
Spreadsheets are simple. They are familiar. They are easy to start with.
That is why many medical device companies still use them to manage PMS trackers, complaint logs, CAPA actions, risk files, supplier follow-ups, and audit preparation.
At first, this feels practical.’

But during an MDR audit, the weakness starts to show.
Because auditors are not only checking whether information exists. They want to know whether the information is controlled, traceable, reviewed, approved, and connected across the full device lifecycle.
A spreadsheet may hold data.
But it often cannot prove compliance.
The Problem Is Not the Spreadsheet
Spreadsheets are not bad tools.
They are useful for simple tracking and early-stage planning. The real problem begins when companies use spreadsheets as their main compliance system.
MDR compliance needs more than rows, columns, and filters. It needs evidence of control.
Auditors may ask simple but difficult questions:
Who updated this record?
When was it changed?
Why was it changed?
Was the change reviewed?
Is this the approved version?
If your spreadsheet cannot answer these questions clearly, it becomes an audit risk.
Traceability Becomes Weak
Under EU MDR, traceability is critical.
Your PMS data should connect with your risk management file. Complaints should link to trend analysis. CAPA actions should connect with root causes. Clinical evaluation should reflect post-market findings.
But spreadsheets often create silos.
One team updates PMS data. Another team maintains risk files. Someone else manages CAPA. Another person tracks complaints.
When these files do not connect, gaps appear.
For example, a complaint trend may be visible in one spreadsheet but missing from the risk management file. A PMS finding may not update the CER. A CAPA may close without clear linkage to the original issue.
These gaps are exactly what auditors look for.
Version Control Can Quickly Collapse
Version control is one of the biggest spreadsheet problems.
One file may sit on a shared drive. Another version may be emailed. Someone may download a copy and edit it offline. Another person may save a new version with a slightly different name.
By the time the audit starts, the team may not know which file is final.
This creates doubt.
And in audits, doubt is dangerous.
Auditors expect controlled records. They expect clear approval history. They expect confidence that the document being shown is current and authorized.
Spreadsheets often struggle to provide that confidence.
Manual Updates Increase Error Risk
Spreadsheets depend heavily on manual work.
Rows can be deleted. Filters can hide data. Formulas can break. Dates can be entered incorrectly. Cells can be overwritten. Actions can be marked complete without evidence.
These may seem like small issues during routine work.
But during an MDR audit, small errors can become major findings.
A missed complaint trend may suggest weak PMS. An outdated risk score may suggest poor risk control. A missing CAPA closure record may suggest poor follow-up.
Auditors do not only review the data.
They review whether the system behind the data is reliable.
Data Integrity Is Hard to Defend
In regulated environments, data integrity is everything.
Manufacturers must show that records are accurate, complete, protected, and trustworthy.
Spreadsheets make this difficult unless strict controls are applied.
If anyone can change the file, delete data, rename versions, or edit records without a reliable audit trail, the integrity of the information becomes questionable.
This is especially risky for PMS, vigilance, complaints, CAPA, risk management, supplier control, and clinical evidence tracking.
These are not simple admin records.
They are part of your compliance evidence.
Accountability Becomes Manual
MDR compliance requires clear ownership.
Every action should have an owner, deadline, review status, and closure evidence.
Spreadsheets can show names and dates, but they do not always prove that the right person reviewed, approved, or closed the action.
That means accountability depends on manual follow-up.
And manual follow-up is easy to miss.
During an audit, this can make the process look weak, even if the team is working hard behind the scenes.
Why This Matters Under MDR
EU MDR expects manufacturers to maintain strong lifecycle control.
This means your compliance system should show how information flows across the device lifecycle.
From clinical evaluation to PMS.
From PMS to risk management.
From complaints to CAPA.
From CAPA to process improvement.
From post-market data back to technical documentation.
When spreadsheets are disconnected, this lifecycle story becomes hard to prove.
That is why spreadsheet-based compliance often struggles during MDR audits.
What Companies Should Do
Companies do not need to remove every spreadsheet overnight.
However, they should identify where spreadsheets create the highest risk.
Start by reviewing critical processes such as PMS, complaints, CAPA, risk management, vigilance, supplier control, and clinical evidence updates.
Ask whether each spreadsheet has proper access control, version control, approval history, audit trail, and linkage with related documents.
If the answer is no, the process may need a stronger system or controlled workflow.
The goal is not just digital transformation.
The goal is audit readiness.
Final Thoughts
Spreadsheets fail during MDR audits because they were not designed to manage complex regulatory compliance.
They are helpful for simple tracking.
But MDR requires stronger control, traceability, accountability, and lifecycle evidence.
In today’s audit environment, having data is not enough.
You must prove that your data is controlled, connected, reliable, and review-ready.
How Bioexcel Can Help
At Bioexcel, we help medical device manufacturers identify compliance gaps before auditors do.
We support MDR audit readiness, PMS and PMCF alignment, CAPA review, risk management linkage, technical documentation review, and lifecycle compliance strategy.
We help companies move from disconnected tracking to stronger, traceable, and audit-ready compliance systems.
Need support preparing for an MDR audit? Partner with Bioexcel for a smarter and stronger compliance approach.



