A public health AI system will be deployed globally (US, EU, UK). According to the chapter, which strategy would be MOST effective for navigating the different regulatory requirements across jurisdictions while ensuring the system meets high standards?
Correct Answer: b) Build a reusable control and evidence baseline, then map the exact system to each jurisdiction’s classification, submission, and post-market requirements
This question tests understanding of practical multi-jurisdictional regulatory strategy, synthesizing the chapter’s coverage of FDA, EU, and UK regulatory frameworks and international harmonization efforts.
The Chapter’s Regulatory Landscape:
The chapter presents three major regulatory frameworks:
1. United States (FDA): - Software as a Medical Device (SaMD) framework - Three pathways: 510(k), De Novo, PMA - Risk-based classification (Class I, II, III) - AI/ML Action Plan (PCCP, GMLP, patient-centered approach)
2. European Union (EU AI Act + MDR/IVDR): - Risk-based classification (Unacceptable, High, Limited, Minimal) - Detailed requirements for high-risk AI: - Risk management (Article 9) - Data governance (Article 10) - Transparency (Article 13) - Human oversight (Article 14) - Accuracy/robustness/cybersecurity (Article 15) - Conformity assessment - Post-market monitoring - Penalties: Article 99 sets different maxima by violation category; the highest tier is EUR 35 million or 7% for prohibited practices
3. United Kingdom (MHRA): - Post-Brexit pragmatic approach - Risk-proportionate regulation - Innovation-friendly fast-track - International alignment (mutual recognition with FDA, EU)
Comparison boundary: There is no single, transferable ranking of jurisdictional stringency. The EU AI Act, EU medical-device rules, FDA requirements, and UK rules classify systems differently and may require different evidence, quality-system controls, submissions, and post-market duties.
The “Design Up” Strategy:
How a shared baseline helps:
1. Full Coverage:
EU AI Act controls can contribute to a shared assurance baseline, but they do not automatically satisfy FDA or MHRA requirements:
Article 9 (Risk Management): - Identified risks - Risk mitigation measures - May support risk-management evidence used in other jurisdictions
Article 10 (Data Governance): - High-quality, representative, bias-examined data - May support data-governance evidence, subject to jurisdiction-specific requirements
Article 13 (Transparency): - Instructions for use, limitations, accuracy levels, failure modes - May support labeling and transparency work, but required content and format differ
Article 14 (Human Oversight): - Users can interpret, override, stop system - May support human-oversight evidence, without determining FDA device status
Article 15 (Accuracy/Robustness): - Validated accuracy - Robust against errors - Cybersecurity measures - May support validation planning, but the required endpoints and evidence remain product-specific
2. Documentation Reusability:
The EU AI Act requires extensive documentation: - Technical documentation - Risk management plan - Data quality report - Model card - Validation report - Human oversight procedures
Parts of this documentation may support other jurisdictions’ applications: - FDA 510(k) submission: Use technical documentation, validation report, risk assessment - FDA De Novo: Use clinical validation, performance metrics, intended use documentation - MHRA UKCA marking: Use conformity assessment, technical documentation, performance data
A controlled core dossier can reduce duplication, but some markets require distinct analyses, evidence, forms, and legal representatives.
3. Future-Proofing:
The chapter notes regulatory convergence: - IMDRF (International Medical Device Regulators Forum) working toward harmonization - Common risk classification frameworks emerging - Mutual recognition agreements developing
IMDRF work can improve alignment, but it does not make one jurisdiction’s compliance package automatically valid in another.
4. Penalties are obligation-specific: Under Article 99, prohibited-practice violations can reach EUR 35 million or 7% of worldwide annual turnover; specified operator and transparency violations can reach EUR 15 million or 3%; and misleading information can reach EUR 7.5 million or 1%, subject to the regulation’s rules for undertakings and SMEs (EU AI Act, Article 99).
The “While maintaining documentation for each market’s specific needs” Caveat:
Each jurisdiction has specific documentation formats and submission requirements:
FDA-specific: - 510(k) premarket notification format - Predicate device comparison (if using 510(k)) - Specific performance metrics (sensitivity/specificity) - FDA-mandated labeling format
EU-specific: - CE marking conformity declaration - Notified body assessment (for certain devices) - EUDAMED database registration - EU-specific adverse event reporting
UK-specific: - UKCA marking declaration - MHRA-specific submission format - UK-specific post-market surveillance reporting
Practical approach: Maintain a controlled core evidence dossier, then complete a jurisdiction-specific classification and gap assessment before preparing each submission or conformity package.
Why Other Options Fail:
Option (a), Design for loosest requirements:
This is a “race to the bottom” that creates multiple problems:
Eventual retrofitting costs: When you try to enter stricter markets (EU), you’ll need extensive redesign and revalidation. Retrofitting is more expensive than designing right initially.
Reputation risk: If your system causes harm in a loosely-regulated market, it damages brand reputation globally. The chapter’s liability section shows this can be catastrophic.
Ethical problems: The chapter emphasizes patient safety and equity. Designing to minimum standards means accepting lower safety/performance, contradicting responsible AI principles.
Regulatory change: Requirements evolve, so change control and periodic legal review are necessary.
Enforcement risk: Penalties and remedies vary by obligation, entity, jurisdiction, and facts. Compliance must be evaluated in each market.
Option (c), Separate systems per jurisdiction:
This is inefficient and unsustainable:
Development costs: Building three entirely separate AI systems triples development costs, technical team, data collection, validation, documentation for each.
Maintenance burden: Three separate systems need three separate update processes, three monitoring systems, three incident response procedures. As the chapter discusses with concept drift, AI requires ongoing maintenance.
Knowledge fragmentation: Learnings from one market do not transfer to others. If you discover a bias in the EU system, you must separately discover and fix it in FDA and MHRA systems.
Scaling problems: What about Canada, Australia, Japan, Singapore? Create separate systems for each? This does not scale.
Misses harmonization trend: The chapter discusses IMDRF working toward harmonization. Separate systems do not use converging standards.
The chapter’s discussion of international harmonization (IMDRF section) implies a common system with jurisdiction-specific documentation is the intended future state, not completely separate systems.
Option (d), Wait for complete harmonization:
This is overly cautious and impractical:
Indefinite wait: The chapter notes: “Challenge: Balancing local sovereignty with global interoperability.” Full harmonization may take years or decades (if ever).
Opportunity cost: While waiting, competitors deploy in available markets. Patients in those markets do not benefit from your AI.
No learning: You do not learn from real-world deployment while waiting. The chapter emphasizes real-world evidence and post-market surveillance, you cannot get this while waiting.
Harmonization progress requires participation: IMDRF harmonization happens through industry engagement. Sitting on the sidelines does not advance harmonization.
Chapter’s policy recommendation (#7): “Support International Harmonization” - Priority: Medium | Timeline: 3-5 years. This is long-term, not immediate. Do not wait 5 years to deploy.
The Pragmatic Multi-Jurisdiction Strategy (Option B):
Phase 1: Design a shared control baseline - Build lifecycle controls for risk, data, validation, human oversight, security, monitoring, and change management - Map each control to EU, FDA, and UK requirements without assuming equivalence - Maintain jurisdiction-specific legal and regulatory gap analyses
Phase 2: Validate for each intended use and market - Define endpoints, comparators, populations, and evidence from the applicable pathway - Reuse verified core evidence where appropriate, while completing market-specific requirements - Generate traceable documentation that distinguishes shared evidence from jurisdiction-specific evidence
Phase 3: Regulatory Submissions - EU: Complete the applicable AI Act and medical-device conformity pathway - FDA: Determine device status, classification, and the applicable 510(k), De Novo, or PMA pathway - MHRA: Apply current Great Britain or Northern Ireland requirements and transition rules
Phase 4: Deployment - Deploy in all three markets - Single unified system (easier to maintain) - Jurisdiction-specific labels/documentation
Phase 5: Post-Market - Single monitoring system tracking performance globally - Report to each jurisdiction in their required format - Updates apply globally (with PCCP or equivalent)
The Chapter’s Supporting Evidence:
1. MHRA’s “International alignment”:
The chapter states MHRA seeks “Mutual recognition with FDA, EU.” This implies designing for EU (strictest) and FDA works for MHRA by default.
2. FDA lifecycle controls:
FDA’s final PCCP guidance and GMLP principles support lifecycle planning, but they do not make EU compliance a substitute for FDA requirements.
3. IMDRF harmonization goals:
- Harmonized definitions and terminology
- Common risk classification framework
- Shared validation standards
- Mutual recognition agreements
These efforts can reduce unnecessary divergence, but they do not establish automatic cross-jurisdictional compliance.
For practitioners:
The chapter’s multi-jurisdiction guidance is implicit but clear:
Global regulatory strategy should: - Use a strong shared control baseline without ranking unlike legal regimes as a single “highest” standard - Maintain documentation supporting each jurisdiction’s specific submission format - Use harmonization efforts (IMDRF, mutual recognition) to reduce duplicative work - Monitor regulatory evolution (FDA’s GMLP, EU AI Act implementation) and adapt
Option B embodies this strategy: maintain shared evidence and controls, then complete jurisdiction-specific classification and compliance work.
This approach supports reuse without erasing differences in intended use, legal classification, or evidence requirements.