does a written mandate exist specifying the authorized representative's responsibilities, and does the mandate cover the tasks listed in Article 11(3)?
Objective evidence
  • Written mandate between the manufacturer and the EU authorized representative — verify it is current, signed by both parties, specifies the tasks the AR is authorized to perform per Article 11(3), and identifies the device types covered
  • AR registration evidence — verify the authorized representative is registered in EUDAMED (or the applicable national system) as the AR for the manufacturer's devices
  • Evidence of AR activity — verify the AR performs the tasks specified in the mandate (e.g., making technical documentation available to competent authorities, cooperating with competent authorities on recalls, ensuring the manufacturer maintains a compliant QMS)
  • Verification that the AR has appropriate organizational capability — staffing, expertise, and systems to fulfill the mandate
Common nonconformities
  • No written mandate exists — the manufacturer has an informal arrangement with an EU-based entity but no formal written mandate per Article 11(1) has been executed (Major NC).
  • Written mandate does not cover all Article 11(3) tasks — the mandate is limited to device registration but does not include making technical documentation available to competent authorities or cooperating with vigilance obligations (Major NC).
  • Authorized representative mandate has expired — the agreement has a defined term that has lapsed, and no renewal exists (Major NC).
  • The authorized representative does not have access to the manufacturer's technical documentation — the mandate specifies responsibility for making documentation available but the AR does not possess or have access to the documents (Minor NC).
Auditor tip

For manufacturers established outside the EU, the authorized representative is their regulatory presence in Europe. The written mandate is a legally significant document — verify it exists, is current, and covers all required tasks. Then verify the AR is actually performing those tasks. A mandate that exists on paper but is not operationally supported is a compliance risk. If the manufacturer is established within the EU, an authorized representative is not required, but verify the manufacturer is performing all AR-equivalent functions directly.

What to sample

Request the written mandate. Verify it covers Article 11(3) tasks. Contact or interview the AR if possible to verify operational capability.

Follow-up questions
  • How frequently do you communicate with your authorized representative, and on what topics?
  • Does your authorized representative have real-time access to your technical documentation and vigilance records?
  • If a competent authority contacted your authorized representative today requesting technical documentation, could they provide it?
Article 13 Has the manufacturer verified that importers of its devices comply with their obligations under Article 13? Do importers verify that the manufacturer has carried out conformity assessment, drawn up technical documentation, attached the CE marking, and appointed an authorized representative?
Objective evidence
  • List of importers that import the manufacturer's devices into the EU — verify the manufacturer knows who imports their devices
  • Quality agreements or distribution agreements with importers specifying Article 13 obligations — verify importers have committed to verifying CE marking, DoC availability, labeling compliance, and UDI assignment before placing devices on the market
  • Evidence that importers perform required verifications — incoming inspection records, label checks, or verification checklists used by importers upon receipt of devices
  • Importer registration evidence — verify importers are registered in EUDAMED (or applicable national system)
Common nonconformities
  • Manufacturer does not know which entities import its devices into EU Member States — no importer tracking exists (Minor NC).
  • No quality agreement or distribution agreement defines the importer's verification obligations — the relationship is purely commercial with no quality or regulatory terms (Major NC).
  • Importers do not verify CE marking or labeling compliance before placing devices on the market — there is no evidence that any incoming verification is performed at the importer level (Minor NC).
Auditor tip

Under EU MDR, importers have direct obligations — this is a significant change from MDD. While the importer is responsible for their own compliance, the manufacturer should ensure that importer obligations do not create a gap in the compliance chain. Verify that the manufacturer has visibility into their distribution chain and that quality agreements or distribution agreements address Article 13 obligations. If the manufacturer sells through distributors who also import, clarify the regulatory role of each entity.

What to sample

Request the list of importers and associated quality agreements. Verify at least one agreement addresses Article 13 verification obligations.

Follow-up questions
  • How do you ensure your importers are complying with their Article 13 obligations?
  • Do you have quality agreements with your EU importers, and what regulatory obligations are included?
  • If an importer receives a complaint about your device, how does that information reach you?
Article 14 Has the manufacturer verified that distributors of its devices understand and comply with their obligations under Article 14? Do distributors verify that the device bears the CE marking, the DoC is available, labeling is in the required language, and — where applicable — the importer has met its obligations?
Objective evidence
  • Distributor agreements specifying Article 14 obligations — verify that distribution agreements include quality and regulatory terms addressing the distributor's verification duties
  • Evidence of distributor compliance monitoring — verification records, audit reports, or self-assessment questionnaires from distributors
  • Procedure for managing distributor quality issues — verify the manufacturer has a process for addressing distributor non-compliance that could affect device safety or regulatory conformity
Common nonconformities
  • Distribution agreements are purely commercial and do not address Article 14 regulatory obligations — the distributor's verification duties are not contractually defined (Minor NC).
  • The manufacturer does not monitor distributor compliance — no audits, questionnaires, or verification activities exist for the distribution channel (Minor NC).
Auditor tip

Distributor obligations under EU MDR are less onerous than importer obligations but still exist. The key requirement is that distributors verify the device appears to comply before making it available on the market (CE marking, labeling language, UDI). For the manufacturer, the focus is on having distribution agreements that address these obligations and maintaining awareness of the distribution chain.

What to sample

Review one distribution agreement for quality and regulatory terms. Verify the manufacturer has a list of active distributors.

Follow-up questions
  • How many distributors do you have in the EU, and how do you monitor their compliance?
  • If a distributor stores or transports your devices incorrectly, how would you become aware of it?
Article 16 When an importer or distributor performs activities that make them a manufacturer under EU MDR (relabeling, repackaging, modifying intended purpose, or marketing under their own name), do they assume the manufacturer's obligations? Does the original manufacturer have visibility into these activities?
Objective evidence
  • Assessment of whether any economic operator in the supply chain performs activities that trigger manufacturer status under Article 16 — verify the manufacturer has evaluated this risk
  • Contractual provisions addressing relabeling, repackaging, or private labeling arrangements — if such arrangements exist, verify the obligations of each party are clearly defined
  • Evidence of communication with economic operators regarding Article 16 applicability — verify economic operators have been informed that certain activities would make them a manufacturer under EU MDR
Common nonconformities
  • A distributor relabels the device with its own name and address without assuming manufacturer obligations — the distributor is operating as a de facto manufacturer under Article 16 but has not performed conformity assessment (Major NC).
  • No assessment exists of whether economic operators in the supply chain perform activities triggering Article 16 — the manufacturer has not evaluated this regulatory risk (Minor NC).
Auditor tip

Article 16 is a tricky provision that many organizations overlook. Any importer or distributor that relabels, repackages, modifies the intended purpose, or markets a device under their own name becomes a manufacturer with full manufacturer obligations. Verify the manufacturer has assessed whether any of their economic operators are performing these activities. This is particularly relevant for private label or OEM arrangements.

What to sample

Review private label or OEM arrangements if they exist. Verify the regulatory role assignment is clear and compliant with Article 16.

Follow-up questions
  • Do any of your importers or distributors sell your device under their own brand name?
  • Are you aware of any entity in your supply chain that relabels or repackages your device?
Article 12 Has the manufacturer ensured that systems and procedures are in place to change the name or registered trade name of a device or to transfer the manufacturer role to another entity in compliance with Article 12? Has the competent authority been notified of any such changes?
Objective evidence
  • Procedure for manufacturer role changes — if applicable, verify a documented process exists for transferring manufacturer status to another legal entity
  • Records of any device name or trade name changes — verify these changes were implemented through proper change control and reflected in technical documentation, labeling, EUDAMED, and NB certificates
  • Competent authority notification records — if a change of manufacturer or device name occurred, verify the competent authority was notified as required
Common nonconformities
  • Device was rebranded without updating the technical documentation or EUDAMED registration — the device name on the label no longer matches the registered device name (Minor NC).
  • Manufacturer legal entity changed due to a corporate restructuring but the competent authority and Notified Body were not notified — certificates and registrations reference the old legal entity (Major NC).
Auditor tip

This provision applies during corporate changes — mergers, acquisitions, rebranding, or legal entity restructuring. If the manufacturer has undergone any such change, verify that the regulatory documentation chain was properly updated. Check that the Declaration of Conformity, EUDAMED registration, NB certificate, and labeling all reference the current legal entity.

What to sample

If applicable, verify consistency of the manufacturer name across the DoC, NB certificate, EUDAMED, and device labeling.

Follow-up questions
  • Has your company undergone any name changes, mergers, or legal entity restructuring in the last 3 years?
  • If so, were all regulatory documents updated to reflect the new legal entity?
§classification Classification and conformity assessment 3 items · ~60 min
Article 51, Annex VIII Has the manufacturer classified each device in accordance with Annex VIII classification rules? Is the classification justified with documented rationale identifying the applicable classification rule(s) and supporting analysis?
Objective evidence
  • Classification rationale document for each device — verify it identifies the applicable Annex VIII rule(s), explains why those rules apply based on the device's characteristics and intended purpose, and states the resulting classification (Class I, IIa, IIb, or III)
  • Analysis of whether any new MDR-specific rules apply — verify the manufacturer has assessed whether rules introduced or modified by EU MDR (Rule 11 for software, Rule 19 for nanomaterials, Rule 21 for substances absorbed/dispersed) affect their device classification
  • Comparison with MDD classification (if transitioning from MDD) — verify any classification changes have been identified and the regulatory implications documented
  • Notified Body agreement with the classification — for Class IIa/IIb/III devices, verify the Notified Body has accepted the manufacturer's classification determination
Common nonconformities
  • No documented classification rationale exists — the manufacturer states the device is Class IIa but cannot produce a document explaining which Annex VIII rule was applied (Major NC).
  • Classification was performed under MDD rules and has not been reassessed under MDR rules — the manufacturer is unaware that certain classification rules changed under MDR (Major NC).
  • Software classification does not follow Rule 11 — the manufacturer classified software as Class I based on MDD criteria but under MDR Rule 11 the software qualifies as Class IIa or higher based on the severity of the information it provides (Major NC).
  • Classification analysis does not consider all applicable rules — only one rule was evaluated when multiple rules apply, and the most stringent rule should determine the classification per Article 51(6) (Minor NC).
Auditor tip

Classification is the foundation — everything else depends on it being correct. Read the intended purpose first, then walk through the Annex VIII rules systematically to verify the manufacturer's determination is correct. Pay special attention to software devices (Rule 11 is frequently misapplied), devices incorporating nanomaterials (Rule 19), and devices that were reclassified from MDD to MDR. When multiple rules apply, the most stringent classification prevails per Article 51(6). If you suspect the classification is wrong, this is a showstopper finding that invalidates the entire conformity assessment.

What to sample

Request classification rationale documents for 2 devices. Verify the analysis is complete, the correct rule is applied, and the resulting classification is justified.

Follow-up questions
  • Walk me through the classification analysis for your highest-risk device — which rules did you consider and how did you determine the applicable one?
  • If your device was classified under MDD, did the classification change under MDR? If not, did you verify that no MDR-specific rules affected it?
  • If your device includes software, how did you apply Rule 11?
Article 52 Has the manufacturer selected and followed the appropriate conformity assessment procedure for each device based on its classification? For devices requiring Notified Body involvement, has a Notified Body been engaged and are their certificates valid?
Objective evidence
  • Conformity assessment route documentation — verify the manufacturer has identified the applicable Annex (IX, X, XI) based on the device classification and justified the selected route
  • Notified Body certificates (for Class IIa/IIb/III) — verify certificates are issued by a Notified Body designated under EU MDR (not just MDD), are within their validity period, and cover the devices in the manufacturer's portfolio
  • Evidence of Notified Body engagement — audit schedules, audit reports, or correspondence demonstrating ongoing Notified Body oversight per the selected conformity assessment procedure
  • For Class I devices (without measuring function, sterile, or surgical/reusable), verification that self-declaration under Annex IV plus internal production control per Annex II is sufficient — or identification of the scenarios where NB involvement is still required (sterile, measuring, surgical reusable)
Common nonconformities
  • Notified Body certificate was issued under MDD (93/42/EEC) and has not been reissued under EU MDR (2017/745) — the manufacturer is operating under a transition certificate that may have expired or may not cover all current devices (Major NC).
  • Conformity assessment route does not match the device classification — the manufacturer followed a conformity assessment procedure intended for a lower risk class (Major NC).
  • No documented analysis exists for why the selected conformity assessment Annex was chosen — the manufacturer cannot explain the choice between Annex IX, X, or XI (Minor NC).
  • Notified Body certificate has expired — the manufacturer continues to place devices on the market under an expired certificate (Major NC).
Auditor tip

This check confirms the manufacturer is using the right regulatory pathway. The conformity assessment route must match the device classification. For Class III and Class IIb implantable devices, the manufacturer must generally follow Annex IX or Annex X plus XI. For Class IIa and IIb, options vary. For Class I, self-declaration is generally sufficient except for sterile, measuring, or reusable surgical devices which require NB involvement. Check NB certificate validity — during the MDD-to-MDR transition, many certificates are expiring or transitioning.

What to sample

Verify NB certificate validity dates and scope. Cross-reference the conformity assessment route against the device classification. Confirm the NB is designated under EU MDR for the relevant conformity assessment procedures.

Follow-up questions
  • When does your current Notified Body certificate expire, and what is your plan for renewal or transition?
  • If your Notified Body's designation were to be revoked or limited, what is your contingency plan?
  • For each conformity assessment route you follow, can you explain why you chose that specific Annex?
Article 10(14) If the manufacturer makes a device available in a Member State, is the device registered in that Member State in accordance with Article 29? Has the manufacturer registered in EUDAMED with a Single Registration Number (SRN)?
Objective evidence
  • EUDAMED actor registration showing the manufacturer's Single Registration Number (SRN) — verify the registration is current and the information (legal name, address, role) is accurate
  • Device registrations per Member State — verify the manufacturer has submitted device information per Article 29 requirements for each Member State where the device is made available
  • If EUDAMED is not yet fully operational, evidence of registration through national competent authority systems
  • Procedure for maintaining registrations — verify updates are submitted when device information, manufacturer information, or certificates change
Common nonconformities
  • Manufacturer has not obtained a Single Registration Number in EUDAMED — actor registration has not been completed (Major NC).
  • Device registrations are not complete for all Member States where the device is marketed — devices are available in 15 Member States but registered in only 8 (Minor NC).
  • Registration data is outdated — the manufacturer's address, device list, or certificate information has changed but EUDAMED entries have not been updated (Minor NC).
Auditor tip

EUDAMED registration obligations are phased, and not all modules may be fully operational. Verify which modules are currently live and whether the manufacturer has met its obligations for each. Actor registration (SRN) is typically the first requirement. Device registration follows. If the manufacturer claims registration is not yet required, verify against the current EUDAMED deployment timeline.

What to sample

Verify the manufacturer's EUDAMED SRN. Cross-reference device registrations against the manufacturer's market list to identify any unregistered markets.

Follow-up questions
  • What is your EUDAMED Single Registration Number, and when was it issued?
  • Are your device registrations current for all Member States where you market your devices?
  • How do you monitor EUDAMED for new module launches that may trigger additional registration obligations?
§gspr General safety and performance (annex i) 6 items · ~120 min
Annex I Section 1-4 Do the devices achieve the intended performance as specified by the manufacturer? Does the manufacturer demonstrate that the devices are safe and effective when used under the conditions and for the purposes intended, with any residual risks being acceptable when weighed against the benefits?
Objective evidence
  • Performance data demonstrating the device meets its specified performance characteristics — verify test reports, clinical data, or simulations that support performance claims
  • Safety data demonstrating the device does not compromise the clinical condition or safety of patients, users, or third persons — verify through risk management file, pre-clinical testing, and clinical evaluation
  • Documentation of state-of-the-art consideration — verify the manufacturer has evaluated the device against current technological and medical knowledge
  • Residual risk acceptability analysis — verify each residual risk has been evaluated against the benefit of the device and found acceptable per the manufacturer's risk acceptability criteria
Common nonconformities
  • Performance claims on the label or marketing materials exceed what is supported by the verification and validation data — the manufacturer claims a performance characteristic that has not been tested or demonstrated (Major NC).
  • Residual risk acceptability is stated without supporting analysis — the manufacturer concludes all residual risks are acceptable but provides no risk acceptability criteria, comparative analysis, or clinical justification (Major NC).
  • State-of-the-art analysis has not been performed — the manufacturer has not compared the device's safety profile against current alternatives and medical knowledge (Minor NC).
Auditor tip

The GSPRs are the 'so what' of the entire technical documentation — they define what the device must achieve and what hazards must be controlled. Start with the manufacturer's performance claims and verify each is supported by objective data. Then review the residual risk analysis to confirm each risk has been evaluated with defined acceptability criteria. The state-of-the-art requirement is often overlooked — the manufacturer must demonstrate they are aware of current technological capabilities and medical knowledge relevant to their device.

What to sample

Select 3 performance claims from the IFU or marketing materials. Trace each to supporting data in the technical documentation. Verify the data supports the claim.

Follow-up questions
  • For each performance characteristic you claim, where is the supporting data — test report, clinical study, or literature?
  • What criteria do you use to determine whether a residual risk is acceptable?
  • How do you stay current with the state of the art in your device's technology area?
Annex I Section 5 Has the manufacturer eliminated or reduced risks as far as possible through safe design and manufacture (inherent safety by design)? Where risks cannot be eliminated, have adequate protection measures been implemented, and where protection measures are insufficient, has information for safety been provided?
Objective evidence
  • Risk management file demonstrating the risk control hierarchy was applied — verify the manufacturer considered inherent safety by design first, then protective measures, then information for safety, in that order
  • Design rationale records showing where design choices were made specifically to eliminate hazards — not just mitigate them through warnings
  • Protective measures (guards, alarms, interlocks, redundancy) — verify they are documented, implemented, and verified for effectiveness
  • Information for safety measures — verify residual risks that cannot be eliminated or protected against are communicated through labeling and IFU (cross-reference to Section 8 of this checklist)
Common nonconformities
  • Risk management file shows risk controls that jump directly to 'information for safety' (label warnings) without documenting why inherent safety and protective measures were not feasible — the risk control hierarchy was not applied (Major NC).
  • No design rationale exists demonstrating inherent safety considerations — the design was optimized for function and cost but safety was addressed only through add-on controls and labeling (Minor NC).
Auditor tip

The risk control hierarchy (design, protect, inform) is mandatory under EU MDR, just as it is under ISO 14971. But under MDR, Notified Bodies are increasingly scrutinizing whether the manufacturer genuinely considered inherent safety by design. Look for design rationale records that explain why certain hazards could not be eliminated through design. If the majority of risk controls are information-based (warnings and precautions), challenge whether design or protective measures were adequately considered first.

What to sample

Review the risk control measures in the risk management file. Verify the hierarchy was applied — look for evidence of design-level controls, not just warnings.

Follow-up questions
  • Give me an example of a hazard you eliminated through design rather than through a warning or protective measure
  • For risks controlled through protective measures, how do you verify the protective measure is effective?
  • When you add a new warning to the IFU, do you first evaluate whether the risk could be controlled through design or a protective measure instead?
Annex I Section 10 For devices with a biological or chemical hazard profile, has the manufacturer addressed biocompatibility, chemical substance restrictions, and biological safety through appropriate evaluation and testing? Are devices designed to minimize risks from substances leaching from the device or from contact with tissues?
Objective evidence
  • Biological evaluation plan per ISO 10993-1 — verify the plan identifies all materials in contact with the body, the nature and duration of contact, and the biological evaluation strategy (testing and/or existing data rationale)
  • Biocompatibility test reports or literature justifications — verify all identified material-tissue contact combinations have been evaluated
  • Chemical characterization of materials — verify the manufacturer has characterized the chemical composition of materials in contact with the body, including extractables and leachables analysis where applicable
  • Assessment of substances of concern (CMR, endocrine disruptors) per Annex I Section 10.4 — verify the manufacturer has assessed whether the device contains substances listed in Annex I Section 10.4.1 and, if so, has justified their use
Common nonconformities
  • No biological evaluation plan exists — the manufacturer relies on material supplier certifications without performing a device-level biocompatibility evaluation (Major NC).
  • Chemical characterization has not been performed — extractables and leachables analysis was not conducted for a device with prolonged tissue contact (Major NC).
  • Device contains a substance classified as CMR (carcinogenic, mutagenic, or reprotoxic) above the threshold in Annex I Section 10.4.1 but no justification for its presence has been documented (Major NC).
  • Biocompatibility testing was performed on raw materials rather than the finished, sterilized device — test results may not reflect the actual biological risk of the device as used (Minor NC).
Auditor tip

EU MDR Annex I Section 10.4 introduces specific requirements for substances of concern (CMR substances, endocrine disruptors, substances on the REACH candidate list) that did not exist under MDD. If the device contains any such substance above 0.1% w/w, the manufacturer must document a justification for its presence. This is a new obligation that many manufacturers have not yet addressed. Check the chemical characterization against the REACH candidate list and CLP Regulation classifications.

What to sample

Request the biological evaluation plan and chemical characterization. Verify materials in contact with the body have been evaluated. Check for Annex I Section 10.4 substance assessment.

Follow-up questions
  • Have you assessed whether any materials in your device contain substances classified as CMR or listed on the REACH candidate list?
  • If your device uses PVC with DEHP or other phthalates, what is your justification for their use?
  • How do you ensure that your biocompatibility testing reflects the finished, sterilized device rather than raw material properties?
Annex I Section 17 For devices incorporating software or for standalone software devices, has the manufacturer developed and validated the software in accordance with the state of the art, taking into account the principles of the development lifecycle, risk management, and information security? Does the software classification match its intended purpose?
Objective evidence
  • Software lifecycle documentation per IEC 62304 — verify the software development process is documented, including requirements, architecture, design, implementation, testing, and maintenance
  • Software classification based on the potential harm from software failure — verify the classification (A, B, or C per IEC 62304) is documented and justified
  • Software verification and validation records — verify unit testing, integration testing, system testing, and user acceptance testing have been performed with documented results
  • Cybersecurity risk assessment — verify the manufacturer has assessed cybersecurity risks per Annex I Section 17.4, particularly for devices connected to networks or the internet
  • Software version management and update procedure — verify a process exists for managing software updates, including regulatory assessment of whether an update triggers a new conformity assessment
Common nonconformities
  • No software lifecycle documentation exists — the software was developed without a formal development process per IEC 62304 (Major NC).
  • Software device classification under Rule 11 has not been performed — the manufacturer has not assessed the software's classification based on the clinical significance of the information it provides (Major NC).
  • Cybersecurity risk assessment does not exist for a device connected to hospital networks — the manufacturer has not considered data integrity, unauthorized access, or denial-of-service risks (Major NC).
  • Software update procedure does not address regulatory impact assessment — updates are released without evaluating whether they constitute a significant change requiring NB notification (Minor NC).
Auditor tip

Software requirements under EU MDR are significantly more detailed than under MDD. Rule 11 in Annex VIII introduces a classification scheme based on the clinical significance of the information the software provides — many software devices that were Class I under MDD are now Class IIa or higher under MDR. Check the classification first. Then verify the software lifecycle follows IEC 62304 and that cybersecurity has been assessed per Section 17.4. For AI/ML-based software, ask about algorithm validation, training data quality, and ongoing performance monitoring.

What to sample

Request the software lifecycle documentation, software risk management file, and cybersecurity assessment. Verify Rule 11 classification is documented and justified.

Follow-up questions
  • How did you classify your software under MDR Rule 11, and what is the clinical significance of the information it provides?
  • How do you manage cybersecurity throughout the software lifecycle — threat modeling, vulnerability scanning, incident response?
  • If your software uses machine learning, how do you validate the algorithm and monitor its real-world performance?
Annex I Section 11-12 For devices emitting radiation (ionizing or non-ionizing) or incorporating energy sources, has the manufacturer designed the device to minimize unintended radiation exposure and energy hazards? Are protection measures in place, and is information provided to the user on residual radiation risks?
Objective evidence
  • Radiation safety analysis — verify the manufacturer has identified all sources of radiation (intended and unintended), assessed exposure levels, and demonstrated compliance with applicable limits or ALARA principles
  • Radiation emission testing results — verify test reports demonstrate compliance with applicable harmonized standards (IEC 60601-1-2 for EMC, IEC 62471 for optical radiation, IEC 60825 for lasers)
  • Electrical safety testing per IEC 60601-1 — for electrically powered devices, verify basic safety and essential performance testing has been completed
  • User information on radiation risks — verify labeling and IFU include warnings about radiation exposure, protection instructions, and any required safety accessories
Common nonconformities
  • EMC testing has not been updated to the current version of IEC 60601-1-2 — the manufacturer tested against an older edition that is no longer listed as a harmonized standard (Minor NC).
  • Radiation emission levels exceed applicable limits but no risk assessment or justification exists for the elevated levels (Major NC).
  • Labeling does not include required radiation warning symbols despite the device emitting ionizing or non-ionizing radiation above de minimis levels (Major NC).
Auditor tip

These requirements apply to a wide range of devices — from X-ray equipment and lasers to wireless connected devices and LED-based devices. Check whether the manufacturer has identified all energy sources and radiation emissions, not just the intended ones. EMC compliance (Section 12) applies to essentially all electrically powered devices and is frequently found to be tested against outdated standards. Verify test reports reference current harmonized standards.

What to sample

Request radiation and EMC test reports. Verify they reference current harmonized standards and demonstrate compliance with applicable limits.

Follow-up questions
  • What sources of radiation does your device emit — both intended and unintended?
  • Which edition of IEC 60601-1-2 did you test against, and is it the currently harmonized edition?
  • How do you ensure that electromagnetic interference from your device does not affect other medical devices in the clinical environment?
Annex I Section 14 For devices that are sterile or supplied with a sterilization method, has the manufacturer validated the sterilization process? Is there a quality system to control the sterilized condition of the device throughout its shelf life?
Objective evidence
  • Sterilization validation records per the applicable standard (ISO 11135 for EO, ISO 11137 for radiation, ISO 17665 for moist heat) — verify validation protocol, execution data, acceptance criteria, and approval
  • Sterility assurance level (SAL) documentation — verify the validated SAL meets regulatory requirements (typically 10⁻⁶ for terminally sterilized medical devices)
  • Packaging validation per ISO 11607 — verify the sterile barrier system has been validated for seal strength, integrity, and sterility maintenance through the stated shelf life
  • Environmental monitoring and cleanroom classification records — for aseptically processed devices, verify environmental controls are monitored and maintained
Common nonconformities
  • Sterilization validation is incomplete — the validation was performed on an initial product configuration but has not been re-validated after changes to the device, packaging, or loading pattern (Major NC).
  • Packaging validation has not been performed — the sterile barrier system has not been validated per ISO 11607 for sterility maintenance through the shelf life (Major NC).
  • No routine sterilization process monitoring exists — the process is validated but there is no evidence of routine dose verification (radiation) or biological indicator monitoring (EO) per production cycle (Major NC).
Auditor tip

Sterilization is a special process — its results cannot be fully verified by subsequent inspection, so validation is essential. Verify the complete validation package: protocol, execution with actual data, acceptance criteria assessment, and approval. Check that routine process monitoring confirms the validated parameters are maintained during production. For EO sterilization, also verify that residual EO and ECH levels comply with ISO 10993-7.

What to sample

Review the sterilization validation package. Verify routine process monitoring records for the last 3 production cycles. Check packaging validation per ISO 11607.

Follow-up questions
  • When was your sterilization process last re-validated, and what triggered the re-validation?
  • How do you confirm that each production sterilization cycle achieved the validated SAL?
  • If you use EO sterilization, how do you verify EO residual levels comply with ISO 10993-7?
§transition Mdr transition and ongoing compliance 3 items · ~60 min
Article 120(3) For devices placed on the market under MDD certificates, has the manufacturer ensured those certificates remain valid, and has it initiated the MDR conformity assessment process with a Notified Body designated under EU MDR? Is there a documented transition plan with milestones?
Objective evidence
  • MDD certificate validity assessment — verify the manufacturer has identified all devices currently on the market under MDD certificates and confirmed the certificate expiry dates against the extended transition deadline
  • MDR transition plan — verify a documented plan exists with milestones for completing MDR conformity assessment for each device or device group, including technical documentation update, NB engagement, and certification timeline
  • Evidence of NB engagement under MDR — verify the manufacturer has contracted with an MDR-designated Notified Body and the conformity assessment process is underway
  • Gap assessment between MDD and MDR requirements — verify the manufacturer has identified the specific gaps between their current MDD-compliant documentation and MDR requirements
Common nonconformities
  • No MDR transition plan exists — the manufacturer has valid MDD certificates but has not planned the transition to MDR conformity assessment (Major NC).
  • MDD certificate will expire before the MDR conformity assessment can be completed, and the manufacturer has no contingency plan for market continuity (Major NC).
  • Gap assessment has not been performed — the manufacturer has not identified what additional documentation, testing, or clinical data is needed for MDR compliance (Minor NC).
  • Manufacturer has not engaged an MDR-designated Notified Body — the current NB is not designated under MDR, and no application has been filed with an MDR-designated NB (Major NC).
Auditor tip

The MDR transition is time-critical. Many manufacturers are racing to complete MDR certification before their MDD certificates expire. Check the transition timeline first — is the manufacturer on track? If the MDD certificate expires before MDR certification is achieved, the manufacturer may need to withdraw the device from the market (subject to sell-off provisions). Also verify that the Notified Body the manufacturer has engaged is designated under EU MDR — not all MDD-designated NBs received MDR designation.

What to sample

Review the MDR transition plan and timeline. Verify NB engagement. Check MDD certificate expiry dates against the transition schedule.

Follow-up questions
  • When do your MDD certificates expire, and when do you expect to receive MDR certificates?
  • What is the critical path in your transition plan — which devices or documentation elements are at greatest risk of delay?
  • If your MDR certification is delayed beyond your MDD certificate expiry, what is your market continuity plan?
Article 120(4) For devices placed on the market under MDD certificates during the transition period, does the manufacturer continue to comply with MDD requirements and applicable MDR provisions (PMS, vigilance, registration, economic operator obligations)? Is there documented evidence of dual compliance where required?
Objective evidence
  • Evidence of MDD compliance maintenance — verify the manufacturer continues to maintain MDD compliance for devices on the market under MDD certificates (QMS, surveillance activities)
  • Evidence of MDR obligation compliance — verify the manufacturer complies with MDR provisions that apply regardless of certification status, specifically: PMS system per Article 83, vigilance reporting per Articles 87-89, EUDAMED registration per Article 29, and economic operator obligations
  • Dual compliance matrix — a documented mapping showing which obligations apply under MDD and which under MDR during the transition period, with evidence of compliance for each
Common nonconformities
  • Manufacturer is not complying with MDR PMS requirements for devices still under MDD certificates — the manufacturer assumes MDD PMS obligations are sufficient, but MDR PMS requirements are more extensive and apply during the transition (Major NC).
  • Vigilance reporting continues under MDD timelines and criteria rather than MDR requirements — Article 87 applies to all devices regardless of certificate type during the transition (Minor NC).
  • No dual compliance analysis exists — the manufacturer has not mapped which obligations apply under each regulatory framework during the transition period (Minor NC).
Auditor tip

The transition period creates a dual-compliance scenario. Even for devices on the market under MDD certificates, certain MDR obligations apply immediately — particularly PMS, vigilance, EUDAMED registration, and economic operator obligations. Verify the manufacturer understands which obligations apply from each regulation and is meeting both sets of requirements. This is a frequently confused area — many manufacturers incorrectly assume that MDD compliance is sufficient until their MDR certificates are issued.

What to sample

Review the dual compliance mapping. Verify MDR PMS and vigilance obligations are met for MDD-certified devices. Check EUDAMED registration status.

Follow-up questions
  • Which MDR obligations are you currently complying with for devices still under MDD certificates?
  • How do you handle vigilance reporting during the transition — are you using MDD or MDR criteria and timelines?
  • Have you registered in EUDAMED for devices under MDD certificates?
Article 120 For devices already placed on the market or put into service before the MDR application date, does the manufacturer comply with the sell-off provisions? Are devices that were lawfully placed on the market still being distributed within the allowed timeframe?
Objective evidence
  • Inventory of devices placed on the market under MDD that are still in the distribution chain — verify the manufacturer tracks which legacy devices are still being sold through or distributed
  • Sell-off timeline compliance — verify devices in the distribution chain are being sold within the allowed sell-off period per Article 120
  • PMS and vigilance compliance for legacy devices — verify the manufacturer continues to meet PMS and vigilance obligations for legacy devices still in the distribution chain
Common nonconformities
  • Devices placed on the market under MDD are still being distributed after the sell-off deadline has passed — the manufacturer has not tracked inventory in the distribution chain against the regulatory timeline (Major NC).
  • PMS obligations have been discontinued for legacy devices — the manufacturer stopped collecting PMS data for devices transitioned out of production but still in use in the field (Major NC).
Auditor tip

The sell-off provisions allow devices lawfully placed on the market before certain deadlines to continue to be made available or put into service for a limited period. The key question is timing — verify the manufacturer knows which devices are still in the distribution chain and whether they are within the allowed sell-off period. Also verify that PMS and vigilance obligations continue for devices in the field, even after production has ceased.

What to sample

Review the inventory of legacy devices. Verify sell-off timeline compliance. Confirm PMS continues for devices in the field.

Follow-up questions
  • Do you have legacy MDD devices still in the distribution channel? If so, when is the sell-off deadline?
  • How do you maintain PMS and vigilance obligations for devices that are no longer in production but still in use?

Each item shows its evidence, common nonconformities and auditor tips. The PDF holds the same content, formatted for a clipboard.

Frequently Asked Questions

What is the EU MDR?

The EU Medical Device Regulation (MDR) 2017/745 replaced the Medical Device Directive (MDD) 93/42/EEC. It establishes a comprehensive regulatory framework for medical devices in the European Union, covering the entire product lifecycle from design through post-market surveillance. Full application began May 26, 2021.

What are the key differences between EU MDR and MDD?

The EU MDR introduces stricter clinical evaluation requirements, mandatory post-market surveillance for all device classes, a new UDI system, expanded vigilance reporting, economic operator obligations, and requirements for a Person Responsible for Regulatory Compliance (PRRC). Classification rules were also updated, resulting in some devices being reclassified to higher risk classes.

Do I need a new CE mark under EU MDR?

Devices certified under the MDD with valid certificates can benefit from transitional provisions, but all devices must eventually comply with the EU MDR. New devices placed on the market must comply with EU MDR requirements and obtain certification from a Notified Body designated under the MDR. The transition timeline depends on device class and certificate expiry dates.

What is EUDAMED?

EUDAMED is the European Database on Medical Devices. Under the EU MDR, manufacturers must register their devices, upload UDI data, and submit certain documentation through EUDAMED. The database will also be used for vigilance reporting, clinical investigations, and market surveillance. Full EUDAMED functionality is being rolled out in phases.
Aligntra also runs this kind of documentation review automatically — see how it works.