Pre-market Services

Data Management & Governance

Establish structured data management and governance procedures for medical devices and AI systems to support regulatory compliance, traceability, and data integrity.

Services

  • Data management operating procedures
  • Data governance policies (e.g. data acquisition, data supplier management)
  • Data supplier management
  • Data protection frameworks
  • Data protection impact assessments
  • Data standard compliance (e.g. IEC PAS 63621, ISO/IEC 5259)
  • AI/ML dataset governance support
  • Data classification and access management
  • Data retention and documentation controls
  • GDPR and health data protection (e.g. NEN 7510-1, ISO/IEC 27001)
  • Data management process implementation
Our Specialty

What Do We Offer?

Medical devices and AI systems rely heavily on structured, reliable, and traceable data. Regulatory frameworks increasingly expect manufacturers to demonstrate how data is collected, managed, protected, and maintained throughout the product lifecycle.

We support organisations in implementing data management and governance processes aligned with MDR, IVDR, EHDS, FDA requirements, GDPR, AI Act and applicable data management standards. This includes governance structures, traceability, data integrity controls, data risks (e.g. bias, drift), and dataset management for AI/ML systems.

Our approach focuses on practical implementation throughout the full product lifecycle. Effective governance supports compliance while improving consistency, transparency, and long-term maintainability of medical device and software systems.

Relevant Resources - EU

  • MDR 2017/745 (EU Medical Device Regulation)
  • IVDR 2017/746 (EU In Vitro Diagnostic Medical Device Regulation)
  • GDPR 2016/679 (General Data Protection Regulation)
  • AI Act 2024/1689 (EU Artificial Intelligence Act)
  • EHDS 2025/327 (European Health Data Space Regulation)
  • MDCG 2020-1 – Guidance on Clinical Evaluation (MDR) / Performance Evaluation (IVDR)
  • European Commission – Ethics Guidelines for Trustworthy AI

Relevant Resources - US

  • FDA Digital Health Policy Navigator
  • FDA Artificial Intelligence-Enabled Medical Devices
  • FDA Guidance – Marketing Submission Recommendations for a Predetermined Change Control Plan for AI/ML-Enabled Device Software Functions
  • HIPAA (Health Insurance Portability and Accountability Act)
  • HITECH Act Information
  • FDA Guidance – Use of Real-World Evidence to Support Regulatory Decision-Making for Medical Devices

Relevant Resources - Others

  • ISO/IEC 5259 Series – Data Quality for Analytics and Machine Learning
  • ISO 13485 – Quality Management Systems for Medical Devices
  • ISO/IEC 27001 – Information Security Management Systems
  • NEN 7510-1 – Information Security in Healthcare
  • IMDRF Software as a Medical Device (SaMD) Framework Documents
  • Health Canada – Software as a Medical Device Guidance
  • TGA (Australia) – Software-Based Medical Devices Guidance
Blog Hub

Latest Insights & Updates

Explore our blog posts on MDR, IVDR, and EU AI Act medical device compliance to stay ahead of regulatory changes.

Frequently Asked Questions

Find answers to common questions about our services, compliance processes, and how we can assist your business.

Why is data management important for medical devices and AI systems?

Medical devices and AI systems increasingly depend on large volumes of data across development, validation, cybersecurity, post-market activities, and regulatory documentation. Poor data management can create challenges around traceability, consistency, audit readiness, and regulatory compliance.

What does data governance mean in a regulated healthcare environment?

Data governance refers to the processes and controls used to manage how data is acquired, stored, accessed, updated, shared, and maintained throughout the product lifecycle. In regulated environments, governance is important for ensuring data integrity, security, accountability, and compliance with applicable regulations.

How does data governance relate to MDR, IVDR, EHDS and the AI Act?

Regulations increasingly expect manufacturers to demonstrate control over the quality, traceability, security, and reliability of data used within medical devices and AI systems. This includes considerations around validation data, cybersecurity, interoperability, clinical evidence, post-market monitoring, and transparency obligations.

Can MedQAIR support governance for AI/ML-enabled medical devices and other digital health products (e.g. EHR Systems, wellness applications)?

Yes. MedQAIR supports organisations in establishing governance processes for AI/ML-enabled and software-based medical devices, including documentation structures, data traceability, lifecycle management, cybersecurity alignment, and regulatory readiness across MDR, IVDR, FDA, and AI-related frameworks.

Are there already established standards to support data management processes for digital health products, such as medical devices?

The number of standards in the field of data management are expanding at a fast pace. There are international standards that support data management such as the (SC42) ISO/IEC 5259 standards series (parts 1 through 6), the medical device specific (TC62) IEC PAS 63621, and current standards under development within JTC 21 (e.g. EN 18284). Note, these standards are today not yet recognised by the FDA or harmonised in the European Union, but may be considered ‘State of the Art’.


In addition, Quality and Information Security Management System standards (Management System standards) further support the management of data from a quality (ISO 13485) and information security (NEN 7510-1, ISO 13485) perspective.

What are typical risks associated with data?

Typical risks associated with data include data which is not representative of the intended purpose for which it is used, data may be incomplete, data may be homogeneous or skewed and therefore include inherent bias, it may be outdated and not represent current state of the art, and so on. 


Over time, data may further become outdated, for example, if data is used to train or test AI algorithms, it is important to ensure that data continues to represent what it is used for. Continued retesting an AI algorithm against outdated data when introducing changes to the AI algorithm has a risk of overfitting on test data, and further has a risk of no longer being representative of the current clinical field, where population (e.g. age), disease (e.g. epidemics) or contextual (e.g. medical terminology) characteristics may have changed or where technology has made technological advancements. 


Data may drift over time, which can have adverse consequences for products trained on such data, actively being used in the field.

What is data traceability and why is it important?

Data traceability is the ability to understand where data originates, how it is processed, how it changes over time, and how it is used throughout a product lifecycle. For medical devices and AI systems, traceability supports regulatory compliance, audit readiness, validation activities, incident investigations, and confidence in the reliability of outputs generated from the data.

How should organisations manage data suppliers and external data sources?

Organisations should establish processes to assess, monitor, and document the quality, suitability, and contractual controls associated with external data providers. This includes understanding how data was collected, whether it is representative of its intended use, any licensing restrictions, and how changes to the data source may affect product performance, validation activities, or regulatory compliance.

What is a Data Protection Impact Assessment (DPIA) and when is it required?

A Data Protection Impact Assessment (DPIA) is a structured process used to identify and mitigate privacy risks associated with the processing of personal data. Under the GDPR, a DPIA may be required when data processing activities are likely to result in a high risk to the rights and freedoms of individuals, particularly when handling health data, large-scale monitoring, or AI-supported decision-making systems.

How do data governance processes support AI and machine learning systems?

AI and machine learning systems depend heavily on the quality, representativeness, and management of data. Effective governance helps organisations manage issues such as bias, drift, traceability, data quality, version control, and change management. Strong governance also supports transparency and regulatory expectations under emerging AI-related frameworks.

What is data integrity and how can organisations demonstrate it?

Data integrity refers to the accuracy, completeness, consistency, and reliability of data throughout its lifecycle. Organisations can demonstrate data integrity through documented procedures, access controls, audit trails, validation activities, change management processes, and controls that ensure data remains trustworthy from collection through long-term retention.

How does EHDS affect data management requirements for healthcare organisations?

The European Health Data Space (EHDS) introduces additional expectations around the availability, interoperability, sharing, and secondary use of electronic health data within the European Union. Organisations may need to review their governance structures, documentation practices, and technical controls to ensure health data can be managed and exchanged in accordance with applicable EHDS requirements.

How can MedQAIR help organisations establish data management and governance processes?

MedQAIR supports organisations in developing practical data management and governance frameworks aligned with MDR, IVDR, EHDS, FDA expectations, GDPR, and AI-related requirements. This includes governance structures, data classification, supplier management, traceability controls, AI/ML dataset governance, privacy assessments, and implementation of processes that support long-term compliance and operational efficiency.

Book a Free 30-Minute Consultation

Schedule a Meeting With Our Experts

Get a Free Consultation