
ISO/TS 24971-2:2026 / Guidance on the application of ISO 14971 - Part 2: Machine learning in AI
ID 26897 | 13 Agosto 2026 / Preview attached
ISO/TS 24971-2:2026
Medical devices - Guidance on the application of ISO 14971 - Part 2: Machine learning in artificial intelligence
Valid from 17.06.2026
This document provides guidance on risks specific to artificial intelligence (AI) and machine learning (ML) and how to apply the risk management process of ISO 14971 to ML-enabled medical devices (MLMD). This document is intended to be used in conjunction with ISO 14971 and ISO/TR 24971.
This document does not apply to MLMD employing large language models (LLM) or generative AI.
Artificial intelligence (AI) is rapidly advancing and offers transformative potential for the healthcare sector. These advantages can be related to improved benefits for the patient, increased efficiency in clinical workflows and more effective management of healthcare overall. However, the implementation of new technologies such as AI can also present new risks and can, for example, jeopardize patient safety, affect privacy and security, influence user actions, undermine trust in healthcare or adversely affect the management of healthcare.
The safety and effectiveness of AI in medical devices was explored in an AAMI-BSI document[16], which identified three ways in which AI-based medical devices differed from “traditional” (non-AI) medical devices:
This document focuses on machine learning (ML) techniques and is restricted to ML-enabled medical devices (MLMD). Machine learning is considered a subset of AI that involves an ML model and an ML algorithm.
The ML model and the ML algorithm are the results of the concept development for a new MLMD, together with acceptance criteria for the eventual MLMD. It is noted that the supporting infrastructure (computing framework, hardware, network and other IT components) can be an important aspect in concept development. The MLMD acceptance criteria are different from the criteria for risk acceptability. It is important to establish the MLMD acceptance criteria at the start, as part of concept development, and not at the end of the MLMD development. Otherwise, the results of MLMD testing could influence the decisions when establishing those criteria.
After concept development, the ML model is trained by using an ML algorithm enabling it to learn patterns from training data without being explicitly programmed. Next, the trained ML model is applied to test data to verify its performance. The training data and the test data are different (disjoint) sets. They can be actual patient data or synthetic data, i.e. data created to simulate a patient for training or testing purposes. The tested ML model can then be applied to new patient data in a clinical setting. More information on MLMD can be found in IMDRF documents N67 and N88 and in guidance documents from FDA, Health Canada and MHRA.
It is recognized that the ML model can require retraining after a period of use to redefine its parameters and to ensure its continued performance. This can be achieved by planned retraining with collected patient data or on a continuous basis with each new patient data. The latter is referred to as “continuous learning” throughout this document and sometimes as “adaptive” in other documents.
All medical devices come with inherent risks. Manufacturers are required to demonstrate that their medical devices do not pose unacceptable risks, and that the benefits of the intended use outweigh the overall residual risk. ISO 14971 details how manufacturers can identify, assess and control risks to protect the patients, the users and other persons as well as property (for example objects, data, other equipment) and the environment. This includes risks related to data and systems security and cybersecurity. Guidance on the application of ISO 14971 is provided in document ISO/TR 24971. Additionally, IEC 80001-1 and IEC/TR 80002-1 address software internal to a medical device that can support AI or ML.
This document was developed to provide specific guidance on the application of ISO 14971 to MLMD. It does not provide a new risk management process, nor does it expand the requirements of ISO 14971. This document addresses risks related to machine learning and topics such as data management, feature extraction, unwanted bias, information security, training the ML model by an ML algorithm, evaluation and testing of the trained ML model. See Annex A for an explanation of bias. The report AAMI TIR34971 provided valuable input for this document.
[...]
Fonte: ISO
Collegati
Allegati
|
Descrizione |
Lingua |
Dimensioni |
Downloads |
|
|
EN |
940 kB |
0 |