A Predetermined Change Control Plan is the FDA's answer to a structural problem with AI-enabled devices: they are built to be updated, but the traditional device framework would make many updates each trigger a new submission. The PCCP glossary entry covers what the mechanism is and where it came from. This page is the working view — what actually goes into a plan, the principles that shape it, and what the first authorized plans tell us about how the tool is being used. As of July 2026.
What a PCCP authorizes
A PCCP is documentation the FDA reviews inside a device's marketing submission so that pre-specified updates can ship without a separate submission each time. The final guidance states the point directly: the plan lets a manufacturer implement the described modifications "without necessitating additional marketing submissions for implementing each modification described in the PCCP" 1. The final guidance was originally issued December 4, 2024, and the edition on the FDA's site is dated August 18, 2025 12. The mechanism's statutory footing traces to the Food and Drug Omnibus Reform Act of 2022, as the glossary entry sets out.
The critical word is bounded. A PCCP grants flexibility inside a fence the manufacturer draws and the FDA approves — the flexibility to make the changes in the plan, and no others.
The three sections, turned into what you write
The guidance recommends three sections, reviewed together 1:
| PCCP section | What it does | What the manufacturer actually writes |
|---|---|---|
| Description of Modifications | Names the specific planned changes | The exact modifications — e.g., periodic retraining on new data, a logic update, or adding a compatible input source |
| Modification Protocol | Shows how each change is developed, validated, and implemented safely | Verification and validation activities with pre-defined acceptance criteria, plus a step-by-step account of implementation |
| Impact Assessment | Weighs the benefits and risks of the changes | An analysis of the benefits and risks of each modification and its mitigations, individually and in combination |
The Modification Protocol is where most of the engineering rigor lives. The guidance describes it as including "the verification and validation activities (including pre-defined acceptance criteria) for those modifications" and providing "a step-by-step delineation of how the modifications included in the PCCP will be implemented while ensuring the device remains safe and effective" 1. In practice, this is the difference between "we may retrain the model" and "we will retrain on data meeting these inclusion rules, validate against these metrics at these thresholds, and roll back if the thresholds are missed." The acceptance criteria are the safety rail: they are set in advance, so a change either clears the pre-agreed bar or it does not ship.
A worked example
Consider the most common case, a periodic-retraining plan. The Description of Modifications names it: the model will be retrained quarterly on newly collected data from the same clinical settings, with no change to inputs, outputs, or intended use. The Modification Protocol then makes it auditable — it specifies the data-inclusion and quality rules, the held-out test set, the performance metrics and the exact acceptance thresholds each retrained version must meet, the human review step, and the rollback procedure if a version misses. The Impact Assessment reasons about what could go wrong: could retraining on a shifted population degrade performance for a subgroup, and what mitigations catch that before release? Written this way, a single reviewed plan can cover a year of updates — which is the entire point — while every update remains inside the fence the FDA approved 1.
The five guiding principles
Before the final US guidance, the FDA, Health Canada, and the UK's MHRA jointly set out five guiding principles for PCCPs, drawing on the Good Machine Learning Practice principle that deployed models are monitored and retraining risks managed 3. They read as design constraints for anyone drafting a plan:
| Guiding principle | What it asks of a plan |
|---|---|
| Focused and Bounded | Describe specific, limited changes — the plan is a fence, with no open-ended latitude |
| Risk-based | Match the depth of validation to the risk each change introduces |
| Evidence-Based | Justify the plan with evidence generated across the total product lifecycle |
| Transparent | Communicate the plan clearly to users, patients, and reviewers |
| Total Product Lifecycle (TPLC) perspective | Plan pre-market for the changes and monitoring that follow post-market |
These principles are why a credible PCCP is narrow and specific. A plan that asks for broad latitude fails the first principle; a plan without pre-set acceptance criteria fails the third.
The approach did not appear overnight. The idea traces back to a 2019 FDA discussion paper on modifications to AI/ML-based software, which drew substantial feedback and evolved into the current three-section structure of Description of Modifications, Modification Protocol, and Impact Assessment 1. The international alignment came next: the joint principles let a manufacturer design one plan against a shared logic recognised by the FDA, Health Canada, and the MHRA, rather than three divergent national expectations 3. For a global development pipeline funneling toward multiple regulators, that shared vocabulary is part of what makes the mechanism usable at all.
What the first authorized plans look like
The theory meets reality in the plans the FDA has actually authorized. A cross-sectional analysis identified "26 AI/ML-enabled medical devices with authorized PCCPs" cleared or approved before May 30, 2025, of which "92% were cleared via the 510(k) pathway, and all were classified as moderate risk" 4. The authorized changes were modest and concentrated:
| Authorized modification | Share of the 26 devices |
|---|---|
| Model retraining | 69% |
| Logic updates | 42% |
| Expansion of input sources | 35% |
The analysis found the plans "most commonly allowing model retraining (69% of devices), logic updates (42% of devices), and expansion of input sources (35% of devices)" 4. Their character is telling: the devices "were primarily intended for use in diagnosis or clinical assessment," six carried consumer-facing components, and thirteen underwent human-factors testing 4. All were moderate-risk 510(k) clearances rather than higher-risk approvals — the tool has so far been used where the FDA is most comfortable letting it run, which is worth remembering before assuming a PCCP signals a heavily scrutinised device.
This matters for how you read the word "flexibility": the authorized plans so far cover controlled, batched changes such as periodic retraining, rather than a model that rewrites itself continuously in the field. That discipline is deliberate — unmanaged updates are how a device slides into model drift.
Where the evidence is thin
The same analysis is candid about the gaps, and this is the part a buyer should read closely. Preapproval testing was limited: "seven devices prospectively evaluated and thirteen undergoing human factors testing." On fairness, "subgroup analyses were reported for eleven devices and none included patient outcomes data." On what happens after clearance, "no postmarket studies or recalls were identified," and "user manuals could be identified online for 54% of devices, though many lacked performance details or mentioned PCCPs" 4. The authors' conclusion is worth quoting: FDA authorization of PCCPs "grants manufacturers substantial flexibility to modify AI/ML-enabled devices postmarket, while preapproval testing and postmarket transparency are limited" 4.
The reading is not that PCCPs are unsound — it is that the plan on paper is only as good as the monitoring behind it, and the public evidence that monitoring is happening has been sparse.
A due-diligence checklist for health systems
Because much of the assurance lives in documents and monitoring rather than in a one-time clearance, a deploying health system carries real responsibility. Before relying on a "PCCP-enabled" device, work through this:
- Read the Description of Modifications. It tells you precisely what the vendor is permitted to change without re-review. If you cannot obtain it, you cannot know what you are buying a year from now.
- Ask for the acceptance criteria. The Modification Protocol's thresholds are the safety rail; ask what they are and what triggers a rollback 1.
- Ask for subgroup and outcome evidence. Given that subgroup analyses appeared for only eleven of the first authorized devices and none reported patient outcomes 4, ask specifically whether the device was evaluated on patients resembling yours.
- Confirm the intended use is unchanged. A change to intended use falls outside any PCCP and requires a new submission; make sure an update has not quietly moved the device beyond what you validated.
- Plan local monitoring. The plan presumes surveillance. Building your own algorithmovigilance around the device is how you catch a post-update regression the vendor's summary would not show you.
The boundaries of a plan
Three boundaries keep a PCCP honest.
First, it bounds change; it does not open it up. A PCCP authorizes only the modifications written into it and validated against its protocol. Anything outside the plan — above all a change to the device's intended use — still requires a new marketing submission 1.
Second, it presumes monitoring. The acceptance criteria mean something only if the manufacturer and the deploying system actually watch real-world performance. A plan is a promise about how change will be governed, rather than a substitute for governing it.
Third, it sits inside a larger framework. The PCCP is the change-control piece of the FDA's wider lifecycle approach to AI devices, which describes the PCCP as the way to "prospectively specify and seek premarket authorization for intended modifications to an AI-DSF ... without needing to submit additional marketing submissions" 5. Read the two together: one covers the device you validate today, the other the changes you pre-authorize for tomorrow.
How to read this — and a compliance note
The counts here are dated and will move as more plans are authorized; we revisit this page every ninety days. The figures on the first authorized plans come from a single cross-sectional analysis and describe an early, small cohort 4 — informative about direction, limited as a base rate. And this is orientation, not regulatory or legal advice: whether a PCCP is appropriate for a given device, and what a specific plan permits, are determinations for regulatory affairs and counsel. Confirm any device's authorized plan, acceptance criteria, and current status with the manufacturer and your compliance team before relying on them.
Sources and method
The three sections, the Modification Protocol's acceptance-criteria language, and the "without necessitating additional marketing submissions" purpose come directly from the FDA's final PCCP guidance 1, with its edition dates confirmed on the FDA guidance page 2 and its Federal Register availability notice 6. The five guiding principles are drawn from the joint FDA–Health Canada–MHRA document 3. The figures on the first authorized plans — counts, modification types, and the limits on preapproval and post-market evidence — come from a cross-sectional analysis of the FDA's public list 4. The relationship to the wider framework is quoted from the FDA's draft lifecycle guidance 5. For the definition and origin story, see the PCCP glossary entry; for how many devices carry a plan, see the FDA AI-enabled device list tracker and the tracker of FDA-cleared AI devices by year and specialty. We update this page every ninety days and whenever the guidance or the evidence base changes.