Book a call
EU AI Act · MDR · SaMD

Your AI model works.
Can you prove it to a notified body?

EU AI Act and MDR require AI models in medical devices to be supported by third-party statistical evidence — dataset representativeness, stratified performance, calibration, drift detection. Self-assessment does not satisfy a notified body. And the deadline is closer than it looks.

Dec 2027 EU AI Act hard deadline — standalone Annex III AI systems
12–18 mo typical NB review queue under MDR for SME submissions
Now latest viable start date if remediation is needed after evidence review
Book a 30-minute call → No commitment · Honest answer even if it is no
PhD Physics · CERN · 15y Boston Scientific · Medical Devices · EMEA Analytics & Data Science · Six Sigma · EU AI Act · MDR
Why the deadline is already here
NOW Jul 2026 EVIDENCE GENERATION + possible remediation 3–12 months TECHNICAL FILE compile + submit 2–4 months NOTIFIED BODY REVIEW queue + assessment 12–18 months DEADLINE Dec 2027 17–34 MONTHS MINIMUM · BUFFER IS ZERO

Backward-plan from December 2027: NB queue + technical file prep + evidence generation = start date is now. Remediation of a data representativeness or calibration gap adds 6–12 months.

Why self-assessment is not enough
What companies assume

"Our data science team can run the numbers"

Internal teams can run the statistics. What they cannot produce is third-party evidence. Notified bodies systematically discount first-party performance claims — the same way they require independent audit for QMS. The value of the certificate comes from who signed it, not from the measurement itself.

What the regulation requires

Article 9 of the EU AI Act is explicit on risk management evidence

AI Act and MDR Annex II require documented evidence of performance under real distributional conditions, calibration across subgroups, and ongoing drift monitoring — all traceable to an identifiable responsible party. Internal documentation meets neither the independence nor the traceability standard a notified body applies.

What RE:MARK provides

Third-party evidence your notified body can cite

An independent evidence package — SHA-256 audit manifest, regulatory cross-references, structured findings — produced by a physicist with 15 years in medical devices. The package is designed to be submitted as-is into a technical file, not summarised or re-formatted by your team.

The data never leaves your environment

Client-controlled execution, independent output

The validation library runs in your infrastructure on your data. No patient data, device data, or proprietary training sets are transmitted or stored externally. What RE:MARK produces is the evidence report — the output, not a copy of the input. This satisfies both medtech data governance and GDPR requirements for sensitive health data.

Five evidence modules · One submission-ready package
M1

Dataset Characterisation Report

Structured inventory of the training and evaluation dataset: class distribution, demographic and site stratification, label quality assessment, and representativeness analysis relative to the intended population. Flags gaps between training distribution and intended use population before they become a notified body finding.

AI Act Art. 10 MDR Annex II §6.1 Output: dataset characterisation PDF + audit log
M2

Stratified Performance Assessment

Performance metrics decomposed across clinically relevant subgroups — demographic strata, device configurations, acquisition sites. Bootstrap confidence intervals on all reported metrics. Reveals subgroup gaps that aggregate accuracy hides: a model with 93% overall accuracy and 71% on a key subgroup is a regulatory problem.

AI Act Art. 9 MDR Annex II §6.2 Team-NB Q14–Q16 Output: stratified performance tables + CI plots
M3

Calibration Audit

Reliability diagrams, Expected Calibration Error (ECE), and overconfidence analysis. A model whose confidence scores do not match empirical probabilities fails the risk management standard even if its accuracy is acceptable — clinicians using AI-assisted outputs rely on calibrated confidence, not raw scores.

AI Act Art. 9 §2(d) MDR Annex II §6.2 Output: calibration curves + ECE table
M4

Distribution-Shift Detection Log

Statistical tests for covariate and concept drift between training and deployment distributions, and across time windows in post-market data where available. Documents the evidence base for the post-market surveillance plan required under MDR and AI Act Art. 72.

AI Act Art. 72 MDR Art. 83 · PMCF Team-NB Q20 Output: drift test report + monitoring protocol
M5

Prediction Set Coverage Guarantees

Conformal prediction sets with guaranteed marginal coverage — a distribution-free, assumption-minimal method that produces statistically valid uncertainty bounds even when model assumptions are not met. Documents the uncertainty quantification requirement under AI Act Art. 9 in the strongest available form.

AI Act Art. 9 §2(f) MDR Annex II §6.3 Output: coverage analysis + prediction interval report
How the engagement runs
Phase 01 · Week 1 · Scope

Define the regulatory context

Identify the applicable regulatory pathway (AI Act risk class, MDR device class, IVDR), the intended use population, the evaluation dataset available, and the notified body's known question pattern for this device category. Scoping produces the evidence plan before any analysis begins.

Phase 02 · Weeks 2–4 · Execution

Run the evidence battery

The five-module library executes in your controlled environment. Each module produces a structured output with a hash-signed audit log. Findings that indicate gaps — dataset imbalance, subgroup underperformance, miscalibration — are reported with severity and recommended remediation path.

Phase 03 · Week 5 · Package

Produce the submission-ready report

All module outputs compiled into a single PDF evidence package with regulatory cross-references, SHA-256 audit manifest, and a structured findings summary. Format matches what notified bodies expect to see in a technical file annex. One document, ready to submit.

Who commissions this
VP Regulatory Affairs · SaMD Manufacturer

Evidence that holds up in an audit

You are preparing for MDR conformity assessment or responding to a notified body's AI-specific questions during surveillance. You need third-party statistical evidence that is structured, traceable, and immediately insertable into the technical file — not a consulting report you have to translate yourself.

CEO · SME SaMD Company

Compliance without building the capability internally

You have a Class IIa or IIb device with an AI component. Your team built the model; no one on staff has produced EU AI Act evidence packages before. You need a fixed-price engagement with a defined output, not an open-ended consulting relationship, and you need it before the timeline closes.

VC / PE Fund · MedTech Portfolio

AI Act exposure in your portfolio, resolved before exit

You hold SaMD companies with AI models in their products. Unresolved EU AI Act compliance is a valuation and exit risk — buyers and notified bodies will surface it. An evidence package produced now, before a transaction, removes that risk from the data room and from the deal conversation.

PRRC · Quality & Regulatory Consultant

Statistical evidence for your client's technical file

You manage the regulatory pathway but do not have a statistical validation team in-house. RE:MARK produces the evidence package; you integrate it into the technical file alongside the clinical evaluation and QMS documentation. Fixed scope, defined output, no open billing.

A regulatory affairs consultant maps compliance gaps against a checklist and tells you what is missing. A data science consultant writes the code and hands you the numbers. Neither produces third-party statistical evidence in the format a notified body expects to find in a technical file.

The combination that makes this work is specific: a physics-trained experimenter who has spent 15 years inside medical device development — at Boston Scientific, across EMEA, at the intersection of clinical data and regulatory submissions — and who has since built the statistical validation tooling from scratch. The evidence is produced by someone who understands both what the regulation requires and what the numbers actually mean.

Fixed-price engagement · Scope agreed before we start · No open-ended billing · Data stays in your environment

AI model in a medical device facing an EU AI Act deadline?

A 30-minute call to understand your device, your timeline, and whether this engagement is the right next step. No commitment. No proposal before we have understood the situation.

Book 30 minutes → Or write directly
Giulio Piana Founder and Principal · RE:MARK giulio.piana@brandcraft.it

Evaluating an industrial AI or medtech target for investment?

RE:MARK Technical Due Diligence & Integration Advisory →