Predetermined Change Control Plans for Learning Systems

Effective change control is central to maintaining compliance and quality in medical device software systems. In the context of AI-based software as a medical device, change control must be formalised through predefined plans that align with regulatory expectations. These plans ensure that any modifications to AI systems are reviewed, tested, and approved before implementation. The MHRA and EU regulatory frameworks expect organisations to have documented processes for managing software updates, including those derived from AI models or machine learning algorithms.

Lesson concept diagram

Establishing a Change Control Framework

A predetermined change control plan must clearly define roles, responsibilities, and approval pathways. For example, a clinical software team may identify a new machine learning model version that improves diagnostic accuracy. The change control process must specify who evaluates the impact, who tests the updated software, and who authorises deployment. The plan should also identify the type of change, such as a minor update or a major revision, and assign appropriate levels of scrutiny. The plan must align with ISO/IEC 42001:2023, which requires documented processes for managing AI systems throughout their lifecycle. This includes defining what constitutes a change, how it is logged, and how it is reviewed against safety, performance, and regulatory requirements.

  • Roles must be clearly defined, such as software engineer, clinical reviewer, and regulatory affairs specialist
  • All changes must be logged in a centralised system with timestamps and version control
  • Each change must undergo risk assessment, including clinical and technical impact

Change Control for AI Models and Algorithms

Changes to AI models or algorithms require special attention due to their potential impact on clinical outcomes. For instance, an AI-based diagnostic tool used for detecting diabetic retinopathy must undergo rigorous validation if its underlying machine learning model is updated. The change control plan must specify that such updates are reviewed by clinical experts, data scientists, and regulatory specialists. The plan must also ensure that any change is tested against clinical data to confirm that it does not reduce accuracy or introduce bias. The EU AI Act, which became enforceable in February 2025, places obligations on organisations to ensure AI systems do not fall into prohibited categories. Changes to AI models must not reintroduce these prohibited practices, such as social scoring or real-time biometric identification.

In addition, the Digital Omnibus on AI, which came into force in July 2026, introduces new obligations for AI systems placed on the market before August 2026. These systems must meet machine-readable marking by December 2026. This requirement affects change control processes, as any updates must ensure that the AI system remains properly identified and traceable. The plan must include steps to maintain or update machine-readable data, such as model versions, training data sources, and usage conditions.

Predetermined Change Control Plans for Learning Systems

Implementation and Ongoing Monitoring

A successful change control plan must be embedded into daily operations. For example, a clinical software team updating an AI-based clinical decision support tool must submit a change request through a formal process. The request must include clinical validation data, risk assessment, and impact analysis. The plan must also specify that any change is reviewed by the clinical governance team and that clinical staff are informed of updates. The MHRA and EU expect these processes to be repeatable and auditable. Regular audits of the change control process ensure that it remains effective and aligned with evolving regulatory expectations.

Organisations must also consider the implications of AI certification under ISO/IEC 42001:2023. The standard requires that AI systems are managed through a defined process, including change control. The first UKAS-accredited certification body, BSI, began offering certification in January 2026. Companies that have adopted this standard must ensure that their change control plans meet the requirements of clause 7.4, which addresses the management of AI systems through defined processes. The certification body ISO/IEC 42006:2025 provides guidance on how these processes are reviewed and verified.

In summary, a well-structured change control plan is essential for maintaining regulatory compliance and clinical safety. The plan must be adaptable to AI-specific considerations, such as model updates, data drift, and clinical validation. Regular updates to these plans ensure alignment with evolving regulatory frameworks such as the EU AI Act and the Digital Omnibus on AI. The goal is to ensure that any change to an AI-based medical device software is safe, traceable, and compliant with current standards.