MedTech · Robotics · Hardware + software
    CASE STUDY

    Steel, electronics and Class C software in one tree.

    One regulator judges the whole machine, so the whole machine lives in one graph: the software safety class falls out of the hardware risk, automatically.

    EU MDR 2017/745ISO 13485ISO 14971IEC 62304IEC 60601-1FDA 510(k)
    koddex.app · SYS-001 · v2.1
    Assembly / partQtyMass
    Robot-assisted platformSYS-001
    388.70 kg
    6-axis robotic armARM-100
    ×132.50 kg
    Mobile cartCART-110
    ×1310.00 kg
    Optical navigation stationNAV-300
    ×146.00 kg
    Control workstationWKS-400
    ×10.00 kg
    Planning softwareSW-500
    ×1Class C
    Motion control softwareSW-510
    ×1Class C
    Confirmation softwareSW-520
    ×1Class B ≠ C
    Sterile instrument guideGUID-200
    ×10.12 kg

    The workstation reads 0.00 kg because its children are software. That is also why the roll-up and the declared mass disagree; see the limits below.

    5
    engineering domains, one model
    388.7 kg
    rolled up from the leaves
    Class C
    computed, not declared
    1
    misclassified module found
    Sector Interventional roboticsDomains Mechanics, electronics, software, sterileInstalled base 4 hospital sitesStandards 7, held as items

    A reference workspace built on the structure of a real class of programme, not a customer deployment. Manufacturer, suppliers, hospital sites, clinicians and commercial names are removed. Every figure on this page is read off that live workspace.

    The pain

    Five trades, five tools, one regulator

    The answer

    One tree, and the numbers compute themselves

    Safety class is argued, not derived

    IEC 62304 asks what harm the software can cause. That severity lives in another tool, so the class gets set in a meeting and defended from memory.

    The class is a consequence

    Severity rises from the risks a module controls, and the class follows. A standing filter lists every module whose declared class disagrees. It found one.

    No BOM holds a byte and a bracket

    PLM parts have a mass and a supplier. Software has neither, so it leaves the BOM.

    A 32 kg arm and a module are the same object

    Both are components with a domain. Mass rolls up through mechanics, safety class through risk, in the same tree, with no bridge to maintain.

    “Are we ready?” takes a week

    Someone rebuilds a spreadsheet from four sources. By Monday it is wrong again, and nobody can say which line moved.

    Readiness is a screen, not a report

    Coverage, approvals, open changes and risks above threshold are computed from the tree. Nobody assembles them.

    Technicians in cleanroom gowns assembling medical device components on a stainless steel line
    The hardware decides what the software owes. Nothing in the usual tool chain carries that link.
    The proof

    Harm sets severity, severity sets the software class

    The models doing the work

    Component
    21 attributes · 9 computed
    ƒ
    Requirement
    12 attributes · 3 computed
    ƒ
    Risk
    8 attributes · 3 computed
    ƒ
    Bill of materials
    5 attributes · 3 computed
    ƒ
    Risk control measure
    5 attributes · 1 computed
    ƒ
    System cockpit
    16 attributes · 11 computed
    ƒ

    Read it backwards and it answers an auditor

    This module is Class C because of that harm.

    Harm
    Hazardous situation
    Hazard
    Severity
    Probability
    Risk index
    severity x probability
    Risk control
    Requirement
    max severity of its controls
    Component
    62304 class from max severity

    Three risks, one typed column

    A reviewer enters probability. Severity is read through to the harm; the index and the level follow.

    RiskSeverityProbabilityRisk indexLevel
    RSK-01 · Insertion along a deviated trajectory428ALARP
    RSK-02 · Uncontrolled motion with needle engaged326ALARP
    RSK-03 · Loss of patient tracking under EM noise236ALARP

    ƒ Risk index is computed by Koddex, not typed by anyone.

    The module the graph disagreed with

    Confirmation software

    SW-520
    Component·Live values · component of the control workstation
    ContentAccessFilesActivityRevisionsWhere-used
    Domain
    Software (IEC 62304)
    Version
    v3.2.1
    Allocated requirement
    Confirm trajectory before advance
    Max severity
    4max(severity of the risks it controls)
    Declared 62304 class
    Class B
    Computed 62304 class
    Class Cseverity ≥ 3 → Class C
    Linked · technical documents
    DOC-SW-152Module verification file
    DOC-SW-002IEC 62304 development plan

    Three formulas do most of the work

    Software safety class
    = severity ≥ 3 → Class C

    Derived in public from the mechanical hazard, not decided in a room.

    Classification gaps
    = declared class ≠ computed class

    A permanent filter, not an audit. It currently returns one module.

    Total mass
    = sum of the sub-components, recursively

    388.70 kg from the leaves against 520.00 kg declared. Both on screen, which is the useful state.

    The machine

    Software sits in the BOM, under the station that runs it

    koddex.app · SYS-001 · v2.1
    Assembly / partQtyMass
    Robot-assisted platformSYS-001locked
    388.70 kg
    6-axis robotic armARM-100locked
    ×132.50 kg
    Mobile cartCART-110in review
    ×1310.00 kg
    Optical navigation stationNAV-300locked
    ×146.00 kg
    Control workstationWKS-400locked
    ×10.00 kg
    Planning softwareSW-500locked
    ×1Class C
    Motion control softwareSW-510locked
    ×1Class C
    Confirmation softwareSW-520in review
    ×1Class B ≠ C
    Sterile instrument guideGUID-200in review
    ×10.12 kg
    Patient marker crownREF-310locked
    ×10.08 kg
    Mass rolled up
    388.70 kg
    Mass declared
    520.00 kg
    Software items
    3
    Classification gaps
    1

    The workstation reads 0.00 kg because its children are software. That is also why the roll-up and the declared mass disagree; see the limits below.

    The field

    Four sites point at the design. None holds a copy

    SiteRegionProceduresStatusOperated by
    SITE-01Europe450In service since 2021Interventional radiology
    SITE-02North America210In service since 2023Interventional radiology
    SITE-03Europe12Installed, training runningInterventional radiology
    SITE-04Europe0Installation planned, Q4To be confirmed

    “Which sites run a misclassified module?” is one traversal, not four phone calls.

    The result

    What changed

    PLM + eQMS + risk sheet + ALMOne graph
    Where software livesOutside the BOMIn the BOM, under its station
    Justifying a 62304 classRebuilt by hand, years laterDerived, permanently
    Finding a misclassified moduleA review campaign, if anyone runs oneA filter that returns one item
    Answering “are we ready”A spreadsheet from four sourcesA cockpit that computes nothing itself
    A site asking what it runsAn export, stale on arrivalThe same item R&D edits
    Straight answers

    What this does not do

    A roll-up only reflects its model

    The workstation reads 0.00 kg because its only children are software, so the total lands at 388.70 kg against 520.00 kg declared. The graph shows the gap. It did not fix it.

    A suggested class is not a justification

    It flags that the declared class disagrees. The segregation argument and the software safety case a notified body will read are still yours to write.

    This is a reference workspace

    Not a customer deployment. No timeline, saving or audit outcome is claimed here, because none was measured.

    Frequently asked questions

    Can one tool hold a 310 kg cart and a software module?

    They are the same object type: a component with a domain. Mass roll-ups return zero for software, risk roll-ups return a class for both.

    How is the IEC 62304 class computed?

    Each component takes the maximum severity of the risks its requirements control. Severity 3 or above suggests Class C. The declared class stays human, so the two can disagree.

    We are a robotics team outside medtech. Does this transfer?

    The medical standards are the vocabulary, not the shape. A performance level in machinery safety or a DAL in avionics is the same graph with other names.