What it is
Risk Management is a documented, ongoing process to identify hazards, estimate and evaluate risks, implement controls, and monitor effectiveness so devices remain safe and perform as intended. It links design, manufacturing, labeling, and post-market data and must stay current across the lifecycle (ISO 14971:2019; MDR 2017/745 Annex I Ch. I §1–9; IVDR Annex I; FDA 21 CFR 820 QMSR).
Regulatory framework
- EU (MDR/IVDR): General Safety and Performance Requirements mandate risk management integrated with design, usability, and clinical evidence (MDR Annex I Ch. I §1–9; Art. 10(2); IVDR Annex I).
- US (FDA): QMSR (21 CFR 820) expects risk-based controls across design and production; design validation must address user needs and intended use (21 CFR 820.30(g)).
- Core standards: ISO 14971:2019 (risk process), ISO/TR 24971 (guidance), IEC 62366-1 (use-related risk), IEC 62304/IEC 82304-1 (software risk), IEC 60601-1 (residual risk disclosure).
Key elements
- Risk management plan with roles, criteria, and methods.
- Hazards, hazardous situations, foreseeable misuse, and user errors.
- Risk estimation and acceptance criteria aligned with policy.
- Risk controls: inherent safety by design, protective measures, and information for safety.
- Verification of control effectiveness and evaluation of residual risk/benefit-risk.
- Risk management report and continuous PMS/PMCF feedback.
Process — how it works
- Plan: Define scope, criteria, and interfaces; then approve the risk plan (ISO 14971 §4).
- Analyze: Identify hazards from design, use, software, and supply chain; estimate risks with clear assumptions.
- Control: Select and implement controls; verify they work; update usability, software, and labeling accordingly.
- Evaluate: Reassess residual risk and overall benefit-risk; document rationales and any risk-benefit trade-offs.
- Monitor: Trend complaints, vigilance, and manufacturing data; trigger CAPA and update the file through PMS/PMCF.
Common pitfalls
- Listing hazards without linking to specific controls or tests.
- Ignoring foreseeable misuse and user errors identified by HFE.
- Accepting residual risk without a clear benefit-risk justification.
- Stale files that do not reflect field data, changes, or software updates.
- Using warnings as first-line controls instead of inherent design measures.
Quick checks / Tips
- Can you trace each hazard → control → verification → residual risk?
- Do acceptance criteria match company policy and standards?
- Do PMS/PMCF signals revise risk estimates and labeling fast enough?
- Are usability and software risks handled per IEC 62366-1 and IEC 62304?
FAQ
Is risk management mandatory?
Yes. EU MDR/IVDR and FDA QMSR require a documented, maintained risk process aligned with ISO 14971 throughout the lifecycle.
What counts as an effective control?
Design measures first, protective measures next, and information for safety last—verified for effectiveness and tied to specific hazards (ISO 14971 §7).
How does risk management link to clinical evidence?
Risk controls and residual risks inform endpoints, inclusion/exclusion, and labeling; CER/PMCF must confirm the benefit-risk conclusion over time (MDR Annex I, Annex XIV).
Do software and AI need special treatment?
Yes. Apply IEC 62304/IEC 82304-1 and cybersecurity controls; manage data quality, model updates, and real-world performance as part of the risk file.
When should we update the risk file?
At design changes, process changes, new complaints or trends, field actions, or new scientific information—then re-evaluate overall benefit-risk.