blog

AI Audits for Medical Devices Beyond ISO 13485 | Qserve

Written by Coenraad Davidsdochter | Aug 5, 2026, 11:19:24 AM

As artificial intelligence becomes integral to medical device functionality, from diagnostic imaging to predictive software for patient care, manufacturers face a new layer of scrutiny. ISO 13485 remains the foundation of a medical device quality management system, but it doesn't cover the risks, lifecycle considerations, and regulatory expectations AI introduces. A dedicated AI audit closes that gap.

Why Notified Bodies Are Looking Harder at AI/ML

Manufacturers of medical devices and IVDs incorporating AI and machine learning face a shift: Notified Bodies are running deeper, more structured assessments of AI/ML than before. These assessments now cover more than the technical documentation showing a device is safe and well understood by its users; they also examine whether the QMS itself builds in the processes needed to keep AI/ML development under control.

Most Notified Bodies now assess AI-enabled devices against the Team-NB questionnaire on AI, a process-oriented checklist Team-NB published jointly with IG-NB in November 2024, mapping AI-specific expectations onto the manufacturer's QMS. Worth knowing: the questionnaire itself doesn't yet incorporate the EU AI Act's specific requirements — Team-NB has said an AI Act-aligned update will follow. That doesn't lower what NBs expect today; it just means AI Act compliance is currently tracked separately from the questionnaire, not folded into it.

Where the AI Act Currently Stands for Medical Devices

Under the EU AI Act, an AI system counts as "high-risk" if it's a safety component of a product covered by EU harmonisation legislation listed in Annex I, which includes the MDR and IVDR, and that product requires third-party conformity assessment. Most NB-assessed AI-enabled medical devices and IVDs meet that test, which is why they're treated as high-risk AI systems today.

Two separate developments are worth tracking, and they're easy to conflate. First, the "Digital Omnibus on AI," which the Council gave final approval on 29 June 2026, pushed the compliance deadline for high-risk AI embedded in regulated products like medical devices from August 2027 to 2 August 2028, and gave the Commission a narrower route to exempt specific AI Act requirements where the MDR or IVDR already covers the same ground. Second, and separately, the proposed MDR/IVDR revision published in December 2025 ("MDR 2.0") would move the MDR and IVDR from Annex I Section A to Section B of the AI Act — a change that, if adopted, would make the MDR/IVDR the primary framework and sharply narrow the AI Act's direct reach into medical devices. That move hasn't been decided; it's a separate, ongoing legislative process with its own timeline.

Either way, Notified Bodies aren't waiting for these questions to resolve. They're now asking for evidence of AI-specific QMS processes, and manufacturers who wait for the legislative picture to settle risk running out of runway before their next audit.

Why a Routine ISO 13485 Audit Isn't Enough

Routine ISO 13485 audits check organisational processes: documentation control, design validation, supplier management. They confirm your QMS works as intended, but they were never built to test algorithmic bias, training data representativeness, or model retraining governance. That gap runs in two directions.

First, the general AI obligations that apply to any AI-enabled device, locked or adaptive, sit at the core of the AI Act's high-risk chapter and the Team-NB questionnaire:

  • Data governance: representativeness, provenance, and bias controls across training, validation, and test datasets.
  • Transparency and explainability: whether users can correctly understand, interpret, and challenge model outputs.
  • Human oversight: design measures that make meaningful clinical oversight and intervention possible, not just nominal.
  • Accuracy, robustness, and cybersecurity against AI-specific failure modes, including adversarial inputs and data poisoning.
  • Logging and record-keeping sufficient to reconstruct why the model behaved as it did.

    Second, the dynamic elements standard QMS models struggle to handle:
  • Continuous learning systems that modify outputs beyond their initial certification scope.
  • Software of Unknown Provenance (SOUP) incorporated into AI pipelines — foundation models, for example.
  • Post-market performance drift from changes in input data or clinical practice, and the retraining governance needed to respond to it.

A routine ISO 13485 audit assesses neither dimension in depth. The standard's process lens was never built for them. Without targeted auditing, both can be identified as nonconformities under the AI Act and MDR Annex I (General Safety and Performance Requirements).

What a Dedicated AI Audit Covers

Our dedicated AI audit complements your routine ISO 13485 audit rather than replacing it, focusing on the additional expectations the AI Act and Team-NB questionnaire introduce. Through a structured review, we help you:

  • Bridge the regulatory gap between ISO 13485 and the AI Act.
  • Build AI risk management and lifecycle documentation aligned with Team-NB guidance.
  • Strengthen data quality and algorithm traceability for regulator confidence.
  • Prepare technical documentation for Notified Body AI assessments.

NBs are asking for this evidence today, regardless of how the AI Act timeline evolves. Once the AI Act's high-risk requirements formally apply to your device, the technical documentation built on AI-specific QMS processes needs to already be in place. Given how long that documentation takes to build properly, the real runway is shorter than the 2028 deadline suggests.

Partner with Experts Who Understand Both Worlds

We combine regulatory depth in MDR/IVDR with hands-on experience in the AI Act and the Team-NB framework, so our auditors know what NBs are looking for. Whether you're preparing a new medical device AI system for CE marking or adapting an existing QMS to AI Act obligations, a dedicated AI audit is the fastest way to know exactly where you stand.

Talk to our team about a dedicated AI audit