Risk Management
The lifecycle process defined by ISO 14971 for identifying, analyzing, evaluating, controlling, and monitoring risks associated with a medical device throughout its life cycle.
Definition
Risk management, as codified in ISO 14971:2019, Application of risk management to medical devices, is a systematic process manufacturers apply throughout a device's entire life cycle. The process includes risk analysis (identifying hazards, hazardous situations, and estimating associated risk), risk evaluation (comparing estimated risk against defined acceptability criteria), risk control (implementing measures such as inherent safety by design, protective measures, and information for safety, then verifying their effectiveness and evaluating any residual and newly introduced risks), overall residual risk evaluation and benefit-risk analysis, and collection and review of production and post-production information to confirm the risk management file remains valid. The output is a risk management file that a manufacturer must maintain and update throughout the device's commercial life.What this means in practice
Risk management is not a one-time design activity; ISO 14971 explicitly requires manufacturers to establish a system for actively collecting and reviewing production and post-production information (complaints, field data, literature, PMS/vigilance data) and feeding it back into the risk management file. Under MDR Article 10(2) and Annex I Section 3, and the equivalent IVDR provisions, risk management is a mandatory GSPR obligation, not merely good practice, and its output is reviewed by notified bodies as part of technical documentation assessment.- •Treating risk management as a design-phase-only activity and failing to actively update the risk management file with post-market surveillance data.
- •Setting risk acceptability criteria after the fact to justify an already-designed device, rather than defining criteria upfront per the ISO 14971 process.
- •Conflating risk management with usability engineering or software lifecycle processes instead of properly interfacing them as ISO 14971, IEC 62366-1, and IEC 62304 each require.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsThe systematic identification of hazards, foreseeable sequences of events, and resulting hazardous situations that underpins a device's ISO 14971 risk management process.
Set of records and outputs from the ISO 14971 risk management process.
Assessment weighing probable benefits against probable risks of a device.
International standard for the application of risk management to medical devices.
More in Quality & Risk
· Same categoryAbility of a material to perform with an appropriate host response in a specific application.
Verification step confirming a corrective or preventive action actually fixed the problem.
Formal QMS process for evaluating, approving, and implementing changes that could affect product quality or compliance.
Process for receiving, evaluating, and responding to device complaints.
Where this term appears across MedTech Terms.
Sources
3 sourcesEvery citation below opens the original document. Each is graded against our source-tier hierarchy so you can see what rests on binding law versus commentary.
- 1ISO 14971:2019Tier 1 VerifiedISOiso.org
- 2Regulation (EU) 2017/745, Annex I Section 3Tier 1 VerifiedEUR-Lexeur-lex.europa.eu
- 3ISO 13485 Standard PageTier 1 VerifiedISOiso.org
Inline markers like [1] jump to the matching reference above.