Risk Management
ISO 14971: Risk Management for Medical Devices
ISO 14971 describes the process a manufacturer uses to identify hazards, estimate and evaluate risks, control them and monitor whether the controls work over the device's whole life. It is the reference point for device risk management, and under Compliance Program 7382.850 FDA inspections start from the firm's risk management documentation.
At a Glance
- Standard
- ISO 14971
- Subject
- Risk Management for Medical Devices
- Group
- Risk Management
- Industries
- 19 industry guides reference it
A plain-language summary of scope, not the standard itself. Buy the current edition from the publisher and check which edition your auditor or market expects.
What It Covers
The standard defines a process, not acceptable risk levels. The manufacturer sets its own policy for risk acceptability, writes a risk management plan for each device, identifies intended use and reasonably foreseeable misuse, identifies hazards and hazardous situations, then estimates and evaluates the associated risks. Risks that aren't acceptable are controlled, in priority order, through inherent safety by design, protective measures, and information for safety.
Once controls are implemented and verified, the manufacturer evaluates the residual risk of each hazardous situation and the overall residual risk, weighing it against medical benefit where needed. A review before commercial release confirms the plan was carried out. The process continues after launch: production and post-production information, such as complaints, service data and published literature, is collected and fed back into the risk analysis.
ISO 14971 applies to all medical devices, including software and IVDs, and most other device standards connect to it. Biological evaluation, usability engineering, software life cycle and electrical safety standards all expect a risk management process that conforms to it. The risk management file is the set of records that shows the process was actually followed.
Who It Applies To
- Manufacturers of any medical device, including software as a medical device and IVDs
- Teams preparing premarket submissions that rely on risk documentation
- Firms responding to observations about design, CAPA or complaint risk assessment
- Contract manufacturers and suppliers whose processes affect device risk
What Auditors Check
Risk Management Plan
A plan for each device covering scope, life cycle phases, responsibilities, criteria for risk acceptability, and the verification and review activities.
Risk Management File
One coherent set of records, not scattered spreadsheets, showing hazard analysis, risk estimates, evaluations and decisions for the current design.
Traceability From Hazards to Verification
A clear trace from each hazard and hazardous situation to its risk controls, and from each control to verification of its implementation and effectiveness.
Residual Risk and Benefit-Risk
Evaluation of residual risk and overall residual risk, and a documented benefit-risk judgment wherever risk isn't acceptable on its own.
Production and Post-Production Feedback
Evidence that complaints, nonconformances, service records and field data are reviewed and update the risk analysis when they reveal new hazards or change estimates.
Links to Design, CAPA and Change Control
Risk assessments updated when the design or process changes, and used to set CAPA priority and the depth of investigations.
Related Services
AI-Assisted QMS Gap Assessment
An AI-assisted first pass over the QMS documents you already have, with every result reviewed by an advisor.
CAPA System Remediation
Fixing a CAPA system auditors keep citing: the procedure, the records, root cause, effectiveness and backlog.
FDA Inspection Readiness (CP 7382.850)
FDA device inspection preparation built around Compliance Program 7382.850 and its risk-based approach.
Submission Readiness (510(k), De Novo, PMA, Pre-Sub, 513(g))
The design, risk and V&V evidence behind a 510(k), De Novo or PMA, organized and gap-checked.
Industry Guides That Reference ISO 14971
- Class II Device Manufacturers
- Class III Device Manufacturers
- Software as a Medical Device and AI-Enabled Devices
- In Vitro Diagnostics
- Combination Products
- Implantable Devices
- Electromedical and Capital Equipment
- Orthopedic Devices
- Cardiovascular Devices
- Diagnostic Imaging
- Dental Devices
- Ophthalmic Devices
- Wearables and Digital Health
- Startups and First-Time Submitters
- Established Manufacturers Expanding to New Markets
- Medical Supply Manufacturers
- Durable Medical and Home-Use Equipment
- Reprocessors, Refurbishers and Servicers
- Specification Developers
Questions
Why does risk management carry so much weight in FDA inspections now?
Under Compliance Program 7382.850, FDA device inspections are risk-based and start from the firm's risk management documentation. Investigators use it to decide where to look, then test whether design, production, CAPA and complaint records are consistent with it. A thin or outdated risk file shapes the rest of the inspection.
Is a risk management file the same thing as an FMEA?
No. An FMEA can be one useful technique within the file, but ISO 14971 covers the whole process: plan, hazard analysis, evaluation, controls, verification, residual risk, review and post-production monitoring. FMEAs also focus on failures and can miss hazards that arise when the device works as designed or is misused.
How often should the risk file be updated?
Whenever new information changes the picture: a design or process change, a new hazard surfacing in complaints or field data, or new knowledge in the literature. The plan should define how production and post-production information is reviewed, so updates are triggered by data rather than by the calendar alone.
Does ISO 14971 tell us what level of risk is acceptable?
No. The manufacturer defines its own policy and criteria for risk acceptability, based on applicable regulations, relevant standards and the generally acknowledged state of the art. Auditors check that the criteria exist, are justified and are applied consistently across products.
ISO 14971
Check Your Quality System Against ISO 14971
An AI-assisted first pass maps your existing documents against the requirements in scope, and an advisor reviews every result. Please don't send confidential documents yet: secure upload is set up after onboarding.


