Frameworks / GMLP
Good Machine Learning Practice for Medical Device Development
FDA / Health Canada / MHRA · US-UK-CA · effective 2021-10-27 · GMLP
Ten guiding principles for AI/ML in medical devices: representative datasets, performance on the intended population, and monitoring of deployed models.
10 controls, mapped to the evidence that satisfies each
Every control links to the dimension whose evidence would satisfy it. That mapping is the working link between an obligation written in law or a standard and a document somebody has to produce. Each row has its own address: link to a single control.
| Control | Title | Requirement | Satisfied by |
|---|---|---|---|
| GMLP-9 | Clear, essential information for users | Users have ready access to the device's intended use, subgroup performance, training/test data characteristics, known limitations and how to report concerns. | D1 |
| GMLP-4 | Training data independent of test data | Training and test data sets are selected and maintained to be independent of one another, addressing patient, acquisition and site sources of dependence. | D2 |
| GMLP-5 | Reference data sets based on best available methods | Reference standards used in development and testing are built with accepted, best-available methods, with the reference's limitations understood. | D2 |
| GMLP-8 | Testing under clinically relevant conditions | Statistically sound test plans generate performance evidence independent of the training data, covering the intended population, subgroups and clinical use conditions. | D2 |
| GMLP-2 | Good software engineering and security practices | Model design follows sound software engineering, data quality assurance, data management and cybersecurity practices, with decisions and rationale documented. | D3 |
| GMLP-6 | Model design tailored to the data and intended use | Model design is suited to the available data, mitigates known risks such as overfitting and performance degradation, and supports the device's intended use. | D3 |
| GMLP-7 | Focus on the performance of the human-AI team | Where a human is in the loop, human factors and interpretability of outputs are addressed with emphasis on the combined human-AI team's performance, not the model in isolation. | D3 |
| GMLP-3 | Representative clinical study participants and data sets | Clinical study participants and training/test data sufficiently represent the intended patient population's relevant characteristics, so results generalize and bias can be managed. | D4 |
| GMLP-1 | Multi-disciplinary expertise throughout the life cycle | Clinical, statistical, engineering and human-factors expertise is applied across the device's whole life cycle, not only at initial design. | D6 |
| GMLP-10 | Monitoring and management of re-training risk | Deployed models are monitored for real-world performance, and where periodic or continual re-training occurs, controls manage overfitting, unintended bias and drift. | D6 |
What this mapping is, and what it is not
It is a reading of a published instrument, with each control cited to its source, mapped to the kind of evidence that would satisfy it. It is not legal advice, not a certification, and not a statement that any organisation complies with anything. Where an instrument is not yet in force, this page says so rather than selling urgency.
Talk to the person who built this
If you assess clients against this instrument, the mapping is the part you can check line by line. There is no sales team: this is founder-led, so it reaches the founder directly. Tenant access is $500 a month, and free early access to the method, the corpus and the router is on offer first if that is useful. If it is not a fit, saying so costs you one reply.