← All work

AI-powered cloud SaaS quality management system for medical device manufacturers.

How we built a full-compliance QMS covering 8 modules, with AI-driven risk intelligence, a regulatory AI assistant, 21 CFR Part 11 e-signatures, and real-time compliance KPIs — delivered under ISO 27001 certification from day one.

Client
Anonymous medical device QMS provider
industry
Healthcare
country
European Union
engagement
End-to-end product build
stack
OpenAI
AWS
8
Compliance modules covering the full quality lifecycle
ISO 27001
Certified development process from day one
21 CFR
Part 11 e-signatures built in across all modules
AI
Risk intelligence with traceable regulatory citations
01 / Client
A SaaS provider building the QMS that the medical device market was missing.

Medical device quality is one of the most regulated processes in any industry. Most teams manage it in spreadsheets.

Quality management for medical device manufacturers is one of the most regulated and documentation-intensive processes in any industry. FDA 21 CFR Part 820, ISO 13485, MDR, CE marking — the regulatory frameworks are overlapping, demanding, and unforgiving of gaps.

Yet most small and mid-size medical device companies manage their quality systems in a patchwork of spreadsheets, shared drives, and email chains. This client set out to build the QMS platform that the market was missing: cloud-native, AI-augmented, covering the full compliance lifecycle, and genuinely usable by quality managers without specialist IT support. They needed a development partner who could deliver a complex multi-module SaaS product under the security and compliance requirements that medical device customers demand.

02 / Challenge
Eight regulated domains, all interconnected, all critical to get right — plus AI that earns trust.

Building a QMS that only covers document management doesn't solve the problem.

The platform needed to span the full quality lifecycle with genuine workflow automation in each module — not just document storage. Eight compliance domains, all interconnected, all regulated, all critical to get right. The AI features needed to deliver genuine value, not superficial compliance theatre.

01

Breadth of regulatory coverage

The platform needed to span the full quality lifecycle — Documents, Training, CAPA, Risk, Supplier, Audits, Change Control, and Post-Market Surveillance — with genuine workflow automation in each, not just document storage.

02

21 CFR Part 11 compliance

FDA regulations for electronic records and signatures are specific and technically demanding. The e-signature implementation needed to satisfy audit trail, signature meaning, and record integrity requirements.

03

Making AI genuinely useful in compliance

The AI risk intelligence and regulatory assistant needed to deliver genuine value — surfacing risk insights quality managers would act on, and giving regulatory guidance traceable to the correct regulatory source.

04

ISO 27001 delivery requirements

Medical device manufacturers buying a compliance platform need confidence in the security of the platform holding their quality records. ISO 27001 certification was a customer expectation, not an option.

03 / Approach
8 interconnected modules, AI grounded in regulatory text, signatures locked under audit trail.

From spreadsheets to a full-compliance AI-powered QMS.

0
1
Core modules

8 interconnected compliance modules with full workflow automation

Each module is a structured workflow system, not a document folder. Cross-module linkages mean a non-conformance in Document Management automatically creates a CAPA record, a finding in an audit triggers Change Control review, and supplier issues feed into Risk Management automatically.

0
2
Signatures

21 CFR Part 11 electronic signatures

Each signature carries the signer's authenticated identity, the meaning of the signature, the date and time, and an unalterable audit trail. Signed records are cryptographically locked against modification after signing.

0
3
AI intelligence

AI risk intelligence and regulatory AI assistant

The AI risk module analyses risk records, CAPA history, and post-market surveillance data to surface emerging risk patterns before they breach threshold. The regulatory AI assistant answers questions about FDA, MDR, and ISO 13485 requirements, grounded in the actual regulatory text with clause-level citation.

0
4
Visibility

Real-time compliance KPI dashboard and API integrations

The KPI dashboard gives quality managers a real-time view of their compliance posture: open CAPAs by age and severity, document review overdue counts, training completion rates, audit findings, and supplier risk scores. APIs expose every record for ERP and EDC integrations.

04 / Delivered
Nine modules covering document management through post-market surveillance.

What we shipped.

0
1

Document Management

Controlled document lifecycle — authoring, review, approval, versioning, and distribution with 21 CFR Part 11 signatures.

0
2

Training Management

Training assignment, completion tracking, and effectiveness assessment linked to document updates.

0
3

CAPA Management

Root cause analysis, corrective action planning, implementation tracking, and effectiveness verification.

0
4

Risk Management

FMEA-based risk assessment with AI risk intelligence and cross-module risk linkage.

0
5

Supplier Management

Supplier qualification, evaluation, and risk scoring with automatic audit schedule triggers.

0
6

Audit Management

Internal and external audit planning, finding management, and CAPA linkage.

0
7

Change Control

Change request workflow with impact assessment, approval chains, and implementation verification.

0
8

Post-Market Surveillance

Complaint handling, vigilance reporting, and PMS data trending with AI pattern detection.

0
9

Real-time KPI dashboard

Configurable compliance KPIs with threshold alerts and trend views across all modules.

05 / Results
From spreadsheet patchwork to a single audit-ready compliance platform.

Eight modules connected. AI surfacing risk early. Audits trivial.

8
Compliance modules covering the full quality lifecycle
ISO 27001
Certified development process from day one
21 CFR
Part 11 e-signatures built in across all modules
AI
Risk intelligence with traceable regulatory citations

Eight modules. Complete lifecycle.

Every stage of the medical device quality lifecycle is covered in a single platform — no spreadsheet supplements, no module gaps, no manual handoffs between systems.

ISO 27001 certified development process

The entire engagement was delivered under ISO 27001 certification, giving medical device customers confidence in the security of the platform holding their quality records.

21 CFR Part 11 compliant from day one

Full 21 CFR Part 11 e-signature implementation — every record signed under audit-traceable, cryptographically-protected workflows that satisfy FDA electronic records requirements.

AI risk intelligence that acts early

The AI risk module surfaces emerging risk patterns before they breach threshold, moving quality management from reactive gap-closing to proactive risk prevention.

06 / In the team's words
"
The AI had to earn trust by being traceable, not just fluent. A regulatory assistant that gives confidently wrong answers is worse than no AI at all in a quality management context. Every AI response is grounded in the actual regulatory text and cites the relevant clause — quality managers need reliable guidance they can reference in an audit.
UT
Project lead
Unlocking Tech · Engineering team
07 / Stack
Mature, auditable, regulated-environment-ready.

Technology stack.

Built under ISO 27001 certification from day one. The AI layer is grounded in the actual regulatory text — every answer cites the clause it came from. Every signed record is cryptographically locked against modification after signing.

OpenAI
AWS
.Net
ReactJs
Start a Project

Building a regulated QMS or compliance platform?

If you're building a compliance platform or quality management system for medical devices, we've delivered ISO 27001-certified QMS software with AI intelligence and 21 CFR Part 11 e-signatures. It's worth a chat.

Related Work

More related case studies.

All work →