Practical guidance · Reviewed 14 September 2026

FDA Predetermined Change Control Plan (PCCP)

Practical guide for AI-enabled device software functions

  • Optional mechanism
  • Specific authorized changes
  • Evidence before implementation

FDA’s current final PCCP guidance was issued on August 18, 2025. It addresses AI-enabled devices, including the device constituent part of applicable device-led combination products, reviewed through 510(k), De Novo and PMA pathways. A PCCP is optional and must be authorized as part of the device’s marketing submission before it can support the described changes.

FDA final guidance · August 2025

The examples illustrate practitioner reasoning. They are fictional and do not represent regulatory authorizations, approved risk assessments, or executed validation evidence. Apply the source to the specific product, process and jurisdiction.

36 topics · Jump to a section

1. What is a PCCP?

A Predetermined Change Control Plan, or PCCP, is a plan included in a device marketing submission that describes certain future modifications the manufacturer intends to make to an AI-enabled device software function.

FDA reviews the PCCP as part of the marketing submission.

If FDA authorizes the PCCP, modifications that remain within the authorized PCCP can be implemented according to that plan without requiring a new marketing submission for each individual modification, provided the change is implemented consistently with the authorized PCCP and applicable requirements.

The controlled sequence is:

  1. Submit the current AI-enabled device software function (AI-DSF) and proposed PCCP in the marketing submission.
  2. FDA reviews the device and the PCCP; any authorization defines the permitted modification boundaries.
  3. Confirm that a later modification falls within the authorized PCCP.
  4. Follow the authorized Modification Protocol, verify and validate, and confirm acceptance criteria.
  5. Assess the impact, authorize release under the applicable quality system, implement and monitor.

A PCCP is therefore not permission to change the AI model however the manufacturer wants.

It establishes controlled boundaries for specific anticipated modifications.

Source context: FDA final PCCP guidance.

2. Why does FDA allow PCCPs?

AI-enabled devices can require changes over time.

Examples include:

  • model retraining
  • performance improvement
  • changes addressing specific populations
  • changes to inputs
  • algorithm modifications
  • certain performance-related modifications

Traditional device-change regulation can require manufacturers to evaluate whether a new submission is needed after a modification.

PCCPs provide a mechanism for FDA to review certain anticipated changes before those changes are implemented.

FDA describes the objective as supporting iterative improvement while maintaining reasonable assurance of safety and effectiveness.

Source context: FDA final PCCP guidance.

3. A PCCP is optional

A manufacturer is not required to have a PCCP simply because the device uses AI.

A manufacturer may continue to manage modifications through normal design control, risk management, change assessment, and applicable premarket submission requirements.

A PCCP becomes useful when:

  1. future AI-DSF modifications can reasonably be anticipated;
  2. the modifications can be clearly bounded;
  3. the manufacturer can define how those modifications will be developed and validated;
  4. FDA can evaluate the safety and effectiveness implications in advance.

FDA’s PCCP webinar materials explicitly describe PCCPs as an optional mechanism.

Source context: FDA final-guidance webinar transcript.

4. The Three Main Parts of a PCCP

FDA’s guidance organizes the PCCP around three elements.

QuestionPCCP elementWhat it establishes
What will change?Description of ModificationsThe specific anticipated modifications and their boundaries.
How will it be controlled?Modification ProtocolDevelopment, verification, validation, acceptance, implementation and monitoring methods.
Why is it acceptable?Impact AssessmentThe effects of the modifications and the safety and effectiveness rationale.

Primary reference: FDA PCCP guidance, Sections VI–VIII.

5. Description of Modifications

This section defines the boundaries of the future changes.

The description should be specific enough that FDA can understand what the manufacturer intends to modify.

Avoid vague statements such as:

The model may be improved over time.

or:

Future algorithm enhancements may be implemented.

Those statements do not establish useful boundaries.

Source context: FDA final PCCP guidance.

6. Better Modification Description

Suppose an AI-enabled imaging device identifies suspected lesions.

A better modification description could define that future changes may:

  • retrain the existing model using additional representative images;
  • improve sensitivity for defined lesion categories;
  • improve performance for specified demographic subgroups;
  • adjust model parameters using the approved training process;
  • maintain the same intended use;
  • maintain the same input imaging modality;
  • maintain the same clinical output.

Now the proposed change space is more understandable.

7. Focused and Bounded

FDA, Health Canada and MHRA identify Focused and Bounded as a foundational PCCP principle.

The planned modifications should be specific and remain within the intended use or intended purpose of the original device.

Think of the PCCP as a controlled boundary:

Potentially inside the authorized PCCP, if specifically covered:

Defined model retraining.

Defined performance improvement.

Defined data expansion.

Defined acceptance criteria.

Same intended use.

Outside the PCCP when not authorized:

New disease indication.

New patient population outside the authorized scope.

New clinical purpose.

New input modality not covered.

Major architecture change outside the defined protocol.

A change outside the PCCP must go through the normal regulatory change-assessment process.

Source context: FDA, Health Canada and MHRA guiding principles.

8. Example: Modification Within the PCCP

Authorized device

AI software assists radiologists in detecting pulmonary nodules on chest CT.

PCCP permits

Retraining the existing model with additional representative chest CT images to improve sensitivity while maintaining specified performance requirements.

Later change

Manufacturer adds additional representative chest CT data and retrains the model according to the authorized protocol.

Potentially:

Within PCCP

assuming all authorized conditions are met.

9. Example: Modification Outside the PCCP

Same product.

Manufacturer now wants the software to:

diagnose pulmonary embolism.

That changes the clinical function.

It is not simply performance improvement of pulmonary-nodule detection.

This would not become acceptable merely because the device already has a PCCP.

The manufacturer needs the applicable regulatory assessment.

10. Modification Protocol

The Modification Protocol is where the manufacturer explains how the planned modification will be controlled.

This is the operational core of the PCCP.

The protocol should address the methods used to:

develop

evaluate

verify

validate

implement

and where applicable:

monitor

the modification.

FDA’s final guidance describes the PCCP as including the methodology used to develop, validate, and implement the planned modifications.

Source context: FDA final PCCP guidance.

11. Data Management

For AI-enabled devices, the data used to modify the model is critical.

The Modification Protocol should establish appropriate controls around data.

Questions include:

Where will data come from?

Clinical sites?

Historical datasets?

Prospective data?

Real-world data?

Who is represented?

Age groups?

Sex?

Race/ethnicity where relevant?

Disease severity?

Clinical sites?

Device types?

Is the data appropriate for intended use?

How will data quality be assessed?

How will duplicates be identified?

How will missing data be handled?

How will labels or reference standards be established?

How will training, tuning and test datasets remain appropriately separated?

Source context: FDA final PCCP guidance.

12. Example: Dataset Expansion

Device:

AI diabetic-retinopathy screening software.

Planned modification:

Improve performance across additional clinical sites.

Modification Protocol defines:

Data source

Images from predefined clinical environments.

Data quality

Image-quality acceptance criteria.

Reference standard

Qualified specialist adjudication.

Dataset separation

Training dataset independent from final evaluation dataset.

Subgroup evaluation

Performance evaluated across relevant demographic and clinical groups.

This is much stronger than:

We will retrain using more data.

13. Retraining Method

The PCCP should make the modification process predictable enough to evaluate.

Depending on the device, this could include:

  • retraining methodology
  • preprocessing
  • feature handling
  • model architecture constraints
  • hyperparameter process
  • optimization approach
  • training stopping criteria
  • version control
  • reproducibility controls

The level of detail should be appropriate to the modification and risk.

Source context: FDA final PCCP guidance.

14. Performance Evaluation

Before implementing a modification, the manufacturer needs evidence that the modified device continues to meet appropriate performance requirements.

Possible measures include:

  • sensitivity
  • specificity
  • positive predictive value
  • negative predictive value
  • AUROC
  • false-positive rate
  • false-negative rate
  • calibration
  • agreement
  • error rate
  • clinical-performance measures

The correct metrics depend on the intended use.

Do not choose a metric merely because it produces the highest number.

Source context: FDA final PCCP guidance.

15. Overall Accuracy Can Be Misleading

Consider an AI system evaluating 10,000 cases.

9,900 are normal.

100 contain an important abnormality.

The model correctly classifies all normal cases but detects only 40 abnormal cases.

Overall accuracy:

99.4%

That sounds excellent.

But sensitivity for the important abnormality is:

40%

The device misses:

60 of 100 abnormal cases.

The model misses most abnormal cases. If the clinically justified sensitivity criterion exceeds 40%, this version fails that criterion despite its high overall accuracy. Acceptability depends on the intended use and prespecified clinical criteria.

The PCCP should therefore define performance measures appropriate to the clinical risk.

16. Acceptance Criteria

The PCCP should define how the manufacturer determines whether a proposed modification is acceptable.

Example:

Sensitivity

Must remain ≥ defined threshold.

Specificity

Must remain ≥ defined threshold.

Critical subgroup

Performance must remain within predefined acceptance criteria.

Calibration

Must remain within defined limits.

Safety-related failure

Must not exceed predefined rate.

The actual thresholds should be scientifically and clinically justified.

FDA’s international PCCP principles emphasize scientifically and clinically justified methods and metrics proportionate to risk.

Source context: FDA final PCCP guidance.

17. Verification and Validation

Do not limit verification to:

model-performance testing.

A modification may affect the complete device.

Consider:

software functionality

model performance

user interface

interfaces

data handling

cybersecurity

human factors

clinical workflow

risk controls

labeling

interoperability

depending on the modification.

Source context: FDA final PCCP guidance.

18. Example: AI Output Change

Suppose the existing product displays:

High Risk

or:

Low Risk

A planned modification adds:

Intermediate Risk.

This may affect more than the model.

Assess:

  • model performance
  • user-interface presentation
  • clinician interpretation
  • downstream workflow
  • labeling
  • risk controls
  • human factors
  • training

The PCCP should consider the device, not only the algorithm.

19. Impact Assessment

The third major PCCP element is the Impact Assessment.

The question is:

What is the impact of implementing the planned modifications, individually and collectively?

This connects the modification to:

  • intended use
  • device performance
  • risk management
  • benefit-risk
  • user interaction
  • labeling
  • clinical workflow
  • other device functions

Source context: FDA final PCCP guidance.

20. Individual and Cumulative Changes

Suppose a PCCP allows three modifications:

Modification 1

Improve sensitivity.

Modification 2

Expand training data.

Modification 3

Adjust model calibration.

Each change may be acceptable individually.

But what happens after:

Modification 1 + Modification 2 + Modification 3?

The cumulative device may differ more substantially from the originally authorized configuration.

FDA’s international guiding principles specifically emphasize evaluating individual and cumulative changes throughout the total product lifecycle.

Source context: FDA, Health Canada and MHRA guiding principles.

21. Risk Management

Risk management should be integrated throughout the PCCP.

Do not create:

PCCP risk assessment

as an isolated document disconnected from the device risk-management file.

For each planned modification ask:

What new failure can occur?

Can an existing failure become more likely?

Can severity change?

Can a risk control be affected?

Can performance vary for a subgroup?

Can user behavior change?

Can cybersecurity risk change?

Source context: FDA final PCCP guidance.

22. Example Risk Chain

Modification

Retrain model using additional clinical data.

Failure

Retrained model performs worse for a defined patient subgroup.

Hazardous situation

Clinician receives an inaccurate recommendation for patients in that subgroup.

Potential harm

Delayed or inappropriate clinical management.

Controls

Representative training data.

Independent test dataset.

Subgroup performance criteria.

Clinical evaluation.

Post-implementation monitoring.

Evidence

Dataset characterization.

Performance results.

Subgroup analysis.

Risk-management update.

Release decision.

23. Implementation Controls

A PCCP should describe how an acceptable modification reaches production.

A useful implementation process is:

Proposed modification → Confirm within authorized PCCP → Develop modification → Verify / validate → Evaluate acceptance criteria → Update risk management → Impact Assessment → Quality review / release approval → Deploy → Monitor

Training completion alone does not justify deployment. Manual and automatic implementation both need to follow the authorized protocol and its acceptance, release, and monitoring controls.

24. Stop Criteria

This is an important practical control.

Define circumstances where the modification must not be implemented.

Examples:

  • sensitivity below acceptance criterion
  • unacceptable subgroup degradation
  • critical new failure
  • unacceptable cybersecurity issue
  • failed software regression
  • unresolved critical anomaly
  • data quality below requirement
  • modification outside PCCP boundary

Decision:

Stop. Do not deploy.

25. Rollback

FDA’s international PCCP principles specifically recognize mechanisms to detect and revert or stop implementation when changes fail specified performance criteria.

The manufacturer should determine where rollback is appropriate.

Example:

New model version:

3.8

is deployed.

Monitoring identifies unexpected degradation.

Controlled rollback:

3.8 → 3.7

The process should address:

  • decision authority
  • configuration control
  • patient/device impact
  • data compatibility
  • user communication
  • investigation
  • corrective action

Source context: FDA, Health Canada and MHRA guiding principles.

26. Transparency

Users may need to understand that the device changes over time.

Transparency considerations may include:

  • device version
  • modification implemented
  • performance characteristics
  • known limitations
  • intended population
  • update information
  • user actions
  • monitoring information

FDA, Health Canada and MHRA identify Transparency as one of the five PCCP guiding principles.

Source context: FDA, Health Canada and MHRA guiding principles.

27. Labeling

Assess whether implementation of a PCCP modification requires labeling updates.

Possible areas:

performance

supported population

warnings

limitations

software version

clinical interpretation

user instructions

technical requirements

The PCCP should explain how labeling impact will be assessed.

Source context: FDA final PCCP guidance.

28. Total Product Lifecycle

PCCP control does not stop when the modified model is released.

The device continues through the Total Product Lifecycle.

Relevant activities can include:

  • complaint monitoring
  • performance monitoring
  • adverse-event information
  • cybersecurity monitoring
  • software-problem reporting
  • model-performance trends
  • subgroup performance
  • user feedback
  • CAPA
  • risk-management updates

The international PCCP principles explicitly frame PCCPs using a TPLC perspective.

Source context: FDA, Health Canada and MHRA guiding principles.

29. Post-Implementation Monitoring

Suppose a modified model passes pre-release validation.

That does not necessarily mean performance will remain identical in actual use.

Potential changes include:

population

clinical practice

input-device characteristics

data distribution

workflow

environment

Therefore monitoring should be linked to intended use and risk.

30. Example Monitoring Dashboard

For an AI diagnostic-support device:

MeasurePredefined expectationMonitoring
Sensitivity≥ defined criterionMonthly
Specificity≥ defined criterionMonthly
Critical missesBelow defined thresholdContinuous/periodic
Subgroup performanceWithin approved criteriaQuarterly
Software incidentsNo unresolved critical trendContinuous
ComplaintsTrend reviewedMonthly

This is an illustrative monitoring schedule, not an FDA-mandated cadence. Actual timing, denominators, ground-truth availability, alert thresholds and response responsibilities should follow device risk and approved procedures.

31. Change Inside or Outside the PCCP?

Every proposed modification should begin with this question.

Step 1

Is this modification specifically described or bounded by the authorized PCCP?

If No:

→ normal regulatory change assessment.

If Yes: → Step 2

Can the authorized Modification Protocol be followed?

If No:

→ outside PCCP / further regulatory assessment.

If Yes: → Step 3

Does the modification meet predefined acceptance criteria?

If No:

→ do not implement.

If Yes: → Step 4

Does the Impact Assessment remain acceptable?

If No:

→ do not implement / regulatory assessment.

If Yes: → Step 5

Quality release and controlled implementation.

Source context: FDA final PCCP guidance.

32. PCCP and Automatic Learning: Authorized Boundaries Still Apply

A PCCP does not give a deployed model unrestricted permission to retrain and replace itself whenever new data become available.

FDA’s final guidance allows a Description of Modifications to identify manual or automatic implementation. For automatic updates, FDA recommends describing the controls and guardrails defining the update range and discussing the approach through the Q-Submission Program.

Whether an update is manual or automatic, it must remain within the authorized PCCP and follow its development, validation, acceptance, implementation and monitoring controls. Training completion is not a release criterion by itself.

Primary reference: FDA PCCP guidance, Section VI.B.

33. PCCP and Design Controls

The PCCP does not replace design and development controls.

A modification still needs appropriate:

  • requirements
  • design
  • risk management
  • verification
  • validation
  • configuration management
  • problem resolution
  • release control
  • documentation

The PCCP changes the regulatory pathway for certain anticipated modifications, not the expectation for controlled product development.

Current U.S. quality-system context: QMSR became effective on February 2, 2026. Apply the current Part 820 framework and its incorporated ISO 13485:2016 requirements where applicable; a PCCP does not replace them. FDA QMSR information.

34. PCCP and IEC 62304

For an AI-enabled medical-device software function:

PCCP

Defines the authorized future modification space.

IEC 62304

Controls the software lifecycle used to implement the modification.

Example:

PCCP permits:

retraining using additional representative data.

IEC 62304 lifecycle controls still address:

requirements

architecture impact

implementation

software verification

configuration

problem resolution

maintenance.

Apply the relevant edition and regulatory context. IEC 62304 official scope and CSVtoCSA software lifecycle guide.

35. PCCP and ISO 14971

ISO 14971 supports the risk-management process.

For each PCCP modification:

Modification → Potential failure → Hazard / hazardous situation → Harm → Risk controls → Verification → Residual risk → Benefit-risk where applicable

The risk-management file should remain current as authorized modifications are implemented.

ISO 14971 official source and CSVtoCSA device risk-management guide.

36. PCCP and IEC 82304-1

For standalone health software:

IEC 82304-1 can provide the product-level framework for:

  • use requirements
  • system requirements
  • product validation
  • product identification
  • accompanying information
  • maintenance
  • revalidation
  • post-market activities.

A PCCP modification should be assessed for impact on these product-level elements.

IEC 82304-1 official scope. Applicability to the product and jurisdiction should be assessed separately; a PCCP does not itself mandate a standard.