Skip to main content
Category: Monitoring & Drift

Post-Market Surveillance

Also known as: PMS, Postmarket Surveillance, Postmarketing Surveillance, Post-Market Monitoring
Simply put

Post-market surveillance is the practice of continuing to monitor a product for safety and performance after it has been approved and released for sale, rather than only assessing it beforehand. In the evidence provided, the term originates in the medical device and pharmaceutical sectors, where manufacturers collect and evaluate real-world experience once a product is in use. The goal is to catch problems that may only appear after wider deployment.

Formal definition

As commonly defined in the medical device and pharmaceutical contexts reflected in the evidence, post-market surveillance (PMS) refers to a set of activities conducted by manufacturers—and, in some jurisdictions, required of them—to systematically collect and evaluate experience gained from a product after it has been cleared, approved, or commercially released. In these sectors it typically encompasses monitoring the ongoing safety, effectiveness, and performance of the product in real-world use, with the aim of identifying, assessing, and responding to risks that emerge post-deployment. The evidence packet documents PMS specifically for medical devices (e.g., WHO guidance) and drugs (e.g., FDA/CDER postmarketing surveillance programs); it does not establish a definition, scope, or binding requirement for AI systems, governance frameworks, or model risk management, and the term's application to AI is not supported by the sources provided here.

Why it matters

Post-market surveillance addresses a fundamental limitation of pre-release evaluation: some safety and performance problems only become apparent once a product is used at scale, across diverse populations, and under real-world conditions that controlled pre-approval testing cannot fully replicate. In the medical device and pharmaceutical sectors reflected in the evidence, PMS is the mechanism by which manufacturers continue collecting and evaluating real-world experience after a product has been cleared, approved, or commercially released, allowing emerging risks to be identified and addressed rather than assumed away at the point of approval.

Because the evidence provided documents PMS specifically in the context of medical devices (for example, WHO guidance) and drugs (for example, FDA/CDER postmarketing surveillance programs), its significance here is best understood within those regulated domains, where ongoing monitoring is described as a manufacturer activity and, in some jurisdictions, a requirement. The sources do not establish a definition, scope, or binding requirement for AI systems, and any application of the term to AI governance or model risk management is not supported by the evidence packet. Readers working in AI contexts should treat conceptual parallels—continued monitoring after deployment—as analogies rather than as established regulatory equivalence.

Who it's relevant to

Medical device manufacturers
In the evidence, PMS is framed primarily as an activity conducted by manufacturers to collect and evaluate experience gained from medical devices after they have been cleared for sale. Some sources describe it as a requirement for medical devices, though the specific obligations depend on jurisdiction and are not fully detailed in the evidence packet.
Pharmaceutical regulators and drug safety teams
The FDA/CDER material referenced describes efforts to assure the ongoing safety and effectiveness of drug products currently marketed in the United States. Professionals responsible for drug safety monitoring within that jurisdiction encounter PMS as part of postmarketing surveillance programs, though scope beyond the U.S. context is not established by the sources here.
Quality and regulatory affairs professionals in regulated sectors
Those responsible for monitoring product safety and performance after commercial release rely on PMS as the structured process for evaluating real-world safety and efficacy. The evidence situates this work within the medical device and pharmaceutical domains.
AI governance and model risk professionals (with caution)
The concept of continued monitoring after deployment may resonate with practitioners of ongoing model monitoring, but the sources provided do not establish a definition, scope, or binding requirement for PMS as applied to AI systems, governance frameworks, or model risk management. Any use of the term in an AI context should be treated as an analogy that is not supported by this evidence.

Inside PMS

Ongoing Monitoring
The continuous or periodic observation of an AI system's behavior, inputs, and outputs after deployment to detect anomalies, drift, or performance changes over time. This is distinct from pre-deployment validation and focuses on the operating environment rather than the development phase.
Incident and Event Logging
The systematic recording of malfunctions, unexpected outcomes, or serious incidents arising from the system in production. Under the EU AI Act, providers of high-risk AI systems are typically expected to maintain such records; the specific reporting obligations and thresholds are defined by that framework and should not be assumed to apply outside its jurisdiction.
Corrective Action Mechanisms
Processes for responding to identified issues, which may include recalibration, retraining, restriction of use, or withdrawal of the system. These measures aim to reduce or manage risk rather than eliminate it.
Feedback and Data Collection Plan
A documented approach for gathering real-world performance data, user reports, and outcome data to inform whether the system continues to operate as intended. The scope of what data is collected varies by framework and sector.
Governance Roles and Escalation
The assignment of accountability for surveillance activities, including which line of defense conducts monitoring versus independent review, and how findings are escalated. This overlaps with, but is distinct from, model risk management's ongoing monitoring expectations.

Common questions

Answers to the questions practitioners most commonly ask about PMS.

Is post-market surveillance the same as ongoing model monitoring under model risk management?
Not exactly, though they overlap. Post-market surveillance is a term most closely associated with product-safety and certain regulatory regimes, referring to the systematic monitoring of a system's behavior after it has been placed into service or on the market. Ongoing monitoring under model risk management (as commonly framed by guidance such as SR 11-7) is a related discipline focused on tracking model performance and risk over time. The two share techniques but arise from different framings: one is typically oriented around continued conformity and safety obligations, the other around identifying, measuring, and controlling model risk. Treating them as interchangeable can cause professionals to overlook obligations specific to each. The precise scope depends on the applicable framework and jurisdiction.
Does having a post-market surveillance process mean the system's risks have been eliminated?
No. Post-market surveillance is a measure that helps detect, manage, and reduce risk after deployment; it does not eliminate risk. Its purpose is typically to identify emerging issues, performance changes, or unanticipated behavior so that corrective action can be taken. Residual risk generally remains even with an effective surveillance program in place, and the process itself has limitations tied to the quality of the data collected, the sensitivity of monitoring thresholds, and the timeliness of response. Describing surveillance as guaranteeing safety or compliance would overstate what such controls can achieve.
What signals or indicators are commonly tracked in a post-market surveillance process?
In many frameworks, surveillance tracks indicators that reveal changes in how a system behaves relative to its intended use and expected performance. These can include shifts in input data relative to what the system encountered during development, changes in output distributions or error patterns, incidents or complaints raised by users, and observed outcomes compared against expected outcomes. The specific indicators depend on the system's purpose, the risks it presents, and the requirements of the applicable framework, so a fixed universal list should not be assumed.
How should thresholds for escalation or corrective action be set?
Thresholds are typically defined so that meaningful deviations trigger review or corrective action, but the appropriate levels depend on the system's risk profile, its intended use, and organizational risk tolerance. Setting thresholds too tightly can generate excessive alerts, while setting them too loosely can delay detection of material issues. As commonly practiced, thresholds are documented, justified, and periodically revisited rather than fixed permanently. There is no single authoritative threshold applicable across contexts, so calibration to the specific use case is important.
Who is responsible for carrying out post-market surveillance within an organization?
Responsibilities are often distributed across organizational functions rather than held by a single owner. Under a lines-of-defense framing, operational teams that own and run the system typically perform day-to-day monitoring, while independent oversight functions may review the adequacy of surveillance and challenge findings, and internal audit may assess whether the overall process operates as intended. The precise allocation depends on the organization's governance structure and applicable requirements, and blurring these roles can weaken the independence that such structures are designed to provide.
How does post-market surveillance connect to the response and remediation process?
Surveillance is generally most effective when linked to defined pathways for investigation, escalation, and corrective action, so that detected issues lead to a response rather than remaining as observations. In many frameworks this connection includes documenting findings, assessing their significance, determining appropriate corrective or mitigating actions, and, where relevant, feeding lessons back into the system's development or controls. The specific steps, timelines, and reporting expectations vary by framework and jurisdiction, so the exact requirements should be confirmed against the applicable regime.

Common misconceptions

Post-market surveillance is the same as model validation.
Validation typically occurs before or at deployment to assess whether a model is conceptually sound and fit for purpose, whereas post-market surveillance concerns the system's behavior once it is in operational use. The two are related and complementary but are not interchangeable; surveillance may trigger revalidation but does not replace it.
Post-market surveillance requirements apply universally to all AI systems.
The term is most closely associated with the EU AI Act's obligations for providers of high-risk AI systems and is not a universal legal requirement across all jurisdictions or sectors. Other frameworks may address ongoing monitoring under different terminology, scope, and legal status, and these should not be treated as interchangeable.
Effective post-market surveillance means the deployed system carries no remaining risk.
Surveillance is a mechanism for detecting and managing risk after deployment, not for eliminating it. It reduces residual risk by enabling timely corrective action, but a monitored system still retains inherent and residual risk.

Best practices

Define clear monitoring metrics and thresholds before deployment so that anomalies, drift, and performance changes can be detected objectively rather than judged after the fact.
Maintain systematic incident and event logging, and confirm which reporting obligations and thresholds apply to your system based on its jurisdiction and risk classification rather than assuming a single standard.
Assign explicit accountability for surveillance activities, separating operational monitoring from independent review consistent with your organization's lines-of-defense structure.
Document a feedback and data collection plan that specifies what real-world data is gathered and how it feeds into decisions about recalibration, retraining, or withdrawal.
Establish escalation and corrective action pathways in advance so that identified issues lead to timely, proportionate responses that manage rather than merely record risk.
Treat surveillance findings as potential triggers for revalidation, keeping post-market monitoring distinct from, but connected to, pre-deployment validation activities.