· PRODUCT LIFECYCLE · PHASE 14 OF 15

Post-Market Surveillance

GVPGDocPCSVQMS

Post-market surveillance is the discipline of watching a marketed product's real-world performance and acting on what is seen — the counterpart, for devices and product-quality feedback generally, of the pharmacovigilance phase's medicine-safety machinery. For medical devices it is an explicit, planned system: the EU MDR requires every manufacturer to run a post-market surveillance system under a documented plan, proportionate to risk class, feeding periodic outputs — up to the periodic safety update report for higher classes — and keeping the clinical evaluation and the ISO 14971 risk-management file alive with real-world evidence. In the US, complaint handling under the quality-system regulation and medical device reporting under 21 CFR 803 impose the reactive spine: complaints evaluated for reportability, and deaths, serious injuries, and reportable malfunctions filed on regulatory clocks.

What this page does not claim

Phases are an organising device, not a regulatory mandate — real programmes overlap them, and a medical device, a food product and a small-molecule drug traverse them differently. Each page says where the differences bite.

What happens in this phase

Post-market surveillance is the discipline of watching a marketed product's real-world performance and acting on what is seen — the counterpart, for devices and product-quality feedback generally, of the pharmacovigilance phase's medicine-safety machinery. For medical devices it is an explicit, planned system: the EU MDR requires every manufacturer to run a post-market surveillance system under a documented plan, proportionate to risk class, feeding periodic outputs — up to the periodic safety update report for higher classes — and keeping the clinical evaluation and the ISO 14971 risk-management file alive with real-world evidence. In the US, complaint handling under the quality-system regulation and medical device reporting under 21 CFR 803 impose the reactive spine: complaints evaluated for reportability, and deaths, serious injuries, and reportable malfunctions filed on regulatory clocks.

The operational engine is the complaint-to-action pipeline. Every complaint is a data point about the product in use: logged, investigated where warranted, assessed against reporting criteria, and trended — because the individual complaint is rarely the finding, but the trend almost always is. Signals cross thresholds and become CAPA; CAPA conclusions sometimes become field actions — recalls, field safety corrective actions, software patches — executed through distribution records and reported to authorities. For software-based and connected devices, surveillance extends to the software lifecycle: maintenance under IEC 62304, post-market cybersecurity watching, and update mechanisms that are themselves controlled design changes. Non-device industries run recognisable variants: product-quality complaints in pharma feeding deviation and recall systems, consumer-complaint monitoring for food and cosmetics.

What distinguishes mature surveillance is the direction of information flow. Immature systems are purely reactive — complaints processed, reports filed, files closed. Mature systems close the loop into design: complaint trends interrogate the risk file's assumptions about foreseeable use and failure rates; real-world evidence updates the clinical evaluation; recurring field issues drive design changes through change control rather than perpetual corrective maintenance. Quality owns the honesty of the thresholds — reportability decisions made against criteria rather than reluctance, trend limits set to detect rather than to reassure — and the discipline that keeps surveillance data flowing back into the documents that claimed the product was acceptably safe. A risk file that has not changed since launch, above a product with three years of field data, is not stable; it is unread.

THE GATES
TO ENTER THIS PHASE
  • Product on the market with a documented post-market surveillance plan proportionate to its risk.
  • A complaint-handling system operating, with intake channels, investigation criteria, and reportability decision procedures defined.
  • Vigilance and adverse-event reporting connections established with the authorities of each market.
  • The risk-management file and, for devices, the clinical evaluation staged to receive post-market evidence.
TO LEAVE IT
  • This phase runs for the marketed life of the product; its gates are continuous rather than terminal.
  • Complaints evaluated, investigated, and dispositioned with reportability decisions documented against criteria.
  • Reportable events filed within regulatory timelines, with trend analyses performed and acted on.
  • Field actions executed, effectiveness-checked, and reported where required.
  • Periodic surveillance outputs produced and fed back into risk management, clinical evaluation, and design.

SPEQ synthesis. Phase boundaries and gate criteria are an organising device for planning and review, not a regulatory mandate. Real programmes overlap phases and re-enter them; treat these as the questions worth answering, not a compliance checklist.

WHAT QUALITY OWNS, AND WHAT THE PHASE PRODUCES
THE QUALITY ROLE HERE
  • Own the reportability decision discipline — criteria-driven, documented, and audited, because under-reporting is the finding regulators pursue hardest.
  • Run complaint trending with limits designed to detect signals, and force CAPA when thresholds are crossed.
  • Govern field actions end-to-end: decision, execution through distribution records, authority notification, and effectiveness verification.
  • Enforce the feedback loop into the risk file, clinical evaluation, and design change — surveillance that never changes a document upstream is decoration.
  • Audit the surveillance system and its data flows, including service, distributor, and user-facility channels that can swallow complaints.
KEY DELIVERABLES
  • The post-market surveillance plan and its periodic reports
  • Complaint records with investigations and reportability decisions
  • Vigilance / adverse-event reports filed with authorities (MDR reports, field-safety notices)
  • Trend analyses and the CAPAs they triggered
  • Field action files — decision, execution, notification, effectiveness
  • Updates to the risk-management file and clinical evaluation driven by field evidence
WHERE IT GOES WRONG, AND WHAT IT COSTS DOWNSTREAM
  • Complaints defined narrowly so service calls, returns, and social-channel reports never enter the system that counts them.
  • Reportability decided by reluctance — "no injury this time" — against criteria that ask about potential, not just outcome.
  • Trending that averages away signals: global rates diluting a lot-specific or version-specific spike a stratified view would catch.
  • Field actions scoped by optimism, requiring a second, larger action when the first proves too narrow.
  • The risk file and clinical evaluation frozen at launch while surveillance accumulates evidence that their assumptions were wrong.
STANDARDS THAT BITE HERE · 6
Open the library →

Derived from the 6 standards SPEQ maps to this phase, across 4 regulatory bodies: FDA, ISO, EC, IEC.

SYSTEMS THAT HOLD THIS PHASE'S RECORDS
TOPICS THIS PHASE TURNS ON
MEDICAL DEVICE QUALITYMedical Device Quality System (ISO 13485 / QMSR)ISO 13485, the FDA QMSR harmonisation with 21 CFR 820, device risk management (ISO 14971), and software (IEC 62304).QUALITY SYSTEM / CAPACAPA: Corrective & Preventive ActionThe three words the industry uses interchangeably and shouldn’t — correction, corrective action, preventive action — and why most "CAPAs" are none of the last two.MEDICAL DEVICE QUALITYComplaint Handling & Device VigilanceEvery complaint is not a reportable event, and every reportable event is not a recall — the three decisions a device maker must keep distinct, and why under-reporting is a classic finding.MEDICAL DEVICE QUALITYClinical Evaluation & the CERThe clinical evidence that a device is safe and performs — why the how-to guidance and the legal requirement come from two different documents, and why the CER is never "done".
DISCIPLINES PRACTISED HERE

FREQUENTLY ASKED

What is the difference between post-market surveillance and pharmacovigilance?

Scope and machinery. Pharmacovigilance is the medicine-specific safety system — case-based adverse-event processing on regulatory clocks, signal management, and benefit-risk reporting under GVP. Post-market surveillance is the broader, device-anchored discipline: a planned system watching all real-world performance — complaints, malfunctions, use errors, clinical outcomes — and feeding it back into risk management and design. They overlap at the adverse event but diverge in posture: pharmacovigilance is organised around the individual case and its clock; surveillance is organised around the product and its evidence base. Combination products, and companies spanning both worlds, must run both without letting either swallow the other.

When does a complaint become reportable?

When it meets the regime's criteria — which turn on potential, not just outcome. Under 21 CFR 803, a device manufacturer reports deaths and serious injuries the device may have caused or contributed to, and malfunctions that would be likely to cause or contribute to death or serious injury if they recurred: the malfunction prong explicitly requires imagining recurrence, not just recording this instance's luck. The EU vigilance system runs on serious incidents and field safety corrective actions with its own timelines. The defensible pattern everywhere: written decision criteria, a documented decision per complaint, and periodic audit of the decisions against the criteria.

What does "closing the loop" into design actually look like?

Traceable movement of field evidence into controlled documents. Concretely: complaint and trend data reviewed against the risk-management file's estimated occurrence rates, with the file revised where reality disagrees; real-world performance feeding the clinical evaluation on its defined update cycle; recurring failure modes driving design changes through change control, with risk assessment of the change itself; and management review seeing surveillance metrics beside the rest of the quality system. The audit test is simple: pick a three-year-old recurring complaint theme and ask what document changed because of it. If the answer is none, the loop is open.