← Back to Insights

SaMD Production Controls and the Real Cost of Post-Market Failures

Sherif Elkhadem
29 May 2026
6 min read
SaMD Production Controls and the Real Cost of Post-Market Failures

Two stories caught my attention this week, and together they illustrate a tension that every medical device manufacturer faces: the challenge of maintaining rigorous production controls in an evolving regulatory landscape, and the very real consequences when those controls fail. On one hand, we're seeing renewed scrutiny around whether ISO 13485's production and service provision requirements genuinely apply to Software as a Medical Device (SaMD)—a question that reflects the sector's struggle to apply hardware-era frameworks to agile, cloud-native products. On the other, Insulet has just recalled 7 million patch insulin pumps due to tubing tears that have caused 24 serious adverse events. It's their second recall this year for the same root cause. These aren't unrelated events. They're symptoms of the same underlying challenge: how do you scale quality management systems to match the pace and complexity of modern medical devices?

Do Production Controls Really Apply to SaMD?

The short answer is yes—emphatically. But the confusion is understandable. ISO 13485:2016, Clause 7.5 on production and service provision, was written in an era when 'production' meant manufacturing physical components, running validated production lines, and maintaining environmental controls in cleanrooms. Software doesn't fit neatly into that mental model. There's no assembly line. Updates deploy to thousands of users simultaneously. Changes happen iteratively, sometimes weekly. And for many SaMD products, the notion of 'finished goods' becomes blurred when your platform is continuously evolving in the cloud.

But here's what the regulatory community has been increasingly clear about: production controls aren't about the medium—they're about reproducibility, traceability, and validation of the processes that create your medical device. For SaMD, 'production' includes software builds, version control, deployment pipelines, configuration management, and release processes. It means your build environment must be controlled and documented. It means you need validated processes for creating each software version, with traceability from requirements through to released code. It means your deployment process—whether that's an app store update or a cloud service push—must be validated and controlled just like a sterilization cycle or an injection moulding run.

The regulatory logic is straightforward: if your software is making diagnostic decisions, delivering therapy, or controlling life-supporting functions, the processes that produce that software must be subject to the same discipline as any other critical manufacturing process. EU MDR Annex I requires general safety and performance throughout the device lifecycle. ISO 13485 Clause 7.5 operationalises that requirement. The fact that your 'production line' is a CI/CD pipeline doesn't exempt you—it simply changes what controls look like in practice. Version pinning, automated testing, code signing, environment validation, change control for production environments—these are your production controls. Treat them accordingly.

When Production Controls Fail: The Insulet Case Study

Which brings us to Insulet. The company is recalling 7 million Omnipod and Omnipod DASH insulin patch pumps because tears in the device tubing can cause insulin leakage, leading to under-delivery of insulin. For people with diabetes, that's not a minor inconvenience—it's a potentially life-threatening failure that can result in hyperglycemia and diabetic ketoacidosis. Twenty-four serious adverse events have been reported. And critically, this is the second recall this year for tubing integrity issues. That repetition signals something deeper than a one-off manufacturing defect.

We don't yet have full root cause analysis, but the pattern suggests possible gaps in design validation, supplier controls, or production process validation. Perhaps material specifications weren't robust enough to account for real-world stress conditions. Perhaps incoming inspection didn't catch batch-to-batch variation in tubing properties. Perhaps the validated production process drifted over time without adequate monitoring. Whatever the proximate cause, the recurrence points to a gap in the quality management system—specifically, in the production and process validation controls that should have either prevented the first failure or ensured the corrective action was effective.

This matters because Insulet isn't a startup struggling with their first regulatory hurdle. They're an established player with mature QMS processes and significant regulatory experience. If production control failures can reach this scale at that level of maturity, it's a reminder that QMS discipline isn't something you achieve once and then coast. It's an ongoing, active process that requires continuous vigilance, especially as production scales, supply chains evolve, and designs are modified.

The Thread That Connects These Stories

The connection between SaMD production controls and hardware recalls might not be immediately obvious, but the underlying principle is identical: your production processes—whatever they look like—must be validated, controlled, and continuously monitored. The regulatory frameworks don't care whether you're injection moulding plastic or compiling code. They care whether you can demonstrate that what you're releasing to patients is safe, performs as intended, and is produced through repeatable, controlled processes.

For SaMD manufacturers tempted to think that software's intangibility somehow makes production controls less relevant, the Insulet recall is an instructive counterpoint. Physical devices can and do fail catastrophically when production controls aren't rigorous. Software failures—whether that's deploying untested code, releasing without proper version control, or pushing updates that haven't been validated in production-equivalent environments—can be equally catastrophic. The only difference is that software failures can propagate to every user simultaneously, often making the blast radius even larger than a traditional manufacturing defect.

Both scenarios also highlight the post-market surveillance obligations under EU MDR Article 83 and ISO 13485 Clause 8.2.1. Whether you're monitoring for tubing failures or software bugs in production, you need systems to detect, analyse, and respond to field performance data. Insulet's second recall suggests their corrective action from the first incident may not have addressed the root cause—a classic CAPA failure that post-market surveillance should have flagged earlier.

What This Means for Your Team

If you're developing SaMD, stop treating production controls as an afterthought or a hardware-only concern. Your ISO 13485 compliance must include documented, validated processes for software builds, deployments, and configuration management. That means version control that's traceable to risk management files and design history files. It means validated build environments where you can reproduce any historical release. It means controlled deployment processes with documented verification that what you intended to release is what actually reached users. And it means configuration management for cloud infrastructure that's treated with the same rigor as device master records.

For all manufacturers—software or hardware—the Insulet recall is a prompt to audit your production process validation and supplier controls. Are your critical process parameters actually being monitored? Do you have statistical process control in place for key characteristics? When suppliers change materials or processes, are you catching that through incoming inspection or supplier audits? And perhaps most importantly, when you implement corrective actions, are you validating their effectiveness through objective evidence, or are you assuming the problem is solved?

Post-market surveillance is the other critical piece. Both EU MDR and UK MDR require proactive systems to collect and analyse field data. For SaMD, that might be automated logging, error telemetry, or usage analytics. For hardware, it includes complaint handling, trend analysis, and vigilance reporting. The key is having systems sensitive enough to detect emerging patterns before they become Class I recalls affecting millions of devices. Insulet's second recall for similar issues suggests their PMS or CAPA processes didn't close the loop effectively—a gap that's increasingly unacceptable under the heightened scrutiny of EU MDR.

Key Takeaways

  • ISO 13485 production controls absolutely apply to SaMD—treat your software build, deployment, and configuration management processes with the same validation rigor you'd apply to traditional manufacturing
  • Insulet's 7M device recall, their second this year for similar root causes, illustrates the real-world consequences of production control or CAPA process failures, even for mature manufacturers
  • Post-market surveillance must be robust enough to detect emerging failure patterns early—recurrent recalls for the same issue signal a gap in either PMS or corrective action effectiveness validation
  • Whether you're developing software or hardware, production process validation isn't a one-time event; it requires continuous monitoring, periodic revalidation, and vigilant supplier management to maintain control
  • EU MDR's stricter requirements for production controls and post-market surveillance make these failures increasingly costly—now is the time to audit your QMS for gaps before regulators or patients find them for you

The regulatory landscape is getting more demanding, not less. Notified Bodies are applying heightened scrutiny to production controls under EU MDR, and competent authorities are increasingly willing to take enforcement action when post-market surveillance failures lead to preventable patient harm. For SaMD developers, that means accepting that you're subject to the same production discipline as traditional device makers—just with different tools. For all manufacturers, it means treating production validation and post-market surveillance as core competencies, not compliance checkboxes. The cost of getting this wrong—in recalls, patient harm, and regulatory consequences—has never been higher. If your team needs support strengthening production controls or post-market surveillance systems, particularly in navigating the SaMD-specific interpretations of ISO 13485, that's exactly the kind of practical, implementation-focused guidance SMEDTEC provides to manufacturers across the UK and EU markets.

Sources cited in this digest

  • Greenlight Guru Blog
  • MedTech Dive

Need Regulatory Guidance?

Get expert help with your medical device regulatory strategy. From EU MDR compliance to FDA submissions, we're here to help.

Get Started →More Articles