Five reasons sponsors, CROs and MedTech innovators choose qointa
1. We answer the question that decides the others
Whether a technology is regulated, in which markets, and on what basis — recorded with the reasoning, not just the conclusion. Every downstream cost follows from that answer: validation scope, submission strategy, supplier obligations, inspection exposure. Getting it late is what makes it expensive.
2. The specialisation is real
Digital health technologies in regulated research is what we do, not a practice area bolted onto a generalist firm. We work to EU MDR 2017/745 and IVDR 2017/746, the FDA framework for digital health technologies in clinical investigations, ICH E6(R3), ISO 13485:2016, ISO 14971, IEC 62304, IEC 62366-1, 21 CFR Part 11, EU GMP Annex 11, the EMA 2023 guideline on computerised systems and electronic data in clinical trials, and the EU AI Act where an AI-enabled function is in scope. Our quality and information-security practices are aligned with ISO 9001 and ISO/IEC 27001. Personal data is handled under Regulation (EU) 2016/679 and, where trials fall within it, Regulation (EU) 536/2014.
3. Digital transformation that survives an inspection
The same controlled loop applied to a whole clinical operation rather than one device: inventory, assessment across the stacked perimeters, controlled change management for apps, firmware, operating systems and algorithms, data integrity enforced on the edge devices themselves, and evidence packs produced as a by-product rather than assembled under pressure. See Digital Transformation of Clinical Operations.
4. Validation sized to the risk, not to the invoice
Computer system validation under GAMP 5, 21 CFR Part 11 and EU GMP Annex 11 — and, for trials, the EMA 2023 guideline on computerised systems — with critical thinking applied to where patient and data-integrity risk actually sit. We also move organisations from traditional CSV to computer software assurance without leaving a gap in the handover — and we build medical device software to IEC 62304 with risk management running throughout rather than documented at the end.
5. Participant-facing work treated as regulated work
Education, remote monitoring, support programmes and patient-reported outcomes designed so the thing that keeps participants enrolled does not quietly become an unassessed medical device. Retention and data integrity are the same problem: a disengaged participant does not produce missing data neatly, they produce late, batched and proxy entries.
What you actually receive
Six controlled, versioned, attributable documents you keep: a Snapshot Regulatory Impact Assessment, a Trigger Register naming who is accountable for noticing each event, a Fit-for-Purpose evidence pack tied to your endpoint, Mid-Study Change Classifications, change control plan handling for devices and algorithms designed to change, and an Inspection Readiness Evidence Index mapping every obligation to the artefact that satisfies it. How the method works →
