Regulations don't have
to be complicated.

At GRC BV, we clarify the opportunities of regulations. With years of experience in the MedTech and LifeScience sectors, we offer practical guidance to help you navigate the maze of regulations and identify necessary processes for the EU and the US. We listen, think along, and offer solutions that truly benefit you – independent, straightforward, and pragmatic. Our goal is to eliminate complexity and help you achieve results.

See how we can help you
Discover our services

Services

Market Access Strategy

Help develop clear strategies for rapid market entry, tailored to your product and target region.

Product Development

Provides advice during every phase of product development, to be compliant from concept to end-of-life.

Quality Management

Supports to improve and/or establish a suitable QMS, including requirements for ISO certification.

Compliance & Audits

Performs gap analyses, internal audits and update of technical documentation and QMS processes.

Training & Coaching

Provides training and coaching in skills and/or awareness of regulations and standards.

Organizational Development

Provides guidance in setting up RA teams and stakeholder management for your organization.

Market Access Strategy

Help develop clear strategies for rapid market entry, tailored to your product and target region.

Product Development

Provides advice during every phase of product development, to be compliant from concept to end-of-life.

Quality Management

Supports to improve and/or establish a suitable QMS, including requirements for ISO certification.

Compliance & Audits

Performs gap analyses, internal audits and update of technical documentation and QMS processes.

Training & Coaching

Provides training and coaching in skills and/or awareness of regulations and standards.

Organizational Development

Provides guidance in setting up RA teams and stakeholder management for your organization.

Partnerships and Memberships

Expertise

Software in the medical context

We help you determine the correct software qualification and classification for the EU and USA, the associated requirements and their impact on products and processes, identify relevant ISO/IEC standards and how to establish the necessary proof of compliance.

Why is this important for the manufacturer?
Software in the medical context may or may not be a medical device, an IVD, and/or an AI system. Depending on the manufacturer's product claims, the software may have a medical purpose. Software without a medical purpose is used for storing or exchanging patient data, communication, or lifestyle & wellness, for example. The relevant legislation in both situations has a significant impact on the manufacturer's product and process requirements and varies by region. Examples of legislation include the EU MDR, EU IVDR, EU AI Act, GDPR, and FDA 21CFR.

AI software & AI systems

We can help you navigate today's complex regulatory landscape, determine the impact of the EU AI Act, and coordinate the right route to market in consultation with Notified Bodies.

Why is the EU AI Act complex?
Artificial Intelligence (AI) is a rapidly evolving field with enormous potential for healthcare, education, government and mobility. It can quickly gather essential information from data, make processes more efficient, offer new solutions to complex problems, and enhance human capabilities. There is a difference between AI software based on mathematical calculation rules and AI systems that imitate human skills such as learning, reasoning, problem-solving, and decision-making. When an AI system has a medical purpose, the EU AI Act may apply in addition to the EU MDR/IVDR. The timelines for complying with the EU AI Act are short, with requirements imposed on both the provider and the deployer, and in addition expectations from Notified Bodies.

Data Management

We can help you develop your data management strategy for product development, clinical studies, finished products, and market access.

Why a regulatory data strategy?
Data management is essential during the process of gathering evidence for intended use, clinical applicability, and product claims. This is also part of the regulatory strategy for obtaining market access. High-quality and usable data for development, verification, and validation are key. Data strategy and management must consider, e.g., the General Data Protection Regulation (GDPR), the European Data Act and Data Governance Act (DGA). Applying ISO 8000 and ISO 27000 standards may be relevant to demonstrating regulatory compliance.

Privacy & Cybersecurity

We can help you determine the requirements you and your customers need to meet to secure devices, software, platforms, and IT networks. We can also assist in identifying the necessary evidence and reporting required for market access applications.

Why is it of public interest?
Personal data and medical records are privacy sensitive. This makes them highly valuable to criminals and often the target of cyberattacks. When developing products, it is crucial to determine which personal data is required and the conditions attached to it. It is also important to determine what type of data the final product will use. All of this influences the level of evidence and risk mitigation required for privacy and cybersecurity under the GDPR, EU and/or FDA cybersecurity legislation, and NIS2. Evidence of implementation can be expected in the form of a Secure Product Development Framework (SPDF), a Software Bill of Materials (SBOM), and robust cybersecurity risk management plans.

Software as an IVD

We can support you during the development of your IVD software product to meet all the requirements of the EU IVDR.

Why specifically EU IVDR?
The regulation for medical devices, the EU MDR, is better known and more widely implemented. The EU IVDR is intended for a specific group of medical devices, in vitro diagnostic products, such as tests developed for the analysis of human materials. Software as an IVD is a specific group of IVD products that must also comply with the IVDR. Correctly interpreting the IVDR for these software products is often seen as a challenge, particularly with regard to the requirements for performance evaluation and product claims, and the expectations regarding demonstrating safety and effectiveness.

Regulatory at Concept Phase

We can guide you at concept phase in determining and optimizing the paths to market access.

Why already at Concept Phase?
For well-informed decisions about grants and investments, not only is the technical feasibility of the product concept necessary, but also the intended claims and the regulatory-based market access strategy. In addition to the product requirements, insight into the requirements for the (quality) management system is crucial, as are the associated timelines and costs. Exploring opportunities in various markets (e.g., the EU and the US) and understanding the step-by-step development of product claims can reveal opportunities that form a key component of the strategic business plan.

Cases

Real questions.
Real solutions.

It is important to think in terms of solutions and opportunities, not in terms of problems. At GRC BV, we think proactively, adapt quickly, and always look for what is possible. This practical approach ensures we keep moving forward, even when things get tough. We do not use a one-size-fits-all approach; we adapt to the situation. This way we keep it simple, clear and above all effective.

At GRC BV, we do not focus on theory, but on what really works. Our cases are snapshots of complex issues that we have tackled. A clear, practical approach, always centred on the person behind the project, is crucial.

Regulatory strategy for startups

Identified requirements for AI systems for database search, symptom recognition, and image analysis....
2025

Performance Evaluation IVDR

Trained development teams and assisted to ensure technical documentation is compliant....
2025

Tailored QMS – EU IVDR, Biobanking, FDA 21CFR

Analysed, identified, and resolved critical areas for improvement to ensure QMS compliance....
2024

EU AI Act impact

Assessed and documented the impact of using AI in medical applications and for government services....
2024

About

At GRC BV, we believe that complex regulations don't have to be an obstacle. With over 30 years of experience in the MedTech and Life Sciences sector, founder Monique Greijmans helps companies navigate the world of quality requirements, compliance, and market access in a clear and practical way.

By listening carefully, asking questions, and actively contributing, we don't offer a standardized approach, but support that truly fits your situation. Whether it's developing a regulatory strategy, improving processes, or coaching teams, we're ready to help, provide structure, and create clarity.

We avoid complex language or unnecessary formalities. Instead, we offer honest and independent advice, clear explanations, and rapid responses. It's all about collaboration based on equality, professionalism, trust, and respect. This is how we build sustainable solutions that deliver results.

Career

1987-1991

Philips
Research

1991-2005

N.V. Organon
Product Engineer
Steriele & 
Combinatie producten

2005-2011

N.V. Organon - MSD
Scientist
CMC
Contraceptives

2011-2016

Philips
Sr. Manager QA & RA
Healthcare
Informatics

2016-2022

Philips
Director RA & CA
Digital & Computational
Pathology and Oncology

2022-2024

Philips
Sr. Director RA
Precision Diagnosis Cluster

2024-present

GRC B.V.
Principal Consultant 
RA & QA