Hattrick IT
Regulated Agile · How we work

How do you run sprints and still satisfy the FDA?

Every sprint produces working software and the evidence regulators expect — requirement, design, tests and risk, story by story.

REQ · requirement DSN · design TEST · verification RISK · safety CYBER · security
Let’s talk about your product
Scroll — the methodology in four moves
Sprint 14 · Increment 7 Trace matrix current
Display patient risk score on dashboard
REQ ✓ DSN ✓ TEST RISK ✓
Two-factor login for clinicians
REQ ✓ DSN ✓ TEST ✓ CYBER ✓
Peer review in progress
Timestamp shown on stale data
REQ ✓ DSN ✓ TEST ✓ RISK ✓
Evidence in controlled repo
Grounded in IEC 62304 ISO 14971 ISO 13485 AAMI TIR45:2023 21 CFR 820.30

The model, in four moves.

A teaser of the methodology we bring to every engagement — the full playbook is what we build with you.

01

Think in layers.

Strategic decisions at the product layer. Synchronization and formal reviews at increment and release boundaries. Day-to-day regulatory work inside every story. Different deliverables belong at different levels — mixing them up is how teams end up doing Waterfall in sprint-sized chunks.

Product — set up once
Release — ↻ per release
Increment — ↻ per sprint
Story — ↻ requirement · design · tests · risk
02

The Definition of Done is the gate.

Approved requirement, documented design, traced tests, peer-reviewed code, updated risk assessment — a story that misses any of these isn’t done, period. It’s the mechanism that makes regulatory work happen at the story level instead of getting deferred.

Story S-12 · DoD check
Requirement approved → SRS
Detailed design documented → SDS
Tests executed & traced → V&V
Peer review complete → merged
Risk assessment updated → RMF
03

Documents assemble from parts.

No monolithic SRS written in one heroic sitting. Each story emits versioned, approved parts into a controlled repository; at increment boundaries the full documents are assembled — largely mechanically. Documentation stays current, reviews stay small, traceability is built in from the start.

REQ DSN TEST RISK
Controlled
repository
SRS SDS V&V
04

The whole team works concurrently.

Developers, tester, architect, RA/QA, UX and cybersecurity work in parallel within every sprint — on different stories at different stages. RA/QA isn’t a downstream gate; they’re in planning, running risk sessions, reviewing artifacts as they’re produced.

Project ManagerSoftware ArchitectDevelopersManual TesterRA/QA SpecialistUX/UI DesignerCybersecurity
Embedded in every sprint — not a gate at the end. Verification is never done by the author.

Prefer to read this offline? The full playbook — layers, DoD, team shape, documentation model — is a free 25-page PDF.

Get the whitepaper
Backed by a quality system

Process, not good intentions.

Our sprints run under SOPs backed by a QMS, with tooling that keeps traceability as objective evidence from day one. Compliance isn’t retrofitted — the records exist because the process produced them, reviewed and approved as the work happened.

SOPs under a QMSPlans in place before sprint 1Traceability from artifact creationNo DHF recreated after the fact

Curious what this looks like on your product?

Talk it through with us.

30 minutes with the people who run this model every sprint. No pitch deck.

Let’s talk
Or read the playbook first.

The full model in a free 25-page PDF, sent to your inbox.

Get the whitepaper