All customer stories
Medical Devices / Regulatory Compliance Flagship programme

Johnson & Johnson (J&J MedTech)

Three Connected Apps Turn a Notified Body Audit Into a Continuous Operating Model for J&J MedTech

Solution
Regulatory Audit Suite, AI Assisted Prototyping
Geography
Global
Timescale
Prototype-validated within weeks, ahead of production Power Platform build

3

Connected applications

2

Regulatory frameworks

9

Readiness status ladders

7

Audit day personas

Cloud Solutions PartnersSource Group International

Flagship programme. A single named team covered Power Platform build, AI-assisted prototyping and regulated-industry governance for a global medtech manufacturer across multiple sites, under one delivery contract rather than a set of separate staffing lines.

The organisation

Johnson & Johnson MedTech is the medical technology arm of Johnson & Johnson, one of the world's largest healthcare companies, designing and manufacturing devices used in surgery, orthopaedics, vision and cardiovascular care across a global manufacturing footprint. Its plants operate under strict international regulation, including EU MDR 2017/745 and MDSAP, and are subject to recurring Notified Body audits across multiple sites, making continuous, evidence-backed compliance a board-level priority.

The challenge

A multi-site medical device operation governed by EU MDR and MDSAP faced periodic Notified Body audits across several plants, thousands of clause-level obligations, and a permanent expectation of evidence on demand. Readiness, the live audit, and post-audit observation closure were three disconnected, spreadsheet-driven efforts with no shared measurement. Quality teams, wary of systems that add administration without giving anything back, needed proof that any new approach would work in their hands before a single euro was committed to production build.

Before

  • Readiness tracked in workbooks per site, never comparable
  • Evidence hunted down in the weeks before each inspection
  • Live audit run on chat threads, paper notes and hallway relays
  • Observations closed slowly in a tracker nobody else could see

After

  • Continuous readiness percentage by site, framework and chapter
  • Every MDR article and MDSAP clause assignable to a named owner
  • Live request board, scribe notes and back room console on audit day
  • Observations synced from the quality system and driven to closure

The solution

The engagement was structured as prototype first. Each of three applications, a Readiness Hub, an Audit Preparation and Observation workspace, and a Live Audit Cockpit, was built as a fully interactive prototype using AI assisted coding, seeded with realistic synthetic audit data and a role switcher so any workshop participant could step into any of seven audit-day personas. Regulatory teams played the entire lifecycle through, correcting workflow and guardrails against working software rather than a slide deck. Every screen sat on a service interface seam, with fields, choice sets and transitions mapped field-for-field to a Dataverse column, so the engineering team could hand the validated experience to Power Apps Code Apps without redesign. The three applications share one role and permission matrix, one status transition engine and one audit trail model, turning EU MDR articles and MDSAP clauses into assignable, evidence-backed work, and giving the client a single connected system for readiness, execution and closure across every site.

How we ran it

  1. 01

    Discover

    Mapped the full EU MDR and MDSAP obligation set across sites and interviewed quality teams to understand why prior spreadsheet-based efforts had failed to connect.

  2. 02

    Design

    Designed one shared data model, role model and transition engine underpinning all three applications, so readiness, live audit and observation data could speak to each other without reconciliation.

  3. 03

    Develop

    Built each application as an AI assisted, fully interactive prototype with synthetic data and a persona switcher, letting real users validate workflow before any production code was written.

  4. 04

    Deliver

    Converted validated prototypes one-to-one into production Power Apps Code Apps on Dataverse, preserving every signed-off decision through a single-team handoff.

Inside the suite

Two of the apps, on screen

Both applications below are working prototypes built with AI-assisted delivery and shaped around the real audit operating model, planning the inspection, then running it. They are built against a service-layer seam so the same interface ports to a Power Apps code app on Dataverse without redesign. Use these screens in a customer conversation to show the operating model, not a slide about it. Click any screen to enlarge it.

App 01 · Before the auditor arrives

Inspection Readiness

A single planning surface for every regulatory audit across the group, notified body, MDSAP, FDA, ANVISA, from the divisional calendar down to the individual preparation task at a manufacturing site. It replaces the spreadsheet-and-inbox cycle that most quality organisations still run before an inspection.

Audit scope: every open audit with its framework, dates, chapter and task counts in one list.

Group-wide audit calendar

Every planned and completed audit by division, region, entity and authority, read as a table or a waterfall so leadership can see collision points and quiet windows months ahead.

Scope builder per audit

Tick the frameworks, chapters and tasks that belong to an audit; the app expands them into a working checklist, 11 chapters and 165 tasks on a full MDSAP recertification, with no manual copying between cycles.

Entity readiness and ownership

Preparation tasks are assigned to named SMEs at each entity, with progress rolled up from site to division so the readiness percentage is a fact rather than an assertion.

Risk register with mitigation trail

Any task can be flagged as a risk, given a mitigation owner and due date, and tracked as at-risk, ongoing, mitigated or overdue, with the discussion thread kept alongside the evidence.

The group audit calendar as a waterfall, entity by entity, authority by authority.
Risk register: status, owner, due date and mitigation thread, rolled up the hierarchy.

Pre-sales angle: this is the app that converts audit preparation from a heroic effort by two or three people into a governed, repeatable programme. The buyer is the quality or regulatory director who cannot currently answer "are we ready?" without a week of chasing.

App 02 · While the auditor is in the room

Live Audit Cockpit

The operational command centre for the audit week itself. It runs the request ladder from the auditor's question to the delivered document, keeps four parallel audit streams synchronised, and produces the daily wrap-up and post-audit actions as a by-product of the work rather than an evening admin task.

The request board: every auditor request, four parallel streams, ageing visible at a glance.

Request board (ATMS)

Every auditor request tracked across the ladder, new, SME assigned, confirmed, ready, in front room, closed, with dedicated late, stuck, clarification and escalation lanes so nothing quietly ages.

Front-room command centre

The host sees what is ready to present, which SME is on the way with an ETA, the attachments already gathered, and confirms or scraps scribe proposals in one place.

Live scribe and open points

A time-stamped transcript per stream, with any line promotable into a request or an open point, and a read-only note viewer for everyone else, including auditor mood as a running signal.

Daily wrap-up and follow-up

Volumes logged, closed, open, stuck and urgent per stream; focus points for the next day per room; and a post-audit follow-up list that carries actions out of the audit and into the CAPA cycle.

Front room: open points, scribe proposals and what is ready to walk into the room.
Scribe pad: the live feed, with lines promoted into requests and open points as they happen.
Daily wrap-up: the day's numbers and tomorrow's focus points, generated from the work.

Pre-sales angle: this is the app people feel immediately. Ask a prospect how they currently track auditor requests during an inspection, the answer is a shared spreadsheet and a runner. Multi-screen pop-outs, role-based views and narrated tutorials mean back room, front room and SMEs all work from the same live picture.

The result

Within a matter of weeks, the client had three validated applications covering the full audit lifecycle instead of four disconnected trackers, with regulation turned into named, evidenced work and a defensible readiness score comparable across every site. Audit-day execution moved onto a governed, role-gated request board with live scribe notes and observation flagging. Because the whole suite was proven with real users as working software first, production investment was committed with the scope, workflow and guardrails already signed off, removing the single largest risk in a regulated technology programme.

We did not ask the client to imagine the system from a slide deck. We put three working applications in front of the people who run audits and let them play the whole lifecycle through. On audit day the difference between prepared and exposed is measured in minutes, and the cockpit exists so no request, note or concern is ever held in someone's head.

Regulatory Compliance Lead, J&J MedTech

Next story

Elida Beauty

Consumer Goods (Trade Promotion Management)

Read it