preloader

Email Us

info@prorelixresearch.com

Single Blog

ISO/TS 24971-2:2026 Is Here: Your AI Medical Device Risk Ready?  

ISO/TS 24971-2:2026 Is Here: Your AI Medical Device Risk Ready?  

The latest ISO/TS 24971-2:2026 guidance is here. See what AI medical device manufacturers should know about ML risk management and ISO 14971.

Artificial intelligence and machine learning are changing how medical devices are designed, tested, and used. But as machine learning becomes part of clinical decision-making, a difficult question follows:

Can manufacturers demonstrate that the risks created by machine learning are being identified and controlled throughout the medical device lifecycle?

That question has gained new relevance with the publication of ISO/TS 24971-2:2026, Medical devices, Guidance on the application of ISO 14971, Part 2: Machine learning in artificial intelligence.

Published in June 2026, this new Technical Specification provides guidance on applying the ISO 14971 risk management process to machine learning enabled medical devices (MLMDs). It is designed to be used alongside ISO 14971 and ISO/TR 24971 rather than replacing them.

For medical device manufacturers, software developers, regulatory teams, and quality teams working with ML-enabled products, this publication marks an important development in the way machine learning specific risks can be considered within established medical device risk management.

YOUR AI MEDICAL DEVICE RISK READY?  

iso/ts 24971-2:2026 update: your ai medical device risk ready?
Figure 1: Your AI Medical Device Risk Ready? ISO/TS 24971-2:2026

What Is ISO/TS 24971-2:2026?  

ISO/TS 24971-2:2026 is a new Technical Specification from ISO/TC 210 that provides guidance on risks specific to artificial intelligence and machine learning and how the ISO 14971 risk management process can be applied to ML-enabled medical devices.

The document was published on 17 June 2026 and is the first edition. ISO identifies it as a 32-page Technical Specification.

The important point is that this publication does not create a separate risk management system for AI medical devices.

Instead, it helps manufacturers consider the characteristics of machine learning within the established medical device risk management framework.

ISO 14971:2019 remains the core international standard for medical device risk management. It provides the framework for identifying hazards, estimating and evaluating risks, implementing risk controls, and monitoring the effectiveness of those controls across the device lifecycle.

This makes ISO/TS 24971-2:2026 particularly relevant for organizations that already have an ISO 14971 based risk management process but need to address the additional considerations associated with ML.

Why Does Machine Learning Change the Risk Conversation?  

Traditional medical device software follows defined logic. Machine learning introduces a different development and performance environment.

The behavior of an ML-enabled medical device can depend heavily on the data used to train, validate, and test the model. Differences in datasets, model development, clinical populations, implementation environments, or future changes to the model can affect performance.

That means a risk assessment cannot focus only on the final software output. Manufacturers may need to consider the relationship between:

machine learning changes the risk conversation
Figure 2: Machine Learning Changes the Risk Conversation

Data → Model → Output → User → Clinical Decision → Patient Outcome

A weakness at any point can potentially become a safety concern.

For example, imagine an ML-enabled diagnostic device trained using data that does not adequately represent a particular patient population. The model may perform well during development but perform differently when used in another population.

The technical challenge is therefore not simply asking:

“Does the model work?”

The more meaningful risk management question becomes:

“Under which conditions does the model work, where can performance vary, and what controls are needed when it does?”

That is where ML-specific risk management becomes particularly important.

What Risks Should Medical Device Manufacturers Consider?  

ISO/TS 24971-2:2026 focuses on risks specific to AI and machine learning. Available descriptions of the published specification identify areas such as data management, feature extraction, unwanted bias, information security, ML model training, and evaluation and testing. The specification also recognizes situations where models may require retraining after deployment.

For practical risk management, manufacturers should consider questions such as:

Is the training data suitable for the intended purpose?

Are the training and test datasets appropriately separated?

Could data quality, integrity, representativeness, or population differences affect performance?

Poor data decisions can create downstream risks that may not be visible from model accuracy alone.

Bias and Performance Differences  

An ML model can produce different performance levels across patient groups or clinical environments.

Manufacturers should therefore consider whether the available evidence supports the intended population and use environment and whether differences in performance could create safety risks.

Model Evaluation and Testing  

Model development should not stop with a promising performance metric.

Risk management should connect model evaluation and testing to the actual intended use of the medical device.

The question should be whether the evidence supports safe use under reasonably foreseeable conditions.

Information Security  

Machine learning systems also exist within software and data environments.

Security related weaknesses can potentially affect data, model behavior, availability, or device performance. Information security therefore needs to be considered in the broader risk management context.

Human Interaction and Transparency  

A medical device may produce an output, but a healthcare professional may interpret or act on that output.

What happens if the user misunderstands the result?

What information does the user need to interpret the output appropriately?

FDA, Health Canada, and MHRA guidance on transparency similarly emphasizes communicating information about intended use, development, performance, limitations, and relevant logic to users.

Changes After Deployment  

One of the biggest challenges with ML-enabled products is what happens after deployment.

Models may be retrained, updated, or exposed to new data. This makes change management and ongoing monitoring particularly important.

FDA guidance on predetermined change control plans highlights the importance of risk-based, evidence-based approaches to planned changes and lifecycle management for ML-enabled medical devices.

ISO/TS 24971-2:2026 vs ISO 14971: What Changes?  

A common misconception could be that manufacturers now need to replace ISO 14971 with a new AI-specific risk management standard.

That is not what ISO has published.

ISO/TS 24971-2:2026 is intended to work with ISO 14971 and ISO/TR 24971. ISO 14971 remains the foundational risk management standard, while the new Technical Specification provides additional guidance for ML-enabled medical devices.

AreaISO 14971:2019ISO/TS 24971-2:2026
Primary roleMedical device risk managementGuidance for ML specific risk considerations
ScopeMedical devices, including software and IVDsML-enabled medical devices
Risk frameworkIdentifying, evaluating, controlling, and monitoring risksApplies the ISO 14971 approach to ML characteristics
Data considerationsConsidered as relevant to device riskGreater focus on ML-related data considerations
BiasAddressed where relevant to device riskML-specific considerations include unwanted bias
Model performanceRelevant to device safety and performanceSpecific ML evaluation and testing considerations
LifecycleCovers the device lifecycleHighlights ML characteristics including retraining and ongoing changes
RelationshipCore risk management standardUsed in conjunction with ISO 14971 and ISO/TR 24971
Table 1 : ISO/TS 24971-2:2026 vs ISO 14971

The practical message: manufacturers should not create an isolated “AI risk file” disconnected from their existing risk management system. The better approach is to integrate ML-specific risks into the established medical device risk management process.

What Should Medical Device Manufacturers Review Now?  

The publication of ISO/TS 24971-2:2026 gives organizations a timely reason to review existing processes.

A useful internal assessment could begin with six questions:

1. Intended UseIs the intended purpose clearly defined, including the clinical context in which the ML-enabled device will be used?
2. DataAre training, validation, and test data appropriately managed, documented, and representative of the intended use?
3. Risk AnalysisDoes the risk management file identify risks that arise specifically from the ML approach?
4. PerformanceCan the manufacturer demonstrate how model performance was evaluated under relevant conditions?
5. Human FactorsCan intended users understand the device output, limitations, and relevant warnings?
6. Post-Market ChangesWhat happens if the model is retrained, updated, or exposed to new real-world data?
Table 2: What Should Medical Device Manufacturers Review Now?

These questions should not be treated as a one-time checklist.

ISO 14971 follows a lifecycle approach, and FDA’s Good Machine Learning Practice principles similarly emphasize the total product lifecycle for AI/ML-enabled medical devices.

Why the Lifecycle Matters More for ML Medical Devices  

For conventional software, a manufacturer may be able to establish a relatively stable relationship between software changes and device behavior.

ML-enabled products can be more complicated.

Consider a simplified lifecycle:

the machine learning medical device lifecycle
Figure 3: The Machine Learning Medical Device Lifecycle

This creates an important regulatory and quality question:

What happens to the risk profile when the model changes?  

The answer should be connected to the manufacturer’s established change management, risk management, verification, validation, and regulatory processes.

FDA’s work on predetermined change control plans reflects this broader challenge. The agency has highlighted the need for approaches that allow certain planned modifications to ML-enabled device software while maintaining safety and effectiveness.

A Critical Scope Point: This Is Not an LLM or Generative AI Standard  

There is an important distinction that should not be missed when discussing ISO/TS 24971-2:2026.

ISO explicitly states that the Technical Specification does not apply to ML-enabled medical devices employing large language models or generative AI.

That means manufacturers should not automatically describe ISO/TS 24971-2:2026 as a complete risk management framework for every form of generative AI used in healthcare.

The scope matters.

For companies developing conventional ML-enabled medical devices, however, the publication provides a timely resource for considering ML-specific risks within ISO 14971 based risk management.

What This Means for Regulatory and Quality Teams  

For regulatory affairs and quality teams, the publication creates an opportunity to bring several functions closer together.

AI development cannot sit entirely within the data science or software team.Risk management may involve:

risk management may involve
Figure 4: Risk Management May Involve
  • Regulatory affairs
  • Quality assurance
  • Software engineering
  • Data science
  • Clinical experts
  • Human factors specialists
  • Cybersecurity teams
  • Post-market surveillance teams

This cross-functional approach matters because ML risk can originate from multiple parts of the product lifecycle.

A model may be technically strong but unsuitable for a particular clinical environment.

A dataset may produce excellent overall performance but weaker results for a specific patient population.

A software update may improve one performance measure while introducing a new safety concern.

A user may interpret a model output differently from what the development team intended.

Risk management has to connect these pieces.

What Should Manufacturers Do Next?  

The publication of ISO/TS 24971-2:2026 does not mean every medical device manufacturer needs to rebuild its quality system overnight.

A more practical approach is to conduct a structured gap assessment.

Start by mapping the existing ISO 14971 process against the characteristics of your ML-enabled medical device.

Then ask:

Where does ML introduce a new hazard?

Where can data quality affect safety?

Where could performance vary across users or populations?

How are model changes controlled?

How will performance be monitored after deployment?

What information does the user need to understand limitations?

Can every important risk control be traced to verification or validation evidence?

The answers can help determine where additional documentation, testing, controls, monitoring, or cross-functional review may be required.

Final Takeaway  

ISO/TS 24971-2:2026 does not change the fundamental purpose of medical device risk management. It brings greater attention to the characteristics that make machine learning different.

For AI-powered medical devices, risk management cannot end when the model achieves a target performance metric.

The real challenge begins with understanding how data, model development, testing, clinical use, human interaction, security, updates, and post-market experience can influence safety throughout the product lifecycle.

The key question for manufacturers in 2026 is therefore simple:

Your AI Medical Device Risk Ready?  

For organizations developing ML-enabled medical devices, now is a good time to review the existing ISO 14971 risk management process against the new ISO/TS 24971-2:2026 guidance and identify where ML-specific considerations need greater attention.

References  

1. International Organization for Standardization (ISO).
ISO/TS 24971-2:2026, Medical devices — Guidance on the application of ISO 14971 — Part 2: Machine learning in artificial intelligence. ISO/TS 24971-2:2026 — Official ISO page

2. International Organization for Standardization (ISO).
ISO 14971:2019, Medical devices — Application of risk management to medical devices. ISO 14971:2019 — Official ISO page

3. International Organization for Standardization (ISO).
ISO/TR 24971:2020, Medical devices — Guidance on the application of ISO 14971. ISO/TR 24971:2020 — Official ISO page

4. U.S. Food and Drug Administration (FDA).
Good Machine Learning Practice for Medical Device Development: Guiding Principles. FDA — Good Machine Learning Practice for Medical Device Development

5. U.S. Food and Drug Administration (FDA).
Predetermined Change Control Plans for Machine Learning-Enabled Medical Devices: Guiding Principles. FDA — Predetermined Change Control Plans for ML-Enabled Medical Devices

Expert CRO for Medical Device Clinical Trials  

Facing Challenges With Your Medical Device Clinical Trial?  

Developing a medical device with AI or machine learning brings together clinical, regulatory, technical, and risk management considerations. But translating these requirements into a well planned clinical study can be challenging.

From clinical trial planning and study execution to regulatory documentation, investigator coordination, patient recruitment, data management, and reporting, every part of a medical device clinical trial needs to work together.

ProRelix Research supports medical device companies with CRO services designed around the specific requirements of clinical research and medical device development.

Our clinical research support can help with:

  • Medical device clinical trial planning
  • Clinical study management
  • Regulatory and ethical submission support
  • Investigator and site coordination
  • Patient recruitment and retention
  • Clinical data management
  • Medical device safety reporting
  • Clinical study documentation
  • Monitoring and quality oversight
  • Study closeout and reporting

Whether you are developing a conventional medical device, connected medical technology, SaMD, or an ML-enabled medical device, the clinical evidence strategy needs to align with the product’s intended use, risk profile, and regulatory pathway.

Need Clinical Trial Support for Your Medical Device?  

Talk to ProRelix Research about your clinical research requirements and see how our CRO team can support your medical device study from planning through completion.

Get Expert Support

Frequently Asked Questions  

What is ISO/TS 24971-2:2026?  

ISO/TS 24971-2:2026 is a Technical Specification providing guidance on risks specific to AI and machine learning and on applying the ISO 14971 risk management process to ML-enabled medical devices. It is intended to be used together with ISO 14971 and ISO/TR 24971.

Does ISO/TS 24971-2:2026 replace ISO 14971?  

No. ISO states that ISO/TS 24971-2:2026 is intended to be used in conjunction with ISO 14971 and ISO/TR 24971. ISO 14971 remains the core international standard for medical device risk management.

What types of risks does ISO/TS 24971-2:2026 address?  

The Technical Specification addresses risks specific to AI and ML. Published descriptions identify considerations including data management, feature extraction, unwanted bias, information security, ML model training, and evaluation and testing. It also considers situations where models may require retraining after use.

Does ISO/TS 24971-2:2026 apply to generative AI or LLM-based medical devices?  

No. ISO explicitly states that the document does not apply to ML-enabled medical devices employing large language models or generative AI.

Why should manufacturers review their risk management process now?  

ML-enabled medical devices can introduce risks associated with data, model performance, bias, security, user interaction, and changes after deployment. Reviewing the existing ISO 14971 process can help manufacturers identify whether these ML-specific considerations are adequately addressed across the product lifecycle. This aligns with the broader lifecycle focus found in international Good Machine Learning Practice principles.

Niranjan Andhalkar

https://prorelixresearch.com/mr-niranjan-andhalkar/

He is the Director – Director – Strategic Management & Planning at ProRelix Research. His visionary leader with 17+ years of experience in clinical research, pharmaceuticals, CROs, and healthcare IT. Known for driving business growth, strategic collaborations, and innovation, he has successfully built and scaled organizations in the global clinical research ecosystem. With academic expertise in Biotechnology, Clinical Research, and an MBA in Operations Management, he combines scientific knowledge with strong business strategy to create impactful and sustainable healthcare ventures.

Subscribe to our Newsletter

Be the first to know the latest trends in clinical research, real-world case studies, and industry secrets.

Loading
prorelix research

ProRelix Research is the rapidly growing Contract/ Clinical Research Organization (CRO) with multi-country service capability supporting phase 1, 2, 3, & 4 clinical trials of Pharma, Biotech, Biopharma, Medical Device, Nutraceutical & Herbal companies to conduct in the USA, India, Europe & South East Asia.