The way it works is: the manufacturer of a medical device assesses the harm that can be caused by a software malfunction, and assigns it a safety classification (class A, B or C). Class A is used when no injury is possible, and class C is used when death or serious injury is possible (e.g. a surgical robot). The manufacturer also provides a "failure modes and effect analysis" document that looks at everything that could go wrong, what is the likelihood of the failure happening and what is the effect on the patient.
Based on the safety classification, IEC 62304 requires different levels of rigour. For example, the standard only requires blackbox testing for class B software, whereas for class C software it requires whitebox tests as well.
The manufacturer also needs to come up with a software development plan that ensures that all of the requirements of the standard are met, and an "argument" (supported by test reports, process documentation, source control history, etc) that the software was developed according to the plan.
And that is what the FDA audits: they look at the development process of a given feature and they check that the plan was followed. I think they rarely delve into the details of the implementation and are generally just checking that the safety arguments are sound and supported by evidence.
What does this mean?
More generally, the regulatory body will be looking for you to have a formal engineering process in place and be able to demonstrate its efficacy. Part of that will be looking for how you do hazard and risk analysis, how you handle CAPA (corrective and preventative actions in FDA-speak), how you do system trace, design history file generation, etc. etc. That you have a software development plan and can demonstrate how you follow it.
So they aren't really interested in code reviews per se, but they are very interested in how you view code reviews, how you perform them when you do, what gets documented, how you perform trace an V&V etc.
Some of the most elegant code is terse, but it takes years of education, experience, and intelligence to be able to produce that logic.
They intentionally built an unfair advantage so that they could sell it.
Here's[1] a patent they have filed towards the system. Claims 1-18 and 20 are focused on the training of the neural network. Looks like Claims 1-18 are going to be granted soon largely in that form also from looking at PAIR[2].
[1] https://patents.google.com/patent/US20160292856A1/en?q=AI,ar... [2] https://portal.uspto.gov/pair/PublicPair
In general though approval to market for particular indications is for one fixed configuration of a product, so your model parameters won't change.
All of this is in the process of being hashed out, but I expect for a while at least if you are doing on-line learning it will be in non-clinical configurations only and you will end up releasing an update periodically. Depending on the changes this may need a new 510(k) or not, but would definitely need a formal release.