What FDA Auditors Check First in SaMD Quality Systems — and How AI Is Changing the Prep Work
FDA auditors follow a predictable playbook in SaMD inspections. Here's what they check first — and how AI-augmented audit prep is cutting readiness timelines.
Design controls — specifically 21 CFR 820.30 — have ranked among the top five most-cited observations in FDA medical device inspections for more than a decade running. For Software as a Medical Device companies, that stat carries extra weight. SaMD quality systems carry documentation layers that traditional hardware-centric device files don’t: software lifecycle records, algorithm validation evidence, risk classification rationale under IEC 62304, and now — with FDA’s AI/ML Predetermined Change Control Plan guidance finalized in late 2024 — a forward-looking plan for how your algorithm is allowed to evolve post-clearance.
Inspectors walk in knowing exactly what a weak SaMD quality system looks like. Most of them have seen dozens. What follows is a direct account of what they look for first — and why AI-augmented audit preparation is changing how companies get ready.
The First Three Documents an FDA Auditor Opens
Before an inspector spends a minute reviewing your production records or CAPA logs, they’re going to establish whether your design controls tell a coherent story. For SaMD, that means three specific document packages.
The Design History File (DHF). Under 21 CFR 820.30(j) — and its counterpart in the QMSR, which became effective February 2, 2026 — manufacturers must maintain a DHF demonstrating the device was developed in accordance with the approved design plan. For SaMD, this means the DHF must contain not just design inputs and outputs, but traceable evidence that software requirements were formally established, tied to architecture, and verified at each lifecycle stage. Gaps in traceability are the single most common finding in SaMD audits, and they’re surprisingly easy to create in agile development environments where documentation is added after the fact.
The Software Validation and Verification (V&V) Package. FDA expects a Software Validation Master Plan that connects directly to your IEC 62304 safety class determination. Class C software — whose failure could result in death or serious injury — requires 100% requirements traceability, documented unit testing, integration testing, and system testing. Auditors will cross-reference your safety class determination against your actual risk analysis to make sure you haven’t under-classified. Under-classification is common when early-stage companies assign safety classes before a thorough hazard analysis is complete.
Risk Analysis Documentation. ISO 14971:2019 is the medical device risk management standard FDA references in its current software guidance. Your risk file needs to address software-specific hazards explicitly — not just device-level hazards with a brief software appendix. An auditor who finds a risk analysis built almost entirely around hardware failure modes, with two paragraphs addressing software, will issue a 483 observation before the opening meeting ends.
Design Controls Under the QMSR — and Where SaMD Companies Are Still Getting Caught
The QMSR’s alignment with ISO 13485:2016 was intended to ease compliance burden for manufacturers already certified to the ISO standard. For SaMD developers who were FDA-focused but never pursued ISO 13485 certification, the transition introduced unfamiliar documentation expectations — particularly around design review records.
Under ISO 13485 Section 7.3, design and development reviews must be conducted at suitable stages and documented formally, including who participated and what decisions were made. FDA auditors trained on the new QMSR are looking for evidence that these reviews happened in real time, not reconstructed during a documentation cleanup effort ahead of a 510(k) filing. The distinction sounds administrative. But auditors who’ve seen both versions — genuine real-time records versus retrofit documentation — can usually tell the difference.
Traceability matrices have become essentially non-negotiable. If you can’t hand an auditor a document tracing every software requirement to a test case, and every test case to a test result, you’re in trouble. This isn’t bureaucratic overhead — it’s how you demonstrate that the device that cleared 510(k) review is actually the device being deployed to clinical environments.
Design transfer is another persistent gap. Under 21 CFR 820.30(h), procedures must ensure that design outputs are correctly translated into production specifications. For SaMD, “production” means your deployment pipeline. If you don’t have documented change control over what gets pushed to production — and records confirming that the validated version is what clinicians are actually using — that’s a direct audit target.
AI/ML-Based SaMD: The Audit Wrinkle That Catches Companies Off Guard
The FDA published its AI/ML-Based SaMD Action Plan in January 2021, and the industry largely noted it and moved on. That was a miscalculation. The agency had been quietly building toward a framework requiring proactive oversight of adaptive algorithms, and the culmination was the Predetermined Change Control Plan (PCCP) final guidance, issued in December 2024.
Here’s the audit exposure: if your SaMD uses a machine learning model that continues to retrain after deployment — what FDA calls an “adaptive” algorithm, as opposed to a “locked” one — you need a PCCP. And that PCCP needs to be included in your premarket submission and approved as part of your device authorization. An auditor who finds evidence that your algorithm’s performance parameters have drifted post-clearance, with no PCCP on file, is looking at a potential major nonconformance.
Even for locked algorithms, FDA’s transparency expectations mean your technical file needs to describe the training data, the algorithm’s known limitations, and how outputs are intended to be interpreted by the end user. These aren’t aspirational guidelines — they’re increasingly showing up as direct expectations during CDRH inspections of AI-enabled 510(k)-cleared devices.
The IMDRF SaMD risk framework (N41) organizes SaMD risk across four categories based on the significance of the information provided and the severity of the healthcare situation involved. FDA’s current thinking aligns closely with that framework. If your AI diagnostic tool operates in a Category III or IV situation — informing treatment decisions for serious or life-threatening conditions — your validation package needs to match that risk weight. Auditors assess whether the evidence is proportionate to the risk. A Category IV device validated against a small retrospective dataset is going to attract hard questions.
How AI-Augmented Audit Prep Is Cutting SaMD Readiness Timelines
Traditional SaMD audit preparation — the kind where you bring in regulatory compliance consulting services two to three months before an expected inspection — follows a familiar pattern. A consultant reviews your DHF, V&V records, and risk file, produces a gap report, and you remediate. That cycle typically runs six to twelve weeks, and the consultant’s effectiveness depends on their ability to manually cross-reference hundreds of pages of technical documentation against current FDA guidance language. Human reviewers are good at this. They’re not infallible at page 300 of a 450-page design history.
AI-augmented audit preparation changes the economics substantially. When you can feed a complete SaMD technical file into a decision-grade AI system trained on current QMSR, IEC 62304, ISO 14971, and FDA software guidance, the gap identification phase compresses from weeks to days. The system doesn’t lose focus or skip a footnote that contains a critical deviation.
At Aurora TIC, our DeepGMP engine is purpose-built for this kind of engagement. It maps your documentation against a structured QMSR + IEC 62304 + ISO 14971 requirement set, flags discrepancies with citation-level precision, and generates a prioritized remediation list ranked by inspection risk. AI-augmented SaMD gap assessment engagements start at $500 — a fraction of what traditional regulatory compliance consulting services cost for comparable scope, and typically complete faster.
The AI handles pattern recognition at scale. The judgment calls — whether your design transfer records are genuinely adequate, whether your risk analysis rationale would hold up under questioning from a seasoned CDRH inspector — still require someone who’s been in those rooms. Our approach pairs DeepGMP’s analytical speed with consulting expertise that understands what “adequate” means to a device auditor in 2026, not 2019.
The companies that arrive at FDA inspections most prepared aren’t the ones with the longest documentation packages. They’re the ones who found their own gaps first — and had a defensible answer ready before the inspector’s first request.
Before your next inspection or premarket submission, run this three-question self-check: Can you produce a complete, current traceability matrix within 48 hours? Does your risk file address software-specific hazards explicitly under IEC 62304? And if your product uses an adaptive AI component, is your PCCP approved and on file? Those three questions map directly to the first hour of a CDRH audit. Know your answers before the inspector does.
Written by Sam Sammane, Founder & CEO, Aurora TIC | Founder, Qalitex Group. Learn more about our team
Reserve early access to our AI audit tools Contact us
Related from our network
- ISO 17025-Accredited Testing for Medical Device Manufacturers — Qalitex Laboratories provides third-party analytical and biocompatibility testing for device component qualification and supplier audits.
- Health Canada Medical Device Compliance Testing — Androxa supports device manufacturers entering the Canadian market with GMP-aligned testing and regulatory documentation services.
هل تحتاج إلى مساعدة في اختيار المختبر المناسب؟
تُؤازر Aurora TIC المصنّعين والعلامات التجارية في إيجاد مختبرات الاختبار المعتمدة — بسرعة ومجاناً ووفقاً لمتطلبات منتجكم.
احصل على عرض سعر مجاني