Services AI & ML Compliance

AI & Machine
Learning Compliance

PCCP GMLP SaMD

The algorithm is not just your product. It is your evidence. We help life sciences organizations navigate FDA's evolving AI/ML regulatory framework before it creates liability.

When software makes clinical decisions, the regulator examines the logic, not just the output.

Software that learns

An algorithm that changes after clearance is a regulatory event. We plan for the change, not just the snapshot.

FDA's approach to AI/ML is fundamentally different from traditional software regulation. The agency now expects sponsors to treat the algorithm's lifecycle as a continuous regulatory obligation, not a one-time validation exercise cleared with a 510(k) and forgotten.

Organizations that approach AI/ML compliance the way they approach legacy SaMD validation find out the difference when a Warning Letter arrives or a premarket submission is placed on hold.

The Algorithm Is the Label

For AI/ML-based SaMD, FDA evaluates training methodology, validation datasets, and performance specifications with the same scrutiny as a 510(k) predicate comparison, often more. The model's behavior in edge cases is now a regulatory question.

Post-Market Changes Are Not Free

Algorithm modifications after clearance, even to improve performance, can constitute a new device requiring a new submission. Without a Predetermined Change Control Plan filed and cleared by FDA, sponsors often learn this only after making the change.

The Standard Is Accelerating

FDA's Digital Health Center of Excellence, Good Machine Learning Practice principles, and PCCP guidance are producing new expectations faster than most compliance teams can absorb. A cleared device may not meet the standard against which it will be compared in the next review cycle.

Bring your AI/ML program to a senior regulatory partner before the submission, not after the Complete Response Letter.

Schedule a Strategy Call

The Full Lifecycle. Algorithm Design Through Post-Market Surveillance.

We do not treat AI/ML compliance as a checklist appended to a 510(k). Every engagement starts from where your algorithm sits in its lifecycle and builds a regulatory strategy outward from that point.

AI/ML SaMD Regulatory Strategy & Pathway Selection

Choosing the right regulatory pathway for an AI/ML-based device (De Novo, 510(k), or PMA) requires understanding both the predicate landscape and the agency's current review posture on the specific algorithm type. We map your AI/ML system against FDA's SaMD risk framework, identify predicate strategies, and structure your technical file to support the Total Product Lifecycle approach FDA now applies to adaptive systems.

  • SaMD risk classification
  • De Novo request strategy
  • 510(k) predicate analysis
  • TPLC architecture
  • DHCoE pre-Sub strategy

Predetermined Change Control Plans (PCCPs)

A PCCP filed at clearance gives sponsors a defined corridor for post-market algorithm updates without triggering a new submission for every modification. Writing a PCCP FDA accepts requires deep familiarity with what the agency has reviewed to date: it must be specific enough to be binding, yet broad enough to allow meaningful improvement — FDA's final guidance sets three required elements for the filing, not an open-ended narrative. We draft, negotiate, and file PCCPs across diagnostic, therapeutic, and monitoring AI/ML applications.

  • PCCP authoring & filing
  • Performance monitoring thresholds
  • Algorithm change protocols
  • FDA Q-sub strategy
  • Post-market change procedures

Good Machine Learning Practice (GMLP) Implementation

The joint GMLP principles published by FDA, Health Canada, and MHRA in 2021 define the floor for how regulators globally expect ML-based devices to be designed, trained, and validated. We translate these principles into operational quality system documentation: SOPs, design controls, data governance frameworks, and model governance structures, each aligned to satisfy multiple agency requirements in parallel.

  • GMLP gap assessment
  • Training data governance
  • Model governance documentation
  • Design controls for ML
  • Multi-agency alignment

Algorithm Validation, Testing & Bias Assessment

Validating an ML model for regulatory submission differs from standard software V&V. Test set independence, subgroup performance analysis, distributional shift assessment, and explainability requirements each introduce technical validation demands that traditional IQ/OQ/PQ frameworks do not address. We design validation protocols for diagnostic, therapeutic, and prognostic AI that satisfy FDA technical review standards and pre-empt the most common objections in AI/ML reviews.

  • Statistical performance evaluation
  • Subgroup & bias analysis
  • Test dataset independence
  • Explainability documentation
  • Distributional shift protocols

Post-Market AI/ML Surveillance & Performance Monitoring

AI/ML devices cleared under a PCCP, or any adaptive algorithm operating in real-world conditions, require active performance monitoring programs that detect model drift before clinical impact occurs. We design post-market surveillance architectures for AI systems: real-world data collection pipelines, statistical process control for model performance, adverse event evaluation for algorithm-driven errors, and MAUDE reporting protocols for AI-related events.

  • Model drift detection
  • Real-world performance monitoring
  • MAUDE AI reporting
  • Post-market data pipeline design
  • Adverse event evaluation

AI/ML in Drug Development & Pharmacovigilance

AI is not only a medical device regulatory question. It reaches into drug development: FDA-qualified biomarkers derived from AI models, AI-assisted clinical trial design under decentralized trial frameworks, digital endpoints, and AI-driven pharmacovigilance signal detection each carry distinct regulatory obligations under CDER and CBER oversight. We navigate these requirements across modalities, from AI-based diagnostic companion tests to ML-powered safety surveillance systems.

  • AI biomarker qualification
  • Decentralized trial AI strategy
  • Digital endpoint validation
  • Pharmacovigilance AI compliance
  • CDER/CBER AI frameworks
Neural network visualization representing an AI/ML medical model
The model is only half the submission

A capable algorithm still has to arrive as evidence a reviewer can accept under the FDA and CBER AI frameworks.

The Three Filings That Define an AI Device

Pathway, change plan, and the practice behind them.

SaMD Strategy

The right pathway is not always the obvious one.

FDA's risk framework classifies AI/ML devices by the significance of the information and the healthcare situation it informs. But the choice between De Novo and 510(k) also turns on predicate specificity and how stable your algorithm architecture is. We pick the pathway that fits the product, not just the flowchart.

Predetermined Change Control

The change you need tomorrow requires the filing you make today.

FDA's 2024 PCCP guidance lets sponsors describe, in advance, the algorithm modifications they intend to make post-market and the testing that will validate each one. A cleared PCCP is a license to keep improving the model without a new submission, but only if it is written well now.

Good Machine Learning Practice

International regulators are now reading your training documentation.

The joint FDA, Health Canada, and MHRA GMLP principles extended expectations across data management, model design, testing, human factors, and ongoing monitoring. We build the development record these principles now assume you kept all along.

Software and data pipeline behind a regulated AI/ML system
Traceability the principles assume

Good machine learning practice assumes a data and change record you kept all along. We build it in from the start.

Regulatory Landscape

Five Years of FDA AI/ML Policy. One Accelerating Standard.

FDA has moved from a discussion paper to an active regulatory framework faster than most organizations have adapted. Understanding where each guidance sits in the hierarchy, and which elements carry premarket review weight versus post-market inspection weight, is foundational to strategy.

Good Machine Learning Practice

Validation, bias, and change control wired into the model lifecycle, not audited in after.

2019
Discussion Paper: AI/ML-Based SaMD

FDA proposes a Total Product Lifecycle (TPLC) regulatory approach for AI/ML software as a medical device, recognizing that adaptive algorithms require ongoing oversight beyond initial premarket review.

2021
AI/ML-Based SaMD Action Plan

FDA formalizes a five-pillar action plan: good machine learning practice, algorithm transparency, representative datasets, real-world performance monitoring, and regulatory science tools. The framework becomes the template for subsequent guidance.

2021
Digital Health Center of Excellence Established

CDRH formally establishes the DHCoE to build regulatory science and provide a coordinated review point for digital health and AI/ML submissions across device categories.

2022–23
Good Machine Learning Practice: Joint Principles

FDA, Health Canada, and MHRA jointly publish GMLP principles covering data management, model design, validation, and monitoring. The international alignment signals that submissions must satisfy multiple regulatory bodies simultaneously.

2023
Draft PCCP Guidance

FDA releases draft guidance establishing the formal framework for Predetermined Change Control Plans: the mechanism allowing cleared devices to implement defined algorithm modifications without new premarket submissions.

2024
PCCP Final Guidance & Expanded AI Policy

FDA finalizes PCCP guidance and extends AI oversight into drug development, pharmacovigilance, and decentralized clinical trials under CDER and CBER jurisdiction. AI compliance is no longer exclusively a device question.

Now
Active Standard Under Active Enforcement

Regulators are examining AI/ML systems in premarket submissions, post-market inspections, and pharmacovigilance audits against the full body of GMLP, PCCP, and TPLC expectations. Organizations without mature AI compliance programs face increasing submission delays and inspection findings.

Regulatory Practitioners. Not AI Vendors.

Our AI/ML compliance work is done by senior regulatory professionals who have managed SaMD submissions at FDA and in industry, not by software engineers or data scientists who have pivoted into regulatory consulting. The distinction matters when submissions are under review.

SaMD Submission Experience

Practitioners with direct experience managing 510(k), De Novo, and PMA submissions for software-only and AI/ML-driven devices across diagnostic imaging, clinical decision support, and continuous patient monitoring applications.

CDRH Division Relationships

We track review posture by CDRH division and product code for AI/ML applications. Where you submit and how you frame the algorithm matters; we bring the pattern recognition that comes from following cleared submissions across the landscape.

Quality System Depth

AI/ML compliance failures often live in the quality system, not the submission. We design QMS extensions (model governance, design control integration, training data traceability) that satisfy both FDA 21 CFR 820 and ISO 13485 requirements simultaneously.

Global Regulatory Alignment

An AI/ML device cleared in the U.S. faces separate, and not always harmonized, requirements in Europe (EU MDR AI Act obligations), Japan (PMDA), and Canada (Health Canada SaMD framework). We plan for all markets from the initial regulatory strategy.

Data scientist reviewing an AI/ML model for regulatory readiness

Regulatory Frameworks We Navigate

  • FDA AI/ML SaMD Action Plan
  • GMLP Joint Principles
  • 21 CFR Part 820 QSR
  • 21 CFR Part 11
  • ISO 13485:2016
  • EU MDR 2017/745
  • EU AI Act
  • IEC 62304
  • IMDRF SaMD Framework
  • PMDA AI Guidance
  • Health Canada SaMD

Your AI/ML Regulatory Strategy Starts With a Conversation.

Tell us where your algorithm is in its lifecycle (development, pre-submission, cleared, or post-market) and we'll identify the highest-risk regulatory gaps and the fastest path to address them. All inquiries are strictly confidential.