Every medical device already carries an ISO 14971 risk management file. ISO/TS 24971-2, published this year as Part 2 of the 24971 guidance, tells you how to apply that same process to the machine learning inside the product. It does not change what 14971 requires. It shows you how to run it when part of the device learns from data.
The risks it names will look familiar if you have read the FDA guidance: data management, unwanted bias, information security, the training of the model itself, evaluation and testing of the trained model, model drift, and continuous learning. It walks those across development, testing, deployment, retraining, and post-production monitoring, so the ML-specific hazards land in the same file as every other hazard the device has.
Risk and security stop being separate conversations for an AI model. A poisoning attack is a data-management risk and a security threat at the same time. Drift is a performance risk that an attacker can induce on purpose. Because 24971-2 puts information security and these ML hazards inside the 14971 process, the cybersecurity work and the safety work reference the same analysis instead of living in two disconnected documents.
The practical move is to open your existing risk file and add the ML section this guidance describes, rather than starting a separate AI risk exercise off to the side. Reviewers read the 14971 file. Putting the machine learning risks where they already look is how the analysis actually gets seen.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.