Scope boundary · 20

Configuration and change control

Reassess software, models, instruments, accessories, consumables, networks, site workflow and maintenance changes before clinical use.

Evidence statusClinical evidence framework · intended use, jurisdiction and care-pathway validation requiredLast reviewed: 15 August 2026
20

FUURAA thesis

Evidence belongs to a configuration and use system; uncontrolled change breaks that link.

Engineering map

Turn the title into engineering objects that can be observed, measured and reviewed.

Each layer states the boundary to establish and the evidence needed for the next decision.

01

Identify

Version every safety- and performance-relevant component and dependency.

02

Assess

Determine regulatory, risk, verification, usability, training and clinical impact.

03

Release

Approve, install, confirm, monitor and retain rollback evidence.

Verification questions

Write the questions first, then decide whether a demo, test, pilot or operating record can answer them.

Each question needs an object, conditions, denominator, threshold and accountable decision owner.

  1. 01

    What changed since supporting evidence?

  2. 02

    Does the change alter intended use or risk?

  3. 03

    Which evidence must be repeated?

  4. 04

    Can affected cases be traced?

Evidence to preserve

Enable the next reader to reconstruct conditions, results, failures and the decision.

A conclusion alone loses reviewability; raw records, configuration and exclusions matter too.

  1. 01

    Evidence package 1

    Versioned configuration baseline

  2. 02

    Evidence package 2

    Change-impact and approval record

  3. 03

    Evidence package 3

    Deployment, monitoring and rollback log

Scope boundary

State what this evidence still cannot be generalised to.

Sources and evidence status

Read standards scope, measurement evidence and application conclusions separately.

Source dates and review status remain visible; external sources open in a new tab.

01
U.S. FDA · Final guidance 2025-06-27 · page verified 2026-08-15

Cybersecurity in Medical Devices

Addresses secure design, labeling, premarket documentation, vulnerability management and patient-safety preparation across the product lifecycle.

02
ISO · Published 2019-12 · current edition verified 2026-08-15

ISO 14971:2019 — Medical-device risk management

Specifies a lifecycle process for identifying hazards, estimating and evaluating risk, controlling risk and monitoring control effectiveness.

03
ISO · Published 2016-03 · confirmed 2025

ISO 13485:2016 — Medical-device quality management systems

Sets quality-system requirements for organisations involved in design, production, installation and servicing of medical devices.

04
Beijing Medical Products Administration · Published 2025-04-03

2025 inspection guide for surgical-robot manufacturing quality management

Details expectations spanning design, algorithms, assembly, software installation, inspection, supplier control, maintenance and after-sales capability.