EU MDR Compliance Checklist
Objective Evidence
- Declaration of Conformity per Article 19 and Annex IV — verify it references the correct EU MDR regulation number (2017/745), lists applicable conformity assessment procedures, and is signed by an authorized person with a recent date
- Technical documentation per Annex II demonstrating design and manufacturing controls — confirm it exists as a structured file rather than a loose collection of documents
- Evidence of conformity assessment route selection based on device classification — verify the selected Annex (IX, X, XI) matches the device risk class per Annex VIII
- Notified Body certificate (for Class IIa/IIb/III) — confirm validity dates, scope coverage, and any restrictions or conditions noted on the certificate
Common Nonconformities
- Declaration of Conformity references the old Medical Device Directive (93/42/EEC) instead of EU MDR 2017/745 — the organization has not updated its declarations despite placing devices on the market under EU MDR (Major NC).
- No documented system exists for ensuring ongoing conformity — the organization treats conformity as a one-time event at product launch rather than a continuous obligation (Major NC).
- The conformity assessment route selected does not match the device classification — a Class IIb device is being assessed under a procedure intended for Class IIa, indicating a classification error or procedural gap (Major NC).
- Technical documentation exists but has not been updated to reflect design changes made after initial market placement — Article 10(1) requires ongoing conformity, not just initial conformity (Minor NC).
Auditor Tips
Start by asking for the Declaration of Conformity and work backwards. The DoC is the manufacturer's formal claim of compliance — if it references the wrong regulation, the wrong classification, or an expired Notified Body certificate, everything downstream is suspect. Check that the organization understands the difference between MDD and MDR declarations, especially during the transition period.
Follow-Up Questions
- Walk me through how you determined the conformity assessment route for your highest-risk device — what analysis supported that decision?
- When was the last time you updated your Declaration of Conformity, and what triggered the update?
- If a design change is made to a device already on the market, what is your process for reassessing conformity?
What to Sample
Request the Declaration of Conformity for 2 devices of different risk classes. Cross-reference against Notified Body certificates and technical documentation to confirm alignment.
Objective Evidence
- Risk management plan per ISO 14971 — verify it references EU MDR Annex I general safety and performance requirements (GSPRs) and covers the full product lifecycle including post-market phases
- Risk management file containing hazard identification, risk analysis, risk evaluation, and risk control records — confirm completeness against the risk management plan
- Benefit-risk analysis per Article 10(2) and Annex I Section 1 — verify it explicitly concludes that residual risks are acceptable when weighed against benefits under normal conditions of use
- Evidence that risk management outputs feed into design controls, labeling, and post-market surveillance — trace at least one identified risk through to its control measure and monitoring plan
- Post-production risk management activities — verify that complaint data, vigilance reports, and field safety actions feed back into the risk management file
Common Nonconformities
- Risk management file was created during product development but has never been updated with post-market data — no evidence that field complaints, PMCF data, or trend analyses have been incorporated (Major NC).
- Benefit-risk determination is a single statement in the risk management report without supporting quantitative or qualitative analysis — the conclusion is unsupported (Minor NC).
- Risk management plan does not reference EU MDR Annex I GSPRs — the plan is written to ISO 14971 alone without addressing regulation-specific requirements (Minor NC).
- No documented link between identified risks and corresponding labeling warnings or instructions for use — risk controls that rely on information supplied with the device are not traceable to actual label content (Major NC).
Auditor Tips
EU MDR explicitly requires that risk management cover the entire product lifecycle, which is a broader scope than many organizations practiced under MDD. Look specifically for post-market feedback loops — the risk management file should be a living document that gets updated with real-world data, not a static design-phase artifact. The benefit-risk analysis is an MDR-specific obligation that goes beyond ISO 14971 and must be documented explicitly.
Follow-Up Questions
- Show me an example where post-market data led to a change in your risk management file — what was the data source and what action was taken?
- How do you determine whether a residual risk is acceptable — what criteria do you use and who makes the final determination?
- How does your risk management system address risks from foreseeable misuse?
What to Sample
Select one device and trace a single hazard from identification through risk analysis, control implementation, verification of effectiveness, and post-market monitoring. Verify the chain is complete and documented.
Objective Evidence
- Clinical evaluation report (CER) per Annex XIV Part A — verify it follows a systematic methodology (literature review, clinical investigation data, and/or equivalence analysis), includes defined search criteria, and reaches a documented conclusion on safety and performance
- Clinical evaluation plan defining the scope, appraisal methodology, and update frequency — confirm it addresses both pre-market and post-market clinical data requirements
- PMCF plan per Annex XIV Part B — verify it defines specific clinical questions to be addressed, data collection methods, and the rationale for chosen methods (surveys, registries, investigations)
- PMCF evaluation report documenting results of post-market clinical data collection and any actions taken — confirm it references the PMCF plan and addresses each planned clinical question
- Evidence of CER update within the organization's defined review cycle — for Class III and implantable devices, verify annual update per Article 61(11)
Common Nonconformities
- Clinical evaluation report is a literature review from three years ago that has not been updated to incorporate recent publications, adverse event data, or PMCF results — the CER does not reflect current clinical knowledge (Major NC).
- PMCF plan exists as a template but no PMCF activities have been performed — the organization treats PMCF as a theoretical requirement rather than an operational obligation (Major NC).
- CER relies on equivalence to a predicate device but does not demonstrate equivalence across all three dimensions required by Annex XIV (clinical, technical, and biological) — the equivalence claim is insufficiently supported (Major NC).
- No documented process for triggering a CER update when new clinical data becomes available — updates are ad hoc rather than systematic (Minor NC).
Auditor Tips
Clinical evaluation is one of the most scrutinized areas under EU MDR. Notified Bodies routinely raise findings on insufficient CERs, particularly around equivalence claims and PMCF execution. The bar for demonstrating equivalence has increased significantly under MDR compared to MDD — ask specifically how clinical, technical, and biological equivalence was established and whether a contractual access agreement exists for the equivalent device's technical documentation. For Class III and implantable devices, verify annual CER updates as a hard regulatory requirement.
Follow-Up Questions
- If you claim equivalence to another manufacturer's device, do you have a contractual agreement to access their technical documentation? If not, how do you demonstrate equivalence?
- What triggered your most recent CER update, and what new data was incorporated?
- How do you integrate PMCF findings back into your benefit-risk analysis and risk management file?
What to Sample
Request the CER and PMCF plan for one device. Verify the CER's literature search is reproducible (defined databases, search terms, date ranges). Check whether PMCF results have actually been collected and analyzed per the plan.
Objective Evidence
- Technical documentation index or table of contents showing coverage of all Annex II elements — device description, design and manufacturing information, GSPRs, benefit-risk analysis, product verification and validation, clinical evaluation
- Post-market surveillance documentation per Annex III — PMS plan, PMS report or PSUR, PMCF plan and report
- Evidence that technical documentation has been reviewed and updated following design changes, manufacturing changes, or new post-market data — verify revision history and approval records
- Document control system showing how technical documentation is maintained, versioned, and retrievable — confirm the system supports Notified Body audit access
Common Nonconformities
- Technical documentation is incomplete — one or more Annex II sections are entirely missing or contain only placeholder text (Major NC).
- Technical documentation was prepared for initial certification but has not been updated to reflect three subsequent design changes — the current documentation does not describe the device as manufactured and placed on the market (Major NC).
- Post-market surveillance documentation per Annex III does not exist as a structured component — PMS data is scattered across complaint files with no consolidated PMS plan or report (Minor NC).
- Technical documentation is stored across multiple systems with no master index — the manufacturer cannot readily present the complete file for inspection within a reasonable timeframe (Minor NC).
Auditor Tips
Think of the technical documentation as the manufacturer's proof file — it must tell the complete story of the device from concept through post-market experience. Under MDR, the technical documentation requirements are more prescriptive than under MDD. Walk through the Annex II checklist systematically: device description and specification, information supplied by the manufacturer, design and manufacturing information, GSPRs, benefit-risk analysis, product verification and validation, and clinical evaluation. Each section should contain substantive content, not just references to other documents that may or may not exist.
Follow-Up Questions
- If I asked your Notified Body auditor to produce your complete technical documentation for one device within 24 hours, could your team do it?
- How do you decide when a change to a device triggers an update to the technical documentation versus when it does not?
- Who is responsible for maintaining the technical documentation, and how do you ensure completeness when multiple departments contribute content?
What to Sample
Select one device and walk through the Annex II table of contents. Open 3 random sections and verify they contain current, substantive content with approval signatures and revision dates.
Objective Evidence
- Record retention policy or procedure specifying retention periods for EU MDR documentation — verify it explicitly states 10 years (or 15 years for implantable devices) from the date the last device covered by the DoC was placed on the market
- Document management system configuration showing retention period settings for technical documentation, DoCs, and certificates — confirm settings match policy
- Evidence that historical documentation is actually retrievable — request a DoC or technical documentation for a device placed on the market more than 2 years ago and verify it can be produced
- Backup and disaster recovery procedures for regulatory documentation — confirm that electronic records are protected against loss
Common Nonconformities
- Record retention policy specifies 5 years, which is the ISO 13485 minimum but does not meet the EU MDR 10-year requirement — the policy was not updated for MDR transition (Minor NC).
- No distinction in retention periods between standard devices (10 years) and implantable devices (15 years) — all documentation is subject to the same retention period regardless of device type (Minor NC).
- The retention period is calculated from the date of document creation rather than from the date the last device was placed on the market — the calculation method does not comply with Article 10(8) (Minor NC).
- Historical technical documentation from 4 years ago cannot be retrieved because the document management system was migrated and older records were not carried forward (Major NC).
Auditor Tips
This is a straightforward compliance check but frequently missed during MDR transition. Organizations that had 5-year retention under MDD or ISO 13485 often fail to update their retention policies to the MDR minimum. Pay special attention to how the retention clock starts — it is not from document creation date but from the date the last device covered by the Declaration of Conformity was placed on the market, which could be many years after the document was first created.
Follow-Up Questions
- How do you determine the date the last device was placed on the market for purposes of starting the retention clock?
- If your document management system were to fail, how would you recover your regulatory documentation?
- Do you have any implantable devices, and if so, are their retention periods set to 15 years?
What to Sample
Check the record retention procedure. Then request documentation for the oldest device still on the market. Verify it is retrievable and complete.
Objective Evidence
- Post-market surveillance plan per Article 84 — verify it defines data sources (complaints, vigilance, literature, registries, PMCF), collection methods, analysis frequencies, and responsibilities
- PMS report (Class I) or Periodic Safety Update Report (PSUR, Class IIa/IIb/III) — verify it is current within the required update cycle and contains actual data analysis, not just data summaries
- Evidence that PMS data feeds back into risk management, clinical evaluation, and design — trace at least one PMS finding through to a corrective or preventive action
- Trend analysis methodology and results — verify the manufacturer is actively looking for statistically significant increases in complaints, incidents, or adverse events
Common Nonconformities
- PMS plan exists but the manufacturer has not actually collected or analyzed post-market data — the plan is a paper exercise without operational implementation (Major NC).
- No trend analysis is performed on complaint and incident data — individual events are investigated but no population-level trend analysis exists (Major NC).
- PSUR has not been updated within the required cycle — for Class IIb and III devices the PSUR must be updated at least annually, and the most recent version is more than 18 months old (Minor NC).
- PMS system does not include proactive data collection methods — the manufacturer waits for complaints rather than actively collecting data from literature, registries, or clinical follow-up (Minor NC).
Auditor Tips
PMS under EU MDR is fundamentally different from the MDD approach. It is no longer sufficient to passively collect complaints — manufacturers must proactively seek out and analyze safety and performance data from multiple sources. The key test is whether PMS data actually flows back into the risk management file, clinical evaluation, and preventive actions. Ask to see the data flow, not just the plan.
Follow-Up Questions
- Show me an example where PMS data changed your risk assessment or triggered a CAPA — what was the data source and how long did it take from data collection to action?
- How do you identify trends in your post-market data — what statistical methods or thresholds do you use?
- What proactive data sources do you monitor beyond customer complaints?
What to Sample
Request the PMS plan and the most recent PMS report or PSUR. Verify the report contains actual data analysis (not just summaries) and that at least one finding resulted in a documented action.
Objective Evidence
- Label samples for each device variant — verify they include all elements required by Annex I Section 23 (manufacturer name and address, UDI carrier, device description, warnings, sterility status, lot/serial number, CE mark with Notified Body number where applicable)
- Instructions for use (IFU) for each device — verify they include all elements required by Annex I Section 23.4 (intended purpose, user profile, contraindications, warnings and precautions, residual risks, performance characteristics, installation and maintenance instructions)
- Language matrix showing which languages are provided per target market — verify compliance with Member State language requirements for each market where the device is placed
- Label and IFU review records showing regulatory and quality review prior to release — confirm that label content is traceable to design outputs and risk management conclusions
Common Nonconformities
- Label does not include a UDI carrier in machine-readable format — the organization has not implemented UDI on labels despite the device being within the applicable timeline (Major NC).
- Instructions for use do not address residual risks identified in the risk management file — there is a gap between risk management outputs and information supplied with the device (Major NC).
- Device labels are provided only in English but the device is marketed in Member States that require national language labeling — no translated labels exist for France, Germany, or Italy (Major NC).
- Warnings and precautions on the label do not match those specified in the risk management report — the label was not updated after the most recent risk management file revision (Minor NC).
Auditor Tips
Labeling is a frequent finding area because it sits at the intersection of multiple requirements — risk management outputs must feed into labeling content, UDI must be implemented per the applicable timeline, and language requirements vary by Member State. Pull a physical device (or production label sample) and systematically check it against the Annex I Section 23 checklist. Then cross-reference against the risk management file to verify that residual risks requiring user information are actually addressed on the label or in the IFU.
Follow-Up Questions
- How do you ensure that label content stays synchronized with risk management file updates?
- Walk me through your label change control process — when risk management identifies a new residual risk requiring user information, how does that become a label change?
- How do you manage language translations — do you use validated translation processes?
What to Sample
Pull a production label and IFU for one device. Check against Annex I Section 23 requirements point by point. Then open the risk management file and verify that residual risks identified as requiring user information are addressed in the IFU.
Objective Evidence
- Documented designation of the PRRC including name, role, and reporting line — verify the designation is formal (appointment letter, job description, or quality manual reference) rather than informal
- Evidence of PRRC qualifications — diploma or degree in a qualifying field plus at least one year of professional experience in regulatory affairs or quality management systems for medical devices, or four years of professional experience in those fields
- Job description defining PRRC responsibilities per Article 15(3) — verify it covers technical documentation conformity, DoC preparation, PMS obligations, reporting obligations, and clinical investigation statement issuance where applicable
- Evidence that the PRRC has operational access and authority to fulfill the role — meeting minutes, sign-off authority on regulatory submissions, or delegation records
Common Nonconformities
- No formal PRRC designation exists — the quality manager informally performs regulatory compliance tasks but has not been formally appointed as PRRC (Minor NC).
- The designated PRRC does not meet the qualification requirements — the individual has relevant experience but no qualifying diploma and fewer than four years of professional experience (Major NC).
- PRRC responsibilities are not documented — the individual has been designated by name but there is no documented scope of responsibilities matching Article 15(3) requirements (Minor NC).
- The PRRC has been designated but has no operational authority — regulatory submissions and technical documentation approvals are made by other personnel without PRRC review or sign-off (Minor NC).
Auditor Tips
PRRC is an EU MDR-specific requirement that did not exist under MDD. Many organizations have struggled with implementation, particularly micro and small enterprises that may use an external PRRC. Verify both the formal designation and the practical ability of the PRRC to fulfill the role. If the PRRC is external (e.g., a consultant), verify that a contractual agreement exists per Article 15(2) and that the arrangement allows the PRRC to genuinely fulfill responsibilities rather than being a paper exercise.
Follow-Up Questions
- Can I speak with your PRRC directly? How do they stay informed about regulatory changes that affect your devices?
- If the PRRC identifies a compliance concern, what authority do they have to halt a market release?
- Is your PRRC an employee or an external consultant? If external, how do you ensure they have sufficient access to your QMS and technical documentation?
What to Sample
Request the PRRC designation document and qualification evidence. Interview the PRRC about their role — ask them to describe their last interaction with a technical documentation review or vigilance reporting decision.
Objective Evidence
- Device description document within the technical file — verify it includes product name, model/variant identifiers, intended purpose statement, indications, contraindications, target patient population, intended user profile, and conditions of use
- Device classification justification per Annex VIII — verify the classification rule(s) applied, the rationale for the selected rule, and the resulting classification (I, IIa, IIb, III)
- Description of novel features or technologies and how they differ from existing devices — if the device incorporates novel materials, software algorithms, or nanomaterials, verify they are identified and their safety implications discussed
- Accessories and other devices intended to be used in combination — verify they are identified and their interaction described
- Configuration and variant matrix — for devices with multiple variants, verify the rationale for grouping them under a single technical documentation set
Common Nonconformities
- Intended purpose statement is vague or overly broad — it does not specify the medical condition being addressed, the target patient population, or the clinical context of use (Major NC).
- Device classification rule is cited without supporting rationale — the manufacturer states 'Rule 11' without explaining why that rule applies to the device's characteristics and intended purpose (Minor NC).
- Novel features are not identified — the device incorporates a proprietary algorithm for diagnostic support but the technical documentation does not describe it as novel or address its specific safety implications (Major NC).
- No variant or configuration matrix exists for a product family with 12 variants — it is unclear which technical documentation content applies to which variant (Minor NC).
Auditor Tips
The device description is the foundation of the entire technical documentation file — if the intended purpose is wrong or imprecise, everything that follows (classification, risk analysis, clinical evaluation, labeling) will be misaligned. Read the intended purpose statement carefully and compare it against marketing materials, labeling, and clinical evaluation scope. Misalignments between the regulatory intended purpose and how the device is marketed are a common and serious finding.
Follow-Up Questions
- Is the intended purpose in your technical documentation identical to what appears on your labeling and marketing materials? If there are differences, why?
- How did you determine that your classification rule is correct — did you consider alternative rules that could apply?
- Do any of your device variants have sufficiently different risk profiles that they should have separate technical documentation?
What to Sample
Compare the intended purpose in the technical documentation against the label, IFU, and any marketing materials. Verify the classification justification against Annex VIII rules.
Objective Evidence
- Current label artwork or proof for each device variant — verify all mandatory label elements per Annex I Section 23 are present
- Current Instructions for Use — verify content completeness against Annex I Section 23.4 requirements
- Language translation records — verify that translations exist for all Member States where the device is placed on the market
- Label review and approval records — confirm that label content was reviewed against design outputs and risk management file before release
Common Nonconformities
- Technical documentation does not contain the actual label artwork — only a text specification exists, and the final printed label has never been verified against the specification (Minor NC).
- IFU content is incomplete — mandatory sections such as contraindications, warnings related to residual risks, or maintenance requirements are missing (Major NC).
- Translations have not been verified by a qualified reviewer — machine-translated labels are used without human review, risking inaccurate safety information in the target language (Minor NC).
Auditor Tips
Compare what is in the technical file against a physical production label or finished product packaging. Discrepancies between the documented label design and the actual label on devices indicate a label control gap. Also check that information required by risk management (residual risk warnings) actually appears in the IFU.
Follow-Up Questions
- How do you ensure the printed label matches the approved artwork in the technical documentation?
- When a risk assessment identifies a new residual risk requiring user information, how does it get into the IFU?
What to Sample
Pull a finished product unit and compare the label against the technical documentation artwork. Check the IFU for completeness against Annex I Section 23.4.
Objective Evidence
- Manufacturing process flow diagram showing all process steps from incoming materials through packaging and release — verify it includes in-process controls, hold points, and inspection points
- Process validation records for special processes (sterilization, bonding, welding, sealing, software compilation) — verify validation protocols, execution records, and acceptance criteria are documented
- Supplier qualification records for critical suppliers — verify approved supplier list, quality agreements, and incoming inspection procedures exist
- Manufacturing site information — address, capabilities, GMP status, and whether manufacturing occurs at the manufacturer's own facility or at a subcontractor
- Design transfer records — evidence that design outputs were translated into production specifications with verification that production outputs meet design requirements
Common Nonconformities
- Process validation records for sterilization do not exist or are incomplete — the sterilization process is treated as a standard process rather than a special process requiring validation (Major NC).
- Subcontracted manufacturing processes are not described in the technical documentation — a critical assembly step is performed by a subcontractor but the technical documentation does not describe this arrangement or include the subcontractor's quality controls (Major NC).
- Supplier qualification records show initial qualification but no ongoing monitoring — suppliers qualified 5 years ago have never been re-evaluated (Minor NC).
Auditor Tips
This section must tell the story of how the device is actually made. Walk the manufacturing process flow and verify that each step described in the documentation matches what happens on the production floor (or at the subcontractor). Special processes — anything whose results cannot be fully verified by subsequent inspection — must be validated. Under EU MDR, subcontractors must be identified and their quality controls documented.
Follow-Up Questions
- Which of your manufacturing processes are classified as special processes, and how did you determine which processes require validation versus verification?
- How do you qualify and monitor your critical suppliers and subcontractors?
- When you make a manufacturing process change, what is the change control pathway?
What to Sample
Select one validated process and review the validation package (protocol, execution data, acceptance criteria, approval). Verify supplier qualification records for the top 2 critical suppliers.
Objective Evidence
- GSPR checklist or compliance matrix — verify it lists every requirement from Annex I Chapters I, II, and III, identifies which are applicable and which are not (with justification for non-applicability), and references the specific document or evidence that demonstrates compliance
- Cross-references from the GSPR checklist to supporting documentation — verify that at least 5 referenced documents exist and contain the claimed evidence
- Evidence that the GSPR checklist is maintained as a living document — revision history showing updates when new evidence becomes available or requirements change applicability
- Harmonized standards and common specifications applied — list of EN ISO standards used to demonstrate conformity with specific GSPRs, with applicability statements
Common Nonconformities
- GSPR checklist is incomplete — several applicable requirements are not addressed and no justification for exclusion is provided (Major NC).
- GSPR checklist references documents that do not exist — the checklist cross-references a biocompatibility report and a software validation report, but neither document can be located in the technical documentation (Major NC).
- GSPR checklist has not been updated since initial certification — new GSPRs added during design changes are not reflected in the current checklist (Minor NC).
- No distinction between applicable and non-applicable GSPRs — the checklist lists all requirements as applicable without evaluating which ones genuinely apply to the specific device (Minor NC).
Auditor Tips
The GSPR checklist is a powerful audit tool — it should function as a navigational map to the entire technical documentation. If the checklist is well-maintained, it accelerates the audit by directing you to evidence. If it is poorly maintained, that is itself a finding and also signals that the manufacturer may not understand which requirements apply to their device. Spot-check at least 5 cross-references to confirm the referenced evidence actually exists and supports the claimed compliance.
Follow-Up Questions
- For GSPRs you marked as not applicable, walk me through the justification for one of them — how did you determine it does not apply?
- When you apply a harmonized standard to demonstrate conformity with a GSPR, how do you handle requirements in the GSPR that are not covered by the standard?
- How frequently do you review the GSPR checklist for completeness and accuracy?
What to Sample
Request the GSPR checklist. Select 5 entries at random and trace each to the referenced supporting evidence. Verify the evidence exists and supports the compliance claim.
Objective Evidence
- Benefit-risk analysis document — verify it contains explicit identification of benefits (clinical outcomes, diagnostic accuracy, treatment efficacy), explicit identification of risks (from the risk management file), and a comparative analysis reaching a documented conclusion
- Risk management report summarizing the overall residual risk and its acceptability — verify it references the benefit-risk analysis and is signed by an authorized individual
- Risk-benefit ratio consideration for each identified residual risk — verify the analysis is not a generic statement but addresses specific risk-benefit trade-offs
- State-of-the-art analysis — evidence that the manufacturer considered current medical knowledge and available alternatives when determining risk acceptability
Common Nonconformities
- Benefit-risk analysis is a single paragraph concluding that benefits outweigh risks without any structured analysis — the determination is unsupported by evidence or methodology (Major NC).
- Benefits are described qualitatively but risks are described quantitatively, making meaningful comparison impossible — the analysis lacks methodological consistency (Minor NC).
- No consideration of the state of the art — the manufacturer has not compared the risk profile of the device against available alternatives or current clinical practice (Minor NC).
Auditor Tips
EU MDR places explicit emphasis on benefit-risk analysis in a way that MDD did not. The analysis must be substantive, not perfunctory. Look for actual clinical benefit data (from the CER or clinical investigations) being weighed against actual risk data (from the risk management file). A common shortcut is to state that benefits outweigh risks without demonstrating how that conclusion was reached. Challenge this — ask to see the methodology, the data inputs, and the decision criteria.
Follow-Up Questions
- What clinical evidence supports the benefits you claim in your benefit-risk analysis?
- How did you determine that the residual risks are acceptable — what threshold or criteria did you apply?
- How does your benefit-risk analysis account for alternative treatments or devices available to the patient?
What to Sample
Review the benefit-risk analysis document. Verify that benefits and risks are described with comparable rigor. Cross-reference benefits against clinical evaluation data and risks against the risk management file.
Objective Evidence
- Design verification test reports — verify they demonstrate that design outputs meet design inputs, with clear pass/fail criteria and actual results
- Design validation records — verify the device was validated under actual or simulated use conditions with representative users
- Biocompatibility evaluation per ISO 10993-1 — for devices contacting the body, verify a biological evaluation plan exists and appropriate testing has been completed
- Electrical safety and EMC test reports (where applicable) — verify testing was performed to applicable harmonized standards and results are within acceptance criteria
- Software verification and validation records (where applicable) — verify software lifecycle documentation per IEC 62304
- Sterilization validation records (where applicable) — verify the sterilization process is validated per the applicable standard (ISO 11135, ISO 11137, ISO 17665)
Common Nonconformities
- Design verification testing was performed on a prototype that differs from the production device — there is no evidence that verification results are applicable to the device as manufactured (Major NC).
- Biocompatibility evaluation consists of material data sheets only — no biological evaluation plan or testing per ISO 10993-1 has been performed (Major NC).
- Software validation records do not exist — the device contains embedded software but no software lifecycle documentation per IEC 62304 is available (Major NC).
- Design validation was performed by internal engineers rather than representative users — the validation does not reflect actual use conditions (Minor NC).
Auditor Tips
This section is where the technical evidence lives. Do not accept summaries or test report titles — open the actual reports and verify they contain raw data, acceptance criteria, and conclusions. For pre-clinical testing, check that the test articles match the production device (same materials, manufacturing process, sterilization method). For software, look for IEC 62304 lifecycle documentation including software requirements, architecture, unit testing, and integration testing. Missing pre-clinical data is one of the most common reasons Notified Bodies reject or delay technical documentation review.
Follow-Up Questions
- Are the test articles used in verification and validation testing representative of production devices — same materials, same manufacturing process, same sterilization?
- For your biocompatibility evaluation, what was the rationale for the tests selected — did you perform a biological evaluation plan per ISO 10993-1?
- How do you handle software changes — does every software change trigger re-validation, or do you have criteria for when re-validation is required?
What to Sample
Select one test report from each of 3 categories (mechanical/physical, biocompatibility, software/electrical). Verify that test articles match production specifications and that acceptance criteria were met.
Objective Evidence
- PMS plan per Article 84 — verify it covers data sources, analysis methods, indicators and thresholds for action, update frequency, and responsibilities
- PMS report (for Class I devices) or PSUR (for Class IIa/IIb/III devices) — verify the document is current within the required update cycle and contains data analysis conclusions and resulting actions
- PMCF plan per Annex XIV Part B — verify it defines specific clinical questions, data collection methods (surveys, registries, studies), and timelines
- PMCF evaluation report — verify it presents results from PMCF activities and any conclusions or actions resulting from the analysis
Common Nonconformities
- PSUR for a Class III device has not been updated annually as required — the most recent version is 20 months old (Major NC).
- PMCF plan exists but no PMCF activities have been conducted — the plan references a registry study that was never initiated (Major NC).
- PMS report for a Class I device exists but contains no actual data — it states 'no complaints received' without describing the complaint collection system or data sources monitored (Minor NC).
Auditor Tips
Annex III is specifically about post-market documentation within the technical file. Check that all four documents (PMS plan, PMS report or PSUR, PMCF plan, PMCF evaluation report) exist and are current. For PSURs, verify the update frequency matches the device class requirement. The PMCF plan and report are often the weakest — many manufacturers have a plan but have not executed it.
Follow-Up Questions
- When is your next PSUR due, and what data will it incorporate that was not in the previous version?
- What specific PMCF activities have you completed in the last 12 months?
What to Sample
Request all four Annex III documents for one device. Verify currency and completeness. For the PSUR, confirm data analysis is substantive.
Objective Evidence
- Regulatory strategy document or procedure — verify it identifies applicable conformity assessment procedures (Annex IX, X, XI) for each device, defines the manufacturer's approach to maintaining conformity, and assigns responsibilities
- Change management procedure for device modifications — verify it distinguishes between significant changes (requiring Notified Body notification per Article 10(9)(a)) and non-significant changes, with documented criteria for the distinction
- Records of device modifications showing the change evaluation process was followed — verify at least 2 recent changes were assessed for significance and the assessment is documented
- Procedure for notifying the Notified Body of planned significant changes — verify the procedure exists and has been followed for any significant changes since the last NB audit
Common Nonconformities
- No documented criteria for distinguishing significant from non-significant changes — all changes are treated equally, with no risk-based approach to determining NB notification requirements (Major NC).
- Device modifications have been implemented without a documented change evaluation — changes were made to manufacturing processes and materials without assessing whether the Notified Body should be notified (Major NC).
- Regulatory compliance strategy does not exist as a documented element of the QMS — the organization relies on informal knowledge of regulatory requirements without a systematic compliance framework (Minor NC).
Auditor Tips
The MDR places significant emphasis on change management for devices — particularly the requirement to notify the Notified Body of 'planned substantial changes.' Ask to see the criteria the manufacturer uses to determine whether a change is substantial. Then review actual change records and verify the criteria were applied consistently. If the manufacturer has made changes since the last Notified Body audit, verify they were assessed and — if significant — the Notified Body was notified.
Follow-Up Questions
- How do you determine whether a device modification is a 'significant change' requiring Notified Body notification?
- Show me the last 3 device changes — how was each one evaluated for significance?
- Has your Notified Body ever disagreed with your significance assessment? If so, what was the outcome?
What to Sample
Review the change management procedure and 3 recent device change records. Verify the significance assessment was performed and documented for each.
Objective Evidence
- Design and development procedure — verify it covers planning, inputs, outputs, review, verification, validation, transfer, and change control, with defined roles and responsibilities at each stage
- Production control procedures — verify they address work instructions, equipment qualification, environmental controls, in-process inspection, and final release criteria
- Purchasing and supplier management procedure — verify it includes supplier selection criteria, evaluation and re-evaluation processes, quality agreements, and incoming inspection requirements
- Records demonstrating implementation — design history file for a recent device, production batch records, supplier audit reports or evaluation records
Common Nonconformities
- Design and development procedure exists but no design history file has been created for the most recent device — the procedure is not being followed (Major NC).
- Supplier evaluation consists of a self-assessment questionnaire only — no on-site audits, performance monitoring, or quality agreements exist for critical suppliers (Minor NC).
- Production control procedures do not include acceptance criteria for in-process inspections — operators perform inspections but there are no documented criteria for pass/fail determination (Minor NC).
Auditor Tips
These are familiar QMS elements for organizations that have ISO 13485 certification. The key MDR-specific angle is ensuring these procedures also address MDR-specific requirements — for example, design and development must include clinical evaluation integration, and purchasing must address EU MDR economic operator obligations for importers and distributors in the supply chain.
Follow-Up Questions
- How does your design and development process integrate clinical evaluation — at which stage does clinical data inform design decisions?
- What triggers a supplier re-evaluation, and what actions do you take if a supplier fails re-evaluation?
- How do you verify that your production process consistently produces devices that conform to the design specifications?
What to Sample
Review a recent design history file for completeness. Check supplier evaluation records for the top 3 critical suppliers. Review one production batch record.
Objective Evidence
- Traceability procedure — verify it describes how devices are traced from incoming materials through production, distribution, and final customer, using lot or serial numbers and UDI where applicable
- Complaint handling procedure — verify it defines complaint intake, initial assessment for reportability (vigilance), investigation, root cause analysis, CAPA linkage, and closure criteria
- Vigilance reporting procedure — verify it defines serious incident identification criteria, reporting timelines (per Article 87), and responsibilities for submitting reports through EUDAMED or national competent authority systems
- FSCA procedure — verify it describes the process for initiating, planning, executing, and closing field safety corrective actions, including customer notification and competent authority communication
- Records of complaint investigations and any vigilance reports submitted — verify at least 3 recent complaints were investigated and the reportability assessment was documented
Common Nonconformities
- Complaint handling procedure does not include a reportability assessment step — complaints are investigated for root cause but not evaluated against Article 87 serious incident criteria (Major NC).
- No FSCA procedure exists — the manufacturer has never executed a field safety corrective action but also has no procedure for doing so if needed (Minor NC).
- Traceability records are incomplete — distribution records do not identify the end customer or healthcare facility, making downstream traceability impossible (Major NC).
Auditor Tips
Traceability and vigilance are areas where EU MDR is more demanding than many other regulatory frameworks. The traceability chain must extend to the end customer (hospital, clinic, or user) where possible. For complaints, verify that every complaint is assessed for reportability as a serious incident — even if the organization concludes it is not reportable, the assessment must be documented. Ask to see 3 complaints and trace each through the process from intake to closure.
Follow-Up Questions
- Walk me through a recent complaint — how did you determine whether it was reportable as a serious incident?
- How far downstream does your traceability extend — can you identify which healthcare facilities received a specific lot of your device?
- If you needed to execute a field safety corrective action tomorrow, what is your first step?
What to Sample
Select 3 complaints from the past 12 months. Verify each was assessed for reportability with a documented rationale. Check that traceability records can link a specific device lot to its distribution destination.
Objective Evidence
- Management review procedure and records — verify reviews are conducted at planned intervals, include inputs required by the QMS procedure (audit results, complaints, CAPA status, regulatory changes, PMS data), and produce documented decisions and actions
- CAPA procedure — verify it includes problem identification, root cause investigation methods, effectiveness verification, and escalation criteria
- Internal audit program and records — verify audits cover all QMS processes within the defined audit cycle, auditors are independent of the areas audited, and findings are tracked to closure
- Continual improvement evidence — verify that management review outputs, CAPA results, and audit findings are used to drive measurable improvements in the QMS
Common Nonconformities
- Management review records do not include PMS data as an input — post-market surveillance results are not presented to or considered by management (Minor NC).
- CAPA effectiveness verification is not performed — CAPAs are implemented and closed without evidence that the corrective action actually prevented recurrence (Major NC).
- Internal audit program has not been completed within the defined cycle — 4 of 12 planned audits were not conducted in the last 12 months and no justification exists for the gap (Minor NC).
- No documented continual improvement objectives — management review minutes do not set improvement targets or track progress against previous targets (Minor NC).
Auditor Tips
These are standard QMS management processes, but under EU MDR they must integrate MDR-specific elements. Management review must include PMS data and vigilance trends. CAPA must connect to vigilance investigations. Internal audits must cover MDR-specific requirements (UDI, PRRC, PMS). Look for these connections — if the management system processes exist but do not incorporate MDR-specific inputs, the QMS is not fully MDR-aligned.
Follow-Up Questions
- How does your management review incorporate post-market surveillance findings — show me where PMS data appears in the last review record?
- For your most recent CAPA, how did you verify that the corrective action was effective?
- Do your internal auditors assess MDR-specific requirements such as UDI, PRRC, and clinical evaluation, or only ISO 13485 clause requirements?
What to Sample
Review the last management review record and verify PMS data was included. Select one CAPA and verify effectiveness verification was performed with documented evidence. Review the internal audit schedule and confirm MDR-specific topics are covered.
Frequently Asked Questions
Get the Full 57-Item Checklist
Download the complete EU MDR compliance checklist with all 57 expert items, objective evidence requirements, common nonconformities, auditor tips, and a professional scoring rubric.
This checklist is an educational resource for audit preparation. It does not constitute professional regulatory advice. Always consult qualified auditors for certification decisions.