---
title: "Risk Acceptability Matrix, Definition | MedTech Terms"
description: "Pre-defined matrix mapping severity × probability combinations to acceptable, ALARP, or unacceptable risk. Plain-English Quality &amp; Risk definition for MedTech t"
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/risk-acceptability-matrix#term",
        "name": "Risk Acceptability Matrix",
        "description": "Required by ISO 14971, the risk acceptability matrix is the manufacturer's policy on how risk levels translate into action. It must be defined before risk evaluation and applied consistently across the risk management file.",
        "url": "https://medtechterms.com/terms/risk-acceptability-matrix",
        "termCode": "risk-acceptability-matrix",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/risk-acceptability-matrix#article",
        "headline": "Risk Acceptability Matrix",
        "description": "Pre-defined matrix mapping severity × probability combinations to acceptable, ALARP, or unacceptable risk.",
        "url": "https://medtechterms.com/terms/risk-acceptability-matrix",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/risk-acceptability-matrix"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/risk-acceptability-matrix#term"
        },
        "articleSection": "Quality & Risk",
        "inLanguage": "en",
        "keywords": "Risk Acceptability Matrix, Quality & Risk, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "ISO 14971",
            "url": "https://www.iso.org/standard/72704.html",
            "publisher": {
              "@type": "Organization",
              "name": "ISO"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "AAMI - Quality Systems Resources",
            "url": "https://www.aami.org/standards",
            "publisher": {
              "@type": "Organization",
              "name": "AAMI"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "MDIC Case for Quality",
            "url": "https://mdic.org/program/case-for-quality/",
            "publisher": {
              "@type": "Organization",
              "name": "MDIC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/iso-14971#term",
            "name": "ISO 14971",
            "url": "https://medtechterms.com/terms/iso-14971"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Quality & Risk",
            "item": "https://medtechterms.com/terms?cat=Quality%20%26%20Risk"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Risk Acceptability Matrix",
            "item": "https://medtechterms.com/terms/risk-acceptability-matrix"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/risk-acceptability-matrix#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "What is the primary purpose of a risk acceptability matrix?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "The primary purpose is to provide a consistent framework for determining whether identified risks are acceptable or if further risk reduction is necessary, aligning with the manufacturer's risk management policy."
            }
          },
          {
            "@type": "Question",
            "name": "Who defines the risk acceptability criteria?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "The manufacturer responsible for the medical device defines the risk acceptability criteria, often involving a cross-functional team with expertise in clinical, technical, and regulatory aspects."
            }
          },
          {
            "@type": "Question",
            "name": "Can the risk acceptability matrix be updated?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Yes, it can be updated, but any changes must be justified, documented, and applied consistently to ensure ongoing compliance with ISO 14971 and the device's risk management file."
            }
          },
          {
            "@type": "Question",
            "name": "Are there different types of risk acceptability matrices?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "While the fundamental concept remains, matrices can vary in complexity, often using qualitative, quantitative, or semi-quantitative scales for probability and severity, along with a defined acceptability threshold."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Quality & Risk](/terms?cat=Quality%20%26%20Risk)
6.  /
7.  Risk Acceptability Matrix

[All terms](/terms)

Quality & Risk [Quality System](/ecosystems/quality-system)

# Risk Acceptability Matrix

Pre-defined matrix mapping severity × probability combinations to acceptable, ALARP, or unacceptable risk.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

Required by  [ISO 14971](/terms/iso-14971), the risk acceptability matrix is the manufacturer's policy on how risk levels translate into action. It must be defined before risk evaluation and applied consistently across the  [risk management file](/terms/risk-management-file). 

What the regulation says

Under  [ISO 14971](/terms/iso-14971):2019, specifically clause 4.2 and 6.4, manufacturers must establish criteria for risk acceptability, which often takes the form of a risk acceptability matrix. This matrix defines when a risk is considered acceptable without further mitigation, or when additional risk control measures are required. The criteria must be defined based on the manufacturer's policy for determining acceptable risk before risk evaluation, as outlined in ISO 14971:2019 clause 4.2. 

## What this means in practice

Notified Bodies frequently challenge inconsistent or unjustified matrices; aligning to  [ISO/TR 24971](/terms/tr24971) examples is a defensible starting point. 

## Examples

-   A manufacturer defines a 3x3 risk matrix where risks with "medium" probability and "moderate" severity are deemed "acceptable with review," prompting further analysis.
-   During design control, a risk of software malfunction is assessed using the established risk acceptability matrix, leading to a decision that additional software testing is required to reduce the risk level.
-   A Notified Body auditor reviews the risk management file and cross-references the risk acceptability matrix with the residual risk evaluations to confirm consistency and adherence to the manufacturer's policy.

Common pitfalls

-   • Failing to define the risk acceptability matrix before conducting risk evaluation can lead to biased assessments and non-compliance with ISO 14971. 
-   • Inconsistently applying the risk acceptability criteria across different hazards or use scenarios will result in a non-compliant risk management file. 
-   • Defining overly aggressive or overly conservative risk acceptability criteria without justification can lead to regulatory scrutiny or an unmarketable device. 
-   • Not documenting the rationale for the chosen risk acceptability criteria is a common audit finding. 
-   • Using a generic risk matrix without tailoring it to the specific device and its intended use is a significant oversight. 

## Frequently asked questions

What is the primary purpose of a risk acceptability matrix? 

The primary purpose is to provide a consistent framework for determining whether identified risks are acceptable or if further risk reduction is necessary, aligning with the manufacturer's risk management policy. 

Who defines the risk acceptability criteria? 

Can the risk acceptability matrix be updated? 

Are there different types of risk acceptability matrices? 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Standards

ISO 14971

International standard for the application of risk management to medical devices.





](/terms/iso-14971)

### Risk & Usability Deep Dive

· From this learning path 

[

Quality & Risk

Risk Management File(RMF) 

Set of records and outputs from the ISO 14971 risk management process.

Adjacent lesson 

](/terms/risk-management-file?from=risk-and-usability)[

Standards

IEC 62366-1

Application of usability engineering to medical devices.

Adjacent lesson 

](/terms/iec-62366-1?from=risk-and-usability)[

Quality & Risk

Summative vs. Formative Evaluation

Iterative usability studies (formative) vs. final validation testing (summative) of a device's user interface.





](/terms/summative-formative?from=risk-and-usability)[

Quality & Risk

Use Specification

Defined description of intended users, uses, use environments, and patient populations for a device.





](/terms/use-specification?from=risk-and-usability)

### More in Quality & Risk

· Same category 

[

Quality & Risk

Biocompatibility

Ability of a material to perform with an appropriate host response in a specific application.





](/terms/biocompatibility)[

Quality & Risk

CAPA Effectiveness Check

Verification step confirming a corrective or preventive action actually fixed the problem.





](/terms/capa-effectiveness)[

Quality & Risk

Change Control

Formal QMS process for evaluating, approving, and implementing changes that could affect product quality or compliance.





](/terms/change-control)

Cited by

Where this term appears across MedTech Terms.

Learning paths (1)

-   [Risk & Usability Deep Dive](/paths/risk-and-usability)Lesson 3 of 9 

Ecosystems (1)

-   [Quality System](/ecosystems/quality-system)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

ISO· 1 AAMI· 1 MDIC· 1 

1.  [1 
    
    ISO 14971
    
    Verified 
    
    ISO · iso.org 
    
    
    
    ](https://www.iso.org/standard/72704.html)
2.  [2 
    
    AAMI - Quality Systems Resources
    
    Verified 
    
    AAMI · aami.org 
    
    
    
    ](https://www.aami.org/standards)
3.  [3 
    
    MDIC Case for Quality
    
    Verified 
    
    MDIC · mdic.org 
    
    
    
    ](https://mdic.org/program/case-for-quality/)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Tying cybersecurity into your QMS?

We help align cybersecurity activities with ISO 13485 design controls and ISO 14971 risk management.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Quality & Risk

Sources

3

Updated

5/5/2026

[Compare with another term](/compare?a=risk-acceptability-matrix)

Learn in 60 seconds

Card Lesson Quiz

Pre-defined matrix mapping severity × probability combinations to acceptable, ALARP, or unacceptable risk.

-   · Notified Bodies frequently challenge inconsistent or unjustified matrices; aligning to ISO/TR 24971 examples is a defensible starting point. 
-   · It must be defined before risk evaluation and applied consistently across the risk management file. 

Remember this

Watch out: Failing to define the risk acceptability matrix before conducting risk evaluation can lead to biased assessments and non-compliance with ISO 14971.

Related terms

-   [ISO 14971 ](/terms/iso-14971)

You may also need

Auto-suggested from Quality & Risk and shared keywords.

-   [Risk Management File(RMF) ](/terms/risk-management-file)
-   [ISO 31000 ](/terms/iso-31000)
-   [Post-Production Information (Risk) ](/terms/post-production-info)
-   [AAMI SW96 ](/terms/aami-sw96)
-   [CAPA Effectiveness Check ](/terms/capa-effectiveness)
-   [Management Review ](/terms/management-review)

[All Quality & Risk terms](/terms?cat=Quality%20%26%20Risk)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Truths 
    
    Common misconceptions about medical device development - debunked.
    
    ](https://mdcmisconceptions.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)