Three places the regulations actually pinch.
Built for the regulation that shares evidence with another.
Three clinical contexts.
A medical-AI vendor selling diagnostic imaging software into EU hospitals.
- Annex I (MDR product) classification recorded; conformity runs through the device's notified body.
- Annex IV reused as the MDR technical-file annex — one source of truth, two regulators.
- The Art. 13 IFU package built once, sealed, sent per hospital with a unique sharing token.
- A public verify URL on the dossier — procurement checks the seal before raising a purchase order.
A 600-bed hospital deploying vendor AI for radiology and cardiology.
- Deployer role detected; provider-only obligations hidden from the dashboard.
- Each system's IFU imported from the vendor; the oversight plan templated from the imported fields.
- The FRIA runs because the system reaches patients; the clinical-governance committee is the assessor.
- Worker notification (Art. 26(7)) tracked for radiographers and cardiologists.
A life-sciences group with internal AI for drug discovery and external AI in clinical operations.
- Separate organisations keep the R&D provider obligations apart from the operational deployer obligations.
- Models used solely for scientific research sit outside the Regulation; operational systems are classified on their own facts.
- The AI-literacy programme covers research scientists and clinical operations, tracked separately.
- A group-level view for the audit committee; per-subsidiary dossiers for inspections.
The capabilities that map to MDR-shaped governance.
Questions clinical teams ask
Our AI is already a medical device under the MDR. Does the EU AI Act add a second conformity assessment?
Usually not a separate one. Clinical AI reaches high-risk through the Annex I product route, so the EU AI Act conformity assessment travels with the MDR notified-body procedure. Veritome records which pathway applies at the Art. 43 step and reuses the Annex IV sections as the MDR technical-file annex.
A hospital deploying vendor AI — what do we actually owe?
The deployer duties: Art. 26 (use per the instructions, human oversight, logs, worker notification) and, where the system is Annex III and you act in a public-services capacity, the Art. 27 fundamental-rights impact assessment. The classification reads your role and skips the provider-only items.
Does patient data change the register?
Yes. Special-category health data brings GDPR Art. 9 and a DPIA into the system's register, and the FRIA and DPIA share their common parts so the assessment is done once. The ISO/IEC 27001 programme covers the information-security controls a hospital IT review expects.
Is a DPIA a substitute for the FRIA?
No. The FRIA is its own assessment under Art. 27, but where a DPIA exists the overlap is mapped so the shared questions are answered once and both records stay consistent.



