ISO 42001 vs ISO 13485: How to Build an AI Medical Device QMS

ISO 42001 vs ISO 13485 is not a choice between two competing quality standards. ISO 13485:2016 is the regulated medical-device quality management system backbone. ISO/IEC 42001:2023 is an organization-wide artificial intelligence management system standard that adds governance for how AI is developed, supplied, deployed, monitored, and improved.

For an AI-enabled medical device, the practical answer is usually integration: retain ISO 13485 for the device QMS, connect it to ISO 14971 risk management and the applicable software lifecycle controls, then add ISO/IEC 42001 processes for AI policy, accountability, data governance, impact assessment, third-party AI, monitoring, and continual improvement.

At a glance: ISO/IEC 42001 does not replace ISO 13485, FDA QMSR, ISO 14971, IEC 62304, clinical evidence, or a regulatory submission. It can strengthen the management system around AI-specific risks and make the evidence chain easier to audit.

If your organization is still completing its US quality-system transition, start with this FDA QMSR and ISO 13485 implementation guide. The comparison below assumes that the core medical-device QMS already exists.

Premium editorial illustration showing the integration of an ISO 13485 quality management system with ISO 42001 AI governance for an AI medical device.
ISO 13485 provides the medical-device QMS backbone; ISO/IEC 42001 adds organization-wide AI governance.

Regulatory note: This article is educational and does not replace device-specific legal, regulatory, clinical, cybersecurity, or conformity-assessment advice. Confirm requirements against the current law, guidance, recognized standards, intended purpose, classification, and target market.

Contents

ISO 42001 vs ISO 13485: What Is the Real Difference?

ISO 13485:2016 specifies quality management system requirements for organizations involved in medical devices and related services. It is centered on consistent fulfillment of customer and regulatory requirements, risk-based processes, design and development controls, supplier controls, production and service controls, complaint handling, corrective action, records, and continual system effectiveness.

ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an artificial intelligence management system, or AIMS. It is sector-neutral. A hospital, software supplier, medical-device manufacturer, cloud provider, or other organization may use it to govern AI activities within a defined scope.

The distinction matters because certification to an AI management system does not approve a medical device, validate a model, establish clinical performance, or authorize market access. Likewise, an ISO 13485 certificate does not by itself show that the organization has comprehensively addressed AI-specific governance questions such as model and dataset inventories, AI impact assessments, upstream foundation-model dependencies, monitoring thresholds, or the responsible use of AI outside the regulated product.

ISO 13485 vs ISO/IEC 42001: Side-by-Side Comparison

DimensionISO 13485:2016ISO/IEC 42001:2023AI medical-device implication
Primary purposeMedical-device quality management for regulatory purposesResponsible governance and continual improvement of an AI management systemUse ISO 13485 as the device-QMS backbone and integrate AI governance into it
ScopeOrganizations involved in medical devices and related servicesOrganizations that develop, provide, or use AI systemsThe AIMS scope may include product AI, internal AI tools, suppliers, and deployed services
Regulatory statusWidely used in medical-device regulatory frameworks; incorporated by reference into FDA QMSRVoluntary management-system standard unless contractually or otherwise requiredISO/IEC 42001 is an additional governance layer, not a market authorization
Risk emphasisProduct and process quality, safety, effectiveness, and regulatory complianceAI-related risks and opportunities across organizational context and lifecycleLink AI impact and governance risks to the device risk-management file
Data governanceCan govern data through design, validation, records, supplier, and regulatory processesMakes AI data and information governance more explicit within the AIMSCreate controlled dataset specifications, lineage, suitability, access, and change records
Design and developmentDesign planning, inputs, outputs, review, verification, validation, transfer, and changeGovernance of AI lifecycle activities, responsibilities, impact, controls, and monitoringAdd model, dataset, prompt, retrieval, and third-party dependency controls to design evidence
Performance over timeProduction and post-production feedback, complaint, CAPA, and change processesMonitoring, measurement, evaluation, and continual improvement of the AIMSDefine drift, subgroup performance, incident, and revalidation triggers before release
SuppliersSelection, evaluation, controls, and purchasing informationAI-system and AI-service supply-chain accountabilityControl data vendors, model/API providers, annotation services, cloud services, and update notices
Certification resultCertification of the medical-device QMS within its stated scopeCertification of the AI management system within its stated scopeNeither certificate is device approval; scope statements must accurately reflect the activities covered

The simplest mental model is this: ISO 13485 controls the regulated medical-device organization and product lifecycle; ISO/IEC 42001 controls how the organization governs AI within the selected AIMS scope. The two systems should share governance, document control, competence, audit, management review, corrective action, and improvement processes wherever practical.

What ISO 13485 Already Does Well for AI Medical Devices

It is inaccurate to say that ISO 13485 cannot handle AI. A properly designed ISO 13485 QMS can control an AI-enabled device because the standard is process-based and technology-neutral. The real problem is usually not the standard; it is an implementation that treats the model as an ordinary static software component.

Design and development controls

Existing design controls can govern intended purpose, user needs, design inputs, architecture, model and software requirements, verification, validation, transfer, and change. For AI, the design plan should also identify dataset activities, evaluation methods, human-AI interaction, performance limits, monitoring responsibilities, and change pathways.

Supplier controls

ISO 13485 supplier controls are directly relevant to external datasets, annotation services, foundation models, cloud inference services, software libraries, cybersecurity services, and contract development. The purchasing controls must define what evidence, notification, access, continuity, and change information the manufacturer requires.

CAPA and post-market feedback

Complaint, nonconformity, CAPA, and post-production processes can capture AI failure signals. The procedures should recognize AI-specific causal categories such as data-quality failure, population shift, label error, model degradation, retrieval-corpus change, prompt or configuration change, automation bias, and upstream service modification.

Documented evidence and traceability

Document control and records provide the foundation for traceability among intended purpose, risk controls, datasets, software and model versions, test evidence, release decisions, complaints, changes, and corrective actions. That traceability is essential whether the device uses a locked model, a periodically updated model, retrieval-augmented generation, or another AI architecture.

What ISO/IEC 42001 Adds to an AI Medical Device QMS

ISO/IEC 42001 adds a management-system lens specifically focused on AI. It helps leadership define which AI activities are in scope, who is accountable, what policies and objectives apply, how AI risks and opportunities are assessed, what controls are selected, how performance is measured, and how the system improves.

1. A controlled inventory and scope for AI

Medical-device companies often govern product software well but have no complete inventory of AI used in development, quality, clinical, customer support, cybersecurity, document generation, or supplier services. An AIMS forces the organization to define its scope and understand where AI is being developed, supplied, or used.

2. AI policy, roles, and decision rights

The AIMS establishes accountable ownership rather than leaving AI decisions entirely within data-science or software teams. For a medical-device manufacturer, this should connect executive leadership, quality, regulatory, clinical, risk, cybersecurity, privacy, human factors, engineering, and post-market functions.

3. AI impact assessment

An AI impact assessment broadens the analysis beyond conventional software failure. Depending on the use case, it may consider affected people, foreseeable misuse, transparency, human oversight, data suitability, performance variation, bias, accessibility, privacy, security, and dependence on external systems. For a regulated device, relevant outputs should feed the ISO 14971 risk-management process rather than sit in a separate ethics file.

4. Data and third-party AI governance

AI performance can depend on training, tuning, validation, monitoring, retrieval, and real-world data as well as third-party models or APIs. ISO/IEC 42001 provides a structure for setting responsibilities, requirements, controls, and evidence around those dependencies. This complements the device-QMS supplier and design controls.

5. Monitoring and continual improvement

An AIMS makes monitoring part of governance, not merely an engineering dashboard. Management should know which AI performance and risk indicators are reviewed, who evaluates them, what thresholds trigger investigation, when revalidation is required, and how corrective actions are verified. For broader context on evolving medical AI, see this review of the future of AI in pharmaceuticals and medical devices.

What Neither ISO 42001 nor ISO 13485 Replaces

A strong article and a strong compliance program must avoid presenting two management-system standards as the complete technical or regulatory stack. An AI-enabled medical device may also need the following, depending on the product and market:

  • Medical-device risk management: ISO 14971:2019 provides the device risk-management process. AI impact assessment should inform, not replace, the device risk file.
  • Software lifecycle controls: applicable software-development and maintenance standards, including IEC 62304 where used by the regulatory strategy.
  • Usability and human factors: controls for intended users, use environments, automation bias, over-reliance, interpretability, alerts, and human intervention.
  • Clinical and performance evidence: evidence appropriate to the intended purpose, claims, population, workflow, and regulatory pathway.
  • Cybersecurity and privacy: threat modeling, secure development, vulnerability management, privacy controls, and market-specific obligations.
  • Regulatory change control: assessment of whether a modification requires a new submission, notified-body review, updated technical documentation, or another regulatory action.

For additional AI risk-management guidance, organizations may also consider ISO/IEC 23894:2023, the NIST AI Risk Management Framework, and the IMDRF Good Machine Learning Practice principles. These resources can support implementation, but the organization must still map them to its product, jurisdiction, and QMS.

FDA QMSR and Artificial Intelligence: The 2026 Position

The FDA Quality Management System Regulation became effective on February 2, 2026. It incorporates ISO 13485:2016 by reference, together with additional FDA requirements in 21 CFR Part 820. It does not incorporate ISO/IEC 42001 and does not make ISO/IEC 42001 certification a condition of US market access.

That does not make AI governance optional. FDA evaluates the safety and effectiveness of the device and the adequacy of the sponsor’s evidence. FDA’s August 2025 final guidance on Predetermined Change Control Plans describes the planned modifications, modification protocol, and impact assessment expected when a sponsor proposes a PCCP for an AI-enabled device.

FDA’s broader AI-enabled device lifecycle guidance remains draft guidance as of this update and is not for implementation. It nevertheless shows the agency’s current thinking on total-product-lifecycle documentation, performance, transparency, bias, monitoring, and risk management.

Practical FDA conclusion: Use ISO 13485/QMSR to operate the regulated QMS. Use ISO/IEC 42001 where it adds disciplined AI governance. Do not describe ISO/IEC 42001 as FDA approval, FDA recognition of a device, or a substitute for submission evidence.

EU AI Act, MDR, and ISO/IEC 42001

In the European Union, an AI-enabled medical device may be governed by the Medical Device Regulation or In Vitro Diagnostic Medical Device Regulation and by the AI Act when the applicable classification conditions are met. The compliance architecture therefore has to connect the device QMS, technical documentation, risk management, post-market processes, and AI-specific obligations.

The European Commission’s current AI Act implementation timeline states that high-risk rules for AI embedded in regulated products are scheduled to apply from August 2, 2028 following the 2026 political agreement on the AI simplification package. Because legislative status and implementation materials can continue to change, confirm the final legal position before relying on a date in a regulatory plan.

ISO/IEC 42001 can help organize AI governance evidence, but certification alone should not be presented as automatic conformity with the AI Act. European harmonized standards and supporting guidance determine whether a standard provides a presumption of conformity for particular legal requirements. The Commission has stated that AI Act standardization work is continuing.

For a broader comparison of the two regulatory systems, read EU AI Act vs FDA SaMD compliance. Also review the current EU MDR and IVDR operating environment before setting conformity-assessment timelines.

Integrated ISO 13485 and ISO/IEC 42001 Crosswalk

The objective is not to create a second, disconnected management system. Use shared processes where the requirements and evidence overlap, then add AI-specific controls where the existing QMS is too generic.

Existing QMS processAI-specific enhancementTypical controlled evidencePrimary owner
Context, scope, and quality planningDefine AIMS scope and AI inventoryAI inventory, scope statement, interested-party and obligation registerExecutive sponsor / Quality
Management responsibilityAI policy, objectives, accountability, and escalationPolicy, RACI, governance committee charter, objectives and metricsTop management
Design and development planningPlan data, model, evaluation, human oversight, monitoring, and update activitiesAI development plan, model and data lifecycle planEngineering / Quality
Risk managementConnect AI impact and governance risks to device hazards and risk controlsAI impact assessment, integrated risk analysis, benefit-risk rationaleRisk manager / Clinical
Design inputsDefine population, data, performance, uncertainty, transparency, and oversight requirementsMeasurable AI requirements and acceptance criteriaSystems engineering
Data managementControl provenance, representativeness, labeling, preprocessing, access, and versioningDataset specification, data sheets, lineage and quality reportsData owner / Privacy
Verification and validationEvaluate variation, subgroup performance, edge cases, human-AI performance, and failure conditionsEvaluation protocol, locked test results, subgroup analysis, usability evidenceV&V / Clinical
Supplier managementAssess model, API, data, annotation, and cloud-service dependenciesSupplier risk assessment, quality agreement, update and incident notification termsPurchasing / Quality
Change controlClassify model, data, prompt, retrieval, interface, and upstream-provider changesAI change-impact assessment, regulatory assessment, revalidation plan, PCCP mappingChange control board / RA
Post-market surveillanceMonitor performance, drift, bias signals, misuse, incidents, and external changesMonitoring plan, dashboards, threshold records, trend reportsPost-market / Data science
CAPAInclude AI-specific root causes and effectiveness checksCAPA records linking data, model, process, supplier, and user factorsQuality
Competence and trainingDefine AI literacy and role-specific competenceCompetency matrix, training records, effectiveness evaluationHR / Functional managers
Internal audit and management reviewAudit the AIMS and review AI performance and risk indicatorsIntegrated audit plan, findings, management-review inputs and actionsQuality / Internal audit

Five Steps to Integrate ISO/IEC 42001 Without Building a Parallel QMS

Step 1: Define the AIMS scope and AI inventory

List every AI system the organization develops, supplies, or uses within the proposed scope. Separate regulated product AI from internal tools, research systems, third-party services, and AI used by suppliers. Record intended purpose, owner, users, affected people, data, provider, deployment model, and regulatory relevance.

Step 2: Map existing controls before writing new procedures

Map ISO/IEC 42001 requirements to the current QMS, information-security, privacy, risk, cybersecurity, and software processes. Reuse document control, training, audit, management review, CAPA, supplier, and change processes when they are adequate. Create new procedures only for genuine gaps.

Step 3: Establish AI impact and risk integration

Define when an AI impact assessment is required, who participates, how risks and opportunities are evaluated, and how relevant outcomes enter the medical-device risk-management process. Avoid separate registers that use inconsistent severity, probability, acceptability, or approval logic.

Step 4: Operationalize data, monitoring, and change controls

Set controlled requirements for dataset suitability, provenance, versioning, access, labeling, evaluation, and release. Define performance and risk indicators, monitoring frequency, subgroup analyses, alert thresholds, investigation rules, revalidation triggers, supplier notifications, and regulatory change assessments.

Step 5: Run an integrated readiness audit

Audit a real AI system from intended purpose through post-market monitoring. Sample the decisions and records, not only the procedures. The audit should be able to reconstruct which data, code, model, configuration, risk controls, validation evidence, approvals, suppliers, and monitoring rules applied to the released version.

Audit-Ready Evidence Checklist

  • Approved AIMS scope and a current inventory of in-scope AI systems.
  • AI policy and governance RACI with decision and escalation authority.
  • Applicable-obligations register covering regulatory, contractual, standard, privacy, cybersecurity, and internal requirements.
  • AI impact assessment connected to the device risk-management file.
  • Dataset specification and lineage for training, tuning, validation, testing, retrieval, and monitoring data as applicable.
  • Performance acceptance criteria tied to intended purpose, population, workflow, and risk controls.
  • Subgroup and failure-condition evaluation with justified actions for identified gaps.
  • Human oversight and transparency evidence appropriate to the intended users and use environment.
  • Supplier controls for external data, models, APIs, cloud services, annotation, and critical software.
  • AI change-impact assessment covering model, data, configuration, prompt, retrieval, interface, and upstream-provider changes.
  • Post-market monitoring plan with thresholds, responsibilities, investigation, CAPA, and revalidation logic.
  • Integrated internal audit and management review showing that AI objectives, risks, performance, incidents, resources, and improvement actions are reviewed.

Seven Common ISO 42001 Implementation Mistakes in MedTech

  1. Calling ISO/IEC 42001 a medical-device approval. It certifies a management system scope, not a device’s safety, effectiveness, or market authorization.
  2. Building a second document-control and CAPA system. Parallel systems create conflicting records, owners, and audit trails.
  3. Keeping AI impact assessments outside ISO 14971. Relevant patient and user risks must connect to the regulated device risk process.
  4. Monitoring only average model accuracy. Operational risk may appear in subgroups, sites, workflows, inputs, user behavior, or external dependencies.
  5. Ignoring third-party model and API changes. A supplier’s update can change product behavior even when your own code is unchanged.
  6. Treating every AI change as ordinary software maintenance. Data, model, prompt, retrieval, and configuration changes need defined impact and regulatory assessments.
  7. Claiming automatic EU AI Act conformity. ISO/IEC 42001 may support governance evidence, but legal conformity depends on the applicable requirements, conformity route, and recognized or harmonized standards.

When ISO/IEC 42001 Certification Is Worth Considering

Certification may be strategically useful when AI is central to the product portfolio, enterprise customers require independent assurance, the organization uses AI extensively beyond the regulated product, procurement teams request responsible-AI evidence, or leadership wants a common governance system across multiple jurisdictions and business units.

Certification may be premature when the organization has not stabilized its ISO 13485 QMS, has no reliable AI inventory, cannot reconstruct datasets and versions, has unresolved product-risk or validation gaps, or is pursuing a certificate mainly as a marketing badge. In those situations, implement the controls first and certify when the scope and evidence are mature.

Leadership takeaway: The strongest architecture is not “ISO 42001 or ISO 13485.” It is one integrated management system in which ISO 13485 governs the medical-device QMS and ISO/IEC 42001 makes AI accountability, impact, data, supplier, monitoring, and improvement controls explicit.

Frequently Asked Questions

Does ISO/IEC 42001 replace ISO 13485 for an AI medical device?

No. ISO 13485 remains the medical-device quality management system standard used within major regulatory frameworks. ISO/IEC 42001 is an AI management system standard that can add organization-wide AI governance. An AI medical-device manufacturer will usually integrate the two rather than replace one with the other.

Is ISO/IEC 42001 mandatory for FDA QMSR compliance?

No. FDA QMSR incorporates ISO 13485:2016 by reference and includes additional FDA requirements in 21 CFR Part 820. ISO/IEC 42001 is not incorporated into QMSR. It may still be useful as a voluntary framework for governing AI-specific organizational risks and evidence.

Does ISO/IEC 42001 certification prove EU AI Act compliance?

No. Certification can support an organization’s evidence of systematic AI governance, but it does not automatically establish conformity with every applicable AI Act requirement. Confirm the legal requirements, conformity-assessment route, Commission guidance, and status of harmonized standards.

How should AI risk management connect to ISO 14971?

Use AI impact and governance assessments to identify relevant hazards, hazardous situations, affected people, foreseeable misuse, performance variation, data issues, and external dependencies. Feed patient- and user-relevant outputs into the ISO 14971 risk-management process, where risk estimation, evaluation, control, benefit-risk analysis, and production or post-production information are governed.

What documents should be added first?

Start with an AI inventory and AIMS scope, AI policy and governance RACI, applicable-obligations register, AI impact-assessment method, dataset and model lifecycle controls, AI supplier criteria, monitoring and threshold plan, and an AI change-impact assessment connected to the existing QMS change-control process.

Authoritative References

Editorial disclosure: This article was prepared as an educational synthesis of publicly available standards information and regulatory sources. Standards must be reviewed in their official editions, and draft guidance should not be treated as binding or final.

QMSR Transition Success: The Definitive FDA 21 CFR 820 & ISO 13485 Guide (2026)

The Critical EU MedTech Innovation Pressure: Navigating 2026 MDR & EY-DG SANTE Updates.

EU AI Act vs FDA SaMD Compliance: 7 Critical Wins

2 thoughts on “ISO 42001 vs ISO 13485: How to Build an AI Medical Device QMS”

Leave a Comment