Why change control is the central AI/ML compliance problem

Hardware medical devices do not spontaneously change their behaviour after certification. AI/ML SaMD does — or at least, it can. Model retraining on new data, drift correction, architecture updates, new training datasets, and threshold adjustments all have the potential to alter the clinical output of a certified device. Regulators wrote change control frameworks before AI was commonplace, and the criteria do not always map cleanly onto software.

The practical consequence is that AI/ML SaMD teams face a recurring compliance question with every release cycle: is this change significant enough to require regulatory notification — and if so, to whom, in which market, with what documentation? Getting this wrong in either direction is costly: notifying unnecessarily delays releases; failing to notify when required is a post-market non-conformity waiting to be found in the next surveillance audit.

The asymmetric risk: Under EU MDR, failing to notify a Notified Body of a significant change is a serious non-conformity that can result in suspension or withdrawal of the CE certificate. The burden of proof that a change was not significant sits with the manufacturer — and it must be documented.

The EU MDR framework: MDCG 2020-3

MDCG 2020-3 (Guidance on significant changes regarding the transitional provision under Article 120 of the MDR) defines what constitutes a significant change. Although originally written for the MDD transition context, it is also the operative guidance for post-certification change control under EU MDR Article 54 — the provision requiring manufacturers to notify their NB of changes that could affect conformity.

MDCG 2020-3 defines a significant change as any modification that could affect the device's safety or performance to a degree that requires a new conformity assessment, or that changes the intended purpose or indications. It then provides examples — but these examples were drafted primarily with hardware in mind.

Applying MDCG 2020-3 to AI/ML changes

For AI/ML SaMD, the key question under MDCG 2020-3 is whether a change could affect the clinical performance — the accuracy, sensitivity, specificity, or clinical decision output — of the device in a way that exceeds what was validated and certified. The following categories require particular attention:

What is generally not significant: Bug fixes that do not alter clinical output; security patches; UI improvements with no effect on clinical workflow; OS or platform adaptations; performance optimisations that produce identical clinical outputs; retraining within pre-specified performance bounds using data representative of the original validation population — provided all of these are documented and justified in the change control record.

The decision tree: does this change require NB notification?

EU MDR change assessment — AI/ML SaMD
Q1: Does the change affect intended use, indications, or target patient population?
YES → Significant change. NB notification required.
NO ↓
Q2: Does the change affect algorithm logic, model weights, inference thresholds, or training data scope?
YES → Proceed to Q3.
NO ↓
Q3: Do post-change performance metrics fall outside pre-specified acceptance thresholds?
YES → Significant change. NB notification required.
NO ↓
Q4: Does the change introduce new hazards or invalidate existing risk controls?
YES → Significant change. NB notification required.
NO → Non-significant change. Document justification. No NB notification required.
Critical prerequisite: Q3 only works if performance acceptance thresholds were pre-specified in the approved technical file before the change. If thresholds were not documented in advance, you cannot use post-hoc threshold comparisons to justify non-notification. Setting performance bounds upfront is not just good practice — it is the mechanism that enables compliant continuous improvement.

Comparison: EU MDR vs HSA CMP vs FDA PCCP

The three major frameworks for AI/ML SaMD change control share the same underlying concern — ensuring that post-market changes do not degrade clinical safety or performance — but differ significantly in architecture and in how much they can accommodate the continuous improvement reality of AI products.

Dimension EU MDR (MDCG 2020-3) Singapore HSA (GN-21 R6) FDA (PCCP framework)
Framework type Reactive — assess each change post-hoc against criteria Tiered notification — change category determines process Prospective — pre-approved change plan submitted with original application
AI-specific guidance None dedicated — MDCG 2020-3 applies general criteria; EU AI Act adds layer for high-risk AI from 2027/2028 Flowchart 2.5 in GN-21 R6 — dedicated ML model update pathway PCCP final guidance (Aug 2025) covers ML model modifications and retraining explicitly
Who approves changes Notified Body (if significant); manufacturer self-assessment (if not) HSA (Technical/Review changes); manufacturer self-declaration (Notification changes) FDA pre-approves the change plan; individual changes within plan don't require new submission
Algorithm retrain Significant if performance metrics change materially — NB notification required Technical change (HSA review) if clinical output affected; Notification if within GN-21 bounds Permitted without new submission if within pre-approved PCCP bounds
Speed for compliant updates Slow — NB review adds months per significant change Moderate — defined tiers give predictable timelines Fast — changes within PCCP scope require no FDA interaction
Documentation burden High — every change requires documented significance assessment regardless of outcome Moderate — tier determines required documentation Front-loaded — PCCP preparation is intensive; ongoing changes are light

What this means for EU-first AI/ML SaMD companies

The absence of a PCCP equivalent in EU MDR is a genuine operational constraint for AI/ML SaMD companies with continuous improvement cycles. Every significant algorithm change — even a well-validated, clearly beneficial retrain — requires NB notification and review, with associated delays. There is no mechanism to pre-approve a defined set of future changes the way FDA now allows.

The practical responses available to EU-certified AI/ML companies are:

Watch the EU AI Act: From December 2027 (Annex III) and August 2028 (Annex I product-embedded AI, including medical devices), high-risk AI systems under the EU AI Act will be subject to additional post-market monitoring and change notification requirements that overlap with — but are not identical to — EU MDR obligations. The interaction between MDR change control and EU AI Act obligations for AI/ML SaMD will require dual compliance mapping. See our EU AI Act and EU MDR guide for current deadlines and what to do now.

The change control record: what to document

Whether a change is assessed as significant or not, the change control record must be sufficient to demonstrate the assessment was performed rigorously. For AI/ML changes under EU MDR, the record should include:

Official sources & references