Risk Management
ISO/TR 24971: Guidance on Applying Medical Device Risk Management
ISO/TR 24971 is the companion guidance to ISO 14971. It is a technical report, not a requirements standard, and it helps teams work out how to apply the risk management process in practice, from writing a risk policy to collecting production and post-production information.
At a Glance
- Standard
- ISO/TR 24971
- Subject
- Guidance on Applying Medical Device Risk Management
- Group
- Risk Management
A plain-language summary of scope, not the standard itself. Buy the current edition from the publisher and check which edition your auditor or market expects.
What It Covers
Where ISO 14971 says what the process must include, ISO/TR 24971 explains ways to carry it out. Its guidance covers topics such as setting a policy for risk acceptability, identifying characteristics related to safety, choosing risk analysis techniques, estimating probability and severity, evaluating overall residual risk, and planning how production and post-production information is gathered and reviewed.
It also discusses how risk management relates to other work, such as information for safety and the disclosure of residual risk, and the role standards can play in risk control. Its annexes give examples and techniques teams can adapt. None of it is mandatory: a manufacturer may use different methods as long as the ISO 14971 process is met.
In practice, quality and engineering teams use it to settle recurring internal questions, like how to estimate probability when data is thin or how to judge overall residual risk, and to train new staff. Auditors don't audit against it, but a firm that can explain its methods in terms the guidance recognizes usually has an easier time defending them.
Who It Applies To
- Risk management owners writing or revising a risk management procedure
- Engineering teams choosing analysis techniques for a new device
- Quality teams defining production and post-production monitoring
- Firms answering findings that their risk methods are unclear or inconsistent
What Auditors Check
A Written Risk Policy
A documented policy for setting risk acceptability criteria, with the reasoning behind it, rather than criteria that exist only inside a template.
Justified Analysis Methods
A rationale for the techniques used and for how probability and severity scales were defined, especially where data is limited.
Overall Residual Risk Method
A defined, repeatable way of evaluating overall residual risk, not one unsupported sentence at the end of the file.
Post-Production Data Plan
Which sources of production and post-production information are monitored, how often they're reviewed, and who decides whether the risk file changes.
Consistency Across Products
The same methods applied across device families, or documented reasons where they differ.
Related Services
AI-Assisted QMS Gap Assessment
An AI-assisted first pass over the QMS documents you already have, with every result reviewed by an advisor.
CAPA System Remediation
Fixing a CAPA system auditors keep citing: the procedure, the records, root cause, effectiveness and backlog.
QMS Build for Startups (Phased)
A QMS built in phases for a device startup: design controls and risk first, the rest before you need it.
ISO/TR 24971
Check Your Quality System Against ISO/TR 24971
An AI-assisted first pass maps your existing documents against the requirements in scope, and an advisor reviews every result. Please don't send confidential documents yet: secure upload is set up after onboarding.


