Find partners
Let's Talk Risk! Podcast

Let's Talk Risk! Podcast

Hosted by Where MedTech professionals gain clarity and confidence to navigate complex decisions.

TechnologyEducationInterviews guests

Episodes

178

Latest episode

Aug 2026

Language

EN

About the show

Let’s Talk Risk! brings together MedTech leaders and practitioners for thoughtful conversations on the challenges that shape risk, quality, innovation, and leadership. With 150+ episodes and more than 30K downloads, it helps professionals gain the clarity and confidence to lead through complex decisions. naveenagarwalphd.substack.com

Listen to episodes

60 recent
August 14, 202627 min

LTR 163: FDA’s New Risk Lens Under QMSR

Summary “I don't think it's as easy to outsource risk as it used to be. Risk is pervasive now.” In this episode of the Let’s Talk Risk! conversation , host Naveen Agarwal speaks with Allyson Mullen , Director at Hyman, Phelps & McNamara, P.C., about what FDA’s early enforcement activity under the Quality Management System Regulation (QMSR) may tell medical device manufacturers about the agency’s evolving expectations. Using the first warning letter discussed in the episode as a starting point, Allyson examines how FDA is citing risk management under ISO 13485 Clause 7.1 and, increasingly, looking at the broader requirement to apply risk-based thinking across QMS processes under Clause 4.1.2. The conversation explores why companies already certified to ISO 13485 should not assume they are fully prepared for an FDA inspection, how FDA inspections may differ from notified-body audits, and why post-market information must feed back into risk management. Naveen and Allyson also discuss the legal and contractual implications of the transition, particularly the importance of reviewing quality agreements and clearly defining responsibilities when activities are outsourced. Finally, Allyson offers practical perspective on responding to FDA 483 observations and warning letters during a period when both regulators and industry are adapting to a new inspection framework. Listen to the full 25-minute podcast or jump to a section of interest listed below. Chapters 01:17 – Introduction and Allyson Mullen’s Regulatory and Legal Backgroun d 02:17 – FDA’s First QMSR Warning Letter and Its Risk Management Findings 03:46 – How FDA’s Language Around Risk Is Changing Under QMSR 05:10 – Risk Beyond Design Control: ISO 13485 Clause 4.1.2 07:42 – When FDA May Look Beyond Product Realization 12:48 – Why ISO 13485 Certification May Not Be Enough 14:59 – Legal Risks and the Importance of Updating Quality Agreements 17:19 – What to Do When FDA May Have Gotten an Observation Wrong 21:21 – Warning Letters and the Challenges of the QMSR Transition 23:40 – Allyson’s Journey from Regulatory Affairs to Law 26:10 – Key Takeaways: Risk, Outsourcing, and Quality Agreements If you enjoyed this podcast, consider subscribing to the Let’s Talk Risk! newsletter . Suggested links: FDA Law Blog: FDA’s First QMSR Warning Letters . LTR Deep Dive: First FDA Warning Letter Under QMSR . LTR: LTR Risk Coach - AI-Powered Decision Support Tool . Key Takeaways * Risk is becoming more pervasive under QMSR. FDA now has clearer regulatory pathways for examining risk beyond traditional design-control activities. * Clause 7.1 may only be the beginning. Product realization provides an obvious entry point, while ISO 13485 Clause 4.1.2 allows FDA to examine whether risk-based thinking is embedded throughout the QMS. * Post-market feedback must close the loop. Complaints, adverse events, recalls, and other post-market information need a defined pathway back into risk management. * ISO 13485 certification does not guarantee an easy FDA inspection. FDA may challenge the methods and reasoning behind risk-based decisions more deeply than organizations have experienced in traditional notified-body audits. * Risk cannot simply be outsourced. Manufacturers remain responsible for understanding and managing risk even when product-realization activities are performed by suppliers or contract manufacturers. * Review quality agreements now. Older agreements may assign responsibilities using the former QSR structure and may not adequately address obligations under ISO 13485 and QMSR. * A 483 is not necessarily the final word. Companies should carefully evaluate FDA observations, provide missing context, correct the record where appropriate, and respond with a complete factual narrative. * The transition creates challenges for both FDA and industry. Early warning letters and inspection observations will be important signals for understanding how FDA applies QMSR in practice. Keywords QMSR, FDA, ISO 13485, Risk Management, Quality Systems, FDA Inspections, Warning Letters, Quality Agreements, Post-Market Surveillance, Medical Devices About Allyson Mullen Allyson Mullen is a Director at Hyman, Phelps & McNamara, P.C. , where her work brings together deep experience in FDA regulatory matters and law. Before joining the firm, she served as a Corporate Attorney and Principal Regulatory Affairs Specialist at Waters Corporation, a Senior Regulatory Affairs Specialist at Boston Scientific, and a Regulatory Affairs Associate at DePuy Mitek. She earned her J.D. from New England Law | Boston and began her career in regulatory affairs before transitioning into legal practice—giving her experience on both sides of regulatory and legal decision-making. Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn. Disclaimer Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations. Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

August 7, 202620 min

Deep Dive: First FDA Warning Letter Under QMSR

Under QMSR, FDA is not only looking for individual quality failures. It is examining how failures connect across the entire quality system. FDA’s warning letter to Linemaster Switch Corporation provides an early look at QMSR enforcement in practice. The cited deficiencies extend across risk management, rework, corrective action, environmental controls, calibration, and software validation. The individual expectations are not entirely new. What has changed is the regulatory structure through which FDA evaluates them. By citing specific ISO 13485:2016 clauses, FDA can follow the connections between manufacturing risk, quality data, operational controls, and postmarket feedback rather than treating each deficiency as an isolated compliance issue. The warning letter also demonstrates how a seemingly simple documentation gap—such as a blank root-cause field—may reveal a much broader failure of investigation, escalation, management oversight, and corrective action. Key highlights covered in the audio: * Why risk management must extend beyond the design file and into product realization * FDA’s citation of a missing process FMEA under ISO 13485 Clause 7.1 * How undocumented rework exposed weaknesses in production control and reevaluation * Why a blank root-cause field represented a failed corrective-action feedback loop * How environmental conditions, calibration accuracy, and software validation became interconnected findings * What earlier warning letters reveal about continuity between QSR and QMSR expectations * Practical areas QA and RA leaders should reassess in legacy quality-system records Keywords: FDA QMSR warning letter, Linemaster Switch Corporation, ISO 13485 enforcement, FDA medical device inspections, QMSR risk management, process FMEA, medical device rework, corrective action, software validation, quality system regulation. 🎧Click Play above to listen to a brief audio summary examining what this warning letter may reveal about FDA’s evolving QMSR inspection approach. Thanks for reading Let's Talk Risk! . If you liked this post, share with others. Note: The audio summary was prepared using Google NotebookLM, an AI-enabled research tool. Here are a few key resources used for this analysis: * FDA (2026, May 27). Linemaster Switch Corporation, Warning Letter (CMS 730215), FDA * FDA (2025, November 11). Envoy Medical Inc., Warning Letter (CMS 718762), FDA * FDA (2026, April 30). ZOLL Medical Corporation, Warning Letter (CMS 711320), FDA. * FDA (2026, February 26). Longhorn Vaccines and Diagnostics LLC, Warning Letter (CMS 721702), FDA. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

July 31, 202627 min

LTR 162: Using HHE for Risk-Based Decisions

Summary “When done well, HHE evolves from a procedural requirement into a strategic tool that reflects how your organization makes risk-based decisions.” In this episode of the Let’s Talk Risk! conversation , host Naveen Agarwal speaks with Kerry Flecknoe, Senior Manager, Global Quality – HHE at Getinge, about the role of Health Hazard Evaluations in postmarket risk management. Kerry explains that although organizations may use terms such as HHE, HHA, or HRA, the terminology is less important than having a structured and documented process for evaluating health risk. In the QMSR era, organizations must be able to demonstrate that risk-based decisions are made consistently and intentionally—not only within formal risk management activities, but across the quality management system. The conversation explores how ISO 14971 can provide a defensible framework for HHEs, why field actions should themselves be evaluated as risk control measures, and how teams can make responsible decisions when complaint data, probability estimates, or other evidence are incomplete. Kerry also shares practical guidance for smaller manufacturers, cross-functional teams, and distributors of third-party products. Listen to the full 25-minute podcast or jump to a section of interest listed below. Chapters 00:00 – Introduction and Why HHE Matters in the QMSR Era 01:24 – What HHE Is, FDA Terminology, and the Need for Documentation 05:04 – Building an HHE Process Around ISO 14971 06:18 – HHE as Postmarket Risk Management and Field Action as a Risk Control 08:41 – Evaluating Probability When Postmarket Data Are Limited 14:08 – Cross-Functional Roles and the Mechanics of an HHE 16:49 – Feeding Postmarket Evidence Back into the Risk Management File 18:42 – Building a Lean HHE Process and Defining Clear Triggers 21:11 – Responsibilities of Legal Manufacturers and Distributors 23:39 – Career Development and Final Takeaways If you enjoyed this podcast, consider subscribing to the Let’s Talk Risk! newsletter . Suggested links: LTR: Risk-Based Assurance, FDA Expectations Under QMSR . LTR: The Missing Step in Risk Decisions . LTR: TR Risk Coach - AI-Powered Decision Support Tool . Key Takeaways * An HHE is a structured, risk-based assessment used to evaluate a known or potential issue affecting products in the market. * Organizations do not have to use a particular name or standardized format. What matters is demonstrating a systematic and documented conclusion about health risk. * ISO 14971 provides a strong framework for defining the problem, identifying hazards and hazardous situations, estimating and evaluating risk, and considering risk control options. * A field correction, product removal, recall, or decision to leave a product in the market should be treated as a risk-based decision. The action itself may introduce additional risks, including product shortages or reduced access to alternative therapies. * Complaint history alone may not provide an adequate probability estimate. Teams should also consider service records, bench testing, production data, inspection results, scrap, nonconformances, and the possibility of underreporting. * When reliable probability data are unavailable, organizations may need conservative estimates, statistical models, cross-functional judgment, or greater emphasis on the potential severity of harm. * Quality, R&D, Medical, Regulatory, Legal, and senior management should be involved early enough to provide appropriate expertise and oversight. Medical personnel should retain independence when making the clinical assessment. * HHE severity and probability classifications should remain consistent with the organization’s risk management system and product-specific risk acceptability criteria. * Postmarket evidence identified through an HHE should feed back into the Risk Management File so that assumptions, failure modes, controls, and benefit-risk conclusions remain aligned with actual device performance. * Every HHE should end with a clear, documented decision for or against field action. Regulators need to understand how the organization reached its conclusion—not simply what it decided. Keywords AI governance, responsible AI, digital health, systems engineering, risk-based decision-making, quality management systems, third-party AI, model drift, regulatory compliance, critical thinking About Kerry Flecknoe Kerry Flecknoe is Senior Manager, Global Quality – HHE at Getinge, where she provides strategic leadership and end-to-end process ownership for the company’s enterprise-wide Health Hazard Evaluation program. Her work includes HHE governance, methods, digital tools, audit readiness, metrics, process improvement, and support of correction and removal decisions across Getinge's global network of medical device manufacturing sites. Kerry is a quality and regulatory compliance leader and Board Certified Medical Affairs Specialist with more than 20 years of medical device experience spanning quality, medical affairs, clinical support, postmarket surveillance, risk management, and product development. Before her current role, she held senior medical affairs positions at Getinge and spent more than a decade supporting cardiac rhythm management products at Boston Scientific. She holds bachelor’s degrees in Biomedical Engineering and Electrical Engineering from Duke University. Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn. Disclaimer Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations. Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

July 24, 202620 min

Deep Dive: FDA's RWE Guidance

Real-world data does not become regulatory evidence simply because it is large, current, or readily available. FDA’s December 2025 final guidance, Use of Real-World Evidence to Support Regulatory Decision-Making for Medical Devices , supersedes the 2017 guidance and provides a more detailed framework for determining when real-world data can generate evidence suitable for a medical device regulatory decision. One important change is FDA’s recognition that a sponsor’s inability to obtain participant-level data does not automatically prevent the Agency from evaluating the evidence. But this flexibility does not lower the evidentiary bar. Sponsors must explain the limits of data access and demonstrate—through rigorous, traceable documentation—that the data and resulting analysis are credible. Key highlights covered in the audio: * The difference between real-world data and real-world evidence * How FDA evaluates relevance , including data availability, timeliness, and generalizability * How FDA evaluates reliability , including data provenance, completeness, consistency, quality controls, and traceability * Why protocols and analysis plans should be established before reviewing outcomes * How sponsors should address bias, confounding, missing data, and data-linkage methods * New documentation recommendations for cover letters, study protocols, reports, and eSTAR submissions * When studies using routinely collected data may—or may not—require an IDE Keywords: FDA real-world evidence guidance, real-world data for medical devices, real-world evidence regulatory strategy, RWE relevance and reliability, medical device regulatory submissions, post-market surveillance data, total product lifecycle. 🎧Click Play above to listen to a brief audio summary for a practical examination of FDA’s evolving expectations for real-world evidence. Thanks for reading Let's Talk Risk! . If you liked this post, share with others. Note: The audio summary was prepared using Google NotebookLM, an AI-enabled research tool. Here are a few key resources used for this analysis: * FDA (2025, December 18), Use of Real-World Evidence to Support Regulatory Decision-Making for Medical Device s, Final Guidance, FDA. * Castor Report (2026, April 26). Beyond the EHR: meeting the FDA’s new real-world evidence standards . * IQVIA. (2026, February 06). FDA Updates Guidance on Real-World Evidence for Medical Devices. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

July 17, 202625 min

LTR 161: AI Governance by Design

Summary “Let’s treat AI governance by design as the connective tissue of a product lifecycle ecosystem.” AI governance is often introduced as another layer of oversight—more procedures, approvals, documentation, and checklists. Ankita Mishra offers a different way to think about it: governance should be designed into the digital health product lifecycle from the beginning. In this episode of the Let’s Talk Risk! conversation , host Naveen Agarwal and Ankita Mishra explore how systems thinking and risk-based decision-making can help organizations innovate responsibly without applying the same level of rigor to every product or use case. They discuss flexible quality systems, the importance of defensible rationale, third-party AI solutions, supplier dependencies, privacy and security, model performance, and the need to monitor AI after deployment. The conversation also addresses what AI means for quality, regulatory, and risk professionals. Rather than making human expertise less relevant, Ankita argues that AI increases the need for critical thinking, judgment, collaboration, and continuous learning. Listen to the full 25-minute podcast or jump to a section of interest listed below. Chapters 00:00 – Introduction and Welcome 01:04 – Ankita Mishra’s Career Journey 04:36 – Reframing AI Governance by Design 06:40 – Shifting Critical Thinking Upstream 09:11 – Matching Development Rigor to Risk 12:20 – Building Defensible Risk-Based Rationales 14:17 – AI Governance Across the Product Lifecycle 16:03 – Evaluating Third-Party AI and eQMS Solutions 18:22 – Preparing Quality and Regulatory Professionals for AI 23:00 – Closing Takeaways on Responsible AI If you enjoyed this podcast, consider subscribing to the Let’s Talk Risk! newsletter . Suggested links: LTR: Proactive AI Governance in MedTech . LTR: Building Trustworthy AI and MedTech Readiness . LTR: Evolving Regulatory Landscape for AI in MedTech . Key Takeaways * AI governance should begin with the design decision—not after the technology has already been selected or deployed. * Start with the intended use and the underlying problem. The first question is not simply how to use AI, but whether AI is necessary. * The level of lifecycle rigor should reflect product risk, regulatory status, and the consequences of failure. Not every requirement needs to be applied identically to every solution. * A flexible, risk-based quality system depends on clear reasoning. Organizations must be able to justify both why a requirement applies and why it may not apply. * Responsible AI governance extends beyond the algorithm. It includes privacy, cybersecurity, infrastructure, suppliers, contracts, deployment, maintenance, performance monitoring, and drift. * Organizations evaluating third-party AI tools should understand whether their data will be retained or used for training, what information may be disclosed, and what additional controls may be needed. * A sandbox approach can reduce uncertainty: start with a controlled, lower-risk application, evaluate whether it produces meaningful value, and scale based on evidence. * AI will change professional responsibilities, but it will not eliminate the need for experienced judgment. Critical thinking, systems thinking, collaboration, and organizational knowledge will become even more valuable. * Lifelong learning is no longer limited to formal training. Professionals can learn by engaging with thought leaders, attending conferences, following emerging standards, sharing ideas publicly, and allowing others to challenge their thinking. Keywords AI governance, responsible AI, digital health, systems engineering, risk-based decision-making, quality management systems, third-party AI, model drift, regulatory compliance, critical thinking About Ankita Mishra Ankita Mishra is the Digital Health Quality Director at Evinova , where her work focuses on AI governance and responsible innovation in healthcare, digital health product strategy, lifecycle management, GCP compliance, global standards, and quality systems. She brings more than 20 years of experience spanning software development, biomedical engineering, medical devices, systems engineering, and software quality. Her career has included roles at AstraZeneca, Senseonics, Medtronic, Terumo Cardiovascular Systems, Integra LifeSciences, and Infosys. Ankita holds a master’s degree in public health from Johns Hopkins University, an MS in biomedical engineering from Drexel University, and a BE in electronics from Nagpur University. Her work centers on enabling innovation and regulatory rigor to advance together rather than treating them as competing objectives. Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn. Disclaimer Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations. Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

July 10, 202617 min

Case Study: Why FDA Cybersecurity Expectations Are Really QMS Expectations

You cannot bolt cybersecurity onto a medical device at the end of development. FDA’s cybersecurity guidance makes a clear shift: cyber risk is now a quality system issue, a patient safety issue, and a lifecycle management issue. For connected and software-enabled devices, it is not enough to show that the software works as intended. Manufacturers also need to show how cybersecurity risks were identified, controlled, verified, traced to patient harm, and managed after release. In this audio summary, we walk through why FDA’s expectations go beyond submission documentation and why QA/RA teams need to understand the practical connections between SPDF, threat modeling, SBOMs, vulnerability management, postmarket patching, and the medical device QMS. Key highlights covered in the audio: * Why cybersecurity now needs to be treated as part of the medical device QMS * How Section 524(b) changes expectations for “cyber devices” * Why cyber risk needs to connect to patient harm, not just IT vulnerability * How SPDF, threat modeling, architecture views, and testing evidence fit together * Why machine-readable SBOMs and VEX documentation matter for vulnerability management * How postmarket patching, CVD, and cybersecurity management plans create lifecycle obligations Keywords: FDA cybersecurity guidance, medical device cybersecurity, cyber device, SPDF, SBOM, medical device QMS, cybersecurity risk management, patient safety, postmarket cybersecurity. 🎧Click Play above to listen to a brief audio summary about this case and lessons QA/RA and Clinical professionals can apply in practice using the newly released FDA Guidance. Thanks for reading Let's Talk Risk! . If you liked this post, share with others. Note: The audio summary was prepared using Google NotebookLM, an AI-enabled research tool. Here are a few key resources used for this analysis: * FDA (2026, February 3), Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions , Final Guidance, FDA. * Apotech Consulting. (2026, May 14). The Software Bill of Materials (SBOM): What Every SaMD Manufacturer Needs to Know . Apotech Consulting. * Espinosa, C. (2026). 1 2 Reasons the FDA Rejects Cybersecurity Submissions . Blue Goat Cyber. * Al-Faruque, F. (2026, February 4). FDA reissues cybersecurity guidance to align with QMSR . Regulatory Affairs Professionals Society (RAPS). * Exponent. (2026, April 6). Navigating FDA's Cybersecurity in Medical Devices Guidance . Exponent. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

July 3, 202647 min

LTR 160: IMSC26 Highlights - From Compliance to Proactive MedTech Safety

Summary “The biggest takeaway was realizing that our perspectives on risk and safety are not isolated. They are shared, validated, and strengthened by others in the field.” In this special episode of the Let’s Talk Risk! conversation , host Naveen Agarwal brings together a panel of medtech safety and risk management leaders to discuss key takeaways from IMSC26 in Boston. The conversation highlights why the conference has become a unique gathering place for the medtech safety community: a forum where risk, quality, regulatory, clinical, and engineering professionals can speak a shared language and challenge each other’s thinking. The panel explores several major themes: moving beyond compliance, bringing patient perspective into risk management, understanding QMSR as a shift toward risk-based quality systems, strengthening judgment and critical thinking, and using AI as a thinking partner rather than a replacement for expertise. Listen to the full 47-minute podcast or jump to a section of interest listed below. Chapters 00:00 – Introduction and Panel Overview 01:23 – Bijan Elahi on the Growth and Vision of IMSC 06:23 – Proactive Safety from Clinic to Home 08:28 – Patient Safety as the Central Stakeholder Theme 10:15 – FDA, QMSR, and the Shift Toward Risk-Based Thinking 18:53 – Design Control, Agile Software, and Surgical Robotics 22:11 – Hidden Influences, Judgment, and Psychological Safety 34:26 – AI as a Tool, Not a Replacement for Expertise 40:00 – Career Day, Final Takeaways, and IMSC27 Preview If you enjoyed this podcast, consider subscribing to the Let’s Talk Risk! newsletter . Suggested links: LTR: Tips for Improving Collaboration in Risk Management . LTR: From Procedures to Judgment - Leading Through QMSR Inspections . LTR: LTR Risk Coach - AI-Powered Decision Support Tool . Key Takeaways * IMSC has become a true medtech safety community. The conference gives risk professionals a rare space to connect, compare experiences, and realize they are not alone in the challenges they face. * Patient safety must be more than a slogan. The panel emphasized that patient perspective needs to show up directly in risk management, especially where traditional harm categories may miss emotional, psychological, or lived-experience impacts. * Risk management is not just a compliance exercise. It is a human practice that requires collaboration, judgment, shared language, and cross-functional maturity. * QMSR raises the bar for risk-based thinking. The discussion framed QMSR as a move toward connected quality systems where FDA may look at whether decisions, processes, and subsystems work together around patient safety. * Judgment cannot be fully proceduralized. Procedures matter, but good risk decisions also require critical thinking, psychological safety, leadership, and comfort with ambiguity. * AI can strengthen risk thinking, but it cannot replace expertise. The panel warned against over-reliance on AI while recognizing its value as a tool to organize thinking, challenge assumptions, and preserve institutional knowledge. Keywords IMSC26, medtech safety, medical device risk management, patient safety, QMSR, FDA, risk-based thinking, quality culture, critical thinking, AI in medtech, design control, safety architecture, patient perspective, regulatory strategy, risk management maturity Guest Speakers Bijan Elahi as an award-winning medical device risk management author, professor and consultant. Dr. Olaf Hedrich is the Chief Medical Safety Officer at Medtronic. Michelle Lott is an executive advisor in regulatory strategy, principal and founder at LeanRAQA, LLC. Aaron Joseph is a principal consultant at Sunstone Pilot. Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn. Disclaimer Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations. Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

June 26, 202642 min

LTR 159: The Evolving Regulatory Landscape for AI in MedTech

Summary “Stop thinking of AI as replacing humans. Think about humans staying in charge while AI is placed in the loop” Artificial intelligence is no longer a future concept in MedTech. It is already inside medical devices, quality systems, regulatory workflows, post-market processes, and product development decisions. In this episode of the Let’s Talk Risk Podcast , host Naveen Agarwal sits down with Priya Setty and Atty Chakraborty for a wide-ranging discussion on how AI is changing medical device regulation and quality practice. Priya frames AI through a human lens: like a child growing into adulthood, AI needs supervision, boundaries, and responsible “parenting.” Atty builds on that by explaining how the conversation has shifted from “How do we regulate AI?” to more practical questions about testing, validation, acceptance criteria, context of use, and lifecycle control. The discussion covers the EU AI Act, FDA’s total product lifecycle approach, global regulatory trends, post-market complaint triage, AI in audits and quality operations, change control, PCCP, and the career implications for QA/RA professionals. A recurring theme is clear: AI can improve the quality, consistency, and timeliness of decisions, but only if humans remain in charge. Chapters 00:00 – Introduction: AI in MedTech and why this conversation matters 03:06 – Priya’s child development lens for understanding AI governance 08:45 – EU AI Act vs MDR: horizontal regulation meets medical device rules 11:15 – FDA’s lifecycle approach to AI-enabled medical devices 23:17 – AI in post-market complaint triage and safety signal detection 31:57 – PCCP for AI-enabled devices: opportunity, adoption, and business case 36:05 – Career implications for QA/RA professionals If you enjoyed this podcast, consider subscribing to the Let’s Talk Risk! newsletter . Suggested links: * Navigating convergence and divergence between the EU MDR and EU AI Act * LTR: Case Study: Contrasting U.S. and EU Approaches to AI Regulation * LTR: LTR Risk Coach - AI-Powered Decision Support Tool . Key Takeaways * AI is not new, but the risk profile has changed. What has changed is broader access, greater autonomy, and higher consequence decisions. * AI governance is about keeping humans in charge. Organizations need clear boundaries, validation, monitoring, and human judgment at critical decision points. * The EU and FDA are approaching AI differently. The EU AI Act creates a broad governance overlay, while FDA continues to emphasize lifecycle control, context of use, and post-market performance. * AI can strengthen QA/RA work if used carefully. It can support complaint triage, audit preparation, regulatory intelligence, quality documentation, and change assessment. * Post-market monitoring becomes even more important with AI. AI systems should not be treated as “validated once and valid forever,” especially when models may drift or behave differently in real-world use. * PCCP is useful when the product roadmap is clear. It can support planned AI changes, but it is not a shortcut for uncertain models or poorly defined strategy. * QA/RA professionals need AI governance fluency. They do not need to become data scientists, but they should understand intended use, bias, drift, validation, and where human review is essential. Keywords AI in medical devices, AI governance, AI-enabled medical devices, EU AI Act, FDA AI guidance, lifecycle management, post-market monitoring, PCCP, complaint triage, AI validation, change control, QA/RA professionals About Priya Setty Geetha priya (Priya) Setty is a regulatory affairs strategist and systems builder with over eight years in global regulatory affairs and more than twenty years in healthcare. Starting her career as a pediatric occupational therapist, Priya brings a unique blend of clinical insight and policy expertise to the evolving world of medical technology. She leads regulatory intelligence and digital transformation initiatives at a global medical device company, specializing in global regulatory strategy, regulatory intelligence, and digital health/AI compliance for high-risk devices. Priya is adept at navigating complex regulations such as the EU AI Act and FDA guidance, ensuring compliance is embedded in every innovation. A certified PMP, RAC (Devices), and ISO 13485 lead auditor, Priya is known for demystifying complex regulations and building systems that keep teams ahead of industry changes. Guided by her mantra, “make a choice, and make it happen,” she is dedicated to leadership, mentorship, and simplifying healthcare through curiosity and purpose-driven action. About Attrayee Chakraborty Attrayee Chakraborty is a quality and regulatory leader specializing in digital health and AI-enabled medical devices. At Analog Devices, she drives QMS development, risk management, and AI governance to meet global regulatory standards. Recognized as Quality Magazine’s 2025 “Rookie of the Year” and a 2025 RAPS Rising Star , Attrayee has delivered talks at major industry events including RAPS, MDM West, and ISPE. She also serves on working groups with IEEE, RAPS, and SQA, shaping the future of healthcare AI compliance. Passionate about empowering early-career professionals, she bridges the gap between regulatory rigor and real-world innovation. Disclaimer Information and insights presented in this podcast are for educational purposes only. Views expressed by all speakers are their own and do not reflect those of their respective organizations. Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

June 19, 202641 min

Case Study: FDA’s New Expectation for Use-Related Risk in Medical Device Submissions

You cannot reverse engineer your human factors regulatory strategy at the 11th hour. FDA’s new human factors guidance is not just about what goes into a marketing submission. It changes the way teams need to think about use-related risk, critical tasks, labeling, training, post-market evidence, and design change control across the product lifecycle. In this audio case study, we walk through why Category 3 human factors validation may become the default concern when critical tasks are introduced or impacted and why Decision Point D is not a shortcut, but an evidence-based exception that depends on history of use, user interface complexity, and the adequacy of existing risk controls. Key highlights covered in the audio: * Why human factors can no longer be treated as a late-stage submission activity * How use-related risk analysis drives the identification of critical tasks * Why Category 3 validation may be triggered by more than obvious design changes * How Decision Point D may reduce submission burden — but only with strong evidence * Why post-market surveillance data now has direct pre-market strategic value Keywords: FDA human factors guidance, medical device marketing submissions, use-related risk analysis, critical tasks, Category 3 human factors validation, Decision Point D, eSTAR, QMSR, medical device usability, post-market surveillance, design validation, medical device labeling. 🎧Click Play above to listen to a brief audio summary about this case and lessons QA/RA and Clinical professionals can apply in practice using the newly released FDA Guidance. Thanks for reading Let's Talk Risk! . If you liked this post, share with others. Note: The audio summary was prepared using Google NotebookLM, an AI-enabled research tool. Here are a few key resources used for this analysis: * FDA (2026, May 29), Content of Human Factors Information in Medical Device Marketing Submissions , Final Guidance, FDA. * Al-Faruque, F. (2026, May 28). FDA provides additional examples, clarity in human factors guidance . Regulatory Affairs Professionals Society (RAPS). * Lenz, A. R. (2026, June 3). FDA Issues Final Guidance for Content of Human Factors Information in Medical Device Submissions . FDA Law Blog. * Pure Global. (2026, June 2). FDA Human Factors Guidance 2026 Update for Device Submissions . Pure Global Regulatory News. * Regulatory Evolution of Human Factors in Medical Device Submissions: A Comprehensive Analysis of the Final FDA Guidance and Its Quality System Implications . (2026). * Strochlic, A. (2026, May 29). Key Updates in the Final FDA Guidance: Content of Human Factors Information in Medical Device Marketing Submissions (2026) . Emergo by UL. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

June 12, 202628 min

LTR 158: Three Questions To Keep Risk Connected to Decisions

Summary “Tools do not remove uncertainty” In this Let’s Talk Risk! conversation , host Naveen Agarwal speaks with Vilma Nasteckiene, PhD , founder of Holistic Business Risk , about a broader and more human view of risk management. Vilma brings experience from banking, fintech, operational excellence, consulting, research, and business transformation. Her work focuses on reconnecting risk management with the real habits, decisions, tensions, and accountability practices that shape how organizations actually operate. This conversation moves beyond medical device risk management in the narrow technical sense. Instead, it explores risk as a business discipline: how companies grow, how complexity creates silos, how risk becomes disconnected from decision-making, and why mature risk management requires more than procedures, reports, and frameworks. Vilma offers three simple questions for a balanced approach to lifecycle risk management: What are we trying to achieve? What do we rely on to achieve it? How could it fail? The discussion connects directly to medtech, where product lifecycle, organizational lifecycle, regulatory expectations, patient safety, and business sustainability often collide. Listen to the full 30-minute podcast or jump to a section of interest listed below. Chapters 00:00 – Introduction 01:10 – Vilma’s journey into holistic business risk 02:40 – When risk management drifts away from real business decisions 05:55 – What lifecycle risk management means 07:20 – Why companies lose risk visibility as they scale 09:00 – Applying lifecycle thinking to organizations and products 12:45 – Co-creating better risk expectations with regulators and industry 15:25 – Mature business practices as risk management practices 20:10 – Strategic planning as a risk control 22:00 – Three questions for reconnecting risk with decisions 25:20 – Why tools do not remove uncertainty 27:20 – Closing remarks and key takeaways If you enjoyed this podcast, consider subscribing to the Let’s Talk Risk! newsletter . Suggested links: LTR: Lifecycle Risk Integration Under QMSR . LTR: Different Functions, Different Risk Lenses . LTR: LTR Risk Coach - AI-Powered Decision Support Tool . Key Takeaways * Risk management cannot be separated from business management. If risk is delegated entirely to a risk department, it will eventually lose contact with the decisions that actually create or reduce risk. * Organizations often outgrow their risk management systems. As companies scale, complexity increases. Risk may shift from real-time decision-making into reporting, dashboards, procedures, and post-hoc justification. * Lifecycle thinking applies at more than one level. It applies to the organization, the product, the service, and the regulatory relationship. A startup, a scale-up, and a mature company should not all manage risk in exactly the same way. * More procedures do not automatically mean better risk management. Vilma challenges the idea that visible documentation equals maturity. A company can have many procedures and still fail to connect risk with daily decisions. * Strategic planning can be a powerful risk practice. Growth, profitability, compliance, innovation, and safety can create competing pressures. If those tensions are not addressed at the strategy level, they are pushed down into functions. * Simple questions can reconnect risk to reality. Vilma’s practical questions are: What are we trying to achieve? What do we rely on to achieve it? How could it fail? * Risk maturity is more than frameworks and tools. Tools can help organize uncertainty, but they cannot remove it. They also cannot fully capture hesitation, silence, weak signals, informal concerns, or leadership behavior. * Regulators and industry can reduce “fake fear” by co-creating expectations. Vilma’s fintech example shows the value of bringing regulators, founders, and practitioners into the same room to design risk expectations that reflect real operating maturity. Keywords Risk management, lifecycle risk management, risk maturity, holistic business risk, Vilma Nasteckiene, medtech risk, fintech risk, business risk, strategic planning, operational risk, risk culture, regulatory expectations, weak signals, leadership habits, decision-making, ISO 31000, risk governance, organizational maturity, risk-based thinking, Let’s Talk Risk About Vilma Nasteckiene Vilma Nasteckiene is the founder of Holistic Business Risk and describes her work as helping organizations “unfake and destigmatize risk management.” Her mission is to humanize risk perception and connect business and risk management to the daily habits of resilient, antifragile organizations. She works with managers, regulators, and auditors to connect purpose, client needs, processes, and risk management into visible collaborative practice. Vilma’s background includes banking, credit risk, operational risk, business process management, consulting, research, and system change. She contributed to fintech regulatory requirements and best-practice development in Lithuania, completed PhD research on risk management in management practices, helped initiate national adoption of ISO 31000 and related standards in Lithuania, and co-founded the Lithuanian Association of Risk Management Professionals. Her work emphasizes the practical connection between strategy, accountability, operations, leadership behavior, and risk maturity. Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn. Disclaimer Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations. Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts