The risk management plan is the document that defines how the risk management process will be applied to a given medical device. Section 4.4 of ISO 14971:2019 specifies its content. It is a planning and governance document — not a results document.
This distinction is fundamental and frequently overlooked. Many manufacturers draft a plan that simultaneously contains both the method and the results. The two belong in separate documents.
What the risk management plan must contain
Device scope. Description of the device concerned, intended use, variants covered. A risk management plan must clearly identify which device or family of devices it covers.
Assignment of responsibilities and authorities. Who is responsible for the risk analysis? Who approves the acceptability criteria? Who validates the control measures? Who signs off on the final risk management report? These responsibilities must be assigned by name or attached to defined functions.
Requirements for reviews. How often is the risk management file reviewed? Which events trigger a revision (reported incident, new clinical publication, modification of the device)?
Risk acceptability criteria. The risk management policy approved by top management, translated into operational criteria: a risk matrix with severity and probability thresholds, acceptability levels (acceptable, reduction desirable, unacceptable).
Hazard identification methods. Which methods will be used to identify hazards: FMEA, fault tree analysis (FTA), preliminary hazard analysis (PHA), literature review on the failure modes known for that type of device.
Link with applicable regulatory requirements. Reference to the requirements of Annex I of the MDR, the applicable harmonised standards, and the relevant MDCG guidance.
What is often wrongly included in the plan
The risk management plan is sometimes confused with the risk management file — the document that contains the results of the analysis. People then include lists of hazards, risk assessments, control measures, and verification of effectiveness.
These elements belong in the risk management file. Including them in the plan creates a hybrid document that is awkward to audit and difficult to keep up to date.
The rule is simple: the plan describes the method. The file contains the results. The report summarises the conclusions.
Calibrating to the device’s risk
A risk management plan for a Class I adhesive bandage should not have the same depth as a plan for a Class IIb defibrillator. ISO 14971 requires proportionality — the level of rigour must be matched to the device’s level of risk. A plan that is excessively complex for a simple device is just as problematic as an insufficient plan for a high-risk device.