← Insights

SOUP is an architecture decision

SOUP is software of unknown provenance: every library, SDK, framework, runtime and ML model your team didn't write. Under IEC 62304 each one carries a regulatory obligation.

Teams see a dependency list. Regulators see a risk artifact.

What stalls submissions

  • No SOUP registry.
  • Version drift between what was assessed and what is running.
  • An AI blind spot: models and AI services nobody classified.

What good looks like

  • Versions are pinned and assessed.
  • Vendors are qualified under ISO 13485 clause 7.4, not just reviewed.
  • AI and ML components are treated as SOUP from day one.

SOUP management is not a quality task. It is an architectural boundary decision.

Seen this differently?

Questions, corrections and counterexamples are welcome.

Related

Keep reading