The mini-QMS for Class I SaMD and AIaMD

IIn the UK, Class I SaMD and AIaMD products are self-certified, which means no UK Approved Body (or EU Notified Body), no ISO 13485 certification, and no third-party conformity assessment.

For many early-stage manufacturers, that sounds like a significantly lighter path to market than it turns out to be. In the US, manufacturers of devices "automated with computer software" must comply with certain requirements of a Quality Management System (QMS).

The regulatory floor for the lowest-risk classification is higher than most people building their first device anticipate. What does a Class I SaMD or AIaMD product actually require in the UK and US? What does the Hardian Health mini-QMS cover? And where do the boundaries lie?

What the regulations require

UK

As of July 2026, two statutory instruments govern Class I self-certified SaMD and AIaMD in Great Britain, both sitting under the Medicines and Medical Devices Act 2021:

  • SI 2002 No. 618 – The Medical Device Regulations (2002) as amended

  • SI 2024 No. 1368 – The Medical Devices (Post-market Surveillance Requirements) (Amendment) (Great Britain) Regulations 2024

Class I SaMD and AIaMD products do not require a full, formally certified QMS. A mini-QMS is recommended instead.

US

The FDA's Quality Management System Regulation (QMSR) requires design control for all SaMD and AIaMD, including Class I exempt products, under 21 CFR 820.10(c)(1). Even if your device falls into the lowest risk tier, design control obligations apply.

UK vs EU Class I

It’s vital to be precise because getting this wrong can lead to some major headaches down the road.

  • UKCA marking covers Great Britain only (England, Scotland, Wales). It does not apply in Northern Ireland.

  • CE marking is required for Northern Ireland, which remains aligned with EU MDR.

  • EU Class I self-certified devices under EU MDR still require a fuller QMS than the UK Class I baseline.

Under EU MDR Article 10(9), EU Class I manufacturers need processes covering regulatory strategy, general safety and performance requirements (GSPR) identification, management responsibility, supplier control, risk management, clinical evaluation and postmarket surveillance (PMS)/ postmarket clinical followup (PMCF), product design and development, UDI verification, postmarket surveillance, communication with regulators and notified bodies, serious incident reporting, corrective and preventive action (CAPA), and ongoing output monitoring. That is 13 requirements, and they sit meaningfully closer to a full QMS than the UK Class I baseline.

Generally for SaMD, certain documentation must also be retained for 10 years after the last device is placed on market, with escrow or equivalent arrangements covering the possibility that the manufacturer ceases trading within that period.

For manufacturers targeting both Great Britain and Northern Ireland, EU MDR obligations need to be built into the documentation approach from the start rather than bolted on later. Non-UK manufacturers deploying into Great Britain must also appoint a UK Responsible Person (UKRP) to handle MHRA registration on their behalf.

What goes into the Medical Device File

Before placing a Class I device on the market, manufacturers must produce a Medical Device File (MDF) demonstrating the device is safe, effective, and cybersecure. For SaMD and AIaMD, the MDF under the EU Medical Device Regulation (EU MDR) and In vitro Medical Device Regulation (EU IVDR) typically covers:

Technical documentation overview
Part What it covers Key documents
A Device description and specification Intended Use Statement, Regulatory Strategy Record, Software Description Overview
B Information supplied by the manufacturer Instructions for Use, Software Installation & Configuration Instructions, Software Support & Maintenance Instructions
C Design and manufacturing information Software Development Plan, Requirements Specification, Software Architectural Description, Design Review Record
D General Safety and Performance Requirements (GSPR), including General Data Protection Regulation (GDPR) GSPR compliance summary, GDPR compliance summary
E Benefit-risk analysis Risk Management Plan, Security Risk Analysis, Risk Management Report, Benefit-Risk Analysis
F Pre-clinical information Software Verification Plan and Report, Usability Evaluation Plan and Report
G Clinical information Clinical Evaluation Plan, Literature Review Report, Clinical Evaluation Report, PMS Plan
Declaration of Conformity Draft DoC for UKCA, CE, and other applicable jurisdictions

The MDF is not the QMS; the MDF is what QMS procedures and templates are used to produce, as described in a previous article.

What a mini-QMS includes

A full ISO 13485-certified QMS, suitable for the UK, EU and US jurisdictions, runs to around 20 procedures across six subsystems in the way that Hardian Health’s reference model QMS is laid-out. A Class I manufacturer doesn't need most of that. The Hardian mini-QMS is built around two areas where obligations are real and meaningful even at Class I.

Design control, clinical evaluation, and risk management

In our reference model, these are covered by four plans written as MDF documents:

  • Software Development Plan (SDP)

  • Clinical Evaluation Plan (CEP) – or Performance Evaluation Plan (PEP) for IVDs

  • Risk Management Plan (RMP)

  • Cybersecurity Management Plan (SMP)

Postmarket surveillance, complaint handling, and regulatory reporting

These are covered by:

  • Postmarket Surveillance Plan (PMP) – covering proactive and reactive monitoring for safety, effectiveness, and cybersecurity

  • Data Protection Procedure

  • Postmarket Surveillance, Feedback, Complaint Handling and Reporting Procedure

  • Corrective and Preventive Action (CAPA) Procedure, including incident handling for

    • Clinical safety incidents

    • Information security incidents

  • Establishment and Product Registration Procedures

What a mini-QMS does and does not include

A common mistake is either over-building (spending months on procedures that aren't required) or under-building (assuming "Class I exempt" means no documentation obligations at all). The table below shows which elements of a full Integrated Management System apply to the mini-QMS and which do not.

Key:

✓ Included in mini-QMS
✗ Not required at Class I
! Recommended but not mandated

Quality management system scope
Subsystem Procedure Mini-QMS
Management Quality Manual including Quality & Infosec Policies, Objectives and KPIs
Management Document Management – control of documented information
Management Human Resources, Infrastructure, Work Environment
Management Organisation & Product Risk Management
Measurement, Analysis & Improvement Auditing – Internal, Supplier, External and Unannounced
Measurement, Analysis & Improvement Corrective and Preventive Action (CAPA) including incident and complaint handling
Measurement, Analysis & Improvement Statistical techniques
Design and Development Design Control and Risk Management
Design and Development Clinical Evaluation / IVD Performance Evaluation (a Clinical Evaluation Plan is still required at Class I)
Production and Service Controls Computer Software Validation
Production and Service Controls Production Control / Installation & Servicing
Production and Service Controls Control of Nonconforming Product
Production and Service Controls Data Protection (GDPR / NHS IG) and Information Security Management (ISO 27001) !
Production and Service Controls Customer Management
Purchasing Supplier Management and Purchasing
Jurisdiction-specific Postmarket Surveillance / Feedback / Complaint Handling / Reporting
Jurisdiction-specific Establishment and Product Registration including UDI !

Design control and risk traceability

One of the areas where a mini-QMS adds the most practical value is in design control. You’ll need to go beyond just writing a standalone Software Development Plan. It’s important to keep a clear trail throughout your entire product lifecycle, connecting your high-level user needs straight through to your design outputs, verification protocols, and validation evidence.

Design Control and Risk Management: requirement and risk tracing

Without this traceability in place, a regulatory submission can demonstrate that a product was built, but not that it was built to satisfy the needs it was intended to meet. That distinction is important to assessors and when the product is updated.

MHRA registration: the five steps

Once the MDF is complete, MHRA registration for a Class I UKCA device follows this sequence:

  1. Confirm the device qualifies as a medical device and can be legitimately classified as Class I UKCA

  2. Select the correct Global Medical Device Nomenclature (GMDN) code and place it on a draft Declaration of Conformity

  3. Complete the MDF, ensuring the relevant Essential Requirements under Annex I of the Medical Device Directive are satisfied

  4. Sign the Declaration of Conformity

  5. Register the company and product on MHRA DORS and pay the registration fee

Why bother with any QMS at all?

If the regulatory minimum for Class I is essentially "produce good technical documentation and put a PMS plan in place," the case for a QMS needs to be made on practical grounds, not just compliance ones.

Without defined processes, the documentation produced for the first submission has no reproducible method behind it. When the software is updated, a clinical claim changes, or a safety event requires a response, there is no systematic record of how decisions were made. The documentation becomes a one-off, and the next submission starts from scratch.

The teams that find regulatory submissions hardest are often those who treat documentation as a sprint at the end of development rather than a continuous and continual output of the development process itself. A mini-QMS changes that, giving a small team enough structure to produce consistent documentation and handle complaints in a way an auditor can follow.

The case for a mini-QMS also rests on forward compatibility. By establishing robust design control and risk management foundations early, a manufacturer ensures that a future transition to a full ISO 13485-certified system does not require a total rebuild. Procedures and templates are designed to map across directly, keeping the regulatory audit trail intact. Should a device eventually shift to a higher risk tier or encounter procurement requirements demanding formal certification, the necessary technical groundwork is already established.

If you're building a Class I SaMD or AIaMD product and want to understand what a proportionate quality system looks like for your stage and jurisdiction, get in touch.

Kristina Melakh

By Kristina Melakh, Associate - Quality Assurance Regulatory

Next
Next

Clinician in the AI Loop: a faulty solution to a thorny problem