UK Routes to Market: UKCA, the MHRA and Northern Ireland


This lesson explains the UK’s regulatory pathways for medical device software, focusing on UKCA conformity, the role of the Medicines and Healthcare products Regulatory Agency (MHRA), and special considerations for Northern Ireland. The UK’s departure from the EU has created distinct regulatory frameworks, which must be carefully navigated by compliance and governance teams.
UKCA Conformity and the MHRA
Medical device software placed on the UK market must meet UKCA (UK Conformity Assessed) requirements. The MHRA is the UK’s regulatory authority for medical devices, including software as a medical device (SaMD). The MHRA administers the UK’s medical device regulations, which are aligned with the EU’s Medical Device Regulation (MDR) but have distinct UK-specific elements. For example, UKCA certification is required for software that meets the definition of a medical device under UK law. The MHRA provides guidance through its website and through its designated notified bodies, which are now UK-based or UK-accredited.
Organisations must ensure that their software meets the applicable UK regulatory requirements, including clinical evaluation, risk management, and post-market surveillance. The MHRA’s website lists the UK’s designated conformity assessment bodies, which are responsible for issuing UKCA certificates. These bodies must be recognised by the UK government, and their names are listed on the MHRA’s official register. Companies must also submit clinical evaluation reports and technical documentation to support their UKCA claims. The MHRA’s approach to software as a medical device is similar to the EU approach, but with distinct UK processes and timelines.
- UKCA certification is required for software classified as a medical device under UK law
- The MHRA is the UK’s regulatory authority for medical devices
- UK-based or UK-accredited conformity assessment bodies issue UKCA certificates
Special Considerations for Northern Ireland
Medical device software placed on the Northern Ireland market must comply with EU regulations, including the EU MDR. The Northern Ireland Protocol allows for this dual regulatory framework. Companies must ensure that their software meets both EU and UK regulatory requirements if they intend to place it on both markets. The MHRA provides guidance for businesses operating in Northern Ireland, including advice on how to maintain compliance with EU rules. The EU’s clinical evaluation and post-market surveillance requirements apply to software placed on the Northern Ireland market, even if it is also placed on the UK mainland.
Organisations must maintain two separate compliance pathways for software placed on both the UK and Northern Ireland markets. The EU MDR applies to software placed on the Northern Ireland market, which means clinical evaluation, clinical investigations, and post-market surveillance must meet EU standards. The MHRA provides support through its Northern Ireland-specific guidance documents, which outline the differences between EU and UK regulatory frameworks. Companies must also ensure that clinical data and clinical evaluation reports meet EU clinical data requirements, including clinical investigations and clinical evaluation reports.
- Software placed on the Northern Ireland market must meet EU MDR requirements
- Companies must maintain two compliance pathways for UK and Northern Ireland
- The MHRA provides Northern Ireland-specific guidance documents
UK AI Regulatory Framework
The UK’s approach to AI regulation is evolving, with the EU AI Act applying to AI systems placed on the EU market. The UK is developing its own AI regulatory framework, which includes the Digital Omnibus on AI Regulation (Regulation (EU) 2026/1744). The UK government is aligning its approach with EU AI Act principles, but with distinct UK-specific elements. The UK’s AI regulatory framework includes obligations for high-risk AI systems, including transparency, human oversight, and data governance. The MHRA is responsible for overseeing AI-related medical device software, including clinical evaluation and post-market surveillance.
Organisations must ensure that AI-based software meets UK AI regulatory requirements, including those related to AI management systems. The ISO/IEC 42001:2023 standard provides guidance for AI management systems, and certification bodies such as BSI have been accredited to provide certification. The MHRA’s guidance documents provide practical advice for software developers, including clinical evaluation, risk management, and post-market surveillance. The UK government is also introducing AI literacy duties, which apply to public sector organisations, and these must be considered by compliance teams.
- UK AI regulatory framework aligns with EU AI Act principles
- ISO/IEC 42001:2023 provides AI management system guidance
- The MHRA oversees AI-related medical device software
Understanding these pathways is essential for compliance and governance staff. The UK’s regulatory environment requires careful attention to both UKCA and EU MDR requirements, particularly for software placed on the Northern Ireland market. The MHRA’s guidance and support are central to navigating these frameworks. The UK’s AI regulatory developments, including the Digital Omnibus on AI, must also be considered by organisations developing AI-based medical device software. The MHRA’s approach to clinical evaluation, clinical investigations, and post-market surveillance remains central to UK regulatory compliance. Companies must stay informed of evolving regulatory expectations and ensure that their software meets all applicable UK and EU requirements.
