AICACT SDAI — the AI Supplier Standard for Healthcare

Healthcare Poland Quality, Audit and Certification Centre

Announcing the standard.
An open invitation to all — across the divides

A voluntary certification programme for suppliers of artificial intelligence solutions to healthcare providers. The standard is in its consultation version — participation is open to suppliers, hospitals, clinicians, patient organisations and the regulator.

10

domains of criteria — exactly as many as there are questions in the AI Buyer’s Guide

3

certificate levels: Basic, Extended, Clinical

45

days minimum period of public consultation

0

purchasing recommendations — an absolute prohibition in the rules

Artificial intelligence entered Polish hospitals faster than the language in which to discuss it across a procurement table came into being.

A director signing a contract for an AI solution receives a presentation, a list of references and an assurance that “the algorithm is ninety-something per cent accurate”. What they do not receive is an answer to the questions they would ask about any other purchase of comparable weight: on what population was it tested, what happens when the data is incomplete, who answers for an erroneous recommendation, what it really costs in the third year, and what becomes of the data when the contract ends.

The Healthcare Poland Foundation announces AICACT SDAI — the AI Supplier Standard for Healthcare. It is a voluntary certification programme run by the Healthcare Poland Quality, Audit and Certification Centre, with a single aim: that a hospital should hold the full set of information before signing a contract, and that a supplier should face one set of questions instead of twenty different questionnaires from twenty different facilities.

Consultation on the standard opens today, and we invite everyone to take part — suppliers of AI solutions, hospitals, learned societies, professional self-governing bodies, patient organisations, academic centres and regulators. No exceptions, no membership test, no division into technological camps.


Why now

Three things have converged.

1. EU law has ceased to be a prospect

The Artificial Intelligence Regulation has applied in stages since 2025. The transparency obligations apply from 2 August 2026. The obligations for high-risk systems carry fixed dates: December 2027 for one group of applications and August 2028 for AI embedded in medical devices. These are not conditional dates.

2. A gap has opened that someone must fill

Until August 2028 there is no statutory certification of AI solutions embedded in medical devices. Technical standards are still being drafted. Hospitals are buying now and suppliers are selling now. It is better that a voluntary mechanism should arise in Poland than that a finished one should be imported.

3. Hospitals face a deadline

The window for entity registration in the national cybersecurity system closes at the beginning of October 2026, and risk management measures must be implemented by April 2027. This is no longer a matter of good practice but of the responsibility of a facility’s board.


The problem we are solving: information asymmetry

The market for AI solutions in healthcare today has a classic design fault. The supplier knows everything about its product: what data it was trained on, where it performs worse, how it behaves with an atypical patient, what maintenance costs after the third year. The buyer knows almost nothing and — worse — often does not know what to ask.

This asymmetry is nobody’s bad faith. It follows from the absence of an agreed format for disclosure.

AICACT SDAI: the premise of the programme

Every hospital asks differently, every supplier answers differently, and comparing two offers side by side is sometimes impossible because they describe entirely different things. Both sides can suffer: the hospital deploys a solution whose limitations it did not know, while a scrupulous supplier loses to one that promises more, because nobody verified whether the promise was matched by evidence.

AICACT SDAI addresses precisely that problem. Not the problem of algorithm quality — conformity assessment and clinical investigation exist for that. It addresses the problem of buyer knowledge: whether the supplier discloses the full set of information, whether it does so reliably, and whether an independent auditor can confirm it.


What AICACT SDAI is

AICACT SDAI is a voluntary certification mark issued by the Healthcare Poland Quality, Audit and Certification Centre to suppliers of solutions based on artificial intelligence intended for entities carrying out medical activity.

The subject of assessment is the supplier, its processes, and the completeness and reliability of the documentation it discloses to the buyer — in relation to a specific solution, in a specific version, and for a specific intended use. The auditor checks whether the supplier holds what it declares: a description of the target population, a validation report prepared in accordance with a recognised reporting methodology, a data processing map, an incident response plan, a procedure for handling an erroneous recommendation, exit conditions, and a full life-cycle cost calculation.

What AICACT SDAI does not do — and this matters just as much

  • It does not confirm the safety or performance of a medical device. Those are confirmed solely by a conformity assessment carried out by a notified body and by the CE marking.
  • It does not replace the CE marking and is not a conformity assessment within the meaning of European Union law.
  • It is not an accreditation. Accreditation in healthcare is granted by the minister responsible for health; accreditation of conformity assessment bodies is granted by the Polish Centre for Accreditation. Healthcare Poland is neither institution and does not use that term of its own activity.
  • It does not adjudicate on clinical effectiveness of a solution, nor on the justification for using it with a particular patient. Clinical assessment of outcomes remains with the hospital and its medical staff.
  • It confers no exclusivity or preference in any public procurement procedure. Procurement law always requires the contracting authority to admit equivalent evidence — and so it should.

We state this plainly, at the outset, rather than in small print at the end. A certificate that promises more than it can confirm is worse than no certificate at all — because it creates a false sense of security in the person who makes a decision affecting patients on the strength of it.


Where the criteria come from

We did not build the standard from scratch, and we regard that as a merit rather than a short cut.

The substantive basis is the AI Buyer’s Guide for healthcare — a document prepared by experts of the Coalition for AI and Innovation in Health, the wZdrowiu team and the Polish Federation of Hospitals. The Guide organises the purchasing decision into ten questions a director should ask before signing a contract. The AICACT SDAI standard has ten domains of criteria, and each corresponds to exactly one question in the Guide — so the certificate answers directly the questions a hospital will ask in any case.

DomainWhat it covers
D1The rationale for using AI, the intended use, the target population, and the role of the human in the decision
D2Completeness and currency of regulatory documentation
D3Reliability of reporting evidence of effectiveness, and disclosure of limitations
D4Operational deployability, interoperability, integration with hospital systems
D5The training package and support for staff competence
D6Fairness of performance across patient subgroups, and handling of an erroneous recommendation
D7Data protection and lawfulness of processing
D8Cybersecurity and support for compliance with the national cybersecurity system
D9Maintenance, model change management, exit conditions and continuity
D10Cost transparency and freedom from supplier lock-in

The methodological layer of the standard rests on recognised international frameworks: the standards on certification bodies and artificial intelligence management systems, health software standards, international consensus guidance for trustworthy AI in medicine, and recognised reporting checklists for studies involving artificial intelligence. The standard recognises documentation produced for conformity assessment and does not duplicate it — a supplier that has already travelled the regulatory route does not do the same work twice.

The standard contains a migration clause: once the European Commission formally cites a harmonised standard covering a given criterion, that criterion is replaced by the requirement of the harmonised standard, with a transitional period for entities already certified.

The standard is meant to lead towards the law, not to compete with it.


Three levels — because suppliers differ

A start-up after its first deployment and a manufacturer of a class IIb device after a prospective study are not the same entity and should not be measured by the same yardstick. The standard provides for three levels, differing in the depth of evidence required, the period of validity and the intensity of surveillance.

LEVEL 1

Basic

The full set of information a hospital needs for an informed purchasing decision: regulatory qualification, data protection, cybersecurity fundamentals, maintenance and exit conditions, cost transparency.

Validity: 2 years
Documentary review once a year

LEVEL 2

Extended

Additionally the supplier’s process maturity, quality management system, interoperability, external validation outside the supplier’s organisation, and post-deployment performance monitoring.

Validity: 3 years
Annual surveillance audit and event-driven surveillance

LEVEL 3

Clinical

Additionally evidence from prospective validation or a clinical study with a registered protocol, validation at several independent centres, an AI system impact assessment, and tools allowing the hospital to verify the solution’s performance on its own site.

Validity: 3 years
Annual and event-driven surveillance, and review of monitoring data

The level is not a ranking. A higher level does not mean a better solution — it means a wider scope of verified disclosure and deeper evidence. An administrative solution supporting operating theatre scheduling does not need a prospective study and should not be penalised for the absence of one. Reading the level, a hospital should learn what has been checked, not who is better.


How the process works

The process is predictable and described stage by stage, with deadlines and responsible persons. No undisclosed stages and no discretionary assessments.

01

Application

The supplier identifies the solution, the version, the intended use and the level applied for.

02

Application review

The Centre establishes scope and effort, checks for absence of conflict of interest, and presents an offer and contract.

03

Assessment

Review of documentation, discussions with the supplier’s team, verification of evidence against public sources, and demonstration of the solution in a working environment.

04

Technical review

Independent verification of the findings by a person who took no part in the assessment.

05

Closure of non-conformities

The supplier has a set period to present evidence of closure. This stage is normal, not a mark of shame — it is what an audit is for.

06

Decision

Taken by a person who took part neither in the assessment nor in the technical review. A refusal always carries written reasons.

07

Certificate and register

Issue of the certificate, entry in the public register, licence to use the mark and the rules governing its use.

08

Surveillance

Planned on an annual cycle, together with event-driven surveillance — described below.

Event-driven surveillance — because a model can change between audits

This is what distinguishes certification of AI solutions from classic product certification. A model learns, is retrained, changes version, and may begin to perform worse on a population that has shifted relative to the training data. A certificate based on the calendar alone would be a fiction in such a world.

The certificate holder is therefore obliged to report events such as a new model version that changes its clinical behaviour, retraining, a change of intended use, a change in the location of data processing, a security incident, or a detected fall in prediction quality. Each such report triggers a supplementary assessment — proportionate to the nature of the event, not a full audit from the beginning.

Failure to report an event is itself a ground for suspending the certificate.


Who may apply

The programme is open to all. We apply no criterion of registered office, legal form, size, membership of any organisation, or origin of capital. Applications may come from:

  • a manufacturer of a medical device or in vitro diagnostic device with an AI component — imaging, diagnostics, clinical decision support, patient monitoring;
  • a supplier of health software outside the scope of device regulation — administrative systems, resource planning, triage, records, transcription, billing support;
  • a supplier of solutions based on generative models in a medical environment — documentation assistants, summaries, handling of patient enquiries;
  • a supplier of HIS, PACS and LIS systems and integration platforms adding an AI component to an existing product;
  • a company providing AI as a subscription service, including with retraining and monitoring on the supplier’s side;
  • a start-up or an entity past pilot stage seeking to put its documentation in order before approaching larger facilities;
  • a foreign supplier entering the Polish market and needing a disclosure format intelligible to a Polish buyer;
  • a research consortium or an entity commercialising the output of a scientific project.

Entities that took no part in developing the standard may apply on the same terms, at any stage, with no waiting period. That principle is written into the rules and is not subject to discretion.


What the supplier gains, and what the hospital gains

Supplier

  • One set of questions instead of many different questionnaires from different facilities
  • Ordered documentation that doubles as material for tender procedures
  • Gaps identified before the buyer or a supervisory authority identifies them
  • Credibility with facilities where it has no references yet
  • Preparation for the obligations arriving in 2027–2028
  • An entry in a public register accessible to every buyer

Hospital

  • Comparability of offers — two different bids finally describe the same things
  • A shorter pre-purchase analysis of its own, including the work of the procurement department and the data protection officer
  • Knowledge of what the supplier has not checked — not only of what it advertises
  • Material for risk assessment and for the facility’s governance documentation
  • Support in meeting the obligations arising from the national cybersecurity system
  • The ability to check certificate status at any time, including after the contract is signed

Public register and transparency

All certificates — valid, suspended, restricted, withdrawn and expired — go into a public register available free of charge, with history retained. An entry covers the identification of the supplier, the solution and version, the intended use, the level, the scope, dates and status.

The register is a register, not a sales catalogue. It contains no promotional material, no user reviews and no claims of effectiveness. We publish the fact of certification and its scope — the rest of commercial communication is for the supplier, on its own responsibility and in accordance with the rules that bind it.

A programme that does not show how many applicants it has refused is not a certification programme.

The annual report on the programme’s operation covers the number of applications, certificates issued, refusals with anonymised reasons, suspensions, withdrawals and appeals.

A good-practice programme across the divides

Certification is an instrument, not an end. The end is that Polish healthcare should acquire a common language for describing AI solutions — used by hospitals, suppliers, the payer and the regulator, regardless of who agrees with whom on other matters.

AICACT SDAI is therefore part of a wider Good Practice Across the Divides Programme, which we address first of all to the Polish Federation of Hospitals — as the organisation bringing together the largest community of Polish hospitals and, at the same time, a co-author of the AI Buyer’s Guide. We invite the Federation to act as the programme’s substantive partner: host of the debate, co-author of the criteria and the voice of the hospital community on the body that sets the standard.

What “across the divides” means in practice

Openness of composition

The body that sets the criteria has balanced representation: hospitals, suppliers, the clinical community, patient organisations and independent experts. No group holds a majority. The chair is independent.

Openness of participation

Any interested entity may take part in work on the standard — including in the preparatory phase and in working groups — on equal, publicly announced terms.

Openness of evidence

We accept any equivalent evidence: a certificate, a report, a standard or another document. We also recognise other certification schemes and publish a list of them. Competition between standards is healthy.

Openness of record

The criteria, the price list and the rules on use of the mark are published free of charge. Consultation runs for no less than 45 days, and the comments received are published together with our responses.


The principles we stand on — and one we state out loud

A certification programme run in an environment that includes buyers must have a safeguard built in against the simplest abuse: turning the certificate into a barrier to market entry. We have written this as an absolute prohibition, not as a declaration of good will.

Prohibitions the programme imposes on itself

  • No organ of the programme, and no organisation participating in it in that capacity, formulates or disseminates recommendations advising purchase solely from certified suppliers or restricting cooperation with uncertified suppliers.
  • The programme maintains no lists of preferred or discouraged suppliers — beyond the register described above.
  • The programme proposes no model award criteria granting points solely for an AICACT SDAI certificate without admitting equivalence.
  • The programme does not differentiate fees or conditions of access by membership of any organisation. There is one price list, public, based solely on actual effort.
  • Hospitals retain full freedom in purchasing. The absence of a certificate restricts access to no procedure and to no market.
Operator impartiality rules — expand

The Centre does not advise the entities it certifies — it does not design their solutions, configure or integrate them, or carry out deployments for them aimed at meeting the standard’s criteria.

A person who has provided services to an applicant within the scope covered by certification in the past two years may take no part in its assessment or in the decision. Auditors’ remuneration is not linked to the number of certificates issued or to the outcome of an assessment.

This is not excessive caution. It is the difference between a standard that builds trust and a mark that becomes the subject of dispute two years later.


The programme’s development path

The standard starts as a voluntary mechanism resting on published criteria and an open procedure. In parallel we are working towards the operator obtaining accreditation from the Polish Centre for Accreditation for voluntary conformity assessment. The Act on conformity assessment and market surveillance systems expressly allows such accreditation, and the Polish Centre for Accreditation accredits certification bodies against private schemes — precedents exist in other sectors.

Until it is obtained we state plainly: the AICACT SDAI certificate is not a certificate of an accredited body within the meaning of the public procurement rules. It may, however, function as a label within the meaning of those rules, provided the conditions of openness, transparency and independence are met — and the standard has been constructed so as to meet them.

We do not promise more than we can deliver.


The scope of the Quality, Audit and Certification Centre

Centrum Audytu i Certyfikacji Healthcare Poland

AICACT SDAI does not arise in a vacuum. The Healthcare Poland Quality, Audit and Certification Centre is a distinct area of the Foundation’s activity, focused on examining quality, processes and conformity in healthcare. The Centre conducts audits and certification of both healthcare providers and technology suppliers.

  • audits of process and documentation conformity with standards on quality management, information security and business continuity;
  • the cybersecurity of healthcare providers, including preparation for the obligations arising from the national cybersecurity system;
  • personal data protection and data governance in a medical environment;
  • preparing suppliers of medical devices for conformity assessment — subject to the reservation that conformity assessment itself is conducted solely by a notified body;
  • sustainability and environmental reporting by healthcare providers;
  • support in building the formal evidence used in public procurement procedures;
  • training programmes and micro-credentials confirming staff competence.

Timetable and invitation

We publish the standard today in its consultation version. The next steps:

StageWhat happensWho may take part
Consultation on the standardPublication of the criteria, collection of comments, publication of comments together with our responses. No less than 45 days.All interested parties — without restriction
Establishment of the standard-setting bodyConstitution of a body with balanced stakeholder representation and an independent chair.Applications open; selection criteria public
Certification pilotA first group of suppliers goes through the full process; the lessons from the pilot feed back into the standard.Suppliers entered through open application
Launch of rolling applicationsCertification available on an ongoing basis, public register live.All suppliers

We invite participation at each of these stages. To the consultation — because a standard created without those it concerns has no right to be good. To the pilot — because the first participants have real influence on the shape of the criteria. And to the conversation — including those who think we are doing this badly, or that someone else should be doing it. Critical comment will be published together with our reply.

Contact on AICACT SDAI certification

Piotr Welenc — Director of the Healthcare Poland Quality, Audit and Certification Centre

CISA, CGEIT, CRISC, CRMA, CDPSE, IRCA ISO 27001 Lead Auditor, IRCA ISO 22301 Lead Auditor. Członek Komitetu Technicznego KT 306 Polskiego Komitetu Normalizacyjnego.

The programme documents, criteria, consultation timetable and application form are published at healthcarepoland.pl.

Centrum Audytu i Certyfikacji Healthcare Poland — kontakt: M: +48 603 692 276, E: centrum@healthcarepoland.pl

Disclaimer

The AICACT SDAI certificate is not a certificate of conformity within the meaning of Article 56 of Regulation (EU) 2017/745 of the European Parliament and of the Council, nor of Article 44 of Regulation (EU) 2024/1689. It does not constitute a conformity assessment within the meaning of European Union law, does not confirm the safety or performance of a medical device and does not replace the CE marking.

The Healthcare Poland Foundation is neither a notified body nor a national accreditation body. The programme does not use the term accreditation of its own activity.

Holding the certificate is not, and cannot be, a condition of access to any market or to any public procurement procedure. Healthcare providers retain full freedom in their purchasing decisions.

Legal position as at 10 August 2026.