10 September 2026

Making AI & SaMD changes under EU MDR: Part 1 - Class IIa/IIb

Making AI & SaMD changes under EU MDR: Part 1 - Class IIa/IIb

Osman El-Koubani

Search…

Search…

In the world of medical device software, updates come with the territory. But which changes do you need to report to Scarlet for assessment under EU MDR? Here, we set out our criteria and what to expect from the process. 

Software and updates go hand in hand. But for medical devices, many of those updates need to be reported to your Notified Body before you can release them to the market. In this two-part blog series, we explain where the regulation currently stands on reportable changes, Scarlet’s policies for AI/Software as a Medical Device (AIaMD/SaMD) changes, and what it all means for manufacturers.

What the regulations say

The EU MDR only provides general requirements: 

  • Manufacturers must establish procedures for managing modifications to their design or quality management system (Annex IX, 2.2(c), eighth indent). 

  • Notified Bodies must have procedures and contracts in place relating to manufacturers’ obligations to report changes and the assessment of changes, including checking the significance of these changes (Annex VII, 4.9).

How to get started

Manufacturers certifying devices with Scarlet should start by categorising each planned change:

  • Reportable, requiring prior approval: the change must be reported to the Notified Body and approved before implementation.

  • Reportable, not requiring prior approval: the change is communicated to the Notified Body, but can be implemented immediately; it is reviewed on a sampling basis during surveillance.

  • Non-reportable: the change is implemented and documented within the QMS, with records reviewed on a sampling basis.

Under EU MDR (Article 10, clause 9), the manufacturer must manage this process. Article 10, clause 9 states that the quality management system shall include “procedures for management of modifications to the devices covered by the system”. Manufacturers must categorise planned changes and take the relevant actions as outlined in their change management processes. These processes must be justified, documented, and controlled within the manufacturer’s QMS. Scarlet will then review these processes and change control records during surveillance. 

Despite this being the manufacturer’s responsibility, Scarlet’s team is available to support customers in navigating this process, particularly for any borderline cases. 

Scarlet’s device-change criteria 

Scarlet's device-change criteria are different for Class IIa/IIb SaMD and Class III SaMD. Below, we outline the criteria for Class IIa/IIb SaMD. Class III SaMD will be addressed in the next post (part 2).

Our Class IIa/IIb SaMD device-change policy is designed to be robust while allowing our customers to put day-to-day software changes into motion faster. 

For changes that do require approval, the process could involve a technical documentation assessment, a QMS assessment, or a special audit. Some changes may only involve an update to the certificate and/or sampling plan.

For Class IIa/IIb SaMD:


Categorising changes: things to watch out for

One area to pay special attention to is device-level changes that may result in a substantial change to the approved QMS. Even if the update itself does not meet the criteria for prior approval, substantial changes to the approved QMS do need prior approval. 

For example, changing from an Anthropic model API to OpenAI is a device-level change, but it also involves a critical-supplier change under the QMS. A substantial change like this would require approval from a Notified Body prior to implementation. (The determination of whether these changes require prior approval is at the discretion of the Notified Body. We encourage manufacturers to engage with their Notified Body in instances of uncertainty.)

Conclusion

For Class IIa or IIb software/AI medical devices, the day-to-day updates such as bug fixes, performance optimisation, and UI refinement are generally non-reportable changes

Class IIa/IIb SaMD device changes (e.g. new features, algorithm changes, and updated indications) are reportable, but unlikely to require prior approval, provided they do not alter your QMS or your device range.  

Changes to the device range and substantial QMS changes will most likely be reportable and require prior approval

For Class III SaMD, the requirements are different. In our next post, the second in this series, we’ll unpack how to navigate reportable changes for those. 



Need to certify an AI medical device?