SAMD
When software has a medical purpose, it's a medical device. In Great Britain that means the UK Medical Devices Regulations 2002 (as amended), overseen by the MHRA, with UKCA marking (CE marking still recognised under transitional arrangements) - plus the DTAC standard if you're deploying into the NHS.
At Taylored Consultancy Ltd, we make software compliance clear and stress-free. From qualification and classification to your software lifecycle and clinical evidence, we help you meet UK requirements and keep pace with the MHRA's evolving software and AI framework.
Clearing the path to market -
regulatory and quality expertise that gets your software safe, compliant, and ready for market.

Is your software a medical device, and if so, what class? We assess intended purpose against UK rules and the IMDRF SaMD framework to confirm your regulatory status.
We help you put a compliant software development lifecycle in place, with the documentation auditors expect.
We help you compile clinical evidence demonstrating your software's safety and performance.
We build your risk management file, including software-specific and (where relevant) AI/ML risks.
We help you evidence usability and human-factors work to show your software is safe to use.
Deploying into the NHS? We help you meet the Digital Technology Assessment Criteria covering clinical safety, data protection, usability and interoperability.
For AI-enabled software, we help you address change management, bias and good machine learning practice - and explore routes like the MHRA AI Airlock.
Non-UK manufacturers need a UK Responsible Person and MHRA registration. We act as your RP and handle registration.
We help you implement a QMS to ISO 13485, the backbone of software medical device compliance.
Regulations can feel like a headache, but they don't have to be. We make sure you're covered, compliant, and ready to sell - without unnecessary delays or legal pitfalls.
EN 62304 / IEC 62304 - Medical device software lifecycle
IEC 82304-1 - Health software products
IEC 62366-1 - Usability / human factors engineering
ISO 14971 - Risk management for medical devices
ISO 13485 - Medical devices QMS
ISO/IEC 42001 - AI management systems
ISO 9001 - General quality management
If your software has a medical purpose, meaning diagnosing, treating, monitoring or managing a condition, it likely qualifies as a medical device under the UK Medical Devices Regulations 2002 (as amended), regardless of whether it's an app, a clinical algorithm or NHS-facing software. The determining factor is intended purpose, not delivery format. We help founders pin this down early, since getting qualification wrong is the biggest cause of delayed launches.
CE marking is still recognised in Great Britain under transitional arrangements, but UKCA marking is the UK's own conformity assessment route and will eventually become mandatory. Most software companies selling into the UK plan for UKCA now rather than treating it as a future problem, since the transitional window won't last indefinitely and MHRA continues to tighten expectations around UK-specific evidence.
DTAC (Digital Technology Assessment Criteria) is the NHS's baseline standard covering clinical safety, data protection, technical security, interoperability and usability. You need it to be considered for NHS procurement and deployment, and it sits alongside, not instead of, your MHRA medical device registration if your software qualifies as a device. Many clients underestimate how much technical documentation DTAC actually demands.
It's MHRA's ongoing work to update UK medical device regulation specifically for software and AI, covering qualification, classification and cybersecurity guidance tailored to how modern digital health products actually behave. It signals that UK regulation is evolving faster for software than for traditional hardware devices, so staying current with MHRA guidance matters more here than in many other product categories.
A UK Responsible Person is a UK-based organisation acting on behalf of an overseas manufacturer to handle registration, technical documentation and regulatory correspondence with MHRA, required if you don't have a UK legal presence. It's a formal legal role, not just an admin function, so the appointee needs genuine regulatory competence. We act as UK Responsible Person for software clients so this doesn't become a bottleneck to launch.
AI-driven clinical decision support is regulated as a medical device if it's intended to inform diagnosis, treatment or care decisions, and MHRA applies the same qualification and classification logic as for any SaMD, plus extra scrutiny on algorithm transparency, bias and change management. ISO/IEC 42001 for AI management systems is increasingly useful evidence to have in place alongside your technical file.
It's usually a straightforward administrative handover rather than a regulatory hurdle. Your new UK Responsible Person takes on your existing MHRA registration and technical documentation, confirms nothing about the software has changed, and updates the RP details attached to your registration. We manage that transition directly with your outgoing provider, so there's no gap in your compliance cover while the switch takes place.
A UK Responsible Person is legally accountable for your software's compliance in Great Britain, which covers holding and maintaining technical documentation, registering the product with the MHRA, handling vigilance reporting for any incidents, and acting as the point of contact for the MHRA if a question arises. It's an ongoing legal responsibility for as long as the software is on the market, not a one-off registration task.
Yes, we review software and app marketing against the UK Advertising Standards Authority's CAP Code, covering claims wording and the evidence you'd need to defend an ad if it were challenged. This sits alongside, not instead of, your wider regulatory claims obligations, so we review both together rather than treating advertising as a separate compliance track.
Still have questions? Contact us and we'll be happy to help.