Risk Acceptability Matrix
Pre-defined matrix mapping severity × probability combinations to acceptable, ALARP, or unacceptable risk.
Definition
Required by ISO 14971, the risk acceptability matrix is the manufacturer's policy on how risk levels translate into action. It must be defined before risk evaluation and applied consistently across the risk management file.What this means in practice
Notified Bodies frequently challenge inconsistent or unjustified matrices; aligning to ISO/TR 24971 examples is a defensible starting point.Examples
- A manufacturer defines a 3x3 risk matrix where risks with "medium" probability and "moderate" severity are deemed "acceptable with review," prompting further analysis.
- During design control, a risk of software malfunction is assessed using the established risk acceptability matrix, leading to a decision that additional software testing is required to reduce the risk level.
- A Notified Body auditor reviews the risk management file and cross-references the risk acceptability matrix with the residual risk evaluations to confirm consistency and adherence to the manufacturer's policy.
- •Failing to define the risk acceptability matrix before conducting risk evaluation can lead to biased assessments and non-compliance with ISO 14971.
- •Inconsistently applying the risk acceptability criteria across different hazards or use scenarios will result in a non-compliant risk management file.
- •Defining overly aggressive or overly conservative risk acceptability criteria without justification can lead to regulatory scrutiny or an unmarketable device.
- •Not documenting the rationale for the chosen risk acceptability criteria is a common audit finding.
- •Using a generic risk matrix without tailoring it to the specific device and its intended use is a significant oversight.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsRisk & Usability Deep Dive
· From this learning pathSet of records and outputs from the ISO 14971 risk management process.
Application of usability engineering to medical devices.
Iterative usability studies (formative) vs. final validation testing (summative) of a device's user interface.
Defined description of intended users, uses, use environments, and patient populations for a device.
More in Quality & Risk
· Same categoryAbility of a material to perform with an appropriate host response in a specific application.
Verification step confirming a corrective or preventive action actually fixed the problem.
Formal QMS process for evaluating, approving, and implementing changes that could affect product quality or compliance.
Primary references
3 sources- 1
ISO 14971VerifiedISOiso.org
- 2
AAMI - Quality Systems ResourcesVerifiedAAMIaami.org
- 3
MDIC Case for QualityVerifiedMDICmdic.org
Inline markers like [1] jump to the matching reference above.