
In October 2022, the MHRA published the Software and AI as a Medical Device Change Programme Roadmap — a programme to ensure regulatory requirements for software and AI are clear and patients are protected. The programme builds on wider UK medical device reforms and delivers bold steps toward a framework that protects patients while positioning the UK as a home of responsible innovation.
For Hong Kong healthcare professionals evaluating digital health products — especially those referencing UK conformity or international harmonisation — understanding this roadmap clarifies what manufacturers should demonstrate across the device lifecycle.
Two workstreams, eleven work packages
The change programme includes eleven work packages across two workstreams:
Stream 1: SaMD lifecycle (eight work packages)
Reforms across the classical software medical device lifecycle:
| Work package | Focus |
|---|---|
| WP 1 Qualification | What qualifies as SaMD; crafting intended purpose; clarifying "manufacturer" |
| WP 2 Classification | Risk-proportionate classification rules aligned with IMDRF; "airlock" sandbox concept |
| WP 3 Premarket requirements | Essential requirements, best practice development, human-centred SaMD, data governance |
| WP 4 Post-market | Vigilance signal detection, adverse incident guidance, change management, PCCPs |
| WP 5 Cyber secure medical devices | Cybersecurity legislation and guidance; unsupported legacy software |
Stream 2: AI-specific challenges (three work packages)
Addresses challenges AIaMD poses over and above classically programmed software:
| Work package | Focus |
|---|---|
| WP 9 AI Rigour | GMLP mapping, standards, best practice AIaMD development, bias frameworks |
| WP 10 Project Glass Box | Human-centred AIaMD; interpretability and transparency for safety |
| WP 11 Project Ship of Theseus | Adaptivity — static, batch-trained, individualised, and continuous-learning models; PCCPs for AIaMD |
Programme aims
Broadly, the change programme seeks to ensure that:
- A. Requirements for software and AIaMD provide assurance that devices are acceptably safe and function as intended
- B. Requirements for manufacturers are clear, supported by guidance and streamlined processes
- C. Friction is reduced through alignment with NICE, NHS England, and international partners including IMDRF
MHRA emphasises international harmonisation — regulatory innovation that departs from global consensus can burden manufacturers and delay access to effective products.
Qualification and classification
WP 1 (Qualification) addresses lack of clarity on what qualifies as SaMD — distinguishing SaMD from wellbeing software, IVD software, medicines, in-house manufacture, and accessories.
WP 2 (Classification) reforms classification rules to align more closely with the IMDRF risk categorisation framework, ensuring rules are proportionate to patient and public safety while allowing flexibility for novel devices.
A well-crafted intended purpose is the cornerstone of compliance — failure to define it adequately impairs quality management, clinical evidence generation, and post-market surveillance.
Post-market vigilance and the Yellow Card scheme
WP 4 (Post-market) strengthens safety signal detection for SaMD. MHRA receives relatively few adverse incident reports for software; investigations indicate reportable incidents — including indirect harm — are often not reported.
Indirect harm may occur when a medical decision, action taken, or action not taken is based on information or results provided by the device. Guidance will clarify what constitutes a reportable adverse incident and emphasise populations within the intended purpose in vigilance processes.
Reporting incidents in the UK
Healthcare professionals and patients can report problems with any medical device — including SaMD — via the Yellow Card scheme or Yellow Card app:
- England and Wales — Yellow Card scheme
- Scotland — NHS National Services Scotland online incident reporting plus local systems
- Northern Ireland — Northern Ireland Adverse Incident Centre plus local systems
For Hong Kong clinicians using UK-origin tools or participating in multi-site trials, understanding that vigilance reporting is expected for indirect as well as direct harm helps set appropriate local incident review processes.
AI work packages in brief
- WP 9 delivered the joint GMLP guiding principles (October 2021) and continues mapping them to UK legal requirements and standards
- WP 10 focuses on human interpretability — ensuring opacity of AIaMD is translated into safety and effectiveness concerns, emphasising human–AI team performance
- WP 11 addresses adaptivity categories: static AIaMD (data drift), batch-trained updates, individualised models, and continuous learning on streaming data — linking to PCCPs
Practical takeaway for Hong Kong
When reviewing vendor documentation, map it against lifecycle stages the roadmap covers: qualification, classification, premarket evidence, post-market surveillance, cybersecurity, and — for AI products — GMLP alignment, transparency, and change management including PCCPs.
Source: MHRA — Software and AI as a Medical Device Change Programme Roadmap (Published 17 October 2022)