Hazard Analysis
The systematic identification of hazards, foreseeable sequences of events, and resulting hazardous situations that underpins a device's ISO 14971 risk management process.
Definition
Hazard analysis is the initial and foundational step of the risk management process described in ISO 14971, involving the systematic identification of hazards (potential sources of harm), the foreseeable sequences of events that could lead from a hazard to a hazardous situation, and the hazardous situations themselves (circumstances in which people, property, or the environment are exposed to a hazard). ISO 14971 Annex C provides examples of questions to help identify hazards related to a device's characteristics, energy sources, materials, and use. Once hazards and hazardous situations are identified, the manufacturer estimates the probability of occurrence and severity of harm for each foreseeable sequence of events, forming the basis for risk estimation and subsequent risk evaluation and control. Common structured techniques used to support hazard analysis include Failure Mode and Effects Analysis (FMEA), which works bottom-up from component or process failure modes, and Fault Tree Analysis (FTA), which works top-down from an undesired top event to its contributing causes.What this means in practice
Hazard analysis should be applied early and iteratively, starting from a device's intended use, foreseeable misuse, and use environment, and refined as the design matures. AAMI TIR57 provides guidance specific to identifying and assessing security-related hazards for connected medical devices, illustrating how hazard analysis techniques extend beyond classic mechanical or electrical failure modes into cybersecurity risk.- •Limiting hazard analysis to obvious design or manufacturing failures while overlooking use-related hazards that only emerge through the usability engineering process under IEC 62366-1.
- •Treating FMEA as a checkbox exercise disconnected from the formal risk management file, so identified failure modes never feed into documented risk evaluation and control decisions.
- •Failing to reassess hazard analysis when the device's intended use, user population, or use environment changes, leaving the risk management file stale relative to the marketed device.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsBottom-up technique for systematically identifying potential failures and their effects.
Top-down deductive analysis tracing how faults can combine to cause an undesired event.
The lifecycle process defined by ISO 14971 for identifying, analyzing, evaluating, controlling, and monitoring risks associated with a medical device throughout its life cycle.
International standard for the application of risk management to medical devices.
More in Quality & Risk
· Same categoryAbility of a material to perform with an appropriate host response in a specific application.
Verification step confirming a corrective or preventive action actually fixed the problem.
Formal QMS process for evaluating, approving, and implementing changes that could affect product quality or compliance.
Process for receiving, evaluating, and responding to device complaints.
Where this term appears across MedTech Terms.
Sources
3 sourcesEvery citation below opens the original document. Each is graded against our source-tier hierarchy so you can see what rests on binding law versus commentary.
- 1ISO 14971:2019, Clause 5.4 and Annex CTier 1 VerifiedISOiso.org
- 2AAMI TIR57, Principles for Medical Device Security, Risk ManagementTier 2 UncheckedAAMIarray.aami.org
- 3MDIC Case for QualityTier 4 VerifiedMDICmdic.org
Inline markers like [1] jump to the matching reference above.