High-mix, low-volume medical electronics manufacturing: configuration, risk, and supplier control – the Assel approach

23.09.2026Maurycy Lewiakowski

 

The high-mix, low-volume (HMLV) model means working with many product variants at once: frequent changeovers, several revisions in effect in parallel, and relatively small batch sizes. This is an operational term, not a legal category or a separate compliance pathway. In medical electronics, the flexibility to run a broad product mix must go hand in hand with documented control over configuration, risk, the supplier base, the manufacturing process, and quality records.

The starting point is a clear division of roles between the device manufacturer (OEM) and the electronics manufacturing services provider (EMS). The OEM sets the requirements that follow from the design, the device's function, its risk assessment, and its target markets, and it is the OEM that demonstrates the device's conformity. The EMS's job is to translate those requirements into a process that can actually be executed and controlled. The scope of responsibilities, acceptance criteria, the change process, and the records required should all be documented in the technical file, specifications, and the quality agreement.

Regulatory Framework: MDR, FDA/QMSR, and ISO 13485

In the European Union, the baseline instrument is Regulation (EU) 2017/745, the MDR. Classes I, IIa, IIb, and III reflect the device's risk level and determine the conformity-assessment route — they do not translate directly into an IPC electronic-assembly class. Among the manufacturer's obligations, the MDR lists maintaining a quality management system, managing risk, keeping technical documentation, conducting post-market surveillance, and overseeing suppliers and subcontractors in proportion to their impact on the device (in particular Article 10(9) and Annexes I and II) [1].

In the United States, the revised 21 CFR Part 820, known as the Quality Management System Regulation (QMSR), has been in effect since February 2, 2026. It incorporates ISO 13485:2016 by reference and adds FDA-specific requirements on top of it. The relevant reference point is therefore the QMSR together with whatever other FDA regulations apply to the given device and to the organization's role in the manufacturing chain [2].

ISO 13485:2016 sets out quality management system requirements for organizations involved in the medical device life cycle, including contract manufacturers [3]. An EMS's certificate, however, is not proof that a specific device conforms, nor a guarantee that a given process is adequate. The OEM should verify the certificate's scope, which processes and sites it covers, how sub-suppliers are overseen, and the evidence that relates directly to the project at hand.

ISO 14971:2019 organizes risk management for the device across its whole life cycle [4]. In manufacturing terms, this means translating the significant risks and functional characteristics into concrete process requirements: acceptance criteria, test scope, the level of traceability required, and how nonconformities are handled. The OEM supplies the information that comes from the design and the risk file, while the EMS contributes knowledge of what the process can achieve and how it can be controlled.

Product standards apply only where they actually match the device's scope. IEC 60601-1 addresses the basic safety and essential performance of medical electrical equipment, and for many devices it still needs to be supplemented with particular or collateral standards — it is not a universal standard for every PCBA [5]. IEC 62304, in turn, describes the life-cycle processes for medical device software, where software is the device or part of it [6]. On the EMS side, this translates into controlled loading of approved firmware and keeping the corresponding production records.

Workmanship Standards: IPC-A-610 and J-STD-001

Put simply, IPC-A-610 is used to judge whether a finished electronic assembly is acceptable, while IPC J-STD-001 specifies how solder joints are to be made, which materials may be used, and how the assembly process itself is controlled [7][8]. The two documents are related, but they serve different purposes.

If a customer's documentation invokes IPC compliance, it should clearly specify at least:

  • the specific document and its revision;
  • the workmanship class that applies to the product, or to selected characteristics;
  • customer requirements recorded in the contract, drawings, and specifications — treated as taking precedence over the generic IPC criteria;

Regardless of whether IPC is invoked, the customer may also set its own rules for approving deviations, repairs, and rework. Where such requirements apply, it is worth recording them separately — in the specification, the technical file, or the quality agreement — together with the division of responsibility between the OEM and the EMS.

Class 3 is intended for products with elevated requirements for continued performance and for the consequences of failure, but the “medical” label alone does not determine whether it applies. It is the OEM that selects the class, based on the device's function and risk analysis, and that decision needs to be agreed with the EMS as early as the design and NPI stage. If the design does not provide suitable pads, spacing, tolerances, or process access, assembly to the chosen class can turn out to be very difficult or outright impossible — and no amount of inspection at the end of the line will fix mistakes made at the design stage.

Assessing workmanship does not stop at visual inspection or AOI — some failure mechanisms remain invisible to them. It is the OEM's job to identify the critical characteristics and the required level of detection confidence, while the choice of inspection method, test access, and any sampling plan are matters to be worked out technically with the EMS.

It is worth remembering that IPC-A-610 primarily describes the acceptability of the assembled PCBA. Final-assembly processes — box build, mechanical integration, harness routing, torqueing, marking, or closing the enclosure — mostly fall outside this document. Where the IPC requirements alone are not enough, the OEM should define its own workmanship and acceptance criteria and agree them with the EMS.

Configuration Control: The Digital Thread from Order to As-Built Record

The biggest systemic risk in HMLV does not arise when the data is wrong in itself, but when several individually correct elements get combined into the wrong configuration. A controlled production package should therefore cover at least:

  • the approved revision of the BOM and the manufacturing documentation;
  • the approved parts list and the rules governing allowed substitutions;
  • the correct programs for the paste printer, pick-and-place, reflow oven, SPI, AOI, AXI, and test stations;
  • the firmware version, along with the programming parameters and verification results;
  • tooling, stencils, and test fixtures, with their calibration or qualification status;
  • current work instructions, acceptance criteria, and any deviations in effect;
  • the release status of materials, work-in-process, and finished product;
  • the required competencies, training, and current qualifications of personnel performing special or inspection operations.

ERP, PLM, document-management, or MES systems can enforce these links, but the name of the system alone proves nothing. What matters is whether the process actually blocks use of the wrong revision, records change approvals, and lets you unambiguously reconstruct the configuration that applies to a given lot or serial number.

Every engineering change should go through a formal ECO/ECN workflow, and its impact assessment must go beyond the BOM alone — covering inventory and work-in-process, open orders, software, testing, labeling, regulatory documentation, validation status, and decisions about units already produced. Maturity is not measured by whether a company has an ECO module in its system, but by whether changes are actually implemented correctly and on time.

UDI and Manufacturing Traceability

The UDI system in force in the EU is built around the device identifier UDI-DI and, depending on the device and how it is labeled, the production identifier UDI-PI. Its purpose is to unambiguously identify the device on the market and to support post-market activities and any recalls (MDR Article 27 and Annex VI) [9]. Under the FDA system, UDI requirements are tied to ISO 13485, the QMSR, and 21 CFR Part 830 [2].

UDI does not require mapping every reel of material to a device serial number. It is the OEM's job to identify the components that matter for the device's safety and function and to justify the required level of traceability. Tracking elements that have nothing to do with risk or function only raises the cost of data, labeling, and handling without a proportional benefit. The scope of traceability needs to be agreed with the EMS, and IPC-1782B can serve as an industry framework for that agreement [10].

It is worth having the traceability matrix separate two distinct data streams:

1. Process and product traceability

It is necessary to decide which operations and parameters matter for the product's function and what evidence of their execution should be kept on record. This can include the date and time of the operation, the operator, the equipment, the program revision, a note that a component was hand-placed, the result of a functional or ICT test, any repair and retest, product release, and the shipping date and lot. Not every machine reading needs to be archived — what counts is data that is genuinely useful for product analysis, complaint investigation, or field actions.

2. Material traceability

For the components the OEM identifies, it must be decided whether traceability needs to go down to the component manufacturer's lot, to the package or reel, to the production or delivery date, or even to an individual serial number. That requirement only makes sense once it is clear what the component manufacturer itself means by “lot” and what can actually be concluded from its lot number. Unit-level traceability is only possible at all when the component carries a unique identifier that can be reliably read and linked to the finished product.

For both streams, it is worth agreeing up front on the data retention period, the export format, how lot splits and merges and component swaps are handled, and the expected turnaround time for a traceability exercise. Only that kind of breakdown shows what information can actually be retrieved when the need arises.

Suppliers and Materials: Qualification, Authenticity, MSL, and Obsolescence

Automated storage, label scanning, and X-ray component counting all improve the accuracy of inventory records, but none of them confirms a part's authenticity or its functional conformity. The whole materials cycle should start with qualifying the purchasing source and controlling the supplier, and only then move on to receiving, storage, issue, returns, and reconciling leftover stock.

For higher-risk components, the OEM and EMS may require purchasing directly from the manufacturer or through an authorized distribution channel, maintaining an unbroken paper trail, and running incoming inspection scaled to the risk involved. Label checks, visual inspection, and screening tests reduce risk, but they do not provide one-hundred-percent certainty about authenticity — an authoritative confirmation of a part's origin and status can really only come from its original manufacturer.

Handling of moisture-sensitive parts is covered by IPC/JEDEC J-STD-033, on the handling, packing, shipping, and use of moisture/reflow-sensitive surface-mount devices [11]. The system should track packaging status, exposure time, storage conditions, and any bake-out, while the shop floor itself maintains temperature and humidity conditions consistent with the process documentation. Controlling the shop-floor environment, on its own, does not replace tracking the floor life of a specific material lot.

The ESD control program should exist as a formal document. ANSI/ESD S20.20 sets minimum requirements and limits for its elements — personnel and workstation grounding, packaging, effectiveness verification, and training [12]. The OEM and EMS may adopt stricter requirements where the sensitivity of the components used justifies it. Humidity is only one environmental condition among several, and on its own it says nothing about how effective the overall ESD program is.

Obsolescence management is best treated as an ongoing process across the product life cycle, not something triggered only once a last-time-buy notice arrives. For medical devices, qualifying a replacement component often calls for additional testing, an update to the risk file and the technical documentation, and — depending on how significant the change is — action within the conformity-assessment process as well. If end-of-life monitoring starts too late, a component can disappear from the market before that work is finished, risking a production stoppage and a break in supply continuity. The process should therefore include early tracking of part status, assessment of single-source risk, an alternatives plan, timely notification of the OEM, and last-time-buy decisions made in good time.

SMT Line Architecture: Line Speed Is Not the Whole Story

In the HMLV model, the cost of frequent product changes can affect production capacity and manufacturing cost more than a placement machine's rated speed does. Modular SMT platforms, off-line program and feeder preparation, and automated PCB support can all shorten downtime, but the actual outcome depends on how the whole changeover is organized.

The SMED approach (Single-Minute Exchange of Die) can help here: it separates internal activities — possible only while the line is stopped — from external activities that can be done ahead of time, and then shifts as much work as possible out of the downtime window [14]. In SMT this translates into preparing and verifying material, feeders, the program, the stencil, and documentation in advance, standardizing the changeover sequence, and running any activities that can be safely parallelized at the same time.

 

The name SMED itself reflects the aspiration to bring changeover time down to single-digit minutes, but that is not a universal requirement for every line. In HMLV, what matters most is repeatability, the absence of configuration errors, and the time measured from the last good unit of the previous variant to the first accepted unit of the next one. For that reason, changeover time is best reported as a distribution — for example, the median and the P90 — within comparable product families.

Process Control: Effectiveness Over the “100% Inspection” Slogan

A claim of “100% 3D SPI and 3D AOI inspection” only tells you that every board passes through that particular machine — it does not mean every defect is detected with certainty. Actual effectiveness comes down to the EMS team's knowledge and experience, the procedures for creating and approving inspection programs, the quality of the chosen parameters, the capability of the measurement method itself, and whether the company learns from the escapes it does detect.

A good EMS should be able to demonstrate:

  • which characteristics and defect types a given inspection method can detect;
  • how it creates, verifies, and version-controls its inspection programs;
  • how it evaluates false rejects, false accepts, and defect escapes;
  • how it responds to trends, nonconformities, and product revision changes;
  • how it maintains the competency of inspection operators and programmers over time.

SPI, AOI, AXI, ICT, and functional test are all different inspection methods, and each one observes different characteristics of the product or the process — so the whole set of methods should be chosen jointly by the OEM and the EMS, matched to the design, its function, test access, and risk. Pre-reflow AOI can be justified for selected components or processes, but it is not a universal condition for HMLV to be cost-effective.

Process Validation and Change: Turning OEM Requirements into EMS Actions

A process requires validation when its output cannot be fully verified by later monitoring or measurement (cf. ISO 13485:2016, clause 7.5.6). The GHTF/SG3 guidance describes the approach to validating medical device processes, including installation qualification (IQ), operational qualification (OQ), performance qualification (PQ), and revalidation [13].

It is the OEM — through its own quality system and device risk assessment — that decides what needs validating and when. IQ/OQ/PQ requirements should be translated into concrete activities, criteria, and EMS responsibilities in the validation plan, the process specification, and the quality agreement. The EMS contributes its knowledge of the equipment, the process limits, worst-case conditions, and the data available, but it should not unilaterally change the agreed validation scope.

When assessing a change, the OEM and EMS should consider, among other things:

  • the impact on critical characteristics and the risk-control measures already in place;
  • whether the material, geometry, equipment, software, or a parameter is changing — and how novel that change is;
  • the limits of the previously demonstrated process window and how representative the existing data still is;
  • any change to the inspection method, tooling, or acceptance criterion;
  • the history of deviations, complaints, and process trends;
  • whether the outcome can be fully verified after the process is complete.

The outcome of that assessment can range from no additional testing being needed, through limited verification or partial requalification, to full revalidation. The term “delta validation” is sometimes used to describe a reduced scope of work, but it does not replace a documented OEM decision and an agreement with the EMS on the specific actions to be taken.

Firmware and Production Software

Where the EMS programs the device, the production record should link the serial number or lot to the approved image version, the configuration, the programming result, and — where required — an integrity identifier. Access to production images, keys, and parameters should be subject to change control and access permissions.

IEC 62304 addresses the development and maintenance of device software and is not, on its own, a set of instructions for validating an MES or a programming station [6]. Software used in production and in the quality system should instead have documented confirmation of its fitness for intended use, proportionate to the risk of a wrong decision being made or of records losing their reliability.

DfM and DfT: Risks to Close Out Before NPI

A DfM/DfT review should produce a log of open questions and risks, each with an owner, a due date, and formal closure before release to production. The sheer number of comments raised says little on its own if it is not clear which of them actually affect safety, function, cost, testability, or validation.

  1. Production data package — consistency across PCB files, drawings, panelization, assembly data, layers, drill data, fiducials, the stackup, and impedance requirements. The source of truth and the order of precedence among documents must be explicitly stated.
  2. BOM and approved materials — unambiguous MPNs, revisions, allowed substitutes, critical parameters, life-cycle status, material requirements, and the applicable legal requirements of the target markets. RoHS/REACH information matters where it applies, but it does not substitute for a conformity assessment of the whole device.
  3. Process feasibility — pads, spacing, tolerances, component orientation, access for soldering and inspection, and requirements for cleaning, conformal coating, bonding, or potting, together with compatibility with the thermal profile.
  4. Testability — test coverage, probe access, boundary scan, the programming method, input stimulation and output observability, pass/fail criteria, retest rules, and result recording.
  5. Device-specific requirements — electrical safety, EMC, cleanliness, biocompatibility of patient-contact materials, sterilization resistance, or sterile-barrier integrity — but only where they genuinely apply to the given device and to the EMS's scope of work.

How to Compare Prospective EMS Partners

Build quality depends first and foremost on the maturity of the design, and only after that on the quality of the materials chosen, the test strategy adopted, the product's complexity, and the techniques used and the maturity of the manufacturing process itself. That is why comparing the FPY figure alone between two different products has no diagnostic value and should not be used as a basis for ranking EMS providers.

The most reliable comparison is between quotes and results for the same product — for instance, after a controlled pilot run. If historical data is used instead, it should come from a genuinely comparable product family, with the design, volume, test coverage, measurement period, and exclusion rules all disclosed. Equally important is evidence of maturity in DfM/DfT, change control, personnel competency, supplier management, and the speed of root-cause analysis.

Supporting KPIs: For Trend Analysis, Not for Comparing Different Products

Metrics make sense when they track the same product, a stable revision, or a clearly defined, homogeneous product family. Every KPI should have its own definition, population, time horizon, target, and exclusion rules.

  • FPY (First Pass Yield) — the share of units that pass through a defined flow the first time, with no repair, rework, or retest; mainly useful for tracking the trend of the same process.
  • Changeover time — measured from the last accepted unit of the previous variant to the first accepted unit of the next one; in HMLV it is worth tracking the median and the P90 within a comparable product family.
  • Escape rate — confirmed nonconformities detected after the product has already been released, expressed against an agreed population and broken down by severity.
  • ECO effectiveness — the share of changes implemented on time and without a configuration error, together with visibility into the actions taken on inventory and work-in-process.
  • Traceability completeness (a proposed KPI) — the proportion of required links successfully reconstructed in an exercise, and the time needed to retrieve the data. If this metric is not yet being measured, rolling it out first requires agreeing the data scope, the frequency of exercises, and a baseline.
  • OTD (On-Time Delivery) — punctuality measured against the confirmed delivery date and the agreed rules for any change to it.

Cost of Quality and the Total Cost of Working with an EMS

The lowest assembly price does not necessarily mean the lowest cost for the OEM. A better way to evaluate a partner is to combine Total Cost of Ownership (TCO) with the cost of quality. In the classic ASQ framework, the cost of quality is split into four categories: prevention, appraisal, internal failure, and external failure [15].

  • Prevention — DfM/DfT, supplier qualification, process development, training, equipment maintenance, and validation.
  • Appraisal — incoming inspection, SPI, AOI, AXI, ICT, functional test, and audits.
  • Internal failure — scrap, rework, retests, sorting, downtime, and re-running a lot.
  • External failure — complaints, RMAs, reverse logistics, field or regulatory actions, and lost sales and reputation.

From a value-creation standpoint, inspection on its own adds nothing to the product's function — it is an appraisal cost, not an improvement to the device. That does not mean it should be eliminated unconditionally, however. The goal is to bring down the total cost of quality through better design, effective prevention, and a stable process, while keeping the controls that are actually justified by real risk. The extra cost of solid NPI work, validation, or testing can be economically justified when it clearly reduces internal and external failure costs.

A proper TCO calculation should include not just the unit price, but also start-up and tooling costs, OEM engineering time, logistics, inventory and the working capital tied up in it, the handling of changes, the cost of quality, and the risk of supply disruption. Only that full accounting shows whether a nominally more expensive EMS actually turns out to be the cheaper, safer option over the whole life cycle.

Conclusion

Control in the HMLV model for medical electronics is not about maximizing automation or imposing the highest possible level of requirements on every product. It is about the OEM correctly identifying the requirements, designing a device that can actually be built reliably, and translating risks and functions into concrete, agreed EMS actions.

A mature partner can demonstrate configuration control, personnel competency, process capability, appropriately chosen inspection methods, separately tracked process and material traceability, efficient changeovers, and a deliberate approach to managing the cost of quality.

Sources

[1] European Parliament and Council of the European Union, Regulation (EU) 2017/745 on medical devices (MDR), official text: https://eur-lex.europa.eu/eli/reg/2017/745/oj

[2] U.S. Food and Drug Administration, Quality Management System Regulation — Frequently Asked Questions, updated February 2, 2026: https://www.fda.gov/medical-devices/quality-management-system-regulation-qmsr/quality-management-system-regulation-frequently-asked-questions

[3] International Organization for Standardization, ISO 13485:2016, Medical devices — Quality management systems — Requirements for regulatory purposes: https://www.iso.org/standard/59752.html

[4] International Organization for Standardization, ISO 14971:2019, Medical devices — Application of risk management to medical devices: https://www.iso.org/standard/72704.html

[5] International Electrotechnical Commission, IEC 60601-1:2005, Medical electrical equipment — Part 1: General requirements for basic safety and essential performance (as amended): https://webstore.iec.ch/en/publication/2606

[6] International Electrotechnical Commission, IEC 62304:2006, Medical device software — Software life cycle processes (as amended): https://webstore.iec.ch/en/publication/6792

[7] IPC/Global Electronics Association, IPC-A-610, Acceptability of Electronic Assemblies: https://shop.ipc.org/ipc-a-610

[8] IPC/Global Electronics Association, IPC J-STD-001, Requirements for Soldered Electrical and Electronic Assemblies: https://shop.electronics.org/ipc-j-std-001

[9] European Commission, Unique Device Identifier — UDI: https://health.ec.europa.eu/medical-devices-topics-interest/unique-device-identifier-udi_en

[10] IPC/Global Electronics Association, IPC-1782B, Standard for Manufacturing and Supply Chain Traceability of Electronic Products: https://shop.ipc.org/ipc-1782/ipc-1782-standard-only/Revision-b/english

[11] IPC/JEDEC, J-STD-033, Handling, Packing, Shipping and Use of Moisture/Reflow Sensitive Surface Mount Devices: https://shop.electronics.org/ipcjedec-j-std-033/ipcjedec-j-std-033-standard-only

[12] EOS/ESD Association, ANSI/ESD S20.20 — overview of the ESD control program scope: https://www.esda.org/news/an-overview-of-ansiesd-s20-20/

[13] Global Harmonization Task Force, GHTF/SG3/N99-10:2004, Quality Management Systems — Process Validation Guidance, IMDRF repository: https://www.imdrf.org/documents/ghtf-final-documents/ghtf-study-group-3-quality-systems

[14] Lean Enterprise Institute, Single-Minute Exchange of Die (SMED): https://www.lean.org/lexicon-terms/single-minute-exchange-of-die/

[15] American Society for Quality, Cost of Quality: https://asq.org/quality-resources/cost-of-quality

CONTACT

LET US WORK TOGETHER!

Benefit from our expertise in electronics manufacturing, today!
Let us learn your problems and requirements, and we will propose a business model that is most suitable for you.

Fundusze Europejskie, Rzeczpospolita Polska, Unia Europejska
Made by Web24