The method is not a new standard layered on top of existing ones. It is the disciplined application of the clauses already in force — applied to a class of technology they were never written for, and structured so that every deployment can be evidenced on demand.
Mapping: Where AI Already Lives in the QMS
Every artificial intelligence deployment in the production environment already falls under governing clauses. The framework locates each one — across device manufacture and in vitro diagnostics. Whether a vision system runs on fixed rules or deep learning, the clause map is the same; the intensity of evidence varies.
7.1.5 — Monitoring and Measuring Resources (Device Manufacture). Vision systems that accept or reject product: cameras inspecting seals, welds, labels, and fill volumes against geometric, chromatic, and dimensional reference parameters. Deep learning versions trained on thousands of conforming and defective images classify each new specimen — and unlike a gauge or a caliper, whose fitness for purpose is demonstrated once through calibration, a learning model can degrade after deployment. Sensors feeding predictive maintenance models and automated measurement chains complete the picture.
7.1.5 — Monitoring and Measuring Resources (IVD). Digital pathology and slide image analysis: algorithms that quantify immunohistochemical markers, classify staining patterns, and pre-screen abnormal cells. Here the vision system operates on material that is biologically variable by nature, not on printed geometries. Model drift is not merely technical: the biological population differs between laboratories and changes over time — a model trained on one clinical dataset degrades precisely where it is deployed on another. Added to this, the interpretation of analytical signal: software correlating amplification curves, reaction kinetics, and analyzer raw data to call results, flag interference, or suggest re-runs — functions that in the IVD perimeter almost always constitute device software and fall under the IVDR. And the validation of assays with machine learning components: kit continuous improvement, interpretation of internal quality controls, and out-of-trend lot flagging, where lot stability monitoring — established practice with classical statistical tools — becomes predictive and less transparent when delegated to a model.
8.4 — Externally Provided Processes, Products and Services. Where AI is procured as a service — inspection platforms, analytics SaaS, algorithm vendors — supplier controls require evaluation, selection, and re-evaluation criteria that address model updates the supplier ships without notice.
8.5.1 — Control of Production. Algorithms that steer maintenance schedules, line adjustments, or release decisions are production controls. Their output must be traceable to defined acceptance criteria, and a model whose behavior drifts silently is a production process drifting without review. For measuring resources across both worlds, fitness for purpose is demonstrated against clinical reference data and control materials — never as a snapshot certificate.
Software Lifecycle — IEC 62304. Where models reside in device or IVD software, the software lifecycle governs them: architecture, risk management linkage (ISO 14971), and verification activities proportionate to software safety classification. Under the IVDR, software that supports diagnostic decisions is device software in its own right — classification, clinical performance evidence, and post-certification change control all apply.
Jurisdictional Overlay
The clause architecture is universal. Each jurisdiction asks its own questions on top of it.
United States — QMSR. The same architecture applies within 21 CFR Part 820, together with FDA guidance on machine learning-enabled device software functions and change control plans for models that evolve after clearance.
European Union — MDR/IVDR and the AI Act. Software with a diagnostic function enters at elevated risk classes under the IVDR, with notified body scrutiny of clinical performance and post-certification change. A model that updates after certification collides with the significant-change regime toward the notified body — a collision no standard resolves. The EU AI Act adds a further layer: AI-enabled medical and IVD devices qualify as high-risk as third-party conformity-assessed products under the MDR or IVDR, with additional requirements on data governance, transparency, and documentation that the quality system is the natural place to absorb.
Switzerland — MedDO/IVDO. Switzerland replicates the European logic with institutions of its own: swissdamed, separate technical evaluation, separate market authorization. Every consideration above doubles — consistent with the dual-access architecture. Federal data protection law and, where clinical data are involved, human research legislation add a further perimeter the QMS must reconcile.
The Evidence Architecture
Mapping establishes where the model lives. The evidence architecture establishes that it is governed.
Each deployment receives four documented elements: a defined intended use stating what the model does and does not decide; a controlled data lineage tracing inputs, training references, and changes; a validated change management regime for models that evolve after deployment; and documented human oversight where outputs touch product, patient, or release. The transparency that matters is documentary — control over the evidence, not visibility into the inner workings of the model.
The principle throughout is one the regulated industry already knows: no technology validates itself. The deployment owner does not certify its own evidence — independent verification, internal audit, and the external certification cycle close the loop.
Readiness
An organization that completes this framework holds a quality system in which every AI deployment is mapped, evidenced, and defensible in audit across every jurisdiction it serves — and reaches full independence in operating it. The engagement ends when the system runs without us.