Proof of regulatory monitoring in an ISO 13485 audit: how to document it
In ISO 13485 audits and notified body reviews, the traceability of regulatory monitoring is systematically questioned. Which sources, how often, with what evidence? A practical guide to documenting your MDR/IVDR watch.
It is one of the questions that comes up most often in ISO 13485 audits and notified body reviews: "How do you monitor regulatory developments, and can you prove it?". Many QA/RA teams do carry out genuine monitoring… but struggle to provide documented evidence of it. Here is what an auditor expects and how to structure irreproachable traceability.
Why regulatory monitoring is required by ISO 13485 and the MDR
Regulatory monitoring is not an optional good practice: it is required at several levels.
- ISO 13485:2016 requires the quality management system to take applicable regulatory requirements into account (in particular §4.1, §4.2 and §7.2.3). To take them into account, you first have to know them, up to date.
- The MDR (Regulation EU 2017/745), Article 10, requires a quality management system including regulatory monitoring and updating, as well as a post-market surveillance system fed by the state of the art.
- ISO 14971 (risk management) assumes an assessment of the state of the art, which evolves with standards and guidance — hence continuous monitoring.
In short: without documented monitoring, you cannot demonstrate that your QMS is up to date.
What the auditor actually wants to see
An auditor is not satisfied with a verbal claim. They look for objective evidence answering four questions:
- Which sources do you monitor? (ANSM, EMA, FDA, MDCG, ISO/IEC standards, notified body…)
- How often? (daily, weekly — and is it actually kept up?)
- How do you trace what has been identified, analyzed and handled?
- What actions followed a regulatory development (update of a document, of a risk analysis, of a technical file)?
The classic pitfalls that fail this point in an audit
- Monitoring exists but is not traced: no register, no date, no evidence that it was done regularly.
- Monitoring is traced but goes nowhere: a development is noted… without demonstrating the impact analysis or the corrective action.
- Sources are incomplete: monitoring only ANSM while selling in the United States (FDA) or depending on an MDCG guidance.
- The evidence rests on a single person: if they leave the company, the traceability disappears.
How to build solid proof of monitoring
Robust proof of monitoring rests on three pillars:
1. A documented scope of sources
Explicitly list the sources monitored and justify their relevance to your markets and your device classes. A "source → frequency → owner" table is an excellent starting point.
2. A timestamped register
Every development identified must be recorded with its date, its source, its summary, its criticality and the action decided. It is this timestamped register that constitutes the evidence to be filed in the QMS.
3. Traceability of the impact analysis
For critical developments, demonstrate the link with a concrete action: revision of a procedure, update of the technical file, of the PMS/PMCF plan or of the risk analysis.
Automating proof of monitoring
Building and maintaining this traceability by hand represents 6 to 10 hours per month — time that is rarely valued, and fragile.
MedQara continuously monitors 18 official sources (ANSM, EMA, FDA, MDCG, RAPS…), analyzes and ranks each publication by criticality, and generates a timestamped PDF export that can be filed directly in your QMS as proof of continuous surveillance — exactly what an ISO 13485 auditor expects.
To go further on this topic, also read our guide Preparing an ISO 13485 audit.
Start your free account and generate your first proof of monitoring in a few minutes.
This article is provided for informational purposes and does not constitute regulatory or quality advice.
Keep receiving this kind of content
Once a week, receive analyses of new ANSM, FDA, EMA, MDR and IVDR publications - straight to your inbox.
No spam. Unsubscribe in 1 click. GDPR compliant.