(Governing the Algorithm — Article #1)
What "Cleared" Actually Certifies
FDA 510(k) clearance is a real, meaningful determination — but it's narrower than most people outside regulatory affairs assume. It certifies that:
✔ The device, as submitted, is substantially equivalent to a predicate
✔ Its performance data, as tested, met the defined safety and efficacy bar
✔ Its intended use, as described in the submission, was appropriately supported
Notice the repetition: as submitted, as tested, as described. Clearance is an assessment of a specific version of the product, evaluated against a specific dataset, at a specific moment in time. It says nothing, by itself, about what happens after that moment.
Where the Gap Opens Up
"We're cleared — why is the hospital still asking about our monitoring plan?"
This question comes up constantly, and it reveals the gap directly. A hospital's compliance and IT teams aren't asking whether the FDA approved the product. They're asking a forward-looking question clearance was never designed to answer:
-
What happens if this model's performance changes after deployment?
-
Who is watching for that, and how often?
-
If something goes wrong six months from now, is there a documented process for catching it — or does the hospital find out from a bad outcome?
None of these are regulatory-affairs questions. They're operational governance questions, and a clearance letter has no opinion on any of them.
Governance Is What Clearance Doesn't Cover
Where clearance is a one-time regulatory judgment, governance is the ongoing management system that keeps a product trustworthy for as long as it's in use. In practical terms, that system covers:
- Data governance
— is the data feeding and monitoring the model still reliable and representative?
- Model risk management
— what could this model get wrong in the field, and how would anyone find out?
- Human oversight
— where does a person actually intervene, and can they meaningfully do so?
- Change control
— what's allowed to change about the model after deployment, and how is that validated?
- Accountability
— when something does go wrong, who is responsible, and was that decided in advance or after the fact?
A cleared product with none of this in place isn't ungoverned because it's non-compliant on paper — it's ungoverned because nothing is actually watching it.
Why This Distinction Is Becoming Impossible to Ignore
A few years ago, "we're FDA cleared" was often sufficient to move a sales conversation forward. That's changing for three concrete reasons:
-
The FDA's own Predetermined Change Control Plan pathway now requires vendors to describe, in advance, how a model is allowed to change — which is explicitly a governance question baked into the regulatory process itself
-
Hospital IT and compliance teams have seen enough AI-related incidents in the news to start asking about oversight before they ask about accuracy
-
Emerging standards like ISO/IEC 42001 are giving buyers a structured way to evaluate governance maturity — turning what used to be an informal trust judgment into something they can actually audit against
Vendors who can only answer the clearance question are increasingly finding that's only half the conversation.
Final Thought
Clearance answers: was this product safe and effective when it was reviewed?
Governance answers: can this product still be trusted today, and tomorrow, and after its next update?
Clearance is a credential.
Governance is a commitment.
The companies that build real governance infrastructure — not just a clearance letter — are the ones that will still be trusted a year after deployment, not just on launch day.
Next in the Governing the Algorithm Series:
The Governance Gap: Why Most AI Vendors Have a Model, Not a Management System
#HealthcareAI #AIGovernance #SaMD #FDA #Compliance #RiskManagement #DigitalHealth #HealthcareInnovation #ArtificialIntelligence #MedTech #QscriptionTechnologies