Can a 20-person SME have a truly effective in-house regulatory function? Yes — provided this function is sized correctly and is not asked to do what it cannot reasonably do alone.
What the in-house regulatory function covers
An in-house regulatory function in a 20-person SME typically comprises one person dedicated 50 to 100% to regulatory affairs and quality, depending on the volume and complexity of the device portfolio.
This person is responsible for keeping the QMS operational between audits, managing complaints and non-conformities on a day-to-day basis, ensuring post-market surveillance (collecting and analysing PMS data), coordinating relations with the notified body and the competent authorities, and performing the PRRC function within the meaning of Article 15 of the MDR.
This is a broad scope. To hold it properly with a single person, processes must be well established and the workload must not simultaneously include an initial MDR compliance effort, an ISO 13485 certification to build from scratch, and active post-market surveillance across several devices.
The required competency profile
The PRRC under Article 15 of the MDR requires either a degree in science, law, pharmacy, medicine or engineering with one year of experience in medical device regulation, or four years of experience in medical device regulation.
Beyond the formal requirements, the necessary operational competencies are: knowledge of the MDR and ISO 13485 frameworks, the ability to write procedures and records, autonomy in managing a QMS, and ease in communicating with notified bodies and authorities.
This profile exists but is not common. A “quality manager” with experience in another industrial sector (pharmaceutical, aerospace) can build up expertise on the specifics of medical devices, but this requires training and time.
What the in-house function cannot do alone
The clinical evaluation of a Class IIa or IIb device cannot be carried out properly by a person without specific experience in this area. It is a competency acquired over several years of practice. Doing it “by self-training” for the first CER of a critical certification is a genuine regulatory risk.
Risk management for complex active devices, responding to major non-conformities raised by a notified body, and preparing for an ANSM inspection are other situations where external support brings value that the in-house resource alone cannot provide, at least in the early years.