Why vigilance data breaks your clinical evaluation update

Hatem Rabeh

Written by HATEM RABEH, MD, MSc Ing

Your Clinical Evaluation Expert And Partner

in
S

I reviewed a clinical evaluation report last month where the manufacturer had diligently monitored EUDAMED for three years. They had evidence of hundreds of incidents logged across Europe for similar devices. Yet, the clinical evaluation made no reference to any of it. When the Notified Body asked why, the answer was: “We thought vigilance was a separate process.”

This is not an isolated case. Many manufacturers treat vigilance data as a compliance checkbox—something to report, track, and close out. But under MDR Article 61, clinical evaluation is not a document you write once. It is a living process that must continuously assess the clinical safety and performance of your device. And vigilance data is one of the most direct signals you have.

EUDAMED is designed to centralize that signal. Since May 2024, the vigilance module has been operational. Manufacturers are required to report serious incidents and field safety corrective actions through the system. What many still miss is that this data does not sit in isolation. It feeds directly back into your clinical evaluation, your benefit-risk analysis, and your post-market surveillance.

If you are not systematically screening vigilance data and reflecting it in your clinical evaluation updates, you are not complying with MDR. And if a Notified Body or competent authority finds that gap, it will not be treated as a documentation issue. It will be treated as a failure to understand the safety profile of your device.

What the vigilance module actually contains

EUDAMED’s vigilance module is not just your own incident reports. It aggregates data from all manufacturers, across all member states, for all registered devices. This means you can see incidents related to devices similar to yours, even if they are from competitors or from classes adjacent to your own.

Under MDR Article 92 and the implementing regulation, manufacturers must report serious incidents and field safety corrective actions within strict timelines. These reports include device identification, incident description, root cause analysis, corrective actions, and clinical impact. Some reports are detailed. Others are less so. But they are public within the system, at least to regulatory users and authorized parties.

What this creates is a growing dataset of real-world safety signals. It is not passive literature. It is not a theoretical risk catalogue. It is evidence of what actually went wrong, in real clinical use, with devices that may share design features, indications, or patient populations with yours.

Key Insight
EUDAMED vigilance data is not optional background reading. It is direct post-market evidence that must be systematically screened and evaluated against your device’s benefit-risk profile. Ignoring it is a gap in clinical evaluation, not just in quality management.

How vigilance data connects to clinical evaluation

The clinical evaluation is required to assess all available clinical data. MDR Annex XIV, Part A, Section 1 is explicit: this includes post-market data from the manufacturer’s own device and from equivalent or similar devices. Vigilance data falls squarely into this category.

When you update your clinical evaluation—whether through a Clinical Evaluation Report update or a PMCF Evaluation Report—you are expected to address new safety signals. If incidents have been reported in EUDAMED that involve failure modes, adverse events, or user errors relevant to your device, those must be acknowledged. You must assess whether they apply to your device. If they do, you must evaluate whether they change your benefit-risk conclusion. If they do not, you must document why.

This is not a theoretical exercise. Notified Bodies and competent authorities have direct access to EUDAMED. If they see vigilance reports for devices similar to yours and your clinical evaluation does not mention them, they will ask why. And “we were not aware” is not an acceptable answer. The data is available. You are expected to monitor it.

Common Deficiency
Manufacturers update their clinical evaluation annually but only search published literature. They do not systematically query EUDAMED vigilance data for similar devices. When incidents appear that involve the same failure mode or clinical risk, the clinical evaluation remains silent. This creates a documented gap between available evidence and stated conclusions.

What systematic screening actually means

Screening vigilance data is not the same as reading every incident report. That would be impractical and inefficient. But it does require a structured approach.

First, you need to define your search criteria. This includes your device classification, intended use, anatomical site, and known risk profile. If your device is a cardiovascular stent, you need to monitor incidents related to stents with similar design, material, or deployment mechanism. If your device is a surgical instrument with a specific ergonomic feature, you need to monitor incidents involving similar instruments where user interaction was a factor.

Second, you need to establish a monitoring frequency. This depends on your device class and risk profile. For Class III devices or devices with active PMCF, quarterly screening is reasonable. For lower-risk devices with stable performance, biannual screening may be acceptable. But the frequency must be documented and justified.

Third, you need a process for evaluating relevance. Not every incident will apply to your device. But the decision that it does not apply must be documented. If an incident involves a failure mode you have already mitigated through design or labeling, document that. If it involves a patient population you do not target, document that. The key is traceability.

Finally, you need to feed the results into your clinical evaluation and post-market surveillance. If vigilance data reveals a new risk or increases the frequency of a known risk, that must be reflected in your benefit-risk analysis. If it triggers a need for additional PMCF data, that must be documented in your PMCF plan.

The integration trap: treating vigilance as separate

The most common mistake I see is organizational. Vigilance is handled by the quality team. Clinical evaluation is handled by regulatory affairs or clinical affairs. Post-market surveillance is sometimes handled by yet another group. Each team does its job. But the data does not flow between them.

This creates a situation where vigilance reports are filed on time, clinical evaluation reports are updated on schedule, and PMCF is executed according to plan—but none of them reference each other. When a Notified Body reviews the technical documentation, they see three parallel streams of work that should be interconnected but are not.

Under MDR, this is not acceptable. Article 10(9) requires manufacturers to have a system for post-market surveillance that includes vigilance data, complaint data, clinical follow-up data, and literature. All of this must feed into the clinical evaluation. The regulation does not allow for silos.

Practically, this means your clinical evaluation update process must include a formal input from your vigilance system. Before you finalize a CER update, someone must confirm: Have we screened EUDAMED? Have we reviewed our own incident reports? Have we identified any trends or signals that require analysis? If the answer to any of these is no, the update is incomplete.

Key Insight
Integration is not a documentation exercise. It is a process requirement. Your clinical evaluation, vigilance, and PMCF processes must exchange data systematically. If they operate in parallel without formal handoffs, you are not compliant—even if each process runs perfectly on its own.

What happens when vigilance data changes your benefit-risk

Sometimes, vigilance data does more than confirm what you already know. It reveals something new. A failure mode you did not anticipate. A user error pattern you did not model. An adverse event in a subpopulation you thought was low-risk.

When that happens, the clinical evaluation must respond. If the new data increases the severity or frequency of a known risk, your benefit-risk analysis must be updated. If it introduces a new risk, that risk must be added to your risk management file and reflected in your instructions for use. If the change is significant, you may need to notify your Notified Body and potentially trigger a significant change assessment.

This is where many manufacturers hesitate. They fear that acknowledging a new risk will delay certification or trigger additional scrutiny. But the opposite is true. Notified Bodies expect you to respond to new data. If you identify a signal, evaluate it, and implement appropriate mitigations, that demonstrates a mature quality system. If you ignore it and they find it later, that demonstrates a failure in post-market surveillance.

The key is documentation. If vigilance data reveals a concern, document how you became aware of it, how you assessed its relevance, what analysis you performed, and what actions you took. If you conclude that no action is needed, document why. But do not stay silent.

How to structure the vigilance input to clinical evaluation

In practice, this should be formalized in your clinical evaluation procedure. Before each scheduled update, a vigilance review should be conducted. This review should produce a short report that summarizes:

• The search strategy used in EUDAMED (search terms, date range, device categories)
• The number of incidents identified and reviewed
• The number of incidents deemed relevant to your device
• A summary of relevant incidents, including root causes and corrective actions
• An assessment of whether these incidents affect your benefit-risk conclusion
• Any actions triggered (risk management updates, labeling changes, PMCF modifications)

This report becomes an input to the clinical evaluation. It does not need to be long. But it must exist. And it must be traceable.

If no relevant incidents were found, that should also be documented. A statement like “EUDAMED vigilance data was screened for similar devices. No incidents were identified that alter the benefit-risk profile of our device” is acceptable—if it is true and if the search was properly conducted.

Common Deficiency
Manufacturers add a generic statement in the clinical evaluation: “Vigilance data was reviewed.” But there is no supporting document. No search log. No list of reviewed incidents. No rationale for why certain incidents were excluded. When audited, this creates an immediate gap. The claim cannot be verified.

What this means for PMCF planning

Vigilance data also influences your PMCF plan. If EUDAMED reveals incidents that suggest a risk is more frequent than anticipated, that may justify expanding your PMCF to collect more targeted data. If it reveals a user error pattern, that may justify a human factors follow-up study. If it reveals variability in performance across clinical settings, that may justify a registry or observational study.

MDCG 2020-10-1 on PMCF plan templates emphasizes that the plan must be responsive to emerging evidence. Vigilance data is one of the clearest forms of emerging evidence. If your PMCF plan is static and does not adapt when safety signals appear, it is not fulfilling its intended purpose.

This does not mean you need to launch a new study every time an incident is reported. But it does mean your PMCF plan should include a mechanism for reviewing vigilance data and determining whether additional follow-up is warranted. That mechanism should be documented.

Where this is heading

EUDAMED is still maturing. The vigilance module is operational, but not all member states are fully synchronized. Some data is still being migrated from legacy systems. Query functions are improving, but they are not yet as refined as some commercial databases.

But the direction is clear. EUDAMED will become the primary source of post-market safety data in Europe. As the system stabilizes, the expectation for manufacturers to actively use it will only increase. Competent authorities will assume you are monitoring it. Notified Bodies will reference it in their assessments. And if your clinical evaluation does not reflect it, that will be a finding.

The manufacturers who adapt early will have an advantage. Not because they are avoiding scrutiny, but because they are building a feedback loop that improves their devices. Vigilance data, when properly analyzed, does not just satisfy regulatory requirements. It reveals real-world performance gaps that you can address before they become field actions.

If your clinical evaluation process does not yet include a formal vigilance data review, now is the time to build it. Not because a guidance document says so, but because the data is available, and it matters. And the regulators reviewing your file already know that.

Peace,
Hatem
Clinical Evaluation Expert for Medical Devices
Follow me for more insights and practical advice.

Frequently Asked Questions

What is a Clinical Evaluation Report (CER)?

A CER is a mandatory document under MDR 2017/745 that demonstrates the safety and performance of a medical device through systematic analysis of clinical data. It must be updated throughout the device lifecycle based on PMCF findings.

How often should the CER be updated?

The CER should be updated whenever significant new clinical data becomes available, after PMCF activities, when there are changes to the device or intended purpose, and at minimum during annual reviews as part of post-market surveillance.

What causes CER rejection by Notified Bodies?

Common reasons include inadequate equivalence demonstration, insufficient clinical data for claims, poorly structured SOTA analysis, missing gap analysis, and lack of clear benefit-risk determination. Structure and logical flow are as important as the data itself.

Which MDCG guidance documents are most relevant for clinical evaluation?

Key documents include MDCG 2020-5 (Equivalence), MDCG 2020-6 (Sufficient Clinical Evidence), MDCG 2020-13 (CEAR Template), MDCG 2020-7 (PMCF Plan), and MDCG 2020-8 (PMCF Evaluation Report). MDR Article 92, MDCG 2020-10-1

Need Expert Help with Your Clinical Evaluation?

Get personalized guidance on MDR compliance, CER writing, and Notified Body preparation.

Peace, Hatem

Your Clinical Evaluation Partner

Follow me for more insights and practical advice.

References:
– MDR 2017/745 Article 61 (Clinical Evaluation)
– MDR 2017/745 Article 92 (Vigilance Reporting)
– MDR Annex XIV (Clinical Evaluation Requirements)
– MDCG 2020-10-1 (PMCF Plan Template and Evaluation Report Template)

Deepen Your Knowledge

Read Complete Guide to Clinical Evaluation under EU MDR for a comprehensive overview of clinical evaluation under EU MDR 2017/745.