AI/ML SaMD

Predetermined Change Control Plans for AI/ML Medical Devices: A Practical Drafting Guide

By Andre Butler  ·  August 11, 2026  ·  ← All Insights

Predetermined Change Control Plans (PCCP) for AI/ML devices: a practical drafting guide

Photo by Zulfugar Karimov on Unsplash

Why Your AI/ML Device Needs a PCCP Before You Ship

If your medical device incorporates artificial intelligence or machine learning, your software will change after market authorization. Models will be retrained. Performance thresholds will be refined. Data pipelines will evolve as real-world inputs replace your training set. The core regulatory question is not whether your algorithm will change -- it is whether you have a credible, documented plan for managing those changes without submitting a new 510(k) or PMA supplement every time your model updates.

That is exactly what a Predetermined Change Control Plan (PCCP) is designed to solve. For founders and regulatory teams building AI/ML-enabled Software as a Medical Device (SaMD), understanding how to draft a defensible PCCP is no longer optional. It is a competitive and compliance necessity.

The Regulatory Foundation You Need to Know

FDA's authority to accept PCCPs comes from Section 515C of the Federal Food, Drug, and Cosmetic Act, as amended by the FDA Safety and Innovation Act and later strengthened by the AI/ML Action Plan published in January 2021. The agency's January 2025 final guidance, Predetermined Change Control Plans for Artificial Intelligence-Enabled Devices, is the governing document you must work from. It supersedes the 2023 draft and represents FDA's current thinking on scope, content, and review expectations.

Relevant regulatory hooks include 21 CFR Part 820 (Quality System Regulation, now harmonized with ISO 13485 under the Quality Management System Regulation), 21 CFR Part 880 for certain SaMD classifications, and the existing Software as a Medical Device guidance framework that FDA adopted from IMDRF. Your PCCP does not exist in isolation -- it is an extension of your device's software lifecycle documentation and your overall Design Controls under 21 CFR 820.30.

What a PCCP Must Actually Contain

FDA's final guidance specifies three core components. If your PCCP is missing any of them, expect a deficiency letter or an AI/ML-specific request for additional information during substantive review.

1. Description of Planned Modifications

This section must articulate, with specificity, the types of modifications you anticipate. Vague language like 'performance improvements' will not pass review. Instead, define the modification by category: algorithm architecture changes, updates to training data inputs, recalibration of decision thresholds, changes to the intended use population, or modifications to output display logic. Each category should map to a clinical or performance rationale -- why would this change be needed, and what would it affect in the device's risk profile?

2. Methodology for Implementing Modifications

This is where your engineering rigor is on display. FDA expects you to describe the processes, testing protocols, and performance evaluation methods that will govern how each modification type is implemented. This includes your approach to training data governance, bias and drift monitoring, and the statistical validation benchmarks a modification must meet before it is deployed. Reference your software development lifecycle (SDLC) documentation and specify how your change implementation ties back to design verification and validation activities under 21 CFR 820.30(f) and 820.30(g).

3. Impact Assessment

For each planned modification category, you must document how you will assess whether the change affects safety or effectiveness in ways that would require a new premarket submission. This is not a checkbox exercise. FDA wants to see a structured risk-based decision framework -- one that considers changes to intended use, changes to indications for use, and modifications that could introduce new failure modes not covered in your original submission's risk analysis under ISO 14971.

Common Drafting Mistakes That Trigger Deficiencies

  • Overly broad modification descriptions that give you flexibility but give FDA nothing to evaluate. Specificity builds credibility.
  • Disconnected validation methodology that references internal procedures without describing them. If your PCCP cites a validation protocol, summarize its decision criteria in the submission itself.
  • Missing performance benchmarks. FDA expects quantitative thresholds -- sensitivity, specificity, AUC, or device-specific metrics -- that define when a modification is acceptable versus when it triggers escalation to a new submission.
  • Ignoring real-world performance monitoring. Your PCCP should describe how post-market data feeds back into your change control decisions. FDA's guidance explicitly expects this closed-loop approach.
  • Treating the PCCP as a standalone document. It must integrate with your 510(k) or PMA submission's software documentation, labeling, and risk management file.

Strategic Considerations for Startup Founders

If you are pre-submission, the time to design your PCCP is during your algorithm development phase -- not after you have locked your model architecture. The modifications you anticipate must be technically plausible given your current development roadmap. A PCCP that describes changes your engineering team has no infrastructure to execute will not survive FDA scrutiny, and it will not serve your post-market operations either.

For companies pursuing De Novo classification for a novel AI/ML device, the PCCP is an opportunity to shape the special controls that FDA will assign to your device type. Proactively drafting a PCCP that demonstrates responsible AI governance can actually strengthen your De Novo request by showing FDA that your organization has the quality infrastructure to support an iterative, continuously learning device.

Work With a Regulatory Partner Who Knows AI/ML SaMD

Drafting a PCCP that satisfies FDA while giving your development team the operational flexibility they need is a precision exercise. At ADB Consulting and CRO Inc., we have helped medical device companies structure AI/ML submissions that reflect both regulatory defensibility and real-world product strategy. Whether you are preparing your first 510(k) with a PCCP module or responding to deficiencies on an existing submission, we can help you get it right.

Book a free discovery call with Andre Butler at adbccro.com and let's build your PCCP the right way -- before FDA asks why you did not.

Andre Butler

Principal Consultant — ADB Consulting & CRO Inc.

Andre Butler has 20+ years of hands-on FDA regulatory experience guiding medical device companies through 510(k), PMA, De Novo, AI/ML SaMD, and FDA 483 response engagements. He specialises in Section 524B cybersecurity compliance and ISO 13485 quality management systems, with a track record across cardiovascular, orthopedic, diagnostic, and software-as-a-medical-device categories.

Ready to Navigate the FDA Process with Confidence?

Book a free 30-minute discovery call with Andre Butler. No sales pitch -- just expert regulatory guidance on your specific device and situation.

Book a Free Pathway Call

Or call directly: (888) 450-8607

Explore our flat-fee FDA services →