Quality and regulatory assurance, written to be defended

QMS implementation, pre-market submissions, risk management, EU AR and PRRC services for medical device and life-sciences organisations.

2
accountable roles we can hold — PRRC · EU AR
6
things clients ask us for, in order of frequency
510(k)
submissions and EU technical documentation — the two files we prepare
ISO 13485:2016 · FDA QMSR
the standard and the regulation a QMS is now built against

Quality and regulatory work is not paperwork you produce at the end. It is the record that shows why every decision about your device was the right one — written while the decision is being made, and still defensible three years later when somebody asks.

qointa provides quality assurance and regulatory affairs support to medical device and life sciences organisations: implementing the quality system, preparing the submission, closing the gaps an auditor will find, and holding the roles EU law requires a manufacturer to hold. We work as part of your team, on your documents, in your system.

How QARA connects to the device decision

Quality and regulatory assurance is not a parallel track to DHT governance — it is how the device decision is implemented in your quality system. A Snapshot assessment can conclude that a wearable is a regulated measuring instrument; QARA is how that conclusion becomes a design history file, a risk management report, a clinical evaluation or a submission section that an auditor can follow.

We work inside your QMS — procedures, templates, records — so the artefacts inspectors expect are the artefacts you already use, not a second library that diverges from production.

Not sure which of these you need yet

Start where it costs nothing. The free DHT readiness scorecard takes ten minutes, asks for no sign-up, and returns a scored view across the seven perimeters. It will not tell you how to close a gap. It will tell you which gaps are real, which is the part most programmes get wrong before they buy anything.

What we take on — and what stays with you

Engagements range from gap closure before an audit to standing capacity as your PRRC or regulatory lead. In every case we leave you with:

What stays with you: product ownership, signatory authority and the commercial relationship with your notified body. What we provide: the regulatory reasoning, the document set and the discipline to keep them aligned when the device changes.

One quality system, across the whole product lifecycle

Quality is not a stage you pass through on the way to market. The QMS sits at the hub, and risk management, design controls and PRRC oversight run through every spoke — design, verification, validation, submission, market and post-market.

QMSISO 13485:2016FDA QMSRDesignVerificationValidationSubmissionMarketPost-marketCAPARisk management · ISO 14971runs through every stageDesign controls · DHF / technical fileevidence assembled as you goPRRC oversight · MDR Art. 15named accountability
Quality is not a stage. The QMS sits at the hub, and risk management, design controls and PRRC oversight run through every spoke.

Verification, validation and risk management

Risk management under ISO 14971 is not a document you write once. Every hazard is identified, controlled and then re-evaluated, and what matters at audit is the residual risk after controls — and the evidence that you decided it was acceptable, on the record, before release.

Use errorSoftware faultCyberElectricalData lossacceptableriskbefore controlsresidual, after controls
Each hazard is brought below the line, one control at a time.

Six things we are asked for

Most engagements start with one of these and grow into the next.

A quality system that survives an audit

QMS implementation against the FDA QMSR (21 CFR Part 820, in force since 2 February 2026) and ISO 13485:2016, SOPs and process guidelines written to be followed rather than filed, document control and change management, internal training, and the periodic evaluation that keeps the system current as the regulation moves. Includes QMS, supplier and training audits to find the gaps before an auditor does.

Submissions built to clear first time

Pre-market documentation for 510(k) submissions and EU technical documentation for CE marking, a regulatory strategy and compliance roadmap for the markets you are actually entering, and a gap analysis of the Design History File and technical documentation against what the reviewer will expect to see.

Design evidence, not design opinion

Design verification and validation across systems and subsystems; ISO 14971 risk management including hazard analysis, FMECA and FTA; design FMEA; human factors and usability engineering to FDA and MDR expectations; reliability engineering across the intended lifecycle; and system integration testing where software, hardware and subsystems meet.

The standards your device is actually held to

IEC 60601-1 gap analysis, testing and certification support. IEC 62304 software lifecycle management. ISO 13485 certification support. Cybersecurity to FDA and EU expectations. Interoperability against HL7 and FHIR where a device has to speak to something else.

A supply chain you can answer for

Supplier engineering and qualification audits, supplier agreements that make quality obligations explicit, risk-based CAPA so corrective action is prioritised by consequence rather than by who complained, lean process audits, and ongoing vendor risk assessment including geopolitical and logistical exposure.

Data protection that holds on both sides of the Atlantic

US and EU data privacy compliance, data integrity (ALCOA+) and privacy (GDPR, HIPAA) audits, cybersecurity risk assessment, incident response planning that names who does what, and cross-border transfer compliance for data that does not stay where it was collected.

An inspection date turns quality work into triage

Most readiness engagements begin the same way: a notified body audit, an FDA inspection or a sponsor qualification visit lands on the calendar, and the honest answer to are we ready is we do not know. The work at that point is not to rebuild the quality system. It is to establish what an inspector will open first, close those gaps in severity order, and rehearse the conversation before it counts.

The Regulatory & Audit Readiness Fast-Track is that engagement, run in four stages against your date.

CONTINGENCYyour datean audit noticeand a date1Discovery callScopewhich body, framework,sites and dateQMS, DHF, vendor andtraining records2Gap assessmentFindings registerseverity, owner and theevidence to close ityour subject-matterowners3Remediation sprintInspection binderprocedures, records,CAPA made demonstrablethe people who willbe in the room4Mock auditCorrective action planplus targeted retrainingfor the people in the roomIf the date is not achievable, you hear it at stage 2 — not on the day.
Four stages against a fixed date. What you bring is above the line; what the stage produces is below it.
  1. Discovery call. Which body, which framework, which sites, which date. Scope is set against the audit programme you are actually facing, not against a generic checklist.
  2. Gap assessment. A documented review of device and DHT evidence against the FDA QMSR and ISO 13485:2016, against EU MDR 2017/745 technical documentation and vigilance obligations, and — where the device sits inside a trial — against the GCP requirements of ICH E6(R3). Every gap is written up with a severity, an owner and the evidence needed to close it. Available on its own, scoped and priced, as the Inspection Readiness Evidence Pack Review.
  3. Remediation sprint. Gaps close in severity order: procedures written or rewritten, evidence gathered into an inspection binder organised the way a reviewer reads it, CAPA handling made demonstrable rather than described, and — for devices already placed on the market — field safety corrective action procedures put in place before they are needed rather than drafted during an incident.
  4. Mock audit. We run the inspection against you: document requests, floor questions, the interviews. Findings come back as a corrective action plan, with targeted retraining for the people who will actually be in the room.

Engagements of this shape run in weeks rather than months. The sprint is bounded by what can honestly be closed before the date, and if the gap assessment shows that the date is not achievable, you hear it at the gap assessment — with the case for a deferral, a narrowed scope or a disclosed remediation plan — rather than on the day.

Where the fast-track sits. The readiness scorecard tells you whether you have a problem. The Inspection Readiness Evidence Pack Review is the assessment bought on its own: an evidence index across every device in the study, findings written the way an inspector would write them, and a prioritised remediation plan with owners and dates. It stops there by design — it does not close the findings it raises. The fast-track is that review with the remediation sprint and a live mock audit attached, so the findings are closed and rehearsed before the date rather than handed over as a plan. Standing PRRC or EU Authorised Representative capacity, below, is what you put in place afterwards so that the next inspection is not a project.

Start the Regulatory & Audit Readiness Fast-Track

Tell us the date, the inspecting body and the framework you are being held to. The discovery call takes fifteen minutes and ends with a scoped gap assessment you can approve or decline — no obligation to run the sprint.

Book the discovery call

We can hold the PRRC role for micro and small enterprises

EU MDR and IVDR require a manufacturer to have a Person Responsible for Regulatory Compliance with defined qualifications. qointa provides a qualified PRRC who oversees technical documentation, post-market surveillance and incident reporting — a named, accountable person rather than a box ticked. Only micro and small enterprises may use an external PRRC (EU MDR and IVDR Art. 15(2)); for them, that is what this is.

Talk to us about PRRC cover

We can also act as your EU Authorised Representative

The Authorised Representative is a distinct legal role under EU MDR 2017/745 and IVDR 2017/746, with its own mandate and its own liabilities. If you are a non-EU manufacturer placing a device on the European market, see EU Authorised Representative.

PRRC and Authorised Representative are two roles, not one

These are routinely confused, and the confusion is expensive: appointing one does not discharge the obligation to appoint the other. qointa can hold either, or both — the PRRC role for micro and small enterprises.

Not sure which role you need? Talk to us.

A non-EU manufacturer needs both. An EU manufacturer needs the first. Neither role discharges the other.
Person Responsible for Regulatory ComplianceAuthorised Representative
Legal basisEU MDR 2017/745 Art. 15; IVDR 2017/746 Art. 15EU MDR 2017/745 Art. 11; IVDR 2017/746 Art. 11
Who must have oneEvery manufacturer — and every authorised representativeEvery manufacturer established outside the EU
Where it sitsWithin the manufacturer’s organisation — or, for micro and small enterprises, permanently and continuously at its disposalEstablished in the Union, under a written mandate
Accountable forConformity checked before release; technical documentation and the declaration kept current; post-market surveillance; vigilance reportingVerifying the declaration and technical documentation exist; registration; holding documents for authorities; forwarding vigilance — with defined joint liability
Can qointa hold itYes, for micro and small enterprises — a named, qualified PRRCYes — full-scope EU AR mandate

Two papers behind this service

A free account opens both — no approval step, no sales call attached.

Quality & Regulatory Assurance — service brochure qointa Services brochuresFree

Quality & Regulatory Assurance — service brochure

Quality and regulatory assurance — QMS design, regulatory strategy and ongoing compliance support for life-science organisations.

Download PDF →
The Inspection Lens Position papersFree

The Inspection Lens

A companion reading on what an inspection of a digital trial actually examines — and where the evidence has to be built long before it

Read the summary →
QMS Integration: Embedding DHT Controls across Sponsor and Vendor Quality Systems Position papers

QMS Integration: Embedding DHT Controls across Sponsor and Vendor Quality Systems

Why the seam between GCP, ISO 13485 and software-lifecycle quality systems is where DHT control is won or lost.

Read the summary →

All papers in the library →

Talk to a specialist

Bring one device and one protocol — a wearable, a sensor, an app, anything. We will tell you which regulatory perimeters it opens and what it takes to close them.

Book a 15-minute call