Let’s Talk Risk! brings together MedTech leaders and practitioners for thoughtful conversations on the challenges that shape risk, quality, innovation, and leadership. With 150+ episodes and more than 30K downloads, it helps professionals gain the clarity and confidence to lead through complex decisions.
A qualified tool does not eliminate regulatory scrutiny. It eliminates the need to keep proving that the same ruler works.
What if one of the biggest sources of friction in medical device development is not the device itself—but the tool being used to measure its performance?
Historically, FDA evaluated many of these tools as part of individual device submissions. The Medical Device Development Tools (MDDT) program creates a different pathway: qualify a tool for a defined context of use, and sponsors can rely on that qualification in subsequent device development and regulatory submissions without having to repeatedly establish the tool’s suitability for that same use.
This Deep Dive explores what that means for evidence generation, regulatory strategy, and medical device development.
Key highlights covered in the audio:
* Why MDDT exists: reducing repeated evaluation of the same measurement and assessment methods across device submissions.
* Context of use is everything: qualification applies only within clearly defined boundaries for how, where, and for what purpose the tool is used.
* Different forms of evidence: qualified tools can include clinical outcome assessments, biomarker tests, non-clinical assessment models, and other specialized tools.
* From patient-reported outcomes to computational models: examples show how FDA is qualifying increasingly diverse ways of generating evidence.
* A more predictable development strategy: the MDDT process allows developers to establish the scientific credibility of a tool before relying on it in future regulatory decisions.
The important point is that MDDT qualification does not replace evaluation of the medical device itself.
Instead, it can reduce uncertainty around something equally important: whether the method being used to generate the evidence is scientifically credible for its intended purpose.
Keywords:
FDA MDDT, Medical Device Development Tools, Context of Use, Regulatory Science, Clinical Outcome Assessments, Biomarker Tests, Non-Clinical Assessment Models, Computational Modeling, Evidence Generation, Medical Device Development
🎧Listen to the Deep Dive for a closer look at how FDA’s MDDT program can reduce repeated validation work, improve predictability, and change how medical device teams think about evidence-generation strategy.
Thanks for reading Let's Talk Risk!. If you liked this post, share with others.
Note:
The audio summary was prepared using Google NotebookLM, an AI-enabled research tool. Here are a few key resources used for this analysis:
* FDA (2020). CDRH Qualification of the Kansas City Cardiomyopathy Questionnaire (KCCQ) as a Clinical Outcome Assessment Instrument.Listed in the FDA MDDT Qualified Tools Registry
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe
Deep Dive: What FDA’s QMSR Warning Letters Are Revealing
vendredi 11 septembre 2026 • Durée 21:13
If you’re trying to manage risk in isolated silos, your quality management system is already obsolete.
What happens when a supplier changes a device label without triggering design controls? When operators quietly rework nonconforming product? Or when serious post-market signals never make it back into the risk file?
This Deep Dive examines recent FDA inspection and warning-letter examples through one common lens: the integration of risk management across the quality system.
The cases illustrate how seemingly separate failures in supplier controls, manufacturing, complaints, nonconforming product, CAPA, and infrastructure can become connected risk-management failures under QMSR.
Key highlights covered in the audio:
* Why ISO 13485 Clause 7.1 is becoming so important — and how risk management increasingly connects multiple parts of the QMS.
* Supplier changes can become risk-management events when labeling, intended use, or other product assumptions change without adequate escalation.
* Undocumented shop-floor rework can hide risk signals, leaving management metrics looking healthy while process problems accumulate.
* CAPA cannot work in isolation when environmental controls, process data, nonconformances, and risk analyses are disconnected.
* A static risk file is no longer enough. Post-market experience, manufacturing changes, supplier issues, and emerging hazards must continually inform lifecycle risk management.
The broader lesson is straightforward: QMSR is pushing companies away from managing compliance clause by clause and toward managing risk as an interconnected system.
And that raises an important question for medical device organizations:
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
Deep Dive: The PFAS Substitution Risk Paradox in Medical Devices
vendredi 4 septembre 2026 • Durée 20:26
FDA: There is no reason to restrict the continued use of fluoropolymers in medical devices.
What happens when pressure to eliminate a material creates greater risk for the patient?
This Deep Dive examines the growing regulatory tension around PFAS and medical-device fluoropolymers, and why evaluating substitution requires more than asking whether a material belongs to a broad chemical category.
Key highlights covered in the audio:
* Not all PFAS present the same risk. The discussion distinguishes small-molecule PFAS from large, biostable fluoropolymers such as PTFE and PVDF used in medical devices.
* FDA’s position is supported by extensive clinical experience. Decades of use and a large ECRI review found no conclusive evidence of patient harm from PTFE.
* Substitution can introduce new clinical hazards. Changes in friction, flexibility, chemical resistance, sealing, or coating integrity can directly affect device performance and patient safety.
* This creates a substitution risk paradox. Eliminating one perceived material hazard may introduce more immediate risks such as reduced trackability, altered drug delivery, particulate shedding, or embolic complications.
* The decision belongs inside risk management. Under ISO 14971, the key question is how substitution changes the device’s total risk profile—not simply whether the original material can be removed.
* A defensible strategy requires evidence. Chemical characterization, toxicological assessment, clinical evidence, and post-market surveillance can support continued use of a proven material.
Keywords:
PFAS, Fluoropolymers, PTFE, Medical Devices, FDA, Material Substitution, ISO 14971, Benefit-Risk Assessment, Patient Safety, Risk Management
🎧 Listen to the Deep Dive for a closer look at why eliminating a perceived material hazard does not necessarily reduce the overall risk of a medical device.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
Deep Dive: When Patient Preference Becomes Regulatory Evidence
vendredi 28 août 2026 • Durée 32:10
Patient preference is no longer a soft qualitative afterthought.
What if a device carries significant risks, but patients are willing to accept them for a meaningful clinical benefit?
This Deep Dive examines how FDA’s evolving approach to Patient Preference Information (PPI) can turn those tradeoffs into quantitative evidence for regulatory benefit-risk decisions.
Key highlights covered in the audio:
* PPI is not the same as a patient-reported outcome. PROs describe what patients experience. PPI asks what risks patients are willing to accept to obtain a particular benefit.
* Risk tolerance can be quantified. Methods such as discrete choice experiments and threshold techniques can establish measures such as Maximum Acceptable Risk (MAR) and help define the level of benefit patients consider meaningful.
* Study design matters enormously. Patient comprehension, health numeracy, neutral presentation of risk, attribute selection, statistical analysis plans, and appropriate visual communication can determine whether preference data are credible.
* FDA engagement needs to happen early. The discussion highlights the importance of using the Q-Submission process to align on attributes, ranges, methodology, and statistical analysis before the study is conducted.
* PPI can extend beyond premarket approval. Preference information may inform labeling, shared decision-making, post-market benefit-risk assessments, and other decisions across the total product lifecycle.
Keywords:
Patient Preference Information, FDA Guidance, Benefit-Risk Assessment, Risk Tolerance, Medical Devices, Discrete Choice Experiment, Maximum Acceptable Risk, Q-Submission, Total Product Lifecycle, Risk Management
🎧 Listen to the Deep Dive for a closer look at how patient preference is becoming part of the quantitative language of medical-device risk management.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
Deep Dive: Designing Safety Into Autonomous Robotic Devices
vendredi 21 août 2026 • Durée 20:30
The vulnerability of the modern clinical lab is quite literally concentrated at the point of the needle.
Clinical laboratories have automated almost everything after the blood reaches the tube. Yet one of the most common invasive procedures in healthcare still depends on a person finding a vein by sight and touch and manually inserting a needle.
FDA’s De Novo authorization of Vitestro’s Aletta® may signal that this last major manual bottleneck is beginning to change.
But this Deep Dive is about much more than a robot drawing blood.
It explores a bigger question for anyone working in risk management, quality, regulatory, clinical, or medical-device development.
What does it take to make an autonomous medical device safe enough to perform an invasive clinical procedure on its own?
In this audio brief, we unpack how Aletta combines imaging, robotics, software constraints, clinical supervision, and layered fail-safes — and how FDA evaluated a technology for which no predicate existed before.
The result is a fascinating case study in how risk management changes when a machine begins doing what previously required a trained human.
Key highlights covered in the audio:
* De Novo pathway: De Novo authorization was necessary because there was no existing predicate for autonomous robotic phlebotomy.
* Risk controls built around autonomy: imaging, software constraints, movement detection and supervisory intervention create multiple layers of protection.
* Clinical performance: the ADOPT study reported a 94.5% first-stick success rate when a suitable vein was identified, including strong performance in patients with obesity and difficult venous access.
* Specimen quality: robotically collected samples demonstrated analytical equivalence for the laboratory parameters evaluated.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
LTR 163: FDA’s New Risk Lens Under QMSR
vendredi 14 août 2026 • Durée 27:54
Summary
“I don't think it's as easy to outsource risk as it used to be. Risk is pervasive now.”
In this episode of the Let’s Talk Risk! conversation, host Naveen Agarwal speaks with Allyson Mullen, Director at Hyman, Phelps & McNamara, P.C., about what FDA’s early enforcement activity under the Quality Management System Regulation (QMSR) may tell medical device manufacturers about the agency’s evolving expectations.
Using the first warning letter discussed in the episode as a starting point, Allyson examines how FDA is citing risk management under ISO 13485 Clause 7.1 and, increasingly, looking at the broader requirement to apply risk-based thinking across QMS processes under Clause 4.1.2.
The conversation explores why companies already certified to ISO 13485 should not assume they are fully prepared for an FDA inspection, how FDA inspections may differ from notified-body audits, and why post-market information must feed back into risk management.
Naveen and Allyson also discuss the legal and contractual implications of the transition, particularly the importance of reviewing quality agreements and clearly defining responsibilities when activities are outsourced.
Finally, Allyson offers practical perspective on responding to FDA 483 observations and warning letters during a period when both regulators and industry are adapting to a new inspection framework.
Listen to the full 25-minute podcast or jump to a section of interest listed below.
Chapters
01:17 – Introduction and Allyson Mullen’s Regulatory and Legal Background02:17 – FDA’s First QMSR Warning Letter and Its Risk Management Findings03:46 – How FDA’s Language Around Risk Is Changing Under QMSR05:10 – Risk Beyond Design Control: ISO 13485 Clause 4.1.207:42 – When FDA May Look Beyond Product Realization12:48 – Why ISO 13485 Certification May Not Be EnoughLegal Risks and the Importance of Updating Quality AgreementsWhat to Do When FDA May Have Gotten an Observation WrongWarning Letters and the Challenges of the QMSR TransitionAllyson’s Journey from Regulatory Affairs to LawKey Takeaways: Risk, Outsourcing, and Quality Agreements
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
Deep Dive: First FDA Warning Letter Under QMSR
vendredi 7 août 2026 • Durée 20:36
Under QMSR, FDA is not only looking for individual quality failures. It is examining how failures connect across the entire quality system.
FDA’s warning letter to Linemaster Switch Corporation provides an early look at QMSR enforcement in practice. The cited deficiencies extend across risk management, rework, corrective action, environmental controls, calibration, and software validation.
The individual expectations are not entirely new. What has changed is the regulatory structure through which FDA evaluates them. By citing specific ISO 13485:2016 clauses, FDA can follow the connections between manufacturing risk, quality data, operational controls, and postmarket feedback rather than treating each deficiency as an isolated compliance issue.
The warning letter also demonstrates how a seemingly simple documentation gap—such as a blank root-cause field—may reveal a much broader failure of investigation, escalation, management oversight, and corrective action.
Key highlights covered in the audio:
* Why risk management must extend beyond the design file and into product realization
* FDA’s citation of a missing process FMEA under ISO 13485 Clause 7.1
* How undocumented rework exposed weaknesses in production control and reevaluation
* Why a blank root-cause field represented a failed corrective-action feedback loop
* How environmental conditions, calibration accuracy, and software validation became interconnected findings
* What earlier warning letters reveal about continuity between QSR and QMSR expectations
* Practical areas QA and RA leaders should reassess in legacy quality-system records
Keywords:
FDA QMSR warning letter, Linemaster Switch Corporation, ISO 13485 enforcement, FDA medical device inspections, QMSR risk management, process FMEA, medical device rework, corrective action, software validation, quality system regulation.
🎧Click Play above to listen to a examining what this warning letter may reveal about FDA’s evolving QMSR inspection approach.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
LTR 162: Using HHE for Risk-Based Decisions
vendredi 31 juillet 2026 • Durée 27:41
Summary
“When done well, HHE evolves from a procedural requirement into a strategic tool that reflects how your organization makes risk-based decisions.”
In this episode of the Let’s Talk Risk! conversation, host Naveen Agarwal speaks with Kerry Flecknoe, Senior Manager, Global Quality – HHE at Getinge, about the role of Health Hazard Evaluations in postmarket risk management.
Kerry explains that although organizations may use terms such as HHE, HHA, or HRA, the terminology is less important than having a structured and documented process for evaluating health risk. In the QMSR era, organizations must be able to demonstrate that risk-based decisions are made consistently and intentionally—not only within formal risk management activities, but across the quality management system.
The conversation explores how ISO 14971 can provide a defensible framework for HHEs, why field actions should themselves be evaluated as risk control measures, and how teams can make responsible decisions when complaint data, probability estimates, or other evidence are incomplete. Kerry also shares practical guidance for smaller manufacturers, cross-functional teams, and distributors of third-party products.
Listen to the full 25-minute podcast or jump to a section of interest listed below.
Chapters
00:00 – Introduction and Why HHE Matters in the QMSR Era01:24 – What HHE Is, FDA Terminology, and the Need for Documentation05:04 – Building an HHE Process Around ISO 1497106:18 – HHE as Postmarket Risk Management and Field Action as a Risk Control08:41 – Evaluating Probability When Postmarket Data Are Limited14:08 – Cross-Functional Roles and the Mechanics of an HHE16:49 – Feeding Postmarket Evidence Back into the Risk Management File18:42 – Building a Lean HHE Process and Defining Clear Triggers21:11 – Responsibilities of Legal Manufacturers and Distributors23:39 – Career Development and Final Takeaways
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
Deep Dive: FDA's RWE Guidance
vendredi 24 juillet 2026 • Durée 20:51
Real-world data does not become regulatory evidence simply because it is large, current, or readily available.
FDA’s December 2025 final guidance, Use of Real-World Evidence to Support Regulatory Decision-Making for Medical Devices, supersedes the 2017 guidance and provides a more detailed framework for determining when real-world data can generate evidence suitable for a medical device regulatory decision.
One important change is FDA’s recognition that a sponsor’s inability to obtain participant-level data does not automatically prevent the Agency from evaluating the evidence. But this flexibility does not lower the evidentiary bar. Sponsors must explain the limits of data access and demonstrate—through rigorous, traceable documentation—that the data and resulting analysis are credible.
Key highlights covered in the audio:
* The difference between real-world data and real-world evidence
* How FDA evaluates relevance, including data availability, timeliness, and generalizability
* How FDA evaluates reliability, including data provenance, completeness, consistency, quality controls, and traceability
* Why protocols and analysis plans should be established before reviewing outcomes
* How sponsors should address bias, confounding, missing data, and data-linkage methods
* New documentation recommendations for cover letters, study protocols, reports, and eSTAR submissions
* When studies using routinely collected data may—or may not—require an IDE
Keywords:
FDA real-world evidence guidance, real-world data for medical devices, real-world evidence regulatory strategy, RWE relevance and reliability, medical device regulatory submissions, post-market surveillance data, total product lifecycle.
🎧Click Play above to listen to a brief audio summary for a practical examination of FDA’s evolving expectations for real-world evidence.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
LTR 161: AI Governance by Design
vendredi 17 juillet 2026 • Durée 25:23
Summary
“Let’s treat AI governance by design as the connective tissue of a product lifecycle ecosystem.”
AI governance is often introduced as another layer of oversight—more procedures, approvals, documentation, and checklists. Ankita Mishra offers a different way to think about it: governance should be designed into the digital health product lifecycle from the beginning.
In this episode of the Let’s Talk Risk! conversation, host Naveen Agarwal and Ankita Mishra explore how systems thinking and risk-based decision-making can help organizations innovate responsibly without applying the same level of rigor to every product or use case. They discuss flexible quality systems, the importance of defensible rationale, third-party AI solutions, supplier dependencies, privacy and security, model performance, and the need to monitor AI after deployment.
The conversation also addresses what AI means for quality, regulatory, and risk professionals. Rather than making human expertise less relevant, Ankita argues that AI increases the need for critical thinking, judgment, collaboration, and continuous learning.
Listen to the full 25-minute podcast or jump to a section of interest listed below.
Chapters
00:00 – Introduction and Welcome01:04 – Ankita Mishra’s Career Journey04:36 – Reframing AI Governance by Design06:40 – Shifting Critical Thinking Upstream09:11 – Matching Development Rigor to Risk12:20 – Building Defensible Risk-Based Rationales14:17 – AI Governance Across the Product Lifecycle16:03 – Evaluating Third-Party AI and eQMS Solutions18:22 – Preparing Quality and Regulatory Professionals for AI23:00 – Closing Takeaways on Responsible AI
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
Podcasts Similaires Basées sur le Contenu
Découvrez des podcasts liées à Let's Talk Risk! Podcast. Explorez des podcasts avec des thèmes, sujets, et formats similaires. Ces similarités sont calculées grâce à des données tangibles, pas d'extrapolations !
When a new signal appears anywhere in your quality system, can it actually find its way back to the assumptions in your risk analysis?
Keywords:
QMSR, ISO 13485, ISO 14971, Risk Management, FDA Warning Letters, CAPA, Supplier Controls, Nonconforming Product, Design Changes, Lifecycle Risk Management
🎧 Listen to the Deep Dive for a closer look at what recent FDA QMSR warning letters reveal about the growing expectation to integrate risk management across the entire quality system.
Thanks for reading Let's Talk Risk!. If you liked this post, share with others.
Note:
The audio summary was prepared using Google NotebookLM, an AI-enabled research tool. Here are a few key resources used for this analysis:
* Patient acceptance: 90% reported similar or less pain than manual phlebotomy, while 82% preferred the robotic system or had no preference.
* A different workforce model: FDA-authorized use allows one trained phlebotomist to supervise up to three devices simultaneously.
Keywords:
FDA De Novo, Aletta, Vitestro, autonomous medical devices, robotic phlebotomy, artificial intelligence, medical robotics, risk management, clinical evidence, human oversight, diagnostic testing, automation
🎧Click Play above to listen to a brief audio summary about this groundbreaking technology.
Thanks for reading Let's Talk Risk!. If you liked this post, share with others.
Note:
The audio summary was prepared using Google NotebookLM, an AI-enabled research tool. Here are a few key resources used for this analysis:
* Giesen LFP, Roest JA, et al. (2026, April 14). Performance, Safety, and Patient Experience of an Autonomous Robotic Phlebotomy Device: A Multicenter Trial, Clinical Chemistry (hvag029), Oxford Academic
* Evidence-Based Medical Insight (2026, August 19). Clinical, Regulatory, and Operational Analysis of the Aletta Autonomous Robotic Phlebotomy System: A New Paradigm in Preanalytical Automation, Evidence-Based Medical Insight
* Risk is becoming more pervasive under QMSR. FDA now has clearer regulatory pathways for examining risk beyond traditional design-control activities.
* Clause 7.1 may only be the beginning. Product realization provides an obvious entry point, while ISO 13485 Clause 4.1.2 allows FDA to examine whether risk-based thinking is embedded throughout the QMS.
* Post-market feedback must close the loop. Complaints, adverse events, recalls, and other post-market information need a defined pathway back into risk management.
* ISO 13485 certification does not guarantee an easy FDA inspection. FDA may challenge the methods and reasoning behind risk-based decisions more deeply than organizations have experienced in traditional notified-body audits.
* Risk cannot simply be outsourced. Manufacturers remain responsible for understanding and managing risk even when product-realization activities are performed by suppliers or contract manufacturers.
* Review quality agreements now. Older agreements may assign responsibilities using the former QSR structure and may not adequately address obligations under ISO 13485 and QMSR.
* A 483 is not necessarily the final word. Companies should carefully evaluate FDA observations, provide missing context, correct the record where appropriate, and respond with a complete factual narrative.
* The transition creates challenges for both FDA and industry. Early warning letters and inspection observations will be important signals for understanding how FDA applies QMSR in practice.
Keywords
QMSR, FDA, ISO 13485, Risk Management, Quality Systems, FDA Inspections, Warning Letters, Quality Agreements, Post-Market Surveillance, Medical Devices
About Allyson Mullen
Allyson Mullenis a Director at Hyman, Phelps & McNamara, P.C., where her work brings together deep experience in FDA regulatory matters and law.
Before joining the firm, she served as a Corporate Attorney and Principal Regulatory Affairs Specialist at Waters Corporation, a Senior Regulatory Affairs Specialist at Boston Scientific, and a Regulatory Affairs Associate at DePuy Mitek.
She earned her J.D. from New England Law | Boston and began her career in regulatory affairs before transitioning into legal practice—giving her experience on both sides of regulatory and legal decision-making.
Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn.
Disclaimer
Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards.
* An HHE is a structured, risk-based assessment used to evaluate a known or potential issue affecting products in the market.
* Organizations do not have to use a particular name or standardized format. What matters is demonstrating a systematic and documented conclusion about health risk.
* ISO 14971 provides a strong framework for defining the problem, identifying hazards and hazardous situations, estimating and evaluating risk, and considering risk control options.
* A field correction, product removal, recall, or decision to leave a product in the market should be treated as a risk-based decision. The action itself may introduce additional risks, including product shortages or reduced access to alternative therapies.
* Complaint history alone may not provide an adequate probability estimate. Teams should also consider service records, bench testing, production data, inspection results, scrap, nonconformances, and the possibility of underreporting.
* When reliable probability data are unavailable, organizations may need conservative estimates, statistical models, cross-functional judgment, or greater emphasis on the potential severity of harm.
* Quality, R&D, Medical, Regulatory, Legal, and senior management should be involved early enough to provide appropriate expertise and oversight. Medical personnel should retain independence when making the clinical assessment.
* HHE severity and probability classifications should remain consistent with the organization’s risk management system and product-specific risk acceptability criteria.
* Postmarket evidence identified through an HHE should feed back into the Risk Management File so that assumptions, failure modes, controls, and benefit-risk conclusions remain aligned with actual device performance.
* Every HHE should end with a clear, documented decision for or against field action. Regulators need to understand how the organization reached its conclusion—not simply what it decided.
Keywords
AI governance, responsible AI, digital health, systems engineering, risk-based decision-making, quality management systems, third-party AI, model drift, regulatory compliance, critical thinking
About Kerry Flecknoe
Kerry Flecknoeis Senior Manager, Global Quality – HHE at Getinge, where she provides strategic leadership and end-to-end process ownership for the company’s enterprise-wide Health Hazard Evaluation program. Her work includes HHE governance, methods, digital tools, audit readiness, metrics, process improvement, and support of correction and removal decisions across Getinge's global network of medical device manufacturing sites.
Kerry is a quality and regulatory compliance leader and Board Certified Medical Affairs Specialist with more than 20 years of medical device experience spanning quality, medical affairs, clinical support, postmarket surveillance, risk management, and product development. Before her current role, she held senior medical affairs positions at Getinge and spent more than a decade supporting cardiac rhythm management products at Boston Scientific. She holds bachelor’s degrees in Biomedical Engineering and Electrical Engineering from Duke University.
Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn.
Disclaimer
Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards.
* AI governance should begin with the design decision—not after the technology has already been selected or deployed.
* Start with the intended use and the underlying problem. The first question is not simply how to use AI, but whether AI is necessary.
* The level of lifecycle rigor should reflect product risk, regulatory status, and the consequences of failure. Not every requirement needs to be applied identically to every solution.
* A flexible, risk-based quality system depends on clear reasoning. Organizations must be able to justify both why a requirement applies and why it may not apply.
* Responsible AI governance extends beyond the algorithm. It includes privacy, cybersecurity, infrastructure, suppliers, contracts, deployment, maintenance, performance monitoring, and drift.
* Organizations evaluating third-party AI tools should understand whether their data will be retained or used for training, what information may be disclosed, and what additional controls may be needed.
* A sandbox approach can reduce uncertainty: start with a controlled, lower-risk application, evaluate whether it produces meaningful value, and scale based on evidence.
* AI will change professional responsibilities, but it will not eliminate the need for experienced judgment. Critical thinking, systems thinking, collaboration, and organizational knowledge will become even more valuable.
* Lifelong learning is no longer limited to formal training. Professionals can learn by engaging with thought leaders, attending conferences, following emerging standards, sharing ideas publicly, and allowing others to challenge their thinking.
Keywords
AI governance, responsible AI, digital health, systems engineering, risk-based decision-making, quality management systems, third-party AI, model drift, regulatory compliance, critical thinking
About Ankita Mishra
Ankita Mishrais the Digital Health Quality Director at Evinova, where her work focuses on AI governance and responsible innovation in healthcare, digital health product strategy, lifecycle management, GCP compliance, global standards, and quality systems.
She brings more than 20 years of experience spanning software development, biomedical engineering, medical devices, systems engineering, and software quality. Her career has included roles at AstraZeneca, Senseonics, Medtronic, Terumo Cardiovascular Systems, Integra LifeSciences, and Infosys.
Ankita holds a master’s degree in public health from Johns Hopkins University, an MS in biomedical engineering from Drexel University, and a BE in electronics from Nagpur University. Her work centers on enabling innovation and regulatory rigor to advance together rather than treating them as competing objectives.
Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn.
Disclaimer
Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards.