How do you bring market authorization, quality and post-market surveillance together so that your product stays compliant on the market?
We support pharma, biotech, MedTech and IVD manufacturers across the entire compliance lifecycle: from market authorization through quality management and authority interaction to post-market surveillance and IT-supported compliance processes. The real leverage lies not in any single regulation, but at the interfaces: regulatory strategy, the quality management system and surveillance obligations interlock, and anyone who runs one of these layers in isolation creates gaps that only become visible during an audit or inspection.
- Pharma
- Biotech
- MedTech
- IVD
Overview
Which requirements does Regulatory & Compliance connect across the domains?
Consulting across all four domains (pharma, biotech, MedTech and IVD) along MDR (EU 2017/745), IVDR (EU 2017/746), GMP requirements and ISO 13485:2016
Last updated: 2026-06-13
Regulatory & Compliance is not a single procedure but the interplay of several sets of obligations that, depending on the product, fall under different regulations. Four areas determine whether a product is not only authorized but stays compliant on the market:
- Market authorization and strategy: Medical devices fall under the Medical Device Regulation (EU) 2017/745, in-vitro diagnostics under the IVDR (EU 2017/746), and medicinal products under the centralized or decentralized European authorization procedure. The choice of procedure and the timing of authority interaction define the critical path.
- Quality, audits and authorities: A QM system per ISO 13485:2016 for medical devices, or per GMP requirements (EU GMP Guide, EudraLex Volume 4) for medicinal products, is a prerequisite for authorization and the subject of recurring audits and inspections.
- Post-market and surveillance: MDR (EU 2017/745) and IVDR (EU 2017/746) require systematic post-market surveillance and vigilance; in the medicinal products world this corresponds to pharmacovigilance as an ongoing obligation across the entire lifecycle.
- Compliance operations and systems: Computerized systems, data integrity and governance are subject to their own requirements; for AI-based products, the EU AI Act (Regulation (EU) 2024/1689) adds a second conformity layer alongside MDR/IVDR, and the handling of personal data falls under the GDPR (EU 2016/679).
Services
How we support you
Market authorization & regulatory strategy
Defining the authorization pathway per MDR (EU 2017/745), IVDR (EU 2017/746) or the applicable medicinal product procedure, including classification, a strategy paper and a roadmap with the regulatory milestones.
Learn more →Quality management & audits
Building and maintaining a QM system per ISO 13485:2016 or per GMP requirements (EudraLex Volume 4), preparation for certification and surveillance audits as well as authority inspections, with a documented gap analysis and action plan.
Learn more →Post-market surveillance & vigilance
Building post-market surveillance and the vigilance or pharmacovigilance system with plans, reporting channels and periodic reports, linked to risk management per ISO 14971.
Learn more →Compliance operations & systems
Validation of computerized systems, safeguarding data integrity and establishing governance for AI-based products under the EU AI Act (Regulation (EU) 2024/1689), aligned with GDPR obligations (EU 2016/679).
Learn more →Authority interaction & inspection readiness
Preparation and support for meetings with authorities, scientific advice and inspections, with a documented inspection readiness status and structured handling of findings.
Learn more →How we work together
What it comes down to
Regulatory & Compliance rarely fails because of a single regulation, but because of the interfaces between four areas that depend on one another: Market authorization sets the regulatory framework, that is, MDR (EU) 2017/745 for medical devices, IVDR (EU) 2017/746 for in-vitro diagnostics, or medicinal product law for pharma and biotech. The QM system per ISO 13485:2016 or per the GMP requirements is a prerequisite for this authorization, not a consequence of it. Post-market surveillance turns the one-time authorization into an ongoing obligation. And the compliance systems (validation, data integrity, AI governance under the EU AI Act (Regulation (EU) 2024/1689)) carry the evidence on which everything else rests.
The bottleneck is almost always the sequence: whoever clarifies the product's classification first knows which regulatory framework applies before the QM system and documentation are built. Whoever links post-market surveillance and risk management per ISO 14971 to the QM system from the outset avoids the gap between authorized and compliant on the market. That is exactly where our assessment starts: it makes visible which of the four strands is critical, before effort is spent on the later strands that are more costly in the audit.
Our approach
Our approach
Step
Result
Compliance assessment
A baseline review across all four areas: where the product stands on authorization, the QM system, post-market and compliance systems, and what is critical.
Authorization strategy
A defined authorization pathway per MDR (EU 2017/745), IVDR (EU 2017/746) or the applicable medicinal product procedure, with a prioritized roadmap.
QM and documentation build-out
A QM system built per ISO 13485:2016 or GMP requirements, with regulatory documentation evidenced against the requirements.
Submission & authority interaction
A submitted application, supported meetings with authorities, and structured handling of questions and findings.
Post-market & surveillance
Post-market surveillance and vigilance or pharmacovigilance in operation, linked to the QM system and risk management.
Compliance operations
Validated systems, safeguarded data integrity and an ongoing level of inspection readiness.
Common pitfalls
Where projects commonly fail
The four areas are run in silos.
Authorization, QM, post-market and IT compliance are owned separately, so that changes at one point are not fed back into the other strands. This creates gaps that surface in the surveillance audit or in the inspection.
Classification points to the wrong regulatory framework.
Whether a product falls under MDR (EU 2017/745), IVDR (EU 2017/746) or medicinal product law is clarified too late; correcting the classification entails a different conformity pathway and new documentation.
Post-market surveillance is treated as a final document.
The surveillance obligations under MDR and IVDR are an ongoing system; without a link to risk management per ISO 14971 and to the QM system, a gap arises that only becomes visible in the audit.
The EU AI Act is overlooked alongside MDR/IVDR.
For AI-based products, Regulation (EU) 2024/1689 creates a second conformity layer; anyone who does not integrate it into the existing QM system ends up running two separate compliance systems instead of one.
Data integrity and system validation are left until later.
Computerized systems without documented validation and without safeguarded data integrity undermine the robustness of the entire regulatory documentation on which the authorization rests.
FAQ
Frequently asked questions
Sources
- Regulation (EU) 2017/745 (MDR): primary text
- Regulation (EU) 2017/746 (IVDR): primary text
- Regulation (EU) 2024/1689 (EU AI Act): primary text
- ISO 13485:2016: Quality management systems for medical devices
- ISO 14971: Application of risk management to medical devices
- EU GMP Guide (EudraLex Volume 4)
- https://theentourage.de/regulatory-compliance/ (existing page content, revised)
Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Case Studies
What this looks like in practice
Related insights
All insights →Regulations & standards considered
- EU 2017/745 (MDR)
- EU 2017/746 (IVDR)
- ISO 13485:2016 (QM system for medical devices)
- ISO 14971 (risk management for medical devices)
- ISO 9001:2015 (quality management system)
- EU AI Act (Regulation (EU) 2024/1689)
- EU GMP Guide (EudraLex Volume 4)
- EU 2016/679 (GDPR)
Related topics
Regulatory Affairs →
Strategic market access and authorization procedures beyond the compliance obligations
MDR Consulting →
Authorization of medical devices under EU 2017/745 in detail
IVDR Readiness →
Conformity of in-vitro diagnostics under EU 2017/746
GxP Audit Consulting →
Audits and inspection preparation for GMP and QM systems
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences


