Life Sciences AI Governance
FDA Computer Software Assurance (CSA) Guidance for AI Tools
CSA replaces validate-everything habits with a question: if this software feature fails, could safety foreseeably be compromised? Kriv AI helps device manufacturers apply that question to AI-enabled production and quality tools and keep a record an auditor can follow.
The FDA's Computer Software Assurance guidance, issued in final form on February 3, 2026, asks device manufacturers to validate production and quality system software by risk. AI and machine learning tools are in scope. Rigor follows whether a failure could foreseeably compromise safety. Kriv AI's governance work starts at $200 per hour.
context
What the FDA CSA Guidance Covers
The FDA's guidance Computer Software Assurance for Production and Quality Management System Software (docket FDA-2022-D-0795) was issued on February 3, 2026 by CDRH and CBER. It supersedes the version issued on September 24, 2025. It gives recommendations on computer software assurance for computers and automated data processing systems used as part of medical device production or the quality management system.
Scope: production and quality system software, not the device
The guidance applies to software used as part of device production or the quality management system. It does not address design and development verification or validation for device software functions, meaning software that is itself a device. Cloud computing used in production or the quality system is in scope, including SaaS, PaaS, and IaaS models, while cloud used as part of a device software function is not.
The guidance defines computer software assurance as a risk-based approach for establishing and maintaining confidence that software is fit for its intended use. It describes this as a least-burdensome approach, where the burden of validation is no more than necessary to address the risk. It is nonbinding: it describes the FDA's current thinking, and an alternative approach is allowed if it satisfies the applicable statutes and regulations.
Where it sits in the regulation
The guidance notes that the FDA's final rule amending 21 CFR Part 820 took effect on February 2, 2026, and incorporates ISO 13485:2016 by reference. The software validation obligations the guidance addresses come from subclauses 4.1.6, 7.5.6, and 7.6 of ISO 13485. The guidance also supplements the FDA's General Principles of Software Validation and supersedes Section 6 of that document.
ai gap
How CSA Applies to AI and Machine Learning Tools
The guidance states that its approach can be applied to, but is not limited to, automation tools such as bots or automatic workflows, data analytic tools, artificial intelligence and machine learning tools, and cloud computing when used as part of production or the quality management system. It does not publish AI-specific test methods, so the work is applying its general risk framework to each AI feature.
The framework starts with intended use, examined at the level of individual features, functions, and operations. Software used directly in production or the quality system, or used to support it, must be validated. General business tools such as email or accounting software, and infrastructure not specific to production or the quality system, generally fall outside. The FDA recommends documenting how you decided whether a feature is in or out.
The next step is the process risk call. A feature is high process risk when its failure may result in a quality problem that foreseeably compromises safety. The guidance lists examples that are generally high process risk, including features that measure, inspect, analyze, or determine acceptability of product or process with limited or no additional human awareness or review, and features that adjust process parameters from automated feedback without human review. For an AI model this makes the human-review question central: the same classifier is a different risk depending on whether a qualified person checks its output before it matters.
Features that generally are not high process risk include CAPA routing, automated complaint logging and tracking, automated change control, and alerts when an exception occurs in an established process. The guidance presents risk in a binary way, high or not high, but allows a manufacturer to rate risk as moderate or low for choosing activities. High process risk work is assured in proportion to medical device risk. Everything else is assured in proportion to process risk.
capabilities
Assurance Activities and Records
Choosing assurance activities
For high process risk features the guidance says manufacturers may choose more rigor, such as scripted testing or a hybrid of scripted and unscripted testing. For features that are not high process risk it points to unscripted methods: scenario testing, error guessing, and exploratory testing. It also says these are not exclusive, and that unscripted testing may suit a high process risk feature while automated scripted tests may suit a lower risk one.
Leveraging vendors and existing controls
The guidance lets manufacturers reduce effort by using purchasing controls, vendor evaluation, vendor validation work, process controls that would catch a failure, and data the software collects to monitor itself after deployment. Vendor evaluation can include reviewing Service Organization Controls reports, certifications, development and cybersecurity practices, and data integrity controls such as audit trails and access controls. For lower risk supporting software, vendor evaluation plus installation and configuration may be all the assurance needed.
The record
The recommended record includes the intended use, the result of the risk-based analysis, a description of testing, issues found, a conclusion on acceptability for the intended use, who tested and when, and review and approval where appropriate. The FDA recommends using digital records such as system logs and audit trails instead of screenshots or duplicated paper where possible, while considering accuracy, reliability, integrity, availability, and authenticity.
differentiation
How This Differs From Our Other Life Sciences Pages
This page covers the FDA's device-side CSA guidance for production and quality system software. Our 21 CFR Part 11 and GxP validation page and our page on why AI validation fails under Part 11 cover electronic records and drug-side validation. Our page on the FDA's draft AI credibility framework covers AI models that support regulatory decisions about drugs. CSA sits alongside those and does not replace them.
engagement
How an Engagement Works
A scoped engagement usually starts with an inventory of AI-enabled and automated tools used in production or the quality system. We then document intended use per feature, make the high process risk call with your quality team, match assurance activities to each risk level, and set up the record. We work alongside your quality, regulatory, and IT teams. We do not provide legal advice or certify compliance.
tiers
What You Get at Each Tier
1. Enterprise / regulated (device makers, pharma, biotech)
Intended use and process risk documentation for AI-enabled production and quality tools, assurance plans, vendor evaluation templates, and records designed for quality review.
2. Fractional CTO / AI governance lead
Ongoing oversight of AI tool changes, re-assessment when features change, and audit preparation as your tool portfolio grows.
3. Specialized advisory
A single session or second opinion on a risk determination or assurance plan you have already drafted.
rate card
Kriv AI's Rates for This Work
These are Kriv AI's own published rate floors, not an industry average.
| Track | Kriv hourly rate | Typical engagement model | Minimum engagement |
|---|---|---|---|
| Enterprise / regulated (banks, broker-dealers, payment processors) | From $200/hr | Fixed-scope project or retainer | $8,000 |
| Fractional CTO / AI governance lead | $300 to $400/hr | Part-time, ongoing (monthly) | $8,000 |
| Specialized advisory (vendor evaluation, second opinion) | $400 to $700/hr | Hourly, per-session | Varies by engagement |
| Small business | $150/hr | Referred to Kriv AI's partner network | n/a |
get a quote
How to Get a Real Quote
The rates above are floors, not a quote. Actual price depends on how many AI-enabled production or quality tools are in scope, how much validation evidence already exists, and your quality system maturity. Book a discovery call and we will scope it honestly.
Straight answers
Frequently asked questions about FDA Computer Software Assurance (CSA) Guidance for AI Tools
What is FDA Computer Software Assurance?
It is the FDA's risk-based approach for establishing confidence that software used in medical device production or the quality management system is fit for its intended use, with effort scaled to risk.
Does CSA apply to AI and machine learning tools?
Yes. The guidance says its approach can be applied to automation tools, data analytic tools, AI and machine learning tools, and cloud computing when used as part of production or the quality management system.
Is the CSA guidance final?
Yes. The FDA issued it in final form on February 3, 2026, superseding the version issued September 24, 2025. It is still nonbinding guidance.
What makes a software feature high process risk?
Its failure may result in a quality problem that foreseeably compromises safety, for example a feature that determines product acceptability with limited or no additional human review.
Does CSA cover software that is itself a medical device?
No. It does not address design and development validation for device software functions. It covers software used in production or the quality management system.
What does this cost with Kriv AI?
Kriv AI's rates start at a $200/hr floor for enterprise and regulated life sciences work, with an $8,000 minimum engagement. Specialized advisory runs $400 to $700/hr.
Talk to the team that would do the work
Bring your requirements to a working session with the person who'll actually deliver.
Book a Discovery Call