AI needs a quality management system

Bob Bouthillier
Written by Bob Bouthillier

Quality Management Systems in medical device development have never been designed to govern technology itself—they exist to govern systems. Over more than three decades, the industry has successfully integrated successive waves of new technology: microprocessors, wireless connectivity, cloud computing, mobile applications, machine learning, and generative AI. Each innovation brought new capabilities alongside new risks, interactions, and validation challenges. The QMS role throughout has remained constant: ensuring the complete system behaves safely, predictably, and consistently across its lifecycle.

Artificial intelligence should be viewed through exactly the same lens. Yet current discourse treats AI as though it exists outside traditional engineering disciplines, focusing on model performance, hallucinations, prompt engineering, and regulation while neglecting a more fundamental question: where does AI belong within a validated system? The answer lies not in replacing traditional engineering with AI, but in deliberately combining deterministic engineering and artificial intelligence in architectures that leverage the distinct strengths of each.

Two projects that changed my perspective

Two personal projects reshaped a fundamental assumption about AI development: that improving outcomes requires improving the AI itself.

The first involved building a podcast AI assistant using Retrieval Augmented Generation (RAG), which indexed transcripts so a language model could retrieve relevant passages before generating answers. Early performance was strong, but as the transcript library grew, the assistant paradoxically became less reliable—not because the model degraded, but because the retrieval architecture struggled to surface relevant context at scale. The lesson: the focus had been misplaced on the AI component rather than the system surrounding it.

A second project made the point more sharply. A temp resource agency with roughly 150,000 résumés planned to run every résumé through a large language model for each new job posting. The approach would work technically but would cost approximately $2,400 per position—economically indefensible. Rather than seeking a cheaper model, the problem was reframed architecturally. A deterministic database search first filtered the full pool to fewer than 200 objectively qualified candidates. AI was then applied only to that shortlist, handling the nuanced work it excels at: comparing strengths, ranking candidates, and explaining recommendations. Cost dropped from $2,400 to roughly $3, while the system became faster, simpler, and easier to validate.

Neither outcome improved by selecting a better language model. Both improved by designing a better system. This distinction reframes where AI development effort should actually be directed—away from chasing model improvements and toward thoughtful system architecture.

From prompt engineering to systems engineering

Two formative experiences reshaped the approach to AI-enabled solutions, shifting the starting point from prompt engineering to systems engineering. Before selecting any model, the design process now begins with diagnostic questions: Which workflow portions are already deterministic? Which functions require identical outputs every time? Which business rules can be validated directly? Where does genuine uncertainty exist? Only after answering these questions is AI introduced.

The resulting architectures divide responsibility clearly. Deterministic software handles business rules, calculations, workflow orchestration, database operations, audit trails, regulatory controls, and data integrity. AI is reserved for tasks where deterministic software falls short: summarizing clinical reports, identifying patterns in unstructured data, classifying documents, generating draft content, and explaining complex technical concepts.

Notably, AI still contributes to building the deterministic components—accelerating development, generating code, improving documentation, and assisting with testing. Once reviewed and validated, those components become deterministic assets within the overall architecture. AI functions as an engineering partner rather than the system’s foundation.

This single architectural shift produces assistants and automation workflows that are more robust, more economical, easier to maintain, and significantly easier to validate, because much of their behavior is inherently repeatable.

Extending the quality management system

The central challenge in designing AI-enabled systems is not validating AI in isolation, but validating the complete architecture in which deterministic software and AI operate together. Traditional Quality Management Systems (QMS) already provide a strong foundation for this work, governing requirements, risk management, software development, verification, validation, configuration management, and continuous improvement. These principles remain fully relevant in the age of AI. What changes is the scope of what must be managed.

The proposed next evolution is AI Systems Quality Management (AISQM)—the application of established quality management principles to systems that intentionally combine deterministic software with artificial intelligence. AISQM does not replace the existing QMS; it extends it. Just as software engineering became a recognized discipline within medical device quality systems, AI-enabled architectures require additional engineering practices governing the unique components AI introduces. These include: AI model selection and version history, prompt template management, routing logic between deterministic and AI services, retrieval source configuration and version control, configuration history for AI-enabled workflows, validation evidence across both function types, operational performance monitoring, cost and resource utilization monitoring, and continuous improvement based on measured outcomes.

Critically, most of these are configuration management questions, not AI questions. For decades, engineers have tracked software versions, firmware revisions, hardware configurations, and verification evidence because understanding change is essential to understanding system behavior. Yet many AI implementations cannot answer equally fundamental questions: Which model produced this result? Which version? Which prompt template was active? Which retrieval source supplied the information? Which routing rules applied? When was the configuration last changed? Without this information, reproducing successful outcomes is difficult, and diagnosing degraded performance becomes even harder. Configuration management should not end where AI begins.

AISQM provides a framework for extending proven quality management disciplines into this new architectural landscape. Its goal is not to make AI deterministic—doing so would forfeit one of AI’s greatest strengths: reasoning through ambiguity, interpreting language, and generating insights beyond explicitly programmed logic. Instead, AISQM ensures AI is deployed within an architecture where its strengths complement deterministic engineering rather than replace it. Deterministic components continue to provide repeatability, traceability, and predictable execution, while AI contributes reasoning, interpretation, and adaptability where those capabilities genuinely add value.

The return of the systems engineer

Silicon Valley has branded the “Forward Deployed Engineer” as a novel, high-paying role, but viewed through the lens of regulated product development, the function is deeply familiar. The responsibilities—understanding customer workflows, integrating disparate technologies, managing legacy systems, defining validation strategies, building feedback mechanisms, and ensuring reliable AI performance in daily operations—describe application-level systems engineering. The title is new; the discipline is not.

Systems engineers have long been responsible for understanding how individual components interact to produce reliable system behavior. AI introduces another powerful component into that architecture, but the underlying engineering challenge remains the same. The organizations achieving the greatest success are not necessarily those with access to the most advanced models, but those that understand how to integrate those models into thoughtfully engineered systems.

Looking ahead

Artificial intelligence represents one of the most significant technological advances in medical device engineering in decades, already transforming engineering productivity, accelerating software development, improving documentation, and extracting insight from complex information. Yet AI does not change the fundamentals of engineering—it reinforces them. Reliable systems are still built by understanding requirements, assigning responsibilities to appropriate components, managing change, validating behavior, and improving performance based on objective evidence. AI simply expands the set of available components.

The organizations leading the next generation of medical innovation will not distinguish themselves by deploying the most AI, but by building the best architectures—ones where deterministic software provides repeatability, AI provides reasoning, configuration remains fully traceable, and quality systems govern the complete solution rather than individual parts.

The central question is no longer whether AI belongs in healthcare, but whether engineering disciplines will evolve quickly enough for AI to earn the same level of trust built into every other critical subsystem over decades. Extending today’s Quality Management Systems into AI Systems Quality Management is considered one of the most important steps toward achieving that goal.

Up next: MedTech World Asia 2026 | Hong Kong

As Asia Pacific continues to strengthen its position as a global MedTech powerhouse, the conversations defining the region’s healthcare ecosystem have never been more important. From market access and commercialization to investment, cross-border collaboration, digital health, and AI, these topics will take center stage at MedTech World Asia 2026, taking place 26–28 August at the Hong Kong Convention and Exhibition Centre (HKCEC).

Bringing together founders, investors, healthcare leaders, policymakers, and industry experts from across the region and beyond, the event provides a platform to explore the opportunities, challenges, and partnerships driving innovation across Asia Pacific.

Be part of the conversations driving MedTech across Asia Pacific and secure your place today.

Ways to participate in MedTech World Asia

MedTech World Hong Kong 2026