Skip to main content
Category: Monitoring & Drift

Post-Market Monitoring

Also known as: PMS, Post-Market Surveillance, Postmarket Surveillance, Postmarketing Surveillance
Simply put

Post-market monitoring refers to the activities carried out to keep track of a product's safety and performance after it has been released for use or sale. In the medical device and drug context, where this term is well established, it means manufacturers collect and evaluate real-world experience once a product is on the market, rather than relying only on pre-release testing. The goal is to catch problems that emerge in actual use and respond to them.

Formal definition

As commonly defined in the medical device and pharmaceutical domains, post-market monitoring (often called post-market surveillance) is a structured set of activities conducted by manufacturers to systematically collect and evaluate real-world experience with a product after its commercial release or regulatory clearance, in order to assess ongoing safety and efficacy. It functions as an umbrella term covering a range of monitoring, reporting, and evaluation activities, and typically includes mechanisms for capturing adverse events or problems from users and health professionals (for example, voluntary reporting programs). Note that the evidence provided here concerns medical devices and drugs specifically; the term is also used analogously in AI governance contexts (for example, ongoing monitoring of deployed AI systems), but such AI-specific regulatory usage is out of scope for the sources cited and should not be assumed to carry the same requirements.

Why it matters

Pre-release testing, whether clinical trials for a drug or bench and clinical evaluation for a medical device, is conducted under controlled conditions that cannot fully anticipate how a product will behave across the full diversity of real-world users, settings, and use patterns. Post-market monitoring exists to close this gap: it provides a structured way to detect safety and performance problems that only surface once a product is in broad use, and to respond before those problems accumulate harm. In the medical device and pharmaceutical domains, where the term is well established, this ongoing evaluation is treated as a manufacturer responsibility rather than an optional activity.

The practical significance is that a product cleared or approved as acceptably safe at launch can reveal issues later that were not visible in pre-release data. Mechanisms such as the FDA's MedWatch program allow health professionals and members of the public to voluntarily report serious reactions and problems with medical products, feeding real-world signals back to manufacturers and regulators. Without such feedback loops, problems occurring in actual use may go unrecognized or unaddressed.

It is worth being precise about scope: the evidence here concerns medical devices and drugs. The concept of monitoring a released product for emerging problems maps intuitively onto the ongoing monitoring of deployed AI systems in model risk management and AI governance, but the specific requirements, reporting channels, and regulatory obligations described in these medical sources should not be assumed to transfer to AI contexts. Readers applying the idea to AI systems should confirm the governing framework for their own domain rather than importing medical-device obligations by analogy.

Who it's relevant to

Medical device manufacturers
In the device domain, post-market surveillance is generally treated as a manufacturer responsibility: monitoring products after they have been cleared for sale and carrying out the range of activities needed to track ongoing safety and performance. Manufacturers are typically the parties expected to collect and evaluate real-world experience and to maintain the processes that feed those signals into evaluation.
Pharmaceutical companies and drug safety teams
For drugs, post-market (or postmarketing) surveillance supports continued assessment of safety after approval. Teams responsible for pharmacovigilance rely on real-world reporting channels, such as the FDA's MedWatch program, to capture adverse events and problems that emerge once a product is in broad use.
Regulators and market supervisors
Regulatory and supervisory bodies have an interest in whether manufacturers carry out required post-market surveillance activities and in the signals those activities generate. Reporting programs that gather problems from health professionals and the public provide regulators visibility into real-world product performance beyond the pre-release evidence base.
AI governance and model risk professionals (by analogy, with caution)
The term is also used analogously in AI governance contexts to describe ongoing monitoring of deployed systems, and professionals in these fields may find the underlying concept useful. However, the medical-device and drug requirements described here are out of scope for AI-specific regulation and should not be assumed to carry the same obligations; practitioners should confirm the framework governing their own domain.

Inside PMS

Ongoing Performance Tracking
Continuous or periodic observation of a deployed system's behavior against expected outcomes, typically to detect drift, degradation, or unanticipated behavior after the system enters operational use.
Incident and Event Logging
Recording of malfunctions, anomalous outputs, complaints, or adverse events associated with the deployed system, so they can be investigated and, where applicable, reported to relevant parties or authorities.
Corrective Action Mechanisms
Processes for responding to identified issues, which may include retraining, recalibration, restriction of use, or withdrawal of the system. These are risk-reduction measures and do not eliminate risk.
Feedback Collection
Structured gathering of information from users, affected persons, or downstream operators to surface real-world issues that may not appear in pre-deployment testing.
Documentation and Record-Keeping
Maintenance of records describing monitoring activities, findings, and responses, which supports accountability and, in some frameworks, reporting or audit obligations.
Escalation and Reporting Pathways
Defined routes for raising significant findings to accountable functions or, where required by an applicable framework, to external supervisory or regulatory bodies.

Common questions

Answers to the questions practitioners most commonly ask about PMS.

Is post-market monitoring the same as ongoing model validation?
No, though the two overlap and are often confused. Post-market monitoring, as commonly framed, refers to observing an AI system's behavior and outcomes after it is deployed or placed on the market. Ongoing model validation is a broader activity within model risk management that assesses whether a model remains conceptually sound and fit for purpose, typically including independent review, benchmarking, and challenge of assumptions. Monitoring often feeds validation, but it does not replace it, and treating monitoring data as a substitute for periodic independent validation is a common error.
Does post-market monitoring guarantee that emerging risks or harms will be caught?
No. Post-market monitoring is a risk-reduction measure, not a guarantee. It increases the likelihood of detecting performance degradation, drift, or unexpected outcomes, but its effectiveness depends on the metrics chosen, the thresholds set, data availability, and the timeliness of review. Harms outside the monitored dimensions, or those that manifest slowly or in unmeasured subgroups, may still go undetected. Describing monitoring as eliminating post-deployment risk overstates what it can achieve.
What indicators are typically tracked in post-market monitoring?
Programs commonly track indicators such as predictive performance metrics, input and output data drift, changes in population or usage patterns, error rates, and outcome-based measures where ground truth becomes available. Some programs also monitor operational signals like latency or override rates. The appropriate indicators depend on the system's use case and risk profile, and selection should be justified rather than adopted by default. Out of scope here is any single mandated metric set, as requirements vary by framework and sector.
How often should post-market monitoring be performed?
Frequency is generally calibrated to the system's risk level, the volatility of its inputs, and the rate at which its environment changes. Higher-risk or fast-changing applications may warrant continuous or near-real-time monitoring, while more stable, lower-risk systems may be reviewed on a periodic schedule. There is no universally fixed cadence; the interval should be documented and defensible relative to the identified risks.
Who is responsible for post-market monitoring within an organization?
Responsibilities are often distributed across lines of defense. In many organizations, the business or model owner (first line) operates day-to-day monitoring, while risk or compliance functions (second line) set standards and provide oversight, and internal audit (third line) evaluates whether the process works as intended. The specific allocation varies by organizational structure and governance model, and clarity of ownership and escalation paths is generally emphasized over any single prescribed arrangement.
What actions should follow when monitoring detects a problem?
Detection is typically linked to predefined escalation and response procedures. Depending on severity, responses may include investigation of root cause, adjustment or retraining of the model, temporary restrictions on use, or decommissioning. Establishing thresholds, triggers, and documented remediation steps in advance is commonly regarded as good practice, since it reduces ad hoc decision-making. The appropriate response depends on the nature of the issue and the system's risk profile.

Common misconceptions

Post-market monitoring is the same as pre-deployment validation, just repeated over time.
Validation (assessing whether a model is suitable for its intended use before or during deployment) is conceptually distinct from post-market monitoring, which observes real-world behavior after deployment. Monitoring may draw on validation-like activities, but the two serve different purposes and should not be collapsed.
A robust monitoring program eliminates model risk.
Monitoring is a risk-management and detection measure that can reduce and help control risk by surfacing issues, but it does not remove inherent or residual risk from a deployed system.
Post-market monitoring obligations are uniform across all jurisdictions and frameworks.
The scope, terminology, and legal weight of monitoring expectations vary. What is framed as post-market monitoring in one instrument may appear as ongoing monitoring within a model risk management context in another. Practitioners should confirm which framework applies and whether it is binding law, guidance, or a voluntary standard before assuming specific requirements.

Best practices

Define measurable performance indicators and thresholds before deployment so that drift or degradation can be detected against a clear baseline rather than judged after the fact.
Distinguish monitoring of model performance degradation from monitoring for broader model risk, and design the program to capture both rather than assuming one covers the other.
Establish clear escalation and corrective-action pathways in advance, specifying who is accountable for investigating findings and authorizing responses such as retraining, restriction, or withdrawal.
Maintain contemporaneous documentation of monitoring activities, findings, and responses to support accountability and any applicable audit or reporting obligations.
Confirm which regulatory framework or internal policy governs the system and scope the monitoring program to its specific expectations rather than assuming requirements are interchangeable across jurisdictions.
Incorporate structured feedback channels from users and affected persons so that real-world issues not visible in pre-deployment testing can be surfaced and acted upon.