LATEST NEWS - GMP, ISO & INDUSTRY BLOGS

ISO 14971 Risk Management 101

ISO 14971 Risk Management 101

September 09, 20269 min read

ISO 14971 is the international standard for applying risk management to medical devices. ISO 14971:2019, the third edition, remains the current edition and was confirmed by ISO in 2025. It applies to medical devices, including software as a medical device and in vitro diagnostic medical devices, and establishes a systematic process for identifying hazards, estimating and evaluating risks, implementing risk controls, and monitoring the effectiveness of those controls throughout the device life cycle.

Need Support with ISO 14971? Talk to Us Today

For organisations developing or manufacturing medical devices, understanding ISO 14971 is essential because risk management is not simply a document produced before regulatory submission. It is an ongoing process that should influence design decisions, manufacturing controls, verification and validation activities, labelling, usability considerations, post-market activities, and changes made throughout the life of the device.

What Does ISO 14971 Actually Require?

At its core, ISO 14971 establishes a structured risk management process.

The process begins with defining how risk management will be conducted for the particular device. The manufacturer establishes a risk management plan and defines appropriate criteria for evaluating risk. The process then moves through risk analysis, risk evaluation, risk control, evaluation of residual risk, risk management review, and production and post-production activities.

This distinction is important because risk management is considerably broader than creating a risk matrix.

Risk analysis is only one component of the overall process. The objective is to establish a continuing body of evidence showing that risks have been identified, evaluated, controlled where necessary, and monitored appropriately.

The standard also requires manufacturers to establish objective criteria for risk acceptability. ISO 14971 does not prescribe universal acceptable risk levels because what constitutes acceptable risk depends on the particular device, its intended use, and the applicable context.

Start With Intended Use

Risk management cannot be meaningful without a clear understanding of what the medical device is intended to do.

Intended use establishes the context in which hazards and hazardous situations need to be considered. The manufacturer also needs to consider reasonably foreseeable misuse.

This means the risk analysis should not be limited to the idealised way in which a device is supposed to be used. Users may misunderstand instructions, operate a device differently than anticipated, combine it with other equipment, fail to perform required maintenance, or otherwise interact with it in foreseeable ways.

A clear description of intended use therefore provides the foundation for identifying the characteristics of the device that could affect safety.

Identify Hazards and Hazardous Situations

Hazard identification is a central part of ISO 14971 risk analysis.

A hazard is a potential source of harm, while a hazardous situation describes circumstances in which people, property, or the environment are exposed to one or more hazards. Harm is the resulting injury or damage.

The distinction matters because simply listing hazards does not necessarily establish how harm could occur.

A useful analysis considers the sequence of events that could lead from a device characteristic or failure through a hazardous situation to harm. This helps the manufacturer identify appropriate points at which risk can be controlled.

Depending on the device, considerations may include electrical energy, mechanical hazards, radiation, biological hazards, biocompatibility, usability, software behaviour, data and systems security, environmental conditions, and other characteristics relevant to safety. ISO specifically identifies areas such as biocompatibility, electricity, moving parts, radiation, usability, and data and systems security within the life-cycle risk management process.

Estimate and Evaluate Risk

Once hazards and hazardous situations have been identified, the manufacturer estimates the associated risks and determines whether those risks require further control.

ISO 14971 defines risk in terms of the combination of the probability of occurrence of harm and the severity of that harm. However, the practical application of risk estimation depends on the characteristics of the device and the information available.

The manufacturer should have a defined and consistently applied methodology rather than changing its approach from one risk assessment to another.

Risk evaluation then compares estimated risk against the manufacturer's predefined acceptability criteria.

This is one reason why the risk management plan matters. Decisions about acceptability should not be improvised after a particular risk has already been identified.

Risk Control Comes Before Documentation

The purpose of risk management is not to produce an impressive-looking risk file. It is to reduce risks associated with the device to an appropriate level.

Where risk reduction is required, the manufacturer identifies and evaluates risk control options and implements appropriate measures.

Risk controls can take different forms. They may involve inherent safety by design, protective measures within the device or manufacturing process, or information provided for safety.

The hierarchy is important because relying solely on warnings or instructions may not provide the same level of risk reduction as eliminating a hazardous condition through design.

After controls are implemented, the manufacturer must assess the resulting residual risk. It is therefore not sufficient to identify a control and record it as complete. The organisation needs evidence that the control was implemented and that it achieves the intended risk reduction.

Consider Risks Introduced by Risk Controls

Risk controls themselves can introduce new hazards or create new risks.

For example, modifying a device to reduce one hazard could introduce another failure mode, affect usability, alter performance, or create additional maintenance requirements.

ISO 14971 therefore requires consideration of risks arising from risk control measures.

This is an important safeguard against treating risk controls as automatically beneficial. Every significant design or process change should be considered in the context of the complete risk profile rather than evaluated in isolation.

Residual Risk and Benefit-Risk Analysis

After risk controls have been implemented, residual risks remain.

The manufacturer evaluates whether the remaining risks meet the established acceptability criteria. Where residual risk is not acceptable, further controls may be required.

ISO 14971 also includes benefit-risk analysis. Where a residual risk is not acceptable according to the established criteria and further risk control is not practicable, the manufacturer considers whether the benefits of the intended use outweigh that residual risk.

This decision needs appropriate justification and supporting evidence. Benefit-risk analysis should not become a mechanism for routinely accepting poorly controlled risks.

The objective remains to reduce risk as far as required through appropriate controls before relying on a benefit-risk determination.

Overall Residual Risk

Looking at individual risks is not enough.

A medical device can have numerous individual risks, each assessed separately, while the combined residual risk profile still requires consideration.

ISO 14971 therefore includes evaluation of overall residual risk.

This requires the manufacturer to consider the totality of the residual risks associated with the device and determine whether the overall risk is acceptable in relation to the intended use and anticipated benefits.

This broader evaluation is particularly important for complex devices where multiple individual risks may interact or where several residual risks affect the same user population.

The Risk Management File

The risk management process generates objective evidence that the required activities have been performed.

The resulting documentation is commonly maintained within a risk management file. The file provides traceability between the risk management plan, risk analysis, identified risks, risk controls, verification of controls, residual risk evaluations, and other relevant outputs.

The exact structure of the documentation may differ between organisations and devices, but the underlying principle is consistency and traceability.

A reviewer should be able to understand what risks were identified, how they were evaluated, what controls were selected, how those controls were verified, and why the resulting residual risks were considered acceptable.

Risk Management Does Not End at Product Launch

One of the most important concepts in ISO 14971:2019 is that risk management continues throughout the device life cycle.

Production and post-production information can reveal new hazards, previously underestimated risks, unexpected failure modes, or problems associated with actual use.

Relevant information can come from sources such as complaints, service data, manufacturing information, returned products, nonconformities, surveillance activities, and other post-market information.

That information needs to be reviewed and considered within the risk management process.

If new evidence changes the understanding of a risk, the relevant risk analysis and controls may need to be reconsidered.

Common Mistakes in ISO 14971 Implementation

One common mistake is treating risk management as a regulatory document-generation exercise. A risk file that is disconnected from engineering, manufacturing, usability, clinical information, and post-market experience is unlikely to provide an effective representation of actual device risk.

Another problem is excessive reliance on numerical risk scores. Numbers can support structured decision-making, but a numerical score does not automatically demonstrate that an assessment is scientifically justified.

Weak hazard identification is another recurring issue. If the initial analysis does not adequately consider reasonably foreseeable misuse, reasonably foreseeable sequences of events, or relevant device characteristics, subsequent calculations may simply provide false precision.

Risk controls also need careful attention. Recording a control without demonstrating its implementation and effectiveness leaves an important gap in the evidence.

Finally, risk management should not become static after design verification or regulatory submission. New information can change the risk profile, and the system needs to be capable of responding.

Building an Effective ISO 14971 Process

A robust ISO 14971 process connects risk management with the technical and quality activities that generate meaningful risk information.

Engineering should be able to use risk information when making design decisions. Verification and validation should provide evidence relevant to risk controls. Manufacturing should understand process-related hazards and controls. Usability activities should inform risks associated with use. Post-market information should feed back into the risk management process.

This creates a functioning system rather than a collection of independent documents.

ISO 14971:2019 provides the framework, but effective implementation depends on how well that framework is integrated into the development and life-cycle management of the device.

The standard is therefore best understood not as a risk assessment template, but as a structured method for making and documenting safety-related decisions.

For organisations developing medical devices, the fundamentals are straightforward: understand the intended use, identify hazards and hazardous situations, estimate and evaluate risk, implement appropriate controls, verify those controls, evaluate residual risk, consider overall residual risk, and continue monitoring relevant information throughout the device life cycle.

That disciplined process is the foundation of ISO 14971 risk management. It provides a consistent framework for turning information about hazards and potential harm into documented decisions, effective controls, and ongoing oversight of device safety.

ISO 14971 Risk Management 101
Back to Blog

Resources: QSN Academy · Blog · Webinars · eBooks · Scorecards · Book

Connect: LinkedIn (QSN) · LinkedIn (QSN Academy) · Linkedin (Dr Kathy Walsh) · Facebook · Email at info@qualitysystemsnow.com.au · Contact Us

Legal: Privacy Policy · Terms & Conditions · Complaints Procedure · Sitemap · QSN ABN 42 621 334 754