🛡️ Risk management — ISO 14971

End-of-life risk management review: when and how to conduct it

A serious incident, a novel complaint or a product change trigger an update of the risk management file: clause 10 of ISO 14971 requires tracing each review, which the notified body then checks at surveillance.

8 min read

Risk management under ISO 14971 does not stop at market launch. Clause 10 of the standard requires the collection and analysis of information in the post-production phase, and the revision of the risk management file accordingly. This is the part of the process most often neglected in SMEs.

What clause 10 of ISO 14971 requires

The manufacturer must set up a system for the collection and review of information generated after market launch, including user complaints, post-market surveillance data, vigilance data (incidents reported by the manufacturer or by other parties), and new clinical publications on comparable devices.

This information must be analysed to determine whether it reveals hazards that were not initially identified, whether it changes the estimation of risks already identified (probability or severity differing from those initially estimated), or whether it calls into question the conclusion on the benefit/risk ratio.

The triggers for a revision of the risk management file

A revision is necessary in several situations.

A serious incident or a near-miss. An incident involving the device, even if causality is not established with certainty, must trigger a review of the corresponding failure modes in the FMEA.

A complaint identifying an unforeseen failure mode. If users report a problem not covered by the existing FMEA, the file must be updated.

A clinical publication documenting an adverse effect on comparable devices. If a hazard identified in the literature is not covered by the FMEA, it must be added and assessed.

A significant modification of the device. Any modification that affects safety or performance characteristics must trigger a revision of the risk management file for the aspects concerned.

A regulatory update. New MDCG guidance, a new harmonised standard, or an amendment to the MDR may change the risk acceptability criteria or the assessment methods.

How to document the review

Each review of the risk management file must be traced: date, input data examined, conclusions, and decisions taken (update of the FMEA, revision of the control measures, triggering of an FSCA, revision of the benefit/risk report). This traceability is what the notified body asks for during surveillance audits to verify that the risk management process is genuinely continuous and not merely initial.

Topics covered:

ISO 14971 risk management review medical device life cycle medical device risk update