Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

I

ISO/IEC 42001 (AI management system)

ISO/IEC 42001:2023 is the international standard specifying requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (AIMS) within an organisation. Published in December 2023, it is the first certifiable management-system standard dedicated to AI, built on the same high-level structure as ISO 9001 (quality), ISO/IEC 27001 (information security) and ISO/IEC 27701 (privacy information management), which allows integration with existing certified systems.

The standard requires the organisation to understand its context and the expectations of interested parties, define an AI policy and objectives, assign roles and responsibilities (an AI Officer function in practice), assess and treat AI-specific risks and impacts, provide resources and competence, control the AI lifecycle from design through deployment and decommissioning, manage third-party components and data, monitor performance, conduct internal audits and management reviews, and drive continual improvement. Annex A lists 38 controls in areas such as AI policies, internal organisation, resources for AI systems, impact assessment, lifecycle management, data for AI systems, information for interested parties, use of AI systems and third-party relationships; Annex B gives implementation guidance, and the companion standards ISO/IEC 42005 (AI system impact assessment) and ISO/IEC 23894 (AI risk management) supply methods.

ISO/IEC 42001 is not a presumption of conformity with the EU AI Act, which will rely on harmonised European standards developed by CEN-CENELEC JTC 21, but it maps closely to the Act's quality management system requirement for providers of high-risk AI systems (Art. 17), to risk management (Art. 9), data governance (Art. 10), human oversight (Art. 14) and post-market monitoring, and it gives deployers a framework for their Art. 26 duties. For life sciences companies, certification demonstrates to regulators, notified bodies, partners and investors that AI governance is systematic, and integrates naturally with the MDR quality management system (ISO 13485) and the information security management system under ISO/IEC 27001. iliomad, itself ISO 27001 and 9001 certified, supports AIMS implementation as part of its AI compliance services.