From Research Prototype to Regulated Medical Software
Holding
The transition from research prototype to regulated medical software is not a cosmetic refactor. It is a change in evidence, lifecycle control, intended use, risk management, and organizational accountability.
Authority
FDA quality system rules, EU medical device requirements, and IMDRF SaMD definitions all make intended medical purpose and lifecycle control central. A research tool may become regulated when it is positioned to inform diagnosis, treatment, or other medical decisions.
Issue
The failure mode is prototype carryover. Experimental notebooks, undocumented preprocessing, informal datasets, and ad hoc thresholds move into production while retaining the evidentiary weakness of research code.
Resolution
The organization should restate intended use, classify risk, define requirements, establish configuration control, verify software behavior, validate clinical performance, create a change-control process, and monitor real-world performance after release.
Evidence Package
The record should include intended-use statement, requirements, architecture, risk file, design history, verification and validation evidence, release approval, user instructions, change log, and monitoring plan. Research code becomes product only when its behavior can be inspected and controlled.