Keep it, but add or change elements
Qualified position: the requested changes or conditions in the passage are part of the position, not treated as unconditional support.
Read the source passage
Response to Discussion Question 1 – Risk Assessment I support FDA's objective of establishing a risk-proportionate framework for the regulation of GenAI-enabled medical devices. The proposed two-axis framework based on device activity and the consequences of relying on an incorrect output may provide a useful and pragmatic starting point for high-level regulatory decision-making. However, I believe that the framework would benefit from a clearer definition of the type and purpose of the “risk assessment” being performed. The Discussion Paper appears to focus primarily on an initial assessment used to derive regulatory requirements for a given device. This is an important phase to consider. However, this type of risk assessment may be confused with the product-specific risk assessment that is performed during product development and throughout the product lifecycle. In the Discussion Paper, it seems that the term “risk” is used at both levels even though the underlying concepts do not fully coincide. At the first level, only information that is already defined and can be reliably supported when the initial regulatory criticality is assigned (e.g., in the device description) should be used. Information that becomes available only through subsequent development and risk management should not yet be relied upon. For example, reliable product-specific estimates of the probability of occurrence of harm, or of probabilities associated with specific failure and harm scenarios, may often not yet be available at this stage. This ambiguity becomes even clearer when considering the definition of risk in ISO 14971. In ISO 14971, risk is defined as the “combination of the probability of occurrence of harm and the severity of that harm”. As discussed above, product-specific probabilities may often not yet be sufficiently characterized during the initial phase. Consequently, the term “risk” as used for the initial regulatory assessment may be interpreted differently from the ISO 14971 definition of product risk, which could create ambiguity. In relation to the two-axis framework as proposed in the Discussion Paper, this definition of risk overlaps with the consequences axis. Some passages of the Discussion Paper appear to use the consequences axis more broadly by also considering factors that affect reliance on an incorrect output or the likelihood that such an output results in harm. This seems to be more related to product-specific risk assessment. However, this relationship is not explicitly defined. From my perspective, the Discussion Paper should clarify more explicitly the context in which the term risk is used. It should always be clear at which level the term operates. The two levels should be clearly separated and the terminology should indicate the respective context. I suggest using different terms to avoid confusion: the first level could be described as “criticality” of the product, whereas the second could remain “risk” in accordance with ISO 14971. Furthermore, I suggest separating the two phases and clearly delineating them. I propose the following names for them, while recognizing that these terms are not established regulatory categories. 1. Criticality Assessment / (Regulatory) Criticality Stratification: This phase is used to determine the appropriate level of regulatory oversight and evidence for a defined device and use context. At this stage, only information that is already defined and can be reliably supported should be used, e.g., the type of activity as defined in the Discussion Paper or the severity of a potential harm. Other factors, such as the application context, the required competency profile of users (e.g., lay persons/patients versus healthcare professionals), or other fixed parameters regarding integration of the device into the clinical workflow, may also be considered. This phase could be called Criticality Assessment when it focuses on the general assessment of criticality. Subsequently, I use the term Criticality Stratification because it refers to a categorization into criticality levels that can then be used to determine the applicable regulatory requirements. 2. Product-Specific (Safety) Risk Management This phase refers to the established risk management process according to ISO 14971 that is performed throughout device development and the total product lifecycle, including risk analysis, risk evaluation, risk control, and evaluation of residual risk consistent with ISO 14971. For the following comments, I interpret Section IV of the Discussion Paper primarily as referring to the first phase, i.e., the Criticality Stratification introduced above. The following considerations are based on this interpretation. This initial phase sets the anchor for subsequent regulatory and development steps. Accordingly, only factors that are defined and can be reliably supported at this stage should be used. These may include the following factors where the first two entries primarily correspond
Original source ↗