System anatomy · 07

Device and software assurance

Treat mechanics, software, algorithms, sensors, instruments, networks and accessories as one controlled safety case.

Evidence statusClinical evidence framework · intended use, jurisdiction and care-pathway validation requiredLast reviewed: 15 August 2026
07

FUURAA thesis

The clinically deployed configuration—not an isolated component—is the unit that must remain verified.

Engineering map

Turn the title into engineering objects that can be observed, measured and reviewed.

Each layer states the boundary to establish and the evidence needed for the next decision.

01

Configuration

Bind hardware, firmware, software, models, instruments and consumables.

02

Verification

Cover nominal, boundary, fault, timing, interference and recovery behaviour.

03

Release

Require traceability, approval, installation check and rollback readiness.

Verification questions

Write the questions first, then decide whether a demo, test, pilot or operating record can answer them.

Each question needs an object, conditions, denominator, threshold and accountable decision owner.

  1. 01

    What exact configuration was tested?

  2. 02

    Which interfaces are safety-critical?

  3. 03

    How are model and software changes controlled?

  4. 04

    Can the previous safe state be restored?

Evidence to preserve

Enable the next reader to reconstruct conditions, results, failures and the decision.

A conclusion alone loses reviewability; raw records, configuration and exclusions matter too.

  1. 01

    Evidence package 1

    Configuration bill and trace matrix

  2. 02

    Evidence package 2

    Verification, anomaly and release records

  3. 03

    Evidence package 3

    Installation and rollback evidence

Scope boundary

State what this evidence still cannot be generalised to.

Sources and evidence status

Read standards scope, measurement evidence and application conclusions separately.

Source dates and review status remain visible; external sources open in a new tab.

01
ISO · Published 2019-12 · current edition verified 2026-08-15

ISO 14971:2019 — Medical-device risk management

Specifies a lifecycle process for identifying hazards, estimating and evaluating risk, controlling risk and monitoring control effectiveness.

02
ISO · Published 2016-03 · confirmed 2025

ISO 13485:2016 — Medical-device quality management systems

Sets quality-system requirements for organisations involved in design, production, installation and servicing of medical devices.

03
U.S. FDA · Final guidance 2025-06-27 · page verified 2026-08-15

Cybersecurity in Medical Devices

Addresses secure design, labeling, premarket documentation, vulnerability management and patient-safety preparation across the product lifecycle.

04
Beijing Medical Products Administration · Published 2025-04-03

2025 inspection guide for surgical-robot manufacturing quality management

Details expectations spanning design, algorithms, assembly, software installation, inspection, supplier control, maintenance and after-sales capability.