Executive Summary
A practical guide to medical device vigilance reporting under EU MDR 2017/745: serious-incident deadlines, FSCA duties, and how manufacturers, importers, and distributors stay compliant.
A hospital in Southern Europe pulled three operating tables out of service on a Friday afternoon after a clinician reported an unexpected collapse of the backrest locking mechanism. By Monday, the distributor was fielding calls from two more clinics, the national competent authority had opened a file, and the manufacturer — a factory halfway around the world — was still waiting for a translated incident description. The problem was that nobody had a rehearsed process for medical device vigilance reporting, so the first 72 hours dissolved into confusion about who reports what, to whom, and by when.
If you manufacture, import, or distribute surgical lights, operating tables, hospital beds, medical pendants, or trolleys, that scenario is not hypothetical. Under the EU Medical Device Regulation (MDR 2017/745), vigilance is a legal obligation with hard statutory deadlines, not a customer-service courtesy. Miss a reporting window and you face enforcement action, forced recalls, and reputational damage that no marketing budget can repair. The manufacturers we work with at Sanyang Medical’s OEM and ODM localization program learn this early: the same discipline that keeps a production line consistent keeps a vigilance system compliant.
This guide walks through the entire medical device vigilance reporting chain in plain, practical language. We will define what counts as a reportable event, break down each economic operator’s responsibilities, lay out the MDR Article 87 deadlines, explain field safety corrective actions, and show how to coordinate cleanly between a European authorized representative and a Chinese manufacturing partner — turning vigilance from a panic response into a routine, auditable process.

What Medical Device Vigilance Reporting Actually Means
Vigilance is the systematic monitoring, reporting, and analysis of incidents involving medical devices already on the market — the post-market safety net that catches problems no amount of pre-market testing could fully predict. A device can pass every bench test, earn its CE marking, and still reveal a failure mode only after thousands of clinical uses across different environments, cleaning chemicals, and user habits.
Two definitions anchor the entire system, and getting them wrong is the most common cause of both over- and under-reporting. The first is the serious incident, defined in MDR Article 2(65) as an incident that directly or indirectly led, might have led, or might lead to a death, a serious deterioration in someone’s state of health, or a serious public health threat. Notice “might have led” — you do not wait for a fatality; a near-miss that could have caused serious harm is reportable. The second is the field safety corrective action (FSCA), defined in Article 2(68) as an action a manufacturer takes for technical or medical reasons to prevent or reduce the risk of a serious incident from a device already on the market.
A useful mental model separates the signal from the response. The serious incident is the signal — something went wrong or nearly went wrong in the field. The FSCA is the response — what the manufacturer does about it, such as a recall, a retrofit, a software update, a labeling change, or a destruction notice, and the two are often reported together. The European Commission’s MDCG 2024-1 guidance on the vigilance system for CE-marked devices reinforces that manufacturers must operate a documented vigilance system as part of their quality management system, not as an ad-hoc reaction to complaints.
In my experience, the companies that get vigilance wrong are rarely the ones that ignore safety. They are the ones that treat every complaint as a crisis or, worse, dismiss every complaint as user error. Calibrate the threshold once, in writing, and train the whole team to apply it consistently — so a scratched housing panel stays a quality complaint while a near-miss that could have caused harm is escalated the same day.
Who Has to Report: Manufacturer, Importer, and Distributor Duties
One of the biggest misconceptions in our industry is that vigilance is “the manufacturer’s problem.” It is not. The MDR assigns distinct obligations to every economic operator in the supply chain, and a distributor or importer who assumes the factory will handle everything is taking on unmanaged legal risk. Articles 13 and 14 set out the general obligations of importers and distributors, and the Medical Device Coordination Group’s MDCG 2021-27 guidance clarifies how those obligations apply in practice.
The manufacturer carries the heaviest load. Under Article 10 and the vigilance chapter, the manufacturer must establish, document, and maintain a vigilance system; report serious incidents and FSCAs to the relevant competent authorities; conduct trend reporting; and coordinate field safety corrective actions. The manufacturer also owns the post-market surveillance plan, the periodic safety update report (PSUR), and the post-market clinical follow-up that feed the system with data.
The importer — the entity that places a device from a third country onto the EU market — must verify that the manufacturer and authorized representative have met their obligations, keep records of complaints and non-conforming devices, and inform both when a serious incident comes to light. Under Article 13, importers must also cooperate with competent authorities and provide samples or documentation on request. The distributor — anyone further down the chain who makes a device available — must verify CE marking and labeling before supply, and under Article 14 must immediately inform the manufacturer, authorized representative, and importer when a device presents a risk and cooperate with any corrective action.
| Economic Operator | Core Vigilance Duty | When an Incident Surfaces | MDR Basis |
|---|---|---|---|
| Manufacturer | Operate the vigilance system; report serious incidents and FSCAs; trend reporting; PSUR | Investigate, assess causality, report within statutory deadlines, launch FSCA if needed | Art. 10, Art. 83–92 |
| Authorized Representative | Act as the EU point of contact; confirm the mandate covers vigilance tasks | Receive authority queries, forward incident data, cooperate with investigations | Art. 11 |
| Importer | Verify manufacturer/AR compliance; keep complaint and non-conformity records | Inform manufacturer and AR; keep samples; cooperate with authorities | Art. 13 |
| Distributor | Verify CE marking and labeling before supply; monitor devices in the field | Immediately inform manufacturer, AR, and importer; support corrective action | Art. 14 |
For a distributor sourcing operating tables or hospital beds from China, this table is your risk map. Even if your contract says the manufacturer “handles all regulatory matters,” you remain the operator who physically supplied the device to the hospital. If a serious incident occurs and you failed to pass the information upstream or cooperate with the authority, your name is in the file too. The practical fix is a written vigilance cooperation agreement that spells out who does what, with named contacts and response-time commitments, signed before the first container ships.

Reporting Deadlines Under MDR Article 87
Article 87 of the MDR is the heartbeat of medical device vigilance reporting because it sets the deadlines everyone fears and few internalize. It requires manufacturers to report serious incidents and field safety corrective actions to the competent authority of the member state where the incident occurred or where the corrective action is taken. The critical detail is that the clock does not start when the incident happened — it starts when the manufacturer becomes aware of it and establishes a causal link, or a reasonable possibility of one, with the device.
Article 87(3) sets three upper reporting limits depending on severity. The default deadline is not later than 15 days after the manufacturer becomes aware of a serious incident. If the incident involves a serious public health threat, the report must go out immediately but not later than 2 days. If it involves death or an unanticipated serious deterioration in a person’s state of health, the deadline is not later than 10 days. These are maximums, not targets — the regulation expects you to report as soon as you reasonably can and to follow up as the investigation progresses.
| Situation | Maximum Deadline | Typical Trigger Example |
|---|---|---|
| Serious public health threat | Immediately, no later than 2 days | A systemic sterilization or contamination risk affecting many patients at once |
| Death or serious deterioration in health | No later than 10 days | A table collapse or electrical fault linked to a patient fatality or serious injury |
| Other serious incident | No later than 15 days | A near-miss that could have caused serious harm but did not |
Two practical points trip up even experienced teams. First, the initial report can — and often should — be incomplete: the regulation explicitly allows an initial report with the information you have, followed by a full investigation report later. Waiting for a perfect root-cause analysis is how companies blow the 15-day window. Second, FSCAs are reported through the field safety notice route, and the timing of that notice is tied to the urgency of the risk — you cannot wait for the next quarterly review cycle.
Report early, report incomplete, then follow up. A timely partial report that you supplement is always safer than a late perfect one. Competent authorities would far rather receive an initial notification on day 12 and a full report on day 40 than a single polished document on day 25.
Field Safety Corrective Actions and Field Safety Notices
When investigation confirms that a device in the field poses a risk, the manufacturer moves from reporting to action. A field safety corrective action (FSCA) is any action taken for technical or medical reasons to prevent or reduce the risk of a serious incident. The range is broad: a recall, a return for repair, a retrofit kit, a software or firmware update, a device modification, a destruction notice, a change to the instructions for use, or an advisory telling users to apply additional checks before each procedure. The action must be proportionate to the risk — you do not recall a whole production run to fix a labeling typo.
The vehicle for communicating an FSCA to customers and users is the field safety notice (FSN). Regulatory guidance, including the UK MHRA’s field safety notice guidance for manufacturers, emphasizes that an FSN must be clear, actionable, and written for the people who actually use the device. A good FSN identifies the affected device and batch or serial range precisely, describes the hazard and when it can occur, states the actions the user must take immediately, and provides a clear contact for questions.
The logistics of an FSCA are where distributor relationships are truly tested. If you supplied 200 operating tables across six countries, an effective corrective action depends on tracing exactly which serial numbers went to which hospitals — and reaching them quickly. This is why traceability is the backbone of every successful field action, not just a quality-system checkbox. Manufacturers with clean batch and serial records, and distributors with accurate delivery records, can execute a targeted FSCA in days rather than resorting to a costly blanket recall.

Coordinating Vigilance With a Chinese Manufacturing Partner
Most surgical equipment reaching European, Middle Eastern, and African hospitals is manufactured in China, which makes cross-border vigilance coordination a daily reality. The manufacturer sits in one jurisdiction while the authorized representative and the affected devices sit in another, and the Article 87 clock does not pause for time zones, language, or holidays. The distributors who handle this well build coordination into the relationship from day one, the same way they build it into a CE MDR versus FDA import compliance plan.
China operates its own adverse event monitoring regime under the Provisions for Medical Device Adverse Event Monitoring and Re-evaluation, in effect since 2019, which places obligations on the marketing authorization holder (MAH). A Chinese manufacturer that also sells domestically must report adverse events to the National Medical Products Administration (NMPA) in parallel with any EU vigilance reporting. For a European buyer this is an advantage when managed well: a manufacturer with a mature domestic monitoring system already has the complaint intake, investigation, and trend-analysis infrastructure to extend to export markets.
When we evaluate a manufacturing partner’s vigilance readiness, we look for concrete capabilities rather than glossy certificates. The questions below form a practical due-diligence checklist you can adapt, and they pair naturally with the verification steps in our guide to auditing a China medical factory.
- Named vigilance owner. A specific person responsible for vigilance, with a deputy, rather than a vague “quality department.”
- Documented procedure. A written SOP defining the serious-incident threshold, the reporting timeline, and the escalation path.
- English-language intake. The ability to receive, translate, and triage an incident report from a European hospital without a multi-day delay.
- Traceability depth. Tracing a serial number back to its production batch, components, and test records within hours.
- Authorized representative alignment. A mandate with the EU authorized representative that explicitly covers vigilance cooperation.
- Corrective action track record. Evidence the factory has executed an FSCA before and can show how it communicated and closed it out.
Time-zone discipline deserves special attention. A 15-day deadline sounds generous until you subtract weekends, a public holiday in both countries, three days of translation, and two days of internal debate about whether the event is “really” reportable. The manufacturers that meet deadlines consistently pre-authorize the safety officer to file an initial report without waiting for executive consensus — because a partner that needs a committee meeting to send a preliminary notification will miss a deadline under pressure.

Building a Vigilance-Ready Quality Management System
Vigilance does not live in isolation. It is one output of a quality management system built to ISO 13485 and connected to the post-market surveillance requirements of MDR Articles 83 to 86. A healthy QMS discovers serious incidents faster, investigates them more rigorously, and reports them on time almost as a side effect. The difference is whether complaint handling, trend analysis, and corrective action are connected in a closed loop or sit in separate silos.
The connection points matter. Every customer complaint should flow into a complaint-handling log that the safety officer reviews on a defined cadence. That log feeds the post-market surveillance plan, which watches for trends — a single locking-mechanism complaint is a service ticket, but five similar complaints across three hospitals in a quarter is a signal that demands investigation and possibly a serious-incident assessment. When complaint handling, trend analysis, and corrective action talk to each other, vigilance becomes a byproduct of routine monitoring rather than a fire drill.
Training is the most undervalued component. The person who first hears about an incident is rarely the regulatory affairs manager — it is a sales rep, a service engineer, or a customer-service agent. If that person does not recognize a reportable event or know how to escalate it within hours, the best SOP in the world is useless. We rehearse vigilance scenarios with frontline staff so escalation becomes a reflex, not a debate. Pairing this with a clear ISO 13485 test report and documentation checklist keeps the evidence trail audit-ready.
- Written vigilance SOP with the serious-incident decision tree, deadlines, and named roles.
- Centralized complaint log reviewed on a fixed schedule by the safety officer.
- Trend-analysis routine that escalates clusters into investigation and, where warranted, FSCA assessment.
- Authority contact map listing the competent authority and portal for every market you sell into.
- FSN templates drafted in advance so a notice can be finalized in hours, not days.
- Frontline training and drills so the first responder to a complaint knows the escalation path cold.
- Spare-parts and service linkage so corrective retrofits deploy quickly through your spare parts and after-sales service channel.

Common Vigilance Mistakes and How Auditors Catch Them
After years of watching vigilance systems succeed and fail, the failure modes are remarkably consistent. The most common is misclassifying complaints — treating a potentially serious incident as an ordinary service call, or burying it in a generic “customer feedback” category nobody reviews for safety signals. Auditors catch this by sampling your complaint log and asking how each entry was triaged. If you cannot show a consistent decision rule applied across entries, the gap is obvious.
The second common failure is late or missing trend analysis: a manufacturer handles each complaint correctly yet never sees the same failure mode recurring. Notified bodies look specifically for whether recurring complaints triggered investigation and corrective action. The third is poor traceability — the inability to define the affected population for a corrective action, forcing a broader, more expensive recall than necessary.
There is also a cultural failure that no checklist fully captures: the reluctance to report. Some teams fear that reporting a serious incident will trigger a recall or damage the brand, so they minimize or delay. This instinct backfires. Regulators treat a prompt, transparent report very differently from a late one that surfaces through a hospital complaint or a competitor — a proactive report signals a functioning safety culture, while a concealed one invites the harshest enforcement.
A vigilance system is a mirror of your quality culture. If your team hides bad news internally, they will hide it from regulators too — and the delay will cost far more than the truth ever would.
Conclusion
Medical device vigilance reporting is not a bureaucratic burden; it is the discipline that protects patients, customers, and your business. The MDR makes the obligations clear and the deadlines unforgiving: serious incidents within 15 days, within 10 days for death or serious deterioration, and within 2 days for a serious public health threat, with field safety corrective actions communicated through clear field safety notices. Every economic operator has a defined role, and assuming someone else will handle it is the single most expensive mistake in the chain.
For distributors and importers sourcing surgical lights, operating tables, hospital beds, pendants, and trolleys from China, the practical path is to treat vigilance as a selection criterion, not an afterthought. Choose a manufacturing partner with a named vigilance owner, a documented procedure, English-language intake, deep traceability, and a proven corrective-action track record. Build a written cooperation agreement, rehearse the escalation path with frontline staff, and connect complaint handling to trend analysis so signals surface early. To assess how a factory-direct partner can support your vigilance and compliance obligations, talk to our team or learn more about Sanyang Medical and how we build compliance into every product we ship.
Frequently Asked Questions
What is the deadline for reporting a serious incident under the EU MDR?
Under MDR Article 87(3), the default deadline is no later than 15 days after the manufacturer becomes aware of the serious incident. The window shortens to 10 days for an incident involving death or serious deterioration in health, and to 2 days for a serious public health threat. These are maximums — report as soon as you reasonably can and follow up with additional detail as the investigation continues.
Do distributors and importers have to report adverse events, or only manufacturers?
Manufacturers carry the primary reporting duty, but importers and distributors have their own obligations under MDR Articles 13 and 14. They must inform the manufacturer, the authorized representative, and each other when they become aware of a serious incident or a device that presents a risk, keep records of complaints and non-conforming devices, and cooperate fully with competent authorities. Assuming the factory will handle everything leaves a distributor exposed.
What is the difference between a serious incident and a field safety corrective action?
A serious incident is the signal — an event that led, might have led, or might lead to death, serious harm, or a public health threat, as defined in MDR Article 2(65). A field safety corrective action (FSCA) is the response — the action a manufacturer takes to prevent or reduce that risk, such as a recall, retrofit, software update, or labeling change, defined in Article 2(68). The two are often reported together, with the FSCA communicated to customers through a field safety notice.
Can I submit an initial vigilance report before the investigation is complete?
Yes, and you generally should. The MDR allows an initial report with the information available at the time, followed by supplementary reports as the investigation progresses. Waiting for a complete root-cause analysis before notifying the competent authority is a common cause of missed deadlines. A timely partial report that you later supplement is far safer than a late, complete one.
How should a distributor coordinate vigilance with a Chinese manufacturer?
Establish a written vigilance cooperation agreement before the first shipment, with named contacts and response-time commitments on both sides. Confirm the manufacturer has a named vigilance owner, a documented SOP, English-language intake, and deep serial-number traceability, and verify that its mandate with its EU authorized representative covers vigilance cooperation. A manufacturer already running China’s NMPA adverse-event monitoring as a marketing authorization holder often has infrastructure you can extend to export markets.