Every device manufacturer selling into the EU has, by now, named a person responsible for regulatory compliance under MDR Article 15. Most of those appointments will survive a documentation check: the qualification file is in order, the org chart shows a name in the role. Fewer of them will survive the harder question a notified body auditor or a national competent authority is entitled to ask — can this person actually stop a device from shipping, and did anyone ever test that they could?
Two ways to qualify, one way to fail
Article 15 gives manufacturers two main routes to a qualified PRRC. The first pairs a formal qualification — a diploma or degree in law, medicine, pharmacy, engineering, or another relevant scientific discipline — with at least one year of professional experience in regulatory affairs or quality management systems relating to medical devices. The second drops the formal-qualification requirement entirely in favor of at least four years of relevant professional experience, which is the pathway that lets experienced device-industry professionals without a specific degree still fill the role. Manufacturers of custom-made devices have a further, experience-based alternative of their own. None of this is where compliance programs actually fail. Companies that have been through a EU MDR & IVDR compliance build already know how to run this qualification check and document it.
The duties a title alone cannot discharge
The PRRC's job under Article 15 is not advisory. It includes ensuring the conformity of devices is properly checked before release, that technical documentation and the EU Declaration of Conformity are drawn up and kept current, that post-market surveillance obligations are actually complied with, that vigilance and serious-incident reporting obligations are met, and — for investigational devices — that the required Annex XV statement is issued. Every one of those is a point where the PRRC has to be able to act: hold a release, require a technical file correction, escalate a vigilance signal. A PRRC who reports three levels down from the decision-maker who actually controls shipping dates cannot discharge that duty no matter how the qualification file reads.
- Sign-off, not sign-along. The PRRC needs genuine authority to hold a device release, not a courtesy notification after the decision is already made.
- A reporting line that reaches the top. Article 15's duties touch conformity, technical documentation, PMS, and vigilance — functions that span the organization, which the role cannot oversee from a subordinate seat inside one department.
- Documented capability, not just credentials. Regulators expect evidence the manufacturer confirmed the individual can actually perform the role's duties — not only that their résumé clears the Article 15 bar.
- A genuinely resourced “at their disposal” arrangement. For micro and small enterprises using a contracted PRRC, disposal has to mean real, continuous access — not an annual check-in structured to satisfy an audit question.
Article 15 protects a PRRC from being penalized for doing the job properly. That protection is meaningless for a PRRC who was never given enough authority to do anything a manufacturer might want to penalize. Why authority has to precede the non-disadvantage protection
Where this shows up under audit
A notified body or competent authority reviewing PRRC arrangements is not primarily testing the qualification file — that is the easy part to get right. It is testing whether the role functioned: whether a release was ever held, whether a technical documentation gap the PRRC flagged actually got fixed, whether vigilance reporting ran through a person with the standing to insist on it. Building that evidence trail is quality management system work as much as it is a hiring decision — the PRRC's authority has to be written into procedures, escalation paths, and sign-off gates the same way any other quality-critical role's authority would be. Manufacturers that treat the appointment as satisfied once the qualification file is complete are the ones who discover, mid-audit, that the role exists on the org chart and nowhere else.
- Confirm the qualification pathway and document the evidence. Degree-plus-experience or experience-only — keep the file, but do not stop there.
- Write the authority into procedures. Sign-off gates, escalation paths, and release-hold power belong in the QMS, not just the job description.
- Test it before an inspector does. Confirm the PRRC has actually exercised release-hold or escalation authority at least once, on the record.
- For micro/small enterprises, resource the “at their disposal” arrangement for real. Continuous, genuine access — not an annual box-check with a contracted consultant.
None of this requires reinventing the role. It requires treating Article 15 as an organizational-design question as much as a hiring one: confirm the qualification, then build the authority the duties actually demand, and prove — before an inspection asks — that the person in the role can act on what they are legally responsible for. As part of a broader European regulatory strategy, that is a bounded piece of work. Skipped, it is the gap between a compliant hire and a compliant role.
Frequently asked questions
What qualifies someone to be a PRRC under EU MDR Article 15?
Article 15 sets two main pathways: a diploma, certificate, or other formal qualification in law, medicine, pharmacy, engineering, or another relevant scientific discipline plus at least one year of professional experience in regulatory affairs or quality management systems relating to medical devices; or, without the formal qualification, at least four years of professional experience in regulatory affairs or quality management systems relating to medical devices. Manufacturers of custom-made devices have a separate experience-based pathway.
Do micro and small enterprises need an in-house PRRC?
No. Micro and small enterprises, as defined by Commission Recommendation 2003/361/EC, are not required to employ the PRRC within their own organization, but they must have a qualified person permanently and continuously at their disposal — commonly satisfied through a consultant or contracted regulatory lead who genuinely has the standing to perform the role's duties, not merely a name on file.
What protection does the PRRC have against being penalized for their duties?
Article 15 provides that the PRRC must not suffer any disadvantage within the manufacturer's organization for properly carrying out their duties, regardless of whether they are an employee. That protection only means something if the role also carries the authority to act on those duties in the first place.
Sources & further reading
- EUR-Lex. Regulation (EU) 2017/745 (MDR), consolidated text — Article 15. eur-lex.europa.eu
- European Commission, MDCG. MDCG 2019-7 Rev.1: Guidance on Article 15 of Regulation (EU) 2017/745 and Article 15 of Regulation (EU) 2017/746 on a ‘person responsible for regulatory compliance’ (PRRC). health.ec.europa.eu
This article is provided for general informational purposes and reflects the regulatory landscape as of August 2026. It is not legal or regulatory advice. Confirm current Article 15 subparagraph citations and MDCG guidance with EUR-Lex, the European Commission, or qualified counsel before acting.