ISO/IEC DTR 18988
(Main)Artificial intelligence — Application of AI technologies in health informatics
General Information
- Abstract
- Status
- Not Published
- Technical Committee
- ISO/IEC JTC 1/SC 42 - Artificial intelligence
- Drafting Committee
- ISO/IEC JTC 1/SC 42 - Artificial intelligence
- Current Stage
- 5020 - FDIS ballot initiated: 2 months. Proof sent to secretariat
- Start Date
- 14-Aug-2026
- Completion Date
- 14-Aug-2026
Buy Documents
ISO/IEC DTR 18988 - Artificial intelligence — Application of AI technologies in health informatics
REDLINE ISO/IEC DTR 18988 - Artificial intelligence — Application of AI technologies in health informatics
Overview
ISO/IEC DTR 18988: Artificial Intelligence - Application of AI Technologies in Health Informatics is a technical report developed by ISO/IEC JTC 1/SC 42, focusing on how artificial intelligence (AI) is transforming health informatics. This document provides a high-level overview of the conditions, considerations, and processes relevant to integrating AI in clinical and health information environments. As the healthcare ecosystem faces increasing challenges-such as ageing populations, workforce shortages, and rising expectations-AI-enabled health informatics presents opportunities to enhance healthcare delivery, improve outcomes, and optimize operations across a variety of settings.
ISO/IEC DTR 18988 is a landscape document, exploring both industry-agnostic standards and healthcare-specific needs. The report addresses unique requirements for patient safety, ethical deployment, and regulatory oversight that distinguish health informatics from other sectors using AI. This standardization effort is designed to complement existing ISO/IEC and IEC standards and assists stakeholders in understanding best practices, lifecycle management, and effective governance of AI in health contexts.
Key Topics
Healthcare Context
AI is increasingly incorporated to support direct patient care, public and population health, research, policy, and training. The sector’s unique demands include stringent regulatory oversight, requirements for clinical validation, and a high bar for patient safety and trust.Ethical and Regulatory Environment
Ethical principles such as autonomy, fairness, transparency, and inclusivity are vital for AI in healthcare. Regulatory frameworks often include requirements for validation, risk management, human oversight, and continuous monitoring. The document references significant initiatives, such as the World Health Organization’s guidance on ethics and governance of AI for health.AI System Lifecycle
The lifecycle model for AI in health informatics spans:- Inception (defining objectives and scope)
- Design and development (solution architecture and model building)
- Verification and validation (testing intended use and quality)
- Deployment (integration into clinical systems)
- Operation and monitoring (post-market surveillance, performance checks)
- Continuous learning and evaluation (feedback-driven improvements)
- Retirement (decommissioning systems responsibly)
Risk Management and Trustworthiness
Healthcare AI requires robust risk assessment, mitigation strategies, transparency, explainability, and governance mechanisms to build trust among clinicians, administrators, and patients.Bias, Inclusivity, and Data Governance
Special attention is given to challenges of unwanted bias, ensuring inclusivity, and establishing robust data governance and pseudonymization strategies.Generative AI and Large Language Models
Emerging technologies, including generative AI systems and large language models, require specific guidance for responsible deployment, validation, and oversight due to their unique capabilities and risks.
Applications
AI-enabled health informatics has extensive practical value, supporting stakeholders such as healthcare providers, policymakers, IT vendors, and regulators:
- Clinical Decision Support: AI algorithms enhance diagnosis, risk prediction, and treatment planning.
- Medical Documentation: Ambient scribing and automated transcription tools streamline clinical workflows.
- Population Health Management: AI analyzes real-world data to inform public health strategies and resource allocation.
- Administrative Automation: AI optimizes scheduling, billing, and operational tasks for healthcare organizations.
- Remote and Home Health Monitoring: Intelligent sensors and continuous learning models support personalized care outside traditional clinical environments.
- Research and Educational Tools: Natural language processing and generative AI assist in literature reviews, patient communications, and clinician training.
- Regulatory Compliance: AI solutions adhering to international standards facilitate global interoperability and support market access.
Related Standards
Stakeholders should consider the following related international standards and guidance documents for comprehensive AI health informatics deployment:
- ISO/IEC 22989: Artificial intelligence concepts and terminology
- EN ISO 13485: Medical devices - Quality management systems
- ISO/TR 18307: Health informatics - Requirements for an electronic health record architecture
- EN ISO 25237: Health informatics - Pseudonymization
- IMDRF Good Machine Learning Practice (GMLP)
- WHO and ITU Guidance on Ethics and Governance of Artificial Intelligence for Health
- ISO/IEC JTC 1/SC 42 portfolio: Covering foundational and specialized AI topics
By referencing ISO/IEC DTR 18988, organizations can align their AI applications in health informatics with best practices and internationally recognized standards, supporting safer, more effective, and ethically sound healthcare innovation.
Buy Documents
ISO/IEC DTR 18988 - Artificial intelligence — Application of AI technologies in health informatics
REDLINE ISO/IEC DTR 18988 - Artificial intelligence — Application of AI technologies in health informatics
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

NYCE
Mexican standards and certification body.
Sponsored listings
Frequently Asked Questions
ISO/IEC DTR 18988 is a draft published by the International Organization for Standardization (ISO). Its full title is "Artificial intelligence — Application of AI technologies in health informatics". This standard covers: Artificial intelligence — Application of AI technologies in health informatics
Artificial intelligence — Application of AI technologies in health informatics
ISO/IEC DTR 18988 is classified under the following ICS (International Classification for Standards) categories: 35.240.80 - IT applications in health care technology. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/IEC DTR 18988 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
FINAL DRAFT
Technical
Report
ISO/IEC JTC 1/SC 42
Artificial intelligence — Application
Secretariat: ANSI
of AI technologies in health
Voting begins on:
informatics
2026-08-14
Intelligence artificielle — Application des technologies
Voting terminates on:
d'intelligence artificielle à l'informatique de santé
2026-10-09
Member bodies are requested to consult relevant national interests in ISO/TC
215 before casting their ballot to the e-Balloting application.
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
FINAL DRAFT
Technical
Report
ISO/IEC JTC 1/SC 42
Artificial intelligence — Application
Secretariat: ANSI
of AI technologies in health
Voting begins on:
informatics
Intelligence artificielle — Application des technologies
Voting terminates on:
d'intelligence artificielle à l'informatique de santé
Member bodies are requested to consult relevant national interests in ISO/TC
215 before casting their ballot to the e-Balloting application.
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms .3
5 Current state of the health informatics ecosystem .3
5.1 Healthcare context .3
5.2 Ethical and regulatory environment .4
5.2.1 Ethics .4
5.2.2 Regulation .6
6 Considerations in use of AI in health informatics . 6
6.1 Lifecycle .6
6.2 Risk management .10
6.2.1 General .10
6.2.2 AI/ML in Medical Devices .11
6.3 Transparency . 12
6.4 Governance . 15
6.5 Trustworthiness .16
6.6 Explainability.17
6.7 Unwanted bias in AI systems . 20
6.7.1 Impact . 20
6.7.2 Sources .21
6.7.3 Consequences . 22
6.7.4 Mitigation . . 22
6.8 Generative AI systems and large language models . 23
6.9 Continuous learning. 23
6.10 Inclusivity . 23
6.10.1 Low and middle income countries . . 23
6.10.2 Accessibility .24
6.11 Data governance .24
6.11.1 Data quality management .24
6.11.2 Security and privacy .24
6.11.3 Pseudonymization . . . 26
6.12 Evaluation .27
6.13 Verification and validation . 28
6.13.1 General . 28
6.13.2 Validation in medical device development . 28
6.13.3 Validation in machine learning model development . 28
6.14 Human factors . 28
6.14.1 Ergonomic perspective . 28
6.14.2 Human oversight and human-machine teaming . 29
Annex A (informative) Classifications of AI systems for healthcare .31
Annex B (informative) Generative AI systems and large language models .33
Annex C (informative) Continuous Learning .38
Bibliography .40
© ISO/IEC 2026 – All rights reserved
iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 42, Artificial intelligence.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html. and
www.iec.ch/national-committees.
© ISO/IEC 2026 – All rights reserved
iv
Introduction
This document is a landscape document which aims to describe certain key factors that can impact the use
of AI-enabled health informatics in various clinical settings including in healthcare delivery organizations
and home healthcare environments.
The document is written at a point in time and acknowledges that the use of large language models and
agentic AI is undergoing rapid evolution in the way AI systems are being applied in many industries,
including healthcare.
It is recognized that there is substantial existing and ongoing work on the development of standards for AI
system use applicable across all industries and relevant references are included in the Bibliography.
The work programme of ISO/IEC JTC1 SC 42, Artificial intelligence, can be found at
https://www.iso.org/committee/6794475/x/catalogue/p/0/u/1/w/0/d/0.
There is also a mature body of standards related to AI use in medical device software. The
work programme of IEC TC 62 Medical equipment, software, and systems can be found at
https://www.iec.ch/dyn/www/f?p=103:23:::::FSP_ORG_ID:1245.
The medical device sector is highly regulated and has stringent requirements for compliance. Health
informatics has an important interface with medical devices that arises when the data from the device is
used to inform clinical care.
This document is intended to help understand how some of the factors described can lend themselves to
standardization and be seen as opportunities to complement the existing work of both ISO/IEC JTC1 SC42
and IEC TC 62.
The primary concern for healthcare is consideration of the extent to which standards adequately account for
health informatics requirements. That outcome could be achieved by:
— developing any required healthcare specific documents,
— developing healthcare specific parts related to existing documents, or
— providing healthcare expertise and advice into the development and review of existing “horizontal”
documents.
© ISO/IEC 2026 – All rights reserved
v
FINAL DRAFT Technical Report ISO/IEC DTR 18988:2026(en)
Artificial intelligence — Application of AI technologies in
health informatics
1 Scope
This document provides an overview of AI-enabled Health Informatics (AIHI). This document describes
the properties, factors, available methods and processes relating to the use of AI in health informatics to
effectively realize the potential benefits for healthcare use cases. This document identifies considerations
for the use of AI systems in healthcare when developing AIHI-related standards, such as mapping and
categorization, and points out some differences from horizontal cross-industry AI system standards.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 22989, Information technology — Artificial intelligence — Artificial intelligence concepts and
terminology
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 22989 and the following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
IEC Electropedia: available at https:// www .electropedia .org/
3.1
ambient scribing product
tool that uses advanced speech technologies to automatically convert spoken words into text and other
outputs, requiring minimal user intervention
Note 1 to entry: Ambient scribing products are designed to support clinical or patient documentation and workflows
in healthcare.
3.2
generative AI system
generative artificial intelligence system, noun
GenAI system, noun
AI system based on techniques and models that aim to generate new content
Note 1 to entry: Examples of generated content can include text, audio, code, video, and image.
Note 2 to entry: Generated content encompasses new information or new ways to express pre-existing information.
That pre-existing information can be drawn from the input, a dataset involved in building the model or an external
repository.
[1]
[SOURCE: ISO/IEC 22989:2022/DAmd 1 , 3.1.38]
© ISO/IEC 2026 – All rights reserved
3.3
health informatics
scientific discipline that is concerned with the cognitive, information processing and communication tasks
of healthcare practice, education and research, including the information science and technology to support
these tasks
[2]
[SOURCE: ISO/TR 18307:2001 , 3.73, modified — "healthcare" changed to "health".]
3.4
intended use
intended purpose, noun
use for which a product, process or service is intended according to the specifications, instructions and
information provided by the manufacturer
Note 1 to entry: The intended medical indication, patient population, part of the body or type of tissue interacted with,
user profile, use environment, and operating principle are typical elements of the intended use.
[3]
[SOURCE: ISO 14971:2019 , 3.6]
3.5
medical device
instrument, apparatus, implement, machine, appliance, implant, reagent for in vitro use, software, material
or other similar or related article, intended by the manufacturer to be used, alone or in combination, for
human beings, for one or more of the specific medical purpose(s) of:
— diagnosis, prevention, monitoring, treatment or alleviation of disease;
— diagnosis, monitoring, treatment, alleviation of or compensation for an injury;
— investigation, replacement, modification, or support of the anatomy or of a physiological process;
— supporting or sustaining life;
— control of conception;
— disinfection of medical devices;
— providing information by means of in vitro examination of specimens derived from the human body; and
does not achieve its primary intended action by pharmacological, immunological or metabolic means, in
or on the human body, but which may be assisted in its intended function by such means
Note 1 to entry: Products which may be considered to be medical devices in some jurisdictions but not in others
include:
— disinfection substances;
— aids for persons with disabilities;
— devices incorporating animal and/or human tissues;
— devices for in vitro fertilization or assisted reproduction technologies.
[4]
[SOURCE: ISO 13485:2016 , 3.11]
3.6
pseudonymization
pseudonymization particular type of de-identification that both removes the association with a data subject
and adds an association between a particular set of characteristics relating to the data subject and one or
more pseudonyms
[5]
[SOURCE: ISO 25237:2017 , 3.42]
© ISO/IEC 2026 – All rights reserved
4 Abbreviated terms
AI Artificial intelligence
AI-DSF Artificial Intelligence-Enabled Device Software Functions
AAMI Association for the Advancement of Medical Instrumentation
AIHI AI-enabled health informatics
AIMD Active implantable medical device
CHAI Coalition for Health AI
CLS Continuous learning system
EHR Electronic health record
FFP Fit for purpose
FG-AI4H Focus Group on Artificial Intelligence for Health
GenAI Generative AI
GI-AI4H Global Initiative on Artificial Intelligence for Health
GMLP Good machine learning practice
HIS Hospital information system
HMT Human machine teaming
IMDRF International Medical Device Regulators Forum
LLM Large language model
MSS Management systen standard
NCD Non-communicable disease
OECD Organisation for Economic Co-operation and Development
PCCP Predetermined Change Control Plan
RWD Real-world data
SaMD Software as a medical device
5 Current state of the health informatics ecosystem
5.1 Healthcare context
ISO TC 215 health informatics Task Force 5 has previously examined the challenges being faced by the
healthcare system in the 21st Century ( Application of AI Technologies in Health Informatics ISO/TC 215
[6]
AHG2 – Final Report March 1, 2021 ). These challenges are expected to continue shaping the ways in which
AI is applied in health informatics to support managing and delivering healthcare.
Some of the challenges affect multiple industries (e.g. climate change) but the impact is different. Many are
not controllable in the short term (e.g. changing population demographics) and possibly not even controllable
© ISO/IEC 2026 – All rights reserved
in the long term. The challenges identified can also have a differential impact in different geographies and
cultures. These include
— ageing populations in many countries
— growing socio-economic inequalities within and between countries
— reduced healthcare funding at both individual and government levels
— clinical workforce shortages
— disruption to global supply chains
— rising levels of chronic disease
— increased pandemic risk
— rising consumer expectations of control over their personal data
— increasing regulation
— new technologies (including genomics and artificial intelligence)
There have been ongoing policy and operational responses to these challenges including
— moving from an illness to a wellness model of health
— greater focus on population and public health
— person centred rather than organization centred models of care
— greater use of remote provision of care
— increased monitoring of social indicators
— funding reforms (e.g. value based care)
— technology innovation (e.g. cloud technology, AI, interoperability)
The application of health informatics is very wide and can include use of information to support direct
patient care, population health, clinical research, policy development, training and operational management.
The provision of healthcare services has increasingly diffuse boundaries with close interaction with social,
education and justice systems. For this reason, alignment with horizontal industry agnostic AI standards
is beneficial and desirable. However, healthcare AI applications also have unique characteristics including
patient safety requirements, regulatory oversight, clinical validation needs, and ethical considerations
indicating a need for either healthcare-specific standards or significant adaptation or extension of the
horizontal industry agnostic standards.
Various approaches to the classification of different types of AI systems that are used in healthcare are
described in Annex A.
5.2 Ethical and regulatory environment
5.2.1 Ethics
Healthcare has existing guidance and regulation pertaining to quality, safety, goals, and ethical principles.
[7]
Ethical principles include: autonomy, justice, beneficence, and non-maleficence . When extended to public
[8]
health they also include health maximization, efficiency, and proportionality . Digital ethics goes beyond
established legal principles and highlights the underlying principles and values of respecting fundamental
rights (e.g. dignity, privacy and data protection).
© ISO/IEC 2026 – All rights reserved
More than 84 ethics initiatives have published reports describing high-level principles, tenets, and abstract
[9]
requirements for the development and deployment of AI systems . An analysis of 36 prominent sets of
such principles revealed the following 8 themes:
— privacy,
— accountability,
— safety and security,
— transparency and explainability,
— fairness and non-discrimination,
— human control of technology,
— professional responsibility, and
[10]
— promotion of human values .
These principles apply to the development and deployment of AI-enabled health applications. They can
be applied at every stage of the AI health application lifecycle, from needs determination and design
[11]
through decommissioning . When pertinent, to promote trustworthiness, they can be applied as basic
requirements for the development, deployment, use, and evaluation of AI health applications. Moreover,
relevant principles and requirements can also be applied to the development and revision of health
informatics standards pertaining to or encompassing AI health applications, providing, whenever applicable,
full transparency about an AI product throughout its lifecycle, e.g. how the algorithm works, what data were
used to train it, what tests were conducted, how the trained product performed in such tests, experience
with use in practice, etc.
In 2021 the World Health Organization (WHO) published its guidelines on Ethics and governance of artificial
intelligence for health: WHO guidance which proposed six ethical principles
— Protect human autonomy
— Promote human well-being and safety and the public interest
— Ensure transparency, explainability and intelligibility
— Foster responsibility and accountability
— Ensure inclusiveness and equity, and
[12]
— Promote AI that is responsive and sustainable
The WHO principles were subsequently endorsed in 2022 by the Focus Group on Artificial Intelligence
for Health (FG-AI4H) which was abolished in July 2023 with the formation of the Global Collaboration on
Artificial Intelligence in Health (GC-AI4H) a collaborative endeavour led by three specialized Agencies of the
United Nations, namely, World Health Organization (WHO), International Telecommunications Union (ITU)
and World Intellectual Property Organization (WIPO).
In 2025 GC-AI4H published Ethics and governance of artificial intelligence for health: Guidance on large multi-
[13]
modal models which reiterated the continued applicability of the WHO principles published in 2021 when
considered in the context of generative AI.
While these ethical principles originated as voluntary guidance, they are forming the basis of legally
enforceable requirements in some jurisdictions, where mandatory measures related to transparency, safety
testing, fairness, accountability, and human oversight are being introduced for what is considered high-risk
AI in healthcare.
© ISO/IEC 2026 – All rights reserved
5.2.2 Regulation
It can be difficult to apply current regulatory frameworks for health and medical technologies to
applications utilizing artificial intelligence. For instance, medical device regulations across the world
require validation (6.13) that devices and processes produce reproducible and expected outputs or results.
While reproducibility of outputs is not a problem that is specific to artificial intelligence, reproducibility
is already an issue being discussed particularly for continuous learning applications of AI. Many existing
medical device regulations were not written with generative AI systems and large language models in mind.
These regulations are in a state of flux with the expectations of healthcare professionals, regulators, device
manufacturers and other stakeholder groups to be understood.
Interpretation and guidance can be helpful for applying existing regulations to AI technology. Modified or new
regulations and standards can help to fill in possible gaps and to resolve ambiguities in existing regulations.
Wherever possible, it is preferable for regulations and standards to be harmonized internationally to ensure
access to current state of the art technologies and to prevent the development of technical barriers to trade
that raise costs and limit access to healthcare.
From a healthcare perspective, the sector's use of AI systems is split between the highly regulated use of
medical devices (including medical device software) and use for other administrative and clinical purposes.
The medical device community has a long history of regulation and management of the use of AI systems
including, for example, requirements for post-market surveillance. The level of oversight required for
the device manufacturers is based on the assessed level of risk of the device. While there are some local
variations in its application, the risk framework used for medical devices is a matrix approach that considers
both the clinical risk and the level of autonomy. A description of the risk framework for medical devices is
provided in 6.2. Recent initiatives by medical device regulatory agencies emphasize an AI lifecycle approach
as described in 6.1, with the goal of implementing risk controls in both pre- and post-market phases.
As an example of global regulatory initiatives, the IMDRF working group on Artificial Intelligence and
Machine Learning-enabled (AI/ML) and Software as a Medical Device (SaMD) have been developing useful
[14]
documentation such as Good Machine Learning Practice (GMLP) , Essential Principles and Content of
[15]
Predetermined Change Control Plans , etc. to provide internationally harmonized principles.
It has yet to be agreed how the appropriate level of risk (and associated need for regulation) of non-device
uses of AI systems in healthcare will be determined. Many jurisdictions are reviewing this need and
undertaking consultation with the community and clinicians. To date there has been no internationally
consistent approach and many countries are yet to introduce or modify their legislation. Some jurisdictions
have assessed that all use of AI in healthcare is high risk and some others have adopted the medical device
model to be applied for more general use by default. In most jurisdictions whenever AI is being applied
outside of usage as a medical device, such as in the use of ambient scribing products, there is an expectation
of a 'human in the loop' prior to any clinical action being taken.
It could be considered that all AI used for clinical purposes is regulated - but some systems fall into
a lower risk category with developers needing to monitor "lower-risk" AI systems to ensure they do not
stray into the "high-risk" category. Many jurisdictions require a human in the loop for AI applications
used outside legislated medical device frameworks. This is increasingly described as meaningful human
oversight ensuring a qualified human can understand system outputs, intervene when needed, and assume
responsibility for clinical decisions supported by AI.
Ongoing regulatory developments in many countries reflect a converging global movement toward risk-
based governance for AI systems. Harmonized international standards can help to support interoperability
of regulatory expectations and facilitate access to safe and effective AI technologies across borders.
6 Considerations in use of AI in health informatics
6.1 Lifecycle
The AI lifecycle model describes the progression of an AI system from conception to retirement, providing
a structured framework to support stakeholders in developing AI systems more effectively and efficiently.
© ISO/IEC 2026 – All rights reserved
The concept of an "AI lifecycle" varies across standards and guidelines, reflecting different perspectives
depending on their specific focus.
[16]
For example, ISO/IEC 22989 defines the lifecycle of an AI system from the viewpoint of AI system-specific
processes, comprising the following eight stages:
— Inception: Identifying objectives and requirements, considering risk management, transparency,
accountability, cost, funding, resources, and feasibility.
— Design and development: Determining the overall approach and architecture, developing code, processing
training data, and implementing risk treatment.
— Verification and validation (6.13): Testing software for functionality and defects, verifying that AI
capabilities operate as intended, confirming the system meets quality criteria, and performing risk
monitoring and review. The terms “verification” and “validation” can be used with different meanings
depending on the context. In medical device development, validation typically refers to confirmation
that the system fulfils its intended clinical use, whereas in machine learning development the term
“validation” is often used to refer to model tuning or performance evaluation during training.
— Deployment: Installing, releasing, and configuring the AI system, along with risk treatment.
— Operation and monitoring: Maintaining and updating the system, monitoring its performance, and
performing ongoing risk management.
— Continuous validation: Validating the system on an ongoing basis, particularly relevant in the context
of continuous learning. In this context, “continuous validation” refers to ongoing confirmation that the
AI system continues to fulfil its intended use in its operational environment. This does refer to routine
software testing or model tuning.
— Re-evaluation: Reviewing operational results, refining objectives and requirements, and conducting risk
reassessment.
— Retirement: Decommissioning and disposing of the system, with replacement as appropriate.
The structure is not strictly linear; certain stages (e.g. “Re-evaluation” or “Continuous Validation”) can
involve cyclic processes that return to earlier phases such as “Design and Development” or “Operation and
Monitoring.”
In a similar vein, the U.S. Food and Drug Administration (FDA) published an executive summary in November
[17]
2024 entitled "Total Product Lifecycle Considerations for Generative AI-Enabled Devices" . This document
outlines a lifecycle model tailored to AI-enabled software, including generative AI applications, comprising
seven stages:
— Planning and design: Defining goals, scope, and technical architecture.
— Data collection and management: Gathering and organizing training/testing data to ensure quality and
relevance.
— Model building and tuning: Developing and refining models using collected data.
— Verification and validation: Assessing the model’s reliability and performance.
— Model deployment: Integrating the model into the target operational environment.
— Operation and monitoring: Ensuring stability post-deployment, including maintenance activities such as
bug fixes and updates.
— Real-world performance evaluation: Evaluating system performance under actual operating conditions.
[16]
This framework is comparable to ISO/IEC 22989 but introduces a finer separation between data handling
(Stages 2 and 3) and model development. It also merges post-deployment feedback loops (e.g. “Re-evaluation”
and “Continuous Validation”) into a consolidated “Real-World Performance Evaluation” stage.
© ISO/IEC 2026 – All rights reserved
[18]
Coalition for Health AI (CHAI) published a draft guide (v0.3, June 2024) titled, “Responsible AI Guide”
which provides comprehensive guidance on quality and ethics for AI systems in healthcare. The AI lifecycle
model, which the guide defines, consists of the following steps:
— Define problem and plan: Identifying the problem, understanding stakeholder needs, evaluating
feasibility, and deciding whether to build, buy, or partner.
— Design the AI system: Capturing technical requirements, designing system workflow, and planning
deployment strategy.
— Engineer the AI solution: Developing and validating the AI model, preparing data, and planning for
operational deployment.
— Assess: Conducting local validation, establishing a risk management plan, training end users, and
ensuring compliance.
— Pilot: Implementing a small-scale pilot, monitoring real-world impact, and updating risk management.
— Deploy and monitor: Deploying the AI solution at scale, conducting ongoing monitoring, and maintaining
quality assurance.
The CHAI draft guide is cited for illustrative purposes to reflect emerging practices rather than established
standards.
[19]
From another angle, BS 30440 defines lifecycle phases for evaluating the development of safe, effective,
and ethical healthcare AI systems, covering both regulated medical devices and unregulated healthcare AI
systems. The phases include:
— Inception: Identifying the clinical need to be addressed.
— Development: Engaging stakeholders, managing training data ethically, and documenting model creation
and usability.
— Validation: Assessing clinical effectiveness, external validity, and bias mitigation.
— Deployment: Addressing resource planning, cost implications, cybersecurity, and explainability,
alongside risk management.
— Monitoring: Conducting post-deployment monitoring and managing updates and decommissioning.
[19]
The BS 30440 lifecycle condenses and integrates some stages, while aligning closely with the core
principles of safety, effectiveness, and equity in the healthcare domain.
In contrast to these system-focused frameworks, the OECD report "Advancing Accountability in AI: Governing
[20]
and Managing Risks throughout the Lifecycle for Trustworthy AI" approaches the AI system lifecycle from a
risk governance perspective. The OECD defines the lifecycle in terms of six core stages:
— Plan and design
— Collect and process data
— Build and use model
— Verify and validate
— Deploy
— Operate and monitor
Each of these stages is mapped to four overarching risk management functions: Define, Assess, Treat, and
[21]
Govern, echoing the structure of ISO 31000 but adapted to AI-specific challenges. This model is intended
to guide the implementation of accountability mechanisms and risk controls throughout the lifecycle of an
AI system.
© ISO/IEC 2026 – All rights reserved
[22]
Additionally, ISO/IEC 8183 defines a data lifecycle framework that emphasizes data-centric operations
across the full lifespan of an AI system, from conceptualization to decommissioning. It consists of ten
distinct stages:
— Idea conception
— Business requirements
— Data planning
— Data acquisition
— Data preparation
— Building model
— System deployment
— System operation
— Data decommissioning
— System decommissioning
This framework complements system-focused lifecycles by offering detailed guidance on data stewardship
and governance activities necessary to support AI system functionality. A similar data life cycle model is also
[23] [22]
defined in ISO/IEC 5259-1 , which is derived from ISO/IEC 8183 and therefore identical in structure.
The six examples presented above define AI system lifecycle stages from different perspectives, resulting
in variations in granularity and structure. Nevertheless, a broad correspondence among the stages can be
established. Table 1 provides a comparative mapping of the lifecycle phases across the six frameworks.
[16] [17]
Table 1 — Comparison of AI system lifecycle stages: ISO/IEC 22989 , FDA executive summary ,
[18] [19] [20] [22]
CHAI Responsible AI Guide , BS 30440 , OECD report and ISO/IEC 8183
FDA executive
[16] [18] [19] [20] [22]
ISO/IEC 22989 CHAI BS 30440 OECD report ISO/IEC 8183
[17]
summary
Inception Planning and Define Problem Inception Plan and design Idea Conception
Design and Plan
Business Require-
ments
Design and Devel- Data collection Design the AI Development Collect and pro- Data Planning
opment and management System cess data
Engineer the AI Data Acquisition
Solution
Data Preparation
Model Building Build and use Building Model
and Tuning model
Verification and Verification and Assess Validation Verify and vali- Throughout "Data
Validation Validation date planning" to
Pilot
"Building model"
© ISO/IEC 2026 – All rights reserved
TTaabblle 1 e 1 ((ccoonnttiinnueuedd))
FDA executive
[16] [18] [19] [20] [22]
ISO/IEC 22989 CHAI BS 30440 OECD report ISO/IEC 8183
[17]
summary
Deployment Model Deploy- Deploy and Mon- Deployment Deploy System Deploy-
ment itor ment
Operation and Operation and Monitoring Operate and System Operation
Monitoring Monitoring monitor
Continuous Vali- Real-World Throughout "Data
dation Performance Eval- planning" to "Sys-
uation tem operation"
Re-evaluation
Retirement N/A N/A N/A N/A Data Decommis-
sioning
System Decom-
missioning
The FDA executive summary and the OECD report divide the “Design and Development” stage into two
[22]
separate stages based on process flow, while ISO/IEC 8183 divides it into four stages from a data lifecycle
[19]
perspective. In contrast, stages such as “Monitoring” in BS 30440 and the OECD report are addressed in
more granular terms in other frameworks.
[22]
In ISO/IEC 8183 , the “Verify & Validate” stage can occur following “Building Model,” but it is not strictly
limited to that point. It can also occur iteratively or continuously between “Data Planning” and “Building
Model.” Similarly, the stages of “Continuous Validation” and “Re-evaluation” (as defined in ISO/IEC 22989
[16]
) can occur throughout various phases, including from “Data Planning” to “System Operation.” The
“Retirement” stage is not explicitly defined in the executive summaries or lifecycle descriptions provided in
[17] [20] [19] [18]
documents published by FDA , OECD , BS 30440 or CHAI . Nevertheless, the concept of retirement
is implicitly addressed across these frameworks through activities such as ongoing monitoring, revalidation,
withdrawal from use, decommissioning, or replacement of AI systems when they no longer meet safety,
performance, or governance expectations.
6.2 Risk management
6.2.1 General
In recognition of the unique risk profiles of AI-enabled healthcare solutions, regulatory authorities across
regions such as Canada, the United States, the European Union, Australia, and others are charting
...
ISO/IEC JTC 1/SC 42
ISO/IEC CD TR 18988(en)
Secretariat: ANSI
Date: 2026-07-31
Artificial intelligence — Application of AI technologies in health
informatics
Intelligence artificielle — Application des technologies d'intelligence artificielle à l'informatique de santé
DTR stage
MMMememembbbererer b b booodddiiieeesss ar ar are re re reqeqequuueeessstttededed t t tooo cccooonnnsssuuultltlt r r relevelevelevanananttt n n natatatiiiooonnnal al al iiinnntttererereeessstttsss iiinnn I I ISSSOOO///TTTCCC 2 2 2111555 b b befoefoeforrre ce ce caaassstttiiinnnggg t t thhheieieirrr
bbbaaallllllooot tot tot to th th theee e e e---BBBaaalllllloootttinininggg a a apppppplllicaicaicatttioioionnn.
ISO/IEC CD TRDTR 18988:2026(en)
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
E-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
ISO/IEC CD TRDTR 18988:2026(en)
Contents
Foreword . iii
Introduction . iii
Scope . iii
Normative references . iii
Terms and definitions . iii
Symbols and abbreviated terms . iii
Current state of the health informatics ecosystem . iii
Healthcare context . iii
Ethical and regulatory environment . iii
Considerations in use of AI in health informatics . iii
Lifecycle . iii
Risk management . iii
Transparency . iii
Governance . iii
Trustworthiness . iii
Explainability . iii
Unwanted bias in AI systems . iii
Generative AI systems and large language models . iii
Continuous learning . iii
Inclusivity . iii
Data governance . iii
Evaluation . iii
Verification and validation . iii
Human factors . iii
(informative) Classifications of AI systems for healthcare . iii
(informative) Generative AI systems and large language models . iii
(informative) Continuous Learning . iii
Bibliography . iii
Foreword . v
Introduction . vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 3
5 Current state of the health informatics ecosystem . 4
5.1 Healthcare context . 5
5.2 Ethical and regulatory environment. 6
6 Considerations in use of AI in health informatics . 8
6.1 Lifecycle . 8
6.2 Risk management . 12
6.3 Transparency . 14
6.4 Governance . 17
6.5 Trustworthiness . 19
© ISO/IEC 2026 – All rights reserved
iii
ISO/IEC CD TRDTR 18988:2026(en)
6.6 Explainability . 21
6.7 Unwanted bias in AI systems . 24
6.8 Generative AI systems and large language models . 27
6.9 Continuous learning. 27
6.10 Inclusivity . 27
6.11 Data governance . 28
6.12 Evaluation . 32
6.13 Verification and validation . 33
6.14 Human factors . 34
Annex A (informative) Classifications of AI systems for healthcare . 36
Annex B (informative) Generative AI systems and large language models . 39
Annex C (informative) Continuous Learning . 45
Bibliography . 48
© ISO/IEC 2026 – All rights reserved
iv
ISO/IEC CD TRDTR 18988:2026(en)
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of
documentsdocument should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives or
www.iec.ch/members_experts/refdocs).www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the use of
(a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any claimed
patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not received
notice of (a) patent(s) which may be required to implement this document. However, implementers are
cautioned that this may not represent the latest information, which may be obtained from the patent database
available at www.iso.org/patents and https://patents.iec.ch.www.iso.org/patents and https://patents.iec.ch.
ISO and IEC shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see
www.iso.org/iso/foreword.html.www.iso.org/iso/foreword.html. In the IEC, see www.iec.ch/understanding-
standards.www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC1/SC42 Joint Working Group 3 AI
enabled health informatics JTC 1, Information technology, Subcommittee SC 42, Artificial intelligence.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html. and www.iec.ch/national-
committees.
© ISO/IEC 2026 – All rights reserved
v
ISO/IEC CD TRDTR 18988:2026(en)
Introduction
This technical reportdocument is a landscape document which aims to describe certain key factors that can
impact the use of AI-enabled health informatics in various clinical settings including in healthcare delivery
organizations and home healthcare environments.
The document is written at a point in time and acknowledges that the use of large language models and agentic
AI is undergoing rapid evolution in the way AI systems are being applied in many industries, including
healthcare.
It is recognisedrecognized that there is substantial existing and ongoing work on the development of
standards for AI system use applicable across all industries and relevant references are included in the
Bibliography.
The work programme of ISO/IEC JTC1 SC42SC 42, Artificial Intelligenceintelligence, can be found at
https://www.iso.org/committee/6794475/x/catalogue/p/0/u/1/w/0/d/0.
There is also a mature body of standards related to AI use in medical devicemedical device software. The work
programme of IEC TC62TC 62 Medical equipment, software, and systems can be found at
https://www.iec.ch/dyn/www/f?p=103:23:::::FSP_ORG_ID:1245.
The medical devicemedical device sector is highly regulated and has stringent requirements for compliance.
health informaticsHealth informatics has an important interface with medical devices that arises when the
data from the device is used to inform clinical care.
This document is intended to help understand how some of the factors described can lend themselves to
standardization and be seen as opportunities to complement the existing work of both ISO/IEC JTC1 SC42 and
IEC TC62TC 62.
The primary concern for healthcare is consideration of the extent to which standards adequately account for
health informatics requirements. That outcome could be achieved by:
— developing any required healthcare specific documents,
— developing healthcare specific parts related to existing documents, or
— providing healthcare expertise and advice into the development and review of existing “horizontal”
documents.
© ISO/IEC 2026 – All rights reserved
vi
ISO/IEC CD TRDTR 18988:2026(en)
Artificial intelligence — Application of AI technologies in health
informatics
1 Scope
This document provides an overview of AI-enabled Health Informatics (AIHI). This document describes the
properties, factors, available methods and processes relating to the use of AI in health informatics to effectively
realize the potential benefits for healthcare use cases. This document identifies considerations for the use of
AI systems in healthcare when developing AIHI-related standards, such as mapping and categorization, and
points out some differences from horizontal cross-industry AI system standards.
2 Normative references
There are no normative references in this document.
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 22989, Information technology — Artificial intelligence — Artificial intelligence concepts and
terminology
3 Terms and definitions
For the purposes of this document, the terms and definitions given in Information technology — Artificial
intelligence — Artificial intelligence concepts,and terminology EN ISO/IEC 22989[1] and ISO/IEC
22989[2]ISO/IEC 22989 and the following apply.
ISO and IEC maintain terminological terminology databases for use in standardization at the following
addresses:
— IEC Electropedia: available at http://www.electropedia.org/
— ISO Online browsing platform: available at http://www.iso.org/obphttps://www.iso.org/obp
— IEC Electropedia: available at https://www.electropedia.org/
3.1
ambient scribing product
tool that uses advanced speech technologies to automatically convert spoken words into text and other
outputs, requiring minimal user intervention.
Note 1 to entry ambient: Ambient scribing products are designed to support clinical or patient documentation and
workflows in healthcare.
3.2
generative AI system
generative artificial intelligence system, noun
GenAI system, noun
AI system based on techniques and models that aim to generate new content
Note 1 to entry: Examples of generated content can include text, audio, code, video, and image.
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
Note 2 to entry: Generated content encompasses new information or new ways to express pre-existing information. That
pre-existing information can be drawn from the input, a dataset involved in building the model or an external repository.
[SOURCE: ISO/IEC 22989:2022/DAmd 1, 3.1.38]
3.23.3
health informatics
scientific discipline that is concerned with the cognitive, information processing and communication tasks of
healthcare practice, education and research, including the information science and technology to support
these tasks [SOURCE:ISO/TR 18307[3] , 3.73]
3.3
Intended[SOURCE: ISO/TR 18307:2001, 3.73, modified — "healthcare" changed to "health".]
3.4
intended use/
intended purpose, noun
Useuse for which a product, process or service is intended according to the specifications, instructions and
information provided by the manufacturer.
Note 1 to entry: The intended medical indication, patient population, part of the body or type of tissue interacted with,
user profile, use environment, and operating principle are typical elements of the intended use.[SOURCE: ISO/IEC Guide
63[4] , 3.4 and ISO 14971[5] , 3.6].
[SOURCE: ISO 14971:2019, 3.6]
3.43.5
medical device
instrument, apparatus, implement, machine, appliance, implant, reagent for in vitro use, software, material or
other similar or related article, intended by the manufacturer to be used, alone or in combination, for human
beings, for one or more of the specific medical purpose(s) of: —
— diagnosis, prevention, monitoring, treatment or alleviation of disease; —
— diagnosis, monitoring, treatment, alleviation of or compensation for an injury; —
— investigation, replacement, modification, or support of the anatomy or of a physiological process; —
— supporting or sustaining life; —
— control of conception; —
— disinfection of medical devices; —
— providing information by means of in vitro examination of specimens derived from the human body; and
does not achieve its primary intended action by pharmacological, immunological or metabolic means, in
or on the human body, but which may be assisted in its intended function by such means.
Note 1 to entry: Products which may be considered to be medical devices in some jurisdictions but not in others include:
— disinfection substances; — aids for persons with disabilities; — devices incorporating animal and/or human tissues;
— devices for in vitro fertilization or assisted reproduction technologies.
— disinfection substances;
— aids for persons with disabilities;
— devices incorporating animal and/or human tissues;
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
devices for in vitro fertilization or assisted reproduction technologies.[SOURCE: EN ISO 13485[6] , 3.11]
—
[SOURCE: ISO 13485:2016, 3.11]
3.53.6
pseudonymization
pseudonymization particular type of de-identification that both removes the association with a data subject
and adds an association between a particular set of characteristics relating to the data subject and one or more
pseudonyms [SOURCE:EN ISO 25237[7] , 3.42]
Symbols and abbreviated[SOURCE: ISO 25237:2017, 3.42]
4 Abbreviated terms
AI artificial intelligence
AI-DSF Artificial Intelligence-Enabled Device Software Functions
AAMI Association for the Advancement of Medical Instrumentation
AIHI AI-enabled health informatics
AIMD active implantable medical device
CHAI Coalition for Health AI
CLS continuous learning system
EHR electronic health record
FFP fit for purpose
FG-AI4H Focus Group on Artificial Intelligence for Health
GenAI generative AI
GI-AI4H Global Initiative on Artificial Intelligence for Health
GMLP good machine learning practice
HIS hospital information system
HMT human machine teaming
IMDRF International Medical Device Regulators Forum
LLM large language model
MSS management systen standard
NCD non-communicable disease
OECD Organisation for Economic Co-operation and Development
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
PCCP Predetermined Change Control Plan
RWD real-world data
SaMD software as a medical device
AI Artificial intelligence
AI-DSF Artificial Intelligence-Enabled Device Software Functions
AAMI Association for the Advancement of Medical Instrumentation
AIHI AI-enabled health informatics
AIMD Active implantable medical device
CHAI Coalition for Health AI
CLS Continuous learning system
EHR Electronic health record
FFP Fit for purpose
FG-AI4H Focus Group on Artificial Intelligence for Health
GenAI Generative AI
GI-AI4H Global Initiative on Artificial Intelligence for Health
GMLP Good machine learning practice
HIS Hospital information system
HMT Human machine teaming
IMDRF International Medical Device Regulators Forum
LLM Large language model
MSS Management systen standard
NCD Non-communicable disease
OECD Organisation for Economic Co-operation and Development
PCCP Predetermined Change Control Plan
RWD Real-world data
SaMD Software as a medical device
5 Current state of the health informatics ecosystem
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
5.1 Healthcare context
ISO TC215TC 215 health informatics Task Force 5 has previously examined the challenges being faced by the
healthcare system in the 21st Century ( Application of AI Technologies in Health Informatics ISO/TC 215 AHG2
[8] [6]
– Final Report March 1, 2021 ) . ). These challenges are expected to continue shaping the ways in which AI
is applied in health informaticshealth informatics to support managing and delivering healthcare.
Some of the challenges affect multiple industries (e.g. climate change) but the impact is different. Many are not
controllable in the short term (e.g. changing population demographics) and possibly not even controllable in
the long term. The challenges identified can also have a differential impact in different geographies and
cultures. These include
— ageing populations in many countries
— growing socio-economic inequalities within and between countries
— reduced healthcare funding at both individual and government levels
— clinical workforce shortages
— disruption to global supply chains
— rising levels of chronic disease
— increased pandemic risk
— rising consumer expectations of control over their personal data
— increasing regulation
— new technologies (including genomics and artificial intelligence)
There have been ongoing policy and operational responses to these challenges including
— moving from an illness to a wellness model of health
— greater focus on population and public health
— person centred rather than organization centred models of care
— greater use of remote provision of care
— increased monitoring of social indicators
— funding reforms (e.g. value based care)
— technology innovation (e.g. cloud technology, AI, interoperability)
The application of health informaticshealth informatics is very wide and can include use of information to
support direct patient care, population health, clinical research, policy development, training and operational
management. The provision of healthcare services has increasingly diffuse boundaries with close interaction
with social, education and justice systems. For this reason, alignment with horizontal industry agnostic AI
standards is beneficial and desirable. However, healthcare AI applications also have unique characteristics
including patient safety requirements, regulatory oversight, clinical validation needs, and ethical
considerations indicating a need for either healthcare-specific standards or significant adaptation or
extension of the horizontal industry agnostic standards.
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
Various approaches to the classification of different types of AI systems that are used in healthcare are
described in Annex A.
5.2 Ethical and regulatory environment
5.2.1 Ethics
Healthcare has existing guidance and regulation pertaining to quality, safety, goals, and ethical principles.
[9] [7]
Ethical principles include: autonomy, justice, beneficence, and non-maleficence . . When extended to public
[10] [8]
health they also include health maximization, efficiency, and proportionality . . Digital ethics goes beyond
established legal principles and highlights the underlying principles and values of respecting fundamental
rights (e.g. dignity, privacy and data protection).
More than 84 ethics initiatives have published reports describing high-level principles, tenets, and abstract
[11] [9]
requirements for the development and deployment of AI systems . . An analysis of 36 prominent sets of
such principles revealed the following 8 themes:
— privacy,
— accountability,
— safety and security,
— transparency and explainability,
— fairness and non-discrimination,
— human control of technology,
— professional responsibility, and
[12] [10]
— promotion of human values . .
These principles apply to the development and deployment of AI-enabled health applications. They can be
applied at every stage of the AI health application lifecycle, from needs determination and design through
[13] [11]
decommissioning . . When pertinent, to promote trustworthiness, they can be applied as basic
requirements for the development, deployment, use, and evaluation of AI health applications. Moreover,
relevant principles and requirements can also be applied to the development and revision of health
informaticshealth informatics standards pertaining to or encompassing AI health applications, providing,
whenever applicable, full transparency about an AI product throughout its lifecycle, e.g. how the algorithm
works, what data were used to train it, what tests were conducted, how the trained product performed in such
tests, experience with use in practice, etc.
In 2021 the World Health Organization (WHO) published its guidelines on Ethics and governance of artificial
intelligence for health: WHO guidance which proposed six ethical principles
— – Protect human autonomy
— – Promote human well-being and safety and the public interest
— – Ensure transparency, explainability and intelligibility
— – Foster responsibility and accountability
— – Ensure inclusiveness and equity, and
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
[14][12]
— – Promote AI that is responsive and sustainable
The WHO principles were subsequently endorsed in 2022 by the Focus Group on Artificial Intelligence for
Health (FG-AI4H) which was abolished in July 2023 with the formation of the Global Collaboration on Artificial
Intelligence in Health (GC-AI4H) a collaborative endeavour led by three specialized Agencies of the United
Nations, namely, World Health Organization (WHO), International Telecommunications Union (ITU) and
World Intellectual Property Organization (WIPO).
In 2025 GC-AI4H published Ethics and governance of artificial intelligence for health: Guidance on large multi-
[15][13]
modal models which reiterated the continued applicability of the WHO principles published in 2021
when considered in the context of generative AI.
While these ethical principles originated as voluntary guidance, they are forming the basis of legally
enforceable requirements in some jurisdictions, where mandatory measures related to transparency, safety
testing, fairness, accountability, and human oversight are being introduced for what is considered high-risk AI
in healthcare.
5.2.2 Regulation
It can be difficult to apply current regulatory frameworks for health and medical technologies to applications
utilizing artificial intelligence. For instance, medical devicemedical device regulations across the world require
validation (6.13 )) that devices and processes produce reproducible and expected outputs or results. While
reproducibility of outputs is not a problem that is specific to artificial intelligence, reproducibility is already
an issue being discussed particularly for continuous learning applications of AI. Many existing medical
devicemedical device regulations were not written with generative AI systems and large language models in
mind. These regulations are in a state of flux with the expectations of healthcare professionals, regulators,
device manufacturers and other stakeholder groups to be understood.
Interpretation and guidance can be helpful for applying existing regulations to AI technology. Modified or new
regulations and standards can help to fill in possible gaps and to resolve ambiguities in existing regulations.
Wherever possible, it is preferable for regulations and standards to be harmonized internationally to ensure
access to current state of the art technologies and to prevent the development of technical barriers to trade
that raise costs and limit access to healthcare.
From a healthcare perspective, the sector's use of AI systems is split between the highly regulated use of
medical devices (including medical devicemedical device software) and use for other administrative and
clinical purposes. The medical deviceThe medical device community has a long history of regulation and
management of the use of AI systems including, for example, requirements for post-market surveillance. The
level of oversight required for the device manufacturers is based on the assessed level of risk of the device.
While there are some local variations in its application, the risk framework used for medical devices is a matrix
approach that considers both the clinical risk and the level of autonomy. A description of the risk framework
for medical devices is provided in 6.2 . Recent initiatives by medical device regulatory agencies emphasize an
AI lifecycle approach as described in 6.1 ,, with the goal of implementing risk controls in both pre- and post-
market phases.
As an example of global regulatory initiatives, the IMDRF working group on Artificial Intelligence and Machine
Learning-enabled (AI/ML) and Software as a Medical Device (SaMD) have been developing useful
[16] [14]
documentation such as Good Machine Learning Practice (GMLP) ,) , Essential Principles and Content of
[17] [15]
Predetermined Change Control Plans , , etc. to provide internationally harmonized principles.
It has yet to be agreed how the appropriate level of risk (and associated need for regulation) of non-device
uses of AI systems in healthcare will be determined. Many jurisdictions are reviewing this need and
undertaking consultation with the community and clinicians. To date there has been no internationally
consistent approach and many countries are yet to introduce or modify their legislation. Some jurisdictions
have assessed that all use of AI in healthcare is high risk and some others have adopted the medical device
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
model to be applied for more general use by default. In most jurisdictions whenever AI is being applied outside
of usage as a medical device medical device, such as in the use of ambient scribing products ambient scribing
products, there is an expectation of a 'human in the loop' prior to any clinical action being taken.
It could be considered that all AI used for clinical purposes is regulated - but some systems fall into a lower
risk category with developers needing to monitor "lower-risk" AI systems to ensure they do not stray into the
"high-risk" category. Many jurisdictions require a human in the loop for AI applications used outside legislated
medical device frameworks. This is increasingly described as meaningful human oversight ensuring a qualified
human can understand system outputs, intervene when needed, and assume responsibility for clinical
decisions supported by AI.
Ongoing regulatory developments in many countries reflect a converging global movement toward risk-based
governance for AI systems. Harmonized international standards can help to support interoperability of
regulatory expectations and facilitate access to safe and effective AI technologies across borders.
6 Considerations in use of AI in health informatics
6.1 Lifecycle
The AI lifecycle model describes the progression of an AI system from conception to retirement, providing a
structured framework to support stakeholders in developing AI systems more effectively and efficiently. The
concept of an "AI lifecycle" varies across standards and guidelines, reflecting different perspectives depending
on their specific focus.
For example, EN ISO/IEC 22989[1]Information technology — Artificial intelligence — Artificial intelligence
concepts and terminologyISO/IEC 22989 defines the lifecycle of an AI system from the viewpoint of AI system-
specific processes, comprising the following eight stages:
— Inception: Identifying objectives and requirements, considering risk management, transparency,
accountability, cost, funding, resources, and feasibility.
— Design and Developmentdevelopment: Determining the overall approach and architecture, developing
code, processing training data, and implementing risk treatment.
— Verification and Validationvalidation (6.13 ):): Testing software for functionality and defects, verifying
that AI capabilities operate as intended, confirming the system meets quality criteria, and performing risk
monitoring and review. Note that theThe terms “verification” and “validation” can be used with different
meanings depending on the context. In medical deviceIn medical device development, validation typically
refers to confirmation that the system fulfils its intended clinical use, whereas in machine learning
development the term “validation” is often used to refer to model tuning or performance evaluation during
training.
— Deployment: Installing, releasing, and configuring the AI system, along with risk treatment.
— Operation and Monitoringmonitoring: Maintaining and updating the system, monitoring its performance,
and performing ongoing risk management.
— Continuous Validationvalidation: Validating the system on an ongoing basis, particularly relevant in the
context of continuous learning. In this context, “continuous validation” refers to ongoing confirmation that
the AI system continues to fulfil its intended use in its operational environment. This doesreferdoes refer
to routine software testing or model tuning.
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
— Re-evaluation: Reviewing operational results, refining objectives and requirements, and conducting risk
reassessment.
— Retirement: Decommissioning and disposing of the system, with replacement as appropriate.
The structure is not strictly linear; certain stages (e.g. “Re-evaluation” or “Continuous Validation”) can involve
cyclic processes that return to earlier phases such as “Design and Development” or “Operation and
Monitoring.”
In a similar vein, the U.S. Food and Drug Administration (FDA) published an executive summary in November
[18] [17]
2024 entitled "Total Product Lifecycle Considerations for Generative AI-Enabled Devices" ." . This document
outlines a lifecycle model tailored to AI-enabled software, including generative AI applications, comprising
seven stages:
— Planning and Designdesign: Defining goals, scope, and technical architecture.
— Data Collectioncollection and Managementmanagement: Gathering and organizing training/testing data
to ensure quality and relevance.
— Model Buildingbuilding and Tuningtuning: Developing and refining models using collected data.
— Verification and Validationvalidation: Assessing the model’s reliability and performance.
— Model Deploymentdeployment: Integrating the model into the target operational environment.
— Operation and Monitoringmonitoring: Ensuring stability post-deployment, including maintenance
activities such as bug fixes and updates.
— Real-World Performance Evaluationworld performance evaluation: Evaluating system performance
under actual operating conditions.
This framework is comparable to EN ISO/IEC 22989[1]ISO/IEC 22989 but introduces a finer separation
between data handling (Stages 2 and 3) and model development. It also merges post-deployment feedback
loops (e.g. “Re-evaluation” and “Continuous Validation”) into a consolidated “Real-World Performance
Evaluation” stage.
[19][18]
Coalition for Health AI (CHAI) published a draft guide (v0.3, June 2024) titled, “Responsible AI Guide”
which provides comprehensive guidance on quality and ethics for AI systems in healthcare. The AI lifecycle
model, which the guide defines, consists of the following steps:
— Define Problemproblem and Planplan: Identifying the problem, understanding stakeholder needs,
evaluating feasibility, and deciding whether to build, buy, or partner.
— Design the AI Systemsystem: Capturing technical requirements, designing system workflow, and planning
deployment strategy.
— Engineer the AI Solutionsolution: Developing and validating the AI model, preparing data, and planning
for operational deployment.
— Assess: Conducting local validation, establishing a risk management plan, training end users, and ensuring
compliance.
— Pilot: Implementing a small-scale pilot, monitoring real-world impact, and updating risk management.
— Deploy and Monitormonitor: Deploying the AI solution at scale, conducting ongoing monitoring, and
maintaining quality assurance.
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
The CHAI draft guide is cited for illustrative purposes to reflect emerging practices rather than established
standards.
From another angle, the British Standards Institution (BSI) published BS 30440[20]Validation framework for
the use of artificial intelligence (AI) within healthcare – Specification. This standardBS 30440 defines lifecycle
phases for evaluating the development of safe, effective, and ethical healthcare AI systems, covering both
regulated medical devices and unregulated healthcare AI systems. The phases include:
— Inception: Identifying the clinical need to be addressed.
— Development: Engaging stakeholders, managing training data ethically, and documenting model creation
and usability.
— Validation: Assessing clinical effectiveness, external validity, and bias mitigation.
— Deployment: Addressing resource planning, cost implications, cybersecurity, and explainability, alongside
risk management.
— Monitoring: Conducting post-deployment monitoring and managing updates and decommissioning.
The BSIThe BS 30440 lifecycle condenses and integrates some stages, while aligning closely with the core
principles of safety, effectiveness, and equity in the healthcare domain.
In contrast to these system-focused frameworks, the OECD report "Advancing Accountability in AI: Governing
[21] [20]
and Managing Risks throughout the Lifecycle for Trustworthy AI" " approaches the AI system lifecycle
from a risk governance perspective. The OECD defines the lifecycle in terms of six core stages:
— Plan & Designand design
— Collect & Process Dataand process data
— Build & Use Modeland use model
— Verify & Validateand validate
— Deploy
— Operate & Monitorand monitor
Each of these stages is mapped to four overarching risk management functions: Define, Assess, Treat, and
Govern, echoing the structure of ISO 31000[22]ISO 31000 but adapted to AI-specific challenges. This model is
intended to guide the implementation of accountability mechanisms and risk controls throughout the lifecycle
of an AI system.
Additionally, ISO/IEC 8183[23]Information technology — Artificial intelligence — Data life cycle
frameworkISO/IEC 8183 defines a data lifecycle framework that emphasizes data-centric operations across
the full lifespan of an AI system, from conceptualization to decommissioning. It consists of ten distinct stages:
— Idea Conceptionconception
— Business Requirementsrequirements
— Data Planningplanning
— Data Acquisitionacquisition
© ISO/IEC 2026 – All rights reserved
ISO/IEC CD TRDTR 18988:2026(en)
— Data Preparationpreparation
— Building Modelmodel
— System Deploymentdeployment
— System Operationoperation
— Data Decommissioningdecommissioning
— System Decommissioningdecommissioning
This framework complements system-focused lifecycles by offering detailed guidance on data stewardship
and governance activities necessary to support AI system functionality. A similar data life cycle model is also
defined in ISO/IEC 5259-1[24] , Data quality for analytics and machine learning (ML) — Part 1: Overview,
terminology, and examples, which is derived from ISO/IEC 8183[23]ISO/IEC 5259-1, which is derived from
ISO/IEC 8183 and therefore identical in structure.
The six examples presented above define AI system lifecycle stages from different perspectives, resulting in
variations in granularity and structure. Nevertheless, a broad correspondence among the stages can be
established. Table 1 belowTable 1 provides a comparative mapping of the lifecycle phases across the six
frameworks.
Table 1 — Comparison of AI system lifecycle stages: EN ISO/IEC 22989[1] ,ISO/IEC 22989, FDA
[18] [17] [19] [18] [21]
executive summary , , CHAI Responsible AI Guide , BS 30440[20], , BS 30440, OECD report ,
[20]
and ISO/IEC 8183[23]ISO/IEC 8183
ISO/IEC BS ISO/IEC
FDA executive OECD report
[18] BS ISO/IE
22989:2022ISO CHAI 30440:2023 8183:2023
[17] [20]
summary
30440 C 8183
/IEC 22989
Inception Planning and Define Problem Inception Plan & Idea Conception
Design and Plan Designand
Business
design
Requirements
Design and Data collection Design the AI Development Collect & Process Data Planning
Development and management System Dataand process
data
Engineer the AI Data Acquisition
Solution
Data Preparation
Model Building Build & Use Building Model
Modeland use
and Tuning
model
Verification and Verification and Assess Validation Verify & Throughout
Validation Validation Validateand "Data planning"
Pilot
validate to "Building
model"
Deployment Model Deploy and De
...







