Resources
Risk Management — ISO 14971
ISO 14971 risk management: hazard analysis, risk estimation and control, benefit-risk reporting and alignment with the MDR.
10 articles
Use-Related Risk Management: ISO 62366 and Its Articulation with ISO 14971
ISO 62366 identifies foreseeable use errors while ISO 14971 assesses and controls the resulting risks. A technical file that addresses usability through the generic FMEA alone remains incomplete.
End-of-life risk management review: when and how to conduct it
A serious incident, a novel complaint or a product change trigger an update of the risk management file: clause 10 of ISO 14971 requires tracing each review, which the notified body then checks at surveillance.
The MDR benefit-risk report: how to demonstrate that the benefits outweigh the risks
The most scrutinised section of the technical file collapses as soon as it settles for a claim without quantified evidence. Its conclusion must weigh quantified clinical gains against the dangers remaining after control, per ISO 14971.
The risk management plan: required content and structural mistakes
Section 4.4 of ISO 14971:2019 expects a document of method and governance, not a collection of results. Pouring hazards and assessments into it produces a hybrid that is hard to audit and to keep up to date.
Risk control measures: hierarchy, effectiveness and verification
Inherently safe design outranks protection, which outranks information: the order of the three levels is not negotiable. Clause 6.3 demands objective proof of each measure's effectiveness, and 6.4 forbids creating new risks.
ISO 14971:2019: key changes compared with the 2012 version
A now mandatory risk management policy, clinical benefits integrated into the benefit/risk analysis, overall residual risk and post-production data: four substantive changes set the 2019 edition apart from the previous one.
Hazard Identification under ISO 14971: Method, Sources and Completeness
Section 5.4 of ISO 14971:2019 requires crossing several sources to list hazards: intended use, foreseeable misuse, vigilance data. The notified body checks not the completeness of the list but the systematic nature of the approach.
Risk Management for Medical Software: IEC 62304 and ISO 14971 Together
IEC 62304 sorts software into three safety classes, from A for negligible harm to C for death or serious injury, while ISO 14971 covers the whole device: the notified body expects both approaches to be linked in the file.
Risk estimation and risk evaluation: acceptability criteria and the risk matrix
Under ISO 14971, a risk matrix only holds if its acceptability thresholds rest on data rather than a copied template. Notified bodies look above all for the same effect scored 3 on one line and 5 on another with no justification.
FMEA applied to medical devices: a relevant tool, but often poorly used
A poorly filled FMEA table is more dangerous than a blank one: it simulates an analysis while the real risks go unexamined. Overly generic failure modes, unjustified ratings and unverified controls drain the tool of its substance.
Ready to secure your regulatory compliance?
Contact us to discuss your project. We will get back to you within 24 hours.