The CER Problem No One Is Talking About
Clinical Evaluation Reports are one of the most demanding documents in the EU MDR compliance process. A thorough CER for a complex medical device can run hundreds of pages — covering clinical background, state of the art, clinical data appraisal, post-market clinical follow-up planning, and benefit-risk analysis. The amount of work that goes into a well-constructed CER is enormous.
And yet — for AI-enabled medical devices — even the most thorough CER is almost always missing something critical.
Not the clinical evidence section. Not the equivalence analysis. Not the PMCF plan. Those are well understood and well documented.
What most CERs are missing is independent third-party evidence that the AI component of the device meets applicable AI-specific regulatory requirements — specifically EU AI Act Articles 9, 10, and 14, ISO 42001:2023 Clauses 6.1, 8.4, and 9.1, and NIST AI RMF functions GOVERN, MAP, MEASURE, and MANAGE.
This is not a theoretical gap. It is a gap that Notified Bodies are beginning to ask about — and that manufacturers are consistently unprepared to answer.
A CER documents the clinical evidence for a medical device. For AI-enabled devices, the AI component introduces risks and requirements that clinical evidence alone does not address — and that EU MDR's existing technical documentation requirements were not designed to capture. The EU AI Act fills this gap — but only if manufacturers have built the AI compliance evidence package to support it.
What Notified Bodies Are Now Asking About AI
Notified Bodies began asking about ISO 42001 in MDR audits before most manufacturers had heard of it. The same pattern is now emerging with the EU AI Act — Notified Bodies are asking about AI governance evidence ahead of the formal 2027 deadline.
The questions showing up in audit findings and deficiency letters include:
- Where is the AI-specific risk assessment — separate from the ISO 14971 file — covering hallucination, model drift, demographic bias, and SOUP dependency?
- What independent evidence do you have that the AI component's performance has been validated against defined objectives — not just internally tested?
- How are you monitoring the AI component post-deployment? What are your drift thresholds, who is accountable, and what triggers revalidation?
- How does the AI component's training data composition address demographic representation — specifically age, sex, race, and geography as required by EU AI Act Article 10?
- What human oversight mechanisms are in place for the AI component's outputs — as required by EU AI Act Article 14?
These questions cannot be answered by pointing to your ISO 14971 risk management file or your IEC 62304 software lifecycle documentation. They require a separate AI compliance evidence package — and most manufacturers do not have one.
If your technical documentation for an AI-enabled device does not include AI-specific risk assessment, independent performance validation evidence, and post-deployment monitoring documentation — your next Notified Body audit is at risk of generating deficiency findings specifically on AI governance. These findings can delay or block CE marking renewal.
The Three AI Compliance Gaps Most CERs Miss
Based on the evaluations and assessments ClearanceAI has conducted, three AI compliance gaps appear in almost every CER for an AI-enabled medical device.
The Framework Evidence a CER Needs for AI
A complete AI compliance evidence package for inclusion in or alongside a CER should map to the following named requirements. This is not an exhaustive list — the applicable frameworks depend on the device's regulatory jurisdiction and risk classification — but these are the requirements most likely to be examined in a Notified Body audit for an EU MDR device with an AI component.
| Framework | Clause / Article | What the Evidence Must Show |
|---|---|---|
| EU AI Act | Article 9 | AI-specific risk management system covering the full AI lifecycle — separate from ISO 14971 |
| EU AI Act | Article 10 | Training data governance — demographic composition documented, bias examination conducted |
| EU AI Act | Article 14 | Human oversight mechanisms — defined procedures for human review and override of AI outputs |
| ISO 42001:2023 | Clause 6.1 | AI risk assessment — systematic identification of AI-specific hazards including hallucination, drift, bias, SOUP |
| ISO 42001:2023 | Clause 8.4 | AI system performance evaluation — documented testing against named performance objectives with evidence |
| ISO 42001:2023 | Clause 9.1 | Post-deployment monitoring — defined metrics, drift thresholds, revalidation triggers, accountability |
| NIST AI RMF | MEASURE 2.5 | Bias testing — subgroup performance evaluation across demographic groups with documented results |
| ISO 14971:2019 | § 4.4 | AI-specific hazard identification — hallucination, drift, and demographic bias as named hazards |
| IEC 62304:2006 | § 8.1 | SOUP identification — third-party AI components documented as Software of Unknown Provenance |
Every one of these requirements generates a specific documentation obligation. The question for manufacturers preparing a CER for an AI-enabled device is not whether these requirements apply — they do — but whether the evidence package exists and whether it is independent enough to satisfy a Notified Body auditor who has no reason to take the manufacturer's word for it.
Why Internal Evidence Is Not Enough
This is the question that comes up most often in conversations with regulatory affairs professionals who are preparing CERs for AI-enabled devices: "We have all of this documentation internally — our risk assessment, our validation data, our monitoring plan. Why isn't that sufficient?"
The answer is the same answer that has governed financial reporting for over a century. Internal documentation is necessary. It is not sufficient for third-party reliance.
When a Notified Body auditor reviews a CER for an AI-enabled device, they are evaluating evidence produced by the same organization that built the AI and has a financial interest in its approval. The auditor has no way to verify — from the documentation alone — whether the AI risk assessment identified the right hazards, whether the performance validation was conducted rigorously, or whether the monitoring program is actually operational rather than planned.
Independent third-party evaluation changes this. An independent assessment conducted by a credentialed external evaluator — with no financial relationship with the manufacturer and no stake in the outcome — produces evidence that a Notified Body can rely on without taking the manufacturer's word for it.
This is exactly what ClearanceAI provides. Our Layer 2 independent assessment evaluates the AI component against the named requirements in the table above, produces a formal 9-section compliance report with credentialed expert reviewer sign-off, and delivers a SHA-256 anchored Assessment Statement that can be included in or referenced from the CER technical documentation package.
A ClearanceAI Layer 2 Assessment Report is not a replacement for the CER. It is the independent AI compliance evidence layer that the CER references — the third-party documentation that answers the Notified Body's AI governance questions with evidence rather than assertions.
How to Close the Gap Before Your Next Audit
If you are preparing a CER for an AI-enabled medical device — or updating an existing CER ahead of a renewal audit — here is the specific sequence of steps to close the AI compliance evidence gap.
Step 1 — Conduct an AI-specific risk assessment
Separate from your ISO 14971 risk management file, produce a documented AI risk assessment that specifically addresses hallucination, model drift, demographic bias, adversarial input handling, and SOUP dependency for your AI component. This satisfies EU AI Act Article 9 and ISO 42001 Clause 6.1. If this document does not exist in your technical documentation, it is the first deficiency finding a Notified Body will raise.
Step 2 — Document training data composition
EU AI Act Article 10 requires data governance documentation covering the demographic composition of your training dataset — specifically age, sex, race, and geography. If your training data composition has never been formally documented and a bias examination has never been conducted, this needs to happen before your next audit. The absence of this documentation is a specific and growing audit finding for AI-enabled devices.
Step 3 — Get independent performance validation
Your internal validation data is necessary but not sufficient. Engage an independent third-party evaluator to assess your AI component's performance against defined objectives and produce a formal report with expert reviewer sign-off. This satisfies ISO 42001 Clause 8.4 and provides the independent evidence that answers the Notified Body's question about third-party validation.
Step 4 — Stand up your post-deployment monitoring program
A PMCF plan and an AI post-deployment monitoring program are different things. Your AI monitoring program needs defined performance metrics, specific numerical drift thresholds with documented clinical justification, revalidation triggers, named accountability, and evidence that the program is operational — not planned. This satisfies ISO 42001 Clause 9.1 and EU AI Act Article 9.
Step 5 — Define human oversight mechanisms
EU AI Act Article 14 requires documented human oversight mechanisms for high-risk AI systems — defined procedures for how clinicians or operators review, override, or reject AI outputs. If your device's intended use describes it as decision-support with mandatory clinician review, that mandatory review needs to be documented as a formal oversight mechanism — not just stated in the intended use description.
Step 6 — Reference independent evidence in the CER
Once the independent AI compliance assessment is complete, reference the Assessment Report in the appropriate section of your CER — typically within the risk management section and the post-market surveillance planning section. The ClearanceAI Assessment Statement provides a SHA-256 anchored, timestamped independent evaluation record that becomes a permanent part of your technical documentation.
None of these steps are impossible. None require rebuilding your technical documentation from scratch. But all of them require deliberate action — and the December 2027 deadline is closer than it appears when you account for the time required to conduct an AI risk assessment, compile training data documentation, engage an independent evaluator, and stand up a monitoring program.
The manufacturers who start this work now will walk into their next Notified Body audit with an AI compliance evidence package that answers every question before it is asked. The manufacturers who wait will be scrambling to produce documentation under audit pressure — which is exactly the wrong time to discover that your CER has a gap.
Where Does Your AI Stand Against EU AI Act Requirements?
Our free 5-minute assessment gives you an instant clause-by-clause gap analysis across EU AI Act Articles 9, 10, and 14 — ISO 42001 Clauses 6.1, 8.4, and 9.1 — and all other applicable frameworks. No signup required.
Take Free Assessment → View Sample Report