Pathstone keeps your documentation accurate and traceable.
Every time your product changes, it checks your QMS and technical file, flags the gaps and drafts the fix for your approval.
- You approve every change
- Full version history
- Every change sourced
Continuous SOP checks
SOP-014 Software change control
§5 Change evaluation
Gap against IEC 62304 §7.4.2
No step to assess a change's effect on existing risk controls.
1 gap found · redline drafted
Change impact analysis
Model v2.4 retrain
Pathstone: this change affects 4 items.
- SRS-12Performance requirement: new metrics attached
- RISK-07False-negative control: evidence out of date
- CER §4.2Clinical claim no longer matches results
- ChangeChange assessment drafted for review
Proposed · RISK-07
Remove: Verified sensitivity ≥ 92% on test set v2
Add: Verified sensitivity ≥ 94% on test set v3
3 sources linked
Version history
RISK-07 False-negative control
v3.2 · Approved by Head of Quality
Today, 14:02
v3.2 · Proposed by Pathstone from PR #122
Today, 09:41
v3.1 · Approved by RA Lead
12 Aug
v3.0 · Approved at design review
3 Jun
Audit trail · export ready
For teams working under
- FDA 21 CFR 820
- EU MDR 2017/745
- ISO 13485
- IEC 62304
- ISO 14971
- IEC 62366-1
- IEC 81001-5-1
- EU AI Act
- PCCP
- GMLP
Works alongside GitHub, Jira, Confluence, Google Drive and your eQMS.
A real example
The SOP said 5 working days. The regulation said 2.
A UK device maker's complaints SOP gave the team 5 to 6 working days to evaluate a complaint. EU MDR can require a serious incident to be reported within 2. Nobody noticed until the audit.
Without Pathstone
Complaint handling SOP · §4 Evaluation
Complaints are received and evaluated within 5 to 6 working days.
Minor NC at audit
With Pathstone
Complaint handling SOP · §4 Evaluation
Complaints are evaluated within 1 to 2 working days. Potential serious incidents are escalated the same day for reporting under EU MDR Article 87.
Fixed before the audit
Had a serious incident come in, the SOP would have missed the reporting deadline. Under MDSAP, a finding like that is reported to every participating regulator, and repeat findings can cost you market access.
EU MDR Article 87 sets serious incident reporting deadlines of 2, 10 or 15 days depending on severity.
Human in the loop
Proposals, not silent edits.
Pathstone drafts. Your team decides. Every decision is on the record.
1 · Pathstone proposes
SOP-014 §5 Change evaluation
5.2 For each change, the developer shall document the affected software items
Inserted: and assess its effect on existing risk control measures, recording the result in the risk file.
Removed: Risk impact is reviewed at the next design review.
Proposed by Pathstone · nothing changed yet
Time
Weeks of document work, down to a review
One change ripples through SOPs, risk files and the technical file. Pathstone finds every affected document and drafts the update, so your team reviews instead of rewrites.
- 2–3 weeks
- for one QA team to update their QMS after a single staff change
- 3–4 weeks
- to answer one round of notified body questions
2 · Every line has a source
Why this change
- PR #122 Model v2.4 retrainPull request
- VR-031 Validation reportReport
- Test set v3 dataset cardDataset
- IEC 62304 §7.4.2Clause
- ISO 14971 §7.2Clause
Money
Consultant days for judgement, not clause-checking
Small RA/QA teams pay consultants to map procedures to standards and prep submissions. Pathstone does that repetitive conformity work, without a full eQMS price tag.
- $125–450/hr
- typical regulatory consultant rates, often with multi-day minimums
- £25–30k/yr
- eQMS quotes that small device makers turn down
3 · Your team decides
Review
Head of Quality
Reviewer
Approved by the Head of Quality.
Saved as SOP-014 v4.2
v4.1 kept · decision logged 14:02
Risk
Find the gap before the auditor does
Auditors go straight to open NCs and procedures that don't match the standard. Pathstone checks continuously and keeps every decision on an audit-ready trail.
- 130
- open NCRs one quality lead inherited, with none closed to show the auditor
- 5 days
- for MDSAP auditors to notify every regulator of a grade 5 finding
Team figures from conversations with UK device makers. Consultant rates: Qualio and Kolabtree industry surveys. MDSAP: Post-Audit Activities and Timeline Policy.
What Pathstone takes off your plate
Compliance isn't an audit. It's every week.
Each code change, dataset and threshold tweak can quietly put your file out of date. Here's the work that eats your week, and what Pathstone does instead.
Manual drafting
Documents written from scratch or generic templates, translating engineering into regulatory language by hand.
Cost: Weeks of writing per artefact
What Pathstone does: Drafts the update for you
Proposes the redline in regulatory language, with the ticket, test or clause behind every line.
Silent invalidation
A retrain, new dataset or label change makes requirements, risk controls or claims wrong, and nobody notices.
Cost: The file drifts away from the product
What Pathstone does: Watches every change
A merged PR, new dataset or label change triggers an impact check across the file, rated by severity.
Cross-checking by reading
Consistency between risk file, requirements, tests, labeling and clinical evidence depends on someone reading it all.
Cost: Gaps surface late, at review or audit
What Pathstone does: Traces it end to end
Links each requirement to its risks, tests and labeling, so one change shows everything it touches.
Know-how lives in heads
What to do next, in which order, against which clause, is often unclear to a small team.
Cost: Rework, detours and consultant dependency
What Pathstone does: Checks SOPs against the clause
Reviews your procedures against the standards you're certified to, and flags the ones that fall short.
Who it's for
Built for the small team that owns compliance
At most SaMD companies, two or three people carry the whole QMS, the technical file and the next audit. Pathstone is built for them.
Head of Quality / QA lead
You own the QMS, the NC and CAPA log, and the next audit.
Use Pathstone to
- Check SOPs against your standards before an auditor does
- Close NCs and CAPAs with the evidence already linked
- Walk into surveillance and MDSAP audits without the scramble
Regulatory affairs lead
You own the technical file, the submissions and the questions that come back.
Use Pathstone to
- Keep technical documentation in step with every release
- Answer notified body and FDA questions with sources attached
- Assess each change against significant-change criteria
CTO / engineering lead
You ship the product. The file has to keep up without slowing you down.
Use Pathstone to
- See the regulatory impact of a PR before it merges
- Keep requirement, risk and test traceability out of spreadsheets
- Stop losing weeks to documentation catch-up before release
A good fit if you
- Build SaMD or AI-enabled medical device software
- Have a QA/RA team of one to five people
- Ship software changes monthly or faster
- Submit to FDA, EU MDR or both, including via MDSAP
- Run your QMS in an eQMS, SharePoint or Google Drive
Frequently asked questions
Does Pathstone replace our eQMS or our consultant?
No. Pathstone produces the content your eQMS stores and your consultant reviews, and works alongside both.
Is this only for audit prep?
No. Most regulatory work happens between audits: change control, risk updates, SOP reviews. Pathstone works on that day-to-day flow so audit prep stops being a scramble.
Who is accountable for what Pathstone produces?
The manufacturer, as today. Pathstone doesn't replace the PRRC, the Notified Body or clinical judgment, and every approval is recorded in the audit trail.
What if a draft is wrong?
Reject or edit it. Each proposal links to the ticket, test, dataset or clause behind it, so you can check the reasoning before anything changes.
Let's look at your regulatory workload together.
Tell us about your device and where you are in the journey. We'll show you where Pathstone saves your team time, consultant spend and audit risk.
Book a demo
