Risk Management in Medical Devices: How to Build an ISO 14971-Compliant Process in 2026

Medical device risk management is the thread that connects every element of your ISO 13485 QMS — and the first place an auditor looks. This guide covers all five stages of the ISO 14971:2019 process, required documentation at each step, how to set defensible acceptability criteria, and the most common findings in notified body and FDA audits.

A step-by-step implementation guide for medical device manufacturers building or strengthening a risk management framework under ISO 14971:2019 and ISO 13485:2016

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Risk Management File Is the First Thing an Auditor Opens

Not your QMS manual. Not your SOPs. Your risk management file.

That is where a notified body auditor or FDA inspector starts — because risk management in medical devices is the thread that connects every other element of your quality system. If your risk file is thin, incomplete, or disconnected from your design and production controls, the rest of your documentation will not save you.

Most medical device companies understand that ISO 14971:2019 requires a risk management process. Fewer understand what that process actually looks like when it is fully implemented — the outputs required, the decisions that must be documented, and the points where ISO 13485:2016 Clause 7.1 and ISO 14971 intersect in ways that catch teams off guard during audits.

This article walks through the complete risk management process for medical devices: what ISO 14971 requires at each stage, how those requirements connect to your QMS, and where most teams fall short.

I have spent 25 years in heavy industrial manufacturing running quality systems under ISO 9001, managing nonconformances, and building risk-based approaches to process control. When I transitioned into the ISO 13485 space, the discipline was familiar — but the regulatory stakes were different. In manufacturing, a process failure costs you time and scrap. In medical devices, the same gap in your risk file can cost you a 483 observation, a warning letter, or a market withdrawal. The rigor required is not optional, and it is not theoretical. Every output described in this article is something auditors actively look for.

Before you read further: If you have not yet assessed where your current risk management process stands against ISO 14971:2019 requirements, start there. A structured gap assessment takes less time than an audit finding.

📥 Download the ISO 13485 Gap Assessment Checklist — Free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including risk management obligations under Clause 7.1.


In This Guide

  • What ISO 14971:2019 actually requires — the full process, not just the outputs
  • How ISO 13485 Clause 7.1 connects to your risk management file
  • The five stages of the ISO 14971 process with required documentation at each step
  • How to set acceptable risk criteria — the decision most teams get wrong
  • Post-production surveillance and why it feeds back into your risk file
  • The most common audit findings in risk management reviews
  • Training options for teams building or rebuilding a compliant process


👉 Start Here: Top Resources for Medical Device Risk Management

If you are building or rebuilding your risk management process, these are the resources that will move you fastest:

  • ISO 14971:2019 — ANSI Webstore — The current edition of the standard. Required reading for anyone responsible for a device risk management file. Use code CC2026 for 5% off at checkout.
  • ISO 13485 Training — BSI Group — BSI offers ISO 13485 implementation and auditor training that covers risk management integration in depth.
  • ISO 13485 Training — ISOQAR — ISOQAR provides training and certification services for ISO 13485, with risk-based thinking woven throughout their courses.

What ISO 14971:2019 Requires

ISO 14971 risk management lifecycle infographic showing the seven stages of risk management in medical devices and required outputs from planning through post-production surveillance.
A visual overview of the ISO 14971 risk management lifecycle and the documentation outputs auditors expect to see.

ISO 14971:2019 is the international standard for the application of risk management to medical devices. It applies throughout the full device lifecycle — from concept through post-market surveillance.

The standard does not prescribe a specific risk analysis method. It does not tell you to use FMEA, FTA, or a risk matrix of a particular format. What it requires is a documented, systematic process that produces specific outputs at each stage.

The core framework in ISO 14971:2019 includes:

StageWhat ISO 14971 Requires
Risk management planDefine scope, responsibilities, criteria for risk acceptability, and review activities
Risk analysisIdentify intended use, reasonably foreseeable misuse, and associated hazards and hazardous situations
Risk evaluationCompare estimated risk against criteria — determine if risk reduction is required
Risk controlSelect and implement controls; verify effectiveness; assess residual risk and any new risks introduced
Benefit-risk analysisWhere residual risk remains, evaluate whether the overall benefit outweighs remaining risk
Risk management reportSummarize the process and confirm residual risks are acceptable
Post-production informationCollect and review field data; feed findings back into risk management

Every output — the plan, the analysis, the controls, the report — must be captured in a risk management file.


How ISO 13485 Clause 7.1 Connects

ISO 13485:2016 Clause 7.1 requires that your organization document risk management requirements throughout product realization. This is not a standalone obligation — it is a QMS-level requirement that ties your risk file to your design controls, supplier management, production processes, and CAPA system.

The key connection points:

Design and development (Clause 7.3): Risk management inputs and outputs must be included in design planning. Design reviews, verification, and validation activities must all reference and be consistent with the risk management file.

Purchasing and supplier controls (Clause 7.4): Supplier-introduced risks must be identified and addressed. If a supplier failure creates a patient hazard, that scenario belongs in your risk analysis.

Production and service provision (Clause 7.5): Special processes — sterilization, labeling, software-dependent controls — require risk-based validation. Your risk file should identify where these controls are critical and what happens if they fail.

CAPA (Clause 8.5): Post-market findings, complaints, and nonconformances are data sources for your risk management process. A complaint that reveals a hazardous situation not previously identified in your risk analysis must trigger a risk file update.

Most common finding: Auditors frequently cite a disconnect between the CAPA system and the risk management file — complaints and CAPAs are processed and closed without evaluating whether the risk file needs to be updated.

If you are evaluating your current QMS against these connection points, the gap assessment checklist above covers all of them.


The Five-Stage Risk Management Process

Stage 1: Risk Management Plan

Your risk management plan is not a form — it is a governing document for the entire risk process for a specific device. It must define:

  • The scope of activities (which device, which lifecycle phases)
  • Roles and responsibilities for risk management activities
  • Requirements for review of risk management activities
  • Criteria for risk acceptability — what level of residual risk is acceptable and on what basis

The last item is where most teams take shortcuts. Acceptability criteria cannot simply reference “ALARP” or “as low as reasonably practicable” without defining what that means for your device and patient population. Auditors will push on this.

Stage 2: Risk Analysis

Risk analysis begins with a thorough description of the device — its intended use, intended users, and reasonably foreseeable misuse. From there, you identify:

  • Hazards (potential sources of harm)
  • Hazardous situations (circumstances in which people could be exposed to a hazard)
  • Harm sequences (how the hazardous situation leads to harm)

ISO 14971 Annex C provides a non-exhaustive list of hazard categories: energy hazards, biological hazards, environmental hazards, hazards related to incorrect output, and others. Use it as a prompt, not as a complete list.

Common analysis methods include FMEA (Failure Mode and Effects Analysis), FTA (Fault Tree Analysis), and HAZOP. Most device teams use FMEA as the primary tool. None of these methods is required by the standard — but whatever method you use must be documented and consistently applied.

Stage 3: Risk Evaluation

Once you have estimated the probability and severity of each harm, you evaluate whether each risk requires reduction. This evaluation is made against the acceptability criteria defined in your risk management plan.

If a risk exceeds your acceptable threshold, risk reduction is required. If it falls below the threshold, you still need to document the evaluation decision — not just assume silence means acceptable.

📥 If you are not confident your current risk file covers these evaluation decisions consistently, download the ISO 13485 Gap Assessment Checklist and work through Section 7 — it maps directly to these requirements.

Stage 4: Risk Control

ISO 14971 infographic showing the risk control hierarchy and residual risk evaluation process for medical device risk management.
ISO 14971 requires organizations to prioritize design controls first, verify effectiveness, and document residual risk decisions before closing risk.

ISO 14971 requires you to follow a three-level hierarchy when selecting controls:

  1. Inherent safety by design — eliminate or reduce the hazard through design choices
  2. Protective measures — add guards, alarms, or protective barriers in the device or manufacturing process
  3. Information for safety — labeling, instructions for use, training requirements

You must implement controls in this order of preference. You cannot jump to warnings and labeling as your primary control if a design solution is practicable.

After implementing each control:

  • Verify the control was implemented as intended
  • Verify the control is effective at reducing risk
  • Assess whether the control introduces any new hazards
  • Re-evaluate residual risk after all controls are applied

Stage 5: Residual Risk and Benefit-Risk Analysis

After controls are in place, residual risk will remain for most devices. If residual risk exceeds your acceptability criteria even after all practicable controls have been applied, you must perform a benefit-risk analysis: does the clinical benefit of the device outweigh the remaining risk?

This analysis must be documented. “We believe the benefit outweighs the risk” is not documentation. The analysis must reference clinical evidence, intended use, and the nature and magnitude of remaining harm.


Setting Acceptable Risk Criteria

This is the decision most risk management teams get wrong, and it is the one auditors examine most carefully.

Your risk acceptability criteria must be:

  • Defined before you begin risk analysis — not after you have already seen your risk estimates
  • Based on relevant policy, standards, and guidance applicable to your device category
  • Specific enough to make clear decisions — a matrix with defined severity and probability ranges, not a narrative statement
What Auditors SeeWhat They Want to See
“We aim to reduce risk ALARP”A defined matrix with probability/severity scales and explicit acceptable/unacceptable zones
Criteria defined after the analysis was completedCriteria established in the risk management plan before analysis began
One set of criteria applied across all device typesCriteria appropriate to the specific device and patient population
No documented basis for the criteria chosenReference to applicable guidance documents (IMDRF, EU MDR, FDA guidance)

Reference points that support defensible criteria include FDA guidance on risk management for device software, IMDRF guidance documents, and the introductory notes in ISO 14971:2019 itself.


Risk Control Options and Residual Risk

One of the most common gaps in risk files is incomplete residual risk documentation. Teams identify hazards, apply controls, and then fail to document the post-control risk estimate.

Every control must have:

  • A documented implementation record (the control was actually applied)
  • A verification record (the control works as intended)
  • A post-control risk re-estimate (residual probability × severity)
  • An evaluation of residual risk against acceptability criteria

If your controls introduce new hazards — which software controls, sterilization processes, and combination products frequently do — those new hazards must be analyzed through the full process. There is no shortcut.

If you are preparing for your first ISO 13485 certification audit, verify that every risk control in your file has all four of these elements documented before your Stage 1 audit. Incomplete residual risk documentation is one of the most common major nonconformances found in initial certification audits.

BSI Group offers ISO 13485 implementation training that specifically addresses risk file documentation structure, including residual risk evaluation requirements. ISOQAR provides similar training with a certification pathway.


The Risk Management File

The risk management file is not a single document. It is a collection of records that demonstrates the complete risk management process was followed for a specific device. What it must contain:

  • Risk management plan
  • Risk analysis outputs (hazard list, probability/severity estimates)
  • Risk evaluation records (acceptability decisions)
  • Risk control records (implementation, verification, new hazard assessment)
  • Residual risk evaluation
  • Benefit-risk analysis (where required)
  • Risk management report
  • Post-production information review records

The risk management report is the capstone document. It confirms that the risk management plan was followed, all residual risks are acceptable, and appropriate methods were used to obtain relevant production and post-production information.

Your risk management file must be maintained and updated throughout the product lifecycle. It is not a one-time certification exercise.

ISO 14971 risk management file infographic showing required records and how the file integrates with ISO 13485 quality management requirements.
The risk management file is the central evidence package that demonstrates ISO 14971 compliance across the medical device lifecycle.

Post-Production Information and Surveillance

ISO 14971 Clause 9 requires a systematic process to collect and review post-production information. This includes:

  • Customer complaints and feedback
  • Field service and repair reports
  • Medical device reports (MDRs) and vigilance reports
  • Published literature and adverse event databases
  • Post-market clinical data

This information must be evaluated to determine whether it:

  • Indicates previously unidentified hazards
  • Changes the estimated probability or severity of a known harm
  • Invalidates earlier risk control decisions

If it does, your risk file must be updated. Your CAPA process must have a defined trigger for escalating post-market findings to the risk management team.

Most common finding: Post-market surveillance is treated as a regulatory reporting obligation rather than a risk management input. Complaints are processed through CAPA, but the risk file is never reviewed against complaint trends. This is a major nonconformance under both ISO 13485 Clause 8.2.1 and ISO 14971 Clause 9.


Common Audit Findings in Risk Management Reviews

These are the findings that appear most frequently in ISO 13485 and EU MDR notified body audits:

Incomplete risk analysis scope — Reasonably foreseeable misuse not identified or analyzed. Risk analysis covers intended use only.

⚠️ Acceptability criteria defined after the analysis — Criteria were back-filled to match the estimates, rather than established as the decision framework before analysis began.

⚠️ Missing residual risk evaluation — Controls were implemented and verified, but no post-control risk estimate was documented.

Disconnected CAPA and risk file — Complaints and CAPAs processed and closed without triggering a risk file review.

⚠️ Labeling used as the primary control — Instructions for use are cited as the risk control when a design solution was practicable.

Risk file not maintained post-launch — The risk file was complete at certification but has not been updated since. Design changes, new complaint data, and field findings are not reflected.

⚠️ No benefit-risk analysis where residual risk is above acceptability threshold — Teams acknowledge residual risk exceeds their criteria but do not formally document the benefit-risk justification.


Training for Your Risk Management Team

Risk management competence is a requirement, not a preference. Your team members responsible for risk management activities must be trained — and that training must be documented.

Both BSI Group and ISOQAR offer ISO 13485 training that covers risk management integration. BSI also offers a dedicated Risk Management — Requirements (ISO 14971) e-learning course for teams who need focused training on the standard itself.

If you are already certified under ISO 13485 and preparing for a surveillance audit:

If your risk team has not been formally trained on ISO 14971:2019 since the 2019 edition was published, now is the time to close that gap. The 2019 edition introduced changes to state-of-the-art requirements and manufacturer benefit-risk responsibilities that differ from the 2007 edition.

If you are building your QMS from scratch and need structured implementation support across all 8 clauses:

If you are evaluating implementation support options, review what documentation a compliant ISO 13485 QMS requires before investing in training. It will help you scope what your team actually needs to build.


FAQ

What is the difference between ISO 14971 and ISO 13485 for risk management?

ISO 13485:2016 Clause 7.1 requires that risk management be applied throughout product realization. ISO 14971:2019 is the standard that defines how to do it — the process, the required outputs, and the documentation. ISO 13485 tells you that you must manage risk. ISO 14971 tells you how. Most medical device manufacturers must comply with both.

Is ISO 14971 mandatory?

ISO 14971 is not directly mandated by law in most markets, but it is referenced as a harmonized standard under the EU MDR 2017/745 and EU IVDR 2017/746. For FDA-regulated devices in the US, compliance with ISO 14971 supports conformance with 21 CFR Part 820 design controls requirements. As a practical matter, no notified body or FDA inspection team will accept a risk management process that does not align with ISO 14971.

What is a risk management file?

A risk management file is the complete collection of records that documents the risk management process for a specific device. It includes the risk management plan, risk analysis outputs, evaluation records, control records, residual risk documentation, benefit-risk analysis (where required), the risk management report, and post-production surveillance records. The file must be maintained and updated throughout the device lifecycle.

How often should a risk management file be updated?

Your risk management file must be updated whenever there is a change to the device, its intended use, or new information that could affect risk estimates — including complaints, adverse events, published literature, or design changes. Many organizations establish a formal periodic review (annually or at defined product lifecycle milestones) as part of their post-market surveillance process.

What risk analysis methods does ISO 14971 require?

ISO 14971 does not mandate a specific method. FMEA, FTA, HAZOP, and preliminary hazard analysis are all acceptable approaches. What the standard requires is that the method be documented, systematic, and capable of identifying hazards and estimating risk. Most medical device manufacturers use FMEA as their primary method.

What is the difference between a hazard, a hazardous situation, and harm in ISO 14971?

A hazard is a potential source of harm — for example, excessive electrical energy in a device. A hazardous situation is a circumstance in which people, property, or the environment could be exposed to the hazard — for example, a patient contact point that can carry excessive current under a specific failure condition. Harm is the physical injury or damage to health that results. ISO 14971 requires that you trace the full sequence from hazard to harm for each risk identified.

How does ISO 14971 relate to CAPA in ISO 13485?

Your CAPA process should have a defined trigger for escalating complaints, adverse events, and nonconformances to the risk management team for evaluation. If a post-market finding reveals a previously unidentified hazard or changes the estimated probability of an existing risk, your risk file must be updated. Closing a CAPA without evaluating its implications for the risk file is one of the most common major findings in ISO 13485 surveillance audits.

What changed in ISO 14971:2019 compared to the 2007 edition?

ISO 14971:2019 introduced several substantive changes: clarified the concept of state-of-the-art and how manufacturers must use it; expanded and clarified the benefit-risk analysis process; updated the overall residual risk evaluation process; and revised the structure of the standard to align with ISO management system high-level structure conventions. Teams trained only on the 2007 edition may have gaps in their current process.


📥 Free Resources

These tools are available at no cost to support your ISO 13485 and risk management implementation:

  • ISO 13485 Gap Assessment Checklist — Free checklist for medical device manufacturers assessing their QMS against ISO 13485 requirements, including risk management obligations under Clause 7.1
  • ISO 9001 Roadmap — Step-by-step implementation guide for manufacturers building or improving a quality management system
  • Manufacturing Compliance Checklist — Practical compliance reference covering key ISO, OSHA, and quality requirements for production environments
  • Supplier Quality Checklist — Evaluation tool for assessing supplier quality controls and flow-down compliance before audits or new contracts
  • AS9100 Rev D Gap Assessment Checklist — 74-item clause-by-clause checklist for aerospace suppliers assessing their QMS before certification

Not Sure What to Do Next?

🔹 Still building your understanding of ISO 13485 requirements? Start with the ISO 13485 Implementation Roadmap — it walks through all 8 clauses and how they connect before you invest in building documentation.

🔹 Ready to implement and need training for your risk management team? Both BSI Group and ISOQAR offer ISO 13485 training with risk management integration. BSI also has a dedicated ISO 14971 e-learning course.

🔹 Need to purchase ISO 14971:2019 for your quality team? Get it from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


Risk management is not a documentation exercise you complete before certification and revisit every few years. It is the living framework that keeps your device safe, your quality system defensible, and your audits clean. Build it right from the start — and maintain it like the regulatory asset it is.

The Standards Navigator covers ISO 13485, ISO 14971, FDA requirements, and medical device quality management in depth. Use the resources above to move from gap to compliant.


Stay Current on Medical Device Compliance

Most teams that struggle with ISO 13485 audits are not missing knowledge — they are missing a system for keeping their risk files, documentation, and compliance processes current as requirements evolve.

Organizations that pass surveillance audits consistently have one thing in common: their quality teams are not surprised by what auditors look for. They have a process for staying ahead of requirement changes, notified body expectations, and post-market obligations.

The Standards Navigator covers ISO 13485, ISO 14971, FDA QMSR, and medical device compliance requirements in plain language for quality professionals and regulatory teams.

👉 Get updates on the medical device compliance cluster — new articles, requirement changes, and implementation guidance delivered directly to your inbox.

👉 Be first to access new free resources, including the ISO 13485 Documentation Starter Kit when it launches.

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.

What Is ISO 14971? Risk Management for Medical Devices Explained (2026 Guide)

ISO 14971 is not optional supplementary guidance for ISO 13485 — it is the required risk management framework woven throughout the medical device lifecycle. This guide covers what ISO 14971:2019 requires clause by clause, how its six-step process works across the device lifecycle, what changed in the 2019 edition, and why the FDA’s QMSR makes a well-maintained Risk Management File more critical than ever.

ISO 14971 is not optional supplementary guidance for ISO 13485 — it is the required risk management framework woven throughout the medical device lifecycle. Here’s what it requires, how it works, and why the FDA’s QMSR makes understanding it more important than ever.

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


From the Shop Floor

Risk management in manufacturing is not a new concept. Every process engineer who has ever run a failure modes and effects analysis on a production line understands the core logic: identify what can go wrong, estimate how likely it is and how bad it would be, put controls in place, and verify those controls work.

What ISO 14971 adds to that foundation is structure, lifecycle scope, and documentation discipline.

After 25 years in heavy industrial manufacturing — including quality systems, process control, and operational risk — the single most consistent gap I see in medical device risk management is the treatment of the Risk Management File as a design-phase deliverable rather than a living operational document. Teams build an impressive RMF during product development, get through their certification audit, and then let the file sit static while the real world generates new information about how the device actually performs.

That approach worked well enough under the old QSR. It does not work under the QMSR.

FDA investigators under CP 7382.850 are not looking at your RMF to confirm it was done — they are using it as a roadmap to evaluate whether your entire quality system is functioning as an integrated risk management framework. A risk management file that hasn’t been updated since device release is not a minor documentation gap. It is evidence that your risk management process is not integrated with complaint handling, CAPA, and post-market surveillance the way the QMSR requires.

The organizations I have seen handle this well treat the RMF update as a standing agenda item in management review — not a corrective action triggered by an audit finding. If post-market data is generating complaints, those complaints are being evaluated in the context of the risk management file every quarter. That is the operating model QMSR expects.


ISO 14971 Is the Standard Your QMS Is Already Required to Implement

If you are pursuing ISO 13485 certification, operating under the FDA’s QMSR, or manufacturing medical devices for any major regulated market, ISO 14971 is not a standard you get to choose whether to implement.

ISO 13485:2016 explicitly requires risk management per ISO 14971 throughout the medical device lifecycle — in design controls, production processes, supplier controls, complaint handling, and post-market surveillance. Under the FDA’s Quality Management System Regulation (QMSR), effective February 2, 2026, that requirement now carries federal regulatory weight. FDA investigators under Compliance Program 7382.850 are expected to use the risk management file as their inspection roadmap.

Yet despite being one of the most referenced standards in medical device regulation, ISO 14971 remains one of the least understood. Most manufacturers know it exists. Far fewer understand what it actually requires, how its six-step process works across the device lifecycle, or why the 2019 edition introduced changes that many organizations still haven’t fully implemented.

This guide covers all of it — what ISO 14971 is, what it requires clause by clause, how it integrates with ISO 13485 and the QMSR, and what your risk management program needs to look like in practice.


In This Guide

  • What ISO 14971 is and why it exists
  • Who needs ISO 14971
  • The six-step ISO 14971 risk management process
  • Key clause-by-clause breakdown
  • What changed in the 2019 edition
  • The Risk Management File — what it contains and how it’s structured
  • ISO 14971 and ISO 13485 — how they integrate
  • ISO 14971 under the FDA QMSR
  • ISO/TR 24971 — the companion guidance document
  • How to buy the official standard
  • Frequently asked questions


✅ Start Here (Top Resources)

📋 Purchase the official ISO 14971:2019 standard → ISO 14971:2019 — ANSI Webstore — use coupon CC2026 for 5% off through December 31, 2026

📋 Purchase the official ISO 13485:2016 standard — required companion → ISO 13485:2016 — ANSI Webstore — use coupon CC2026 for 5% off

📋 Save up to 50% buying both standards as a bundle → ISO Standards Packages — ANSI Webstore

📋 Get ISO 13485 training that covers ISO 14971 integration → BSI Group ISO 13485 Training

📋 Get ISO 13485 certified with an accredited certification body → ISOQAR ISO 13485 Certification


What Is ISO 14971?

ISO 14971 is the international standard for the application of risk management to medical devices. The current version — ISO 14971:2019 — is the third edition, published in December 2019. It specifies the terminology, principles, and a structured process for identifying hazards associated with medical devices, estimating and evaluating the associated risks, controlling those risks, and monitoring the effectiveness of controls throughout the entire device lifecycle.

The standard applies to:

  • Physical medical devices of all classifications
  • Software as a Medical Device (SaMD)
  • In vitro diagnostic (IVD) medical devices
  • Combination products where the device constituent part requires risk management

Before ISO 14971, there was no universally accepted methodology for risk management in the medical device industry. Different manufacturers used different approaches, different terminology, and different standards for what constituted acceptable risk. ISO 14971 introduced a standardized process that could be consistently applied across the industry globally — giving regulators, certification bodies, and trading partners a shared framework for evaluating whether a manufacturer’s risk management is adequate.

Risk, as defined by ISO 14971, is the combination of two components:

  1. The probability that harm will occur
  2. The severity of that harm

This definition is important because it shapes the entire risk management process. A high-severity potential harm that is extremely unlikely to occur produces a different risk level than a moderate-severity harm that occurs frequently. ISO 14971 requires manufacturers to evaluate both dimensions systematically — not rely on intuition or experience alone.


Who Needs ISO 14971?

ISO 14971 is effectively required for any organization involved in the medical device supply chain. Specifically:

Organizations that must implement ISO 14971:

  • Medical device manufacturers — it is explicitly required by ISO 13485 and referenced throughout FDA QMSR, EU MDR, Health Canada, TGA (Australia), and most other major regulatory frameworks
  • Design-responsible organizations developing medical devices or device software
  • Contract manufacturers producing devices under a design owner’s technical file

Organizations that should implement ISO 14971:

  • Component suppliers whose products are incorporated into medical devices — risk management requirements are increasingly flowed down through quality agreements
  • Software developers producing SaMD or software incorporated into medical devices
  • Sterilization service providers — sterilization process risk must be managed within the device’s overall risk management framework

A critical distinction: ISO 14971 is not legally mandated in the same way a regulation is — regulators like the FDA do not list it as a statutory requirement. However, regulators worldwide recognize ISO 14971 as the state of the art for medical device risk management. Non-conformance with ISO 14971 — or the absence of a risk management program built on its framework — creates significant regulatory exposure. For practical purposes, ISO 14971 is mandatory for any organization intending to demonstrate that their device is safe and effective.


The ISO 14971 Risk Management Process — Six Steps

Infographic illustrating the six-step ISO 14971 medical device risk management process: Risk Analysis, Risk Evaluation, Risk Control, Overall Residual Risk, Risk Management Review, and Post-Production Information.
The six-step ISO 14971 risk management process creates a structured lifecycle approach for identifying hazards, controlling risks, evaluating residual risk, and continuously improving medical device safety.

ISO 14971 defines a six-step risk management process that applies across the entire device lifecycle — from initial concept through design, production, and post-market activities.

Step 1 — Risk Analysis

Risk analysis is the systematic use of available information to identify hazards and estimate the risks associated with a medical device. It consists of two activities:

Hazard identification: Identifying all reasonably foreseeable hazards associated with the device under both normal use conditions and fault conditions. The 2019 edition specifically requires both normal and fault conditions to be considered — a change from the 2007 edition which emphasized fault conditions primarily.

Sources of hazards include:

  • Device energy sources (electrical, thermal, mechanical, radiation)
  • Device materials and their biological interactions
  • Use environment and user characteristics
  • Reasonably foreseeable misuse
  • Software failures and cybersecurity vulnerabilities
  • Interactions with other devices

Risk estimation: For each hazardous situation identified, estimating the risk by determining the probability of occurrence of harm and the severity of that harm. ISO 14971 does not specify acceptable risk levels — manufacturers must establish their own objective criteria based on regulatory requirements, industry standards, and clinical context.

Step 2 — Risk Evaluation

Risk evaluation is the process of comparing estimated risks against the manufacturer’s defined risk acceptability criteria to determine whether risk reduction is required. If the estimated risk exceeds acceptable levels, the process moves to risk control. If the risk is within acceptable limits, it is documented as acceptable residual risk and monitored.

Step 3 — Risk Control

Risk control is the process of implementing and verifying measures to reduce risks that exceed acceptable levels. ISO 14971 requires risk control measures to be implemented in a defined priority order:

  1. Inherent safety by design — eliminate or reduce hazards through design decisions (preferred)
  2. Protective measures — guards, alarms, interlocks in the device or manufacturing process
  3. Information for safety — warnings, instructions for use, training requirements (last resort)

After implementing risk control measures, the residual risk — the risk remaining after controls — must be estimated and evaluated again. The process is iterative: if residual risk is still unacceptable, additional risk control measures must be implemented.

Risk control measures must also be evaluated for introduced risks — a control measure that eliminates one hazard may introduce a new one.

Step 4 — Evaluation of Overall Residual Risk

After all individual risks have been addressed, the overall residual risk of the device must be evaluated — not just each individual risk in isolation. If the overall residual risk is not acceptable using the manufacturer’s risk acceptability criteria, a benefit-risk analysis must be performed.

Benefit-risk analysis (introduced as a formal requirement in the 2019 edition) evaluates whether the clinical benefits of the device outweigh the overall residual risk in the context of the device’s intended use. If the benefits outweigh the risks, and appropriate information is provided to users, the device may be released. If the benefits do not outweigh the risks, the device cannot be released — additional risk control measures are required.

Step 5 — Risk Management Review

Before a device is released for distribution, a formal risk management review must be completed. The 2019 edition changed the title of this clause from “Risk Management Report” to “Risk Management Review” — a deliberate signal that this is an active review activity, not simply a summary document.

The review must confirm:

  • The risk management plan has been fully implemented
  • The overall residual risk is acceptable
  • Appropriate methods are in place to collect and review production and post-production information

Reviewers must be identified in the risk management plan in advance — they cannot be appointed after the fact.

Step 6 — Production and Post-Production Information

Risk management does not end when the device is released. ISO 14971 requires a systematic process for collecting and reviewing information from production and post-market activities throughout the device’s commercial life. This includes:

  • Complaint data and adverse event reports
  • Post-market surveillance information
  • Production nonconformances and CAPA trends
  • New scientific and technical information relevant to device safety

When this information indicates that the risk management process needs to be updated — that a new hazard has been identified, or that an existing risk estimate was incorrect — the risk management file must be revised and risk control measures re-evaluated.


ISO 14971 Clause-by-Clause Breakdown

ClauseTitleKey Content
1ScopeApplicability to all medical devices, SaMD, IVDs, combination products
2Normative referencesISO 9000:2015 for defined terms
3Terms and definitions31 defined terms including risk, hazard, harm, hazardous situation, benefit
4General requirementsRisk management system requirements, management responsibilities, competence requirements
5Risk management planningRisk management plan requirements — device scope, lifecycle phases, risk acceptability criteria
6Risk analysisIntended use, hazard identification, risk estimation
7Risk evaluationComparison to acceptability criteria, benefit-risk analysis (Clause 7.4)
8Risk controlControl option analysis, measure implementation, residual risk evaluation, introduced risks
9Evaluation of overall residual riskOverall residual risk acceptability, benefit-risk if needed
10Risk management reviewPre-release review requirements, reviewer identification
11Production and post-production activitiesInformation collection, new hazard identification, risk file updates

What Changed in ISO 14971:2019

The 2019 edition is the third edition of ISO 14971, replacing the 2007 version. Several changes have practical implementation implications:

Benefit-risk analysis is now a formal requirement. The 2019 edition formally introduced benefit-risk analysis as a defined process step (Clause 7.4) when overall residual risk is not acceptable under the manufacturer’s criteria alone. The 2007 edition referenced this concept but did not treat it as a structured requirement. The FDA’s influence here is direct — the FDA revised its language to place “benefit” before “risk” for novel device submissions, and the ISO 14971 committee adopted this framing in the 2019 revision.

Both normal and fault conditions must be analyzed. Clause 5.4 of the 2019 edition explicitly requires identification of anticipated hazards under both normal use and fault conditions. The 2007 edition emphasized fault conditions — the 2019 edition closes that gap. This has direct implications for FMEA and hazard analysis documentation.

Post-production requirements are more prescriptive. The requirements for production and post-production information collection (Clause 11) are more detailed in the 2019 edition, with stronger emphasis on systematic feedback of real-world performance data into the risk management file.

Risk Management Review replaces Risk Management Report. The title change in Clause 9 (from “report” to “review”) reflects a substantive intent: the activity must be an active review with identified reviewers, not a passive summary document compiled at device release.

EN ISO 14971:2019 + A11:2021 for EU MDR. The European version of the standard includes Amendment A11:2021, which maps ISO 14971 requirements to the General Safety and Performance Requirements (GSPR) of the EU Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR). Organizations selling into the EU need the A11 annex — organizations selling only in the U.S. do not, but the normative requirements are identical in both versions.


The Risk Management File

The Risk Management File (RMF) is the central documentation output of the ISO 14971 process. It is the organized collection of records that demonstrates a manufacturer has systematically identified hazards, evaluated risks, implemented controls, and monitored the effectiveness of those controls throughout the device lifecycle.

The RMF is not a single document. It is a defined collection of records that includes:

  • Risk Management Plan (RMP): Defines the scope of risk management activities, the lifecycle phases covered, the risk acceptability criteria, the risk estimation methodology, and the verification activities planned
  • Risk Analysis records: Hazard identification outputs, risk estimation records, FMEA or other analysis tool outputs
  • Risk Evaluation records: Comparison of estimated risks against acceptability criteria
  • Risk Control records: Selected control measures, implementation records, verification that controls achieved their intended risk reduction, evaluation of introduced risks
  • Overall Residual Risk evaluation: Documentation of the overall residual risk assessment and benefit-risk analysis if required
  • Risk Management Review: Pre-release review record with identified reviewers
  • Post-Production information records: Systematic records of production and post-market information reviewed against the risk management file

A common audit finding is a Risk Management File that functions as a static document compiled at device release — rather than a living record updated throughout the device’s commercial life as post-production information is gathered. Under the QMSR, FDA investigators start inspections with the risk management file. A static RMF that hasn’t been updated since initial device release is a significant inspection vulnerability.

Feature image promoting an ISO 13485 Gap Assessment Checklist for medical device manufacturers, contract manufacturers, and component suppliers preparing for certification and FDA QMSR compliance.
ISO 13485 Gap Assessment Checklist designed to help medical device manufacturers identify compliance gaps, prioritize actions, and prepare for certification and FDA QMSR requirements.

📋 How does your risk management program measure up? Section 6 of the free ISO 13485 Gap Assessment Checklist covers ISO 14971 integration specifically — risk management plan requirements, RMF structure, post-production feedback, and the QMSR inspection implications. Download Free Checklist


ISO 14971 and ISO 13485 — How They Integrate

ISO 14971 and ISO 13485 are companion standards — not alternatives. ISO 13485 is the quality management system framework. ISO 14971 is the risk management framework that ISO 13485 requires to be implemented throughout that QMS.

ISO 13485 references ISO 14971 in multiple clauses:

  • Clause 7.1 — Planning of product realization: Risk management activities must be planned as part of product realization
  • Clause 7.3 — Design and development: Risk management must be integrated throughout design and development activities
  • Clause 7.4 — Purchasing: Supplier controls must reflect risk — suppliers of higher-risk components require more rigorous qualification
  • Clause 8.2.1 — Feedback: Post-market feedback must be evaluated in the context of risk management
  • Clause 8.5 — Improvement: CAPA and continual improvement activities must consider risk management outputs

ISO 14971 is not optional supplementary guidance for ISO 13485. Organizations implementing ISO 13485 must purchase and implement ISO 14971. It is an external document that must be controlled under ISO 13485 Clause 4.2.4 — registered, version-controlled, and accessible to relevant personnel.

For a complete comparison of how ISO 13485 and risk management requirements interact, see ISO 9001 vs ISO 13485 — Key Differences.

📋 Buy ISO 13485:2016 — ANSI Webstore — use coupon CC2026 for 5% off

Infographic mapping ISO 13485 clauses to corresponding ISO 14971 risk management requirements, showing how quality management processes trigger risk management activities across the medical device lifecycle.
ISO 13485 establishes quality system requirements, while ISO 14971 provides the risk management framework that connects planning, design, purchasing, feedback, and improvement activities throughout the medical device lifecycle.

ISO 14971 Under the FDA QMSR

The FDA’s Quality Management System Regulation (QMSR), effective February 2, 2026, incorporated ISO 13485:2016 by reference into 21 CFR Part 820 — and with it, ISO 13485’s explicit requirement for risk management per ISO 14971.

Under QMSR, several specific changes elevate the practical importance of ISO 14971:

Risk management now extends across the entire QMS. Under the old QSR, risk management was concentrated primarily in design controls. Under QMSR, risk-based thinking is required throughout the entire quality system — supplier controls, production processes, CAPA, complaint handling, and post-market surveillance. ISO 14971 is the expected framework for implementing this expanded risk management scope.

FDA investigators start inspections with the risk management file. Under Compliance Program 7382.850 — the new inspection program that replaced QSIT on February 2, 2026 — FDA investigators are expected to begin inspections by reviewing the risk management file and following risk documentation into other quality system areas. A well-maintained, current risk management file is inspection preparation. An incomplete or static risk management file is an inspection liability.

Post-market surveillance feeds the risk management file. The QMSR’s requirements for production and post-production information — complaint handling, MDR, field corrections — are expected to feed systematically into the risk management file. Organizations that maintain complaint handling and risk management as separate, unconnected systems have a QMSR gap.

For the complete QMSR transition guide, see FDA QSR vs ISO 13485: The Complete QMSR Transition Guide.


ISO/TR 24971 — The Companion Guidance Document

ISO/TR 24971:2020 is the technical report published as a companion to ISO 14971:2019. Unlike ISO 14971, which is a normative standard (its requirements are mandatory for certification purposes), ISO/TR 24971 is guidance — it does not add requirements but provides practical methodology for implementing ISO 14971’s requirements.

ISO/TR 24971:2020 covers:

  • Guidance on risk management planning
  • Practical methods for hazard identification and risk estimation
  • Guidance on benefit-risk analysis
  • Application of risk management to software
  • Application of risk management to usability and human factors
  • Guidance on production and post-production information processes

For organizations building or rebuilding their risk management program, ISO/TR 24971 is the practical implementation companion to ISO 14971’s requirements. Many experienced quality and regulatory professionals recommend reading both together.

📋 ISO/TR 24971:2020 — ANSI Webstore — use coupon CC2026 for 5% off


How to Buy ISO 14971

ISO 14971 is a copyrighted document and must be purchased from an authorized source. It cannot be legally downloaded for free.

The ANSI Webstore is the authorized U.S. distributor for ISO standards. ISO 14971:2019 is available in PDF format with immediate download after purchase.

📋 ISO 14971:2019 — ANSI Webstore — use coupon CC2026 for 5% off through December 31, 2026

Bundle with ISO 13485 — Save Up to 50%

Organizations implementing ISO 13485 need both standards. Purchasing as a bundle through the ANSI Webstore saves significantly compared to individual purchases.

📋 ISO Standards Bundles — Save up to 50%

For the complete guide to purchasing ISO 13485, see Buy ISO 13485 — Complete Purchasing Guide.


Frequently Asked Questions

What is ISO 14971 used for?

ISO 14971 is the international standard for applying risk management to medical devices. It provides the structured process — hazard identification, risk estimation, risk evaluation, risk control, overall residual risk evaluation, and post-production monitoring — that manufacturers must use to demonstrate that their devices are safe for their intended use.

Is ISO 14971 required for ISO 13485 certification?

Yes. ISO 13485 explicitly requires risk management per ISO 14971 throughout the medical device quality management system. Organizations cannot achieve ISO 13485 certification without demonstrating that their risk management program is built on the ISO 14971 framework. ISO 14971 must be controlled as an external document within the ISO 13485 QMS.

Is ISO 14971 required by the FDA?

ISO 14971 is not listed as a statutory FDA requirement. However, the FDA recognizes ISO 14971 as the state of the art for medical device risk management. Under the QMSR, effective February 2, 2026, ISO 13485 is incorporated by reference into 21 CFR Part 820 — and ISO 13485 explicitly requires ISO 14971. FDA investigators under CP 7382.850 use the risk management file as their inspection starting point. For practical purposes, ISO 14971 is effectively mandatory for any FDA-regulated medical device manufacturer.

What is the difference between ISO 14971:2007 and ISO 14971:2019?

The 2019 edition introduced several substantive changes: benefit-risk analysis is now a formal requirement when overall residual risk is not acceptable; both normal use and fault conditions must be analyzed during hazard identification; post-production requirements are more prescriptive; and the Risk Management Report was renamed Risk Management Review to signal an active review activity rather than a passive document.

What is the Risk Management File?

The Risk Management File (RMF) is the organized collection of records that demonstrates a manufacturer has systematically implemented the ISO 14971 risk management process. It includes the Risk Management Plan, hazard analysis records, risk evaluation records, risk control records, overall residual risk evaluation, risk management review, and post-production information records. The RMF is a living document — it must be updated throughout the device’s commercial life as post-production information is gathered.

What is ISO/TR 24971?

ISO/TR 24971:2020 is the technical report companion to ISO 14971:2019. It provides practical guidance on implementing ISO 14971’s requirements — methods for hazard identification, risk estimation, benefit-risk analysis, software risk management, and post-production information processes. It does not add normative requirements but is an essential practical companion for organizations building or rebuilding their risk management programs.

What is the difference between ISO 14971 and ISO 31000?

ISO 14971 is specific to medical device risk management and defines risk purely in terms of harm to people — the combination of probability of harm and severity of that harm. ISO 31000 is a broader enterprise risk management standard with a wider definition of risk that includes any effect on objectives, including positive risks (opportunities). The two standards serve different purposes and are not interchangeable in the medical device context.

Does ISO 14971 apply to software as a medical device?

Yes. ISO 14971:2019 explicitly applies to Software as a Medical Device (SaMD). ISO/TR 24971 provides specific guidance on applying ISO 14971 to software. The companion standard IEC 62304 — Medical Device Software Lifecycle Processes — also references ISO 14971 risk management requirements throughout its software development lifecycle requirements.


📥 Free Resources


Not Sure What to Do Next?

✅ You need the official ISO 14971:2019 standard 📋 ISO 14971:2019 — ANSI Webstore — use coupon CC2026 for 5% off through December 31, 2026

✅ You also need ISO 13485:2016 — the required companion QMS standard 📋 ISO 13485:2016 — ANSI Webstore — use coupon CC2026 for 5% off

✅ You need the ISO/TR 24971 implementation guidance companion 📋 ISO/TR 24971:2020 — ANSI Webstore — use coupon CC2026 for 5% off

✅ You want to save buying multiple standards together 📋 ISO Standards Bundles — Save up to 50% — ANSI Webstore

✅ You need ISO 13485 training that covers ISO 14971 integration 📋 BSI Group ISO 13485 Training

✅ You are ready to pursue ISO 13485 certification 📋 ISOQAR ISO 13485 Certification

✅ You want to understand what ISO 13485 requires 📋 What Is ISO 13485? — Complete Guide

✅ You want to understand the FDA QMSR and how ISO 14971 fits 📋 FDA QSR vs ISO 13485 — The Complete QMSR Transition Guide

✅ You want to compare ISO 9001 and ISO 13485 📋 ISO 9001 vs ISO 13485 — Key Differences

✅ You want to understand ISO 13485 purchase options and cost 📋 Buy ISO 13485 — Complete Purchasing Guide 📋 How Much Does ISO 13485 Cost?


Risk Management Is Not a Deliverable. It’s an Operating Model.

ISO 14971 is not a checkbox on a certification audit list. It is the framework that determines whether the medical devices your organization produces — or supplies components for — are demonstrably safe for their intended use.

Under the FDA’s QMSR, effective February 2, 2026, that framework now carries federal regulatory weight. Risk management under QMSR extends across the entire quality system, and FDA investigators under CP 7382.850 are using the risk management file as their inspection roadmap.

The organizations that navigate this environment successfully are the ones that treat risk management as an operating discipline — not a documentation exercise. The Risk Management File is updated because post-market data is being systematically reviewed, not because an audit is scheduled. CAPA is connected to the risk management file because the quality system is integrated, not because an investigator asked to see the connection.

That is what ISO 14971, properly implemented, actually produces.

At The Standards Navigator, complex standards are translated into practical, real-world guidance you can act on.

✅ Get updates on new standards, implementation strategies, and compliance insights ✅ Be first to access new guides, tools, and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required