Agile philosophy emphasises flexibility, adaptability and human‐centred software development. However, in medical software development, integrating regulatory compliance and safety‐critical requirements within Agile methods introduces significant tension. Compliance and safety‐critical are often treated as afterthoughts rather than integrated in a dynamic, Agile workflow, leading to costly rework and system failures. To address these challenges, this study employed a qualitative, multi‐method research design spanning four phases. Two phases involved in‐depth interviews with 30 Agile practitioners from the UK, Nigeria and India, recruited using snowball sampling. In the third phase, a novel practice‐based process model was developed. To establish the model’s practice relevance and transferability, the model was evaluated with eight Agile practitioners in the UK and Nigeria in the fourth phase. To improve credibility, the model was further validated through a case study involving Nigerian practitioners managing a Canadian medical software project. Data from each phase were inductively analysed using techniques informed by grounded theory: open coding, memoing, constant comparison and theoretical saturation. The study identified 39 Agile practices used by practitioners for medical software development. The findings reveal three novel artefacts, the compliance backlog, safety clinical backlog and misuse backlog, and two novel ceremonies: internal clinical demoing and the compliance review. In addition, three specialised roles emerged: the medical scrum master, clinical tester and regulatory expert. These practices were not theorised a priori but emerged inductively from practitioners’ interviews. Practitioners reported that regulatory compliance and safety outcomes improve when regulatory and safety‐critical requirements are embedded dynamically within Agile workflows rather than treated as external constraints. This research contributes a novel, empirically grounded taxonomy of Agile roles, ceremonies and artefacts that goes beyond merely proposing another process design; it presents an operationalised Agile workflow shaped by the real experiences of Agile practitioners in regulated medical software environments. Reflecting how compliance and safety activities are coordinated in practice, the study demonstrates the embedding of ’compliance and safety‐by‐design’ within Agile software development. We recommend using the model, as it includes novel practices for reconciling contextual influences, including weak regulatory implementation and siloed development practices.