What you will learn
By the end of this topic, you should be able to organise an SME around clear medical-device responsibilities, identify which capabilities must remain under management control, create proportionate development governance and recognise when growth is outpacing the organisation's ability to provide safe, compliant and supportable products.
The SME management challenge
An established SME is neither a startup nor a small corporation. It normally has real products, customers and specialist employees, but limited management bandwidth and relatively little duplication of expertise. Informal working relationships that were once efficient can become unsafe as the product range, markets and installed base grow.
Several priorities compete
New development, customer commitments, production problems, audits, complaints and product changes often depend on the same specialists.
Roles have evolved informally
People may carry several titles while important approvals, interfaces and escalation routes remain unclear.
Knowledge is concentrated
A few long-serving employees or consultants may hold critical product and regulatory knowledge that is not captured in controlled records.
The installed base is growing
Every release creates continuing obligations for complaints, vigilance, security, suppliers, obsolescence and change.
Preserve the speed and practical judgement of a smaller company while making responsibilities, decisions and evidence reliable enough to survive growth, staff changes and regulatory scrutiny.
Management accountability cannot be delegated away
Senior management may delegate activities, but it remains responsible for establishing the organisation, resources and quality system needed to meet applicable regulatory requirements and customer needs. Management must know which entity is the legal manufacturer and ensure that it can exercise genuine control over the device throughout its lifecycle.
- Set and communicate quality objectives that support the company's medical-device strategy.
- Provide competent people, infrastructure, time and authority—not merely approve a development budget.
- Review whether the QMS remains suitable and effective as products and markets change.
- Ensure regulatory, clinical, technical, quality and commercial decisions are reconciled before commitment.
- Act when recurring problems, resource conflicts or unresolved risks are escalated.
Organise responsibilities around capabilities
An SME does not need a separate department for every discipline. It does need named owners for every essential capability and a clear distinction between performing work, reviewing it and approving the resulting decision.
Product and regulatory direction
Own intended purpose, claims, markets, classification, regulatory strategy and product priorities.
Quality and design assurance
Maintain the QMS, assure design controls, challenge evidence and preserve independent escalation to management.
Systems and technical leadership
Own requirements, architecture, interfaces, configuration, integration and technical decision records.
Clinical, risk and usability
Connect clinical value, user needs, risk controls, human factors and benefit–risk conclusions.
Verification and validation
Plan objective evidence, representative configurations, acceptance criteria, anomalies and traceability.
Supply and post-market
Control suppliers, transfer, production, release, service, complaints, surveillance, security and change.
Document deputies and succession for critical roles. If only one person can explain or approve an essential activity, the organisation has a continuity risk.
Build a QMS that can scale
A scalable QMS defines the minimum controls that must be applied consistently while allowing the depth of planning, review and evidence to be proportionate to product and process risk.
- Use one clear development framework with defined tailoring rules rather than separate informal methods for every team.
- Make document, configuration, change and approval controls easy enough that people use them during the work.
- Connect risk management to requirements, design, verification, suppliers and post-market information.
- Define when independent review is required and who may approve exceptions.
- Use deviations and corrective action to learn—not to legitimise recurring workarounds.
- Measure whether processes produce reliable outcomes, not simply whether forms are complete.
The objective is controlled evidence, not maximum documentation. A short, current plan used by the team is more valuable than a long template completed after the event.
Manage the portfolio and resources together
SMEs frequently approve more projects than their scarce specialist functions can support. The resulting multitasking delays reviews, weakens verification planning and moves lifecycle work behind visible development milestones.
Capacity planning must include quality, regulatory, clinical, verification, industrialisation and post-market work. These functions are not overhead added after the engineering estimate.
Use development governance to make decisions
Effective gates bring the right functions together to decide whether the product is ready for greater commitment. They should expose uncertainty and actions rather than reward optimistic schedules.
Opportunity and purpose
Confirm the medical need, intended purpose, claims, markets, commercial rationale and accountable owner.
Management decision: Should the organisation invest in a defined development opportunity?Plan and feasibility
Confirm regulatory route, team, major risks, capability gaps, evidence strategy, budget and schedule.
Management decision: Is the plan credible and adequately resourced?Design commitment
Review requirements, architecture, controls, interfaces and unresolved technical or clinical uncertainty.
Management decision: Is the design mature enough for formal implementation and evidence generation?Evidence and transfer
Assess verification, validation, clinical evidence, supplier and production readiness, anomalies and residual risk.
Management decision: Can the company proceed to regulatory submission, transfer or release?Lifecycle review
Review complaints, trends, field performance, changes, security, supply continuity and continued benefit–risk acceptability.
Management decision: Does the product remain supportable, compliant and strategically justified?Use external expertise without creating dependency
SMEs often rely on specialist suppliers and consultants. This can be effective when the company retains product knowledge, decision authority and access to the evidence it needs.
- Identify critical suppliers by their effect on safety, performance, compliance and business continuity.
- Define deliverables, records, acceptance criteria, configuration, intellectual property and change notification contractually.
- Assign an internal owner able to specify, review and integrate outsourced work.
- Monitor supplier performance and investigate recurring quality or delivery problems.
- Plan knowledge transfer and alternatives before a supplier relationship becomes irreplaceable.
Protect released products from development pressure
Management must reserve capacity for the installed base. Complaints, vigilance, corrective action, cybersecurity, regulatory commitments, supplier changes and obsolescence can create urgent obligations that cannot safely wait behind new-product work.
Named lifecycle ownership
Assign responsibility for every supported product, including products no longer actively sold.
Controlled change
Assess effects on requirements, risks, regulatory status, evidence, production and devices already supplied.
Signal visibility
Bring complaints, service, production, security and supplier information together so weak signals are not missed.
Retirement planning
Plan end-of-sale, support, spare parts, data, security and regulatory obligations before capability disappears.
Recognise when the organisation must change
Decisions wait for one person
Delegation, deputies and approval authorities need to mature before the central expert becomes a bottleneck.
Projects repeatedly borrow lifecycle resources
The portfolio exceeds real capacity or lifecycle responsibilities are not represented in planning.
Quality discovers work after completion
Quality and regulatory functions are being used as final inspection rather than development partners.
Supplier knowledge exceeds internal knowledge
The manufacturer may be losing practical control of its own product and evidence.
The same issues recur across projects
Management review and corrective action are not converting experience into organisational improvement.
The SME management dashboard
- Are intended purpose, claims, markets and regulatory assumptions current?
- Does each product and critical capability have an accountable owner and deputy?
- Are portfolio commitments within the capacity of specialist and lifecycle functions?
- Are the most significant product risks, anomalies and decisions visible?
- Are requirements, risk controls, design outputs and evidence traceable?
- Are critical suppliers performing acceptably and notifying relevant changes?
- Are complaint, production, service and security signals reviewed together?
- Are management-review actions improving the organisation rather than remaining open?
Authoritative starting points
- ISO 13485:2016 — Medical-device quality-management systems
- ISO 14971:2019 — Application of risk management to medical devices
- US FDA Quality Management System Regulation
- Regulation (EU) 2017/745 on medical devices
- Regulation (EU) 2017/746 on in vitro diagnostic medical devices
Specific obligations depend on the manufacturer, device, classification, markets and lifecycle arrangements. Confirm current legislation, applicable standards and regulatory guidance for the product.