Updated: 23rd June 2026
Reviewed by: David Small, BSc (Hons), MSc, MTOPRA (Founder and CEO)
Are You Liable? Understanding Your Obligations Under MDR/IVDR
When the EU Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR) came into force, the compliance landscape for medical devices in Europe changed dramatically.
Many importers, distributors, and suppliers still believe that compliance is the manufacturer’s responsibility alone. But under MDR and IVDR, that’s no longer true. Regulators have placed accountability across the entire supply chain, and every economic operator is expected to play their part.
If you’re moving medical devices into or across the EU, the reality is clear: you are legally liable for certain compliance obligations.
In this article, we’ll break down what that means in practice, explore the risks of non-compliance, and show you how Patient Guard can help protect your business.
Understanding the Wider IVDR Framework
Liability and regulatory responsibilities are only one aspect of the EU In Vitro Diagnostic Regulation. For a complete overview of IVDR classification, manufacturer obligations, performance evaluation, technical documentation, CE marking, UDI and compliance requirements, explore our Complete EU IVDR Guide.
Why MDR and IVDR Changed the Rules
- Manufacturers
- Authorised Representatives
- Importers
- Distributors
Unsure How Your IVD Should Be Classified?
Your regulatory obligations under the EU IVDR begin with correctly classifying your in vitro diagnostic device. Learn how the seven IVDR classification rules are applied, how to determine whether your device is Class A, B, C or D, and what your classification means for conformity assessment and compliance in our Complete Guide to IVDR Classification.
The MDR/IVDR Supply Chain Model
- Devices meet safety and performance requirements.
- Proper documentation and traceability exist at every step.
Who Is Responsible Under the MDR & IVDR?
The MDR and IVDR assign legal responsibilities to every economic operator involved in placing medical devices and IVDs on the European market. While manufacturers retain overall responsibility for regulatory compliance, authorised representatives, importers and distributors also have their own independent legal obligations. The table below provides a quick overview of each role before exploring them in more detail.
| Economic Operator | Primary Responsibility | Key Regulatory Duties | Liable Under MDR & IVDR? |
|---|---|---|---|
| Manufacturer | Design, manufacture and maintain regulatory compliance throughout the device lifecycle | Quality Management System (QMS), technical documentation, clinical/performance evaluation, risk management, PMS, vigilance, UDI and regulatory compliance | ✅ |
| EU Authorised Representative | Represent non-EU manufacturers within the European Union | Verify technical documentation and Declaration of Conformity, cooperate with Competent Authorities, retain regulatory documentation and act on behalf of the manufacturer | ✅ |
| Importer | Verify compliant devices before placing them on the EU market | Confirm CE marking, Declaration of Conformity, Authorised Representative designation (where required), labelling, UDI and manufacturer compliance | ✅ |
| Distributor | Verify compliance before making devices available on the market | Check CE marking, labelling, IFU, storage and transport conditions, cooperate with manufacturers and authorities, maintain traceability | ✅ |
Manufacturer Obligations Under the MDR & IVDR
Manufacturers hold the primary legal responsibility for ensuring that their medical devices and IVDs comply with the MDR and IVDR. Even where tasks are delegated to suppliers, consultants or authorised representatives, the manufacturer remains ultimately accountable for regulatory compliance.
Manufacturer obligations include:
- Establishing and maintaining a Quality Management System (QMS) appropriate for the device and compliant with Article 10 requirements.
- Preparing and maintaining complete technical documentation demonstrating conformity with the applicable regulatory requirements.
- Performing risk management throughout the entire device lifecycle in accordance with ISO 14971.
- Conducting clinical evaluation (MDR) or performance evaluation (IVDR) to demonstrate the safety and performance of the device.
- Implementing post-market surveillance (PMS), vigilance and trend reporting procedures to monitor device performance after placing it on the market.
- Assigning a Person Responsible for Regulatory Compliance (PRRC) where required under Article 15.
- Implementing a compliant Unique Device Identification (UDI) system and maintaining device registration within EUDAMED where applicable.
- Taking corrective actions, including Field Safety Corrective Actions (FSCAs), where safety or compliance issues are identified.
These responsibilities extend throughout the entire lifecycle of the device. Manufacturers cannot transfer their legal obligations to another economic operator and remain ultimately responsible for ensuring continued regulatory compliance.
Why Is ISO 13485 So Important for MDR & IVDR Compliance?
A robust Quality Management System forms the foundation of regulatory compliance for medical device and IVD manufacturers. Discover how ISO 13485 supports quality management, risk management, document control, supplier oversight, internal audits and continual improvement to help organisations meet their obligations under the MDR and IVDR.
Why Is ISO 14971 Essential for MDR & IVDR Compliance?
Effective risk management sits at the heart of the MDR and IVDR. Discover how ISO 14971 helps manufacturers identify hazards, evaluate risks, implement risk controls and maintain patient safety throughout the entire medical device lifecycle while supporting ongoing regulatory compliance.
Understanding UDI Responsibilities Under the MDR & IVDR
Unique Device Identification (UDI) plays a vital role in device traceability and regulatory compliance. Learn how manufacturers, authorised representatives, importers and distributors support UDI implementation, EUDAMED registration and supply chain traceability in our Medical Device UDI for Beginners Guide.
Manufacturing an IVD Under the IVDR?
Performance Evaluation is a core manufacturer responsibility under the IVDR. Understand how manufacturers demonstrate scientific validity, analytical performance and clinical performance and maintain that evidence throughout the device lifecycle in our Complete IVDR Performance Evaluation Guide.
Distributor Obligations Under MDR/IVDR
Distributors often underestimate the scope of their responsibilities. But the regulations are clear: if you distribute devices in the EU, you must act as a compliance gatekeeper.
Your obligations include:
- Verifying CE marking – Ensuring the product bears the CE mark before sale.
- Checking language requirements – Instructions for use (IFUs) and labels must be provided in the correct language for each market.
- Confirming Declaration of Conformity – Distributors must verify that the manufacturer has issued an EU Declaration of Conformity.
- Incident reporting – Any complaints, incidents, or suspected non-conformities must be reported to the manufacturer and, if necessary, to competent authorities.
- Maintaining records – Distributors must keep a register of non-conforming devices, product recalls, and withdrawals.
- Cooperation with authorities – Documentation must be made available to regulators upon request.
Failing to perform these checks doesn’t just put patients at risk — it puts your business in the regulator’s spotlight.
Importer Obligations Under MDR/IVDR
Importers act as the EU market entry point for devices manufactured outside the Union. That role carries weight, because regulators see importers as the final checkpoint before products reach European patients.
Importer obligations include:
- Ensuring manufacturer compliance – You must verify that the manufacturer has met all MDR/IVDR requirements.
- Verifying authorised representative designation – If the manufacturer is outside the EU, an EU Authorised Representative must be appointed.
- Labelling products with importer details – Your name and address must be visible on the device, its packaging, or accompanying documents.
- Registering devices in EUDAMED – Importers are responsible for entering product information into the EU’s central medical device database.
- Maintaining traceability – Records must be kept for at least 10 years (15 years for implantable devices).
These duties make importers directly accountable. If something goes wrong, regulators won’t just contact the manufacturer — they will come to you.
EU Authorised Representative Obligations
For manufacturers established outside the European Union, appointing an EU Authorised Representative (EC REP) is a legal requirement before devices can be placed on the EU market. The Authorised Representative acts on behalf of the manufacturer and serves as the primary regulatory contact within the EU.
Authorised Representative obligations include:
- Verifying that the manufacturer has prepared compliant technical documentation and completed the appropriate conformity assessment procedures.
- Confirming that an EU Declaration of Conformity has been drawn up and maintained.
- Keeping copies of the technical documentation, Declaration of Conformity and applicable certificates available for Competent Authority inspection.
- Cooperating with Competent Authorities and responding promptly to regulatory requests and investigations.
- Informing the manufacturer immediately of complaints, suspected incidents or regulatory concerns relating to the device.
- Terminating the mandate if the manufacturer persistently fails to meet its regulatory obligations and notifying the appropriate Competent Authorities where required.
- Maintaining a written mandate clearly defining the responsibilities of both parties in accordance with Article 11.
Although manufacturers retain ultimate responsibility for device compliance, Authorised Representatives have their own independent legal obligations and may also be held liable where they fail to fulfil their regulatory duties.
Do You Need an EU Authorised Representative?
Manufacturers based outside the European Union must appoint an EU Authorised Representative before placing medical devices or IVDs on the EU market. Learn about written mandates, regulatory liaison, documentation responsibilities, EUDAMED requirements and the representative’s independent legal obligations in our Complete Guide to EU Authorised Representatives.
Choosing an Authorised Representative or Importer?
Selecting the right regulatory partner is just as important as understanding their legal obligations. Learn how to evaluate an EU Authorised Representative or Importer, avoid common compliance pitfalls and choose a partner that will support your long-term regulatory strategy in our Guide to Selecting a Compliant Authorised Representative or Importer.
The Risks of Non-Compliance
- Product seizures at borders or by market authorities
- Suspension of sales or withdrawal of products from the market
- Heavy fines and legal action against your company or directors
- Loss of supplier relationships as manufacturers seek compliant partners
Common Mistakes Importers and Distributors Make
- Assuming the manufacturer handles everything – This is no longer true under MDR/IVDR.
- Failing to verify documentation – Many distributors skip the step of confirming CE marking or checking the Declaration of Conformity.
- Weak record-keeping – Without traceability, you can’t prove compliance if audited.
- Not training staff – Employees often don’t understand their role in regulatory compliance.
- Delaying incident reporting – Waiting too long to escalate complaints or non-conformities exposes both patients and businesses.
Building a Compliance Culture Across Your Supply Chain
Achieving compliance with the MDR and IVDR is not a one-off exercise. Manufacturers and other economic operators must establish processes that ensure compliance is maintained throughout the entire product lifecycle. Building a strong compliance culture reduces regulatory risk, improves product quality and demonstrates a proactive commitment to patient safety.
Supplier Qualification and Oversight
Your compliance is only as strong as your supply chain. Before working with suppliers, manufacturers should carry out appropriate due diligence to ensure they can consistently meet regulatory and quality requirements.
This may include:
- Supplier qualification questionnaires
- Quality agreements
- Supplier audits
- Performance monitoring
- Change notification procedures
- Ongoing supplier re-evaluation
Maintaining strong supplier relationships helps reduce the risk of non-conforming products entering your manufacturing process.
Conduct Regular Compliance Audits
Internal audits help organisations identify weaknesses before they become regulatory findings. Routine audits should assess compliance with the MDR, IVDR, ISO 13485 and internal quality procedures.
Regular audits should review:
- Technical documentation
- Risk management files
- Clinical or performance evaluation documentation
- Complaint handling
- Post-market surveillance activities
- Corrective and Preventive Actions (CAPAs)
Early identification of compliance gaps can significantly reduce the likelihood of regulatory action or Notified Body non-conformities.
Invest in Staff Training
Even the best quality system can fail if employees do not understand their regulatory responsibilities. Organisations should provide regular training covering both regulatory requirements and internal procedures.
Training should be appropriate for each role and include topics such as:
- MDR and IVDR requirements
- Quality Management System procedures
- Complaint handling
- Vigilance reporting
- Risk management
- Documentation requirements
Training records should be maintained and periodically reviewed to demonstrate ongoing competency.
Maintain Effective Documentation Control
Regulatory compliance depends upon accurate, controlled documentation. Procedures should ensure that all quality records, technical documentation and regulatory evidence remain current, traceable and readily available for inspection.
Good document control includes:
- Version control
- Change management
- Document approvals
- Record retention
- Secure storage
- Controlled document distribution
Well-managed documentation makes regulatory inspections and Notified Body audits significantly more efficient.
Encourage Internal Reporting and Continuous Improvement
Employees should feel confident reporting quality concerns, customer complaints and potential compliance issues without fear of blame. Early reporting allows organisations to investigate problems quickly and implement appropriate corrective actions before they escalate.
An effective reporting culture supports:
- CAPA management
- Trend analysis
- Complaint investigations
- Vigilance reporting
- Risk management updates
- Continuous improvement initiatives
Perform Annual Compliance Reviews
Regulatory compliance should be reviewed regularly rather than only when an audit or inspection is approaching. Annual management reviews provide an opportunity to evaluate the effectiveness of the Quality Management System and identify opportunities for improvement.
A comprehensive annual review should consider:
- Audit findings
- Customer complaints
- Post-market surveillance data
- Vigilance reports
- Supplier performance
- Regulatory changes
- Risk management activities
- Quality objectives
Regular reviews help ensure the organisation remains compliant as regulations evolve and products continue through their lifecycle.
Compliance Is Everyone's Responsibility
Whether you are a manufacturer, authorised representative, importer or distributor, compliance with the MDR and IVDR depends on more than simply meeting individual legal obligations. It requires collaboration across the entire supply chain, supported by robust quality systems, competent personnel and a culture of continual improvement. Organisations that embed compliance into their day-to-day operations are better positioned to achieve successful regulatory inspections, maintain market access and deliver safe, effective medical devices and IVDs to patients.
How Patient Guard Supports Importers and Distributors
At Patient Guard, we know that MDR and IVDR can feel overwhelming — especially for businesses without in-house regulatory teams. That’s why we specialise in helping economic operators build compliance into their day-to-day operations.
Our services include:
- ✅ Supply chain audits – Identify gaps before regulators do.
- ✅ Team training – Equip your staff with practical compliance knowledge.
- ✅ System development – Create efficient, documented processes that meet EU requirements.
- ✅ Ongoing support – Stay ahead of regulatory changes with expert guidance.
We don’t just help you tick boxes — we help you build a compliance culture that protects patients and safeguards your business.
Frequently Asked Questions About Responsibilities Under MDR & IVDR
Manufacturers, authorised representatives, importers, and distributors. Each has defined legal responsibilities.
Yes. Distributors must verify that products are CE marked and that the manufacturer has issued a valid EU Declaration of Conformity.
Importers must keep traceability records for at least 10 years, and 15 years for implantable devices. Distributors must also maintain records of complaints and recalls.
EUDAMED is the EU’s central database for medical devices. It improves transparency and traceability, and importers are responsible for registering devices.
References
This guide is based on the following legislation and official regulatory guidance relating to legal responsibilities, economic operators and regulatory obligations under the European Medical Devices Regulation (MDR) and In Vitro Diagnostic Medical Devices Regulation (IVDR).
| Organisation | Reference | Why it's relevant |
|---|---|---|
| European Union | Regulation (EU) 2017/745 on Medical Devices (MDR) | Provides the legal framework defining the obligations and responsibilities of manufacturers, Authorised Representatives, importers, distributors and other economic operators placing medical devices on the EU market. |
| European Union | Regulation (EU) 2017/746 on In Vitro Diagnostic Medical Devices (IVDR) | Establishes the legal responsibilities and regulatory obligations for manufacturers and economic operators placing in vitro diagnostic medical devices on the European market. |
| European Commission | Economic Operators | Explains the responsibilities of manufacturers, Authorised Representatives, importers, distributors and system or procedure pack producers under the MDR and IVDR. |
| European Commission | MDCG Endorsed Documents and Other Guidance | Provides official Medical Device Coordination Group (MDCG) guidance supporting the practical implementation of legal obligations under the MDR and IVDR. |
| International Organization for Standardization (ISO) | ISO 13485:2016 – Medical Devices – Quality Management Systems – Requirements for Regulatory Purposes | Defines the internationally recognised Quality Management System requirements that help manufacturers fulfil many of their ongoing regulatory obligations under the MDR and IVDR. |
| International Organization for Standardization (ISO) | ISO 14971:2019 – Medical Devices – Application of Risk Management to Medical Devices | Provides the internationally recognised framework for risk management, supporting manufacturers in meeting their responsibilities for device safety throughout the product lifecycle. |
Legal responsibilities and regulatory expectations continue to evolve. Manufacturers and other economic operators should always consult the latest published legislation, recognised standards and official guidance when placing, maintaining and supporting medical devices and in vitro diagnostic medical devices on the European market.
David Small BSc (Hons), MSc, MTOPRA
Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs, MDR/IVDR compliance and quality systems.
Patient Guards Recent Posts

The Complete Guide to NHS DTAC Compliance for Digital Health Manufacturers
A complete guide to NHS DTAC compliance for digital health manufacturers, covering the five DTAC assessment areas, required evidence, clinical safety, data protection, technical security, interoperability and usability, and how to prepare your digital health technology for NHS procurement.

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance
Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up
Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.
Need Training?
Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.
Posted on Google![]()
Jay Verma1 days agoTrustindex verifies that the original source of the review is Google.
I found Patient Guard Ltd to be an exceptional partner. Their assessment was thorough, their guidance clear, and their support instrumental in helping us achieve our objectives. Steve and Ellie, in particular, were outstanding in steering us through the MHRA Class I medical device registration process.Posted on Google![]()
Munna P54 days agoTrustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.Posted on Google![]()
Peter Reeve81 days agoTrustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.Posted on Google![]()
Derek Timm81 days agoTrustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South LımıtedPosted on Google![]()
BMSCriticalCare118 days agoTrustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,Posted on Google![]()
Thomson Software789 days agoTrustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.Verified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more