ISO 14971: Risk Management for Medical Devices, Explained
ISO 14971 is the international standard for applying risk management to medical devices. The current edition is ISO 14971:2019, with ISO/TR 24971 as its guidance companion, and an EU-specific amendment for harmonisation under the MDR.
It is not a document you satisfy once. It describes a process that runs for the whole life of the device, including after it is on the market, and it is the backbone that ISO 13485 and IEC 62304 both hang risk decisions from.
The process
- Risk management plan. Scope, responsibilities, the criteria for acceptable risk, and how you will verify controls. Written first, not reconstructed.
- Risk analysis. Identify the intended use and reasonably foreseeable misuse, identify hazards, then work out the hazardous situations and the harm that could follow.
- Risk evaluation. For each hazardous situation, decide whether the risk is acceptable against the criteria in your plan.
- Risk control. Reduce what is not acceptable, in the order below.
- Residual risk evaluation. Assess what remains after controls, including whether controls introduced new hazards.
- Overall residual risk evaluation. A separate judgement about the device as a whole, not a sum of the individual ones.
- Risk management report. The record that the plan was followed and the residual risk is acceptable, completed before release.
- Production and post-production information. Feed real complaints, field data and literature back into the file.
Step 8 is where most files go stale. A risk file that has not changed since launch, on a device with two years of complaint history, is telling an auditor that the post-production loop is not running.
The risk control hierarchy, and why order matters
Controls are applied in this order, and the order is not a preference:
- Inherently safe design and manufacture.
- Protective measures in the device itself or in manufacturing.
- Information for safety: warnings, contraindications, training.
You cannot use option 3 to reduce a risk that option 1 could have designed out. This is the single most common substantive finding against a risk file. A warning in the instructions for use is the weakest control available, it depends on someone reading and obeying it, and reaching for it first reads as a design decision made for convenience.
What the 2019 edition changed
- Benefit-risk analysis is required where residual risk is not acceptable, and its place in the process is explicit rather than implied.
- Overall residual risk gets its own evaluation and its own criteria, separate from the individual risks.
- Production and post-production activities are strengthened into a defined process with inputs you have to collect, rather than a closing paragraph.
- The risk management file has a clearer definition of what it must contain and where it can reference other records.
- "Reasonably foreseeable misuse" is treated as part of the analysis, not an edge case.
If your procedures were written against the 2007 edition, the gaps are usually in overall residual risk and in post-production, not in the hazard analysis.
Where risk files fail
- Written after the design. A risk file assembled to accompany a submission, rather than one that shaped the design, is visible: the controls all map to labelling because the design was already frozen.
- Hazards confused with hazardous situations. "Electricity" is a hazard. "The user contacts a live conductor while the enclosure is open" is a hazardous situation. Only the second one can be evaluated or controlled.
- Acceptability criteria set after seeing the scores. The criteria belong in the plan, before the analysis.
- Controls with no verification. Every control needs evidence that it was implemented and that it works.
- No link to complaints. Post-production information that never reaches the risk file makes the file a historical document.
- Probability estimated for software. Software failures are systematic, not random. Where probability cannot be estimated, the standard expects you to treat the probability as high, or evaluate on severity alone.
Frequently asked questions
What is ISO 14971?
The international standard for the application of risk management to medical devices. The current edition is ISO 14971:2019, supported by the guidance in ISO/TR 24971.
Is ISO 14971 mandatory?
It is a voluntary consensus standard, but it is recognised by FDA, referenced throughout ISO 13485, and effectively expected under the EU MDR. In practice a device without a 14971-conformant risk file will not clear review.
What is the risk control hierarchy?
Inherently safe design first, then protective measures, then information for safety. Warnings cannot be used to reduce a risk that design could eliminate.
What is the difference between a hazard and a hazardous situation?
A hazard is a potential source of harm. A hazardous situation is the circumstance in which people or property are exposed to it. Risk is evaluated for the situation, not the hazard.
What changed in ISO 14971:2019?
Explicit benefit-risk analysis, a separate evaluation of overall residual risk, a strengthened production and post-production process, and clearer requirements for the risk management file.
How do you estimate probability for software failures?
You often cannot, because software failures are systematic rather than random. The usual approach is to assume the probability is high and evaluate the risk on severity.