Digital PathologySolutions
News

ISO 13485 quality-management basics for medical device software

What ISO 13485 covers, how a quality-management system supports medical device software, and why a standard is not the same as product authorization.

Digital Pathology Solutions Editorial TeamMedical AI and digital pathology
6 min read
Medical device quality-management documentation on a desk

ISO 13485:2016 is an international standard for quality-management systems used by organizations involved in the life cycle of medical devices. For software and AI used in a medical context, a quality system can organize responsibilities, risk management, design controls, verification, validation, change control, complaints, and post-market activities.

Risk management follows the intended use

Risk depends on what a product is intended to do, who uses it, what information it receives, and what decisions its output may influence. A research tool, a laboratory quality-control tool, and software that supports a diagnostic decision do not automatically have the same risk profile. The intended use and foreseeable misuse should be documented before controls are selected.

Validation is not the same as verification

Verification asks whether specified requirements were met. Validation asks whether the resulting system is suitable for its intended use in the intended environment. For pathology software, validation planning may need to address representative specimens, image conditions, users, workflows, failure handling, and performance limitations.

A certificate does not authorize a product

ISO 13485 addresses the quality-management system, not the regulatory authorization of a specific software product. Certification claims should identify the certified legal entity, scope, certification body, certificate status, and dates. They should not imply that every product, model, dataset, or clinical claim has been independently authorized.

The European In Vitro Diagnostic Regulation sets obligations for applicable devices, including requirements connected with conformity assessment, clinical evidence, technical documentation, post-market surveillance, and vigilance. A quality-management system may support those activities, but the applicable route depends on the device, intended purpose, classification, and other facts. ISO 13485 alone is not a CE marking or IVDR conformity assessment.

For teams planning medical AI, the useful question is not whether a certificate sounds reassuring. It is whether the quality system produces controlled, traceable evidence that supports the specific intended use and remains effective as the software, data, and environment change.

Share this post

Written by

Digital Pathology Solutions Editorial Team

Medical AI and digital pathology

You may also like.

Stay in the loop.

Subscribe or reach out and we’ll get back to you within one business day.

Digital Pathology Solutions is committed to protecting your privacy. We use your personal data solely for managing your inquiry and providing the information you requested.

Learn more in our Privacy Policy.

By clicking "Submit", you consent to Digital Pathology Solutions storing and processing the personal data you have provided above in order to deliver the requested content to you.

I'm not a robot
reCAPTCHA