Registry data quality · Risk-based monitoring · EU MDR Chapter VI

Medical device registry data quality and monitoring.

A registry is only as valuable as the data it holds. We define what good data look like, monitor them as they arrive, and catch the problems while there is still time to fix them, so the evidence holds up in front of a notified body, a payer or a clinical audience.

Registry data quality planRisk-based monitoringTargeted SDVInspection readiness
Medical device registry data quality and monitoring.
WHAT THIS PAGE COVERS
1
Trusted by MedTech manufacturers.
2
Registry evidence a reviewer will actually accept.
3
Every registry exists to answer questions that matter.
4
Three audiences, and three different ways to fail them.
European CRO for medical devices, aligned with Regulation (EU) 2017/745.
Expertise and recognition

A European team of former notified body reviewers

The people who build your evidence have sat on the other side of the table.

EUCROF Platinum Award 2026
EUCROF Platinum Award 2026xShare Open Call for Clinical Research, co-funded by the European Union
Jimmy Andrew HayekJimmy Andrew HayekHead of Quality and ComplianceISO 13485 certified quality system
Sebastien Meier PiantanidaSebastien Meier PiantanidaChief Data OfficerData management and EDC
Charline PetitdemangeCharline PetitdemangeProject Delivery Lead, France and United KingdomStudy start-up and close-out
Trusted by manufacturers

Leading medical device teams work with Eclevar

Terumo
Meril Life Sciences
Nihon Kohden
Vygon
Coloplast
RegenLab

A registry is only as valuable as the data it holds. We define what good data look like, monitor them as they arrive, and catch the problems while there is still time to fix them, so the evidence holds up in front of a notified body, a payer or a clinical audience.

Social proof

Trusted by MedTech manufacturers.

Leading manufacturers rely on Eclevar for registry-based PMCF and real-world evidence. Read all the client success stories.

Regulatory leadership

Registry evidence a reviewer will actually accept.

Monitoring decisions are only as good as the understanding of how the evidence will eventually be read. Our teams combine clinical operations, data management, biostatistics and regulatory expertise, including former notified body reviewers, so the quality thresholds we set are the ones that matter when the dataset is reviewed.

We run our own clinical research associates across Europe rather than subcontracting them, which is what makes site initiation, central review and triggered on-site visits work to a single standard across a multi-year registry.

Ex NBFormer TÜV SÜD reviewer
7Countries with in-house CRAs (UK, DE, FR, SE)
Chapter VIEU MDR Articles 62 to 82
Compliant withEU MDR 2017/745ISO 14155:2026GCPISO 13485GDPR
Why data quality matters

Every registry exists to answer questions that matter.

Is the device performing as expected in routine practice? Are there safety signals that only appear after several years? Do outcomes hold up across different patient populations, different centers and different surgical techniques? The answers are only as reliable as the data behind them. A medical device registry feeds post-market surveillance, post-market clinical follow-up, long-term safety and performance evaluation, health technology assessment submissions and, increasingly, reimbursement discussions.

Registries also carry risks that traditional clinical investigations do not. Many hospitals rather than a controlled set of investigational sites. Large populations, light protocols by design, and years of follow-up. Left unmanaged, those realities produce missing data, inconsistent coding, late entry and site-to-site variability that is impossible to separate from genuine clinical variation once the analysis starts. Good data quality does not remove them. It makes them visible early, keeps them within known limits, and documents them, so the analysis can account for what happened instead of guessing.

Who depends on the answers

Three audiences, and three different ways to fail them.

Each of them reads the registry for something different, and each of them fails differently when the data are weak.

Three audiences, and three different ways to fail them.
01

Regulators and notified bodies

They expect the clinical evidence in a PMCF evaluation report or a periodic safety update report to be traceable and defensible. A dataset with large gaps in follow-up, or with fields that different sites clearly interpreted in different ways, invites questions that are slow and expensive to answer.

02

Clinical teams

They use registry outputs to understand real-world performance and to shape indications, training and technique. Data that do not reflect what actually happens in the operating room, or that quietly miss the patients who never came back, will mislead them.

03

Market access and business teams

They build reimbursement dossiers and commercial claims on real-world evidence. HTA bodies are explicit about the quality of evidence they will accept, and a registry that cannot demonstrate completeness or consistency will not carry the argument.

What makes a registry different

Clinical practice differs between centers, and between countries

Data entry is often done by staff with other priorities. Patients move, change hospitals or stop attending. A registry is not a controlled investigational setting, and treating it as one is how monitoring budgets get spent on paperwork rather than on quality. The distinction, and what it changes in practice, is set out in registry versus clinical investigation.

Building quality into the registry

Quality begins long before the first participant is enrolled.

The decisions taken during registry design determine how much rework will be needed later.

01

Quality objectives, defined first

Agree what the registry has to deliver, and how good the data have to be to deliver it. That means naming the critical data the registry cannot afford to lose: the primary endpoint, device identification and UDI, the index procedure, serious adverse events, device deficiencies, and consent or the applicable legal basis. It also means naming the critical processes: enrollment, follow-up scheduling, event reporting and adjudication.

02

Monitoring thresholds, set in advance

For each critical variable, define what acceptable looks like as a number rather than an intention. A minimum completeness level. A maximum acceptable loss to follow-up at each time point. A maximum delay between visit and data entry. A query resolution target. Setting these before the registry opens means later discussions are about whether a threshold was met, not about whether the quality being seen is good enough.

03

The registry data quality plan

The document that holds it all together: critical data and processes, thresholds, the checks built into the electronic data capture and data management system, the metrics reviewed and how often, who reviews them, how issues escalate and what happens when a threshold is missed. It is a living document, versioned, and one of the first things an inspector will ask to see.

Monitoring what matters most

Monitoring everything to the same depth is the fastest way to exhaust a budget without improving the data.

01

Governance and named roles

Registries fail on ownership more often than on method. The plan names the sponsor, the steering or scientific committee, the coordinating center or CRO, the monitoring lead, the data manager, the statistician, and at each site the principal investigator and the person who actually enters the data. Where an independent adjudication committee is used, its charter and its independence belong here too.

02

Standardized processes

Consistency across sites comes from the tools, not from goodwill. A data dictionary with an unambiguous definition for every field. An eCRF with edit checks, range checks and cross-field logic that stops obvious errors at the point of entry. Written procedures, so two monitors visiting two sites apply the same standard. Training at initiation, and refresher training when staff change, which over a multi-year registry they will.

03

Risk-based, and proportionate

Oversight concentrates on the data and processes most critical to participant safety and to the reliability of the evidence. A low-risk observational registry of a well-established device does not need the monitoring intensity of a registry supporting a novel implant with a new mechanism of action. Our monitoring services are built and priced on that principle.

04

Identifying and prioritizing risks

The risk assessment carried out during design is what produces the monitoring plan. Risks are ranked on likelihood, impact and how easily they would be detected. A site that enrolls heavily but has never run a registry is a different risk from a site enrolling two patients a year. A field that requires clinical judgment carries a different risk from a date field. The ranking tells the plan where to look first.

05

Central review first, visits when triggered

Most quality problems are visible in the data before anyone visits a site: an implausibly low event rate, a variable recorded in different units, entry that stops for six weeks, values distributed too neatly to be real. On-site and remote monitoring then works best when visits are triggered by a central signal, high enrollment, staff turnover, a query backlog or a site's first participants, with a purpose defined in advance.

06

Targeted source data verification

Verifying every field against source documents is neither realistic nor useful in a large multi-year registry. Targeted SDV concentrates on the variables that carry the evidence: consent or legal basis, eligibility, device identification, the primary endpoint, serious adverse events and device deficiencies. Everything else is covered by edit checks, central review and source data review on a sample. The percentage and the selection method are stated in the plan, so the approach can be defended later.

Our methodology

A five-step data quality cycle.

Data quality is not something a registry achieves once. It is a state that has to be held for the life of the study, which for an implantable device may be ten years or more.

1

Define

Critical data, critical processes and the numerical thresholds that go with them, written into the data quality plan before the first site opens.

2

Detect

Metrics reviewed against those thresholds on a defined cadence, so problems get looked at before somebody happens to notice them.

3

Diagnose

Root cause analysis on what the metrics show, because retraining a site that was never the problem fixes nothing.

4

Correct and prevent

A correction for the data already affected, a preventive action on the system rather than on a person, each with an owner, a due date and an effectiveness check.

5

Improve

What is learned goes back into the data quality plan, the monitoring plan, the training material and the eCRF. Over several years, that loop drives more quality than any individual monitoring activity.

Continuous oversight

What gets measured, and what it tells you.

Reviewed typically monthly at operational level, quarterly with the sponsor, and at every steering committee meeting for the scientific view. One metric moving is information. Several metrics moving at the same site is a pattern, and patterns are what oversight exists for.

Completeness

Critical fields populated

Overall and site by site, against the minimum level agreed in the data quality plan.

Follow-up

Retention and visit windows

Visits completed within the protocol window, patients retained at each time point, and loss to follow-up by site and by cohort.

Timeliness

Delay to entry and to reporting

Days from visit to data entry, and days from awareness of an event to its reporting.

Consistency

Queries and edit checks

Query rates, query types, time to resolution, and edit check failure rates by site and by field.

Site performance

One picture per site

Enrollment against plan, deviation rates, outstanding queries and monitoring findings, combined so it is clear which sites need support. Trend analysis is designed with our biostatistics team.

Safety data

Reporting timelines

Reporting timelines met, and the completeness of event documentation. A site whose entry delay is growing, whose query backlog is rising and whose follow-up compliance is slipping is usually a site that has lost its study coordinator. That is fixable in month two, much less so in month nine.

Building trust through traceability

When a reviewer asks how a number was produced, the registry has to answer.

Reliable evidence depends on the data, and on the ability to show how those data came to be.

EU · EU MDR

EU MDR 2017/745

  • Post-market surveillance system under Article 83
  • Periodic safety update reports under Article 86 for higher-risk devices
  • PMCF as part of the clinical evaluation, Annex XIV Part B
  • Notified body review and competent authority reporting
MDCG · Guidance

MDCG 2020-7 and 2020-8

  • What a PMCF plan is expected to contain
  • What a PMCF evaluation report is expected to contain
  • Registry evidence held to the same expectations as the rest of the clinical evidence
  • Traceability from claim to data, and from data to source
ISO · 14155

ISO 14155 and ISO 13485

  • ISO 14155 applies directly where a registry is interventional
  • Where it is observational, its principles on monitoring, source data and documentation remain the reference reviewers use
  • ALCOA: attributable, legible, contemporaneous, original, accurate
  • Run inside a quality management system, ISO 13485
GDPR · Data protection

Personal data and retention

  • Legal basis for processing documented in the registry master file
  • Consent documentation and retention rules in the same traceable record
  • EDC audit trail showing who changed what and when
  • Database lock records and the minutes of scientific decisions
Inspection readiness

A state, not a project

Registries that start preparing when an inspection is announced prepare badly. Registries that keep their documentation current as they go can respond in days. In practice that means filing as you go, keeping the registry master file complete, closing out monitoring findings instead of letting them accumulate, and periodically running an internal check against the documentation an inspector would request. Teams that want the underlying standard in depth can follow our ISO 14155 training.

How Eclevar supports registry data quality

From one specific problem through to full registry oversight.

Shaped around what the sponsor already has in place, not around a fixed package.

01

Registry design and quality planning

Defining critical data and critical processes, setting monitoring thresholds and writing the registry data quality plan, before the first site opens.

02

Risk-based monitoring

Building the risk assessment and a proportionate monitoring plan, then running central, remote and on-site monitoring against it with our own CRA teams across Europe.

03

Data quality oversight

Standing quality metric reporting, site performance review, query management, and the escalation process that goes with them.

04

Issue management

An issue log that records what was found, how, where and with what impact, then root cause analysis, CAPA definition and effectiveness checks.

05

Traceability and inspection readiness

Documentation review, registry master file support and readiness checks ahead of notified body or authority scrutiny.

06

Registry remediation

Assessment and recovery of registries where data quality has drifted, including gap analysis and a prioritized remediation plan.

Where this sits

Part of our registry practice

This page is the data quality and monitoring layer of our medical device registry practice under the EU MDR. It applies the same way to a cardiovascular PMCF registry and to an arthroplasty PMCF registry in the DACH region, and it sits inside the wider medical device CRO offer.

Official content

Our content, signed by Eclevar.

Whitepapers, client voices and publications produced by our teams and our partners (BSI, TÜV SÜD, RegenLab).

FAQ

Registry data quality questions sponsors ask us.

It is the document that describes the registry's critical data and critical processes, the numerical thresholds attached to each of them, the checks built into the EDC system, the metrics that will be reviewed and how often, who reviews them, how issues escalate and what happens when a threshold is missed. It is versioned and kept current. Auditors and inspectors ask for it early, and so do notified bodies when the registry supports a PMCF evaluation report.

No, and in a large multi-year registry it is neither realistic nor useful. Targeted source data verification concentrates on the variables that carry the evidence: consent or the applicable legal basis, eligibility, device identification, the primary endpoint, serious adverse events and device deficiencies. Everything else is covered by edit checks, central review and source data review on a sample. What matters is that the percentage and the selection method are written into the monitoring plan in advance, so the approach can be defended later.

A common cadence is monthly at operational level, quarterly with the sponsor, and at every steering committee meeting for the scientific view. The exact frequency belongs in the data quality plan. The point of having a cadence at all is that problems get looked at on a schedule rather than when somebody happens to notice them.

It should. A monitoring plan written at registry start is a hypothesis about where the risks are, and twelve months of data will show which parts of it were right. The plan is reviewed on a defined cadence and after significant events such as a protocol amendment, a new country joining, a change of EDC system or a safety signal, and intensity moves toward the sites and variables where the evidence says it belongs.

Usually, yes, and the earlier the assessment the less it costs. We run a gap analysis against what the evidence has to support, quantify what is recoverable and what is not, and produce a prioritized remediation plan covering data cleaning, targeted re-monitoring, documentation reconstruction and the process changes that stop the drift recurring. Talk to our registry team about where your registry stands.

FAQ

Questions sponsors ask first

What is a registry data quality plan, and who asks for it?

It is the document that describes the registry's critical data and critical processes, the numerical thresholds attached to each of them, the checks built into the EDC system, the metrics that will be reviewed and how often, who reviews them, how issues escalate and what happens when a threshold is missed. It is versioned and kept current. Auditors and inspectors ask for it early, and so do notified bodies when the registry supports a PMCF evaluation report.

Do we have to verify every field against source documents?

No, and in a large multi-year registry it is neither realistic nor useful. Targeted source data verification concentrates on the variables that carry the evidence: consent or the applicable legal basis, eligibility, device identification, the primary endpoint, serious adverse events and device deficiencies. Everything else is covered by edit checks, central review and source data review on a sample. What matters is that the percentage and the selection method are written into the monitoring plan in advance, so the approach can be defended later.

How often should registry quality metrics be reviewed?

A common cadence is monthly at operational level, quarterly with the sponsor, and at every steering committee meeting for the scientific view. The exact frequency belongs in the data quality plan. The point of having a cadence at all is that problems get looked at on a schedule rather than when somebody happens to notice them.

Can monitoring intensity change once the registry has started?

It should. A monitoring plan written at registry start is a hypothesis about where the risks are, and twelve months of data will show which parts of it were right. The plan is reviewed on a defined cadence and after significant events such as a protocol amendment, a new country joining, a change of EDC system or a safety signal, and intensity moves toward the sites and variables where the evidence says it belongs.

Our registry data quality has already drifted. Is that recoverable?

Usually, yes, and the earlier the assessment the less it costs. We run a gap analysis against what the evidence has to support, quantify what is recoverable and what is not, and produce a prioritized remediation plan covering data cleaning, targeted re-monitoring, documentation reconstruction and the process changes that stop the drift recurring. Talk to our registry team about where your registry stands.

Official content

Our content, signed Eclevar.

Whitepapers and publications produced by our teams with our notified body partners.

Whitepaper by BSI and Eclevar on the EU MDR
Whitepaper · BSI × Eclevar

A BSI and Eclevar whitepaper on the EU MDR.

Written with Notified Body BSI: a practical reading of the clinical evidence expectations under EU MDR 2017/745, the same evidence your file has to support.

Start the conversation

Tell us where your evidence stands today

Send us the device, the claim and the deadline. You get a written answer within 24 hours.

Your documents are reviewed confidentially. An NDA can be signed before we receive any technical or clinical information.

Reforming Clinical Evaluation of Medical Devices in Europe