submissions and EU technical documentation — the two files we prepare
ISO 13485:2016 · FDA QMSR
the standard and the regulation a QMS is now built against
Quality and regulatory work is not paperwork you produce at the end. It is the record that shows why every decision about your device was the right one — written while the decision is being made, and still defensible three years later when somebody asks.
qointa provides quality assurance and regulatory affairs support to medical device and life sciences organisations: implementing the quality system, preparing the submission, closing the gaps an auditor will find, and holding the roles EU law requires a manufacturer to hold. We work as part of your team, on your documents, in your system.
How QARA connects to the device decision
Quality and regulatory assurance is not a parallel track to DHT governance — it is how the
device decision is implemented in your quality system. A Snapshot assessment can conclude that a
wearable is a regulated measuring instrument; QARA is how that conclusion becomes a design
history file, a risk management report, a clinical evaluation or a submission section that an
auditor can follow.
We work inside your QMS — procedures, templates, records — so the artefacts inspectors
expect are the artefacts you already use, not a second library that diverges from production.
Not sure which of these you need yet
Start where it costs nothing. The free DHT readiness scorecard takes ten minutes, asks for no sign-up, and returns a scored view across the seven perimeters. It will not tell you how to close a gap. It will tell you which gaps are real, which is the part most programmes get wrong before they buy anything.
What we take on — and what stays with you
Engagements range from gap closure before an audit to standing capacity as your PRRC or
regulatory lead. In every case we leave you with:
Living procedures — written for how your teams actually work, not a
generic ISO skeleton.
Submission-ready sections — technical documentation, clinical evaluation
reports and vigilance processes that reference the device register.
Audit evidence — traceable records that show the decision was made when it
was made, not reconstructed afterwards.
What stays with you: product ownership, signatory authority and the commercial relationship
with your notified body. What we provide: the regulatory reasoning, the document set and the
discipline to keep them aligned when the device changes.
One quality system, across the whole product lifecycle
Quality is not a stage you pass through on the way to market. The QMS sits at the hub, and risk management, design controls and PRRC oversight run through every spoke — design, verification, validation, submission, market and post-market.
Quality is not a stage. The QMS sits at the hub, and risk management, design controls and PRRC oversight run through every spoke.
Verification, validation and risk management
Risk management under ISO 14971 is not a document you write once. Every hazard is identified, controlled and then re-evaluated, and what matters at audit is the residual risk after controls — and the evidence that you decided it was acceptable, on the record, before release.
Each hazard is brought below the line, one control at a time.
Six things we are asked for
Most engagements start with one of these and grow into the next.
A quality system that survives an audit
QMS implementation against the FDA QMSR (21 CFR Part 820, in force since 2 February 2026) and ISO 13485:2016, SOPs and process guidelines written to be followed rather than filed, document control and change management, internal training, and the periodic evaluation that keeps the system current as the regulation moves. Includes QMS, supplier and training audits to find the gaps before an auditor does.
Submissions built to clear first time
Pre-market documentation for 510(k) submissions and EU technical documentation for CE marking, a regulatory strategy and compliance roadmap for the markets you are actually entering, and a gap analysis of the Design History File and technical documentation against what the reviewer will expect to see.
Design evidence, not design opinion
Design verification and validation across systems and subsystems; ISO 14971 risk management including hazard analysis, FMECA and FTA; design FMEA; human factors and usability engineering to FDA and MDR expectations; reliability engineering across the intended lifecycle; and system integration testing where software, hardware and subsystems meet.
The standards your device is actually held to
IEC 60601-1 gap analysis, testing and certification support. IEC 62304 software lifecycle management. ISO 13485 certification support. Cybersecurity to FDA and EU expectations. Interoperability against HL7 and FHIR where a device has to speak to something else.
A supply chain you can answer for
Supplier engineering and qualification audits, supplier agreements that make quality obligations explicit, risk-based CAPA so corrective action is prioritised by consequence rather than by who complained, lean process audits, and ongoing vendor risk assessment including geopolitical and logistical exposure.
Data protection that holds on both sides of the Atlantic
US and EU data privacy compliance, data integrity (ALCOA+) and privacy (GDPR, HIPAA) audits, cybersecurity risk assessment, incident response planning that names who does what, and cross-border transfer compliance for data that does not stay where it was collected.
An inspection date turns quality work into triage
Most readiness engagements begin the same way: a notified body audit, an FDA inspection or a sponsor qualification visit lands on the calendar, and the honest answer to are we ready is we do not know. The work at that point is not to rebuild the quality system. It is to establish what an inspector will open first, close those gaps in severity order, and rehearse the conversation before it counts.
The Regulatory & Audit Readiness Fast-Track is that engagement, run in four stages against your date.
Four stages against a fixed date. What you bring is above the line; what the stage produces is below it.
Discovery call. Which body, which framework, which sites, which date. Scope is set against the audit programme you are actually facing, not against a generic checklist.
Gap assessment. A documented review of device and DHT evidence against the FDA QMSR and ISO 13485:2016, against EU MDR 2017/745 technical documentation and vigilance obligations, and — where the device sits inside a trial — against the GCP requirements of ICH E6(R3). Every gap is written up with a severity, an owner and the evidence needed to close it. Available on its own, scoped and priced, as the Inspection Readiness Evidence Pack Review.
Remediation sprint. Gaps close in severity order: procedures written or rewritten, evidence gathered into an inspection binder organised the way a reviewer reads it, CAPA handling made demonstrable rather than described, and — for devices already placed on the market — field safety corrective action procedures put in place before they are needed rather than drafted during an incident.
Mock audit. We run the inspection against you: document requests, floor questions, the interviews. Findings come back as a corrective action plan, with targeted retraining for the people who will actually be in the room.
Engagements of this shape run in weeks rather than months. The sprint is bounded by what can honestly be closed before the date, and if the gap assessment shows that the date is not achievable, you hear it at the gap assessment — with the case for a deferral, a narrowed scope or a disclosed remediation plan — rather than on the day.
Where the fast-track sits. The readiness scorecard tells you whether you have a problem. The Inspection Readiness Evidence Pack Review is the assessment bought on its own: an evidence index across every device in the study, findings written the way an inspector would write them, and a prioritised remediation plan with owners and dates. It stops there by design — it does not close the findings it raises. The fast-track is that review with the remediation sprint and a live mock audit attached, so the findings are closed and rehearsed before the date rather than handed over as a plan. Standing PRRC or EU Authorised Representative capacity, below, is what you put in place afterwards so that the next inspection is not a project.
Start the Regulatory & Audit Readiness Fast-Track
Tell us the date, the inspecting body and the framework you are being held to. The discovery call takes fifteen minutes and ends with a scoped gap assessment you can approve or decline — no obligation to run the sprint.
We can hold the PRRC role for micro and small enterprises
EU MDR and IVDR require a manufacturer to have a Person Responsible for Regulatory Compliance with defined qualifications. qointa provides a qualified PRRC who oversees technical documentation, post-market surveillance and incident reporting — a named, accountable person rather than a box ticked. Only micro and small enterprises may use an external PRRC (EU MDR and IVDR Art. 15(2)); for them, that is what this is.
We can also act as your EU Authorised Representative
The Authorised Representative is a distinct legal role under EU MDR 2017/745 and IVDR 2017/746, with its own mandate and its own liabilities. If you are a non-EU manufacturer placing a device on the European market, see EU Authorised Representative.
PRRC and Authorised Representative are two roles, not one
These are routinely confused, and the confusion is expensive: appointing one does not discharge the obligation to appoint the other. qointa can hold either, or both — the PRRC role for micro and small enterprises.
A non-EU manufacturer needs both. An EU manufacturer needs the first. Neither role discharges the other.
Person Responsible for Regulatory Compliance
Authorised Representative
Legal basis
EU MDR 2017/745 Art. 15; IVDR 2017/746 Art. 15
EU MDR 2017/745 Art. 11; IVDR 2017/746 Art. 11
Who must have one
Every manufacturer — and every authorised representative
Every manufacturer established outside the EU
Where it sits
Within the manufacturer’s organisation — or, for micro and small enterprises, permanently and continuously at its disposal
Established in the Union, under a written mandate
Accountable for
Conformity checked before release; technical documentation and the declaration kept current; post-market surveillance; vigilance reporting
Verifying the declaration and technical documentation exist; registration; holding documents for authorities; forwarding vigilance — with defined joint liability
Can qointa hold it
Yes, for micro and small enterprises — a named, qualified PRRC
Yes — full-scope EU AR mandate
Two papers behind this service
A free account opens both — no approval step, no sales call attached.
Bring one device and one protocol — a wearable, a sensor, an app, anything. We will tell you which regulatory perimeters it opens and what it takes to close them.