IEC 62304 Software Life Cycle Processes for AI Products

The IEC 62304 standard provides a framework for managing the software life cycle of medical devices. When applied to AI products, these processes must align with both the clinical and regulatory expectations of software as a medical device (SaMD). The life cycle processes defined in IEC 62304 apply to AI software through the identification, design, development, verification, validation, and maintenance of machine learning models and algorithms. These processes must be tailored to accommodate the unique characteristics of AI, such as data dependency, model adaptability, and evolving performance.

The software life cycle begins with the establishment of a software life cycle process plan. This plan must detail how AI-specific activities such as data governance, model training, validation, and monitoring will be managed. For example, a clinical decision support system using machine learning must have documented processes for data selection, annotation, and validation. The plan must also identify roles and responsibilities, including those of data scientists, clinical specialists, and regulatory affairs staff. The software life cycle process plan must be reviewed and updated through the life cycle, especially when there are changes to the AI model or clinical use.

The design and development phases of AI software must focus on clinical benefit, safety, and effectiveness. Design inputs must clearly define clinical needs, user requirements, and performance criteria. For instance, an AI-based diagnostic tool must have clinical requirements such as sensitivity, specificity, and clinical utility. Design outputs must reflect these inputs through detailed software architecture, data flow diagrams, and algorithmic specifications. The development phase involves building the software, including training machine learning models, implementing data pipelines, and integrating clinical workflows. Regular design reviews must occur to ensure that the AI software meets clinical and regulatory expectations.

Lesson concept diagram

The verification and validation processes are critical for AI software. Verification ensures that the software meets its design specifications. In AI development, this involves checking that models are trained correctly, data is processed as intended, and software functions as designed. Validation confirms that the software fulfills its intended clinical use. For example, a clinical AI tool must be validated through clinical trials or clinical evaluation to demonstrate its effectiveness in real-world clinical settings. The validation process must include testing with clinical data that reflects the intended use and clinical environment.

The software life cycle must also include post-market surveillance and maintenance. AI models may degrade over time due to data drift or changing clinical practices. Regular monitoring of model performance, including metrics such as accuracy, recall, and clinical relevance, must be performed. For example, an AI tool used for image analysis must be reviewed periodically to ensure it continues to perform reliably. Updates or retraining of models must be managed through a change control process, ensuring that any modifications are reviewed, tested, and documented. The software life cycle must also accommodate clinical feedback, adverse event reporting, and updates to clinical guidelines.

The software life cycle processes must align with regulatory expectations under the EU AI Act. The AI Act introduces new obligations for AI systems, including transparency, data governance, and risk management. These obligations must be embedded into the software life cycle through processes such as risk assessment, data quality management, and audit trail documentation. For example, an AI system used for clinical decision-making must have documented risk assessments addressing potential biases or data limitations. The software life cycle must also ensure that AI systems meet the transparency requirements of Article 50, including machine-readable marking for systems placed on the market before 2 August 2026.

The software life cycle must also consider the AI management system standard, ISO/IEC 42001:2023. This standard provides guidance on establishing, implementing, and maintaining an AI management system. The processes defined in IEC 62304 must be aligned with the AI management system framework. For example, the AI management system must include processes for AI governance, data management, and model lifecycle management. The software life cycle must ensure that these processes are integrated into daily operations, including training staff, documenting decisions, and conducting regular audits.

IEC 62304 Software Life Cycle Processes for AI Products

The software life cycle must also accommodate the evolving regulatory environment. The EU AI Act introduces new obligations that must be incorporated into software development processes. For example, AI systems must meet AI literacy requirements under Article 4, which apply from 2 February 2025. The software life cycle must ensure that clinical staff and developers are trained on these requirements. The software must also meet transparency obligations under Article 50, which apply from 2 August 2026. The software life cycle must include processes for machine-readable marking of AI systems placed on the market before that date.

The software life cycle must also consider the Digital Omnibus on AI, which defers certain obligations. The high-risk AI obligations under Annex III apply from 2 December 2027, while embedded-product AI obligations apply from 2 August 2028. The software life cycle must plan for these future obligations, including updating documentation, processes, and clinical validation as needed. The software life cycle must also ensure that clinical data used for AI development meets the data governance requirements of the AI Act.

The software life cycle processes must be reviewed and updated through the life cycle. Regular reviews ensure that the processes remain aligned with clinical needs, regulatory expectations, and technological developments. The software life cycle must also accommodate clinical feedback, clinical trials, and clinical evaluation data. These processes must be documented, reviewed, and maintained through the life cycle. The software life cycle must also ensure that clinical staff, developers, and regulatory specialists collaborate effectively to maintain clinical relevance and regulatory compliance.