The Silent Component

AI Governance & ISO 13485

Artificial intelligence has already entered the regulated production environment. Vision systems determine product quality. Predictive models steer maintenance. Machine learning drives diagnostic software and automated decision paths in devices themselves.

The quality management system is expected to control these processes. It is audited on them. And yet no quality management standard — not ISO 13485, not the QMSR, not the newly published ISO 9001:2026 — contains a single clause that defines how a system which learns and changes after deployment is to be governed, validated, or evidenced.

The Unregulated Interior

Manufacturers are not waiting for the law. They are deploying AI now — in production controls, in supplier-facing systems, in software-defined devices — and carrying it into every audit.

The consequence is a structural exposure. Auditors confront machine learning through interpretations of clauses written for static processes. Manufacturers hold certifications that say nothing verifiable about their most volatile technology. Evidence of control exists — or fails to exist — in a space no standard has mapped.

That exposure has a price today: audit findings that no revision instruction anticipates, vendor qualifications suspended on questions no one can answer, and device documentation that cannot demonstrate control over functions the product actually performs. The constraint is not capability and it is not capital. It is the absence of an architecture designed for the problem.

The Resolution

We engineer the governance of artificial intelligence inside the existing quality system — not beside it, not in a parallel silo of aspirational principles.

The method maps every AI deployment in the production environment to the clauses that already govern it: monitoring and measurement resources (7.1.5), externally provided processes (8.4), production controls (8.5), and software lifecycle management under IEC 62304 where models reside in device software, together with FDA guidance on machine learning-enabled devices where the U.S. market applies.

Each deployment receives its evidence architecture: defined intended use, controlled data lineage, validated change management for models that evolve, and documented human oversight where decisions touch product or patient.

Where an organization extends beyond medical technology, the same architecture connects to ISO/IEC 42001 — the AI management system standard — and to the compliance frameworks regulators and counterparties increasingly request. One system, one chain of evidence.

Outcome

The result is a certified quality system in which artificial intelligence is not an ungoverned passenger but a controlled, auditable component — defensible before Notified Bodies, Swissmedic, and the FDA, in the audits that are already taking place, not the ones still being drafted.

Organizations that build this now set the terms of the audit. Those that wait inherit them.

Read The Framework →