AVAILABLE NOW

Snapshot Regulatory Impact Assessment

One device, one protocol, assessed against all seven perimeters — with the reasoning recorded, not just the conclusion.

7
perimeters assessed — each with its reasoning recorded
2–3 weeks
typical turnaround, stated before work begins
5
items in the package, from report to readout
Fee quoted on scope
in writing, before anything starts

"It's not a device" is a position. This is the assessment that lets you hold it.

Sponsors take a view on a device early — usually that it sits outside the regulations — and then discover at an audit, a submission or a mid-study change that nobody wrote down why. The conclusion may well have been right. Without the reasoning behind it, it is not defensible.

The Snapshot RIA is the shortest path from a position to a defensible one. One device, one protocol, all seven perimeters, two to three weeks. You keep the decision, the basis for each answer, the uncertainty that remains, and the events that would reopen it.

12345677perimeters2–3 WEEKSone deviceone protocoldecision register entrydecision · reasoning · uncertainty · triggers
One device, one protocol, all seven perimeters — and a controlled artefact at the end, not a slide.

Who this is for

Sponsors, CROs and technology vendors with a digital health technology in a clinical trial protocol — or about to add one — who need a defensible answer on its regulatory status before the next milestone. It suits you if a device is already in the protocol and nobody has written down why it is or is not regulated, in which markets, and on what basis.

What you provide

  • The device: make, model, firmware or app version, and who supplied it
  • The protocol, or the sections describing the device and its endpoints
  • Which endpoints or safety decisions depend on the device
  • The participating countries
  • Who configures, labels and ships it, and under whose name
  • Any vendor documentation you already hold — regulatory, technical or validation

What you receive

  • Snapshot RIA report with a recorded decision per perimeter
  • Decision register entry, versioned and prepared for filing to your TMF
  • Trigger list: what would change the answer, and when to re-assess
  • Evidence index referencing every document relied on
  • A 45-minute readout with the specialist who did the work

The RIA does not end at study start

A digital trial’s measurement instrument keeps changing — so the coverage has to keep up. A firmware release, an app update or a retrained model can cross a regulatory perimeter without anyone filing a change request.

Firmware v2.1“signal-quality fix”App updateskip-logic changeModel retrainnew thresholdsSTARTUP RIAAssess once.File. Forget.RIA v1.0doneUnassesseddriftLIVING RIAAssess on everytrigger.RIA v1.0v1.1v1.2v1.3EndpointdefensibleFirst Patient InDatabase Lockan update crosses a regulatory perimeterstartup RIA — coverage breaks, silentlyliving RIA — the register stays on the perimeter
The most dangerous update is the one nobody thought to question. The Snapshot RIA is v1.0 — the trigger list it ships with is what keeps it current.

More details

What you provide
One device and one protocol. Specifically: the technology and its intended use in the study, the endpoints or safety decisions that depend on it, the participating jurisdictions, and who supplied, configured and ships it. If you have the vendor's documentation, send it — if you do not, we will tell you what to ask them for.
What is excluded
A Snapshot RIA covers one device in one protocol. It does not include: more than one device, or a comparative jurisdiction-by-jurisdiction matrix showing where the answers diverge (that is the Full Multi-Perimeter Assessment); execution of any remediation it identifies; preparation or submission of a regulatory filing; validation testing or evidence generation; and it is not legal advice. It records a regulatory position and the reasoning behind it — it does not bind a regulator, notified body or inspector to the same conclusion.
What happens next
The report ends with a trigger list and, where relevant, a prioritised set of gaps. If nothing needs closing, we say so and the engagement ends there. Where something does, you choose whether to close it yourself, with us, or not at all — and only the modules that apply are recommended. Where the triggers warrant it, the device can enter scheduled re-assessment by agreement.
What the output looks like
You receive a single controlled package: 


  1.  Assessment report — the decision for each of the seven perimeters, the reasoning, and the regulatory basis cited to article or clause level. 
  2. Decision register entry — what was decided, on what basis, by whom, on what date, and what would change it. Versioned, so the history survives. 
  3. Trigger list — the specific events that require re-assessment: firmware releases, OS updates, protocol amendments, supplier changes, algorithm retraining. 
  4. Evidence index — every document relied on, indexed so an inspector can follow the reasoning without asking you to reconstruct it.
  5. Readout — a 45-minute session with the specialist who did the work.

Where this sits among the eight

Every assessment leaves the same controlled artefacts — a recorded decision, the reasoning behind it, and the evidence index that makes it defensible. They differ in scope. This one is the entry point: one device, one protocol.

See all eight side by side →

Request this assessment

Tell us about the device and the protocol. We come back with a written scope, price and date — no obligation.

Name, manufacturer and model if you have it. List every item if there is more than one.
The single most important field. Screening, primary endpoint, secondary endpoint, safety monitoring, engagement only?
Which specific endpoints, and whether any safety decision is informed by its output.
e.g. EU, US, UK, Japan, Canada, China.
Who supplies it, whether you relabel, reconfigure or assemble kits, and whether you import into the EU.
Firmware or app updates expected, protocol amendments planned, algorithm retraining, supplier changes.
Vendor declarations, CE certificates, validation reports, prior assessments, DPIAs.
A date or a milestone.

We treat everything you send as confidential and handle it in line with our Privacy Policy. Do not include patient-identifiable data — we never need it.

Before you buy: the one-pager

Free, no account needed. What DHT governance covers and why a device’s status follows its use.

Two papers behind this assessment

The first is free to read; the second opens with a free qointa account. No sales call attached.

Regulatory Impact Assessment (RIA) for Devices and Systems in Clinical Trials Position papersFree

Regulatory Impact Assessment (RIA) for Devices and Systems in Clinical Trials

Why a device’s role and triggers — not the hardware — determine whether an RIA is required

Read the summary →
The Smartphone in Digital Endpoints Position papersFree

The Smartphone in Digital Endpoints

Indispensable conduit, immature instrument — the phone’s role in capturing, processing and submitting digital endpoint data

Read the summary →

All papers in the library →