Making compliance work in practice

Practical Quality Assurance, Regulatory Affairs and Information Security support for organizations active in or related to medical devices and healthcare.
EHM Compliance helps translate requirements from law and legislation, including MDR, ISO 13485, ISO 9001, ISO 27001 and NEN 7510 into clear documentation, workable processes and compliant execution tailored to your organization.

For medtech companies that need clear, structured support to achieve or maintain compliance in quality, regulatory affairs and information security.

From gap assessment to implementation, turning regulatory and quality requirements into practical actions, clear documentation and efficient ways of working.
Compliant, structured and aligned with how your organization actually operates.

Limited in-house expertise

Regulatory requirements can be complex, while the necessary expertise to correctly interpret law and legislation into your QMS, ISMS or Technical File is not always available internally.

Insufficient capacity

The workload is clear, but the available resources are too limited to meet regulatory deadlines and keep critical documentation, decisions and follow-up activities under control.

Slow or inefficient processes

Procedures and policies exist, but they are difficult to apply in practice, leading to inefficient processes, unnecessary delays, rework and inconsistent execution.

Audit findings and identified improvements remain open too long

Findings or opportunities for improvement are known, but there is not enough time, knowledge or structure to resolve them within the expected timelines.

Friction between QA, RA and other departments

When compliance requirements are not clearly understood across teams, collaboration becomes more difficult, increasing the risk of non-compliance.

Not fully prepared for audits or inspections

All of the above situations may result in entering an audit or inspection without being fully in control, increasing the risk of nonconformities and the additional costs required to resolve them.

Services built around your compliance needs

Flexible Quality Assurance, Regulatory Affairs, Information Security and general Compliance support for organizations that need senior expertise to serve a need for temporary capacity or a structured project execution.

Project-based compliance support

QMS/ISMS implementation, optimization or digitalisation, process improvement and structured compliance projects with clear scope, priorities and deliverables.

Remediation or preparation

Quick scan of gaps and risks, preparation for audits or inspections, and practical support with findings, CAPAs and compliance backlogs.

Interim QA/RA management

Interim role as QA/RA Manager or senior quality lead, helping set compliance strategy, guide teams, align priorities and keep daily QA/RA responsibilities moving.

Internal auditor or PRRC services

Independent internal auditing, fulfilment of the PRRC role, or targeted training to support regulatory awareness, objective review and audit-ready follow-up.

With extensive experience in management and leadership roles,
I support healthcare and medical device organizations in quality assurance, regulatory affairs and information security. Over the past 20 years, I have helped organizations translate requirements from complex laws and standards into clear, practical and effective ways of working.
My aim is not only to clarify what needs to be done to work compliant, but also to help people understand why it matters so they can take ownership.

With a pragmatic, structured and hands-on approach, I help organizations move from fragmented or unclear requirements to workable processes, consistent documentation and audit-ready evidence. In doing so, I focus on creating clarity, building buy-in and ensuring that changes can be adopted sustainably by the teams involved.

I work independently, supported by direct access to a trusted specialist network with Notified Body Lead Auditor experience. This provides an additional perspective when complex regulatory or technical interpretation is needed.

  • Getting your medical device CE marked
  • Getting your organization (re)certified for ISO 13458/9001/27001 or NEN7510
  • Build or update technical file
  • Implement or optimize a quality or information security management system
  • Prepare for upcoming audit or inspection
  • Resolve audit findings, CAPAs or change backlog
  • Conduct an internal audit
  • Fulfill PRRC role
  • Train teams and raise awareness
  • Conducting quick compliance scan
  • Without her we would not been able to certify and re-certify for ISO27001, NEN7510, ISO13485 and MDR. She has a keen eye for detail and an enormous commitment to maintain the highest standards.

  • Her versatility and expertise allowed her to make significant contributions across various domains, consistently delivering exceptional results and exceeding expectations. She approaches her work with professionalism, integrity, and commitment to excellence.
  • A committed and professional consultant who carries out her work with great dedication and care. In a complex and demanding quality environment, she was able to get up to speed remarkably quickly and independently find her way in her work.
See the full recommendations on LinkedIn