Writing an AI policy for an ISO 13485 manufacturer
A usable AI policy for a medical device company fits on one page, names what may never reach a public model, and is signed. What to include, and where ISO/IEC 42001 fits.
Most AI policies fail for the same reason most procedures fail: they are written to survive an audit rather than to be read by the person deciding, right now, whether to paste a drawing into a chatbot.
One page, six rules
A policy that works in a device company is short enough to read in two minutes. In practice six rules cover it: approved use is encouraged; no confidential company data in public tools; never any patient-identifying information; AI output is a draft, not a decision; nothing goes straight into a controlled system without Quality approval; report mistakes and leaks with no blame.
The fourth rule is the one that matters most in a regulated setting. AI as decision support is straightforward to defend. AI as an unreviewed input to a device file is not.
Signed, not circulated
In an ISO 13485 environment, awareness has to be attributable. A policy emailed to everyone proves nothing; a policy each person has signed, with a timestamp and a version, is a training record. That distinction costs nothing to implement and is the first thing a notified body asks about.
Version the document and pin each signature to a version. Publishing new rules should create a visible gap — people who accepted v1 have not accepted v2 — rather than silently rewriting what everyone agreed to.
Where ISO/IEC 42001 fits
ISO/IEC 42001 is an AI management system standard. For most manufacturers it is not an immediate certification target, but it is a useful checklist: policy, roles, risk assessment, supplier controls, monitoring, and evidence that all of it happens. Treating it as a structure rather than a certificate keeps the effort proportionate.
The validation question
Anything that touches a QMS record, a device history record or a released document sits inside the validated boundary, and putting AI there is a computer-system-validation exercise, not a pilot. The productive first move is deliberately outside that boundary: drafting, translating, searching and summarising, where a human approves the output before it counts.
That is not timidity. It is how you get a demonstrated benefit and an evidence trail before asking Quality to approve anything harder.
What to write first
Before drafting, find out what people already do. A policy written against imagined behaviour bans things nobody does and permits the one thing everybody does. An anonymous survey first, the policy second — in that order the rules address reality.