Master EUMDR 2017/745 | Quality Management & Risk Management | Your Complete 10-Week Implementation Guide.
Medical Device Insights - Issue #37 May 17, 2026
Hi There, 👋
Welcome to Week 9 of our EU MDR Mastery series! We're bringing it all together. MDR doesn't exist in isolation - it builds on ISO 13485 (QMS) and ISO 14971 (Risk Management). This week: How these three frameworks integrate into one cohesive compliance system.
Why this series?
EU MDR 2017/745 is mandatory for all medical devices sold in Europe. It’s the difference between market access and market exclusion, between CE marking and certification denial, between EU competitiveness.
📚 Series Progress: EU MDR Mastery
✅ Issue #29: EU MDR Introduction & Overview
✅ Issue #30: General Safety & Performance Requirements (Annex I)
✅ Issue #31: Technical Documentation (Annex II & III)
✅ Issue #32: Clinical Evaluation & PMCF
✅ Issue #33: Conformity Assessment & Notified Bodies
✅ Issue #34: UDI, Registration & EUDAMED
✅ Issue #35: Economic Operators & Responsibilities
✅ Issue #36: Post-Market Surveillance & Vigilance
📍 Issue #37 (Today): Quality Management & Risk Management
⬜ Issue #38: Implementation Roadmap & Practical Guidance (SERIES FINALE!)
📌 The Three-Pillar Framework
MDR compliance rests on three interconnected standards:
EU MDR 2017/745
(Legal Requirements)
↓
┌─────────┴─────────┐
↓ ↓
ISO 13485 ISO 14971
(QMS Standard) (Risk Mgmt Standard)How they relate:
EU MDR:
Legal regulation (mandatory).
Defines WHAT must be achieved.
Sets requirements for safety, performance, and compliance.
ISO 13485:
International QMS standard (harmonized).
Defines HOW to organize processes.
Provides a QMS framework.
ISO 14971:
International risk management standard.
Defines HOW to manage risks.
Provides a risk management framework.
Together: Complete compliance system.
🎯 Article 10(9): QMS Requirements
What MDR requires:
“Manufacturers... shall have in place a quality management system which shall be understood as a documented and implemented system comprising... organizational structure, responsibilities, procedures, processes and management resources...”
Based on: ISO 13485 (Medical devices - Quality management systems).
But: MDR adds specific requirements beyond ISO 13485.
🎯 ISO 13485 Foundation
What is ISO 13485?
ISO 13485:2016 - Medical devices - Quality management systems - Requirements for regulatory purposes.
Structure (10 clauses):
Clause 4: Quality Management System.
Clause 5: Management Responsibility.
Clause 6: Resource Management.
Clause 7: Product Realization.
Clause 8: Measurement, Analysis, and Improvement.
We covered this in our first series (Issues #10-19)!
Why ISO 13485 matters for MDR:
1. Harmonized standard
Presumption of conformity with QMS requirements.
Notified Bodies use ISO 13485 as an audit baseline.
2. Annex IX conformity assessment
NB audits QMS per ISO 13485.
Certificate issued for ISO 13485 compliance.
3. International recognition
Accepted globally.
US FDA recognizes (MDSAP).
Canada, Australia, Japan, and Brazil accept.
4. Provides framework
Document control
Design control
Production control
CAPA
Internal audits
Management review
🎯 MDR-Specific QMS Requirements (Beyond ISO 13485)
What MDR adds:
1. Person Responsible for Regulatory Compliance (PRRC)
MDR Article 15:
At least one person is designated.
Specific qualifications required.
Regulatory compliance responsibility.
Available to authorities.
ISO 13485: Doesn’t require PRRC specifically.
Implementation:
Designate PRRC in QMS.
Define role and responsibilities.
Ensure qualifications are met.
Document in the QMS manual.
2. Post-Market Surveillance
MDR Articles 83-86:
PMS system required.
PMS plan documented.
Data collection and analysis.
PMS Report/PSUR.
ISO 13485 Clause 8.2.1: Feedback (but less prescriptive than MDR)
Implementation:
PMS procedure beyond complaint handling.
Proactive data collection.
Regular analysis and reporting.
Integration with other QMS processes.
3. Vigilance System
MDR Articles 87-92:
Serious incident reporting.
Timeline requirements (2/10 days).
Trend reporting.
FSCA procedures.
ISO 13485 Clause 8.2.3: Reporting to authorities (but less detailed than MDR)
Implementation:
Vigilance procedure.
Serious incident criteria.
Reporting timelines defined.
EUDAMED integration.
FSCA process.
4. Clinical Evaluation
MDR Article 61 + Annex XIV:
Clinical evaluation required.
Clinical evaluation plan.
Clinical evaluation report (CER).
PMCF mandatory.
Update throughout the lifecycle.
ISO 13485: Doesn’t explicitly require clinical evaluation.
Implementation:
Clinical evaluation procedure.
Integration with design control.
PMCF as part of PMS.
CER in technical documentation.
5. UDI System
MDR Articles 27-28:
UDI assignment
UDI on labels
UDI database registration
ISO 13485 Clause 7.5.8: Identification (but not UDI-specific)
Implementation:
UDI procedure
Label control includes UDI
Traceability systems capture UDI
EUDAMED registration
6. Economic Operator Traceability
MDR Article 27:
Track who supplied, who supplied to.
UDI-based traceability.
ISO 13485 Clause 7.5.9: Traceability (but less prescriptive)
Implementation:
Traceability procedure updated.
Economic operator records.
UDI captured in records.
7. EUDAMED Registration and Reporting
MDR Article 33:
Actor registration
Device registration
Vigilance reporting via EUDAMED
ISO 13485: No equivalent
Implementation:
EUDAMED access procedures.
Registration maintenance.
Electronic reporting capability.
🎯 Integrating ISO 13485 with MDR
Practical integration approach:
Step 1: Gap analysis
Compare:
Current ISO 13485 QMS.
MDR requirements.
Identify gaps.
Example gap analysis:
Step 2: Update QMS documentation
QMS Manual:
Add MDR-specific sections.
Reference MDR articles.
Define MDR compliance approach.
Procedures:
Update existing procedures (complaints, feedback, design).
Create new procedures (PMS, vigilance, clinical evaluation, UDI, EUDAMED).
Forms/Templates:
PMS plan template.
PSUR template.
Serious incident report.
Clinical evaluation plan.
UDI assignment worksheet.
Step 3: Implement MDR requirements
Organizational:
Designate PRRC.
Assign PMS responsibilities.
Establish a vigilance team.
Define clinical evaluation roles.
Systems:
EUDAMED access.
Vigilance reporting capability.
Literature monitoring.
UDI database.
Training:
PRRC training.
MDR awareness (all staff).
Vigilance training.
Clinical evaluation training.
Step 4: Integrate processes
Don’t create silos - integrate:
Design Control + Clinical Evaluation:
Clinical evaluation informs design inputs.
Design outputs address clinical evidence gaps.
Validation includes clinical validation.
CER updated when design changes.
Complaint Handling + PMS + Vigilance:
Complaints feed PMS analysis.
PMS identifies serious incidents.
Serious incidents trigger vigilance reports.
All feed risk management.
CAPA + PMS:
PMS identifies CAPAs needed.
CAPA effectiveness verified through PMS.
Trend analysis drives preventive action.
Risk Management + Everything:
Risk management is integrated throughout.
PMS data updates risk management.
Clinical evaluation supports benefit-risk.
Design changes trigger risk re-assessment.
🎯 ISO 14971 and MDR
MDR Risk Management Requirements:
Annex I Section 3:
“Manufacturers shall establish, implement, document, and maintain a risk management system.”
This IS ISO 14971!
MDR explicitly references risk management throughout:
Annex I (GSPR) - Multiple sections require risk management.
Annex II (Technical documentation) - Risk management file required.
Article 61 (Clinical evaluation) - Benefit-risk analysis.
Article 83 (PMS) - Information feeds risk management.
ISO 14971:2019 Structure:
Clause 4: Risk Management Planning
Clause 5: Risk Analysis
Clause 6: Risk Evaluation
Clause 7: Risk Control
Clause 8: Overall Residual Risk Evaluation
Clause 9: Production and Post-Production Information
We covered this in our ISO 14971 series (Issues #21-28)!
MDR-Specific Risk Management Requirements:
Beyond ISO 14971, MDR requires:
1. Benefit-risk analysis (Annex I Section 2)
MDR requires:
Demonstrate that benefits outweigh residual risks.
Documented benefit-risk analysis.
Clinical evidence supporting benefits.
Updated with post-market data.
ISO 14971: Addresses benefit-risk but less prescriptively.
Implementation:
Benefit-risk analysis in the risk management file.
Clinical evidence referenced.
PMCF data updates benefit-risk.
Included in CER.
2. Integration with clinical evaluation
MDR requires:
Clinical evidence supports benefit-risk.
CER includes benefit-risk analysis.
PMCF addresses residual uncertainties.
ISO 14971: Less explicit on clinical evidence.
Implementation:
The clinical evaluation plan identifies risks to address.
CER includes a comprehensive benefit-risk section.
PMCF plan targets risk-related questions.
Cross-reference between the risk file and CER.
3. Post-production information (Clause 9)
MDR enhances:
PMS feeds risk management.
Serious incidents trigger risk reassessment.
Trend reports may indicate risk is underestimated.
Field actions based on risk.
ISO 14971 Clause 9: Covers this, but MDR adds specificity.
Implementation:
PMS procedure includes a risk management update trigger.
Vigilance procedure includes risk reassessment.
PSUR includes a risk management section.
Risk management reviews scheduled with PMS reviews.
🎯 The Integrated QMS-Risk-MDR System
How it all fits together:
┌────────────────────────────────────────────────┐
│ EU MDR Compliance │
│ │
│ ┌──────────────────┐ ┌────────────────────┐ │
│ │ ISO 13485 QMS │ │ ISO 14971 Risk │ │
│ │ │ │ Management │ │
│ │ • Design Control │←→│ • Risk Analysis │ │
│ │ • Production │ │ • Risk Evaluation │ │
│ │ • CAPA │←→│ • Risk Control │ │
│ │ • Internal Audit │ │ • Residual Risk │ │
│ │ • Mgmt Review │ │ • Post-Production │ │
│ └────────┬─────────┘ └─────────┬──────────┘ │
│ │ │ │
│ └──────────┬───────────┘ │
│ ↓ │
│ ┌────────────────────────┐ │
│ │ MDR-Specific │ │
│ │ Requirements │ │
│ │ • PRRC │ │
│ │ • PMS/PSUR │ │
│ │ • Vigilance │ │
│ │ • Clinical Evaluation │ │
│ │ • UDI │ │
│ │ • EUDAMED │ │
│ └────────────────────────┘ │
└────────────────────────────────────────────────┘Process integration examples:
Example 1: Design Change
Triggers:
ISO 13485: Design change control.
ISO 14971: Risk re-assessment.
MDR: Clinical evaluation update, NB notification.
Process:
Design change request submitted.
Impact assessment (design, risk, clinical).
Risk management: New/changed risks identified?
Clinical evaluation: Impact on clinical evidence?
Design change approved with all assessments.
Technical documentation updated.
Notified Body notified (if significant).
EUDAMED updated.
Example 2: Serious Incident
Triggers:
MDR Vigilance: Report to the authority.
ISO 14971: Risk re-assessment.
ISO 13485: CAPA, potential design change.
Process:
Serious incident identified.
Immediate report to authority (MDR timeline).
Investigation (ISO 13485 CAPA).
Root cause identified.
Risk re-assessment (ISO 14971): Is risk higher than thought?
Corrective action determined.
FSCA if needed (MDR).
Design change if needed (ISO 13485).
Risk management updated.
Clinical evaluation updated.
PMS monitors effectiveness.
Example 3: PMS Review
Triggers:
MDR: Annual PMS review, PSUR
ISO 14971: Post-production information review
ISO 13485: Management review input
Process:
PMS data collected and analyzed.
Trends identified
Risk management: Do trends indicate risk is underestimated?
Clinical evaluation: Does data affect benefit-risk?
PSUR prepared (includes benefit-risk, PMS, PMCF, risk management)
PSUR submitted to NB
Actions identified from review.
Actions implemented via CAPA.
Effectiveness monitored.
Management review informed.
🎯 Notified Body QMS Assessment
What NB audits (Annex IX):
Part A: Full QMS per ISO 13485
Plus MDR-specific requirements:
PRRC designation and qualifications.
PMS system implementation.
Vigilance system and timelines.
Clinical evaluation process.
UDI implementation.
EUDAMED registration and maintenance.
Economic operator traceability.
Part B: Technical documentation for representative devices
Including:
Risk management file.
Clinical evaluation report.
Benefit-risk analysis.
PMS plan and PMCF plan.
Verification/validation, including risk control verification.
Common NB findings:
Finding #1: Insufficient PMS
Passive (complaints only), not proactive.
No systematic literature review.
No PMCF studies for higher classes.
PSUR superficial.
Fix: Robust PMS system with proactive and reactive elements.
Finding #2: Vigilance timeline non-compliance
Serious incidents were reported late.
Investigation delays reporting.
No procedure for urgent reporting.
Fix: Clear timelines, preliminary reports, dedicated vigilance team.
Finding #3: Risk management is not updated with post-market data.
Risk file static after launch.
PMS data not feeding risk management.
Serious incidents not triggering risk re-assessment.
Fix: Procedure linking PMS/vigilance to risk management updates.
Finding #4: Clinical evaluation not maintained
CER not updated.
PMCF was not conducted per plan.
Post-market data not incorporated.
Fix: Annual CER review minimum, PMCF execution per plan, integration with PMS.
Finding #5: Inadequate benefit-risk analysis
Generic statements.
Not quantified.
Not updated with post-market data.
Disconnect between the risk file and CER.
Fix: Comprehensive benefit-risk in both risk file and CER, quantified with data, regularly updated.
🎯 Practical Implementation Roadmap
Phase 1: Foundation (if not already established)
Implement ISO 13485:
QMS manual
Required procedures
Document control
Design control
Production control
CAPA
Internal audits
Management review
Implement ISO 14971:
Risk management procedure
Risk management plan template
Risk analysis tools (FMEA)
Risk acceptability criteria
Risk file structure
Timeline: 6-12 months for complete QMS/Risk system
Phase 2: MDR Enhancement
Add MDR-specific elements:
Month 1-2:
Designate PRRC
Gap analysis (ISO 13485/14971 vs MDR)
Identify enhancements needed
Month 3-4:
Create/update procedures:
PMS procedure
Vigilance procedure
Clinical evaluation procedure
UDI procedure
EUDAMED procedure
Month 5-6:
Implement UDI system
EUDAMED registration
PMS system enhancements
Vigilance system setup
Month 7-9:
Train personnel
Execute initial PMS activities
Prepare PMS reports/PSUR
Conduct clinical evaluations
Month 10-12:
Internal audits of MDR-specific elements
Management review
Continuous improvement
NB engagement (if applicable)
Phase 3: Integration & Optimization
Ongoing:
Integrate processes (don’t silo)
Optimize efficiency
Leverage synergies
Continuous improvement
Annual:
PMS review and report
PSUR (Class IIa/IIb/III)
Risk management review
Clinical evaluation update
Management review
Internal audits
📊 Series Tracker
✅ Issue #29: EU MDR Introduction & Overview
✅ Issue #30: General Safety & Performance Requirements
✅ Issue #31: Technical Documentation
✅ Issue #32: Clinical Evaluation & PMCF
✅ Issue #33: Conformity Assessment & Notified Bodies
✅ Issue #34: UDI, Registration & EUDAMED
✅ Issue #35: Economic Operators & Responsibilities
✅ Issue #36: Post-Market Surveillance & Vigilance
✅ Issue #37: Quality Management & Risk Management (Today!)
⬜ Issue #38: Implementation Roadmap & Practical Guidance (NEXT WEEK - SERIES FINALE!)
👉 Master PMS Interview Topics
This question trips up candidates because it combines multiple expertise areas:
✅ FDA 21 CFR
✅ EU MDR
✅ ISO 13485
✅ ISO 14971
✅ CAPA & Complaint Handling
✅ Real Case Sudies + Dumy Audit Preperation + Free Podcase
Options:
🟦 eBook only – ₹199
🟥 Live Class + Free eBook – ₹149/hr
💬 DM me on WhatsApp to get your copy of the eBook.
Thanks for reading! Reply and tell me your worst audit finding story - let's learn from each other.
See you next Sunday ✨
– Akash Das
Let’s Connect on LinkedIn ☺️





