India’s drug regulator has introduced a comprehensive guidance framework for medical device software, emphasising AI integration, lifecycle oversight, and global harmonisation to ensure safety and innovation.
India’s drug regulator has moved to tighten oversight of medical device software with a final guidance document that sets out how software products should be assessed, classified and monitored under the Medical Devices Rules, 2017. According to the Central Drugs Standard Control Organisation, the document is intended to give manufacturers, importers and licensing authorities a clearer framework for software that performs a medical function, including in vitro diagnostic products, while bringing India closer to globally harmonised regulatory practice.
The guidance takes a broad, function-based approach rather than relying on labels such as “software as a medical device” or “software in a medical device”. As summarised by Pharmabiz and other industry analyses, the focus is on whether the software is intended for a medical purpose, such as diagnosis, monitoring, treatment, prediction or support of physiological functions, and whether it is embedded in hardware, connected to other systems or offered as a standalone product. It also makes clear that software used only for general wellness, training, storage, communication or similar non-medical functions falls outside the medical device regime, unless it adds medical functionality such as image analysis or clinical decision support.
Artificial intelligence features prominently in the new framework. The guidance expressly recognises AI and machine-learning-based medical device software and asks applicants to explain the underlying methodology, the degree of autonomy involved and the datasets used for training, validation and testing. It also flags risks such as bias, model drift, weak generalisability and hallucinations, and contemplates algorithm change protocols where appropriate. The document further indicates that models developed or validated outside India may need additional evidence showing that they work in Indian clinical settings, reinforcing the expectation that performance must be monitored throughout the product’s life cycle.
The guidance also sharpens expectations around intended use statements, risk classification, quality systems, technical files and post-market surveillance. Under the MDR, software that drives or influences hardware is generally classified with that device, while standalone products are assessed through a matrix that weighs the clinical significance of the information they provide against whether the situation is critical, serious or non-serious. Manufacturers are expected to maintain a quality management system covering development, deployment and maintenance, comply with relevant BIS, ISO or IEC standards, and keep detailed technical documentation on design, validation, cybersecurity and, where relevant, clinical evaluation. Post-market duties include tracking software performance, responding to defects and cybersecurity vulnerabilities, and maintaining records of updates and corrective actions. Industry commentary on the draft version had already suggested that the framework could reduce ambiguity without adding entirely new obligations, and the final guidance appears to confirm that the regulator is trying to balance innovation with stricter lifecycle oversight.
Disclaimer: This content is for informational purposes only and is not intended to be a substitute for professional medical judgment, advice, diagnosis, or treatment.





