fda pccp

How to Prepare an FDA PCCP for AI/ML-Enabled Medical Devices

Introduction

Artificial intelligence and machine learning-enabled medical devices are different from many conventional medical devices because their performance may evolve through controlled software and model updates. 

This creates an important regulatory question: 

How can manufacturers improve an AI-enabled medical device after FDA authorization while maintaining regulatory compliance? 

One mechanism FDA provides for certain planned changes is the Predetermined Change Control Plan (PCCP). 

A PCCP establishes in advance the modifications that may be made and the methodology that will be used to ensure that those modifications continue to meet applicable safety and effectiveness expectations.

Contact Us

Three Key Elements of an FDA PCCP

A PCCP for AI-enabled device software should generally address three fundamental areas: 

  1. Description of Planned Modifications

This section answers: 

What changes does the manufacturer plan to make? 

The manufacturer should clearly identify the modifications and define their boundaries. 

Examples may include: 

  • AI/ML model updates  
  • Algorithm performance improvements  
  • Software compatibility updates  
  • Predefined interoperability changes  
  • User-interface modifications  
  • Performance improvements  

The description within your FDA PCCP must be sufficiently specific for regulators to evaluate the scope and boundaries of proposed software changes.

 

  1. Modification Protocol

This section answers: 

How will the manufacturer develop, verify, validate and implement the modification? 

The protocol may address: 

  • Development methodology  
  • Data management  
  • Dataset selection  
  • Algorithm/model development  
  • Verification  
  • Validation  
  • Performance evaluation  
  • Risk assessment  
  • Cybersecurity assessment  
  • Acceptance criteria  
  • Release criteria 
     

Establishing a clear protocol ensures your FDA Predetermined Change Control Plan provides a repeatable methodology for demonstrating ongoing device safety and effectiveness.

 

  1. Impact Assessment

This section answers: 

What impact could the modification have on the device? 

The manufacturer should consider potential impacts on: 

  • Safety  
  • Effectiveness  
  • Clinical performance  
  • Device performance  
  • Risk controls  
  • Intended users  
  • Patient population  
  • Usability  
  • Cybersecurity  
  • Interoperability  

The assessment should demonstrate that the modification can be appropriately evaluated within the boundaries established by the PCCP.

FDA PCCP Example for an AI Radiology Device

Consider an AI software device that analyzes chest X-rays to assist radiologists in identifying predefined abnormalities. 

Planned modification 

The manufacturer plans to update the AI model to improve performance. 

PCCP may define: 

Modification boundary 

The model may be updated to improve performance while maintaining: 

  • The same intended use  
  • The same clinical indication  
  • The same patient population  
  • The same output type  

Modification protocol 

The manufacturer may define: 

  • Dataset requirements  
  • Data selection criteria  
  • Model development process  
  • Verification testing  
  • Performance validation  
  • Risk assessment  
  • Cybersecurity assessment  
  • Acceptance criteria  

Impact assessment 

The manufacturer would assess potential effects on: 

  • Sensitivity  
  • Specificity  
  • False-positive rate  
  • False-negative rate  
  • Patient safety  
  • Existing risk controls  

This provides a structured framework for determining whether the modification remains within the authorized PCCP. 

Schedule a Compliance Consultation

Accelerate Market Access with End-to-End Regulatory Guidance

PCCP and Risk Management

Risk management should be closely integrated with PCCP activities. 

For each planned modification, manufacturers should consider: 

Modification 

 

Potential hazards 

 

Hazardous situations 

 

Potential harm 

 

Risk controls 

 

Verification/validation 

 

Residual risk 

 

Overall risk acceptability 

This helps demonstrate that the manufacturer has considered how future modifications could affect the device’s existing risk profile. 

PCCP and Verification & Validation

A PCCP should not simply state that the manufacturer will “perform testing.” 

It should establish an appropriate methodology for determining whether the modification is acceptable. 

Depending on the modification, this may involve: 

Modification 

Possible evaluation 

AI model update 

Algorithm verification and performance validation 

UI modification 

Software verification and usability evaluation 

OS compatibility update 

Compatibility testing 

New interface 

Interoperability testing 

Performance improvement 

Performance testing 

Cybersecurity modification 

Security verification/testing 

The exact evidence required will depend on the device and the proposed modification. 

PCCP and Cybersecurity

Cybersecurity should also be considered where a planned software modification can affect the device’s security posture. 

Potential areas include: 

  • Authentication  
  • Authorization  
  • Data protection  
  • Network communication  
  • Third-party software  
  • SBOM  
  • Vulnerability exposure  
  • Security controls  

The manufacturer should determine whether the proposed modification could introduce new cybersecurity risks or affect existing controls. 

PCCP and Usability

If a planned modification affects the user interface or user workflow, the manufacturer should evaluate whether additional usability engineering activities are necessary. 

For example: 

UI modification 

 

Does it affect a critical task? 

 

Does it introduce a new use-related hazard? 

 

Does it affect an existing risk control? 

 

Determine appropriate usability evaluation. 

Therefore, usability should not automatically be excluded from PCCP planning. 

What Makes a Strong FDA PCCP Submission?

A strong PCCP should allow a reviewer to understand: 

  1. What will change?  
  2. How much can it change?
  3. Why is the change needed?
  4. How will it be developed?
  5. How will it be tested?
  6. What acceptance criteria will be applied?
  7. How will risk be assessed?
  8. How will the manufacturer determine that the change remains within the PCCP?

If these questions cannot be answered clearly, the PCCP may be too broad or insufficiently defined.

Conclusion

For AI/ML-enabled medical devices, PCCP can provide a structured mechanism for managing certain anticipated modifications throughout the product lifecycle. 

However, the manufacturer should establish clear boundaries, predefined methodologies, objective acceptance criteria and appropriate risk-based evaluation. 

A PCCP should therefore be developed alongside the device’s software lifecycle, risk management, verification and validation, cybersecurity, usability and clinical/performance evaluation processes.

How Operon Strategist Can Help

Preparing an FDA-compliant Predetermined Change Control Plan (PCCP) for AI/ML-enabled medical devices requires structuring precise modification boundaries, robust protocols, and comprehensive impact assessments.

Operon Strategist provides specialized regulatory consulting services to help AI/ML medical device manufacturers design, document, and execute PCCPs that align with FDA’s latest AI/ML guidance and software lifecycle requirements.

Our Specialized AI/ML PCCP Consulting Services:

  • AI/ML PCCP Strategy & Dossier Development: We assist manufacturers in defining specific, bounded modification descriptions and establishing objective acceptance criteria for AI model retraining, algorithm tuning, and performance optimizations.

  • Modification Protocol & Impact Assessment Design: Complete support in building structured modification protocols—covering dataset selection, verification and validation (V&V), performance evaluation, and risk-based impact assessments on clinical efficacy and safety.

  • Integrated Risk Management & Usability Evaluation: Seamless alignment of PCCP activities with ISO 14971 risk management frameworks, helping you assess potential hazards, evaluate residual risks, and determine necessary usability engineering activities for UI/workflow changes.

  • Cybersecurity & Software Lifecycle Compliance: Guidance on incorporating software security controls, SBOM updates, and architectural documentation into your PCCP in compliance with IEC 62304 software lifecycle standards and FDA cybersecurity expectations.

  • FDA Pre-Submission & Submission Defense: Strategy and preparation for FDA Pre-Submission (Q-Submission) meetings to gain early agency feedback on your proposed PCCP boundaries, along with full support during 510(k), De Novo, or PMA review cycles.

Related Blog: Predetermined Change Control Plan (PCCP) for SaMD: FDA Requirements

Ready to Prepare a Compliant PCCP for Your AI/ML Device?

Contact Operon Strategist Today for a smooth FDA authorization.

FAQ's

An FDA PCCP must include three core sections:

  • Description of Planned Modifications: Specific details on what changes are planned and their boundaries.

  • Modification Protocol: The methodology for developing, verifying, validating, and testing modifications.

  • Impact Assessment: An evaluation of how changes will affect device safety, effectiveness, performance, and risk.

No. All planned modifications within a PCCP must remain within the device’s authorized intended use, clinical indications, and patient population. Any modification altering intended use requires a new FDA marketing submission.

Risk management must be integrated directly into the modification protocol. For every planned AI model or software update, manufacturers must evaluate potential hazards, update risk controls, and ensure overall residual risk remains acceptable before implementation.

Yes. If planned AI updates modify the user interface, clinical workflow, or underlying software architecture, the PCCP must include specific usability engineering and cybersecurity verification protocols.

PCCPs are most commonly rejected when they are overly broad, lack clear boundary limits, or fail to define objective, measurable acceptance criteria for verification and validation.