Skip to main content
METHODOLOGY ASSESSED
All frameworksHealth & Life Sciences

Where AI/ML medical software meets safety classification

Medical device software already carries a formal safety classification under IEC 62304 — Class A (no injury possible), B (non-serious injury possible), or C (death or serious injury possible) — that determines how rigorously it must be developed, documented, and maintained. AI/ML-based Software as a Medical Device adds a specific wrinkle regulators have been actively building guidance for since the early 2020s: these models can change after approval through retraining, so the FDA and international partners built Good Machine Learning Practice (GMLP) and Predetermined Change Control Plans (PCCPs) to govern that.

Reference standard
IEC 62304, FDA GMLP & PCCP
IEC · US FDA · IMDRF (Health Canada, MHRA, FDA)
Rating concept
Software Safety Classification A / B / C
IEC 62304's classification of a software item by the severity of harm a failure could cause a patient.
Positioning

What AIC maps, and against what

AIC maps AI/ML-based medical software and clinical decision-support tools against the IEC 62304 safety-classification discipline and the emerging GMLP/PCCP framework for how such software is allowed to change over time. This applies to organisations building or deploying AI-assisted diagnostic, monitoring, or clinical decision-support software — not to clinical practice itself, and not as a substitute for FDA, MHRA, or other regulatory clearance.

Translation

The established concept, and its AI equivalent

EstablishedAI equivalentWhat it means here
IEC 62304 safety classification (A/B/C)AI/ML software safety classificationThe same severity-of-harm classification applied to the AI component's role in the device or software.
Design history / lifecycle documentationGMLP data & training documentationTraining data representativeness, held-out validation, and algorithm limitations documented as part of the software lifecycle record.
Change controlPredetermined Change Control Plan (PCCP)Anticipated model updates are pre-specified and bounded, rather than each retraining requiring a fresh, unplanned review.
Post-market surveillanceOngoing model performance monitoringThe model's real-world performance is tracked after deployment, not assumed to hold indefinitely from validation-time results.
Labelling & disclosureML-use disclosureEnd users are told the device incorporates machine learning and, where relevant, that a PCCP governs how it may change.
Assessed Against

The safety measures a subject demonstrates

01

Documented safety classification

The AI component's role has been classified for severity of potential harm, consistent with IEC 62304 discipline.

02

GMLP-aligned development record

Training data, validation approach, and known limitations are documented, not just the model's headline performance.

03

A defined change-control plan

How the model is allowed to change post-deployment is pre-specified and bounded, not open-ended.

04

Post-deployment monitoring

Real-world performance is tracked on an ongoing basis, with a path to act if it degrades.

05

Clear ML-use disclosure

Clinicians and patients are told, plainly, that machine learning is part of the software they're relying on.

Where this mapping has limits

The PCCP framework was only finalised in December 2024 and is still maturing through 2025–2026 — practice and regulatory expectations are evolving faster than in the more settled parts of IEC 62304. This mapping is US-FDA-centric by default; the EU (MDR/IVDR), UK, and other regulators apply related but distinct requirements, and AIC's assessment does not substitute for any regulator's clearance process. Most importantly, none of this replaces clinical judgement — it maps the software governance around an AI tool, not the clinical decision a practitioner makes using it.

Reviewed 2026-09-01.

Want to talk through how this applies to your organisation?

Contact us