MedTechCompass
by CAHIR Solutions
Compliance & governance

An AI compliance framework for medical device teams

Medical device development sits at the intersection of quality-system regulation, risk management, software lifecycle controls, data integrity, and emerging AI governance. This page summarizes the compliance frameworks MedTechCompass is designed to align with when it produces medical device market scoring and regulatory triage — why each matters, and which device classes and product types they most directly affect. For broader medical device market intelligence and global FDA pathway coverage, see medtech.cahir.ai.

Framework summaries

Standards by risk class and product type

  • FDA QSR / 21 CFR Part 820

    The U.S. Quality System Regulation defines design controls, purchasing controls, production/process controls, CAPA, and record-keeping expectations for medical device manufacturers.

    Relevant to

    • Class II and Class III devices sold in the United States
    • Any device requiring a 510(k), De Novo, or PMA submission
    • Manufacturers establishing a U.S. quality management system
  • EU MDR 2017/745

    The European Medical Device Regulation governs device classification, clinical evidence, post-market surveillance, and CE marking requirements across EU member states.

    Relevant to

    • All classes of devices placed on the EU market (Class I, IIa, IIb, III)
    • Products requiring a notified-body conformity assessment
    • Legacy MDD certificates transitioning to MDR
  • UK MDR 2002 / UKCA

    Post-Brexit UK medical device rules maintain CE-recognition timelines while introducing UKCA marking and Approved Body oversight for Great Britain.

    Relevant to

    • Devices marketed in England, Scotland, and Wales
    • Manufacturers transitioning from CE to UKCA marking
    • Class I measuring/sterile devices and higher-risk classes
  • ISO 13485

    The international quality-management standard for medical devices emphasizes risk-based processes, traceability, design control, and supplier management.

    Relevant to

    • All risk classes seeking a globally recognized QMS
    • EU MDR and UKCA quality-system evidence
    • Manufacturers pursuing FDA QSR alignment
  • ISO 14971

    The risk-management standard for medical devices provides a framework for hazard identification, risk estimation, evaluation, control, and residual-risk acceptability.

    Relevant to

    • Class II and Class III devices with clinical or biological risks
    • SaMD and connected devices with cybersecurity or algorithmic risks
    • EU MDR and FDA design-control documentation
  • IEC 62304

    The medical-device software lifecycle standard defines activities for software development, maintenance, risk management, and change control.

    Relevant to

    • Software as a Medical Device (SaMD)
    • Embedded software in Class II/III hardware
    • AI/ML-enabled devices with software updates
  • IEC 62366-1

    Usability-engineering standard focused on reducing use-related risks through user research, interface evaluation, and human-factors validation.

    Relevant to

    • Devices with complex user interfaces or high use-error risk
    • Class II/III devices where human factors are critical to safety
    • SaMD with clinician or patient-facing workflows
  • 21 CFR Part 11

    Defines requirements for electronic records, electronic signatures, audit trails, and system validation in FDA-regulated environments.

    Relevant to

    • Electronic QMS, batch records, and design-history files
    • Clinical and regulatory submissions prepared electronically
    • Cloud-based tools used in GxP workflows
  • FDA AI/ML-Based SaMD & GMLP

    FDA guidance and Good Machine Learning Practice principles cover model development, validation, transparency, real-world performance monitoring, and change control for AI-enabled devices.

    Relevant to

    • AI/ML diagnostic, predictive, or monitoring devices
    • SaMD with continuously learning or updated algorithms
    • Products subject to FDA's predetermined change control plans
  • EU AI Act

    The EU's risk-based AI regulation imposes transparency, quality-system, data-governance, and human-oversight obligations on high-risk AI applications, including certain medical devices.

    Relevant to

    • AI-enabled devices classified as high-risk under the AI Act
    • Products placed on the EU market with AI-driven decision support
    • SaMD and clinical decision-support systems
  • NIST AI Risk Management Framework

    A voluntary U.S. framework for governing, mapping, measuring, and managing AI risks across the total product lifecycle.

    Relevant to

    • AI/ML-enabled devices regardless of risk class
    • Organizations building internal AI governance programs
    • Teams aligning AI risk management with cybersecurity and safety
  • GDPR / HIPAA

    Privacy and security regulations governing personal data processing in the EU (GDPR) and protected health information in the U.S. (HIPAA).

    Relevant to

    • Devices collecting, transmitting, or storing patient data
    • Connected devices and cloud-based SaMD
    • Clinical studies and real-world evidence platforms
  • ISO 27001

    The information-security management standard for establishing, implementing, maintaining, and continually improving an ISMS.

    Relevant to

    • Connected devices and cloud-hosted medical-device platforms
    • Organizations handling sensitive regulatory and clinical data
    • Supplement to FDA cybersecurity guidance and EU MDR Annex I
  • SOC 2

    A service-organization control framework covering security, availability, processing integrity, confidentiality, and privacy of customer data.

    Relevant to

    • SaaS platforms used by regulated customers
    • Vendor due diligence for enterprise MedTech buyers
    • Complement to ISO 27001 for U.S. market trust
  • ALCOA+ Data Integrity

    A set of principles ensuring data is Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, and Available across GxP systems.

    Relevant to

    • All regulated data used in design, clinical, and post-market records
    • Electronic records subject to 21 CFR Part 11
    • Audit trails, scoring lineage, and evidence registers

How to read this page

MedTechCompass is a market-intelligence and decision-support tool developed by CAHIR Solutions. It is not itself an FDA-regulated medical device, a notified-body certification, or a legal/regulatory consulting service. The summaries above describe how our internal data practices, scoring workflows, audit logs, and AI governance controls are designed to align with these frameworks. Alignment does not mean certification, accreditation, or formal regulatory approval. Customers should always validate compliance strategy with qualified regulatory, quality, and legal advisors.

See how MedTechCompass puts this into practice

Read the brand story, mission, and audience, or start building your market entry plan with the free checklist.