top of page

The Most Dangerous Regulation Is the One You Don't Know Exists

  • Writer: Team Hoodin
    Team Hoodin
  • Jun 23
  • 5 min read

Updated: Jun 24

“How do you know the list is complete?”


It is a question that should appear at the centre of regulatory governance. Strangely, it almost never does.


Regulatory teams ask many other questions. Has the technical documentation been updated? Has the latest guidance been reviewed? Has the notified body comment been addressed? Has the regulatory update been assessed? Has the market requirement been implemented?


All of these questions matter. None of them are trivial. But they share the same hidden assumption: that the organisation already knows which regulations, requirements and market obligations should be on the table.


That assumption is often more fragile than it appears.


Most regulatory positions are not created in a single, clean moment. They accumulate. A product is launched in one market, then another. A consultant performs an early applicability review. A notified body accepts a classification. A spreadsheet is created. A quality procedure is updated. A local distributor provides input. A regulatory manager leaves. Someone new inherits the file.


After a few years, nobody experiences the regulatory position as a set of decisions anymore. It simply becomes the way the organisation understands the product.

This is where the risk begins.


Not because the organisation is careless. Usually the opposite is true. The regulatory team may be highly competent, highly experienced and deeply familiar with the major frameworks that govern the product. They may know MDR, IVDR, FDA requirements, ISO 13485 and the relevant guidance landscape in detail.



The weakness sits somewhere else.


The organisation becomes very good at maintaining what it already recognises, while gradually losing sight of how much confidence it should have in the boundaries of that recognition.


A medical device manufacturer selling in Germany, Poland, Sweden and the United Kingdom may describe its European regulatory position as “MDR-based”. That description is not wrong, but it can easily become too comfortable. MDR may provide the regulatory backbone, but the actual market position is shaped by much more than the backbone. National requirements, local registration processes, language obligations, authority expectations, vigilance procedures, transitional arrangements and post-Brexit UK divergence all sit around the primary framework.


Experienced regulatory professionals know this. The problem is not awareness of complexity. The problem is operational control over it.

Knowing that local differences exist is not the same as knowing that they have been identified, assessed, documented and maintained for a specific product in a specific market.


That is the uncomfortable gap.


Regulatory organisations tend to build strong processes around known obligations. Once a requirement has been identified, it can be assigned, implemented, monitored and audited. It becomes part of the visible compliance system. The organisation can show activity around it. There are records, decisions, owners and updates.


The unknown requirement leaves no such trace.


It does not appear in the update feed, because nobody is monitoring it. It does not appear in the audit checklist, because nobody placed it there. It does not appear in the regulatory plan, because the regulatory plan was built from the known landscape. It does not create noise until something external brings it into view.


This is why missing regulations are so dangerous. They do not behave like normal compliance problems. A known requirement can create workload, but it can also be governed. An unknown requirement creates false confidence.


The organisation believes it is maintaining its regulatory position, when in reality it may only be maintaining the visible part of that position.

This matters more now than it did ten or fifteen years ago because the regulatory perimeter around life science products has expanded. A connected medical device is no longer governed only by device legislation. Its regulatory context may include cybersecurity, data protection, radio equipment, batteries, environmental requirements, artificial intelligence, product safety, national registration rules and market-specific obligations. A medicinal product or biotech product may face a similarly layered landscape, with pharmaceutical legislation interacting with clinical trial rules, GMP expectations, data obligations, environmental considerations and country-specific implementation.


The hard part is not admitting that this complexity exists. Everyone in senior Regulatory Affairs already knows that.


The hard part is designing a way of working that reduces the risk of missing the parts that do not announce themselves.

This is where many organisations are still surprisingly exposed. They have procedures for regulatory monitoring, but those procedures often begin after the regulatory universe has already been defined. They have processes for assessing updates, but those processes depend on the right instruments being monitored. They have audits that test implementation, but implementation can only be tested against requirements that were previously identified.


In other words, many compliance systems are excellent at answering the second question and weak at answering the first.


The second question is: are we managing the requirements we know about?
The first question is: how do we know we know enough?

That first question is harder, less comfortable and much more important than it appears. It forces an organisation to look at the foundation of its regulatory position rather than the activity built on top of it. It asks whether inherited assumptions have been challenged, whether local markets have been reviewed systematically, whether new regulatory domains have been considered, whether non-applicability decisions have been justified and whether the scope itself remains defensible over time.


This is not about building a larger spreadsheet. Larger spreadsheets often make the problem worse by creating the appearance of completeness. The issue is not the number of rows in the register. The issue is whether the organisation can explain why the right rows are there and why the missing rows are truly missing.


That is a different standard.


It is also where regulatory confidence begins.

Confidence is not the feeling that the team is experienced. It is not the fact that previous audits went well. It is not the existence of a long applicability list. It is the ability to show that the regulatory landscape was identified through a controlled method, that product and market context were used, that local obligations were considered, that exclusions were reasoned and that the position can be challenged without collapsing into memory and assumption.


The most dangerous regulation, therefore, is rarely MDR, IVDR or FDA regulation. Those are visible. They are discussed, monitored and resourced.


The dangerous one is the requirement sitting just outside the organisation’s current field of vision. The German national obligation that was assumed to be covered by MDR. The Polish requirement that never entered the original assessment. The UK divergence that was treated as historical alignment for too long. The cybersecurity or data obligation that was considered “IT” rather than regulatory. The local market condition that only appears when a distributor, authority or auditor asks the wrong question at the wrong time.



By then, the problem is no longer just that a requirement was missed.


The deeper problem is that the organisation has discovered a weakness in how it defines regulatory scope.

That is the point at which regulatory confidence starts to erode. If one requirement was missed, what else was missed? If one local obligation was assumed away, where else did the organisation rely on the same assumption? If the register is incomplete, how much of the compliance programme built on top of it can still be trusted?


This is why the most mature regulatory teams are beginning to treat applicability not as an administrative exercise, but as a governance discipline. The objective is not merely to list regulations. The objective is to maintain a defensible view of regulatory scope across products, markets and time.


That shift matters.


Because in a world of expanding regulatory complexity, the organisations most at risk are not necessarily those that fail to work hard enough. Many are working extremely hard. They monitor, review, document and respond continuously.


Their vulnerability is more fundamental.


They may be working from an incomplete map.


And no amount of disciplined execution can fully compensate for a map that does not show the terrain.



Don't just manage regulations. Govern regulatory scope.


Compliance Studio provides global regulatory coverage to help organisations establish and maintain defensible Regulatory Positions across products, markets and jurisdictions.


Because the biggest compliance risks often sit outside the organisation's current field of vision.



 
 
ChatGPT Image Jun 10, 2026, 02_40_13 PM.png

Start governing live regulatory positions with Vertical AI

Experience how Compliance Studio combines governed regulatory requirements, continuous regulatory awareness, and Vertical AI to maintain defensible regulatory positions across products and markets.

Try Compliance Studio, free access
platform-ill.png
bottom of page