How do medical device manufacturers build a standard-compliant risk management system in accordance with ISO 14971?
We build and review risk management systems in accordance with ISO 14971:2019, from hazard analysis through risk evaluation and the effectiveness of risk controls to the complete Risk Management File. Across the lifecycle we keep the file current with post-production data from post-market surveillance. The critical spot is not the choice of method between FMEA and FTA, but the clean translation of method output into the risk logic of the standard: a failure mode is not yet a hazard, and a top event is not yet a risk.
- MedTech
- IVD
Overview
What requirements does ISO 14971 place on risk management?
Risk management for medical devices (MDR) and IVDs (IVDR) · ISO 14971:2019, ISO/TR 24971, IEC 62304
Last updated: 2026-06-12
ISO 14971:2019 does not require a single document, but a process maintained across the entire product lifecycle. The points where manufacturers most often get stuck in practice:
- Risk management is a mandatory part of the General Safety and Performance Requirements: MDR (EU) 2017/745 Annex I and IVDR (EU) 2017/746 Annex I require documented risk management across the lifecycle. For the EU, EN ISO 14971:2019+A11:2021 (with Annexes ZA/ZB) is the version harmonized under MDR and IVDR.
- Risk acceptability criteria must be defined and justified before risk evaluation; the 2019 version softened the ALARP principle for the European scope of application and requires an evaluation of overall residual risk.
- The Risk Management File must, in accordance with ISO 14971:2019, bring together every hazard, every risk control measure, and evidence of its effectiveness in a traceable manner, rather than being a loose collection of FMEA tables.
- Production and post-production: ISO 14971:2019 requires the ongoing feedback of field data and post-market surveillance information into the risk evaluation, not just an analysis prior to market launch.
- Software and usability are distinct sources of risk: IEC 62304 and IEC 62366-1 provide inputs to risk management in accordance with ISO 14971, but do not replace it.
Services
How we support you
Risk analysis & risk evaluation
Preparation and review of hazard and risk analyses in accordance with ISO 14971:2019 using FMEA, FTA, and Preliminary Hazard Analysis; documented risk acceptability criteria with justification based on clinical data.
Risk Management File & lifecycle
Building a complete Risk Management File in accordance with ISO 14971:2019 with end-to-end traceability from hazard through risk control measure to evidence of effectiveness; anchoring it in the development and change-management process.
Translating methods into ISO 14971 logic
Structured conversion of method output (FMEA failure modes, FTA top events, HAZOP deviations) into hazards, hazardous situations, and risks in accordance with the logic of the standard, as a traceable mapping rather than parallel tables.
Post-production risk review
Evaluation of PMS data, field feedback, and vigilance information for the ongoing risk evaluation; an updated Risk Management File with documented evaluation of overall residual risk.
Learn more →Risk management for software (SaMD)
Risk management for Software as a Medical Device in accordance with ISO 14971:2019 in conjunction with IEC 62304; software safety classification, analyses, and documentation for the regulatory submission.
Linkage with usability & clinical evaluation
Connecting usability engineering per IEC 62366-1 and the clinical evaluation to the Risk Management File; documented bidirectional linkage between clinical evidence and risk acceptability.
How we work together
What it comes down to
The most common question in risk projects is which method to use: FMEA, FTA, HAZOP, or several in parallel. That question falls short. Methods such as PHA, FMEA, FTA, ETA, HAZOP, or HACCP are established tools, but they are not the same as the risk analysis required by ISO 14971:2019. A failure mode from the FMEA is not yet a hazard, and a top event from the FTA is not yet a risk. Between method output and risk analysis there is almost always a separate step: the analytical translation into the logic of the standard, from the hazard through the hazardous situation to harm. This is exactly where most weaknesses arise. It is not methodological breadth but analytical coherence that determines whether the file holds up in an audit.
The right sequence protects against the expensive loops. First the risk acceptability criteria are defined and justified in the risk management plan, then risks are evaluated, not the other way around. First the method output is translated into hazards, then transferred into the Risk Management File in accordance with ISO 14971:2019, which links every risk control measure to its evidence of effectiveness in a traceable way. And the file does not end at market launch: the production and post-production phase of ISO 14971:2019 requires that field data from post-market surveillance feed back into the risk evaluation and that the overall residual risk is reassessed. Anyone who maintains this chain avoids the two findings that most often come up in the surveillance audit: untranslated method tables and an outdated, unmaintained residual risk.
Our approach
Our approach
Step
Result
Scope & risk management plan
Defined scope of application, an established risk management plan, and justified risk acceptability criteria before the analysis begins.
Hazard & risk analysis
Identified hazards and hazardous situations, evaluated risks with method output cleanly translated into the logic of ISO 14971.
Risk control
Defined and prioritized risk control measures following the risk control hierarchy, with planned evidence of effectiveness.
Risk Management File
A complete Risk Management File in accordance with ISO 14971:2019 with end-to-end traceability and evaluation of overall residual risk.
Production & post-production
An established feedback loop from PMS and field data into the risk evaluation, integrated into change management.
Common pitfalls
Where projects commonly fail
Methods are confused with risk analysis.
FMEA, FTA, or HAZOP produce output, but a failure mode is not yet a hazard and a top event is not yet a risk. Without the translation into the logic of ISO 14971:2019, the tables remain without a traceable link to the hazardous situation and to harm. This is the most common audit finding.
Risk acceptability criteria are adjusted to the result after the fact.
ISO 14971:2019 requires the criteria to be set in the risk management plan before risks are evaluated; if they are only defined once the risks are on the table, the acceptance decision cannot be justified.
The ALARP principle is carried over unchanged from old files.
For the European scope of application, ISO 14971:2019 no longer relies on economic reasonableness; files that justify residual risks with cost-and-effort arguments do not conform to the current standard.
The evaluation of overall residual risk is missing.
Individual risks are evaluated, but the overall residual risk across all hazards required by ISO 14971:2019 is not assessed in its own right and weighed against the clinical benefit.
Post-production is treated as a conclusion rather than an input.
Without a documented feedback loop of PMS and field data into the Risk Management File, a gap opens up between MDR post-market surveillance and risk management that is flagged in the surveillance audit.
FAQ
Frequently asked questions
Sources
- ISO 14971:2019: Application of risk management to medical devices, incl. Section 4.5 (Risk Management File) and Section 8 (overall residual risk)
- ISO/TR 24971:2020: Guidance on the application of ISO 14971
- IEC 62304: Software lifecycle processes for medical device software
- IEC 62366-1: Application of usability engineering to medical devices
- Regulation (EU) 2017/745 (MDR): Annex I (General Safety and Performance Requirements)
- Regulation (EU) 2017/746 (IVDR): Annex I (General Safety and Performance Requirements)
- https://theentourage.de/expertise/risikomanagement/ (existing page content, revised)
Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Case Studies
What this looks like in practice
Related insights
All insights →Regulations & standards considered
- ISO 14971:2019 (Application of risk management to medical devices)
- EN ISO 14971:2019+A11:2021 (EU version harmonized under MDR and IVDR)
- ISO 14971:2019 Section 4.5 (Risk Management File)
- ISO 14971:2019 Section 8 (Evaluation of overall residual risk)
- ISO/TR 24971:2020 (Guidance on the application of ISO 14971)
- EU 2017/745 (MDR) Annex I (General Safety and Performance Requirements)
- EU 2017/746 (IVDR) Annex I (General Safety and Performance Requirements)
- IEC 62304 (Software lifecycle for medical device software)
- IEC 62366-1 (Usability / usability engineering)
Related topics
MDR Consulting →
Risk management per ISO 14971 as a core requirement of the MDR (EU) 2017/745
IVDR Readiness →
Risk management as part of the IVDR requirements under EU 2017/746
Post-Market Surveillance →
PMS and field data as input for the ongoing risk evaluation
Labeling & IFU →
Communicating residual risks via the instructions for use and warnings
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences


