@samqadani.bsky.social

SaMD QE, Tel Aviv. IEC 62304 + FDA cyber guidance. Sea swim on Fridays.

Ai act transparency duties are live. Asked friday if our qms assistant discloses itself, "probably fine". Probably fine is not a compliance position. Make disclosure explicit, reviewable & traceable.

iSO 14971 reality check: every risk control must be verified, not just implemented. 'we added the alarm' is half the sentence; 'and here's the test record proving the alarm works' is the other. Without that link, audits see noise, not risk reduction. How do you prove verification in SaMD tests?

cAPA effectiveness checks, going beyond closing the ticket. In SaMD, prove risk reduction after implementation with post-implementation monitoring, trend analysis, and independent verification that residual risk is controlled. If not, it is paperwork. FDA guidance:...

AI-powered QMS is not a feature label; it's governance. If vendors won't name the model and show the human sign-off path, it's just a sparkle emoji on a dashboard. In SaMD, real trust comes from model-level validation with traceable sign-offs.

tamper-evidence is the real defense of 21 CFR Part 11: an insert-only signature ledger that you can't quietly edit. If a DBA rewrites a signature row, the inspector knows it instantly. Build for append-only history and clear chain-of-custody to actually pass audits...

ngl supplier reality: you're legally on the hook for every part touching your device. When did you last verify a critical supplier's ISO 13485 cert or FDA OAI status? One lapse wrecks traceability and audits. Scale your supplier validation, not your risk.

eU AI Act kicks in 2 Aug. Article 50(1): declare AI unless obvious. A sparkle won't cut if it touches CAPAs/change‑control, put a clear label in the UI + audit log for reviewability & traceability.

uS/Canada QMS teams: the EU AI Act isn't about where your HQ sits. If EU users interact with your AI feature, you may be a 'deployer' under the Act regardless of location, so where your users are matters more than your address, and your audit trails must prove control over AI decisions.

Eudamed actor + udi + nb-certificate registration went mandatory on 28 may. The real bottleneck isn't the form; it's data hygiene. One missing link between udi and nb cert breaks the audit trail on day 1. Fix: lock identifiers, reconcile mappings, enforce cross-system traceability.

74% of workers ask AI questions instead of colleagues - with potentially serious consequences A series of studies revealed that employees are spending less time asking their coworkers for help. Here's how that tactic could backfire and how organizations need to adapt. #hackernews #news

74% of workers ask AI questions instead of colleagues - with potentially serious consequences

A series of studies revealed that employees are spending less time asking their coworkers for help. Here's how that tactic could backfire and how organizations need to adapt.

zdnet.com

AI can translate quality jargon and draft SOP outlines, surface FMEA ideas, and map requirements quickly. But it must never set risk priorities or close CAPAs. AI = brainstorming spark; humans own risk scores, controls, and the evidence in the DHF. Keep traceability and audit readiness human-led.

Ein Kniff der ganz gut funktioniert ist ChatGPT oder Claude anzuweisen eine Software zu programmieren, die die Abrechnung erzeugt und dabei auch umfangreiches automatisches Testing zu verlangen. Aber da ist man dann von den Prozessen schon wieder näher an der manuellen Softwareentwicklung

PCCP is the shield between retrains and FDA churn. Define the predetermined change boundary up front, data, validation, risk controls, and you avoid a brand-new review every update. Are you using one?

class II recall: Rapid Refill Continuous Injection System (UPN M00566001), Medline Namic angiographic syringe adaptor can loosen/disconnect.

class II recall: Rapid Refill Continuous Injection System (UPN M00566001), Medline Namic angiographic syringe adaptor can loosen/disconnect.

juniors citing ChatGPT in QMS reviews isn't progress, it's a latent audit risk. AI can draft, not replace source-of-truth artifacts. Enforce provenance: model version, prompts, citations, and versioned outputs linked to the SOP. How does your team enforce provenance?

CAPAs are supposed to prevent recurrence, not just close tickets. A retrained operator report is not a CAPA, root-cause → corrective action → verification that risk actually drops. Without design/process controls and measurable effectiveness, you're just closing a ticket.

CE MDR actually changed the game for software updates: PMCF and ongoing PMS are baked into every SaMD release, not just the big ones. Updates alter risk profiles and demand evidence trails. Stop treating tweaks as minor.

We do, and have a wildly varying user experience depending on which phone you have that flat out ignores the tech specs like being able to ignore the highest level alerts or silence via dnd. It's such a mess. At least you have different alert levels. Here abducted kids us the nukes inbound alert.