🛡️ Risk management — ISO 14971

Risk estimation and risk evaluation: acceptability criteria and the risk matrix

Under ISO 14971, a risk matrix only holds if its acceptability thresholds rest on data rather than a copied template. Notified bodies look above all for the same effect scored 3 on one line and 5 on another with no justification.

8 min read

Risk estimation and risk evaluation are the steps that follow hazard identification in the ISO 14971 process. Estimation quantifies the risk. Evaluation compares it against the acceptability criteria to decide whether a risk control measure is necessary. Both steps depend entirely on the quality of the acceptability criteria defined in the risk management policy.

The two components of risk according to ISO 14971

ISO 14971 defines risk as the combination of two parameters: the probability of occurrence of a harm and the severity of that harm.

Severity is assessed according to the impact on the health of the patient or user: from imperceptible harm to a fatal outcome. ISO 14971:2019 and the technical report ISO/TR 24971 propose indicative severity scales, which each manufacturer adapts to its own context.

Probability is assessed according to the likelihood that the sequence of events leading to the harm occurs under real conditions of use. It takes into account the probability of occurrence of the failure mode, the probability that this failure mode leads to a hazardous situation, and the probability that the hazardous situation leads to the harm.

How to build a defensible risk matrix

The risk matrix visualises the severity/probability combination and defines the acceptability zones. Its construction must rest on documented foundations, not on arbitrary choices.

Step 1: define the severity levels. How many levels? Three, four or five levels are common. The criteria for each level must be clear and distinct, with reference examples.

Step 2: define the probability levels. Same principles. The levels must be calibrated to the device’s context and its expected usage base — the “rare” probability for a device used 100 times a year is not the same as for a device used 100,000 times a year.

Step 3: define the acceptability zones. The green zone (risk acceptable as is), the orange zone (reduction desirable where practicable), the red zone (unacceptable risk, control measures mandatory). The boundaries between these zones must be justified.

Step 4: document the basis of the risk policy. Which references guided these choices? Epidemiological data on similar devices, sector vigilance data, industry standards? This documentation is what makes the matrix defensible before an assessor.

What notified bodies check

The notified body checks that the matrix is consistent with the device’s risk level, that the acceptability thresholds are justified (not simply copied from a template), and that the matrix is applied consistently throughout the FMEA — that is, that the same failure mode would receive the same rating from one row to the next.

An inconsistency in the application of the matrix — the same type of effect rated 3 in one row and 5 in another without justification — signals an FMEA filled in by several people without coordination, or without genuine reflection on the criteria.

Topics covered:

ISO 14971 risk matrix medical device risk acceptability criteria medical device risk evaluation