Certyfikacja jako fundament konkurencyjności TQAMS foto Fundacja Healthcare Poland

Announcing the AICACT SDAI standard. Everyone is invited — above the divides

Centre for Quality, Audit and Certification

Announcing the AICACT SDAI standard. Everyone is invited — above the divides

A voluntary certification standard for suppliers of artificial intelligence solutions in healthcare, built on the AI Buyer’s Guide. Open consultations start today.

Reading time: approx. 12 minutesLegal status: 10 August 2026Consultations: min. 45 daysOpen to all applicants

Artificial intelligence entered Polish hospitals faster than the language needed to discuss it at the procurement table.

A director signing a contract for an AI solution today receives a presentation, a reference list and an assurance that the algorithm is „ninety-something percent accurate”. What they do not receive are answers to the questions they would ask about any other purchase of comparable weight: on which population was it validated, what happens when the data is incomplete, who is accountable for an incorrect recommendation, what does it really cost in year three, and what happens to the data when the contract ends.

Healthcare Poland Foundation announces AICACT SDAI — the AI Supplier Standard for Healthcare. It is a voluntary certification programme run by the Centre for Quality, Audit and Certification of Healthcare Poland, with a single purpose: that the hospital has complete information before signing, and the supplier faces one set of questions instead of twenty different questionnaires from twenty different facilities.

Consultations on the standard open today and we invite everyone to take part: AI suppliers, hospitals, scientific societies, professional self-governing bodies, patient organisations, academic centres and regulators. No exceptions, no membership criterion, no division into technology camps. This is a programme of good practice above the divides, and it was designed that way from the first sentence of its rules.

Why now

Three things came together.

1

EU law is no longer an announcement

The Artificial Intelligence Act has been applying in stages since 2025. Transparency obligations apply from 2 August 2026. Obligations for high-risk systems have hard dates: December 2027 for one group of applications and August 2028 for AI embedded in medical devices.

2

A gap that someone has to fill

Until August 2028 there is no statutory certification for AI embedded in medical devices. Technical standards are still being drafted and the national AI supervisory authority is only now being constituted. Hospitals are buying now. Suppliers are selling now.

3

Hospitals face a deadline

The registration window under the national cybersecurity system closes in early October 2026, and risk-management measures must be implemented by April 2027. This is no longer a matter of good practice but of management board accountability.

The problem we are solving: information asymmetry

The supplier knows everything about its product: the data it was trained on, where it performs worse, how it behaves with an atypical patient, what maintenance costs after year three. The buyer knows almost nothing and — worse — often does not know what to ask.

This asymmetry is nobody’s bad faith. It results from the absence of an agreed disclosure format. Every hospital asks differently, every supplier answers differently, and comparing two offers side by side is often impossible because they describe entirely different things. Both sides can lose: the hospital deploys a solution whose limitations it did not know, and a diligent supplier loses to one that promises more.

AICACT SDAI addresses exactly this problem. Not the problem of algorithm quality — that is what conformity assessment and clinical studies are for. It addresses the buyer’s knowledge: whether the supplier discloses complete information, whether it does so diligently, and whether an independent auditor can confirm it.

What AICACT SDAI is

AICACT SDAI is a voluntary certification mark issued by the Centre for Quality, Audit and Certification of Healthcare Poland to suppliers of artificial intelligence based solutions intended for healthcare providers.

The subject of assessment is the supplier, its processes and the completeness and diligence of the documentation it discloses to the buyer — in relation to a specific solution, a specific version and a specific intended use. The auditor verifies that the supplier actually holds what it declares: a description of the target population, a validation report prepared according to a recognised reporting methodology, a data processing map, an incident response plan, a procedure for handling an incorrect recommendation, contract exit conditions, and a full life-cycle cost calculation.

What AICACT SDAI does not do — equally important

  • The certificate does not confirm the safety or performance of a medical device. These are confirmed solely by conformity assessment carried out by a notified body and by CE marking.
  • The certificate does not replace CE marking and is not a conformity assessment within the meaning of European Union law.
  • The certificate is not an accreditation. Accreditation in healthcare is granted by the minister responsible for health; accreditation of conformity assessment bodies is granted by the Polish Centre for Accreditation.
  • The certificate does not adjudicate on clinical effectiveness or on the appropriateness of using the solution for an individual patient.
  • The certificate grants no exclusivity or preference in any public procurement procedure. Procurement law always requires the contracting authority to accept equivalent evidence.

We state this plainly at the outset, not in small print at the end. A certificate that promises more than it can confirm is worse than no certificate at all.

Where the criteria come from

We did not build the standard from scratch and we consider that a strength, not a shortcut. Its substantive basis is the AI Buyer’s Guide for healthcare — a document prepared by experts of the Coalition for AI and Innovation in Health, the wZdrowiu team and the Polish Hospital Federation. AICACT SDAI has ten criteria domains and each corresponds to exactly one question from the Guide.

Table 1. The ten AICACT SDAI criteria domains — each corresponds to one question from the AI Buyer’s Guide.
DomainScope
D1Rationale for using AI, intended use, target population, the role of the human in the decision
D2Completeness and currency of regulatory documentation
D3Diligence in reporting performance evidence and disclosure of limitations
D4Operational deployability, interoperability, integration with hospital systems
D5Training package and support for staff competence
D6Fairness across patient subgroups and handling of an incorrect recommendation
D7Data protection and lawfulness of processing
D8Cybersecurity and support for compliance with the national cybersecurity system
D9Maintenance, model change management, exit conditions and continuity
D10Cost transparency and absence of vendor lock-in

The methodological layer of the standard draws on recognised international frameworks: standards for certification bodies and AI management systems, health software standards, international consensus guidelines for trustworthy AI in medicine, and recognised reporting checklists for studies involving AI. The standard recognises documentation produced for conformity assessment purposes and does not duplicate it.

Deference clause. Once the European Commission formally cites a harmonised standard covering a given criterion, that criterion is replaced by the requirement of the harmonised standard, with a transition period for already certified entities. The standard is meant to lead towards the law, not compete with it.

Three levels — because suppliers differ

A start-up after its first deployment and a class IIb device manufacturer after a prospective study are not the same entity and should not be measured with the same yardstick. The standard provides three levels, differing in the depth of evidence required, validity period and intensity of surveillance.

LEVEL 1

AICACT SDAI Core

The full set of information a hospital needs for an informed purchasing decision: regulatory qualification, data protection, cybersecurity fundamentals, maintenance and exit conditions, cost transparency.

Validity: 2 years
LEVEL 2

AICACT SDAI Extended

Additionally the supplier’s process maturity, quality management system, interoperability, external validation outside the supplier’s organisation, and post-deployment performance monitoring.

Validity: 3 years
LEVEL 3

AICACT SDAI Clinical

Additionally evidence from prospective validation or a clinical study with a registered protocol, validation in several independent centres, an AI system impact assessment, and tools allowing the hospital to verify performance on its own site.

Validity: 3 years

The level is not a ranking. A higher level does not mean a better solution — it means a broader scope of verified disclosure and deeper evidence. An administrative solution supporting operating theatre scheduling does not need a prospective study and should not be penalised for its absence.

How the process works

The process is predictable and described in terms of stages, deadlines and responsible persons. No undisclosed stages and no discretionary judgements.

  1. Application. The supplier identifies the solution, version, intended use and the level applied for.
  2. Application review. The Centre determines scope and effort, checks for absence of conflicts of interest, and presents the offer and contract.
  3. Assessment. Documentation review, interviews with the supplier’s team, verification of evidence in public sources, demonstration of the solution in a working environment.
  4. Technical review. Independent verification of findings by a person who did not take part in the assessment.
  5. Closing non-conformities. The supplier has a defined time to provide evidence of closure. This stage is normal, not embarrassing — that is what an audit is for.
  6. Decision. Taken by a person who took part in neither the assessment nor the technical review. A refusal always includes written reasons.
  7. Certificate issuance and entry in the public register. Together with a mark licence and rules for its use.
  8. Surveillance. Scheduled — on an annual cycle. And event-driven.

Event-driven surveillance — because a model can change between audits

A model learns, is retrained, changes version, and may start performing worse on a population that has drifted from the training data. A certificate based solely on the calendar would be a fiction in such a world.

The certificate holder must report events such as a new model version altering clinical behaviour, retraining, a change of intended use, a change of data processing location, a security incident, or a detected drop in prediction quality. Each report triggers a supplementary assessment — proportionate to the event, not a full re-audit. Failure to report an event is in itself grounds for suspending the certificate.

Who can apply

The programme is open to everyone. We apply no criterion of registered seat, legal form, size, membership of any organisation or origin of capital. Applicants may include:

Medical device or IVD manufacturers with an AI component Health software suppliers outside device regulation Providers of generative model based solutions HIS, PACS, LIS and integration platform vendors AI delivered as a subscription service Start-ups and post-pilot entities Foreign suppliers entering the Polish market Research consortia and academic spin-offs

Entities that took no part in developing the standard may also apply — on the same terms, at any stage, with no waiting period. This rule is written into the programme rules and is not subject to discretion.

What the supplier gains, and what the hospital gains

Table 2. Effects of certification on the supplier side and on the hospital side.
SupplierHospital
One set of questions instead of many different questionnaires from different facilitiesComparability of offers — two different offers finally describe the same things
Structured documentation that doubles as material for tender proceduresShorter internal pre-purchase analysis, including procurement and DPO workload
Gaps identified before the buyer or a supervisory authority identifies themKnowledge of what the supplier did not verify — not only what it advertises
Credibility with facilities where it has no references yetMaterial for risk assessment and for the facility’s management documentation
Preparation for obligations entering into force in 2027–2028Support in meeting national cybersecurity system obligations
An entry in a public register available to every buyerThe ability to check certificate status at any time, also after the contract is signed

Public register and transparency

All certificates — valid, suspended, restricted, withdrawn and expired — are entered into a free public register with full history. An entry covers the identification of the supplier, the solution and version, intended use, level, scope, dates and status.

The register is a register, not a sales catalogue. It contains no promotional materials, user reviews or performance claims. We publish the fact of certification and its scope — the remaining commercial communication is conducted by the supplier, on its own responsibility.

We also publish an annual programme report: the number of applications, certificates issued, refusals with anonymised reasons, suspensions, withdrawals and appeals. A programme that does not show how many entities it refused is not a certification programme.

A programme of good practice above the divides

Certification is a tool, not the goal. The goal is a shared language for describing AI solutions in Polish healthcare — used by hospitals, suppliers, the payer and the regulator, regardless of who agrees with whom on other matters.

AICACT SDAI is therefore part of the broader Good Practice Above the Divides Programme, which we address first to the Polish Hospital Federation — as the organisation bringing together the largest community of Polish hospitals and, at the same time, a co-author of the AI Buyer’s Guide. We invite the Federation to act as substantive partner of the programme: host of the debate, co-author of the criteria and the voice of the hospital community on the standard-setting body.

What „above the divides” means in practice

Openness of composition

The standard-setting body has balanced representation: hospitals, suppliers, the clinical community, patient organisations, independent experts. No group holds a majority. The chair is an independent person.

Openness of participation

Any interested entity may take part in work on the standard, on equal, publicly announced terms. A refusal requires written reasons and is subject to appeal.

Openness of evidence

We recognise any equivalent evidence: a certificate, report, standard or other document. We also recognise other certification schemes and publish a list of them. Competition between standards is healthy.

Transparency

Criteria, the price list and mark usage rules are published free of charge. Consultations run for no less than 45 days, and submitted comments are published together with our responses — including those we did not accept.

The principles we stand on — and one we say out loud

A certification programme run in an environment that includes buyers must have a built-in safeguard against the simplest abuse: turning the certificate into a market entry barrier. We wrote this in as an absolute prohibition, not a declaration of good will.

Prohibitions the programme imposes on itself

  • No programme body or participating organisation issues recommendations to purchase exclusively from certified suppliers or to limit cooperation with uncertified ones.
  • The programme maintains no lists of preferred or discouraged suppliers — other than the register described above.
  • The programme proposes no model award criteria granting points solely for the AICACT SDAI certificate without allowing equivalence.
  • The programme does not differentiate fees or access conditions by membership of any organisation. There is one price list, public, based solely on actual workload.
  • Hospitals retain full purchasing freedom. Not holding the certificate restricts access to no procedure and no market.

To this are added the operator’s impartiality rules. The Centre does not advise the entities it certifies — it does not design, configure or integrate their solutions, nor run deployments for them aimed at meeting the standard’s criteria. A person who in the last two years provided services to the applicant within the certified scope may not take part in its assessment or decision. Auditors’ remuneration is not linked to the number of certificates issued or to assessment outcomes.

This is not excessive caution. It is the difference between a standard that builds trust and a mark that becomes a subject of dispute two years later.

The programme development path

The standard launches as a voluntary mechanism based on public criteria and an open procedure. In parallel, we are working towards accreditation of the operator by the Polish Centre for Accreditation in the field of voluntary conformity assessment. The Act on conformity assessment and market surveillance systems expressly permits such accreditation, and precedents exist in other sectors.

Until it is obtained we say it plainly: the AICACT SDAI certificate is not a certificate from an accredited body within the meaning of public procurement law. It may, however, function as a label within the meaning of those provisions, provided the conditions of openness, transparency and independence are met — and the standard was designed to meet them. We do not promise more than we can deliver.

Scope of the Centre for Quality, Audit and Certification

AICACT SDAI is not being created in a vacuum. The Centre for Quality, Audit and Certification of Healthcare Poland is a distinct area of the Foundation’s activity, focused on examining quality, processes and compliance in healthcare. The Centre conducts audits and certification of both healthcare providers and technology suppliers, covering in particular:

  • audits of process and documentation compliance with standards for quality management, information security and business continuity;
  • cybersecurity of healthcare providers, including preparation for national cybersecurity system obligations;
  • personal data protection and data governance in the medical environment;
  • preparing medical device suppliers for conformity assessment — noting that conformity assessment itself is carried out solely by a notified body;
  • sustainability and environmental reporting for healthcare providers;
  • support in building formal evidence used in public procurement procedures;
  • training programmes and micro-credentials confirming staff competence.

Timeline and invitation

Today we announce the standard in its consultation version. The next steps:

Table 3. Stages of launching the standard and who may take part in each.
StageWhat happensWho can take part
Consultations on the standardPublication of criteria, collection of comments, publication of comments together with our responses. No less than 45 days.All interested parties — without restriction
Appointment of the standard-setting bodyConstitution of a body with balanced stakeholder representation and an independent chair.Open nominations; selection criteria public
Certification pilotThe first group of suppliers goes through the full process; pilot findings feed back into the standard.Suppliers applying in the open call
Launch of rolling admissionsCertification available on an ongoing basis, public register live.All suppliers

We invite you to take part at each of these stages. To the consultations — because a standard created without those it concerns has no right to be good. To the pilot — because the first participants genuinely shape the criteria. To the conversation — including those who believe we are doing this badly, or that someone else should be doing it. We will publish critical comments together with our reply.

Contact regarding AICACT SDAI certification

Piotr Welenc — Director of the Centre for Quality, Audit and Certification, Healthcare Poland

CISA, CGEIT, CRISC, CRMA, CDPSE, IRCA ISO 27001 Lead Auditor, IRCA ISO 22301 Lead Auditor. Member of Technical Committee KT 306 of the Polish Committee for Standardization.

phone +48 603 692 276

e-mail: global@healthcarepoland.pl

Programme documents, criteria, consultation timeline and application form: Centre website · contact form

Frequently asked questions

Does the AICACT SDAI certificate replace CE marking?
No. CE marking and a notified body certificate are the only documents confirming a medical device’s conformity with European Union law. AICACT SDAI assesses an entirely different subject: the supplier, its processes and the diligence of its disclosure. The two neither replace nor compete with each other.
Do I need the certificate in order to sell to hospitals?
No. The programme is voluntary, and its rules expressly prohibit issuing recommendations that would limit cooperation with uncertified suppliers. Hospitals retain full purchasing freedom.
Does the certificate give an advantage in a tender?
It grants no exclusivity. Public procurement law always requires the contracting authority to accept equivalent evidence. The certificate may, however, make the authority’s assessment easier and shorten the procedure, because it supplies a structured set of information in a single format.
I am a start-up after one deployment. Do I stand a chance?
Yes. The core level is designed precisely for entities that have a working product and want to organise their documentation before entering talks with larger facilities. It requires neither a prospective study nor multi-centre validation.
My solution is not a medical device. Can I apply?
Yes. The programme also covers health software outside device regulation: administrative, scheduling, documentation, transcription and workflow support systems. This is in fact the segment where the standard adds the most value, because no mandatory regime applies there.
Will you require disclosure of source code or model weights?
No. The standard requires disclosure of the information a buyer needs for an informed decision, not trade secrets. Information obtained during the assessment is confidential, and only the scope of the register entry is published.
I already hold ISO 13485, ISO 27001 and MDR documentation. Do I start from scratch?
No. The standard recognises management system certificates and documentation produced for conformity assessment purposes — to the extent they correspond to the criteria. The single technical documentation principle is written into the programme rules.
What happens when I update the model?
You report the event and a supplementary assessment is triggered, proportionate to the nature of the change — not a full re-audit. The reporting duty covers, among others, a new version altering clinical behaviour, retraining and a change of intended use.
Who takes the certification decision?
A person who took part in neither the assessment nor the technical review. A refusal always includes written reasons identifying the criteria not met and may be appealed to an independent committee. The appeal procedure is free of charge.
Can the Centre help me prepare for my own certification?
No. The operator does not advise the entities it certifies. That is a condition of impartiality. Generally available informational training, delivered on equal terms and without reference to a specific applicant, is permitted.
What does it cost?
There is one price list, public and based on actual workload — the number of people involved in developing and maintaining the solution, the number of roles the supplier performs, the number of locations, the level applied for and the scope. We give no discounts for membership of any organisation. A reduction for micro and small enterprises is provided, under a published criterion.
I disagree with the criteria. What can I do?
Submit a comment in the consultations. We publish all submitted comments together with our responses, including those we did not accept. You can also join the work on the standard — participation is open at every stage, including working groups.

Disclaimer

The AICACT SDAI certificate is not a certificate of conformity within the meaning of Article 56 of Regulation (EU) 2017/745 of the European Parliament and of the Council, nor of Article 44 of Regulation (EU) 2024/1689 of the European Parliament and of the Council. It does not constitute a conformity assessment within the meaning of European Union law, does not confirm the safety or performance of a medical device and does not replace CE marking.

Healthcare Poland Foundation is neither a notified body nor a national accreditation body. The programme does not use the concept of accreditation in relation to its own activity.

Holding the certificate is not, and cannot be, a condition of access to any market or public procurement procedure. Healthcare providers retain full freedom of purchasing decisions.

Legal status: 10 August 2026

Healthcare Poland Logo