Regulatory Posture Audit

The regulatory posture audit rates one product's whole regulatory surface in one bounded engagement, for a company placing it on the Swiss or EU market. It determines which of the MDR, IVDR, MepV, AI Act, CRA, NIS2, ISG, DSG, GDPR and PrHG apply to that product, rates the posture per obligation group against a pinpoint citation, and names the deliverable that closes each gap; the fixed fee is quoted before engagement.

Who it serves

  • US and EU companies placing a product or a product line on the Swiss or EU market and unsure which instruments reach it.
  • Companies whose regulatory surface has just widened: an AI feature added to a device, a product that became connected, a first launch into Europe or Switzerland.
  • Companies heading into a financing round, a partnership or a supply agreement where a counterparty will ask what applies and where the company stands on it.
  • In-house teams that need one prioritized view of the whole surface before committing budget to a single framework.

What's included

  • Applicability map: every instrument in the variant's set marked in, out or partial for the product, each with the trigger that decides it stated in one line.
  • Posture rating: each applicable obligation group rated green, amber or red, with a one-line basis and a pinpoint citation to the text the rating rests on.
  • Prioritized gap register: the amber and red findings only, ranked by exposure against the nearest deadline, each row naming the remediation it calls for.
  • Obligation calendar: the dated milestones that reach the product, drawn from the same tracked source the public regulatory tracker publishes, so the calendar cannot drift from it.
  • Recommended engagement path: the deliverable or the retained arrangement that closes each priority gap, in the order the deadlines set. Where the answer is continuity rather than a single deliverable, that path is the fractional counsel arrangement, whose own onboarding opens with a regulatory health check of the same kind.
  • Method note and sign-off: a short account of what was done and why, and the attorney's sign-off before anything leaves the firm, in the careful and conscientious practice the professional rules require (Art. 12 lit. a BGFA).

The three variants

The audit is one product with three instrument sets. Which set applies follows from what the company places on the market, and the set is fixed at intake rather than discovered during the work.

Biotech and pharma

For companies developing or placing a medicinal product on the Swiss or EU market, advanced therapies and orphan products included. The set covers the EU Pharma Package and the HMG, the Swiss establishment license and the batch-release positions under the AMBV, clinical research under the CTR and the HFG, the GMP layer including its computerized-system and AI expectations, data protection under the GDPR and the DSG, any AI used in discovery, manufacturing records or safety under the AI Act, and the liability floor under the PLD and the PrHG. The intake asks for the modality and development stage, the EU and Swiss market and manufacturing footprint, whether trials are sponsored, whether a marketing authorization or a Swiss establishment license is held, and where AI touches the product. Sector page: Biotech & Pharma.

MedTech

For device and IVD manufacturers placing a product on the EU or Swiss market. The set covers the MDR and the IVDR with their Swiss counterparts, the MepV and the IvDV; the AI Act where an AI feature makes the device high-risk through the existing notified-body route (Art. 6(1), Annex I AI Act), which is the overlap most device makers meet first; connected-device security under the CRA, NIS2 and the ISG; clinical investigation and performance studies under the CTR and the HFG; data protection under the GDPR and the DSG; and liability under the PLD and the PrHG. The intake asks for the class and the basis of the classification, software-as-a-medical-device status, the route to each market and whether a CH-REP is appointed, the AI and connectivity surface, and the clinical status. Sector page: MedTech.

ICT and digital health

For SaaS, platform, digital-therapeutic and connected-product companies. The set covers data protection under the GDPR and the DSG, with the treatment health data attracts as particularly sensitive; security under NIS2, the ISG and the CRA; AI systems under the AI Act and the risk tier they fall into; and the MDR and the MepV where a software function meets the medical-device definition, which is the exposure digital-health companies most often miss. Liability sits under the PLD and the PrHG. The intake asks for the product and the data categories it processes, the EU and Swiss transfer footprint, the role AI plays in it, whether any function meets the device definition, and the supply-chain surface. Sector page: ICT & Digital Health.

What the audit does not cover

The boundary is stated in writing before work begins, because a bounded scope is what a fixed fee rests on. The audit does not:

  • draft or remediate any document; each of those is its own deliverable, priced separately;
  • go deep on a single framework, which is what a full gap analysis is for and what a red rating converts into;
  • correspond with an authority or a notified body;
  • cover a group-wide or multi-entity roll-out, which is scoped and quoted separately;
  • perform technical, quality-system or conformity-assessment work;
  • reach any question that needs factual investigation beyond the intake.

The rating is a triage signal that sets the order of action. It is not a reasoned legal opinion on any single question; that is a separate deliverable, and the audit names it where one is needed.

What the firm needs from the client

  • A description of the product or product line and the structural facts around it: the markets it is placed on, the legal entity that places it, the route to each market, where AI and connectivity sit in it, and the clinical or research status.
  • One scoping call, usually under an hour, to settle anything the questionnaire leaves open.
  • Nothing else. The audit works from product and process descriptions only: no patient data and no other particularly sensitive personal data (Art. 5 lit. c DSG, Art. 9 GDPR) enters the engagement, and the intake is built so that none is requested.

How it works

  1. Intake. The variant's questionnaire and a short scoping call establish the product and its structural facts.
  2. Applicability and rating. Each instrument in the set is tested against the product and each applicable obligation group is rated, worked against the tracked instrument set, the firm's published analysis and the legal texts held on file, with every uncertainty flagged rather than resolved quietly.
  3. Attorney pass. Every applicability call and every rating is confirmed or corrected, the flagged points are resolved, and the priority order is set.
  4. Quality gate. Citation integrity against the sources, consistency across the ratings, and the judgment checklist.
  5. Delivery. The rated report, the method note and the recommended engagement path. Nothing leaves the firm without the attorney's sign-off.

Fees

One fixed fee per product line

Quoted before engagement

The audit is a single fixed fee, set by the size of the instrument set the product carries and by whether more than one product line or legal entity is in scope. A priority track is available at a 50 percent uplift, subject to capacity. Group-wide and multi-entity work is scoped and quoted separately.

A written fee proposal follows the intake request and precedes any engagement.

Frequently asked questions

What does the audit produce?
A single rated report in six parts: an applicability map marking each instrument in, out or partial for the product; a posture rating for each applicable obligation group, with a one-line basis and a pinpoint citation; a prioritized register of the amber and red findings; the dated obligation calendar that reaches the product; the recommended engagement path; and a short note on what was done and why. It is delivered in English or in German.
How does the audit differ from a gap analysis?
By breadth against depth. The audit is a broad, shallow scan of a product's whole applicable surface, so that a company knows which instruments reach it and where it stands on each. A gap analysis goes deep on one framework and produces a remediation program. The two are sequential rather than alternative: a red rating in the audit is what a gap analysis is then scoped against.
Is the rating a legal opinion?
No. The rating is a triage signal that sets the order of action, delivered under the same attorney sign-off as any other deliverable. It is not a reasoned opinion on any single question. Each rating carries its own basis and its own citation, so any one of them can be checked against the text it rests on, and a question that needs a reasoned answer is scoped as its own deliverable.
Which instruments does the audit look at?
The set that applies to the product's industry, drawn from the same body of tracked instruments the firm publishes on its regulatory tracker. That body is maintained rather than fixed, so an instrument added to the tracker extends the audit without changing the product. The instruments common to all three variants, the GDPR, the DSG, the AI Act and the two product-liability regimes, are rated in every audit.
Does the firm need patient or customer data?
No. The audit works from product and process descriptions and from structural facts about the company. No patient data and no other particularly sensitive personal data enters the engagement, and the intake is built so that none is requested.