Integration with an Existing QMS

Last Audited: 2026-08-21
NUP AI-Native Verified
ISO 13485:2016 Cl. 7.3 (Design Controls)ISO/IEC 42001:2023 Cl. 8 & 9 (AIMS Integration)FDA 21 CFR Part 820 Sec. 820.30
In Plain Language

A common objection in regulated enterprise conversations is the assumption that adopting an AI-native engineering framework requires dismantling or replacing an existing, certified Quality Management System (QMS). The Netspective Unified Process (NUP) for Probabilistic Software is engineered with an explicit architectural promise: it extends rather than replaces existing QMS structures. By plugging additive AI phase gates, statistical validation harnesses, and post-market drift telemetry directly into standard design controls (ISO 13485 / 21 CFR 820), organizations achieve complete AI compliance with zero disruption to their certified quality baseline.

The Core Integration Promise: Extends, Does Not Replace

Adopting the Netspective Unified Process for Probabilistic Software does not require replacing your ISO 9001, ISO 13485, FDA 21 CFR Part 820, or GAMP 5 Quality Management System.

NUP functions as an additive, modular extension. Your approved Standard Operating Procedures (SOPs), document controls, and CAPA workflows remain 100% active. NUP simply injects the required AI-specific delta procedures—such as statistical validation, prompt context governance, and post-market drift monitoring.

Architectural Orientation: Seamless QMS Harmonization

Traditional quality systems are built around deterministic premises: code is specified, unit-tested with binary assertions, released, and assumed stable until the next formal release. When engineering teams build probabilistic software (RAG agents, generative assistants, LLM decision engines), existing QMS procedures struggle to account for non-deterministic variance and production drift.

Rather than rewriting the entire corporate QMS, NUP introduces targeted, additive phase gates that plug directly into existing Design History Files (DHF) and Technical Dossiers.

NUP QMS Additive Integration ArchitectureAn architecture diagram illustrating how NUP AI extensions overlay existing ISO 9001, ISO 13485, and GAMP 5 Quality Management Systems without disruption.NUP QMS Integration: Additive Overlay ArchitectureExtending existing certified quality baselines with AI-native statistical phase gates and telemetry.UNIFIED AUDIT-READY COMPLIANCE PACKAGESingle cohesive submission package covering FDA 510(k)/PMA, EU AI Act Annex IV Technical Dossiers, and ISO 42001 conformity assessments.NUP ADDITIVE AI EXTENSION LAYER (EXTENDS, DOES NOT REPLACE)6-Stage AI LifecycleStatistical phase gatesKnowledge prep & evalContext & Prompt SpecsVersion-controlled promptsToken & injection rulesStatistical ValidationConfidence interval evalHallucination scoringPost-Market Drift TelemetryContinuous distribution logsReal-time error taxonomiesEXISTING ENTERPRISE QMS BASELINE (PRESERVED 100% UNCHANGED)ISO 13485 / 21 CFR 820Design controls & DHF recordsISO 9001 / GAMP 5Software validation & SOPsRisk Management (ISO 14971)FMEA & hazard mitigationsCAPA & Change ControlIssue tracking & ECO sign-offs

The Four Core Integration Pillars

1. Extends Traditional SDLC

Adds AI-specific phases and statistical validation gates (Topics 4 & 5) while preserving your deterministic build, lint, and unit-test pipelines unchanged.

2. Pre-Mapped Regulatory Assurance

All NUP evidence artifacts are pre-mapped to FDA SaMD/PCCP, EU AI Act Annex IV, and NIST AI RMF standards (Topic 6).

3. Risk-Proportional Scalable Governance

Governance intensity scales with risk: lightweight developer assistant usage policies for internal tools vs. full statistical dossiers for high-risk clinical/financial AI.

4. Audit-Ready Operational Evidence

Every template, log schema, and telemetry pipeline is designed specifically with external third-party assessors and notified bodies as the primary audience.

QMS Delta Integration Crosswalk

This crosswalk demonstrates how NUP AI extension artifacts plug directly into standard ISO 13485 / ISO 9001 / GAMP 5 quality procedures:

Existing QMS ProcedureStandard BaselineNUP Additive AI ExtensionIntegrated Audit Deliverable
Design Verification (ISO 13485 Cl. 7.3.6)Deterministic unit & integration test passesStatistical evaluation & confidence intervalsStatistical Validation Dossier
Risk Management (ISO 14971 / FMEA)Hazard analysis & deterministic failure modesHallucination rates & prompt injection probesAI Hazard & Red-Team Assessment
Change Control (21 CFR 820.30)Engineering Change Orders (ECO)Predetermined Change Control Plans (PCCP)FDA-Compliant PCCP Protocol
Post-Market Surveillance (EU MDR Art. 83)Periodic customer complaint reviewsContinuous distribution & retrieval drift logsContinuous Drift & Telemetry Report

What You Get: The Complete Deliverables Checklist

A forwardable inventory of core assets and frameworks included in the Netspective Unified Process for Probabilistic Software:

1. AI-Native SDLC Process Documentation

Complete stage-by-stage phase gate manual detailing activities, exit criteria, and audit deliverables across all 6 stages.

2. AI Context Playbooks & Manifestos

Developer workflow guidance, IDE assistant policies (Claude Code, Cursor), and engineering manifestos for modern ICs.

3. Knowledge Transformation Tooling Guidance

Architectural patterns for converting enterprise PDFs/DOCX into high-precision Markdown/HTML trust layers with chunk lineage.

4. Trustable AI Interactions Doctrine

Safety guardrails, hallucination measurement harnesses, and grounded citation engineering standards.

5. Tech Stack Philosophy for AI Architectures

Vendor-neutral principles for hybrid search, embedding index topologies, semantic caching, and model routing.

6. AI-Native Technical Communications

Dual-ingestion documentation templates, JSON frontmatter schemas, and user correction feedback loop architectures.

7. Pre-Mapped Regulatory Compliance Guides

Direct clause crosswalks for EU AI Act Annex IV, FDA SaMD & PCCP, ISO/IEC 42001, and NIST AI RMF 1.0.

8. Audit-Preparation Dossier Templates

Checklist-ready templates for Model Cards, Dataset Data Sheets, Context Specs, and Continuous Drift Reports.

The Active Operator Perspective

Netspective does not approach AI governance as an academic advisory exercise. As active engineering operators building regulated clinical and enterprise software, we build the evidence tools that power this framework:

  • Automated Evidence Aggregation: Using tools like surveilr to capture immutable telemetry and database audit trails.
  • Quality Folios: Transforming raw engineering telemetry into verifiable compliance portfolios for regulators.
  • Zero-Trust Telemetry: Verifiable prompt hashes and embedding distributions ensuring non-repudiation during third-party audits.
Category 1 Complete: Core Concepts Mastered

Next Stop: Category 2 — The Four Layers of LLM Engineering

Now that you have mastered the foundational assumptions, lifecycle phase gates, evidence requirements, and QMS integration of the probabilistic paradigm, proceed to Category 2 to explore the tactical four-layer technical architecture of LLM systems (Prompts, Context, Harnesses, and Loops).

Proceed to Category 2: The Four Layers of LLM Engineering
Try This with AI: QMS Delta Integration Assessment Prompt

Use this prompt in your AI assistant to generate a QMS delta assessment for your existing quality procedures.

Act as a Principal QMS & AI Quality Systems Lead. Analyze how to integrate the Netspective Unified Process into our existing Quality Management System: - Existing QMS Baseline: [e.g., ISO 13485:2016 Certified Design Controls for Medical Device Software] - AI Initiative: [e.g., Clinical trial protocol matching diagnostic assistant] - Primary Regulator: [e.g., US FDA Center for Devices and Radiological Health / EU Notified Body] Provide: 1. An explicit list of Standard Operating Procedures (SOPs) requiring additive AI delta annexes (e.g., SOP-004 Design Verification -> Annex AI-1 Statistical Evaluation). 2. The specific changes needed in the Design History File (DHF) index to incorporate model manifests and prompt registers. 3. An executive summary slide draft explaining to leadership why this integration does NOT invalidate existing ISO certifications.
Previous Section
Deterministic Unified Process
Next Track
The Four Layers of LLM Engineering

Community Discussion & Feedback

Attributed peer feedback and official Netspective architecture notes.

Was this documentation helpful?(100% found this helpful • 0 ratings)

Leave Feedback or Question

○ Loading user info...
0/2000 chars

Discussion (0)

Loading discussion thread...