One Change, Many Consequences: The Hidden Impact on Technical Documentation

Rethinking IVDR Technical Documentation – Part 2 of 4

Introduction

IVDR technical documentation is more than a collection of files. In this four-part series, we examine how digitalization can make regulatory information more actionable, maintainable, and suitable for responsible automation. Part 2 focuses on the point at which document-centric processes are often tested most severely: product change. 

A supplier announces that a component used in an IVD will be discontinued. A newer version is available, with the same intended function and similar specifications. Alternatively, the manufacturer may need to source a comparable component from another supplier. 

At first glance, this may look like a procurement or development issue. For regulatory affairs, however, it creates a much broader question: What else might this change affect? Even minor changes rarely only affect a single document. 

A Change to the Device Is Not a Change to One File 

The IVDR requires manufacturers to maintain procedures that keep series production in conformity. Changes in product design or characteristics must be adequately taken into account in a timely manner. The manufacturer’s quality management system must also address the management of device modifications and the selection and control of suppliers and subcontractors. (Regulation (EU) 2017/746, Article 10(8)) 

A component change does not necessarily affect the entire technical documentation. The impact depends on the role of the component and the nature of the change. However, several areas may need to be reviewed, including the device description and configuration, design and manufacturing information, and supplier documentation. The change may also have implications for the applicable GSPRs and supporting evidence, risk management, verification and validation, and performance evaluation. Depending on the specific circumstances, labeling and instructions for use, as well as post-market surveillance activities, may also need to be updated.

Annex II connects these areas within one technical documentation framework. It covers device configurations, critical ingredients, manufacturing sites and suppliers, GSPR conformity, risk management, and product verification and validation. 
(Regulation (EU) 2017/746, Annex II)   

The first challenge is therefore not deciding immediately whether new evidence is required. It is identifying every area that may need to be assessed. 

The Regulatory Radius of a Component Change 

Not every component change has the same consequences. 

A revised catalogue number might represent only an administrative update. A new version may instead involve changes to documentation on raw materials, manufacturing processes, software, acceptance criteria, storage conditions, or reassessment functional performance. 

Replacing a component with one from a different manufacturer raises a number of additional questions. It is important to establish whether the new component is technically comparable and whether its specifications are equivalent for the intended application. The change may also involve a different manufacturing location or process, which means existing supplier controls may need to be reassessed. In addition, the new component could interact differently with other parts of the device. This needs to be considered when determining whether the existing risk controls and performance conclusions remain valid.

The answers determine the actual impact. But before those questions can be answered, the manufacturer must know where the component is used and which regulatory conclusions depend on it. 

This is the hidden complexity of change management. A component is not only an item in a bill of materials. It can be connected to device configurations, claims, risks, performance evidence, instructions, and regulatory decisions. 

Search Finds Words, Not Relationships 

A common first step is to search the technical documentation for the component name or catalogue number. 

This is useful, but it is not a complete impact assessment. 

The same component may also be referred to in different ways across the technical documentation. It might appear under a commercial name or an internal identifier, but it could just as easily be described in generic terms or listed under a former catalogue number. In some cases, the supplier’s name may be used as the reference, while other documents may not name the component explicitly at all. This can make it more difficult to identify where a particular component is referenced and to assess the full impact of a change.

Some impacts are also indirect. A performance report may not mention the component, even though the tested device configuration included it. A risk-control measure may depend on its function rather than its identifier. An IFU may describe an operating limitation caused by the component without naming the component itself. 

A text search can show where a term appears. It cannot reliably show every regulatory relationship that depends on the underlying item. 

Change Control Often Depends on Organizational Memory 

In many organizations, experienced employees know which documents must be reviewed when a component changes. 

They know that a supplier change usually requires quality involvement, that a particular reagent is connected to a performance claim, or that a device variant uses a different configuration. This knowledge may be captured in procedures and checklists, but much of it remains experiential. 

That creates different problems at different organizational scales. 

A startup may change its product quickly while its regulatory processes are still developing. An SME may depend heavily on a small number of experienced individuals. A global manufacturer may have sophisticated systems but struggle to connect information across business units, product families, regions, and acquired organizations. 

In each case, change assessment can become dependent on knowing whom to ask and where to look. 

The risk is not necessarily that nobody evaluates the change. The risk is that one affected relationship remains invisible. 

Not Every Change Requires the Same Regulatory Path

Identifying a potential impact does not mean that every related document must be revised or that every change requires new performance studies. 

A controlled assessment may ultimately show that the existing documentation remains valid and that no additional evidence is needed. In other cases, the change may only require updates to supplier or manufacturing information, with the existing verification considered sufficient. Where the impact is more significant, targeted additional verification may be necessary, or labeling and product claims may need to be revised. Depending on the nature and extent of the change, involvement of the notified body may also need to be considered.

For IVDR-certified devices, requirements for notification or prior approval of the change by a notified body may be needed before applying the change. These requirements depend on the applicable conformity assessment route, the approved quality management system or device range, and whether the planned change could affect safety, performance, or the conditions of use. The manufacturer’s agreed notified body procedures must therefore be considered rather than assuming that all changes follow one universal route (Regulation (EU) 2017/746, Annex IX, Sections 2.4 and 4.11; Annex X, Section 5) 

Legacy devices placed on the market under the IVDR transitional provisions face an additional question: whether a change is significant in relation to design or intended purpose. MDCG 2022-6 provides guidance specifically for that transitional context. It should not be treated as a general change-management framework for all IVDR-certified devices, but an additional assessment. 

Where Digitalization Can Help 

Digitalization cannot decide whether two components are equivalent or whether existing evidence remains sufficient. It can, however, make the assessment more systematic. 

Three capabilities are particularly valuable. 

1. Identifying what changed 

The change should be described consistently and compared with the previously approved state. 

Digital tools can also make the change assessment process more consistent by helping distinguish between different types of changes. For example, they can help identify whether a change is purely administrative, affects a component specification, involves a supplier or manufacturing process, or changes the device configuration. This provides a clearer starting point for determining what parts of the technical documentation may need to be reviewed or updated.

The objective is not automatic classification. It is to provide reviewers with a clear and complete description of the change. 

2. Showing where the change may matter 

Digital tools can also help build a clearer picture of the potential impact of a component change. By connecting relevant information, they can identify which devices and variants use the component, along with the associated suppliers and manufacturing sites. They can also link the component to relevant risks and controls, performance evidence, claims or limitations, and supporting GSPR documentation. This makes it easier to identify which technical documents may be affected and require further review.

This should be understood as a candidate impact map. It provides a starting point for expert assessment rather than a final regulatory conclusion. 

3. Demonstrating that the assessment was completed 

Change control does not end when affected documents have been identified. 

The manufacturer must be able to demonstrate how the change was assessed and how the resulting decisions were made. This includes documenting who assessed each potential impact, what conclusions were reached, and what evidence supported those conclusions. It should also be clear which documents were updated and, just as importantly, why other documents were considered unaffected and left unchanged. The assessment should further capture any required approvals and provide a clear record of when the change was implemented.

Digitalization can support the assignment, tracking, documentation, and closure of these activities. 

Automation Should Propose, Not Decide 

Automation can be particularly useful for the more repetitive parts of change assessment and documentation. It can help compare different component versions, identify the devices that use a particular component, and retrieve related information from connected records. Automated checks can also flag potentially inconsistent content, assign review activities to the appropriate teams, and track impacts that have not yet been resolved. Once the assessment is complete, automation can further support the process by generating summaries of approved changes and the decisions associated with them.

However, there are areas where the use of automation still requires caution. Final decisions about technical equivalence, the sufficiency of supporting evidence, and the acceptability of risks should not be made solely by an automated system. The same applies when determining the regulatory significance of a change, whether notified body involvement is required, or whether the device continues to meet the applicable conformity requirements. These decisions require appropriate technical and regulatory judgement and should remain subject to qualified human review.

These decisions require context, judgement, and accountable approval. 

The objective of automation is therefore not to produce an instant “no impact” conclusion. It is to reduce the likelihood that a relevant impact is never considered. 

Good Change Control Explains Both Change and Non-Change 

A robust impact assessment does not mean that every component replacement results in a complete rewrite of the technical documentation. 

It means that every potentially affected area is considered and that the resulting decisions are traceable. 

Some documents will change. Others will remain valid. Both outcomes should be explainable. 

This is where document-centric processes reach their limits. Documents can record the final result, but they do not automatically reveal all the relationships that should have been assessed before that result was approved. 

Digitalization can make those relationships more visible, guide the assessment, and help demonstrate that every consequence has been resolved. 

But identifying the affected areas is only half of the task. The manufacturer must still determine what the IVDR requires in each context and what information is needed to support the decision. 

That translation from regulatory requirements to device-specific information is the focus of the next article. 

See how IVDR documentation can work from one source of truth

Join the founding partner program and help shape PlatoX® for IVD manufacturers. We’ll show you how it could fit your current documentation workflow—with no obligation.

*We have compiled the above information to the best of our knowledge, yet our blog entries do not constitute expert advice and cannot substitute your own examination of the legal situation applicable to you and your institution.  

Daniel Wieser
Daniel Wieser
Articles: 34