Skip to content

Level 3 · In depth — Arts. 15 and 14, and the MDR crosswalk

§4 — Article 15, deep: a real, blocking gate — with honest limits

Section titled “§4 — Article 15, deep: a real, blocking gate — with honest limits”

Level 2 met Articles 9–13 lightly. The overlay is where an article goes deep, and Level 3’s first deep article is Art. 15 (accuracy, robustness, cybersecurity) — surfaced by the DR-sensitivity gate.

This control is the genuine article: objective (a measured recall_score, not a self-declaration), blocking (enforcement: block — a RED exits non-zero and the residual is not confirmed), and backed by a real power analysis (cluster-bootstrap by patient, so correlated eyes from one patient don’t inflate the sample). V1 RED (0.4165) → V2 clean GREEN (0.8847, CI low 0.8516) is a real risk treated and re-evaluated. That is Art. 15 working as intended.

But honesty means stating the limits out loud, not hiding them behind the green:

  • Specificity is not measured. The gate is sensitivity (recall) only. Whether the screener also avoids over-referring healthy eyes (specificity / TNR) is not gated — the demo SDK has no specificity metric, so its absence is declared, not faked.
  • PPV is audit-only. Positive predictive value (the over-referral counterpart of recall) is measured, but it does not gate. V2 maximises recall by design, so its PPV is modest — disclosed explicitly, not gated to look good.
  • One fold, one seed. The evidence is a single 20% fold, seed = 42. No cross-validation, no multiple seeds.
  • Mono-population. The cohort is ODIR-5K — a single-country (Chinese) cohort. There is no external, temporal, or EU-population validation, and the 0.80 bar is a clinical reference, not a regulator-blessed threshold.

§5 — Article 14, deep: organizational human oversight, not objective-required

Section titled “§5 — Article 14, deep: organizational human oversight, not objective-required”

The overlay’s second deep article is Art. 14 (human oversight) — and it is deep in a different way from Art. 15. Where Art. 15 is an objective, measured, blocking gate, Art. 14 here is organizational and declared, and — importantly — that is legitimate, not a cop-out.

The risk is risk.insufficient-human-oversight: the screener must not become a final diagnosis. The treatment is a set of organizational measures, declared ex ante in the manifest (evaluation: manual, enforcement: audit):

  • HITL (human-in-the-loop). The ophthalmologist confirms or revokes every referral the screener proposes; the clinician can override the model.
  • Clinician review. A named reviewing role is assigned to each referral decision.
  • Automation-bias training. Clinicians are trained to avoid over-trusting the automated output.

These are not measured gates — they are declared, audit-only commitments that surface in the Annex IV dossier rather than blocking the pipeline. And that is the honest, correct treatment for Art. 14, for a specific reason.


§6 — The MDR crosswalk and the notified-body GAP (the payoff)

Section titled “§6 — The MDR crosswalk and the notified-body GAP (the payoff)”

Now the overlay pays off — and so does the honesty. The system declared eu/mdr@2017, so the engine maps its risks and measured controls onto the MDR’s GSPR clauses (Annex I) and signs that mapping. In the committed bundle you can see it directly: the means_of_conformance block lists eu/mdr@2017 with its GSPR clauses — eu/mdr@2017#gspr-17.1 (SaMD performance/repeatability, cited by the sensitivity control), eu/mdr@2017#gspr-9 (consistent performance across the population, cited by the fairness controls), eu/mdr@2017#mdr.gspr-8-residual-risk. The control plane renders this into the full MDR document — a GSPR checklist + post-market plan + SOUP inventory — assembled from the signed bundle.

But read what that document is — and is not:

And the crosswalk is honest about its own holes — these are the GAPs a notified body would open:

  • No notified body. A Class IIa device needs an accredited, independent notified body (MDR Art. 52; AI Act Art. 31 on independence). The demo’s signer is Dev Demofictional, and the manufacturer’s own key, not an independent third party. Self-signing is self-declaration, which Class IIa may not use.
  • No clinical evaluation. The MDR (Annex XIV) requires a clinical evaluation — a benefit-risk determination that the device is clinically safe and effective. That is a clinical-scientific judgement outside the engine. A passing sensitivity gate ≠ clinical benefit-risk.
  • GSPR clauses left as gaps. Several MDR clauses (cybersecurity/adversarial robustness, full clinical performance) the crosswalk honestly marks as gap, not “covered”. (The notified-body evidence audit in docs/security/2026-06-12-notified-body-evidence-audit.md enumerates these from an auditor’s lens.)

That is why beat 4 paused at “requested”: the GAP is not a paragraph in a report, it is the unclosable state of the lifecycle. The engine takes the manufacturer all the way to the notified body’s door — governed, measured, documented, signed — and then honestly stops.