Deliverable 01
Findings Register
A findings register, with each finding rated for defensibility risk and remediation effort, grounded in specific documents, protocols, and records rather than general impressions.
Quiet Vector conducts outside review of design history file quality, traceability, and regulatory defensibility — before a submission, an inspection, a design transfer, or a decision that is difficult to reverse.
Request a consultationDesign evidence is usually complete in volume and weak in linkage. Requirements exist. Hazards exist. Test results exist. What is often missing is the connective argument that a reviewer follows: this intended use produced these requirements, which were allocated to this architecture, which created these hazards, which are controlled by these measures, whose effectiveness is demonstrated by this evidence.
A review is most useful when that argument has not been read end to end by anyone outside the program.
Review scope
A structured, evidence-oriented checklist used to assess design assurance readiness and technical quality.
Design control architecture — user needs, design inputs, outputs, verification and validation structure; DHF organization and index integrity.
Requirements quality and decomposition — testability, ambiguity, and allocation across system, software, and hardware.
Traceability integrity — bidirectional linkage across requirements, hazards, risk controls, verification, validation, and labeling.
Risk file coherence (ISO 14971) — hazard analysis, sequences of events, demonstrated risk control effectiveness, benefit-risk reasoning, and production and post-production feedback.
Verification and validation evidence strength — protocol rigor, acceptance criteria, anomaly and deviation disposition, sample rationale, and regression scope.
Software life cycle conformance (IEC 62304) — safety classification rationale, SOUP and off-the-shelf software handling, integration strategy, configuration and change control, and problem resolution.
Design transfer and change history — essential design outputs, design change records, DHF and DMR boundaries, and readiness for external review.
Defined work products provided at the end of the engagement.
Deliverable 01
A findings register, with each finding rated for defensibility risk and remediation effort, grounded in specific documents, protocols, and records rather than general impressions.
Deliverable 02
A written independent assessment stating where the evidence holds, where it does not, and what a reviewer is most likely to challenge first.
Deliverable 03
A remediation sequence, ordered by regulatory exposure rather than by the order in which gaps were found.
Deliverable 04
A debrief with the program and quality leads. All work is governed by a standard NDA. The assessment is delivered only to the hiring party.
The review is performed by one engineer. The findings are a single judgment, not a committee position.
Some engagements are narrower and harder than a review: a design decision with regulatory consequence that the internal team cannot resolve, a failure that has not been explained, an evidence argument that has already been challenged, or a position that has to be defended in writing. That work is taken on directly, under the same terms.
Standards
ISO 13485 · ISO 14971 · IEC 62304 · IEC 62366 · IEC 60601 · IEC 82304 · IEC 81001-5-1 · ANSI/AAMI SW96:2023 · FDA 21 CFR Part 820 / QMSR · EU MDR
Domain depth
Active implantables · Defibrillators · Neurostimulators · Implantable drug pumps · Programmers · Monitoring and patient data systems · SaMD · Combination products
Intake
A short intake call clarifies scope. I tell you honestly whether I can help — and if I cannot, I say so.
— Wayne Larson, Principal Engineer, Quiet Vector LLC
Concise details help prioritize response and scope.