Use-related risk: reading FDA and MDR expectations the same way
- micoccimassimo
- 1 day ago
- 5 min read
Medical device manufacturers developing for both the US and European markets often treat FDA and MDR usability requirements as two separate compliance tracks — one human factors program for the FDA submission, another usability engineering effort for the Technical Documentation under MDR. This separation is rarely necessary, and it's expensive. Read carefully, the two frameworks converge far more than they diverge. The organizations that recognize this early build one usability engineering program that satisfies both, rather than duplicating effort across parallel workstreams.
A Shared Foundation: IEC 62366-1
Both regulatory systems anchor their expectations in the same international standard: IEC 62366-1, Application of usability engineering to medical devices. FDA references it directly and layers its own guidance on top (notably the 2016 Human Factors and Usability Engineering guidance document); the EU MDR expects conformity with harmonized standards, of which IEC 62366-1 is the recognized benchmark for usability engineering.
This shared foundation means the core process — user needs analysis, use specification, task analysis, use-related risk analysis, formative evaluation, and summative validation of critical tasks — is not something you build twice. A use-related risk analysis performed against IEC 62366-1 principles produces the same critical task list, the same use error taxonomy, and largely the same rationale for included and excluded risks, regardless of which market it's ultimately packaged for.
Where the two diverge is not in what is expected methodologically, but in how much documentation, justification, and post-market follow-through each regulator wants to see, and in the regulatory posture each takes toward residual risk.
Where FDA and MDR Genuinely Differ
Depth of the Human Factors submission. FDA's expectations for a Human Factors Engineering (HFE) report are prescriptive: a defined structure, explicit critical task identification, root-cause analysis for every use error observed in summative testing, and a clear justification for why no critical task was left unmitigated. Notified Bodies reviewing MDR technical documentation expect the same underlying evidence but are often more flexible about report structure, folding usability evidence into the broader risk management file governed by ISO 14971 rather than requiring a standalone HFE report.
Risk tolerance framing. FDA guidance is explicit that use errors during summative testing are expected to be investigated and, wherever possible, mitigated through design — not explained away through labeling or training alone. MDR's General Safety and Performance Requirements (Annex I) push in the same direction but frame it through the risk management hierarchy: eliminate or reduce risk through design first, protective measures second, information for safety last. The philosophy is nearly identical; the language and level of prescriptiveness differ.
Post-market obligations. This is where the paths diverge most meaningfully. MDR requires an active Post-Market Surveillance (PMS) system, and for many devices, a Post-Market Clinical Follow-up (PMCF) plan that must proactively confirm continued safety and performance — including usability — in the real world. FDA's post-market expectations are comparatively less continuous, more complaint- and adverse-event-driven, though FDA increasingly expects real-world data to inform design changes and labeling updates. A manufacturer building only for the FDA pathway can under-invest in structured real-world evidence generation and still pass; a manufacturer building for MDR cannot.
The Common Path: One Usability Engineering File, Two Submissions
Given this overlap, the efficient approach is to design a single usability engineering file structured to IEC 62366-1, front-loaded with enough rigor to satisfy FDA's more prescriptive documentation expectations, and enough continuity planning to satisfy MDR's post-market obligations. In practice, this means:
1. Define critical tasks once, early, and defend them with evidence. The use-related risk analysis and critical task list should be established during formative work and revisited iteratively — not reconstructed separately for each regulatory submission. Both FDA and Notified Bodies will scrutinize why a task was or wasn't classified as critical; having one well-documented rationale, traceable across every design iteration, is stronger evidence than two independently justified lists.
2. Let formative testing carry the weight it should. As covered in our previous piece on formative usability testing, the summative study is only as strong as the formative work behind it. This matters doubly in a dual-market program, because a summative protocol built to satisfy FDA's HFE guidance — representative users, simulated use environments, root-cause analysis of every use error — will, with minor adaptation, generally satisfy MDR expectations as well. Building the protocol to the higher bar (FDA's) from the outset avoids running two separate summative studies.
3. Treat real-world evidence as shared infrastructure, not a market-specific afterthought. Field studies, contextual inquiries, and post-market usability data don't need to be siloed by regulatory audience. A structured PMCF/PMS program designed to capture real-world use errors, near-misses, and environmental variables serves MDR's continuous surveillance requirement directly — and the same data strengthens FDA submissions for related products, labeling changes, or post-market design updates. Real-world evidence generated for one purpose is rarely wasted if it's designed with reusability in mind from the start.
4. Align risk management and usability documentation under one file structure. ISO 14971 governs risk management for both markets; IEC 62366-1 governs usability engineering for both markets. Structuring your Design History File and Technical Documentation so these two standards visibly cross-reference each other — rather than living in separate binders — reduces review friction with both FDA reviewers and Notified Body auditors, who are, after all, looking for the same underlying evidence of use-related risk control.
Optimizing Resources Without Cutting Corners
None of this is about doing less work — it's about not doing the same work twice. A few practical levers consistently pay off:
Sequence formative studies to answer both audiences' open questions simultaneously. If a design uncertainty could plausibly draw scrutiny from either FDA or a Notified Body, resolve it in the same formative round rather than waiting for market-specific feedback.
Recruit summative study populations broadly enough to represent both regions' intended user populations, rather than running separate studies with region-specific inclusion criteria when the underlying user profile doesn't actually differ.
Build the real-world evidence pipeline before you need it. Manufacturers that only start thinking about PMCF once the CE mark is imminent tend to scramble; those that design light-touch field data collection into early launches generate evidence that satisfies MDR's continuous surveillance requirement and gives FDA-facing teams a head start on any future submission involving the same platform.
Keep one integrated risk file. Duplicated risk analyses inevitably drift apart over successive design changes, creating exactly the kind of inconsistency that draws regulatory questions. One file, updated once per design iteration, is both cheaper to maintain and more defensible.
The Takeaway
FDA and MDR usability expectations are not two different philosophies wearing different names — they're the same underlying discipline of use-related risk management, expressed with different emphasis on documentation structure and post-market continuity. Manufacturers who read them as fundamentally aligned, rather than fundamentally different, can build a single usability engineering program — grounded in rigorous formative work, a defensible critical task list, and a real-world evidence strategy designed for reuse — that clears both regulatory bars without paying for the same evidence twice.

Comments