Medical device quality engineer reviewing ISO 14971 risk management documentation in a device development lab

ISO 14971: 10 Things Every Medical Device Professional Needs to Know About Risk Management

TIPS: Medical Device GMPs
Ten things every medical device professional must understand and apply when building and maintaining a compliant ISO 14971:2019 risk management process.
2019
Current Edition
ISO 14971:2019 is the current edition, replacing 2007. The 2019 version aligns more closely with ISO 9001 and expanded risk management scope
ISO 14971:2019
ALARP
Core Risk Principle
ISO 14971:2019 removed the three-region risk matrix but strengthened the principle that residual risk must be reduced as far as possible
ISO 14971:2019, Clause 7
EU MDR
Mandatory Reference
ISO 14971:2019 is referenced as a harmonised standard under EU MDR 2017/745, making its application essential for CE marking of medical devices
EU MDR 2017/745

Risk management is not a documentation exercise. ISO 14971:2019 defines a systematic process for identifying hazards associated with a medical device, estimating and evaluating the risks that arise from those hazards, controlling those risks, and monitoring the effectiveness of the controls. Every medical device entering the EU or US market requires a compliant risk management file, and regulators are increasingly scrutinising the substance of that file rather than just its existence.

These ten tips address the most common gaps, misunderstandings, and inspection findings in ISO 14971 implementation. They are applicable to anyone involved in device design, quality, regulatory affairs, or clinical evaluation.

10 ISO 14971 Tips at a Glance
1. Understand the difference between hazard, hazardous situation, and harm
2. Build the risk management plan before design begins
3. Apply risk controls in the correct hierarchy
4. Never close a risk without verifying control effectiveness
5. Document every risk management decision with rationale
6. Include use error and abnormal use in hazard identification
7. Evaluate the benefit-risk profile, not just residual risk
8. Integrate risk management with the design and development process
9. Update the risk management file throughout the product lifecycle
10. Use post-market data to verify assumptions and close the loop
10 Things Every Medical Device Professional Needs to Know About ISO 14971
1
Understand hazard, hazardous situation, and harm as distinct concepts
ISO 14971 defines these three terms precisely and differently. A hazard is a potential source of harm. A hazardous situation is the circumstance in which people or property are exposed to a hazard. Harm is the actual injury or damage to health. The sequence hazard to hazardous situation to harm is the risk chain. Risk analysis must trace this chain, not collapse it. A common failure is labelling a hazardous situation as a hazard, which leads to incomplete risk control because the hazard itself is never addressed.
ISO 14971:2019, Clause 3
2
Build the risk management plan before design begins
The risk management plan is a required document under ISO 14971 Clause 4.4. It must define the scope of the risk management activities, the roles and responsibilities, the criteria for risk acceptability, and how risk management outputs will be verified. Writing this plan after design is complete is a retrospective exercise, not a design control. Regulators and notified bodies expect to see a plan that was used to drive design decisions, not one that was assembled to document them.
ISO 14971:2019, Clause 4.4
3
Apply risk controls in the correct hierarchy
ISO 14971 Clause 7.4 specifies that risk controls must be applied in a defined priority order: first, eliminate or reduce the risk through inherent safe design; second, add protective measures in the device or its manufacturing; third, provide safety information such as warnings, labels, and instructions. Moving to labelling without first exhausting design and protective measures is a common gap that notified bodies and FDA flag during technical file and 510(k) review.
ISO 14971:2019, Clause 7.4
4
Never close a risk without verifying control effectiveness
After implementing a risk control, ISO 14971 Clause 7.6 requires verification that the control actually achieved the intended risk reduction. This is a separate step from implementing the control. Verification may involve testing, analysis, inspection, or review of objective evidence. Risk files that move directly from control identification to residual risk estimation without a verification step are non-compliant. The verification record must be retained in the risk management file.
ISO 14971:2019, Clause 7.6
5
Document every risk management decision with rationale
ISO 14971 requires traceability throughout the risk management file: from hazard identification through risk estimation, risk evaluation, risk control, and residual risk assessment. Every conclusion, every estimate, and every acceptability decision requires documented rationale. A risk file that contains numbers without explanation, severity or probability estimates without justification, or acceptability conclusions without criteria cannot be defended during audit or regulatory review. Reviewers need to understand how you reached each conclusion, not just what you concluded.
ISO 14971:2019, Clause 4
6
Include use error and abnormal use in hazard identification
ISO 14971:2019 Annex C explicitly addresses use-related risks, and the standard requires that hazard identification consider all reasonably foreseeable misuse, not just intended use. Abnormal use is foreseeable misuse that is not intended. Use error arises from the interaction between users and device interface. Both categories must be included in hazard identification. A risk management process that only considers how the device is supposed to be used will miss many of the hazards that actually cause harm in clinical and home settings.
ISO 14971:2019, Annex C
7
Evaluate the benefit-risk profile, not just residual risk
ISO 14971:2019 Clause 9 requires a risk-benefit analysis as part of overall residual risk evaluation. If residual risks remain after applying all controls, the manufacturer must determine whether the overall residual risk is acceptable in view of the benefits. This is a structured conclusion that requires documented evidence of the benefits the device provides. Benefit-risk analysis is also a core requirement of EU MDR Annex I and is examined in clinical evaluation. A device that has uncontrolled residual risks with no benefit justification cannot reach the market.
ISO 14971:2019, Clause 9
8
Integrate risk management with the design and development process
Risk management outputs must feed directly into design inputs and design verification activities. When a risk analysis identifies a hazard that requires a design control, that control must appear in design specifications, be verified during design verification, and be traced in the technical file. Risk management that runs parallel to but separate from design development produces a risk file that describes the device on paper but does not reflect how it was actually designed. This disconnect is a primary finding during notified body technical file review.
ISO 14971:2019, Clause 4.1
9
Update the risk management file throughout the product lifecycle
ISO 14971 is not a one-time pre-market activity. The risk management file must be maintained and updated whenever changes are made to the device, its intended use, or its manufacturing process, and whenever post-market data reveals new hazards or changes the probability or severity estimates for known risks. A risk management file that was last updated at initial certification and has not been revised despite several design changes and years of post-market complaints is a significant quality system non-conformity.
ISO 14971:2019, Clause 10
10
Use post-market data to verify assumptions and close the loop
ISO 14971 Clause 10 requires that post-production information be systematically collected and reviewed. Complaint data, vigilance reports, post-market clinical follow-up results, and literature reviews all feed back into the risk management process. If post-market data shows that a hazard occurs more frequently than estimated, or that a harm is more severe than assessed, the risk management file must be updated. Closing the loop between post-market surveillance and risk management is one of the most consistently underdeveloped areas in EU MDR technical files.
ISO 14971:2019, Clause 10
ISO 14971 Compliance Checklist
Risk Management Plan and File
✓ Risk management plan in place before design begins
✓ Scope, roles, and acceptability criteria documented
✓ Hazard identification includes foreseeable misuse and use error
✓ Each risk has documented severity and probability rationale
✓ Risk controls applied in correct priority order
✓ Control effectiveness verified with objective evidence
✓ Residual risk evaluated against acceptability criteria
✓ Benefit-risk analysis completed for overall residual risk
Lifecycle and Post-Market
✓ Risk file updated at every design change
✓ Post-market complaint data feeds back into risk estimates
✓ PMCF results reviewed for new or changed risks
✓ Vigilance reports assessed for risk file impact
✓ Risk management report completed and current
✓ Traceability from hazard to control to verification maintained
✓ Risk management integrates with design history file
✓ Risk file reviewed before any new market submission
Common Mistakes in ISO 14971 Implementation
Using a risk matrix without defined acceptability criteria
Many teams create a colour-coded risk matrix without documenting what makes a risk acceptable. ISO 14971:2019 Clause 4.4 requires acceptability criteria to be defined in the risk management plan. A risk matrix with no criteria is not a compliance tool. Reviewers will ask: on what basis was this risk judged acceptable? If the answer is “it fell in the green zone,” that is not a defensible position.
Treating the risk management report as a summary, not a conclusion
ISO 14971 Clause 9 requires a risk management report that confirms the risk management plan has been executed, that overall residual risk is acceptable, and that appropriate methods are in place to collect and review post-production information. Many risk management reports simply summarise the risk file contents. A compliant report must draw explicit conclusions about overall acceptability, with reference to the benefit-risk analysis and the post-market surveillance plan.
Confusing risk control verification with design verification
Design verification confirms a device meets its specifications. Risk control verification confirms that a control measure actually reduces the risk it was intended to address. These are related but distinct. A design verification test that confirms a device meets a dimensional specification does not automatically verify that the specification eliminates the identified hazard. Risk files that cite design verification records without demonstrating the link to specific risk reduction objectives are missing a required step.
Key Takeaways
Risk management is a lifecycle activity, not a pre-market task
ISO 14971 begins before design and ends only when the device is withdrawn from the market. Post-market surveillance data must flow back into risk estimates. Design changes must trigger risk file updates. A risk management file last touched at initial certification is not a compliant document for a device that has been on the market for five years.
Labelling is the last resort, not the first line of defence
The ISO 14971 risk control hierarchy places inherent safe design first, protective measures second, and safety information including labelling and warnings third. Moving to labelling without first exhausting design options is the most common hierarchy violation found during technical file review. If a risk can be engineered out, it must be engineered out before a warning label is considered.
The risk management file must tell a story a reviewer can follow without asking questions
Every risk management decision requires documented rationale. Severity estimates, probability estimates, acceptability conclusions, and benefit-risk analyses must all be supported by evidence and explanation. A reviewer who cannot understand how you reached a conclusion from the documentation alone will raise a finding. Traceability from hazard to harm to control to verification to residual risk assessment must be complete, readable, and defensible without verbal explanation.
Frequently Asked Questions
What changed between ISO 14971:2007 and ISO 14971:2019?
The 2019 edition made several significant changes. The three-zone risk matrix (broadly acceptable, ALARP, unacceptable) was removed; the 2019 version requires manufacturers to define their own acceptability criteria without prescribing a specific model. The standard now requires evaluation of overall residual risk across all risks, not just individual risks. Alignment with ISO 9001 terminology was improved. The annexes were restructured, and Annex ZA/ZB cross-references to EU directives and MDR were updated.
Does ISO 14971 apply to software as a medical device (SaMD)?
Yes. ISO 14971 applies to all medical devices, including software. For SaMD, the companion standard IEC 62304 (Software Life Cycle Processes) references ISO 14971 for risk management activities specific to software. Risk analysis for SaMD must address software-specific hazards including algorithm failure modes, data integrity issues, cybersecurity vulnerabilities, and incorrect outputs. The risk control hierarchy applies to software design decisions in the same way it applies to hardware design.
How do I estimate probability when there is no field data for a new device?
ISO 14971:2019 Annex D addresses probability estimation and acknowledges that quantitative data may not be available for new devices. In this case, qualitative or semi-quantitative methods are permitted, including comparisons to similar devices, expert judgement, failure mode analysis, and literature review. The key requirement is that the method used and the rationale for the estimate are documented. Post-market data must be used to validate or update pre-market probability estimates once the device is in use.
What is the difference between a hazard and a risk under ISO 14971?
A hazard is the potential source of harm, such as electrical energy, sharp edges, or a toxic material. A risk is the combination of the probability that a hazardous situation occurs and the severity of the harm that could result. Risk is not the hazard itself. This distinction matters because risk estimation requires both a probability and a severity assessment. Confusing hazard and risk leads to risk files that describe hazards but never complete the estimation step required by Clause 5.
Is ISO 14971 required for FDA 510(k) submissions?
ISO 14971 is not legally mandated by FDA for 510(k) submissions, but FDA recognises it as a consensus standard and expects risk management documentation to meet its requirements. FDA guidance documents on design controls reference risk management activities that align with ISO 14971. In practice, any 510(k) with inadequate risk analysis documentation will receive a deficiency letter. International submissions, particularly for CE marking, must explicitly demonstrate ISO 14971 compliance.
What is the risk management report and when must it be completed?
The risk management report is required by ISO 14971 Clause 9. It must be completed before the device is released to market and must confirm that the risk management plan has been implemented, that overall residual risk is acceptable, and that a post-production information system is in place. The report is a conclusion document, not a summary. It must be updated whenever the risk management file is updated and must remain current throughout the product lifecycle.
How does post-market clinical follow-up (PMCF) connect to ISO 14971?
PMCF is a post-market surveillance activity required under EU MDR that generates clinical evidence about device performance in real-world use. Under ISO 14971 Clause 10, post-production information including PMCF results must be reviewed and assessed for its impact on risk estimates. If PMCF data reveals that a risk occurs more frequently, causes more severe harm, or manifests in unexpected ways, the risk management file must be updated. PMCF results that do not feed back into the risk file represent a gap in the post-market surveillance system.
Government and Regulatory Sources

Government and Regulatory Sources

  • ISO. (2019). ISO 14971:2019 Medical Devices: Application of Risk Management to Medical Devices : the primary international standard governing risk management for medical devices.
  • FDA. Design Controls Guidance for Medical Device Manufacturers : FDA guidance on design controls and risk management activities expected in 510(k) and PMA submissions.
  • European Commission. (2017). EU Medical Device Regulation (MDR) 2017/745 : the EU regulatory framework that references ISO 14971 as a harmonised standard for risk management.
  • FDA. Design Considerations for Pivotal Clinical Investigations for Medical Devices : FDA guidance on integrating risk management with clinical evidence requirements.
Related VelSafe Articles
CONTINUE LEARNING
Build a Risk Management File That Holds Up to Audit
ISO 14971 compliance is demonstrated through traceability, documented rationale, and a lifecycle approach. Find more medical device regulatory resources at velsafe.com.
Explore More Tips

Comments are closed.