All terms
    Quality & RiskQuality System

    Risk Management

    The lifecycle process defined by ISO 14971 for identifying, analyzing, evaluating, controlling, and monitoring risks associated with a medical device throughout its life cycle.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed September 19, 2026

    Definition

    Risk management, as codified in ISO 14971:2019, Application of risk management to medical devices, is a systematic process manufacturers apply throughout a device's entire life cycle. The process includes risk analysis (identifying hazards, hazardous situations, and estimating associated risk), risk evaluation (comparing estimated risk against defined acceptability criteria), risk control (implementing measures such as inherent safety by design, protective measures, and information for safety, then verifying their effectiveness and evaluating any residual and newly introduced risks), overall residual risk evaluation and benefit-risk analysis, and collection and review of production and post-production information to confirm the risk management file remains valid. The output is a risk management file that a manufacturer must maintain and update throughout the device's commercial life.
    What the regulation says
    MDR Annex I Section 3 requires manufacturers to establish, implement, document, and maintain a risk management system, applying it as an iterative process throughout the entire lifecycle of a device, consistent with the process described in ISO 14971.

    What this means in practice

    Risk management is not a one-time design activity; ISO 14971 explicitly requires manufacturers to establish a system for actively collecting and reviewing production and post-production information (complaints, field data, literature, PMS/vigilance data) and feeding it back into the risk management file. Under MDR Article 10(2) and Annex I Section 3, and the equivalent IVDR provisions, risk management is a mandatory GSPR obligation, not merely good practice, and its output is reviewed by notified bodies as part of technical documentation assessment.
    Common pitfalls
    • Treating risk management as a design-phase-only activity and failing to actively update the risk management file with post-market surveillance data.
    • Setting risk acceptability criteria after the fact to justify an already-designed device, rather than defining criteria upfront per the ISO 14971 process.
    • Conflating risk management with usability engineering or software lifecycle processes instead of properly interfacing them as ISO 14971, IEC 62366-1, and IEC 62304 each require.

    Frequently asked questions

    ISO 14971 itself is a voluntary, harmonisable standard, but MDR Annex I Section 3 and the equivalent IVDR provision impose a legal obligation to operate a risk management system consistent with the ISO 14971 process, so in practice compliance with the standard is the standard route to meeting the legal requirement.
    Grouped by theme
    Cited by

    Where this term appears across MedTech Terms.

    Ecosystems (1)

    Sources

    3 sources

    Every citation below opens the original document. Each is graded against our source-tier hierarchy so you can see what rests on binding law versus commentary.

    Tier 1Binding law and standards· 3
    Link health: 3 verified· last checked 2026-06-20
    ISO·2EUR-Lex·1
    1. 1
      ISO 14971:2019
      Tier 1 Verified
      ISOiso.org
    2. 2
      Regulation (EU) 2017/745, Annex I Section 3
      Tier 1 Verified
      EUR-Lexeur-lex.europa.eu
    3. 3
      ISO 13485 Standard Page
      Tier 1 Verified
      ISOiso.org

    Inline markers like [1] jump to the matching reference above.