(Governing the Algorithm — Article #8)
A Regulatory Pathway Built for a New Kind of Product
Traditional FDA clearance assumes a fixed device: the thing you validate is the thing you ship, and any meaningful change requires a new submission. That assumption never quite fit AI, where models can be retrained and improved as more real-world data accumulates.
The Predetermined Change Control Plan (PCCP) is the FDA's answer to that mismatch. It lets a manufacturer pre-specify, at the time of original clearance, exactly what future changes are anticipated and exactly how each will be validated — so certain updates can happen without a brand-new submission every time.
Why This Shifts What "The Product" Actually Means
Under a traditional 510(k), the product is the model as submitted. Under a PCCP, the product is better understood as the model plus the boundaries and validation method governing everything it's allowed to become next.
✔ Change boundaries — precisely what the model is permitted to update (e.g., retraining on new data within a defined scope), and what it explicitly isn't
✔ Pre-committed validation method — exactly how each anticipated change will be tested before deployment, agreed upon in advance rather than improvised later
✔ Documented change history — an auditable trail of what changed, when, and against what evidence
✔ A defined process for out-of-bounds changes — what happens if a desired update falls outside the pre-approved plan
A weak or vague PCCP doesn't just create regulatory risk — it can leave a company boxed into repeated new submissions anyway, defeating the purpose of having one.
Why Hospitals Are Starting to Ask About This Directly
How is your AI allowed to change after we deploy it?
This question is becoming a standard part of sophisticated procurement and IT governance review — not just a regulatory affairs detail. A hospital adopting a continuously-updating AI wants to know the boundaries of that evolution before agreeing to it, the same way they'd want to know the terms of any other system update policy they're signing up for.
A vendor with a well-constructed PCCP can answer this with specifics. A vendor without one is often answering with "we'll figure that out when it comes up" — which, for a governance-conscious buyer, is not a reassuring answer.
What Founders Consistently Get Wrong
- Treating the PCCP as a submission formality rather than an operational commitment the company has to live inside afterward
- Writing change boundaries too vague to survive FDA review, or too narrow to provide meaningful flexibility once real-world data starts coming in
- Underestimating the monitoring infrastructure required to actually prove, after each change, that performance stayed within the pre-specified bounds — which ties directly back to the drift monitoring discussed earlier in this series
A PCCP is only as strong as the governance and monitoring systems built to execute it. Writing a good plan and then failing to operationalize it is, in practice, no different from not having one.
Final Thought
The original 510(k) proved a specific version of the model was safe and effective.
The PCCP proves the company can be trusted to keep changing that model safely, indefinitely.
510(k) regulates a product.
PCCP regulates a process.
As more AI vendors adopt this pathway, competitive advantage shifts away from who has the best model at launch, toward who has the most credible, well-governed plan for what that model becomes next — and the operational discipline to actually follow it.
Next in the Governing the Algorithm Series:
Post-Market Surveillance for AI: What Hospitals Are Starting to Demand
#HealthcareAI #PCCP #FDA #AIGovernance #SaMD #RegulatoryStrategy #Compliance #DigitalHealth #HealthcareInnovation #ArtificialIntelligence #MedTech #QscriptionTechnologies