Author name: Robert Packard

What is the mdsap pilot?

This article explains what is the MDSAP pilot, and how is the pilot program likely to impact medical device manufacturers.

robs mdsap logo What is the mdsap pilot?

The acronym “MDSAP” stands for “medical device single audit program.” This is a three-year pilot program that began on January 1, 2014. Regulatory bodies are attempting to use a single regulatory audit to meet the requirements for all countries. The MDSAP pilot is one of the direct results of medical device regulatory bodies forming the new International Medical Device Regulators Forum (IMDRF) organization (http://bit.ly/imdrf).

The FDA’s Kim Trautman is the working group chairperson for IMDRF. There is a limited amount of information on the IMDRF webpage (http://bit.ly/imdrf-mdsap), but you can find more information on the US FDA website (http://bit.ly/MDSAP). Four countries are currently participating in the MDSAP pilot:

Japan is an official observer for the program, with the participation of both their device agency (http://bit.ly/Japan-MHLW) and pharmaceutical agency (http://bit.ly/Japan-PMDA). China and Europe are also represented in the mdsap working group at the IMDRF.

Currently, there are 15 recognized registrars for the CMDCAS (http://bit.ly/CMDCAS-webinar) program for medical device companies that want to obtain a medical device license in Canada. Health Canada plans to participate in the mdsap pilot for three years, and then the MDSAP program will become a mandatory replacement for the CMDCAS certification program in 2017.

How will auditors approach MDSAP audits?

The current CMDCAS audit program benefits significantly from Health Canada’s alignment of the Canadian Medical Device Regulations (CMDR) with the ISO 13485 Standard used by third-party auditors. The tool that Health Canada uses to ensure that auditors are consistent is the GD210 audit checklist (http://bit.ly/GD210Guidance). The MDSAP will need to harmonize the regulations of Canada, Australia, Brazil, and the USA. This may seem like an impossible task, but Notified Bodies and consultants have been using multi-national regulatory comparison checklists for years to ensure that all the applicable regulations are covered during audits.

Auditors currently relying primarily upon audit checklists should quickly adapt to the MDSAP with longer lists. However, those third-party auditors that are now using the process approach will need to study the comparison checklists being developed carefully. The process approach will still be the best approach for auditing. Still, auditors will need to be familiar with a larger number of requirements for step in the population of their turtle diagrams (http://bit.ly/Process-Approach).

I recommend looking at what aerospace and automotive auditors do. Auditees are expected to create and maintain process flow charts for each process, but the auditors will also compare previous versions they created in past audits. This makes the process much more efficient–except the first time they create the diagrams.

How will MDSAP audits be different?

The biggest difference between the current CMDCAS audits and the MDSAP will be the duration of audits. SGS indicated on its website (http://bit.ly/MDSAP-SGS) that manufacturers should expect these audits to be 35-100% longer in duration. The typical ISO 13485 audit might be two days, and CMDCAS might add no additional time or as much as a half-day to the duration. However, the MDSAP program will require gathering objective evidence for Australian, Brazilian, and U.S. regulations. Even if this only added a half-day for each country, the combined effect would be four days instead of two and one-half days.

At first glance, this may seem to be a burden, but this should be a relief. Currently, manufacturers might have a CMDCAS audit every year, an FDA inspection every other year, and they are still waiting for an ANVISA inspection so that they can launch a product in Brazil. Instead of a worst-case scenario of three audits/inspections in one year, the MDSAP program will enable companies to schedule a single audit to address each major market at one time. When Japanese and Europeans adopt the MDSAP as well, then companies will realize an even greater overall reduction in the number of audit days each year.

How important will the MDSAP pilot be?

Historically, Health Canada is the only country that made ISO 13485 certification mandatory. However, making ISO 13485 certification mandatory essentially made ISO 13485 a global prerequisite for medical device manufacturers–which has not happened with ISO 9001 certification. Health Canada indicated that it intends to make the MDSAP program mandatory at the end of the 3-year pilot. If Health Canada makes MDSAP audits mandatory, MDSAP may become the new defector auditing standard globally.

In addition to the impact of Health Canada, Brazil has agreed to accept the MDSAP audits instead of initial audits by ANVISA. The current backlog of ANVISA audits more than a year, and companies have resorted to filing lawsuits against ANVISA to get to the “top of the list.” Therefore, all of the companies on the waiting list are likely to jump at the opportunity to participate in the MDSAP pilot.

Let me know if you want to understand specifics about the MDSAP program. Please submit your suggestions for future blogs to our suggestion portal.

What is the mdsap pilot? Read More »

UDI Implementation-Why You Need to Begin Today

udi UDI Implementation Why You Need to Begin Today

In this blog, “UDI Implementation-Why You Need to Begin Today,” the author provides reasons why you should begin your implementation today and the benefits of doing so.

I have taken you through what UDI is, what you need to do to meet its compliance dates, and in the last few blogs, written about the steps you need to take to implement UDI in your organization. With the September 24, 2014 deadline looming, labelers of Class III devices and stand-alone software should be well on their way with implementation. But what about you who label implantable, life-sustaining, life-supporting (9/24/15 deadline), Class II (9/24/16 deadline), or Class I (9/24/18 deadline) devices? Should you wait or begin now?

UDI – Good Business Sense

There are many reasons why implementing UDI makes very good business sense. Two overriding reasons are increased revenues and lower costs. The healthcare industry has been using Automated Identification and Data Capture (AIDC) technology for a number of years. FDA has required since 2004, drug manufacturers use barcodes (NDC number) on their  labels. Now, they require device manufacturers (labelers) use Unique Device Identifiers (UDI) on their medical device labels. 

Hospitals and Group Purchasing Organizations (GPOs) have been at the forefront of persuading many medical device manufacturers to adopt UI for the devices they label. GPOs are now at the point of mandating manufacturers to implement UI to continue and/or obtain contracts to sell their devices to GPO hospital members. Even with that significant pressure, many manufacturers have resisted implementing UI. Of course, now, they will have no choice.

UDI Implementation-Why You Need to Begin Today

Manufacturers who have implemented UI have seen increased revenues and decreased costs. Their hospital/GPO customers view them as “easy-to-do” business with, resulting not only in an increase of sales of contracted devices but also of non-contracted devices. Hospitals must implement systems to reduce their costs. UDI is such a system. It will permit hospitals to manage their inventories better, reducing or eliminating product duplication, as well as realizing improved inventory tracking.

The use of product barcodes will allow hospitals to charge patients more accurately for the devices they use while hospitalized. Manufacturers have also been able to increase the speed to market for a new device compliant with UI, and by adding it to their existing GPO contracts. This can increase the new device’s exposure to the market very quickly.

Becton Dickinson Implementation

The March 2011 Edition of Healthcare Purchasing News published an article by Karen Conway that describes Becton, Dickinson, and Company (BD) Resource Optimization and Innovation (ROi) experiences implementing UI (GS1’s Global Trade Identification Number). Dennis Black (BD) and Alex Zimmerman (ROi) describe the positive impact implementing UI had on their businesses.  They were able to document a 30% reduction in accounts payable days outstanding. Other findings included:

  • 73% reduction in errors on customer orders
  • fewer stock-outs
  • greater process efficiency
  • fewer calls to customer service
  • better charge compliance

All are excellent reasons to start UDI implementation now.

Regulatory Affairs will also benefit from implementing UDIs. Improving the recall process will help reduce costs through easier tracking of which customers to contact, versus what is typically a very arduous and time-consuming process today. Starting now will also allow you to control the pace of the required changes to your organization, and collect data needed to submit to GUDID. This regulation will put your organization under a tremendous amount of pressure without having to deal with the crisis of a short implementation window.

The most common mistake I have seen organizations make is poor planning around UDI implementation. They significantly underestimate the amount of time it will take to implement UDI, the amount of change that will occur within the organization to be compliant, and being able to manage the ongoing requirements of UDI. These issues are compounded for multi-site organizations, where project planning is critical. 

Earlier in this blog, I mentioned hospitals using barcodes to charge fees for devices used by patients. This information will be added to the patient’s electronic health record. From there, this information will work its way into large population databases, such as claim data. Manufacturers will ultimately be able to use this claim data to identify new potential intended uses for products, and thereby expand their target markets.

Implementing UDI now makes good business sense. Why wait and put your organization in jeopardy?

UDI Implementation-Why You Need to Begin Today Read More »

Auditing Nonconforming Materials: 21 CFR 820.90 Compliance

This blog, “Auditing Nonconforming Materials: 21 CFR 820.90 Compliance” focuses explicitly on the identification and segregation of nonconforming materials. 

Identification and Segregation 3 Auditing Nonconforming Materials: 21 CFR 820.90 Compliance

Nonconforming material is not a “bad” thing in and of itself. A total lack of nonconformities is conspicuous. There are three critical aspects to verify when you audit nonconforming materials:

  1. nonconforming materials are identified and segregated
  2. disposition of nonconforming materials is appropriate
  3. feedback from the nonconforming material process interacts with other processes 

Identification & Segregation

Failure to adequately control nonconforming materials is one of the top 10 reasons why companies receive FDA 483s (http://bit.ly/FY2013-483-Data-Analysis). There is no requirement for locked cages in a Standard or 21 CFR 820 (http://bit.ly/21CFR820-90), but you must identify nonconforming materials and keep them segregated from conforming product. How you identify the nonconforming material is also up to your discretion. I do not recommend anything that is colored green because people associate the color green with a product that is accepted and released. In contrast, anything red is typically associated with danger, caution, or rejected. I prefer to keep things simple. Therefore, a red sticker, red tag, or placing a part in a red bin usually works.

I believe in eliminating duplication of work whenever possible. Therefore, I think it’s silly when a procedure requires you to document information on a red sticker or tag that is also on a Nonconforming Material Record (NCR). Every NCR must have traceability to the physical product, and marking the number of the NCR on the red sticker or tag is a simple way to accomplish this. (i.e., NCR # 32).

If you have a barcoding system, you eliminate the possibility of misreading an NCR number, but it’s overkill. Another silly requirement is to attach a hard copy of the nonconforming material record to the box containing the nonconforming product. Every time you revise the NCR, you won’t remove the original and attach a new copy to the box. Furthermore, many auditors just look for a box of products in the quarantine area that is missing a hard copy of the nonconforming material record.

My preference is to have red stickers or tags placed on a nonconforming product at the location it is found and then placed into a red bin. At least once a day, or whenever you perform a “line clearance”, I recommend that the contents of the red bins are moved to a centralized location for nonconformities.

At that location, there should be a log and a computer to either print out a new NCR or to enter information into an electronic record. This centralized location should be visible to the production manager or the quality manager from their desk. The person delivering the nonconformity should complete the next entry in the log and record the number on the sticker or tag. Then, the NCR should be completed with the required information. The NCR should then be delivered to the manager’s desk in a red bin.

Some people argue that you need a large area to store the nonconforming product in the warehouse–in case you have a large quantity of nonconforming product. I disagree. If you have a great deal of nonconforming material (i.e., your red bins are filling rapidly), then you need to stop production and get the situation resolved immediately. This is why you have a CAPA process.

If your inspectors are finding nonconforming product at incoming inspection, this means your supplier shipped nonconforming material. Don’t tolerate nonconforming material from suppliers. Reject nonconforming material and make your suppliers initiate corrective actions.

If the problem is with:

  • Your inspection method, you need to validate your inspection method (i.e., gage R&R studies).
  • Your inspection device, quarantine it, and get another calibrated device.
  • Your specification, fix it now.

Every other type of problem found during an incoming inspection should result in a buyer, or another person responsible for supplier quality management, contacting the supplier ASAP. Ideally, you want all incoming rejected product to be returned the same day it is received. 

How to Audit Identification and Segregation

When I’m auditing this process, I look first for proper identification and segregation. There are three places where auditors need to ask and observe how nonconforming material is identified and segregated: 1) incoming inspection, 2) in-process inspection, and 3) final release (http://bit.ly/21CFR820-80). It is also critical that auditors verify that nonconforming materials are removed from production areas at the end of each lot as part of the line clearance procedure. If this is not done, then there is a risk of losing traceability to the lot.

Auditors should ask how nonconforming material is identified and then verify that the procedure states this. Searching for deviations from the procedure is easy if the procedure was not well written, but these are audit findings of little value. Quality Managers should address this issue when they write the procedure. What is far more important is to verify that everyone is segregating nonconforming material immediately.

  • Red bins are your “friend” and they belong on the floor.
  • Yellow typically indicates that something is waiting to be inspected.
  • Green typically means that something passed inspection and has been accepted.

Auditors should look for situations where multiple parts are in the process of being inspected at the same time. Unless inspection is automated and involves a fixture, I don’t recommend allowing an inspector to inspect more than one part at a time.

As an auditor, once I have verified that the product is adequately identified and segregated, then I look to see how nonconformities are dispositioned. That is the subject of a future blog. If you have a quarantine area that is bursting with rejected components and incorrectly built products, you need to read our next blog (http://bit.ly/MDA-Blog) about the control of nonconforming materials.

Auditing Nonconforming Materials: 21 CFR 820.90 Compliance Read More »

Medical Device Academy-5 Proven Audit Approaches

This article, Medical Device Academy-5 Proven Audit Approaches, reviews how our clients benefit from our tried and true audit principles.  

5 benefits internal audits Medical Device Academy 5 Proven Audit Approaches

1. Process Approach 

I am an advocate for using turtle diagrams (i.e., the process approach) for auditing, instead of audit checklists. Beyond the obvious visual differences between using audit checklists and using turtle diagrams, these two tools result in very different types of observations. An auditor using a checklist typically starts with a regulatory requirement, and then the auditor samples record to verify if the records meet the requirement. Once this verification has been successful once, it is unlikely that the process will have a problem in the future.

Turtle diagrams and the process approach focus on inputs and outputs to a process–instead of specific regulatory requirements. For example, when an auditor uses the element approach to auditing, the auditor will sample one or more process validations from a master validation plan to ensure compliance with 21 CFR 820.75. However, step four of the process approach includes sampling process validation for each process being auditing. If there is a lack of process validation for any process, the auditor will identify the gap. Step four also involves verifying the calibration of devices used in the process and maintenance of any equipment. Therefore, the process approach is sampling requirements for process validation, calibration of measurement devices, and preventive maintenance for each process–instead of once for each regulatory element. 

2. Where Audits are Conducted

Most auditors spend an extraordinary amount of time in conference rooms. If I can audit your records in a conference room, I can also audit your records from my office in Vermont. Remote auditing eliminates the cost of travel. More than half of your quality system records can be effectively audited remotely. Therefore, when any auditor on our team visits your facility, they want to spend more time seeing you demonstrate production processes and interviewing people–instead of reviewing records in your conference room. This also happens to be the only effective method to audit production and process controls, which is one of the four major quality system processes the FDA focuses on during Level 2, comprehensive QSIT inspections. 

3. Read Less and Listen More

Most auditors like to start with a procedure and then look for compliance with the procedure. We begin with an interview of the process owner or a person performing a step in the process. Then we ask for a demonstration, and records and procedures last. I coach new auditors to ask people they are interviewing to show them where a requirement can be found in their procedure. This has several hidden benefits. First, auditors don’t have to spend a lot of time hunting for a requirement because the auditee will find it for the auditor. Second, the auditor will quickly learn how familiar the auditee is with the specific procedure. Finally, if the company is not following a procedure, the auditee is unlikely to be able to locate the requirement in its procedure. 

4. Start at the End with Problems

Most people prefer to follow a process from beginning to end. More specifically, the opening is step one of a procedure, and the end is a product and paperwork resulting from the process. Since most product and paperwork is done correctly, we seldom find anything wrong with a process if we start at the beginning. Alternatively, we can start at the end of a process with a cage of nonconforming material, or a log sheet of complaints. Then we can work our way back to the beginning of the process, and hopefully, we will see what went wrong in the process during our investigation. Therefore, my internal audit agenda often begins with a tour of the facility that will arrive at the location where a quarantined product is stored. Then I work my way back through the process to incoming inspection, then the purchasing process, and finally to the design controls process where specifications were initially created. Using this approach often results in the discovery of problematic processes that have the potential to cause other problems beyond the one example we found in the quarantine area. 

5. Focus on Effectiveness Checks

The last sub-clause of ISO 13485:2016, Clause 8.5.2, is specific to the requirement for verifying the effectiveness of corrective actions. This is not the same as verifying implementation. If an internal audit identifies that there are no maintenance records, then you might attempt to prevent recurrence by creating a procedure that requires maintenance records. A copy of the procedure, records of procedure review, and approval and training records are evidence of implementing the corrective action.

Effectiveness verification requires more (http://bit.ly/CAPA-effectiveness-checks). You need to go back and verify that maintenance records are being created and maintained. Therefore, whenever we write an audit finding, we also review potential corrective actions with the client and suggest possible effectiveness checks to ensure corrective actions work.

If your company needs help with internal auditing and would like a quote, please email Matthew Walker. We also are teaching a lead auditor course in partnership with AAMI starting fall 2020.

Medical Device Academy-5 Proven Audit Approaches Read More »

How to Audit Your Labeling Process for 21 CFR 820 Compliance

This article reviews how to audit your labeling process for 21 CFR 820 compliance with the six requirements of section 820.120.

audit labeling How to Audit Your Labeling Process for 21 CFR 820 ComplianceThe most common cause of recalls is labeling errors. Therefore, one of the best ways to avoid a recall is to perform a thorough audit of your labeling process. Unfortunately, most auditors receive no specific training related to labeling. The primary reason for the lack of labeling-specific training is because most auditor training focuses on ISO certification requirements.

ISO 13485 Requirements for the Labeling Process

ISO 13485 only requires the following labeling requirements: “The organization shall plan and carry out production and service provision under controlled conditions. Controlled conditions shall include, as applicable…g) the implementation of defined operations for labeling and packaging.” ISO 14969 is the guidance document for ISO 13485, and the guidance includes additional recommendations for control of the labeling process to prevent errors. Unfortunately, auditors are trained to audit for compliance with regulations, while guidance documents are neglected almost entirely. ISO labeling requirements are vague. Therefore, auditors need to focus on the six requirements of 21 CFR 820.120–the section of the FDA QSR specific to labeling. Labeling process flowchart1 How to Audit Your Labeling Process for 21 CFR 820 Compliance Most auditors are taught to develop a regulatory checklist to verify requirements. However, the process approach to auditing is a more effective approach to identify ways that the labeling process can break down. Below examples of how the two approaches differ are provided for each of the six requirements:

1. Labeling Procedure

Most auditors, and FDA inspectors, request a copy of a labeling procedure to verify compliance with the first requirement. In their notes, they record the document number and revision of the procedure. The auditor may also review the procedure to ensure that the procedure includes each of the other five regulatory requirements listed below. The process approach to auditing also verifies compliance with the requirement for a procedure. Still, auditors using the process approach ask the process owner to describe the process, and the process description provided is compared with the procedure.

I also teach auditors to ask the process owner to identify where in the procedure, each requirement can be found. This eliminates the need to spend valuable audit time reviewing a procedure and forces the process owner to demonstrate their familiarity with the procedure.

2. Label Integrity

A lack of labeling integrity is seldom raised as an observation by auditors, unless labels are falling off of the product, or if the label content is illegible. During hundreds of audits, I have never noticed a label falling off the product, but I have seen customer complaints about labels falling off. Another way to assess if there is a problem with labeling integrity is to ask how the labeling specifications were established, verified, and validated. The user environment is frequently the determining factor for labeling specifications. For example,

  • Does the label need to be waterproof?
  • Is the print likely to be exposed to abrasion that could rub off the ink?
  • Are the storage conditions likely to include high heat and humidity that could cause the adhesive to fail? 

This type of approach links the labeling of products to customer focus and design inputs.

3. Labeling Process Inspection

The inspection of labeling is more than a visual examination. A thorough inspection requires a systematic review of the label content to ensure that the label information matches the requirements for the specific production lot. The requirements specify verification of:

  • correct expiration date
  • control number
  • storage instructions
  • handling instructions

There is also a requirement to document the date of inspection and the person that performed the inspection. An auditor can verify that the labeling inspection is being performed by reviewing records of the inspection, but you will rarely find an inspection record where the label is nonconforming. If you follow the process, you might ask the process owner where nonconforming labeling is recorded. The nonconforming material records should be an output of every inspection process. Auditors should also ask for metrics regarding a process. The frequency of labeling mix-ups and labeling errors identified during an inspection is an important metric that can be used as an indicator of weaknesses in labeling operations.

4. Labeling Storage

Most auditors will verify that labels are stored in a location to prevent deterioration or damage, but the highest risk is the mix-up of labels. Therefore, it is crucial to control the location of labels so that the incorrect labels cannot be accidentally distributed to the wrong manufacturing line. 

In 21 CFR 820.150, there is also a requirement to establish “procedures that describe the methods for authorizing receipt from and dispatch to storage areas and stock rooms.” Therefore, as an auditor, you might consider asking the process owner what the input to the labeling distribution process is (e.g., a work order) and which distribution records are created during the process. A labeling requisition and/or “pick list” from production planning is often used as an input to the labeling process, while the distribution of labeling to manufacturing usually requires a log entry for distribution from a stockroom, or assignment of a lot number to the batch of labels that must be entered in a log.

5. Labeling Process

It is insufficient to review DHRs for the labeling process. When you interview the process owner, you should determine who is responsible for creating and inspecting labels. Then, I coach auditors to go and view labeling operations at the source. By interviewing operators and asking them to demonstrate entry of variable data for labels and printing of labels, you can answer each of the following questions without even asking:

  • Is validated software is being used?
  • Are label templates protected from inadvertent changes?
  • How do operators ensure that labels from different lots are not mixed up?

Interviewing inspectors can determine if calibrated tools are being used to verify labeling dimensions and the proper placement of labels. You should also observe how inspectors ensure that variable data is correct.

6. Control Number

Most auditors will sample DHR records to verify that lot control numbers are recorded for each batch of products. However, when an auditor is focusing on records, the auditor is unlikely to identify any aspects of label handling that could result in mix-ups. To ensure that processing and segregation of different lots are adequate, an auditor has to observe line clearance procedures and to verify that each lot of labels is identified with regard to the lot number, quantity, and the released status if the identification information about the label is separated from the physical labels, the potential for labeling mix-ups increases.

One final aspect of labeling and control numbers to consider is the impact of new UDI regulations. Labeling will need to indicate the date of manufacture and expiration of the product. This information needs to be incorporated into the variable content of labels. Therefore, if labels are pre-printed, it may be necessary to reprint labels when the date of manufacture changes. This additional requirement is likely to force companies into on-demand printing of labels and automated software control systems. Auditors can verify the successful implementation of labeling process changes by auditing for compliance with the revised procedures.

UDI states that production identifiers (PI) consist of Manufacturing Date, Expiration Date, Lot/Batch Number, Serial Number. The rule also states that if a labeler does not use any of the listed PI, they do not need to have it on their labels. This will most likely apply to Class I device labelers only as Class II, and III labelers usually have one or more of the PI on their labels. Due to the variable nature of the PI, many labelers are adding in-line label verifiers to make sure their labels are readable by scanners.

How to Audit Your Labeling Process for 21 CFR 820 Compliance Read More »

Obtaining an FDA Certificate to Foreign Government for Medical Devices

certificate to foreign gov Obtaining an FDA Certificate to Foreign Government for Medical DevicesThis article explains how to obtain an FDA Certificate to Foreign Government when you are trying to submit an application for registration of a medical device to a regulatory body outside the United States (e.g., COFEPRIS approval for exports to Mexico).

What is an FDA Certificate to Foreign Government?

If you have a medical device that is registered and listed with the US FDA, then you can obtain a Certificate to Foreign Government from the US FDA. A Certificate to Foreign Government is a certificate issued by the US FDA verifying that your company may legally export the device, and the device may be distributed in the United States. Regulatory bodies in some countries request a “Certificate of Free Sale.” Still, these are issued by the US FDA for foods, while the agency issues Certificates to Foreign Governments for medical devices. The name of the certificate is not the same for all countries, and regulators use the terminology most familiar to their country. The US FDA has more information about the different types of certificates on the following FDA webpage: http://bit.ly/FDA-Export-Certificates.

How do you obtain a Certificate to Foreign Government?

The following page on the FDA website answers common questions about exporting medical devices. http://bit.ly/Exporting-Medical-Devices. One of the most common requirements of foreign registrations is providing a Certificate to Foreign Government. If your product is currently registered and listed with the US FDA, you are managing your registration and listing using an FDA Unified Registration and Listings System (FURLS) account (http://bit.ly/registration-listing-blog). Through this account, you can access the new CDRH Export Certification and Tracking System (CECATS). CECATS allows manufacturers to request export documents, including Certificates to Foreign Governments, online versus paper submissions. CECATS reduces certificate processing time and will enable you to validate firm-specific data in real-time. You can also obtain a status update for your certificate request. If you have additional questions about CECATS or export certificates, the FDA also created an Exporting FAQs page: http://bit.ly/Exporting-FAQs.

How much does a Certificate to Foreign Government Cost?

Certificates to Foreign Government are product specific and cost $175 for the original certificate. Each additional copy (official copies from the FDA are usually required) costs $15 per copy. Up to 50 pages (including the certificate, manufacturer page, and attachment pages) may be submitted for the same product. Each time an increment of 50 pages is exceeded, an additional fee of $175 will be charged.

If the original is three pages long and you request an original and ten copies (33 total pages), then your charge will be $175 for the original and $150 for the ten copies–a combined total of $325. However, an original and 20 copies (63 pages) would exceed the 50-page limit, and you would be charged $175 for the first original and $225 for the first 15 copies. You would then be charged $175 for a second original and another $60 for four more copies.

Don’t wait until the last minute to request Certificates to Foreign Governments. I recommend ordering 5-10 copies when you first register a product in the FURLS database, instead of waiting until you need it. The same is true of other types of certificates, such as CE Marking certificates from your Notified Body.

Obtaining an FDA Certificate to Foreign Government for Medical Devices Read More »

Unannounced Audits

This article provides an update on the status of unannounced audits by Notified Bodies for CE Marking of medical devices.

unannounced audits Unannounced Audits

The EU Commission provided recommendations to Notified Bodies last Fall on how they should conduct three different kinds of audits: 1) product assessments, 2) quality system assessments, and 3) unannounced audits (http://bit.ly/Audit-Recommendations). The recommendations do not propose any changes to existing practices for product assessments (i.e., review of CE Marking applications) that are being conducted in accordance with the European Directives, or quality system assessments that are being conducted in accordance with ISO 17021. The recommendation does, however, propose new auditing practices specific to conducting unannounced audits (http://bit.ly/Unannounced-Audits).

The recommendation is addressed to the Member States, rather than Notified Bodies because the intent is for Competent Authorities in each member state to enforce these recommendations when they are reevaluating existing Notified Bodies for renewal. The intent is that the EU Commission and the Member States will use compliance with the “recommendation” for unannounced audits as one of the criteria for deciding which Notified Bodies would retain their status when the new European Medical Device Regulations were approved in 2015. Therefore, all of the Notified Bodies are scrambling to complete a number of unannounced audits before the end of 2014.

Who will be audited in 2014?

In 2014, the primary targets for unannounced audits will be manufacturers of high-risk, Class III devices. The prime targets for unannounced audits are unlikely to contract manufacturers, because Notified Bodies may not have access to all the technical documentation while they are auditing a contract manufacturer. I expect each of the Notified Bodies to plan at least one unannounced audit of a contract manufacturer for a Class III device that is outsourced. Still, I don’t expect this to be the focus of unannounced auditing activities in 2014.

It is already July, and only a handful of unannounced audits have been performed as “pilots.” Most of the Notified Bodies trained auditors on how to conduct unannounced audits in May or June during their annual auditor training. Therefore, we can expect a dramatic increase in the number of unannounced audits during the remaining months of 2014. If your firm has recently had CE Marking compliance issues with a Class III device, you should expect an auditor soon.

4 Ways unannounced audits are different

Unannounced audits differ from traditional quality system audits in four ways.

1. Unannounced audits are truly unannounced–with no warning at all. Even the US FDA inspectors have the courtesy to call on Friday to inform manufacturers of their intent to visit the following Monday or Tuesday. To ensure that auditors can conduct unannounced audits as planned, Notified Bodies are asking manufacturers to provide information about when production activities will be shut-down.

2. Unannounced audits will always be conducted by an auditing team with at least one person that is qualified to review the technical documentation (i.e., Technical File or Design Dossier) and compare it to the actual production activities. This is similar in some ways to how FDA inspectors review a Device Master Record (DMR) and then compare the DMR to production and process controls they observe in manufacturing. However, the technical experts from Notified Bodies typically have a minimum of five years experience similar designing devices, and a two-person team can spread your resources dangerously thin if you are a smaller company that is used to providing a guide for only one auditor or inspector.

3. Unannounced audits will involve more time spent by auditors in production areas, instead of reading documents in conference rooms. You can expect brief opening meetings because auditors need to review critical processes as quickly as possible. Specifically, the auditors are required to use a risk-based approach to select two of the following processes:

  • design controls
  • establishment of material specifications
  • purchasing control and incoming inspection
  • assembling
  • sterilization
  • batch-release
  • packaging
  • product quality control

If a company conducts sterilization on-site, I would expect this to be a likely prospect for sampling. However, the two areas I hope to be sampled most frequently are: 1) purchasing control & incoming inspection, and 2) batch-release. These two processes are expected to be sampled frequently because these processes facilitate ad hoc sampling and demonstration of testing. This is important because Notified Bodies are expected to observe product testing.

4. Unannounced audits will be conducted at suppliers when critical processes are outsourced. Therefore, if Class III device manufacturers outsource final inspection, packaging, and sterilization–the suppliers providing these services may be unannounced audit targets for multiple Notified Bodies. ISO 13485 certified suppliers have enjoyed a decade of little direct involvement by regulators, but unannounced audits are about to change this.

How will unannounced audits change in the future?

In 2015 and beyond, unannounced audits will be conducted at contract manufacturers and manufacturers. Unannounced audits will also be conducted for all risk classifications of devices–unless the device does not have Notified Body involvement (i.e., Class I, non-sterile, and non-measuring devices). The number of unannounced audits will also increase, because Notified Bodies are required to conduct an unannounced audit for each client at least once during three years–and more frequently for high-risk, Class III devices.

What should be done to prepare?

Preparation for unannounced audits should be very similar to your preparation for FDA inspections (http://bit.ly/FDA-Inspection-Webinar). Still, you will now need to evaluate your suppliers more rigorously to ensure they are also prepared for unannounced audits. The FDA rarely visits suppliers, and they are not allowed to review supplier auditing records. Notified Bodies will not have these restrictions. You will need to demonstrate a good balance between incoming inspection activities and other types of supplier controls. If your incoming inspection activities consist primarily of reviewing paperwork, then you need to balance this with supplier auditing (http://bit.ly/Supplier-Audits) and monitoring of in-process and final inspection nonconformities caused by supplier quality problems.

If you are interested in learning more about unannounced audits by Notified Bodies, please click on this link to pre-register for our webinar recording on the topic: http://bit.ly/unannounced-audits-webinar. Pre-registration pricing is $79, compared to our normal webinar price of $129. The pre-registration period ends on July 18.

Unannounced Audits Read More »

9 Major Steps That Should Be In Your UDI Implementation Plan


steps udi 9 Major Steps That Should Be In Your UDI Implementation PlanIn the last blog, I started the discussion on UDI implementation and how it will impact nearly every area of your company.
Successful implementation will take careful planning and coordination throughout the organization, and in some cases, outside your company. As with every other FDA regulation, you will need to have resources available to maintain and update your systems; plus, you will need resources to update and maintain the Global UDI Database (GUDID). 

 What Comes Next?

The UDI regulation is a maze. In trying to solve a maze, it is often easier to start at the end. This same philosophy should be used to implement UDI in your company. Start your implementation process with the outcome in mind. It is more than simply meeting a timeline. UDI implementation should be viewed as a way to improve your business with the processes you use every day. It should help you standardize your daily processes, especially as it relates to data gathering, label design, and communication with your trading partners. This process will yield useful marketing information, which is one of the greatest values resulting from implementing a UDI system.

Create an Implementation Playbook

Creating a playbook or strategic plan is a necessary step. Without one, your hope of ever successfully implementing UDI requirements will be severely reduced. Your playbook should focus on solving real business problems within your organization. Issues such as, how will you collect missing data? Create a “label brand” through standardization? Are you able to develop a cross-functional team for implementation and beyond? Can you streamline your labeling and packing functions? What can other processes be improved? The playbook you develop needs to be tailored to solving your organization’s specific issues.

Now the Specifics

Implementing the strategic plan for your organization requires coordination of UDI-related activities from all impacted areas identified in your plan. In addition to having an overall UDI leader, each area should have a designated person responsible for ensuring the tasks assigned to their area are completed. The major steps of each plan should include:

1. Acquire missing data attributes and create a data management process

o   Develop a protocol for obtaining missing attributes

o   Determine who is responsible for compiling the information

o   Determine who is responsible for managing the collected information

    • Enter into Excel spreadsheet

o   Establish a verification and validation process

o   Determine who is responsible for validating the information

    • Review source documents against gathered information

2. Amend label/packaging composition and components; order by the device compliance date

o   Develop label template for the entire organization

o   Develop label sign-off process to include all impacted areas

o   ADIC Technology will work for you? Concatenated, Stacked, 2-D Matrix? What are the technical capabilities of your trading partners? 

o   What packaging changes are required to accommodate new labels?

o   Determine what the global considerations for label changes are. Do other regulatory agencies need to approve label changes? Did will amend or new device submissions be required?

3. Compose, create, administer and verify/validate software system changes and integrations

o   Does 21 CFR Part 11 apply to these changes?

4. Acquire new or upgrade existing labeling and packaging equipment and verify/validate

o   Does 21 CFR Part 11 apply?

5. Rehearse connectivity with GUDID and verify all systems are functioning correctly

o   Does 21 CFR Part 11 apply?

6. If required, plan for Direct Marking requirements

     o   Obtain etching equipment appropriate for your devices

7. Create/revise Quality System SOPs as needed and conduct process validation

8. Determine if, as part of your strategic plan, your company should invest in building inventory levels – using the three (3)-year extension period for inventory labeled before compliance date – to create a buffer in case implementation is delayed.

9. Develop training programs to train staff on new responsibilities in maintaining the UDI system. Whether the outcome of your implementation is successful or not, it is directly tied to how well your team plans and executes. Validation of the changes becomes a significant aspect of the implementation process and cannot be taken lightly. Remember the adage – “Garbage in, garbage out.” But in this case, there are serious ramifications for “Garbage in.”

UDI – the Forever Project

UDI is not a “one and done” project. The entire system will need continual maintenance. Computer systems will need constant updating, as changes to devices or new ones are developed. You will need to appoint someone with clear responsibility for maintaining your information in GUDID. Postmarket surveillance activities also feed into the post-implementation process, as device changes are made as a result of tracking and reporting activities. And you will find that you will continually need to train your staff on UDI requirements, especially with staff turnover.

The true value is not in the barcode; it is the DATA that will be generated as a result of using barcodes.   And finally, identify the appropriate value proposition for your organization, and remember in healthcare, there is no single answer for all situations.       

9 Major Steps That Should Be In Your UDI Implementation Plan Read More »

How Are EU Device Regulations Changing and When?

Screen Shot 2014 04 15 at 3.01.52 PM 238x300 How Are EU Device Regulations Changing and When?

This blog, “How Are EU Device Regulations Changing and When?” includes 9 of the most significant proposed changes and compliance deadlines. 

The CE Marking process for medical devices is currently defined in three directives:

  1. Medical Device Directive (MDD), 93/42/EEC (http://bit.ly/M5MDD)
  2. Active Implantable Medical Devices (AIMD) Directive, 90/385/EEC (http://bit.ly/AIMDDirective)
  3. In Vitro Diagnostics Directive (IVDD), 98/79/EC (http://bit.ly/currentIVDD)

The EU Commission proposed revising the system from three directives requiring transposition by member states to two regulations: 1) http://bit.ly/EUIVDProposal, and 2) http://bit.ly/EURegs. The most significant proposed changes are:

  1. The Commission will have the opportunity to review recommendations for CE Marking before approval (i.e., the Scrutiny Process)
  2. The ability to create Common Technical Specifications will be expanded from IVDs to all devices
  3. A new class of “Special” Notified Bodies will be created
  4. Notified Bodies will be audited jointly by Competent Authorities
  5. Unannounced audits will be enforced
  6. Spinal implants, devices that control and monitor active implants, nanomaterials, apheresis machines, and combination products will be reclassified as Class III devices requiring a Design Dossier
  7. Most IVD products will require Notified Body involvement
  8. A Unique Device Identifier (UDI) system will be required for labeling, and the Eudamed database will be expanded
  9. Formatting of Declarations and Technical Files will be revised

When Will, the Final EMDR, be Approved?

The EU Commission took from February 2012 to September 2012 to write a proposal for new European device regulations. Parliament took 13 months (i.e., September 2012 to October 2013) to revise and fast-track its version of the new European device regulations, and the Council will probably take a year to finish their version of the regulations. Therefore, the real negotiations between Parliament and the Council will begin after the 2014 summer holiday. The final approval date is unknown, but my current guess is October 2015.

On September 12, 2013, Eucamed released the results of an industry survey (http://bit.ly/CostofEURegs) stating that the proposed regulations are expected to increase the cost of regulatory approvals by 17.5 billion Euros for medical device manufacturers collectively. The details of the survey indicate that implementation of the UDI system improved labeling and clinical performance data will require a 7.5 billion Euro investment to implement new software systems to comply with the UDI regulations. Also, industry survey respondents indicated that an additional 2.5 million Euro investment would be required for each new Class III device that is required to undergo the proposed Scrutiny Process in Article 44. Financial implications and political pressures could force the Council and Parliament to make major revisions to the proposed regulations to reduce the cost of implementation.

Some key elements need to be in place before implementation of the proposed regulations can reasonably begin. First, Notified Bodies need more staff to conduct audits and review technical documentation–especially for high-risk devices. Second, the European Databank of Medical Devices (i.e., Eudamed) must be ready to implement UDI labeling and other documentation required by the EMDR (http://bit.ly/Eudamed). Third, the European Commission plans to build a new centralized organization that will be responsible for oversight of the Notified Bodies. Each of these three elements will take more than a year, and planning has only just begun.

What Is The Compliance Deadline?

The original proposal, released in September 2012, indicated that there would be a three-year transition period for implementation of the EMDR from 2014 to 2017. This transition period would begin with the highest risk Class III devices first, and lower risk devices would be phased in over the three years. However, if the EMDR was finalized in October 2015, the implementation period will end at the end of 2018.

A complete review of the new regulations can be found at http://bit.ly/MDDI-article-EU-Device-Reg-Changes.

How Are EU Device Regulations Changing and When? Read More »

4 Ways to Make the Best Use of Medical Device Remote Audits

This blog identifies how to use medical device remote audits effectively, save time and resources, and when you should not conduct audits remotely.remote audits blog 4 Ways to Make the Best Use of Medical Device Remote AuditsMost audits ISO 13485 are performed onsite at the location where the processes are being performed, and are the most effective approach to internal and supplier audits. But conducting an audit from your desk makes more efficient use of your time as an auditor. A large percentage of audits are conducted from conference rooms where the auditor spends an excessive amount of time reviewing documents and records, or waiting for documents and records to be delivered. 

In 2006, the first edition of the ISO 17021 standard for certification of quality systems by certification bodies was released. ISO 17021 requires that initial certification audits be conducted in two stages. Stage 1 has several requirements, but the first element of Stage 1 is reviewing quality system documentation. In most cases, Stage 1 and Stage 2 audits are conducted onsite. Still, if the auditee is located in a remote location (such as New Zealand), Stage 1 audits will sometimes be conducted via conference call. 

Prior to ISO 17021, a review of quality system documentation was the only task performed before the initial certification audit, and the documentation review was typically conducted remotely as a “desktop” audit. Desktop audits have been used for decades as a way of auditing quality system documentation without traveling. However, desktop audits can be much more than a review of quality system documentation. You can interview auditees on the phone, review records, even ask auditees to demonstrate activities in real-time using a web camera.

Documentation can also consist of much more than text. Raw data, statistical analysis, and photos can be used to communicate additional information. The more multimedia content provided to auditors remotely, the closer a remote audit becomes to auditing on site. The same requirements as certification bodies do not bound internal auditors and supplier auditors, and audits may be conducted onsite or remotely. The most recent version of ISO 19011 (2011), includes a comparison table for onsite and remote auditing in Annex B.

Medical Device Remote Supplier Audits

The use of remote audits to qualify suppliers is not recommended for four reasons:

  1. onsite visits facilitate the building of supplier-customer relationships
  2. touring facilities and watching a demonstration of processes improves understanding of a supplier’s processes better than reading documents and records can
  3. Cleanliness and capabilities of suppliers are best evaluated onsite, where camera angles can be used to crop out important details
  4. sometimes suppliers misrepresent their capabilities by showing photographs on their website of other companies.

After you have qualified a supplier, however, you may not need to audit them onsite regularly. If a supplier’s performance is good and risks associated with nonconforming components supplied are minimal, then you have a justification for conducting a remote audit. However, if a supplier’s performance is poor, you may want to use a remote supplier audit as a precursor to an onsite supplier audit to investigate the reasons for nonconforming components (i.e., a “for cause” audit). Regardless of the situation, the amount of time spent in your supplier’s conference room should always be by reviewing documents and records remotely. This will reduce the amount of time required at each supplier, and enables you to audit two suppliers during the same trip.

Medical Device Remote Internal Audits

It might not occur to you that there would be any need for remote internal audits. However, not all internal audits are performed by a person working at your location. Larger companies have multiple sites, and many of the internal audits are performed by auditors from corporate headquarters and other locations. In the case of internal audits performed by auditors from other locations, travel time can be minimized by performing part or all of the internal audits remotely. This approach can also work for consultants hired to conduct internal audits. There is no need to spend money on the cost of travel for a consultant if the consultant is only going to be auditing documents and records. The following are great examples of processes that can be audited remotely:

  1. CAPA
  2. Management Review
  3. Internal Auditing
  4. Supplier Controls
  5. Complaint Handling
  6. Adverse Event Reporting

Medical Device Remote Re-audits

21 CFR 820.22 indicates that re-audits may be required where corrective actions have been taken to verify the effectiveness of the actions taken: “Corrective action(s), including a re-audit of deficient matters, shall be taken when necessary.” However, if nonconformities identified during an audit are categorized as “high-risk,” it may be essential to conduct a verification of corrective action effectiveness as soon as possible.

Sometimes, effectiveness can be determined by reviewing quantitative metrics. Still, if a re-audit is needed, then a remote re-audit may allow the auditor to verify the effectiveness of corrective actions without the necessity of being onsite. If verification of corrective action effectiveness can be performed by reviewing documents and records, a remote re-audit is appropriate. Other corrective actions, especially those involving production and process controls, typically require onsite verification.

Remote Audit Team Members

Most medical device companies have a limited number of qualified auditors, and auditing is almost always a secondary job duty. However, audits often require specific technical knowledge that only one or two auditors may possess. Therefore, it may be extremely difficult to schedule a team audit when all the required auditors and auditees are available. There is another option to postponing your audit. You might consider having some of your auditing team members audit remotely from their desks, while the rest of the team conducts an onsite audit. For example, most lead auditors can conduct a process audit of incoming inspection, storage, and shipping. However, auditing surface mount assembly lines for the fabrication of printed circuit boards requires more technical knowledge of this type of process. Technical expertise is also needed to audit sterilization or CNC machining.

By working together, onsite audit team members can take directions from a technical subject matter expert working remotely and gather information needed to audit any process properly. This approach minimizes time requirements for subject matter experts, and remote audits by team members reduce the cost of travel.

If you are interested in learning more about Turtle Diagrams and the process approach to auditing, please register for our webinar on the process approach to auditing. If you are interested in learning more about how you can use remote audits to save time and money, please contact us. We can help you identify immediate opportunities.

4 Ways to Make the Best Use of Medical Device Remote Audits Read More »

Scroll to Top