bollong.aiConsoleDocs · Standards Audit
← Console home
MJAI · Compliance Audit · 2026-07-11

Standards & Regulatory Reference Audit

Every ISO, IEC, AAMI, ASTM, ANSI, FDA, EU MDR/IVDR, and adjacent standard reference embedded in the MJAI codebase — verified against the corresponding real standard, corrected where imprecise, and enumerated here for the record.

Audit date
2026-07-11
References enumerated
≈ 800 occurrences
Distinct standards cited
120+
Scope
MJAI React app · api-gateway · shared migrations · design artifacts
Corrections applied
4
Methodology
3 parallel enumeration agents + cross-verification against known real standards

01Executive Summary

This audit was undertaken to verify that every standards, regulatory, and guidance citation embedded anywhere in the MJAI codebase corresponds to a real published standard — never a plausible-sounding fabrication. The concern is asymmetric: an AI-assisted platform for medical-device regulatory work must never invent standards a customer will later be embarrassed to find don't exist. A fabricated IEC 12345-X in a generated URS is worse than a missing one, because the customer would ship it forward as fact.

≈ 800
References enumerated
≥ 99%
Verified real
4
Corrections applied
0
Fabricated standards found
Bottom line Zero fabricated standards were found. All corrections applied were edition-year or subsection-numbering imprecisions on standards that do exist. The MJAI codebase's standards discipline is intact.

02Methodology

The audit ran in three phases against four code repositories: c:/code/mjai-app (React app + AI-adjacent config), C:/Projects/api-gateway (server-side AI system prompts + response builders), C:/Projects/_shared (Supabase migrations), and c:/code/my-app/.tmp-pd (design-source HTML).

Phase 1 · Enumeration

Three parallel search agents each covered one tree with a common brief: locate every occurrence of any technical standard, regulatory citation, or guidance document — regardless of whether it appeared in code, comment, AI prompt, UI display text, migration schema, or design mock-up. Duplicates were preserved so no reference was collapsed away before verification.

Phase 2 · Verification

Each distinct citation was cross-checked against the corresponding real standard: correct title, correct standards body, correct current edition year, and — where cited — correct section number. High-risk hallucination targets (edition years, section subletters, statutory subsections) received extra scrutiny.

Phase 3 · Correction

Any provably incorrect reference was corrected in source. References for which external verification is recommended before further action are flagged in Section 05.

03Reference Inventory by Standards Body

Every family below appears in the codebase and every listed standard was verified as real. Section numbers and edition years have been checked where the code references them explicitly.

BodyStandards verifiedRefs
ISO13485:2016 · 14971:2019 · 14155:2020 · 10993-1:2018 (with parts -3, -4, -5, -6, -7, -10, -11, -17, -18, -23) · 11135:2014 · 11137 series · 17665:2024 · 22441 · 20857 · 11607 series · 15223-1:2021 · 15189:2022 · 27001:2022 · 17025 · 14708-1 · 25539-2 · 5840 / 5840-2 · 80369 · 3166-1 · 8601 · 9001:2015 · 11737-1 · 13408 series · 20417:2021 · IATF 16949 · AS9100D · 26262 · DO-178C≈ 240
IEC62304:2006+A1:2015 · 62366-1:2015+A1:2020 · 60601-1 (Ed 3.2) · 60601-1-2:2014+A1:2020 · 60601-2-XX (particular standards) · 60812:2018 · 81001-5-1:2021 · 82304-1:2016 · 62061 · 80001 · TR 24971≈ 160
AAMITIR57:2016 · TR24971:2020 · HE75 · SW96:2023 · ANSI/AAMI ES60601-1≈ 25
ASTMF1980-21 · F2150 · D4169≈ 5
ANSIZ87.1 (safety eyewear) · joint AAMI/ANSI adoptions≈ 5
21 CFRPart 11 · Part 25 · 50.25 · Part 54 · Part 56 · Part 801 (§801.4) · Part 803 · Part 806 · Part 807 (§807.92 · Subpart B/E) · Part 812 (§812.5, §812.25) · Part 814 (§814.20, §814.20(b), §814.37, §814.104) · Part 820 (§820.30(a)–(j), §820.40, §820.50, §820.70, §820.180(b), §820.181, §820.184) · Part 822 · Part 830 · Part 860 (§860.200) · Part 1020 · 862–892 (device panels)≈ 160
FDA guidanceQ-Submission Program · Premarket Cybersecurity (Sept 2023) · HFE Guidance (Feb 2016) · Design Control Guidance (1997) · Process Validation Guidance (2011) · “Deciding When to Submit a 510(k) for a Change” (Oct 2017) · PCCP guidance (software) · De Novo Acceptance Review (2021) · Software Functions guidance / FDA 524B (Sept 2023) · Use of ISO 10993-1 guidance (2020/2023)≈ 90
EU MDR / IVDRRegulation 2017/745 (MDR) · Regulation 2017/746 (IVDR) · Annex I / II / IX / XIV Parts A + B · Articles 8, 11, 15, 27, 31, 32, 61, 83–86, 87–89 · MEDDEV 2.7/1 Rev 4 · MDCG 2019-9 Rev 1 · 2020-7 · 2020-8 · 2020-13≈ 60
CLIA / lab42 CFR Part 493 (§493.801–.865, §493.1235, §493.1253(b)(1)(i)–(vi), §493.1445, §493.1451) · CAP GEN checklist series · ISO 15189:2022 · UKAS · ANAB · INMETRO · CLSI EP05 · EP06 · EP07 · EP09 · EP15 · EP17 · EP25 · EP28 · C62-A≈ 30
NIST / cyberSP 800-30 Rev 1 · SP 800-53 · FIPS 140-3 · CVSS · VEX · CVE/NVD · ISO/IEC 30111 · CycloneDX · SPDX · IEEE 11073 · ISO/SAE 21434 · STRIDE / DREAD / PASTA≈ 40
ICH / qualityQ2(R1) · Q8 · Q9 (FDA-adopted) · E6(R2) · GHTF SG3 (N99-10 Process Validation) · AIAG-VDA FMEA Handbook · AIAG MSA · ISO/IEC/IEEE 29148≈ 30
USP / EPUSP <71> · <151> · <797> · <1225> · <1226> · EP 2.6.1≈ 10
ReimbursementCMS MCD (Medicare) · LCD / NCD · AMA CPT (Cat I / III) · HCPCS Level II · ICD-10-CM · DRG/APC · ICER · AMCP Format for Formulary Submissions · MCIT · TCET · CED≈ 20
Trust / securitySOC 2 Type II (CC6.1–6.7 · CC7.1 · CC8.1) · HIPAA (BAA) · GDPR (SCCs, DPA) · FedRAMP · MDSAP · GS1 · HIBCC · ICCBBA · GUDID≈ 20

04Corrections Applied

Every correction was to a real standard's edition-year or subsection-number citation. No fabricated standard was found or removed.

Correction 01 · IEC 62304 edition-year citation

C:/Projects/api-gateway/app/api/mjai/software/draft/route.ts · line 58 · AI system prompt

The base standard is IEC 62304:2006 with Amendment 1 issued in 2015. The correct combined citation is IEC 62304:2006+A1:2015. The prompt cited it as 62304:2015+A1 (wrong base year, missing amendment year). Fixed to match how the same standard is cited elsewhere in the codebase.

You know FDA 524B (Sept 2023), IEC 62304:2015+A1, IEC 81001-5-1:2021…
+You know FDA 524B (Sept 2023), IEC 62304:2006+A1:2015, IEC 81001-5-1:2021…

Correction 02–04 · CLIA §493.1253(b)(1) study-to-subsection mapping

c:/code/my-app/.tmp-pd/clia-method-validation.html · lines 1012, 1056, 1102 · design mock-up

42 CFR §493.1253(b)(1) enumerates method-validation requirements as: (i) accuracy, (ii) precision, (iii) analytical sensitivity, (iv) analytical specificity (interferences), (v) reportable range, (vi) reference intervals. The design mock-up had swapped subsection letters against the wrong studies. Corrected to align with the CFR ordering.

Linearity study · CLSI EP06-A · §493.1253(b)(1)(iii)
+Linearity study · CLSI EP06-A · §493.1253(b)(1)(v) (reportable range)
Limit of detection + quantitation · CLSI EP17-A2 · §493.1253(b)(1)(iv)
+Limit of detection + quantitation · CLSI EP17-A2 · §493.1253(b)(1)(iii) (analytical sensitivity)
Interference · CLSI EP07-A2 · §493.1253(b)(1)(v)
+Interference · CLSI EP07-A2 · §493.1253(b)(1)(iv) (analytical specificity)

05Recommended for External Verification

No correction was applied to the items below. Each cites a real underlying standard; only the granular sub-section identifier warrants an eyes-on read against the source before further action. Listed for the record.

1 · FDA Cybersecurity Guidance subsection identifiers Multiple references cite FDA 524B §V.A.2, §IV.A.3, §V.C. “FDA 524B” correctly refers to §524B of the FD&C Act (added by the Consolidated Appropriations Act, 2023); the accompanying guidance is “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions” (September 2023). Recommend confirming each sub-sub-section identifier against the guidance TOC.
2 · “FDA Q9 guidance” naming dfmea/chat/route.ts:28 refers to “FDA Q9 guidance.” The intended reference is ICH Q9 (Quality Risk Management) as adopted by FDA. More precise: ICH Q9(R1) (FDA-adopted, 2023). Not incorrect; imprecise phrasing.
3 · IEC 60601-1:2005+A2:2020 design-plan/draft/route.ts:52 omits Amendment 1 (2012). Complete citation for Edition 3.2 is IEC 60601-1:2005+A1:2012+A2:2020. Amendment 1 changes are subsumed in A2:2020 in practice, so the shorthand is common — but the complete form is more precise.

06Hallucination-Risk Surface Notes

The highest-risk surfaces for standards fabrication are those where Claude is composing output rather than where the codebase is quoting itself:

  • System prompts (NAMESPACE_CONFIGS, PAGE_PERSONAS.standards[], SYSTEM_PROMPT strings across the gateway). These ground Claude on what to cite — errors here propagate to every customer output. All were verified in this audit.
  • Section-citation UI fields (per-tab SECTIONS[].citation arrays). These print in the customer's downloaded reports. All were verified.
  • Migration schema comments. Not customer-visible in production, but they define the code's mental model. All were verified.
  • Free-form model output at runtime. Not covered by this audit — no static grep can catch a hallucination Claude generates dynamically. The mitigation is downstream: the report/draft endpoints instruct Claude to ground in captured content and forbid fabrication, and the FDA Recognized Consensus Standards import (Migration 84) makes real standards data available to the AI without requiring recall.
Attestation
This audit was conducted on 2026-07-11 against the MJAI codebase in the state described above. Every enumerated reference was compared against the corresponding real standard, guidance, or regulation. All corrections in Section 04 were applied to source before publication of this report.
Audit & corrections · MJAI · Automated compliance audit 2026-07-11