One Change, Many Consequences: The Hidden Impact on Technical Documentation

Rethinking IVDR Technical Documentation – Part 2 of 4

Introduction

IVDR technical documentation is more than a collection of files. In this four-part series, we examine how digitalization can make regulatory information more actionable, maintainable, and suitable for responsible automation. Part 2 focuses on the point at which document-centric processes are often tested most severely: product change. 

A supplier announces that a component used in an IVD will be discontinued. A newer version is available, with the same intended function and similar specifications. Alternatively, the manufacturer may need to source a comparable component from another supplier. 

At first glance, this may look like a procurement or development issue. For regulatory affairs, however, it creates a much broader question: What else might this change affect? Even minor changes rarely only affect a single document. 

A Change to the Device Is Not a Change to One File 

The IVDR requires manufacturers to maintain procedures that keep series production in conformity. Changes in product design or characteristics must be adequately taken into account in a timely manner. The manufacturer’s quality management system must also address the management of device modifications and the selection and control of suppliers and subcontractors. 

(Regulation (EU) 2017/746, Article 10(8)) 

A component change may affect different parts of the technical documentation, depending on the role of the component and the nature of the change. Potentially affected areas may include: 

  • device description and configuration 
  • design and manufacturing information 
  • supplier documentation 
  • applicable GSPRs and supporting evidence 
  • risk management 
  • verification and validation 
  • performance evaluation 
  • labeling and instructions for use 
  • post-market surveillance activities 

Annex II connects these areas within one technical documentation framework. It covers device configurations, critical ingredients, manufacturing sites and suppliers, GSPR conformity, risk management, and product verification and validation. 
(Regulation (EU) 2017/746, Annex II https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02017R0746-20240709#anx_II   

The first challenge is therefore not deciding immediately whether new evidence is required. It is identifying every area that may need to be assessed. 

The Regulatory Radius of a Component Change 

Not every component change has the same consequences. 

A revised catalogue number might represent only an administrative update. A new version may instead involve changes to documentation on raw materials, manufacturing processes, software, acceptance criteria, storage conditions, or reassessment functional performance. 

A replacement from another manufacturer raises further questions: 

  • Is the component technically comparable? 
  • Are its specifications equivalent for the intended application? 
  • Has the manufacturing location or process changed? 
  • Do existing supplier controls remain appropriate? 
  • Does the component interact differently with other parts of the device? 
  • Do existing risk controls and performance conclusions remain valid? 

The answers determine the actual impact. But before those questions can be answered, the manufacturer must know where the component is used and which regulatory conclusions depend on it. 

This is the hidden complexity of change management. A component is not only an item in a bill of materials. It can be connected to device configurations, claims, risks, performance evidence, instructions, and regulatory decisions. 

Search Finds Words, Not Relationships 

A common first step is to search the technical documentation for the component name or catalogue number. 

This is useful, but it is not a complete impact assessment. 

The same component may be referenced using: 

  • a commercial name 
  • an internal identifier 
  • a generic description 
  • a former catalogue number 
  • the supplier’s name 
  • or no explicit name at all 

Some impacts are also indirect. A performance report may not mention the component, even though the tested device configuration included it. A risk-control measure may depend on its function rather than its identifier. An IFU may describe an operating limitation caused by the component without naming the component itself. 

A text search can show where a term appears. It cannot reliably show every regulatory relationship that depends on the underlying item. 

Change Control Often Depends on Organizational Memory 

In many organizations, experienced employees know which documents must be reviewed when a component changes. 

They know that a supplier change usually requires quality involvement, that a particular reagent is connected to a performance claim, or that a device variant uses a different configuration. This knowledge may be captured in procedures and checklists, but much of it remains experiential. 

That creates different problems at different organizational scales. 

A startup may change its product quickly while its regulatory processes are still developing. An SME may depend heavily on a small number of experienced individuals. A global manufacturer may have sophisticated systems but struggle to connect information across business units, product families, regions, and acquired organizations. 

In each case, change assessment can become dependent on knowing whom to ask and where to look. 

The risk is not necessarily that nobody evaluates the change. The risk is that one affected relationship remains invisible. 

Not Every Change Requires the Same Regulatory Path

Identifying a potential impact does not mean that every related document must be revised or that every change requires new performance studies. 

A controlled assessment may conclude that: 

  • an existing document remains valid 
  • no new evidence is required 
  • only supplier or manufacturing information needs updating 
  • existing verification is sufficient 
  • targeted additional verification is needed 
  • labeling or claims must change 
  • or notified body involvement must be considered 

For IVDR-certified devices, requirements for notification or prior approval of the change by a notified body may be needed before applying the change. These requirements depend on the applicable conformity assessment route, the approved quality management system or device range, and whether the planned change could affect safety, performance, or the conditions of use. The manufacturer’s agreed notified body procedures must therefore be considered rather than assuming that all changes follow one universal route (Regulation (EU) 2017/746, Annex IX, Sections 2.4 and 4.11; Annex X, Section 5) 

Legacy devices placed on the market under the IVDR transitional provisions face an additional question: whether a change is significant in relation to design or intended purpose. MDCG 2022-6 provides guidance specifically for that transitional context. It should not be treated as a general change-management framework for all IVDR-certified devices, but an additional assessment. 

Where Digitalization Can Help 

Digitalization cannot decide whether two components are equivalent or whether existing evidence remains sufficient. It can, however, make the assessment more systematic. 

Three capabilities are particularly valuable. 

1. Identifying what changed 

The change should be described consistently and compared with the previously approved state. 

Digital support can help distinguish: 

  • administrative changes 
  • specification changes 
  • supplier changes 
  • manufacturing changes 
  • configuration changes 

The objective is not automatic classification. It is to provide reviewers with a clear and complete description of the change. 

2. Showing where the change may matter 

Digital tools can help identify: 

  • devices and variants using the component 
  • related suppliers and manufacturing sites 
  • associated risks and controls 
  • connected performance evidence 
  • affected claims or limitations 
  • relevant GSPR documentation 
  • and technical documents requiring review 

This should be understood as a candidate impact map. It provides a starting point for expert assessment rather than a final regulatory conclusion. 

3. Demonstrating that the assessment was completed 

Change control does not end when affected documents have been identified. 

The manufacturer must be able to show: 

  • who assessed each potential impact 
  • what conclusion was reached 
  • what evidence supported the conclusion 
  • which documents were updated 
  • why other documents remained unchanged 
  • which approvals were obtained 
  • and when the change was implemented 

Digitalization can support the assignment, tracking, documentation, and closure of these activities. 

Automation Should Propose, Not Decide 

Automation is well suited to tasks such as: 

  • comparing component versions 
  • identifying devices using a component 
  • retrieving connected information 
  • flagging potentially inconsistent content 
  • assigning review activities 
  • tracking unresolved impacts 
  • and generating summaries of approved changes 

Where, from today’s perspective, we need to exercise caution in its use, is making (final) decisions about: 

  • technical equivalence 
  • evidence sufficiency 
  • risk acceptability 
  • regulatory significance 
  • notified body involvement 
  • or continued conformity of the device 

These decisions require context, judgement, and accountable approval. 

The objective of automation is therefore not to produce an instant “no impact” conclusion. It is to reduce the likelihood that a relevant impact is never considered. 

Good Change Control Explains Both Change and Non-Change 

A robust impact assessment does not mean that every component replacement results in a complete rewrite of the technical documentation. 

It means that every potentially affected area is considered and that the resulting decisions are traceable. 

Some documents will change. Others will remain valid. Both outcomes should be explainable. 

This is where document-centric processes reach their limits. Documents can record the final result, but they do not automatically reveal all the relationships that should have been assessed before that result was approved. 

Digitalization can make those relationships more visible, guide the assessment, and help demonstrate that every consequence has been resolved. 

But identifying the affected areas is only half of the task. The manufacturer must still determine what the IVDR requires in each context and what information is needed to support the decision. 

That translation from regulatory requirements to device-specific information is the focus of the next article. 

See how IVDR documentation can work from one source of truth

Join the founding partner program and help shape PlatoX® for IVD manufacturers. We’ll show you how it could fit your current documentation workflow—with no obligation.

*We have compiled the above information to the best of our knowledge, yet our blog entries do not constitute expert advice and cannot substitute your own examination of the legal situation applicable to you and your institution.  

Daniel Wieser
Daniel Wieser
Articles: 32