SPEQ
/
Pricing
Sign InFree account
Start Here
  1. Home/
  2. Start Here/
  3. Building a regulated product
[ ORIENT · 1 OF 5 ]

What you have built already has a second name.

A trained model, its training set, the eval notebook and the sentence in your README that says what it is for: a reviewer reads all of them, under names you have probably not used. This route gives you the names, what each one obliges, and where nobody has drawn the line yet. It assumes you can read a confusion matrix. It does not assume you have read ISO 13485.

FREE · NO ACCOUNT · NOTHING IS INFERRED FROM WHAT YOU BROWSE

Already inside a regulated organisation? Start here · Standards library

A specimen repo, read by a reviewer
What you haveWhat a reviewer calls it
README.md
Intended use21 CFR 801.4
train/ · val/ · test/
Controlled dataset, and who drew the labels
model_v3.pt
Design outputISO 13485 §7.3.4
eval.ipynb
Verification recordISO 13485 §7.3.6
requirements.lock · vendor/
Software bill of materialsFD&C Act §524B
git log — v2 → v3 → v4
Predetermined change control planFDA PCCP (2024)
dicom/ · PACS integration
Not yet written

Solid: SPEQ has drawn this pairing (5).Dashed: nobody has yet (2).

OrientLocateLearnPractiseEvidenceSET YOUR SCOPE →

What this page does not claim

SPEQ decodes the names. It does not determine whether your software is a medical device, and it does not give legal advice. Where a seam reaches patent, copyright or contract law, the drawing stops at a marked edge and says so.

Three altitudes

Not three levels of difficulty, and not a course you are enrolled in. The three positions are marked by what a reviewer is holding at each: nothing yet, then your file, then a record they can recompute. Nothing on this page is inferred from what you read.

  1. 01Where you already areThe reviewer holdsnothing yet

    Nothing has been submitted and nobody outside has read anything. What is decided here is whether the thing you built is a device at all, and which of the files on your laptop are already records.

    4 of 4 written

  2. 02The seamsThe reviewer holdsyour file

    The file has crossed the desk. These are the places where a machine-learning practice and a regulated practice describe the same object and disagree about what must happen to it — which is why the collision lives here and not in the first altitude.

    3 of 5 written · 2 not yet

  3. 03The artefactThe reviewer holdsa record they can recompute

    The far end is not a certificate. It is a record of what ran, on what, against criteria fixed before the result was seen — one a reviewer can check without trusting the party that produced it.

    3 of 3 written

01

Where you already are

Nothing has been submitted and nobody outside has read anything. What is decided here is whether the thing you built is a device at all, and which of the files on your laptop are already records.

Whether your software is a deviceThe sentence in your README that says what it is for is the sentence that decides it.→Design controlsThe clauses that turn what you built into inputs, outputs and records of both.→Verification is not validationYour eval notebook answers one of these questions and not the other.→Risk management for a deviceISO 14971 is the frame every later argument about harm is made inside.→
02

The seams

The file has crossed the desk. These are the places where a machine-learning practice and a regulated practice describe the same object and disagree about what must happen to it — which is why the collision lives here and not in the first altitude.

Validating a learned systemWhat "validated" means for something whose behaviour was fitted rather than specified.→Protect or discloseOne clause requires the training set to be written down and handed over; another says its value is that it is not.→The SBOM and its licence tailYour lockfile is a bill of materials, and every entry in it carries a licence someone will read.→
Design inputs for a learned systemA requirement you can trace to a fitted parameter, when the parameter was never specified in the first place.not yet written
Training data as a controlled artefactProvenance, consent, and who drew the labels — the dataset as an object under change control.not yet written
03

The artefact

The far end is not a certificate. It is a record of what ran, on what, against criteria fixed before the result was seen — one a reviewer can check without trusting the party that produced it.

What you may change after clearanceA predetermined change control plan is the agreement about which retrains do not start again.→Change control, applied to weightsThe mechanism that decides whether v4 is the same device as v3.→The governance evidence recordThe eight questions, how an answer is marked, and what verification does not establish.→

Words that mean something else here

The ledger pairs a file with the name a reviewer gives it. These pair a word with the meaning the regulated estate gives it — the same double-naming, applied to vocabulary, because reading a SPEQ page with the wrong sense loaded is a worse failure than not reading it.

What you mean by itWhat it means in the regulated estate
reference standard

The ground truth a model’s output is scored against — whatever the labels say is true.

A characterised reference material of established quality, used to calibrate a method and qualify a result. Its identity is a property of the substance, not of a judgement. where SPEQ defines it →

labelling

The annotation a human drew on a training image, and the process of drawing it.

Everything printed on or accompanying the product — the instructions for use, the carton, and, in the FDA sense, promotional material. It is a regulated output in its own right. where SPEQ defines it →

validation

The held-out split you tuned against, between train and test.

Evidence that the finished thing meets the user’s need and its intended use — the question your eval notebook does not answer, which is design verification instead. where SPEQ defines it →

specificity

The true-negative rate: of the negatives, how many were called negative.

In analytical method validation, the ability to assess the analyte unequivocally in the presence of everything else in the sample. Not a rate at all. where SPEQ defines it →

The left column is SPEQ synthesis — no standard defines these senses, which is the whole problem. The right column points at the page where SPEQ does define the word.

Where the line is not drawn

Two rows in the ledger are dashed and two seams in Altitude 02 have no page behind them. They are the ones most likely to matter to a team building imaging AI: SPEQ has written nothing on how a training corpus and its labellers become a controlled dataset, and nothing at all on DICOM or PACS integration — that second gap was measured across the whole content estate, not assumed.

What SPEQ has not written yet

  • Controlled dataset, and who drew the labelstrain/ · val/ · test/
  • Not yet writtendicom/ · PACS integration
  • Design inputs for a learned systemA requirement you can trace to a fitted parameter, when the parameter was never specified in the first place.
  • Training data as a controlled artefactProvenance, consent, and who drew the labels — the dataset as an object under change control.

Drawn dashed rather than left out: a gap you can see is worth more than a list that looks complete. The first people in the room shape what gets written first.

Where to go next

Each solid row in the ledger is a link into the standard that gives the reviewer-side name its force. Two are worth reading first: the design-control clauses that turn your weights and your eval notebook into a design output and a verification record, and the change-control plan that decides what you may retrain without a new submission.

ISO 13485 →Design outputs and design verification — §7.3.4 and §7.3.6, incorporated by reference into the US QMSR since 2 February 2026.FDA PCCP for AI-enabled devices →What you may change about a model after clearance, agreed in advance — the final guidance, 4 December 2024.
SPEQ

Practitioner-grade GxP execution intelligence for regulated industry.

About SPEQ →
Weekly GxP Briefing

What changed, what cleared review, and what it touches. One email, Tuesdays.

Framework
The FrameworkMaturity ModelProject DeliveryQuality EconomicsEnterprise Pillars
Disciplines
DisciplinesIndustriesSectors
Standards & Topics
StandardsRegulatorsTopic ExplainersGlossary
Tools & Templates
TemplatesInteractive ToolsSoftware Directory
Resources
What ChangedGxP HorizonLive IntelligenceBriefing ArchiveSPEQ Listen
All of SPEQ →Every section, every index, every count.
© 2026 SPEQSPEQGX.COMv1.369.0
MethodologyCoverageContact
PrivacyTerms

SPEQ decodes published standards and does not issue applicability determinations.

TodayStandardsSaved