AI & Threat Landscape

ISO/TS 24971-2 folds machine learning into ISO 14971

Every medical device already carries an ISO 14971 risk management file. ISO/TS 24971-2, published this year as Part 2 of the 24971 guidance, tells you how to apply that same process to the machine learning inside the product. It does not change what 14971 requires. It shows you how to run it when part of the device learns from data.

The risks it names will look familiar if you have read the FDA guidance: data management, unwanted bias, information security, the training of the model itself, evaluation and testing of the trained model, model drift, and continuous learning. It walks those across development, testing, deployment, retraining, and post-production monitoring, so the ML-specific hazards land in the same file as every other hazard the device has.

THE STANDARDS LANDSCAPE FOR AI-ENABLED MEDICAL DEVICESIN DEVELOPMENTIEEE P63685BALLOTEDISO/IEC 27090IEC 63450PUBLISHEDAAMI CR515ISO/TS 24971-2IEC PAS 63621HARMONISEDnone
ISO/TS 24971-2: published, machine learning risk folded into the ISO 14971 process.

Where it meets cybersecurity

Risk and security stop being separate conversations for an AI model. A poisoning attack is a data-management risk and a security threat at the same time. Drift is a performance risk that an attacker can induce on purpose. Because 24971-2 puts information security and these ML hazards inside the 14971 process, the cybersecurity work and the safety work reference the same analysis instead of living in two disconnected documents.

The practical move is to open your existing risk file and add the ML section this guidance describes, rather than starting a separate AI risk exercise off to the side. Reviewers read the 14971 file. Putting the machine learning risks where they already look is how the analysis actually gets seen.

Get started

See your device through ELTON.

Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI MedDevice PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
EnterpriseStartups / SMBs Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
One Solution Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON