Risk management for medical software cannot be carried out using the tools of ISO 14971 alone. IEC 62304 — the standard on the medical software life cycle — introduces its own approach to risks linked to software defects. The two standards are complementary and must be articulated within the technical documentation.
What IEC 62304 brings to software risk management
IEC 62304 classifies software into three safety classes according to the severity of the consequences of a software defect for the patient.
Class A: no injury or negligible injury. Class B: non-serious injury. Class C: death or serious injury.
This classification determines the level of rigour required in the development life cycle: testing, documentation, requirements traceability, code reviews, configuration management. The higher the class, the more formalised the activities and the greater the documented evidence expected.
The IEC 62304 safety classification is distinct from the MDR classification (Rule 11), but related: a Class IIb SaMD under MDR very often implies Class B or C software under IEC 62304.
How ISO 14971 and IEC 62304 interact
ISO 14971 assesses the risks associated with the device as a whole — including risks linked to software defects. IEC 62304 determines the level of rigour in software development needed to control those risks.
The link between the two: the IEC 62304 activities (verification testing, validation testing, code reviews, anomaly management) are software risk control measures within the meaning of ISO 14971. Their effectiveness helps reduce the probability of occurrence of the risks linked to software defects identified in the FMEA.
In the technical documentation, this articulation must be documented: the risks linked to software defects identified in the ISO 14971 FMEA must be linked to the IEC 62304 activities that control them. A notified body reviewing a SaMD file verifies this consistency.
What notified bodies expect in practice
A well-constructed medical software file contains: an FMEA covering the risks linked to software defects, with reference to the IEC 62304 activities as control measures; the IEC 62304 classification documentation with justification of the chosen class level; the verification and validation test results documented in accordance with IEC 62304; and a configuration management report demonstrating the traceability of software requirements throughout the development life cycle.