QMSAdvisor

Risk Management

ISO/TR 24971: Guidance on Applying Medical Device Risk Management

ISO/TR 24971 is the companion guidance to ISO 14971. It is a technical report, not a requirements standard, and it helps teams work out how to apply the risk management process in practice, from writing a risk policy to collecting production and post-production information.

At a Glance

Standard
ISO/TR 24971
Subject
Guidance on Applying Medical Device Risk Management
Group
Risk Management

A plain-language summary of scope, not the standard itself. Buy the current edition from the publisher and check which edition your auditor or market expects.

What It Covers

Where ISO 14971 says what the process must include, ISO/TR 24971 explains ways to carry it out. Its guidance covers topics such as setting a policy for risk acceptability, identifying characteristics related to safety, choosing risk analysis techniques, estimating probability and severity, evaluating overall residual risk, and planning how production and post-production information is gathered and reviewed.

It also discusses how risk management relates to other work, such as information for safety and the disclosure of residual risk, and the role standards can play in risk control. Its annexes give examples and techniques teams can adapt. None of it is mandatory: a manufacturer may use different methods as long as the ISO 14971 process is met.

In practice, quality and engineering teams use it to settle recurring internal questions, like how to estimate probability when data is thin or how to judge overall residual risk, and to train new staff. Auditors don't audit against it, but a firm that can explain its methods in terms the guidance recognizes usually has an easier time defending them.

Who It Applies To

  • Risk management owners writing or revising a risk management procedure
  • Engineering teams choosing analysis techniques for a new device
  • Quality teams defining production and post-production monitoring
  • Firms answering findings that their risk methods are unclear or inconsistent

What Auditors Check

  • A Written Risk Policy

    A documented policy for setting risk acceptability criteria, with the reasoning behind it, rather than criteria that exist only inside a template.

  • Justified Analysis Methods

    A rationale for the techniques used and for how probability and severity scales were defined, especially where data is limited.

  • Overall Residual Risk Method

    A defined, repeatable way of evaluating overall residual risk, not one unsupported sentence at the end of the file.

  • Post-Production Data Plan

    Which sources of production and post-production information are monitored, how often they're reviewed, and who decides whether the risk file changes.

  • Consistency Across Products

    The same methods applied across device families, or documented reasons where they differ.

Related Services

ISO/TR 24971

Check Your Quality System Against ISO/TR 24971

An AI-assisted first pass maps your existing documents against the requirements in scope, and an advisor reviews every result. Please don't send confidential documents yet: secure upload is set up after onboarding.