What is ISO 14971?

ISO 14971 is the international standard for the application of risk management to medical devices. The current edition is ISO 14971:2019, supported by the guidance in ISO/TR 24971.

It is the quiet foundation underneath nearly everything else in medical device compliance. ISO 13485 requires risk management across the quality system but points to 14971 for the method. The EU MDR and IVDR require a risk management system and are supported by 14971 as a harmonized approach. The FDA expects risk management in design controls and recognizes the standard. ISO 10993-1 — biological evaluation — is explicitly framed as taking place within a risk management process. Software work under IEC 62304 and usability work under IEC 62366 both feed into it.

Which means: if your risk management file is weak, the weakness propagates into your design controls, your biological evaluation, your clinical evaluation and your technical documentation. It is the single highest-leverage document set in a device submission, and the one most often assembled retrospectively.

Who needs ISO 14971

It applies to:

  • Medical device manufacturers, at every class
  • In vitro diagnostic manufacturers, under IVDR and FDA requirements
  • Software as a medical device (SaMD) developers
  • Contract manufacturers and design houses producing devices for others
  • Component and material suppliers whose parts carry device risk
  • Organizations preparing for ISO 13485 certification, MDR or IVDR conformity, or an FDA submission
  • Companies remediating risk files after an audit or notified-body finding

In practice, if you are pursuing ISO 13485 you need ISO 14971 as well. They are not alternatives — 13485 tells you to manage risk, 14971 tells you how, and an auditor will examine the risk management file in detail.

What ISO 14971 requires

The standard defines a lifecycle process, not a document you produce once:

  • A risk management plan for the specific device, including risk acceptability criteria established in advance
  • Intended use and reasonably foreseeable misuse — the second half of that phrase does a great deal of work, and is where many files are thin
  • Hazard identification across the full lifecycle: design, manufacture, transport, storage, use, maintenance and disposal
  • Risk estimation — severity and probability of occurrence of harm for each hazardous situation
  • Risk evaluation against your predefined criteria
  • Risk control, applied in a required order of priority: inherent safety by design first, then protective measures, then information for safety — labelling and warnings last, never first
  • Verification that each control was implemented and is effective
  • Residual risk evaluation, individually and in aggregate for the device as a whole
  • Risk-benefit analysis where residual risk is not acceptable but clinical benefit may justify it
  • Assessment of risks introduced by controls — a control can create a new hazard
  • A risk management report concluding on overall residual risk acceptability
  • Production and post-production information — a genuine feedback loop from complaints, vigilance data, field performance and literature, feeding back into the file

Two points are worth emphasizing because they are the most commonly missed. First, the hierarchy of risk control is mandatory, not advisory — you may not jump to a warning label when a design change is practicable. Second, the 2019 edition strengthened the post-production feedback requirement: a risk file that has not changed since launch, on a product with field complaints, is itself a finding.

Where risk files go wrong

Notified bodies and FDA reviewers see the same failures repeatedly, and they are worth naming plainly:

The retrospective file. Risk management performed after the design was finished, to satisfy the paperwork. It is detectable — the risk controls all turn out to be things the design already did, and no design decision was ever changed by the analysis. The process exists to influence the design, and a file that never influenced anything is evidence it was not followed.

Labelling as a risk control of first resort. Adding a warning is cheap and fast, which is exactly why the standard puts it last. A file where most controls are warnings will be challenged.

Acceptability criteria written after the results. Criteria must be established in the plan, before estimation. Criteria that conveniently accommodate whatever the analysis produced are transparent to an experienced reviewer.

Aggregate residual risk ignored. Every individual risk is acceptable, and the overall residual risk of the device is never evaluated. The standard requires both.

A dead file. No post-production feedback, so complaints and field data never reach the risk analysis. Under the 2019 edition this is a specific and frequently cited gap.

Foreseeable misuse treated as user error. If users predictably do something, that is a design input, not their fault.

How QSE builds your risk management file

We bring 30+ years of quality-system work, 900+ organizations certified and a 100% first-time pass rate, with substantial medical experience — ISO 13485, ISO 10993-1 for biological evaluation, ISO 14155 for clinical investigations, IVDR transitions and ISO 15378 for pharmaceutical packaging.

We build risk management as a working process integrated with your design controls, not as a document produced alongside them. That is the single distinction that determines whether a file survives scrutiny. Practically, it means the risk analysis runs during design, informs design decisions, and leaves a visible trail of having done so.

We start with the risk management plan and acceptability criteria — established up front, defensibly. Then we work through intended use and foreseeable misuse, hazard identification across the lifecycle, and risk estimation with your engineering and clinical people, because they hold the knowledge. We apply the control hierarchy properly, pushing back where a warning is proposed and a design change is practicable. We build the verification and residual-risk evaluation, the risk-benefit analysis where needed, and the risk management report.

Then we close the loop: a post-production feedback process that routes complaints, vigilance data and field performance back into the file, so it stays alive. Where you already hold ISO 13485, we integrate rather than duplicate. Most organizations reach a compliant risk management file in about 3 to 6 months.

Common pitfalls we help you avoid

  • Building the file retrospectively, after the design is frozen — visible to any experienced reviewer
  • Using labelling and warnings as first-line risk controls when the hierarchy requires design changes first
  • Setting acceptability criteria after seeing the risk estimates
  • Evaluating individual risks but never overall residual risk
  • No post-production feedback, leaving a static file the 2019 edition specifically targets
  • Treating foreseeable misuse as user error rather than a design input
  • Failing to assess new hazards introduced by risk controls
  • Risk management maintained separately from design controls, so the two contradict each other
  • No traceability between hazards, controls, verification and design outputs
  • Treating ISO 10993-1 biological evaluation as separate when it belongs inside the risk process