Automated Regulatory Documentation Generation for IVDR and FDA Compliance
DOI:
https://doi.org/10.63282/3117-5481/AIJCST-V6I4P110Keywords:
Medical Device Software, IVDR, FDA, IEC 62304, Regulatory Documentation, Traceability, Software Life-cycle, Compliance Automation, Software Bill of Materials, Technical DocumentationAbstract
Medical device software development is subject to strict regulatory regimes that require copious documentation of safety, efficacy, traceability and risk control. During the software development lifecycle many interrelated documents are generated that are required for regulatory submissions under the European in Vitro Diagnostic Regulation (IVDR), the United States Food and Drug Administration (FDA) and software lifecycle standards such as IEC 62304. We present a framework for automated generation of regulatory documentation that translates structured software engineering artefacts into draft regulatory documents, via traceability graph construction, template-based document synthesis and consistency validation. The proposed architecture combines requirement repositories, software development plat-forms, continuous integration pipelines, and software composition analysis outputs to automatically assemble documentation in compliance with IVDR Annex II, Annex III, FDA eSTAR submissions, and related regulatory structures. Analytical evaluation demonstrates improvements in documentation consistency, lifecycle traceability, artifact synchronization, and regulatory preparedness while preserving mandatory human review before final submission. The framework establishes a foundation for future intelligent regulatory automation capable of supporting evolving international compliance requirements.
References
[1] European Parliament and Council, “Regulation (EU) 2017/746 on In Vitro Diagnostic Medical Devices (IVDR),” Official Journal of the European Union, 2017.
[2] International Electrotechnical Commission, IEC 62304: Medical Device Software—Software Life Cycle Processes, Geneva, Switzerland, 2006 (Amendment 1:2015).
[3] International Organization for Standardization, ISO 14971: Medical Devices—Application of Risk Management to Medical Devices, Geneva, Switzerland, 2019.
[4] U.S. Food and Drug Administration, 21 CFR Part 820—Quality System Regulation, Silver Spring, MD, USA.U.S. Food and Drug Administration, “Electronic Submission Template and Resource (eSTAR),” 2023.
[5] National Telecommunications and Information Administration, “The Minimum Elements for a Software Bill of Materials (SBOM),” 2021.
[6] OWASP Foundation, “CycloneDX Software Bill of Materials Specifica-tion,” Version 1.6, 2024.
[7] Linux Foundation, “Software Package Data Exchange (SPDX) Specifi-cation,” Version 3.0, 2024.
[8] Jama Software, “Requirements Traceability Best Practices for Regulated Industries,” White Paper, 2022.
[9] IBM Corporation, “IBM Engineering Requirements Management DOORS Next Documentation,” 2024.
[10] Siemens Digital Industries Software, “Polarion Application Lifecycle Management Documentation,” 2024.
[11] O. Gotel and A. Finkelstein, “An Analysis of the Requirements Trace-ability Problem,” Proceedings of the First International Conference on Requirements Engineering, Colorado Springs, CO, USA, pp. 94–101, 1994.
