SaMD: Possible Framework for Risk Categorization and Corresponding Considerations
Proposes the risk-categorisation framework for Software as a Medical Device: category is driven by the significance of the information the software provides to a healthcare decision and by the state of the healthcare situation or condition it addresses.
What this does not cover
stated in the document's own scope- Proposes a risk-categorisation framework; it does not itself set binding controls or approval requirements, which each regulator determines.
- Builds on, and does not restate, the SaMD definitions established in N10.
- Categorises SaMD by information significance and healthcare-situation state; it is not the IEC 62304 software safety-class scheme, which measures potential severity of harm from software failure.
- Is a harmonisation reference from a voluntary forum, not a regulation or a certifiable standard.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
IMDRF/SaMD WG/N12, "SaMD: Possible Framework for Risk Categorization and Corresponding Considerations," proposes how to categorise Software as a Medical Device by the risk it presents. It builds on the N10 definitions and uses two dimensions: the significance of the information the software provides to a healthcare decision (to treat or diagnose, to drive clinical management, or to inform clinical management) and the state of the healthcare situation or condition it addresses (critical, serious, or non-serious). Combining these yields four categories, from I (lowest impact) to IV (highest), and the framework then discusses the considerations — quality, clinical evaluation, and controls — that should scale with the category.
Scope & applicability
All SaMD. The framework is the conceptual basis several jurisdictions have drawn on when setting software classification and evidence expectations.
Legal basis & how it acquires force
N12 is guidance from IMDRF, a voluntary forum of medical-device regulators, and it is expressly a "possible framework"; it is not binding law and imposes no obligation by itself. It acquires influence when member regulators adopt or adapt its risk logic in their own SaMD guidance. IMDRF harmonises, it does not legislate — national authorities give its concepts force through their own rules and clearances, and MDSAP is a separate authority-run programme, not an IMDRF instrument. The framework is therefore a reference for structuring risk, not a certification a product can hold.
Document structure
| Part | Covers |
|---|---|
| Scope and basis | Purpose of the framework and its grounding in the N10 SaMD definitions |
| Significance of information | The three levels — to treat/diagnose, to drive clinical management, to inform clinical management |
| State of healthcare situation | The three states — critical, serious, and non-serious healthcare situation or condition |
| Risk categories I–IV | The matrix combining the two dimensions into four categories, from lowest to highest impact |
| Corresponding considerations | How quality, clinical evaluation, and control expectations scale with the assigned category |
Key requirements
- Documented SaMD categorisation with the reasoning behind both axes
- Evidence and lifecycle rigour proportionate to the category
- Reconciliation of the framework against each market’s binding classification rules
Implementation tips
- Categorise on intended use and clinical context, never on technical complexity
- Keep the categorisation rationale in the technical file — it is the argument behind your evidence scope
- Re-examine the category whenever intended use or claims change; a claims expansion can move it
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
International alignment
N12 extends the IMDRF SaMD set that begins with N10 and continues into the SaMD quality-management-system and clinical-evaluation documents. Its two-axis risk logic has informed regulator thinking on software risk — including risk-proportionate approaches to SaMD across FDA, EU, and other IMDRF-member frameworks — and it complements, rather than replaces, the software safety classes of IEC 62304 and the device risk-management process of ISO 14971.
IMDRF/SaMD WG/N12: frequently asked questions
Quick answers to common questions about IMDRF/SaMD WG/N12.
How does IMDRF N12 categorise SaMD risk?
By two factors: the significance of the information the software provides to a healthcare decision (to treat/diagnose, to drive clinical management, or to inform clinical management) and the state of the healthcare situation (critical, serious, or non-serious). Combined, they place the software in one of four categories, I to IV.
Is the N12 framework mandatory?
No. It is expressly a "possible framework" from IMDRF, a voluntary regulator forum. It influences national SaMD guidance when member regulators adopt or adapt it, but it is not itself binding law.
How does N12 differ from IEC 62304 safety classes?
N12 categorises SaMD by the significance of the information and the healthcare situation it addresses. IEC 62304 classifies software items (A/B/C) by the potential severity of harm from a software failure. They are complementary risk views, not the same scheme.
Does N12 build on N10?
Yes. N12 uses the SaMD definitions established in N10 as its starting point and adds the risk-categorisation framework on top of them.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.