Regulatory
x Min.
Medical Device Standards: 5 Misconceptions That Make Standards Lists Hard to Defend

Tibor Zechmeister

Marie Salin
Medical device standards look harmless enough:
A few numbers. A few edition dates. ISO here, EN ISO there, perhaps a DIN EN ISO copy that has been passed down like a family heirloom nobody quite remembers buying.
Then the list starts being used and maintained.
Someone asks whether the ISO version is enough. Someone else notices that the harmonized EN version has a different date. The standards list says one thing, the purchased document says another, and a regulatory reference points to an older edition that still seems oddly relevant.
Congratulations: your “simple list” has become a small archaeological site!
This is exactly where many standards discussions take the wrong turn. Teams often jump straight to the biggest question:
Do we have all the right standards?
Important? Absolutely.
But it is not always the best first question.
Before asking whether your standards list is complete, first ask whether it is consistent.
Completeness requires deeper regulatory and technical context: your device, intended purpose, markets, technologies, claims, classification, testing strategy, and regulatory pathways.
Consistency can often be checked earlier. Are the entries understandable? Are versions used deliberately? Are ISO, EN ISO, and national adoptions mixed for a reason? Are amendments, corrigenda, and withdrawn editions visible? Can someone explain why a document is included, excluded, replaced, or still monitored?
A standards list doesn’t become audit-ready by collecting rows.
It becomes defensible when the logic behind those rows is clear.
This article kicks off our series on medical device standards: which standards to monitor, which versions to use, how to handle ISO, EN ISO, and national variants, what to do with amendments and consolidated versions, and how to keep your standards list ready for monitoring, audits, and internal decision-making.
The overview below shows the structure of the series:

Let’s start with the misconceptions that make standards lists harder to defend than they need to be.
Misconception #1: “If standards are voluntary, they are optional in practice.”
Most standards are voluntary. That sentence is true, important, and wildly easy to misuse:
Regulations define the legal obligations; standards usually provide accepted technical routes for meeting them. In medical devices, that distinction matters because manufacturers remain responsible for demonstrating conformity, safety, performance, and the state of the art. Standards can be an important input into that assessment: they may show which methods, processes, tests, or technical expectations are broadly accepted at a given point in time. But a standard does not replace the regulatory analysis behind it. Manufacturers still need to understand why a standard is relevant, whether the selected version is appropriate, and how it relates to their product, market, and documentation.
The tricky part is the word “voluntary”.
In theory, a manufacturer may choose another route. In practice, that route needs to be well justified, properly documented, and convincing to the people reviewing it. Auditors, notified bodies, regulators, test labs, suppliers, and customers may all use standards as common reference points.
That is why standards often become the shared language of compliance. Quality management, risk management, usability, software lifecycle processes, electrical safety, biological evaluation, sterilization, labeling, cybersecurity, and AI are only a few examples. The point is simple: standards help turn broad expectations into recognizable evidence.
So while standards are generally not laws, treating them like decorative PDFs tends to age badly.
Misconception #2: “The regulation tells us exactly what to do.”
Regulations are excellent at defining outcomes. Writing your project plan, however, is not exactly their favorite hobby.
A regulation may require that a device is safe, performs as intended, is appropriately risk-managed, is developed under suitable processes, and includes adequate information for users. These obligations need to apply across thousands of devices, technologies, clinical contexts, and risk profiles. Naturally, they stay broad.
Standards can make those expectations more workable:
They may define processes, test methods, terminology, documentation expectations, acceptance criteria, or ways to evaluate evidence. They give quality, regulatory, engineering, clinical, verification, and validation teams something more concrete to assign, perform, review, and document.
“Meet the regulatory requirements” may look impressive in a meeting, but as an actual work package, it’s less helpful. Standards can bridge that gap: they give teams structure, create a common technical baseline, and make it easier to explain why a certain method, test, process, or documentation approach was chosen.
Of course, applying a standard still requires judgment. Scope, applicability, edition, deviations, exclusions, market relevance, and links to technical documentation all need to be understood. A standard may provide the route, but the manufacturer still needs to know why that route makes sense for this product, this market, and this regulatory strategy.
Misconception #3: “If it is harmonized, we are covered.”
Harmonized standards are powerful, especially in the EU. But “harmonized” is not a blanket answer. Not every EU-harmonized standard automatically supports presumption of conformity under the MDR or IVDR. To support presumption of conformity, a standard needs to be harmonized in the relevant MDR/IVDR context, and only for the requirements, or parts of requirements, that fall within its scope.
In other words, the question is not only whether a standard is harmonized. The question is what it is harmonized for, which requirements it covers, and where its scope ends.
This is where standards lists often get messy:
A company may list a harmonized standard without documenting what it is used for; and another may rely on a newer ISO edition while the harmonized EN version referenced in the EU context is different. A third may keep an older harmonized edition because of a transition situation, but the rationale lives somewhere between “everyone knows” and “please don’t ask.”
And, inconveniently enough, auditors tend to ask.
The actual question is rarely just whether a standard appears in the list. The interesting part is the reasoning behind it:
Why this version?
Why this source?
Why this market?
Why this scope?
Why is the newer edition monitored but not yet implemented?
Why is the harmonized version used for one compliance claim while another edition is monitored for state of the art assessment?
All fair points. A good standards list reduces the number of raised eyebrows before the audit even begins.
Misconception #4: “The newest ISO version is always the right version.”
The latest international edition often deserves extra attention.
It may reflect updated technical thinking, sharper terminology, improved test methods, or a stronger expression of state of the art.
The catch? A newer publication date does not automatically make it the right version for every regulatory purpose.
This is one of the classic standards-management headaches: technical currency and regulatory recognition do not always move at the same speed.
A newer edition may be technically relevant, while an official harmonized or recognized list still refers to an older edition. A market authority, test lab, certification body, or submission pathway may expect a specific version. Meanwhile, your product team may already need to understand the newer edition because it signals where technical expectations are heading.
In other words, version decisions are rarely solved by picking the shiniest date.
The right edition depends on factors such as:
target market
regulatory framework
harmonization or recognition status
transition periods
device type and technology
claims made in technical documentation
test reports and certificates already generated
change impact on design, risk management, verification, validation, labeling, or clinical evidence
A standards list that only records document titles leaves too much interpretive work for later. Version logic needs to be visible: why this edition is used, why another is monitored, why an older one remains relevant, and what would trigger a change.
A useful rule of thumb:
“Latest” is a signal. “Applicable and justified” is the goal.
Misconception #5: “More standards means better compliance.”
A long standards list can feel reassuring. It looks diligent, serious, thorough. But it can also hide confusion with impressive efficiency.
More entries may simply mean that old references were never removed, market-specific standards were copied from a previous submission, national versions were mixed without explanation, amendments were added as separate items, withdrawn editions stayed active, and nobody wanted to delete anything because deletion feels risky.
This is how a standards list slowly turns into a legacy cemetery. One old US submission here, one inherited hardware reference there, a few national adoptions nobody wants to delete, an amendment without the base standard, and suddenly the list has lore.
None of this is unusual. But it’s also not harmless.
When the logic is unclear, the list starts behaving like a project of its own. Active monitoring becomes harder. Audit preparation gets heavier. Impact assessments take longer than they should. And instead of using the standards list as a working document, teams spend their time asking what the list is even trying to say.
A shorter, well-reasoned standards list often carries more weight than a large collection of inherited references. Compliance is easier to defend when every entry has a job, not a mysterious backstory.
Which brings us neatly to …
… the two questions manufacturers should stop mixing
When teams ask, “Is our standards list correct?”, they are often asking two different questions at once.
1. Is our standards list complete?
This is the deeper regulatory and technical question. And, annoyingly enough, it refuses to be answered in a vacuum.
Completeness depends on the product: its intended purpose, technology, user groups, patient population, claims, classification, and risk profile. It also depends on where the device will be marketed and which regulatory pathways, submissions, and testing strategies apply.
Is there software? AI? Electrical hardware? Biological contact? Sterility? Reusable components? Cybersecurity exposure? Clinical performance evaluation? Specific labeling complexity?
All of that changes the standards landscape. A completeness review only makes sense once the product and markets are clear. Without that context, you are basically guessing with formatting.
2. Is our standards list consistent and logically structured?
This question can often be checked much earlier:
Are the listed versions clear? Are ISO, EN ISO, and national adoptions used consistently? Are harmonized or recognized statuses documented where relevant? Are amendments and corrigenda handled in a readable way? Are obsolete standards marked as replaced, withdrawn, historical, or still justified? Are there strange duplicates? Is each standard linked to a product, process, jurisdiction, or rationale?
This kind of check will not tell you whether your standards list is complete. But it can reveal the inconsistencies that make audits, internal reviews, CAPA discussions, and standards monitoring more difficult than they need to be.
At Flinn, we often see that the first challenge is not the number of standards in a list, but the logic behind them. No tool should pretend to decide every applicable standard for every medical device. That would be a bold claim, and not the charming kind. But a structured system can help teams spot inconsistencies earlier: unclear editions, mixed sources, duplicate entries, outdated references, suspicious jurisdictional mismatches, or standards that seem to have wandered into the list without a clear reason.
That matters because a standards list has to survive real life: people need to search it, update it, explain it, audit it, hand it over, and occasionally defend it under fluorescent lighting.
The more logical the list, the less dramatic the room.
A better sequence: check consistency, then assess completeness
The most practical sequence is not to ignore completeness. It is to make the list understandable before assessing whether anything is missing.
First, check whether the existing list is consistent and logically structured. Then assess completeness based on the product, intended purpose, technology, markets, and regulatory pathways.
A consistent standards list makes the next steps easier across the organization. Regulatory and QARA teams can explain version choices without playing detective, quality teams get a cleaner monitoring process, technical teams can see which documents actually matter, and auditors can follow the trail without needing a treasure map.
Teams can then focus on the real questions. Which standards apply? Which versions are justified? And what impact may a change have on the device documentation?
Consistency alone won’t perform regulatory miracles, of course. A beautifully structured list can still miss an important product-specific standard. But when the list is chaotic, it becomes much harder to tell what kind of problem you actually have: completeness, version control, market strategy, document ownership, or just messy naming conventions.
So before expanding the list, make sure the current one is not already quietly plotting against you.
What we’ll untangle next in medical device standards
Over the following articles, we’ll get into the practical questions that tend to turn standards lists from “controlled document” into “why is this still here?”:
Which standards should you monitor, and how do product, intended use, technology, and target market shape that decision?
How should manufacturers handle ISO, EN ISO, DIN EN ISO, ÖNORM, BS, AFNOR, EVS, and other national versions?
What should you buy and reference when a standard exists as a base document, amendment, corrigendum, consolidated version, or redline?
How can a standards list stay audit-ready through monitoring, state of the art review, impact assessment, and documented justification?
How do AAMI, ASTM, ANSI, UL, CLSI, IEEE, and other non-ISO/EN standards fit into a global medical device evidence strategy?
Nobody needs the fantasy that standards are secretly simple. They are standards, after all: acronyms, amendments, national prefixes, transition periods, and an uncanny talent for multiplying at exactly the wrong moment.
The mission is much more useful: make the decision logic clearer.
In audits, monitoring, CAPA discussions, and regulatory work, a strong standards list earns trust through its reasoning. Each row has a job, a rationale, and ideally no mysterious backstory.
So, here’s the takeaway before the standards list quietly grows another appendix:
Before asking whether your standards list is complete, first ask whether it is consistent.
Curious whether your own standards list would hold up?
Flinn flags inconsistent versions, mixed sources, and duplicate entries automatically.
Contact us to find out more.














