What you will learn
By the end of this topic, you should be able to distinguish governance from project management, structure accountability across legal entities and matrix functions, align portfolio investment with evidence and risk, and define the assurance information senior leadership needs without attempting to manage every technical decision.
Leadership governs the system, not every design decision
Corporate leaders create the conditions within which safe and compliant medical devices can be developed and supported. They determine strategy, accountability, investment, organisational capability, risk appetite and escalation. Competent product teams determine the detailed technical solution within that governed system.
Set direction
Align medical purpose, markets, product strategy, quality objectives and acceptable business exposure.
Establish accountability
Define which entity and leaders own manufacturer obligations, products, functions, decisions and escalation.
Provide capability
Maintain sufficient competent people, infrastructure, independent assurance and lifecycle resources.
Demand evidence
Base investment and release decisions on maturity, risk and objective evidence rather than schedule confidence alone.
Delegation should move decisions to competent people while preserving visibility, challenge and timely escalation for matters that could affect patients, compliance, major investment or corporate reputation.
Make legal-manufacturer accountability explicit
In a corporate group, brand ownership, design authority, manufacturing, distribution and regulatory registrations may sit in different entities. Governance must make the legal manufacturer's authority and access to evidence real—not merely contractual wording.
- Identify the legal manufacturer and applicable economic-operator roles for every product and market.
- Define who owns intended purpose, regulatory strategy, technical documentation, QMS and market release.
- Ensure the manufacturer can direct and obtain records from design centres, factories, shared services and suppliers.
- Clarify accountability when platforms, software services or components are shared across business units.
- Define escalation when corporate commercial decisions conflict with manufacturer obligations.
A matrix organisation does not dilute regulatory responsibility. It increases the need for clear decision rights, documented interfaces and access to competent independent advice.
Use a layered governance model
Board and executive oversight
Set strategy, quality policy, major risk expectations, investment boundaries and accountability for the management system.
Focus: enterprise exposure, patient impact, compliance, reputation and sustained capability.Business-unit and portfolio governance
Prioritise products, allocate resources, resolve cross-functional conflicts and authorise major lifecycle commitments.
Focus: portfolio value, evidence maturity, capacity, dependencies and market obligations.Product and programme governance
Review intended purpose, requirements, risk, architecture, evidence, transfer, regulatory readiness and change.
Focus: product-level decisions and objective readiness.Functional and independent assurance
Provide technical authority, quality assurance, regulatory challenge, audit, specialist review and protected escalation.
Focus: competence, consistency, compliance and early warning.Each layer should know which decisions it owns, what evidence it requires and what matters must be escalated. More committees do not create stronger governance unless decision rights become clearer.
Govern the portfolio as a set of lifecycle commitments
A new product does not consume resources only until launch. It creates long-term obligations for surveillance, clinical evidence, security, suppliers, obsolescence, regulatory maintenance and eventual retirement.
Portfolio gates should compare products on evidence-adjusted value. A commercially attractive opportunity with an unclear intended purpose, weak clinical strategy or unavailable specialist capability is not ready for the same commitment as a well-defined programme.
Create assurance and escalation that leaders can trust
Senior leaders need independent signals that the development system is functioning. Assurance should combine product evidence, process performance, audit, management review and real-world outcomes.
First-line control
Product and operational teams own compliant execution, accurate reporting and timely escalation.
Second-line assurance
Quality, regulatory, safety, security and technical authorities define expectations and challenge readiness.
Independent assessment
Internal audit and appropriately independent review assess whether controls work in practice.
Executive action
Leadership resolves systemic constraints, repeated exceptions and material patient, compliance or business exposure.
Escalation criteria should be agreed in advance. Examples include potential unacceptable risk, reportable events, material regulatory nonconformity, critical evidence failure, unresolved release anomalies, cybersecurity exposure and loss of a critical supplier or capability.
Standardise the necessary core—and permit controlled variation
Corporate systems benefit from common terminology, minimum controls, data structures and decision expectations. Excessive local variation hides risk; excessive centralisation can create processes that do not fit different products or regulatory roles.
- Define enterprise minimums for design controls, risk, configuration, change, supplier control and post-market activity.
- Allow documented tailoring based on product, risk, lifecycle phase and local regulatory responsibility.
- Use common identifiers and traceability concepts so evidence can move across functions and systems.
- Control shared platforms and services as products with accountable owners, baselines and supported interfaces.
- Ensure local procedures identify how corporate processes satisfy the legal manufacturer's specific obligations.
Invest in capability and the culture to use it
Headcount alone does not demonstrate capability. Leaders must ensure that specialist expertise, independence, succession, tools and learning are sufficient for the actual product portfolio.
Competence strategy
Map critical skills against future products, technologies, markets and lifecycle obligations.
Technical authority
Give recognised experts authority to set principles, challenge decisions and escalate concerns.
Succession and resilience
Reduce dependence on single experts, sites, suppliers and undocumented organisational knowledge.
Speak-up culture
Reward early disclosure of uncertainty and bad news; do not allow schedule pressure to suppress evidence.
A healthy development culture distinguishes accountable challenge from obstruction. Leaders should expect teams to explain what is known, what is uncertain and what evidence would justify the next decision.
Govern acquisitions, partners and shared services
Transactions and partnerships can create hidden product and compliance liabilities. Due diligence should evaluate the ability to understand, support and control the device—not only its market potential and certificates.
- Assess intended purpose, classifications, registrations, QMS scope and unresolved regulatory commitments.
- Review design history, technical documentation, risk, clinical evidence, complaints, CAPA and cybersecurity exposure.
- Confirm access to source information, intellectual property, suppliers, manufacturing knowledge and competent personnel.
- Identify differences in lifecycle processes, data models, tools and approval authorities.
- Plan integration without interrupting complaint handling, vigilance, supply, security or change control.
Fund the complete lifecycle
Corporate investment models often favour visible new-product programmes while dispersing lifecycle work across operating budgets. Governance should make the total obligation visible and protect resources for products already in use.
“The product is complete at launch.”
Clinical evaluation, surveillance, security, suppliers, regulatory maintenance and corrective action continue.
“Legacy products are low priority.”
An ageing installed base may carry significant safety, supply, security and compliance exposure.
“A platform saves effort automatically.”
Shared components reduce duplication only when ownership, configuration, change impact and evidence reuse are controlled.
“Certification proves the organisation is effective.”
Certification supports confidence in the QMS; leadership still needs evidence of product outcomes and control effectiveness.
“No escalation means no problem.”
It may indicate weak reporting, unclear thresholds or a culture that penalises bad news.
The corporate leadership dashboard
- Are legal-manufacturer and product accountabilities explicit across entities and markets?
- Are portfolio commitments aligned with specialist capacity and lifecycle obligations?
- Which products carry the greatest patient, regulatory, technical, supply or security exposure?
- Are material risks, evidence gaps, anomalies and exceptions escalating early enough?
- Do independent assurance signals agree with programme reporting?
- Are recurring problems producing systemic corrective action across business units?
- Are critical capabilities, platforms, suppliers and succession plans resilient?
- Are released and legacy products adequately funded through retirement?
Authoritative starting points
- ISO 13485:2016 — Medical-device quality-management systems
- ISO 14971:2019 — Application of risk management to medical devices
- US FDA Quality Management System Regulation
- Regulation (EU) 2017/745 on medical devices
- Regulation (EU) 2017/746 on in vitro diagnostic medical devices
Governance arrangements must reflect the organisation's legal entities, regulatory roles, devices, markets and risk profile. Confirm current legislation, applicable standards and competent advice for each manufacturer and product.