perimeters assessed — each with its reasoning recorded
2–3 weeks
typical turnaround, stated before work begins
5
items in the package, from report to readout
Fee quoted on scope
in writing, before anything starts
"It's not a device" is a position. This is the assessment that lets you hold it.
Sponsors take a view on a device early — usually that it sits outside the regulations — and then discover at an audit, a submission or a mid-study change that nobody wrote down why. The conclusion may well have been right. Without the reasoning behind it, it is not defensible.
The Snapshot RIA is the shortest path from a position to a defensible one. One device, one protocol, all seven perimeters, two to three weeks. You keep the decision, the basis for each answer, the uncertainty that remains, and the events that would reopen it.
One device, one protocol, all seven perimeters — and a controlled artefact at the end, not a slide.
Who this is for
Sponsors, CROs and technology vendors with a digital health technology in a clinical trial
protocol — or about to add one — who need a defensible answer on its regulatory status before
the next milestone. It suits you if a device is already in the protocol and nobody has written
down why it is or is not regulated, in which markets, and on what basis.
What you provide
The device: make, model, firmware or app version, and who supplied it
The protocol, or the sections describing the device and its endpoints
Which endpoints or safety decisions depend on the device
The participating countries
Who configures, labels and ships it, and under whose name
Any vendor documentation you already hold — regulatory, technical or validation
What you receive
Snapshot RIA report with a recorded decision per perimeter
Decision register entry, versioned and prepared for filing to your TMF
Trigger list: what would change the answer, and when to re-assess
Evidence index referencing every document relied on
A 45-minute readout with the specialist who did the work
The RIA does not end at study start
A digital trial’s measurement instrument keeps changing — so the coverage has to keep up. A firmware release, an app update or a retrained model can cross a regulatory perimeter without anyone filing a change request.
The most dangerous update is the one nobody thought to question. The Snapshot RIA is v1.0 — the trigger list it ships with is what keeps it current.
More details
What you provide
One device and one protocol. Specifically: the technology and its intended use in the study, the endpoints or safety decisions that depend on it, the participating jurisdictions, and who supplied, configured and ships it. If you have the vendor's documentation, send it — if you do not, we will tell you what to ask them for.
What is excluded
A Snapshot RIA covers one device in one protocol. It does not include: more than one device, or a comparative jurisdiction-by-jurisdiction matrix showing where the answers diverge (that is the Full Multi-Perimeter Assessment); execution of any remediation it identifies; preparation or submission of a regulatory filing; validation testing or evidence generation; and it is not legal advice. It records a regulatory position and the reasoning behind it — it does not bind a regulator, notified body or inspector to the same conclusion.
What happens next
The report ends with a trigger list and, where relevant, a prioritised set of gaps. If nothing needs closing, we say so and the engagement ends there. Where something does, you choose whether to close it yourself, with us, or not at all — and only the modules that apply are recommended. Where the triggers warrant it, the device can enter scheduled re-assessment by agreement.
What the output looks like
You receive a single controlled package:
Assessment report — the decision for each of the seven perimeters, the reasoning, and the regulatory basis cited to article or clause level.
Decision register entry — what was decided, on what basis, by whom, on what date, and what would change it. Versioned, so the history survives.
Trigger list — the specific events that require re-assessment: firmware releases, OS updates, protocol amendments, supplier changes, algorithm retraining.
Evidence index — every document relied on, indexed so an inspector can follow the reasoning without asking you to reconstruct it.
Readout — a 45-minute session with the specialist who did the work.
Where this sits among the eight
Every assessment leaves the same controlled artefacts — a recorded decision, the reasoning behind it, and the evidence index that makes it defensible. They differ in scope. This one is the entry point: one device, one protocol.