ISO 14971:2019 risk management checklist
Practising auditors wrote these 137 audit questions, covering the full standard. Each item names the objective evidence to request, the nonconformities most often raised against it, and what to sample. It is free to read, with no sign-up required.
Download the PDF
Includes all 137 items, formatted for a clipboard.
You will get one email with the file. We will not send anything else.
What each item gives you
This is what an auditor needs at each item. You already hold the standard itself.
Phrases it the way you would ask it in the room.
Names the specific artefacts that satisfy the item, and how to tell a real one from a placeholder.
Lists the findings most often raised here, in the words they get written up in.
Shows where the item usually goes wrong, and what a mature answer sounds like against a rehearsed one.
Explains how many to take, how to choose them, and what to cross-reference them against.
Gives the second and third questions to ask when the first answer is too smooth.
All 137 items on this page
Questions below are grouped by section, and you can check items off as you go — this browser remembers your progress. Open any row for its evidence, common nonconformities and auditor tips.
§4 General requirements for risk management
4 Can the manufacturer show a comprehensive risk management process covering concept through disposal, integrated with the QMS?
- Risk management procedure or standard operating procedure
- Risk management process flowchart
- Risk management policy statement
- Integration with quality management system documentation
- Risk management training curriculum and attendance records
- Cross-functional risk team charter and meeting schedule
- Risk management software or tool validation records
- Process not covering entire product lifecycle
- Missing integration with QMS processes
- Lack of ongoing maintenance procedures
- No clear process ownership or responsibilities
- Risk management activities conducted by a single individual without cross-functional input
- No periodic effectiveness review of the risk management process
A comprehensive risk management process must be established that covers the entire product lifecycle from initial concept through design, manufacturing, distribution, use, and final disposal. This process must be systematic, documented, and continuously maintained with defined roles, cross-functional participation, and integration into the quality management system. The process should address both foreseeable and emerging hazards using structured techniques such as FMEA, fault tree analysis, and severity-probability matrices.
4 Is risk management maintained as an ongoing activity from conception through disposal, rather than a one-time design exercise?
- Lifecycle phase documentation in risk management plan
- Risk management activities mapped to development phases
- Post-production risk management procedures
- Decommissioning risk assessments
- Change management risk assessment procedure
- Post-production risk monitoring metrics dashboard
- Risk management file update log showing lifecycle updates
- Risk management ending at product release
- No post-market risk management activities
- Missing risk assessment for disposal/decommissioning
- Inadequate change management risk assessment
- No documented triggers for risk re-assessment during lifecycle changes
- Post-market surveillance data not linked to risk management file
Risk management is not a one-time activity but must be maintained from initial conception through design, production, distribution, clinical use, servicing, and final disposal of the device. Each lifecycle phase introduces unique hazards that require identification and control. Design changes, manufacturing process modifications, and post-market field data must all trigger risk re-assessment activities to ensure ongoing safety throughout the device's commercial life.
4 Does the process systematically address all four key elements in a coordinated way, with each building on the previous?
- Process documents showing all four elements
- Risk analysis reports
- Risk evaluation criteria and decisions
- Risk control measures and verification
- Post-production monitoring procedures
- Procedure interrelationship diagram showing element linkages
- Training records demonstrating understanding of all four elements
- Missing or weak risk evaluation criteria
- Inadequate post-production activities
- Poor linkage between elements
- Incomplete risk control verification
- Risk control measures implemented without prior risk evaluation
- No feedback loop from post-production back to risk analysis
The risk management process must systematically address all four key elements to ensure comprehensive risk management: risk analysis identifies hazards and estimates risks, risk evaluation determines acceptability, risk control reduces unacceptable risks, and production/post-production activities provide ongoing monitoring. These elements must be interconnected with clear feedback loops, not treated as isolated sequential steps, to maintain a living risk profile throughout the device lifecycle.
4 Is risk management woven into product realization (design, V&V, production), rather than operating separately?
- Design control procedures with risk management integration
- Manufacturing process risk assessments
- Risk-based validation protocols
- Risk management deliverables in project plans
- Process FMEA integrating manufacturing risk with product risk
- Gate review checklists with mandatory risk deliverables
- Supplier qualification risk assessments
- Parallel but disconnected processes
- Risk management as afterthought
- Missing risk-based decision points
- No risk management in change control
- Design reviews proceeding without risk management deliverables
- No risk-based input into verification and validation planning
Risk management must be integrated into existing product development and realization processes rather than operating as a separate parallel system. Design reviews, verification planning, validation protocols, and change control procedures should all include risk management deliverables as mandatory inputs. This integration ensures risk considerations drive design decisions in real time and that design changes trigger immediate risk re-assessment rather than periodic batch updates.
4 Is risk management documented sufficiently for an independent reviewer to confirm compliance with the standard?
- Risk management file
- Risk management plan
- Risk analysis reports
- Risk management review records
- Traceability matrices
- Document control procedure governing risk management records
- Internal audit findings related to risk management documentation
- Incomplete documentation
- Missing approval signatures
- Poor document control
- Inadequate record retention
- Risk management records not controlled under the document control system
- No internal audit coverage of risk management documentation completeness
All risk management activities must be documented to demonstrate compliance with the standard through objective evidence. Documentation must be sufficient for an independent reviewer or auditor to reconstruct the risk management rationale, trace each hazard from identification through control and residual risk acceptance, and verify that the process was followed systematically. Records must be controlled, retained, and readily accessible for regulatory inspection.
4.1 Has the manufacturer established and documented a risk management process covering the full device lifecycle, and is it maintained in practice?
- Risk management procedure document
- Risk management process flowchart with decision points
- Integration points with QMS processes
- Process owner assignments and responsibilities
- Risk management training records
- Process review and update records
- Risk management effectiveness metrics and trending reports
- Process not fully documented
- Missing monitoring effectiveness procedures
- No clear process ownership
- Inadequate training on the process
- Process not regularly reviewed or updated
- Poor integration with change management
- Risk management process not aligned with current regulatory requirements
A risk management process must cover the full device lifecycle: identifying hazards across all reasonably foreseeable use scenarios, estimating risk against defined scales and criteria, evaluating risk against approved acceptability thresholds, implementing risk controls in the established priority order, and monitoring control effectiveness using production and post-market data. The process can sit within the existing quality management system and should connect to product-realization activities such as the design and production controls in ISO 13485. Auditors should confirm the process is actually maintained in practice, not documented once and shelved.
4.1 (Elements) Does the process coordinate all four core elements - risk analysis, risk evaluation, risk control, and production/post-production monitoring?
- Procedures for each element
- Templates for each activity
- Decision criteria documentation
- Element interconnection documentation
- Review and approval requirements
- Completed risk analysis worksheets for current product
- Risk evaluation decision log with rationale
- Post-production information collection and review records
- Weak or missing risk evaluation criteria
- Inadequate post-production procedures
- Poor linkage between elements
- Missing feedback loops
- Risk control implemented without documented risk evaluation
- Post-production monitoring plan absent or generic
The process must systematically address all four core elements of risk management in a coordinated manner: risk analysis to identify and estimate hazards, risk evaluation to judge acceptability, risk control to reduce unacceptable risks, and production/post-production activities for ongoing monitoring. These elements form an iterative cycle where post-production data feeds back to refine risk analysis. Each element must have defined inputs, outputs, decision criteria, and documentation requirements to ensure a complete and auditable risk management record.
4.1 (Integration) Is risk management integrated into existing development processes (design reviews, V&V), not run as a separate parallel administrative exercise?
- Design control procedures with risk management
- Project plans showing risk deliverables
- Gate reviews including risk assessments
- Risk-based validation planning
- Change control risk requirements
- Process FMEA records linked to product risk management
- Supplier qualification risk assessment documentation
- Design review meeting minutes showing risk discussion agenda items
- Separate, uncoordinated processes
- Risk management as add-on activity
- No risk-based decision gates
- Missing from change control
- Design outputs do not reference risk control requirements
- Verification and validation plans lack risk-based test case derivation
Risk management must be integrated into existing development processes, not run in parallel as a separate administrative exercise. Product realization activities such as design input definition, design verification, design validation, process validation, and change control should each incorporate risk management deliverables. Gate reviews must include risk status as a mandatory criterion for progression. This ensures risk considerations actively drive design decisions rather than merely documenting them after the fact.
4.1 (Lifecycle) Does the risk management process operate across the whole lifecycle (concept to disposal), addressing the hazards each phase introduces, not just design?
- Risk management activities in design phase
- Manufacturing risk assessments
- Post-market surveillance risk reviews
- Field action risk assessments
- End-of-life risk considerations
- Decommissioning risk assessment for end-of-life planning
- Change management procedure requiring risk re-assessment
- Supply chain disruption risk evaluation records
- Risk management stops at product release
- No post-market risk management activities
- Missing risk assessment for changes
- No consideration of disposal risks
- Field safety corrective actions not triggering risk file updates
- No defined process for incorporating post-market vigilance data
Risk management must be an ongoing process from initial concept through final disposal, not just during design and development. Each lifecycle phase introduces unique hazards: design decisions may create latent failure modes, manufacturing variations can affect safety margins, distribution and storage conditions can degrade device integrity, clinical use exposes patients to residual risks, and disposal may involve biohazard or environmental concerns. The process must have defined triggers for re-assessment at each phase transition.
4.2 Does top management demonstrate active commitment to risk management through resource allocation and personnel assignment, not just a policy statement?
- Resource allocation documentation
- Budget approvals for risk management
- Personnel assignments and job descriptions
- Training budget and records
- Management review minutes
- Organizational charts showing risk roles
- Risk management policy signed by CEO or executive leadership
- No documented resource allocation
- Insufficient personnel for workload
- Lack of management involvement
- No evidence of commitment
- Inadequate training resources
- Management review minutes show no discussion of risk management topics
Top management must show active commitment through real resource allocation and personnel assignment, not just a signed policy. ISO/TR 24971 stresses that this commitment should be visible and measurable. Operational responsibility can be delegated, but accountability remains with top management, so look for evidence of genuine engagement (budget, headcount, participation in risk reviews) rather than a policy statement alone.
4.2 (Policy) Has management established a policy defining how risk acceptability criteria are determined, considering regulatory requirements and the state of the art?
- Risk acceptability policy document
- Policy approval by top management
- Reference to regulations and standards
- State of the art considerations
- Stakeholder input documentation
- Regulatory landscape analysis informing acceptability criteria
- Periodic policy review and revision records
- No formal policy documented
- Policy not approved by management
- Missing regulatory alignment
- No state of the art consideration
- Stakeholder concerns not addressed
- Risk acceptability criteria not updated when regulations change
Management must establish a formal policy that defines how risk acceptability criteria are determined, considering regulatory requirements and state of the art. The policy should include clear statement of risk philosophy, reference to applicable regulations, process for determining acceptability levels, consideration of similar devices, and benefit-risk framework.
4.2 (Review) Does management periodically review the effectiveness of the risk management process itself (e.g. at least annually), not just individual assessments?
- Management review schedule
- Review meeting minutes
- Process effectiveness metrics
- Action items and follow-up
- Process improvement decisions
- Risk management process effectiveness trend analysis reports
- Corrective actions arising from management review of risk process
- No planned review intervals
- Reviews not documented
- No effectiveness measures
- Actions not tracked to completion
- Process never updated
- Management review agenda does not include risk management process assessment
Management must conduct periodic reviews of the risk management process effectiveness, not just individual risk assessments. ISO/TR 24971 recommends at least annual reviews, or when significant changes occur. Reviews should assess effectiveness indicators such as field issues, process timeliness, quality of assessments, and regulatory findings.
4.3 Are competency requirements defined for risk management roles, with evidence that personnel meet them?
- Competency matrices for risk roles
- Training records and certificates
- Education and experience documentation
- Job descriptions with requirements
- Competency assessments
- Cross-functional team composition
- Annual competency review records for risk management personnel
- No defined competency requirements
- Missing training records
- Inadequate cross-functional expertise
- No ongoing competency assessment
- Single person doing all risk work
- Risk management team lacks clinical or medical expertise representation
Organizations must define competency requirements for risk management roles, ensure personnel meet these requirements, and maintain evidence of competence. ISO/TR 24971 identifies key competency areas: risk management principles and methods, medical device technology, clinical application and use environment, regulatory requirements, statistical methods, human factors/usability engineering, manufacturing processes, and quality system requirements.
4.3 (Knowledge) Does risk-management competence cover both technical device knowledge and clinical/regulatory context, with the right mix per role?
- Clinical use training documentation
- Regulatory training certificates
- Technical device training
- Risk methodology training
- Experience with similar devices
- Cross-functional team composition chart showing expertise areas
- Regulatory affairs training completion certificates
- Missing clinical perspective
- Inadequate regulatory knowledge
- No risk methodology training
- Lack of device-specific knowledge
- No team member with hands-on experience with the device type
- Regulatory training not updated after major regulatory changes
Competence must cover both technical device knowledge and broader contextual understanding including clinical use and regulatory environment. Not every person needs all competencies, but the team collectively should cover all areas including clinical/medical expertise, engineering/design expertise, manufacturing expertise, quality/regulatory expertise, service/field experience, and human factors expertise.
4.3 (Records) Are competence records documented, controlled, and retained, demonstrating not just training completion but actual capability?
- Training database or files
- Competency assessment records
- Qualification certificates
- Experience summaries
- Annual competency reviews
- Electronic training management system reports
- Competency gap analysis with remediation action plans
- Incomplete records
- No retention policy
- Missing update procedures
- No periodic review
- Training records not accessible for regulatory audit
- No procedure for updating competency records when roles change
Competence records must be documented, controlled, and retained per quality system and regulatory requirements. Records should demonstrate not only that training was completed but that competence was assessed and confirmed through objective means such as examinations, practical demonstrations, or supervised work products. Records must be maintained throughout employment and updated when roles change, new competency requirements emerge, or periodic reassessments are conducted.
4.4 Is a documented risk management plan created before risk activities begin, defining scope, responsibilities, review, and acceptability criteria?
- Risk management plan document
- Plan approval records
- Device family justification
- Plan version control
- Plan stored in risk management file
- Risk management plan template with standardized sections
- Plan completeness checklist used before approval
- Plan created after activities begin
- Generic plan not tailored to device
- Plan not formally approved
- Missing from risk management file
- Inadequate device family justification
- Plan scope does not match actual device configurations or variants
A documented plan must be created before risk management activities begin, either for individual devices or device families where appropriate. The plan establishes the scope, methodology, and acceptance criteria for all subsequent risk management activities. Device family plans must include a clear justification for grouping and analysis of common versus unique hazards. The plan must be formally approved, version-controlled, and stored in the risk management file. It serves as the foundational roadmap ensuring systematic and consistent risk management execution.
4.4 (Contents) Does the risk management plan address all required elements (scope, responsibilities, review requirements, acceptability criteria, verification, and production/post-production activities)?
- Scope statement with device description
- Responsibility matrix or RACI chart
- Review schedule and criteria
- Risk acceptability matrix
- Overall residual risk criteria
- Verification plan
- Post-production monitoring plan
- Incomplete scope definition
- Vague responsibility assignments
- Missing acceptability criteria
- No criteria for unknown probabilities
- Inadequate post-production planning
- Verification activities not linked to specific risk control measures
The plan must comprehensively address all aspects of how risk management will be conducted, with specific required elements covering scope, responsibilities, review requirements, acceptability criteria, overall residual risk evaluation methodology, verification activities, and post-production information collection. Each element should be sufficiently detailed to guide execution without ambiguity. The scope must clearly identify the device, lifecycle phases covered, and any exclusions. Responsibility assignments should use a RACI or equivalent framework.
4.4 (Review) Is the plan actively maintained and updated as new information emerges, with defined update triggers?
- Plan revision history
- Review triggers defined
- Update approval records
- Change justifications
- Review meeting minutes
- Plan change approval workflow documentation
- Trigger criteria for unscheduled plan reviews
- Plan never updated after initial approval
- No defined review triggers
- Updates not documented
- No version control
- Plan version history shows no updates since initial approval
- No documented criteria for when plan updates are required
The plan must be actively maintained and updated throughout the risk management process as new information becomes available. This requires defined criteria for when updates are necessary, a formal change control process for plan modifications, management approval of significant changes, and distribution of updated plans to all stakeholders. The plan should be reviewed at minimum when significant design changes occur, when post-market data reveals new hazards, when regulatory requirements change, or when process improvements are identified.
4.4(a) Does the plan define which device(s) and lifecycle phases it covers, with any exclusions justified?
- Device name and model numbers
- Intended use statement
- Lifecycle phase coverage
- Exclusions clearly stated
- Configuration/variant coverage
- Regulatory classification justification linked to scope
- Accessory and component coverage documentation
- Ambiguous device identification
- Missing lifecycle phases
- Unclear variant coverage
- No intended use statement
- Scope does not mention software components or cybersecurity aspects
- No documentation of lifecycle phase boundaries and transitions
The plan must clearly define what device(s) it covers and which lifecycle phases are addressed, including any exclusions with documented justification. The scope should reference the device name, model numbers, intended use statement, regulatory classification, applicable standards, and all variants or configurations covered. Lifecycle phase coverage must explicitly address design, manufacturing, distribution, clinical use, maintenance, and disposal phases. Any narrowing of scope must be justified and approved.
4.4(b) Does the plan assign responsibility and authority for each risk management activity (e.g. via a RACI)?
- RACI matrix for risk activities
- Role descriptions
- Approval authority matrix
- Cross-functional team charter
- Competency requirements
- Succession planning for critical risk management roles
- Conflict of interest disclosure for risk team members
- Unclear approval authorities
- Missing competency requirements
- No backup assignments
- Inadequate cross-functional representation
- Same person both performs and approves risk management activities
- No succession plan for key risk management personnel
Clear assignment of who is responsible and has authority for each risk management activity is essential for accountability and efficient execution. The plan should use a RACI matrix or equivalent to define responsibility, accountability, consultation, and information roles for each major activity. Authority levels for risk acceptance decisions, the composition and charter of the cross-functional risk team, competency requirements for each role, and backup or succession assignments should all be documented.
4.4(c) Does the plan define when and how risk management activities will be reviewed (frequency, participants, criteria, escalation)?
- Review schedule and milestones
- Review criteria and checklists
- Review meeting requirements
- Approval requirements
- Review meeting agenda templates for risk activities
- Independent reviewer qualification criteria
- Review escalation procedures for unresolved issues
- No defined review points
- Unclear review criteria
- Missing review schedule
- Review meetings not documented with attendees and decisions
- No independent review of risk acceptability decisions
- Review outcomes not tracked through corrective action system
The plan must define when and how risk management activities will be reviewed, including the frequency, participants, criteria, and escalation procedures for review activities. Reviews should occur at planned milestones aligned with design control phases, when significant new information becomes available, and at defined intervals during the post-production phase. Review criteria should be objective and testable, reviewer qualifications should be specified, and review outcomes must be documented with action items tracked to closure.
4.4(d) Does the plan define how risk acceptability is determined, including how to handle cases where probability cannot be estimated?
- Risk acceptability matrix
- Probability and severity scales
- Criteria for unknown probabilities
- Benefit-risk criteria
- State of the art considerations
- Semi-quantitative risk matrix with defined probability and severity scales
- Rationale documentation for acceptability threshold selection
- No criteria for unknown probabilities
- Subjective acceptability criteria
- Missing benefit-risk considerations
- Criteria not aligned with regulations
- Risk matrix thresholds not justified by regulatory or clinical evidence
- No guidance for evaluators on borderline risk decisions
The plan must define how to determine if risks are acceptable, including special cases where probability cannot be determined. Criteria must include clearly defined probability and severity scales with unambiguous category boundaries, a risk acceptability matrix showing acceptable, ALARP, and unacceptable zones, specific criteria for handling risks where probability of occurrence cannot be estimated, guidance on benefit-risk considerations for borderline decisions, and alignment with applicable regulatory requirements and state of the art.
4.4(e) Does the plan define how overall residual risk will be evaluated and what makes it acceptable?
- Overall risk evaluation methodology
- Benefit-risk analysis approach
- Acceptability criteria for overall risk
- Decision-making framework
- Overall residual risk evaluation template and procedure
- Risk-benefit analysis framework documentation
- Criteria for distinguishing individual from overall residual risk
- No overall risk evaluation method
- Missing acceptability criteria
- No benefit-risk framework
- Overall residual risk treated as simple sum of individual risks
- No procedure for evaluating synergistic effects of multiple residual risks
- Benefit-risk framework absent for overall residual risk evaluation
The plan must define how all remaining risks will be evaluated collectively and what makes the overall residual risk acceptable. The overall residual risk evaluation must consider not just individual residual risks in isolation but their cumulative and synergistic effects on patient safety. The methodology should address how individual residual risks are aggregated, how interactions between residual risks are evaluated, and how the benefit-risk balance is assessed when overall residual risk exceeds normal thresholds.
4.4(f) Does the plan define how risk control measures will be verified - both that they were implemented and that they are effective?
- Verification plan
- Testing protocols
- Verification acceptance criteria
- Validation requirements
- Verification protocol templates for risk control measures
- Acceptance criteria linked to risk reduction targets
- Verification method selection rationale documentation
- No verification planning
- Unclear verification methods
- Missing acceptance criteria
- Verification activities not linked to specific risk control measures
- No acceptance criteria defined for verification testing
- Verification limited to design verification without clinical validation
The plan must define how risk control measures will be verified to ensure they are effective, including both implementation verification and effectiveness verification. Verification planning should specify methods such as testing, analysis, inspection, or demonstration; acceptance criteria derived from risk reduction targets; sample sizes and statistical rationale where applicable; and the relationship between risk verification activities and QMS design verification and validation activities.
4.4(g) Does the plan define how production and post-market data will be collected and reviewed for risk implications (complaints, adverse events, field data)?
- Post-market surveillance plan
- Complaint monitoring procedures
- Field data review process
- Feedback loops to risk management
- Complaint trend analysis procedures linked to risk management
- Adverse event reporting and risk assessment workflow
- Clinical follow-up data collection and review protocol
- No post-production planning
- Missing data collection methods
- No feedback mechanism
- Post-market surveillance plan does not reference risk management file
- No defined criteria for when field data triggers risk re-assessment
- Complaint handling procedure isolated from risk management process
The plan must define how production and post-market data will be collected and reviewed for risk implications, including sources such as complaint data, adverse event reports, field service records, clinical follow-up studies, and literature monitoring. The plan should specify data collection methods, review frequency, criteria for triggering risk re-assessment, responsible personnel, and feedback mechanisms to update the risk management file. This element ensures risk management remains a living process.
4.5 Is a risk management file maintained with traceability from hazard identification through final risk acceptance?
- Risk management file structure
- Traceability matrices
- Document control procedures
- File organization system
- Cross-reference mechanisms
- Electronic or physical filing system
- Risk management file index with document location references
- Incomplete traceability
- Missing documents
- Poor organization
- No clear structure
- Inadequate cross-referencing
- Mixed device families inappropriately
A risk management file must hold all risk management documentation with clear traceability from hazard identification through final risk acceptance. ISO/TR 24971 recommends a standardized structure spanning the risk management plan, analysis reports, evaluation documentation, control documentation, overall residual-risk evaluation, the risk management review, and post-production information. The file does not have to be a single binder; it can be assembled by reference from other QMS or regulatory records, in any suitable medium, as long as the traceability holds together.
4.5 (Contents) Does the risk management file contain (or reference) all key deliverables - the plan, risk analyses, evaluations, control records, and the overall residual risk evaluation?
- Complete risk management plan
- All risk analysis worksheets/reports
- Risk evaluation decisions
- Risk control verification records
- Risk management review reports
- Post-production surveillance data
- Table of contents with document references for each required element
- Missing post-production information
- Incomplete risk control verification
- No risk management review
- Poor reference management
- Outdated information
- Risk management review report missing from file
The file must contain all key risk management deliverables either directly or through clear references to their locations. ISO/TR 24971 provides content details: risk management plan (version-controlled, approved), risk analysis (all worksheets, FMEAs, FTAs, use error analysis), risk evaluation (decisions with rationale, meeting minutes), risk control (specifications, verification/validation reports), residual risk (final risk levels, benefit-risk analyses), risk review (management review with actions), and post-production (complaint data, field experience, updates).
4.5 (Maintenance) Is the risk management file kept current - updated on design changes, manufacturing changes, and new post-market information?
- File update procedures
- Change control records
- Post-market update logs
- Periodic review documentation
- File revision history
- Annual risk management file review schedule and completion records
- Trigger list for unscheduled file updates with responsible owners
- File not updated post-launch
- No maintenance procedures
- Missing change control
- Outdated risk assessments
- Risk management file has not been updated since initial product release
- No procedure defining when and how the file should be updated
The file is a living document that must be updated with new information throughout the entire device lifecycle. ISO/TR 24971 identifies update triggers: design changes, manufacturing process changes, new clinical data, adverse events, regulatory changes, new standards, complaint trends, and audit findings. Best practices include annual file review minimum, clear update procedures, version control system, archiving superseded documents, and maintaining file integrity.
§5 Risk analysis
5 Is a comprehensive risk analysis performed that systematically identifies and estimates the risks across the device lifecycle?
- Risk analysis procedure
- Risk analysis plan
- Cross-functional team records
- Information sources used
- Analysis methodology documentation
- Completeness verification
- Independent audit records confirming compliance with this requirement
- Incomplete scope definition
- Missing team expertise
- Inadequate information gathering
- No systematic approach
- Poor documentation structure
- No evidence of periodic review or update of this activity
Risk analysis is a comprehensive process that systematically identifies and estimates all risks associated with a medical device throughout its lifecycle. This is the foundation of risk management and must be systematic and comprehensive.
5 Are all five risk-analysis sub-elements completed systematically and documented, each building on the previous?
- Completed analysis for each element
- Integration between elements
- Sequential flow documentation
- Review checkpoints
- Approval records
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Skipping elements
- Poor integration
- No review points
- Inadequate documentation
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
All five sub-elements must be completed systematically and documented for comprehensive risk analysis. Each element builds on the previous one. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
5 Is the risk analysis updated as the design and knowledge evolve (design changes, new clinical data), rather than treated as one-time?
- Analysis update procedures
- Revision history
- Update triggers defined
- Change impact assessments
- Post-market updates
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- One-time analysis only
- No update procedures
- Missing revision control
- Ignoring new information
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Risk analysis is not a one-time activity but must be maintained and updated as the device and knowledge evolve. Updates should occur when design changes, new clinical data emerges, post-market events occur, or regulations change.
5.1 Does the risk analysis cover the scope defined in the risk management plan, including intended use and foreseeable misuse?
- Risk analysis report
- Intended use and misuse documentation
- Safety characteristics checklist
- Hazard identification worksheets
- Risk estimation matrices
- FMEAs, FTAs, or other analysis tools
- Use error analysis
- Missing reasonably foreseeable misuse
- Incomplete hazard identification
- No systematic approach to identification
- Risk estimation without data
- Missing use error considerations
- Inadequate cross-functional input
A comprehensive risk analysis must be performed that systematically identifies and estimates all risks associated with the device, including both intended use and foreseeable misuse scenarios.
5.1 (Documentation) Are the risk-analysis methods, data, and results documented and maintained in the risk management file?
- Risk analysis report
- Supporting data and references
- Meeting minutes and decisions
- Review and approval records
- Traceability to requirements
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Incomplete documentation
- Missing supporting data
- No approval records
- Poor traceability
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
All risk analysis activities, methods, data, and results must be documented and maintained in the risk management file. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
5.1 (Estimation) Does every hazardous situation have a risk estimate, with all possible consequences listed where probability cannot be determined?
- Risk estimation worksheets
- Probability and severity assignments
- Risk matrices or calculations
- Consequences lists for unknown probabilities
- Estimation rationale documentation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Missing risk estimates
- No approach for unknown probabilities
- Inconsistent estimation methods
- Inadequate estimation rationale
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Every hazardous situation must have an associated risk estimate, even when probability cannot be determined. In such cases, list all possible consequences. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
5.1 (Information) Is the risk analysis evidence-based, drawing on all relevant available information sources?
- Literature review documentation
- Standards reviewed list
- Similar device analysis
- Field data analysis reports
- Clinical evidence review
- Expert consultation records
- Database search results
- Limited information sources
- No similar device analysis
- Missing field data review
- Inadequate literature search
- No expert consultation
- No evidence of periodic review or update of this activity
Risk analysis must be evidence-based, using all available relevant information sources to ensure comprehensive hazard identification and accurate risk estimation. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
5.1 (Scope) Does the analysis cover the full scope set in the plan, with completeness across all planned areas?
- Risk analysis scope statement
- Reference to risk management plan
- Coverage of all plan elements
- Lifecycle phase coverage
- Variant/configuration coverage
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Scope mismatch with plan
- Missing lifecycle phases
- Incomplete variant coverage
- Undocumented scope changes
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
The risk analysis must cover the scope defined in the risk management plan, ensuring consistency and completeness across all planned areas. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
5.1 (Systematic) Does hazard identification follow a structured, repeatable methodology for consistency and completeness?
- Hazard identification procedure
- Structured analysis techniques (FMEA, FTA, HAZOP)
- Checklists and templates used
- Team composition and training
- Multiple identification methods
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Ad hoc identification approach
- Single identification method
- No documented methodology
- Inadequate team diversity
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Hazard identification must follow a structured, repeatable methodology to ensure consistency and completeness. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
5.2 Is the intended use documented comprehensively (how, where, by whom, for what purpose), along with reasonably foreseeable misuse?
- Intended use statement in risk management plan
- Medical indication documentation
- Patient population definition
- User profile descriptions
- Use environment specifications
- Operating principle documentation
- Anatomical interaction areas
- Use error analysis documentation
- Task analysis showing error points
- Known misuse from similar devices
- Vague or incomplete intended use
- Missing user profile information
- No use environment consideration
- Patient population not defined
- Operating principle not documented
- Only considering use errors
- Missing intentional misuse
- No systematic misuse analysis
A comprehensive definition of intended use must be documented, covering all aspects of how, where, by whom, and for what purpose the device will be used. Additionally, potential misuse scenarios including both unintentional use errors and intentional misuse must be documented.
5.2 (Documentation) Are intended use and misuse documented in the risk management file and actually used in hazard identification?
- Intended use document in risk file
- Misuse analysis in risk file
- Traceability to hazard identification
- Use in risk analysis worksheets
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
- Not including in risk file
- No link to hazard identification
- Static documents not used
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
- Activities performed without documented procedure or work instruction
Both intended use and misuse documentation must be included in the risk management file and actively used in the hazard identification process. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
5.2 (Intended Use) Is the intended use treated as the starting point of the analysis, capturing patient population, body contact, clinical setting, and operator?
- Intended use statement in risk management plan
- Medical indication documentation
- Patient population definition (age, condition, capacity)
- User profile descriptions (training, experience, limitations)
- Use environment specifications (home, hospital, ambulance)
- Part of body/tissue interaction
- Duration and frequency of use
- Operating principle and technology
- Vague or incomplete intended use
- Missing user profile information
- No use environment consideration
- Patient population not defined
- Operating principle not documented
- No evidence of periodic review or update of this activity
ISO/TR 24971:2020 A.2.5.2 states: 'The intended use of the medical device is an important aspect and is the starting point of the risk analysis. The manufacturer should consider the intended user(s) of the medical device, e.g., whether a lay user or a trained medical professional will use the medical device.'
5.2 (Misuse) Does the analysis consider reasonably foreseeable misuse - use outside the intended use and in ways not intended by the manufacturer?
- Use error analysis documentation
- Task analysis showing error points
- Known misuse from similar devices
- Usability test findings
- Field experience reports
- Intentional misuse scenarios
- Independent audit records confirming compliance with this requirement
- Only considering use errors
- Missing intentional misuse
- No systematic misuse analysis
- Not learning from similar devices
- Ignoring off-label use potential
- No evidence of periodic review or update of this activity
ISO/TR 24971:2020 A.2.5.2 clarifies: 'This analysis should consider that the medical device can also be used in situations other than those intended by the manufacturer and in situations other than those foreseen when the idea for a medical device was first conceived. It is important that the manufacturer tries to look into the future to see the hazards due to potential uses of their medical device and also the reasonably foreseeable misuse.'
5.3 Are all device characteristics that could affect safety identified and documented, with limits defined where applicable?
- Safety characteristics checklist
- Design specifications with safety limits
- Material properties documentation
- Performance parameters and tolerances
- Software characteristics
- Energy output specifications
- Biocompatibility data
- Incomplete characteristic identification
- Missing quantitative limits
- No systematic approach
- Software characteristics overlooked
- Aging/degradation not considered
- No evidence of periodic review or update of this activity
All device characteristics that could potentially impact safety must be systematically identified, documented, and where applicable, have defined limits. This includes physical, chemical, electrical, biological, and software characteristics.
5.3 (Characteristics) Are device characteristics identified systematically (e.g. using the Annex C question set), covering the full lifecycle including degradation?
- Safety characteristics checklist
- Design specifications with safety limits
- Material properties documentation
- Performance parameters and tolerances
- Software characteristics
- Energy output specifications
- Biocompatibility data
- Incomplete characteristic identification
- Missing quantitative limits
- No systematic approach
- Software characteristics overlooked
- Aging/degradation not considered
- No evidence of periodic review or update of this activity
Use ISO 14971 Annex C questions systematically. Document all characteristics with clear limits where applicable. Consider full lifecycle including degradation. Categories include: physical, chemical, electrical, biological, and software.
5.3 (Documentation) Are identified characteristics and their limits documented in the file with traceability?
- Characteristics list in risk file
- Specification documents referenced
- Limit justification documentation
- Updates and revisions tracked
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
- Characteristics not in risk file
- Limits documented elsewhere only
- No revision control
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
- Activities performed without documented procedure or work instruction
All identified characteristics and defined limits must be formally documented and maintained in the risk management file with clear traceability. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
5.3 (Limits) For quantitative safety-relevant characteristics, are acceptable limits defined based on evidence, standards, and clinical need?
- Specification documents with tolerances
- Acceptable range definitions
- Statistical process control limits
- Alert and action limits
- Safety margins documentation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Limits not defined for critical characteristics
- Limits without scientific basis
- No safety margins
- Missing statistical considerations
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
For quantitative characteristics, specific acceptable limits must be defined based on safety requirements. Limits should be based on scientific evidence, standards, and clinical requirements.
5.4 Are hazards and hazardous situations systematically identified across normal use, fault conditions, use errors, and environmental factors?
- Hazard identification worksheets
- Brainstorming session records
- Hazard checklists (ISO 14971 Annex C)
- User task analysis
- Failure mode analysis
- Environmental condition analysis
- Similar device incident data
- Missing use error hazards
- Incomplete fault condition analysis
- No environmental considerations
- Single method used
- Late lifecycle hazards missed
- No team-based identification
All potential hazards must be systematically identified considering normal use, fault conditions, use errors, and environmental factors throughout the device lifecycle. Use multiple identification methods including top-down, bottom-up, and experiential.
5.4 (Documentation) Are all hazards and hazardous situations documented (e.g. a hazard log with unique identifiers) with traceability?
- Master hazard list
- Hazardous situation register
- Supporting analysis documentation
- Team review records
- Approval signatures
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Incomplete documentation
- Poor traceability
- Missing approval records
- No revision control
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
All identified hazards and hazardous situations must be documented comprehensively with clear traceability. Maintain comprehensive hazard log with unique identifiers. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
5.4 (Identification) Are multiple hazard-identification methods used (FMEA, HAZOP, etc.) with a diverse team, and all hazards documented even if later deemed not applicable?
- Hazard identification worksheets
- Brainstorming session records
- Hazard checklists (ISO 14971 Annex C)
- User task analysis
- Failure mode analysis (FMEA/FMECA)
- Fault tree analysis (FTA)
- Environmental condition analysis
- Similar device incident data
- Missing use error hazards
- Incomplete fault condition analysis
- No environmental considerations
- Single method used
- Late lifecycle hazards missed
- No team-based identification
Use multiple identification methods. Include diverse team members. Consider all lifecycle phases. Document all hazards even if later deemed not applicable. Methods include: FMEA, FTA, HAZOP, PHA, incident analysis, and expert consultation.
5.4 (Lifecycle) Does hazard identification address every lifecycle phase (manufacture, transport, use, maintenance, disposal), not just the use phase?
- Lifecycle phase analysis
- Transport/storage hazard analysis
- Installation hazard assessment
- Maintenance procedure review
- Disposal hazard evaluation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Focus only on use phase
- Missing disposal hazards
- No transport considerations
- Inadequate maintenance analysis
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Hazard identification must systematically address every lifecycle phase, not just the use phase. Create lifecycle phase checklist. Analyze each phase systematically. Consider phase-specific standards.
5.4 (Situations) Does the analysis show how hazards lead to hazardous situations through credible event sequences?
- Hazardous situation worksheets
- Event sequence diagrams
- Cause-and-effect analyses
- Scenario descriptions
- Use case analyses
- Combination event matrices
- Bow-tie diagrams
- Direct hazard-to-harm jumps
- Missing intermediate events
- No combination events considered
- Incomplete scenario analysis
- Missing reasonably foreseeable sequences
- No evidence of periodic review or update of this activity
The analysis must identify how hazards lead to hazardous situations through various event sequences, considering the chain of events from hazard to potential harm. Document clear event sequences from hazard to hazardous situation. Consider multiple pathways and combination events.
5.5 Is risk estimated for every hazardous situation by combining probability and severity, using defined scales?
- Risk estimation matrices
- Probability calculations
- Severity classifications
- Risk scoring worksheets
- Statistical analyses
- Clinical data supporting estimates
- Independent audit records confirming compliance with this requirement
- Missing risk estimates for some hazards
- Probability without data support
- Inconsistent severity assignments
- No documented estimation method
- Mixing probability concepts
- No evidence of periodic review or update of this activity
Risk must be estimated for every hazardous situation by combining probability of occurrence and severity of potential harm. Define clear probability and severity scales. Use available data for estimates. Document estimation rationale.
5.5 (Components) Does risk estimation combine the probability of the hazardous situation occurring and of it leading to harm, with severity based on the injury type and number affected?
- Risk estimation matrices
- Probability calculations (P1 × P2)
- Severity classifications
- Risk scoring worksheets
- Statistical analyses
- Clinical data supporting estimates
- Independent audit records confirming compliance with this requirement
- Missing risk estimates for some hazards
- Probability without data support
- Inconsistent severity assignments
- No documented estimation method
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Risk estimation combines P1 (probability of hazardous situation occurring) × P2 (probability of hazardous situation leading to harm). Severity considers type of injury, number affected, duration, reversibility, and impact on quality of life.
5.5 (Documentation) Are all risk estimations - probability, severity, methods, and supporting data - documented?
- Risk estimation worksheets
- Supporting data and references
- Method documentation
- Review and approval records
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
- Missing supporting data
- No method documentation
- Incomplete records
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
- Activities performed without documented procedure or work instruction
All risk estimations including probability, severity, methods used, and supporting data must be documented. Create comprehensive estimation records. Include all supporting information. Maintain clear audit trail.
5.5 (Probability) Are probability estimates based on objective data where available, with sources documented, rather than guesses?
- Statistical analysis of field data
- Failure rate calculations
- Clinical trial adverse event rates
- Database search results
- Expert consensus documentation
- Reliability testing data
- Independent audit records confirming compliance with this requirement
- No data to support probabilities
- Over-reliance on expert opinion
- Not using available databases
- Ignoring uncertainty
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Probability estimates should be based on objective data where available, with multiple information sources considered. Prioritize quantitative data. Document all sources used. Address uncertainty explicitly. Use conservative estimates when data is limited.
5.5 (Severity) Is severity estimated on the worst credible consequence, using defined categories developed with clinical input?
- Clinical consequence descriptions
- Severity scale definitions
- Medical literature on injuries
- Professional medical opinions
- Regulatory guidance on severity
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Underestimating severity
- Not considering worst credible case
- Inconsistent severity scales
- No medical input on consequences
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Severity must be estimated based on the worst credible consequence that could result from the hazardous situation. Define clear severity categories with medical input. Consider worst credible outcomes. Be consistent across similar harms.
5.5 (Systematic) Is a consistent, systematic estimation method applied to all risks, with detail proportionate to device complexity and risk?
- Risk estimation procedure
- Standardized worksheets
- Training records on method
- Quality review of estimates
- Consistency checks
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Ad hoc estimation approaches
- Inconsistent methods used
- Insufficient detail for high risks
- No quality checks
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
A consistent, systematic method must be applied to all risk estimations, with appropriate detail based on device complexity and risk level. Document standard estimation method. Train all participants. Implement peer review. Scale detail to risk level.
§6 Risk evaluation
6 Is every identified risk evaluated against the pre-defined acceptability criteria to decide whether risk reduction is needed?
- Risk evaluation worksheets
- Risk acceptability decisions
- Application of criteria from plan
- Risk matrices with acceptability zones
- Evaluation meeting minutes
- Decision rationale documentation
- Independent audit records confirming compliance with this requirement
- Inconsistent application of criteria
- Missing evaluation for some risks
- Criteria not from approved plan
- No documented rationale
- Subjective decisions without criteria
- No evidence of periodic review or update of this activity
Every identified risk must be evaluated against pre-defined acceptability criteria to determine if risk reduction is needed. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
6 Are risks that meet the acceptability criteria still documented and communicated, even though they need no further control?
- List of acceptable risks
- Justification for acceptability
- Documentation in risk management file
- Communication to stakeholders
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
- Not documenting acceptable risks
- Missing justification
- No disclosure consideration
- Acceptable risks not tracked
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Risks that meet acceptability criteria do not require risk control measures but still need to be documented and communicated. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
6 Does every risk that fails the acceptability criteria proceed to risk control?
- List of unacceptable risks
- Risk control requirements
- Action plans for reduction
- Priority assignments
- Resource allocation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Some unacceptable risks not addressed
- Delayed risk control implementation
- No clear prioritization
- Inadequate resource allocation
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Any risk that does not meet acceptability criteria must proceed to risk control to reduce the risk to acceptable levels. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
6 Is there a deliberate, documented decision on which residual risks are disclosed to users, with rationale for non-disclosure?
- Risk disclosure matrix
- Disclosure decisions and rationale
- Information for safety documents
- Labeling and IFU content
- Regulatory submission disclosures
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- No systematic disclosure process
- Missing non-disclosure justification
- Inconsistent disclosure decisions
- Not aligned with regulations
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
A deliberate decision process must determine which residual risks are disclosed to users, with documented rationale for non-disclosure decisions. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
6 Are all risk-evaluation decisions and their rationale documented in the risk management file?
- Risk evaluation reports
- Decision records
- Meeting minutes
- Approval signatures
- Traceability to criteria
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Incomplete documentation
- Missing decision rationale
- No approval records
- Poor traceability
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
All risk evaluation activities, decisions, and rationales must be documented in the risk management file. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
6 Are the same acceptability criteria applied uniformly to all risks, ensuring objectivity?
- Consistent application evidence
- Review of evaluation consistency
- Training on criteria application
- Quality checks on evaluations
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
- Inconsistent criteria application
- Subjective interpretations
- Criteria drift over time
- Different evaluators using different approaches
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
The same criteria must be applied uniformly to all risks, ensuring objectivity and consistency in evaluation. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
§7 Risk control
7 Is risk control a systematic process that reduces unacceptable risks to acceptable levels following the defined control hierarchy?
- Risk control procedure
- Control measure specifications
- Implementation records
- Verification documentation
- Residual risk assessments
- Benefit-risk analyses
- Independent audit records confirming compliance with this requirement
- No systematic approach
- Skipping hierarchy steps
- Incomplete implementation
- Missing verification
- Poor documentation
- No evidence of periodic review or update of this activity
Risk control is a systematic process to reduce unacceptable risks to acceptable levels through various control measures following a defined hierarchy. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7 Are controls selected following the strict hierarchy - inherent safety, then protective measures, then information for safety?
- Hierarchy application documentation
- Design change considerations
- Protective measure implementations
- Safety information developed
- Justification for hierarchy decisions
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Not following hierarchy
- Jumping to warnings
- No design change consideration
- Inadequate justification
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Risk controls must be selected and applied following a strict hierarchy that prioritizes elimination and engineering controls over warnings. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7 Does the manufacturer consider how control measures can be combined for optimal risk reduction?
- Control effectiveness analysis
- Multi-control strategies
- Cross-risk control mapping
- Combined effect assessments
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
- Single control thinking
- Not optimizing controls
- Missing synergies
- Inadequate effectiveness analysis
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Risk control requires flexible thinking about how measures work and can be combined for optimal risk reduction. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7 Are all six risk-control sub-elements completed systematically?
- Completion checklists
- Section cross-references
- Review records
- Approval documentation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
- Incomplete process
- Missing sections
- No completeness check
- Poor integration
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
All six sub-elements must be completed systematically to ensure comprehensive risk control. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.1 For each unacceptable risk, does the manufacturer identify control measures capable of reducing it to acceptable?
- Risk control worksheets
- Options analysis documentation
- Control measure identification records
- Brainstorming session minutes
- Standards review for controls
- Similar device control analysis
- Independent audit records confirming compliance with this requirement
- Limited control options considered
- No systematic identification approach
- Missing feasibility analysis
- Inadequate cross-functional input
- No consideration of combined controls
- No evidence of periodic review or update of this activity
For each unacceptable risk identified during risk evaluation, the manufacturer must identify potential control measures that can reduce the risk to acceptable levels. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.1 (Practicability) Where risk cannot be reduced to acceptable by any practicable means, is a benefit-risk analysis used to decide acceptability?
- Practicability analysis
- Technical feasibility studies
- Cost-benefit considerations
- State of the art analysis
- Benefit-risk analysis trigger
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Premature declaration of impracticability
- No documented analysis
- Missing state of the art review
- Skipping benefit-risk analysis
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
When risk cannot be reduced to acceptable levels through any practicable means, a benefit-risk analysis is required to determine if the residual risk is acceptable. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.1 (Selection) Are selected control measures documented with traceability to the risks they address?
- Risk control matrix
- Control measure specifications
- Selection rationale
- Traceability matrix
- Review and approval records
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Missing selection rationale
- Poor traceability to risks
- Incomplete specifications
- No approval records
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
All selected risk control measures must be documented with clear traceability to the risks they address. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.1(a) Is top priority given to inherently safe design - eliminating hazards or reducing risk through the design itself?
- Design modifications to eliminate hazards
- Material selection for biocompatibility
- Geometry changes to prevent misuse
- Fail-safe design features
- Reduced complexity designs
- Energy limiting designs
- Independent audit records confirming compliance with this requirement
- Not exploring design alternatives
- Accepting hazards as inherent
- Cost driving decisions over safety
- Late consideration of design changes
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
The highest priority should be given to design features that eliminate hazards entirely or reduce risks through inherent characteristics of the design. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.1(b) Where hazards cannot be eliminated, are protective measures built into the device or process to prevent or detect hazardous situations?
- Alarm specifications and testing
- Guard and barrier designs
- Interlock system documentation
- Redundant system analysis
- Manufacturing process controls
- Fail-safe mechanisms
- Independent audit records confirming compliance with this requirement
- Single point of failure in protections
- Alarms that can be ignored
- Protective measures that can be bypassed
- No verification of effectiveness
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
When hazards cannot be eliminated, protective measures should be built into the device or manufacturing process to prevent or detect hazardous situations. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.1(c) Where risk cannot be adequately controlled by design or protective measures, is information for safety provided to enable safe use?
- Warning labels and symbols
- Instructions for use
- Training curricula and materials
- Quick reference guides
- Contraindication lists
- Maintenance requirements
- User comprehension testing
- Generic or unclear warnings
- Information not reaching end users
- No validation of comprehension
- Missing training effectiveness measures
- Inadequate prominence of warnings
- No evidence of periodic review or update of this activity
When risks cannot be adequately controlled through design or protective measures, information must be provided to users to enable safe use. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.2 Are selected control measures fully implemented in the design, manufacturing process, or accompanying documentation?
- Design change records
- Updated specifications
- Manufacturing process changes
- Labeling updates
- Software modifications
- Training materials created
- Independent audit records confirming compliance with this requirement
- Incomplete implementation
- Implementation delays
- No change control
- Missing documentation
- Partial implementations
- No evidence of periodic review or update of this activity
All selected risk control measures must be fully implemented in the device design, manufacturing process, or accompanying documentation. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.2 (Documentation) Is implementation and effectiveness verification documented with traceability?
- Verification reports
- Test protocols and results
- Approval records
- Traceability matrices
- Change documentation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Incomplete documentation
- Missing traceability
- No approval records
- Poor organization
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Complete documentation of implementation and effectiveness verification must be maintained with clear traceability. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.2 (Effectiveness Verification) Beyond implementation, is the actual risk-reduction effectiveness of each control verified by testing or analysis?
- Effectiveness test results
- Risk reduction calculations
- Usability testing for warnings
- Clinical evaluations
- Simulated use testing
- Field trial data
- Independent audit records confirming compliance with this requirement
- Only verifying implementation
- No effectiveness testing
- Inadequate test methods
- Missing human factors validation
- No quantitative assessment
- No evidence of periodic review or update of this activity
Beyond implementation verification, the actual effectiveness in reducing risk must be verified through appropriate testing or analysis. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.2 (Implementation Verification) Is each implemented control verified as correctly implemented to specification?
- Verification test reports
- Design review records
- Inspection results
- Implementation checklists
- Configuration audits
- Verification protocols
- Independent audit records confirming compliance with this requirement
- No verification performed
- Verification not documented
- Incomplete verification
- No defined criteria
- Missing test evidence
- No evidence of periodic review or update of this activity
Each implemented control must be verified to ensure it was correctly implemented as specified. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.3 Is each risk re-evaluated after controls to confirm the residual risk is acceptable?
- Residual risk assessments
- Updated risk matrices
- Risk reduction calculations
- Acceptability determinations
- Comparison to criteria
- Decision documentation
- Independent audit records confirming compliance with this requirement
- Not re-evaluating after controls
- Using different criteria
- Assuming controls eliminate risk
- No documented evaluation
- Missing some residual risks
- No evidence of periodic review or update of this activity
Each risk must be re-evaluated after controls are implemented to determine if the remaining (residual) risk is now acceptable. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.3 (Acceptable) Are acceptable residual risks still assessed for whether they need disclosure to users?
- Disclosure decision matrix
- Risk communication strategy
- IFU content decisions
- Label warnings
- Training material updates
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- No disclosure decisions
- Hiding acceptable risks
- Over-disclosure causing confusion
- No systematic approach
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Even acceptable residual risks may need to be disclosed to users depending on their nature and significance. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.3 (Documentation) Are residual-risk evaluations, decisions, and supporting analyses documented?
- Residual risk evaluation reports
- Updated risk matrices
- Acceptability decisions
- Disclosure determinations
- Review and approval records
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Incomplete documentation
- Missing decision rationale
- No approval records
- Poor traceability
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
All residual risk evaluations, decisions, and supporting analyses must be documented. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.3 (Unacceptable) Do unacceptable residual risks get additional controls, or a benefit-risk analysis where no further controls are practicable?
- Additional control considerations
- Practicability assessments
- Iteration documentation
- Benefit-risk analysis triggers
- Decision flow records
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Accepting unacceptable risks
- No further control consideration
- Missing practicability analysis
- Skipping benefit-risk analysis
- No iteration documentation
- No evidence of periodic review or update of this activity
Unacceptable residual risks require either additional controls or formal benefit-risk analysis if no further controls are practicable. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.3 (Verification) Does residual-risk evaluation verify both the intended risk reduction and the absence of new risks from the controls?
- Risk reduction calculations
- New hazard analyses
- Control side-effect assessments
- Updated risk registers
- Comprehensive re-evaluation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Not checking for new risks
- Assuming controls work as intended
- Missing indirect effects
- No comprehensive re-assessment
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Residual risk evaluation must verify both intended risk reduction and absence of new risks from controls. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.4 Where risk cannot be reduced to acceptable despite all practicable controls, is a formal benefit-risk analysis performed to justify proceeding?
- Documentation of impracticability
- Clinical benefit evidence
- Literature review results
- Comparative effectiveness data
- Expert clinical opinions
- Patient outcome studies
- Independent audit records confirming compliance with this requirement
- Jumping to benefit-risk without exhausting controls
- Weak benefit evidence
- No systematic literature review
- Missing clinical input
- Inadequate documentation of impracticability
- No evidence of periodic review or update of this activity
When risk cannot be reduced to acceptable levels despite all practicable controls, a formal benefit-risk analysis may justify proceeding with the unacceptable residual risk. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.4 (Conclusion) Does the benefit-risk analysis reach a clear, evidence-based conclusion (benefits outweigh risk, or risk remains unacceptable)?
- Benefit-risk analysis report
- Quantitative benefit measures
- Risk-benefit comparison
- Clinical necessity documentation
- Alternative treatment analysis
- Quality of life assessments
- Independent audit records confirming compliance with this requirement
- Vague conclusions
- Benefits not quantified
- No comparison to alternatives
- Ignoring negative conclusion
- Proceeding without clear evidence
- No evidence of periodic review or update of this activity
The benefit-risk analysis must reach a clear, evidence-based conclusion that is either positive (benefits outweigh risks) or negative (risk remains unacceptable). This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.4 (Disclosure) Are residual risks that required a benefit-risk analysis disclosed to users in the product documentation?
- Instructions for use with risk disclosure
- Warning labels
- Training materials
- Informed consent templates
- Risk communication strategy
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Not disclosing these risks
- Buried in documentation
- Unclear risk communication
- No user training on risks
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Residual risks that required benefit-risk analysis must be disclosed to users in product documentation. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.4 (Documentation) Is the benefit-risk analysis methodology, evidence, reasoning, and conclusion documented?
- Benefit-risk analysis report
- Literature search strategy
- Evidence tables
- Expert opinion documentation
- Decision rationale
- Review and approval records
- Independent audit records confirming compliance with this requirement
- Incomplete documentation
- Missing evidence trail
- No approval records
- Methodology not documented
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Complete documentation of the analysis methodology, evidence, reasoning, and conclusions must be maintained. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.4 (Populations) Where different patient populations have different benefit-risk profiles, are they analyzed separately?
- Subgroup analyses
- Vulnerable population assessments
- Pediatric considerations
- Comorbidity impacts
- Use environment variations
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- One-size-fits-all analysis
- Missing vulnerable populations
- No pediatric consideration
- Ignoring comorbidities
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Different patient populations may have different benefit-risk profiles that must be analyzed separately. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.5 Is every control measure evaluated for whether it introduces new risks or affects existing ones?
- New hazard analysis for controls
- Risk interaction assessments
- Side effect evaluations
- System-level impact analysis
- Cross-risk evaluations
- Unintended consequence analysis
- Independent audit records confirming compliance with this requirement
- Not checking for new risks
- Missing indirect effects
- No system-level thinking
- Ignoring risk interactions
- Incomplete evaluation scope
- No evidence of periodic review or update of this activity
Every risk control measure must be evaluated to determine if it creates new risks or affects other existing risks. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.5 (Documentation) Are all evaluations of risks arising from control measures documented, including new risks and decisions?
- New risk evaluation reports
- Risk interaction matrices
- Control impact assessments
- Management decisions
- Review records
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Incomplete documentation
- Missing evaluation records
- No decision trail
- Poor traceability
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
All evaluations of risks arising from control measures must be documented, including new risks identified and management decisions. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.5 (Lifecycle) Are new risks from controls evaluated considering degradation, wear, and user habituation over time?
- Lifecycle effectiveness analysis
- Degradation studies
- User habituation assessments
- Maintenance impact evaluations
- Long-term effectiveness data
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Only considering initial effectiveness
- Missing degradation effects
- Ignoring user habituation
- No maintenance considerations
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
New risks must be evaluated considering degradation, wear, user habituation, and other time-dependent factors. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.5 (Management) Do new risks introduced by controls go through the full risk management process (estimation through control)?
- Risk analysis for new hazards
- Risk estimation documentation
- Risk evaluation records
- Additional control measures
- Complete risk management cycle
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Not fully managing new risks
- Abbreviated process for new risks
- Missing risk estimation
- No controls for new risks
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
New risks introduced by control measures must go through the complete risk management process from estimation through control. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.5(a) Is each control evaluated for whether it creates entirely new hazards that did not exist before?
- New hazard identification records
- Control-specific hazard analysis
- Design change risk assessment
- Material change evaluations
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
- Assuming controls only reduce risk
- Missing new hazard analysis
- No systematic evaluation
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
- Activities performed without documented procedure or work instruction
Evaluate whether the control measure itself creates entirely new hazards that did not exist before. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.5(b) Is each control evaluated for whether it changes the probability or severity of other existing risks?
- Risk interaction matrix
- Cross-risk impact assessment
- Updated risk estimations
- Trade-off analysis
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
- Only evaluating target risk
- Missing cross-risk analysis
- No trade-off documentation
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
- Activities performed without documented procedure or work instruction
Evaluate whether implementing the control measure changes the probability or severity of other existing risks. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.6 Is a systematic completeness review performed to confirm every identified risk has been addressed by the control process?
- Completeness checklists
- Risk control tracking matrices
- Gap analysis reports
- Cross-reference tables
- Review meeting minutes
- Verification reports
- Independent audit records confirming compliance with this requirement
- Some risks not addressed
- Incomplete control implementation
- Missing verification steps
- No systematic review
- Poor tracking mechanisms
- No evidence of periodic review or update of this activity
A systematic review must verify that every identified risk has been addressed through the risk control process with no gaps or omissions. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.6 (Documentation) Is the completeness review formally documented with evidence of comprehensive verification?
- Completeness review report
- Review checklists signed
- Gap assessment records
- Action closures
- Final approval documentation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- No formal review record
- Incomplete documentation
- Missing signatures
- No evidence of systematic review
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
The completeness review must be formally documented with clear evidence of comprehensive verification. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.6 (Information) Does the completeness review confirm all necessary information for ongoing risk management is available?
- Production risk information
- Post-market surveillance plans
- User information completed
- Training materials finalized
- Monitoring procedures
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Missing production information
- Incomplete user materials
- No post-market plans
- Inadequate training materials
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Risk control completeness includes ensuring all necessary information is available for ongoing risk management. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.6 (Iteration) Are gaps found during the completeness review resolved before risk control is considered complete?
- Gap remediation plans
- Additional control implementations
- Supplementary verifications
- Re-review records
- Final completeness confirmation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Proceeding with gaps
- No remediation process
- Incomplete corrections
- No re-verification
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Any gaps identified during completeness review must be addressed before risk control can be considered complete. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.6 (Residual) Does every residual risk have a documented acceptability decision or completed benefit-risk analysis?
- Residual risk summary
- Acceptability decision log
- Benefit-risk analyses completed
- Management approvals
- Risk acceptance records
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Some residual risks not evaluated
- Missing acceptability decisions
- Incomplete benefit-risk analyses
- No management approval
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Every residual risk must have a documented acceptability decision or completed benefit-risk analysis. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
7.6 (Tracking) Does the completeness review confirm controls are not just present but fully implemented and proven effective?
- Implementation status reports
- Verification completion records
- Effectiveness test summaries
- Action item closure
- Outstanding issue logs
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Controls planned but not implemented
- Implementation without verification
- No effectiveness confirmation
- Open action items
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Completeness review must confirm not just that controls exist, but that they are fully implemented and proven effective. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
§8 Evaluation of overall residual risk
8 Is the cumulative effect of all residual risks evaluated as a whole to judge the device's overall risk-benefit profile?
- Overall residual risk evaluation report
- Cumulative risk assessment
- Risk-benefit analysis documentation
- Clinical benefit evidence
- Comparative device analysis
- Multi-disciplinary review records
- Risk heat maps or dashboards
- Expert panel assessments
- Only evaluating individual risks
- Missing cumulative effects analysis
- Inadequate benefit documentation
- No systematic evaluation method
- Missing management review
- No visualization of overall risk profile
- Risk interaction effects not considered between control measures
- Common mode failure analysis absent from cumulative assessment
The cumulative effect of all individual residual risks must be evaluated as a whole to determine if the device's overall risk-benefit profile is acceptable. This requires: - Systematic method for combining individual risks - Clear documentation of clinical benefits - Visualization tools (risk matrices, dashboards) - Multi-disciplinary review EVALUATION METHODS (ISO/TR 24971 Guidance): QUALITATIVE: - Expert panel assessment - Comparative analysis with predicate devices - Clinical opinion evaluation - Risk profile visualization SEMI-QUANTITATIVE: - Weighted risk scoring - Risk index calculation - Multi-criteria decision analysis - Risk matrices with accumulation CONSIDERATIONS: - Interaction between risks - Common mode failures - Risk accumulation effects - User population vulnerability - Use environment factors BENEFIT ASSESSMENT: Clinical benefits include: - Disease diagnosis improvement - Treatment effectiveness - Patient quality of life enhancement - Reduced invasiveness - Earlier intervention capability Documentation sources: - Clinical literature - Clinical trial data - Real-world evidence - Professional society positions - Regulatory precedents
8 Are the overall-residual-risk acceptability criteria from the plan applied, and significant residual risks communicated to users?
- Application of plan criteria documentation
- Acceptability decision records
- Information for users (IFU warnings)
- Residual risk disclosure matrix
- Training materials on residual risks
- User notification strategy
- Contraindication documentation and labeling updates
- Criteria not from approved plan
- Subjective acceptability decisions without documentation
- Inadequate user communication
- Missing disclosure rationale
- No systematic approach to user information
- Contraindications omitted from instructions for use
Pre-defined criteria from the risk management plan must be applied to determine acceptability, and significant risks must be communicated to users. CRITERIA APPLICATION (ISO/TR 24971 Guidance): - Compare to predefined thresholds - Benchmark against similar devices - Consider medical necessity - Evaluate alternative treatments - Assess societal need DISCLOSURE FRAMEWORK: ALWAYS DISCLOSE: - Death or serious injury risks - Risks requiring user action - Risks with no control measures - Contraindications - High probability events CONSIDER DISCLOSING: - Moderate severity risks - Training-dependent risks - Environment-specific risks - Long-term risks DISCLOSURE METHODS: - Warnings in instructions for use - Device labeling - Training requirements - Quick reference cards - Electronic alerts
8 Where overall risk exceeds the plan's criteria, is a formal benefit-risk analysis with supporting evidence used to justify acceptance?
- Benefit-risk analysis report
- Clinical literature review
- Comparative effectiveness data
- Unmet medical need documentation
- Expert clinical opinions
- Regulatory precedent analysis
- Systematic literature search records
- Proceeding without benefit-risk analysis when risk exceeds criteria
- Weak benefit evidence
- No documented decision
- Ignoring unacceptable conclusion
- Missing external expert input
- Evidence quality hierarchy not applied to supporting literature
When overall risk exceeds plan criteria, a formal benefit-risk analysis with additional evidence may justify acceptance, otherwise the device cannot proceed. BENEFIT-RISK FACTORS (ISO/TR 24971 Guidance): BENEFIT CONSIDERATIONS: - Life-saving capability - Significant morbidity reduction - No alternative treatments available - Breakthrough technology - Address unmet medical need - Public health impact RISK CONSIDERATIONS: - Severity of potential harms - Probability of occurrence - Reversibility of harm - Duration of exposure - Vulnerable populations EVIDENCE HIERARCHY: 1. Randomized controlled trials (highest) 2. Systematic reviews/meta-analyses 3. Observational studies 4. Registry data 5. Expert consensus 6. Case reports (lowest) DOCUMENTATION REQUIREMENTS: - Systematic literature search - Evidence quality assessment - Quantitative benefit measures - Uncertainty analysis - External expert input
8 If overall risk is unacceptable, does the manufacturer add controls, modify the design, or change the intended use rather than proceed as-is?
- Additional control implementation records
- Design modification documentation
- Intended use restriction documentation
- Project termination decision (if applicable)
- Iteration documentation showing return to Section 7
- User population change assessment records
- Risk control measure gap analysis report
- Accepting unacceptable risk without justification
- No documented actions taken
- Proceeding without changes when risk remains unacceptable
- Failure to consider design modification as an alternative to use restriction
- No formal project termination criteria defined for persistent unacceptable risk
- Missing iteration loop back to risk control evaluation after device modification
Unacceptable overall risk requires either additional risk controls, design modification, or intended use changes - the device cannot proceed as-is. OPTIONS TO CONSIDER: - Return to Section 7 for additional risk control measures - Modify device design - Restrict intended use - Change user population - Terminate project if risk cannot be made acceptable All options and decisions must be documented.
8 Is the overall residual risk evaluation - methods, decisions, and evidence - documented in the risk management file?
- Overall evaluation report in risk management file
- Method justification documentation
- Decision records with signatures
- Supporting evidence (clinical data, literature)
- Review and approval records
- Traceability matrix linking individual residual risks to overall evaluation
- Version-controlled evaluation summary with change history
- Incomplete documentation in risk file
- Missing decision rationale
- No approval records
- Supporting evidence not maintained
- Evaluation method not justified or referenced in risk management plan
- No version control or change history for evaluation documents
Complete documentation of the overall evaluation, methods, decisions, and supporting evidence must be maintained in the risk management file. REQUIRED DOCUMENTATION: - Overall evaluation report - Evaluation method and justification - Decision records with rationale - Supporting evidence and analyses - Review and approval records
§9 Risk management review
9 Is a formal risk management review performed before release, verifying the plan was executed completely and properly?
- Risk management review report
- Plan implementation verification checklist
- Overall risk acceptance documentation
- Post-production system verification
- Review meeting minutes
- Management approval records
- Cross-functional review team records
- Review conducted after release to market
- Incomplete review scope
- Missing post-production verification
- No formal review documentation
- Inadequate management involvement
- Single person conducting review
A formal review must verify complete and proper execution of all risk management activities before the device can be released to market. REVIEW TIMING (ISO/TR 24971 Guidance): The review must occur when risk management activities are sufficiently complete but before commercial release. REVIEW PARTICIPANTS: The review team should include representatives from various functions with appropriate competence (technical, clinical, quality, regulatory). REVIEW CHECKLIST: PLAN IMPLEMENTATION: - All planned activities completed - Deviations documented and justified - Required competencies demonstrated - Responsibilities fulfilled as assigned TECHNICAL COMPLETENESS: - Risk analysis comprehensive - All risks evaluated against criteria - Controls implemented and verified - Residual risks assessed DOCUMENTATION: - Risk management file complete - Traceability demonstrated - Decisions documented with rationale - Reviews and approvals obtained
9 Are review findings documented and any gaps resolved before the device is released?
- Risk management review report in risk file
- Finding documentation
- Action item list with status
- Completion evidence for all actions
- Final approval records with signatures
- Gap closure verification records before release authorization
- Review summary with cross-reference to risk management plan elements
- Review not documented in risk file
- Actions not completed before release
- Release despite open findings
- No final approval signature
- Action items without assigned owners or target completion dates
- Review report missing traceability to specific plan requirements
Review findings must be documented, and any identified gaps must be resolved before the device can be released. Per ISO/TR 24971, emphasis is on keeping records of changes to facilitate audit and review of the risk management process for a particular medical device. DOCUMENTATION REQUIREMENTS: - Comprehensive review report - Finding documentation - Action item list - Completion evidence for all actions - Final approval records
9.a Does the review confirm every element of the risk management plan was executed as intended, with appropriate resources and documentation?
- Plan vs actual comparison matrix
- Activity completion checklist
- Personnel competency verification records
- Document completeness assessment
- Deviation documentation with justifications
- Risk management activity timeline showing milestone completion
- Resource allocation records for risk management activities
- Plan elements not verified
- Missing activities not identified
- Competency not confirmed
- Incomplete documentation accepted without justification
- No deviation log for activities that differed from the original plan
- Risk management activities performed by unqualified personnel
The review must confirm that every element of the risk management plan was executed as intended with appropriate resources and documentation. Per ISO/TR 24971, the review should verify that the risk management process has been applied to each identified hazard. VERIFICATION ELEMENTS: - Plan vs actual comparison - Activity completion checklist - Personnel competency verification - Document completeness assessment - Deviation documentation and justification
9.b Does the review verify both individual and overall residual risks are acceptable per the plan's criteria?
- Individual risk acceptability summary
- Overall risk evaluation confirmation
- Criteria application evidence
- Benefit-risk analysis (if applicable)
- Risk communication decisions
- Residual risk register with acceptability status per hazard
- Cumulative risk profile comparison against plan thresholds
- Some risks not evaluated
- Overall risk not assessed
- Criteria not properly applied
- Unacceptable risks ignored or not addressed
- Benefit-risk analysis not performed when required by plan criteria
- No traceability between individual residual risks and overall evaluation
Both individual and overall residual risks must be verified as acceptable according to predetermined criteria from the risk management plan. VERIFICATION REQUIRED: - All individual risks evaluated against criteria - Overall risk assessment performed - Criteria properly applied - Benefit-risk analysis completed (if needed) - Risk communication decisions documented
9.c Does the review confirm the system for ongoing production and post-market risk monitoring is established and adequate?
- Post-production surveillance procedures
- Data collection mechanisms documentation
- Review frequency documentation
- Feedback loop verification
- System adequacy test results
- Post-market surveillance plan aligned with regulatory requirements
- Integration test results showing data flow from complaints to risk file
- No post-production system established
- Inadequate data sources defined
- No review procedures documented
- Missing feedback loops to risk management
- Post-market surveillance plan not covering all marketed regions
- System adequacy not validated before commercial release
The system for ongoing risk monitoring during production and post-market phases must be established and verified as adequate. Per ISO/TR 24971, methods for collection and review of production and post-production information need to be established so there is a formal way to feed back production and post-production information into the risk management process. SYSTEM VERIFICATION: - Post-production surveillance procedures exist - Data collection mechanisms defined - Review frequency documented - Feedback loops established - System adequacy tested
§10 Production and post-production activities
10 Does risk management continue through the full lifecycle with systematic collection and review of real-world data?
- Post-market surveillance procedures
- Production monitoring systems documentation
- Feedback collection mechanisms
- Data review processes
- QMS integration documentation
- Information flow diagrams
- System procedure covering all four elements (10.1-10.4)
- Risk management stops at product launch
- No systematic data collection after release
- Poor QMS integration
- Reactive only approach (no proactive surveillance)
- Missing production phase monitoring
- No defined linkage between complaint handling and risk management updates
Risk management continues throughout the entire product lifecycle with systematic collection and review of real-world data to identify new hazards or changes in risk levels. ISO/TR 24971:2020 ANNEX A.2.10 GUIDANCE: Production and post-production information is essential to verify risk management effectiveness and identify new risks. SYSTEM ELEMENTS: - Information collection mechanisms - Review procedures and frequency - Action triggers and escalation - Documentation requirements - Feedback to risk management - Regulatory reporting links INTEGRATION POINTS WITH QMS: - Complaint handling (ISO 13485:2016, 8.2.2) - Feedback (ISO 13485:2016, 8.2.1) - CAPA system - Management review - Post-market surveillance
10 Is production data monitored for risk-relevant signals (yield, deviations, process variation)?
- Manufacturing deviation reports
- Quality trend analyses
- Non-conformity data with risk relevance assessment
- Process capability studies
- Supplier performance data
- Equipment maintenance records
- Incoming inspection failure reports with risk impact assessment
- Not monitoring production data for risk signals
- Missing trend analysis
- No risk relevance assessment of production issues
- Inadequate supplier monitoring
- Process drift detected but not escalated to risk management
- Calibration excursions not evaluated for patient safety impact
Production data must be monitored for risk-relevant information including quality trends and process variations. PRODUCTION INDICATORS (ISO/TR 24971 Guidance): - Yield rates and trends - Defect patterns - Process drift - Component failures - Calibration issues - Environmental excursions MONITORING SCOPE: - Manufacturing deviation reports - Quality trend analyses - Non-conformity data - Process capability studies - Supplier performance data - Equipment maintenance records
10 Is post-market data systematically collected and analyzed as real-world evidence of performance and safety?
- Field failure reports
- Customer complaints database
- Service/maintenance data
- Clinical follow-up studies
- Literature surveillance records
- Regulatory database monitoring (MAUDE, EUDAMED)
- Similar device tracking
- Limited data sources monitored
- No proactive surveillance
- Missing literature monitoring
- Inadequate global coverage
- Not tracking similar devices
- Adverse event database queries not performed at defined intervals
Post-market data provides real-world evidence of device performance and safety that must be systematically collected and analyzed. POST-MARKET SOURCES (ISO/TR 24971 Guidance): - Direct customer feedback - Distributor reports - Service organization data - Clinical registries - Scientific publications - Regulatory authority databases - Social media monitoring DATA TYPES: - Field failure reports - Customer complaints - Service/maintenance data - Clinical follow-up studies - Literature surveillance - Regulatory database monitoring (FDA MAUDE, EU EUDAMED)
10.1 Does the manufacturer have a systematic, documented system to collect and review production and post-production information for risk implications?
- Post-production surveillance procedure
- Production and post-production activity plan
- Documented risk management system covering production phase
- Major NC: No system exists to collect and review production and post-production information, so the manufacturer is blind to real-world risk signals.
- Minor NC: A system exists but is limited to complaint handling, missing production data and proactive post-market information.
- Minor NC: Information is collected but there is no defined review step linking it back to the risk management file.
- Observation: The system is documented but not demonstrably operating (no records of collection or review).
Production and post-production activities are an integral part of the risk management process. The manufacturer must have a systematic and documented approach to gathering and acting on real-world device performance information throughout the entire product lifecycle.
10.1 (Action Triggers) Are there defined triggers and processes for acting when information indicates potential safety issues?
- Action trigger criteria
- Escalation procedures
- Decision trees for actions
- Action tracking system
- Management notification process
- Examples of triggered actions
- Timeline requirements for action initiation by risk severity
- Unclear action triggers
- No escalation process defined
- Delayed action initiation
- Poor action tracking
- No management involvement criteria
- Action timelines not linked to risk severity classification
The system must have defined triggers and processes for taking action when information indicates potential safety issues or risk changes. ACTION SYSTEM REQUIREMENTS: - Action trigger criteria defined - Escalation procedures documented - Decision trees for actions - Action tracking system - Management notification process - Timelines for action initiation
10.1 (Documentation) Is all post-production information, evaluations, decisions, and actions documented in the risk management file?
- Post-production surveillance reports in risk file
- Information evaluation records
- Decision documentation
- Action plans and completion records
- Risk management file updates
- Trending analysis reports
- Record retention schedule aligned with device expected lifetime
- Incomplete documentation in risk file
- Missing decision rationale
- No link to risk management file updates
- Poor record retention practices
- Trending reports not archived with the risk management file
- Retention periods shorter than regulatory minimum requirements
All post-production information, evaluations, decisions, and actions must be documented and maintained as part of the risk management file. DOCUMENTATION REQUIREMENTS: - Post-production surveillance reports - Information evaluation records - Decision documentation with rationale - Action plans and completion records - Risk management file updates - Trending analysis reports - Retention periods aligned with regulatory requirements
10.1 (Information Relevance) Is collected information evaluated for whether it impacts the risk profile or the validity of previous risk decisions?
- Information evaluation criteria
- New hazard identification records
- Risk re-estimation documentation
- Benefit-risk reassessment records
- State of the art reviews
- Impact assessment reports
- Standards watch list tracking new and revised normative references
- No systematic evaluation process
- Missing evaluation criteria
- Not tracking state of the art changes
- No trigger for risk reassessment
- Inadequate documentation of evaluations
- Benefit-risk reassessment not triggered when new clinical data emerges
Collected information must be systematically evaluated to determine if it impacts the device's risk profile or the validity of previous risk management decisions. EVALUATION CRITERIA: a) New hazards: Previously unrecognized hazards or hazardous situations b) Risk acceptability: Changes that make previously acceptable risks unacceptable c) Benefit-risk validity: Changes affecting benefit-risk balance d) State of the art: Evolution of standards, technology, or best practices SYSTEMATIC EVALUATION REQUIRED: - Information evaluation criteria defined - New hazard identification process - Risk re-estimation triggers - Benefit-risk reassessment process - State of the art monitoring
10.1 (System Establishment) Is a formal system in place to collect and review device information once it enters production and throughout market life?
- Post-production surveillance procedure
- Information collection system documentation
- Data collection forms and databases
- Review process documentation
- Feedback mechanisms
- Surveillance plan
- Responsibility assignment (RACI matrix)
- No formal post-production system documented
- Limited information sources defined
- Irregular review cycles not justified
- Poor integration with risk management
- Missing production phase monitoring
- Surveillance plan not covering all marketed geographies
A formal system must be in place to systematically collect and review information about the device once it enters production and throughout its market life. SYSTEM REQUIREMENTS: - Comprehensive surveillance system covering both production and post-market phases - Clear data collection requirements - Defined review frequencies - Assigned responsibilities - Integration with quality system and regulatory reporting REGULATORY REFERENCES: - FDA: 21 CFR 820.100 - Corrective and preventive action - EU MDR: Article 83-86 - Post-market surveillance - ISO 13485: Clause 8.2.1 - Feedback
10.2 Is information collection systematic, planned, and proactive - covering production data and post-market performance, not just complaints?
- Information collection procedure
- Post-production surveillance plan
- Complaint handling system linked to risk management
- Major NC: Information collection is reactive (complaints only), so emerging risks in production data and the wider market go undetected.
- Minor NC: Collection is not planned or systematic - sources and frequency are undefined.
- Minor NC: Key sources (manufacturing deviations, adverse-event databases, literature, similar devices) are not monitored.
- Observation: Collection occurs but is not documented (no record of what was collected, when, or from where).
Information collection must be systematic, planned, and comprehensive — covering both production-phase data and post-market performance information. Collection must be proactive (not limited to reactive complaint handling) and must feed into the risk management review process.
10.2 (Collection Documentation) Are collection activities documented - what was collected, when, and from which sources?
- Collection procedures
- Source documentation
- Collection logs
- Database records
- Search strategies for literature
- Surveillance reports
- Data management procedures
- Undocumented collection methods
- No collection records maintained
- Missing search strategies
- Poor data management practices
- Data integrity controls absent for collected information
- Retention periods not defined or not aligned with regulatory requirements
All collection activities must be documented with clear records of what was collected, when, and from which sources. DOCUMENTATION REQUIREMENTS: - Collection procedures - Source documentation - Collection logs - Database records - Search strategies (for literature) - Surveillance reports - Retention periods defined - Data integrity controls
10.2 (Collection Frequency) Is collection frequency risk-based, with higher-risk devices collected more frequently?
- Collection schedule documentation
- Frequency justification
- Risk-based interval determination
- Continuous monitoring evidence
- Periodic review cycles documentation
- Frequency adjustment records when device risk profile changes
- Regulatory-mandated collection interval compliance evidence
- No defined frequency
- Arbitrary intervals without justification
- Not risk-based
- Infrequent collection for high-risk devices
- Collection frequency not adjusted for newly launched devices
- No mechanism to increase frequency after safety signal detection
Collection frequency should be risk-based with higher-risk devices requiring more frequent data collection. ISO/TR 24971 GUIDANCE - FREQUENCY FACTORS: - Device risk classification - Market maturity - Historical issue rate - Regulatory requirements - Technology novelty TYPICAL FREQUENCIES: - High risk devices: Continuous or weekly - Moderate risk devices: Monthly - Low risk devices: Quarterly - Literature surveillance: Quarterly minimum IMPLEMENTATION: - Define risk-based collection frequencies - Consider device classification - More frequent for new devices - Document rationale for chosen frequencies
10.2 (Collection System) Is the collection system proactive (active methods, not just complaint handling) and comprehensive?
- Information collection plan
- Data collection procedures
- Surveillance protocols
- Collection forms and tools
- Database systems
- Automated collection mechanisms
- Active surveillance programs
- Only reactive collection (complaints only)
- No collection plan documented
- Limited data sources
- Manual only processes with no automation consideration
- Inconsistent collection methods
- No active surveillance methods such as clinical follow-up or targeted surveys
Information collection must be proactive and comprehensive, not limited to complaint handling or adverse event reporting. ISO/TR 24971 GUIDANCE - COLLECTION METHODS: ACTIVE METHODS: - Targeted surveys - Clinical follow-up studies - Proactive customer contacts - Field observations - Focus groups PASSIVE METHODS: - Complaint systems - Service reports - Warranty claims - Sales feedback - Social media monitoring SYSTEMATIC METHODS: - Literature searches - Database queries - Registry participation - Benchmarking studies IMPLEMENTATION REQUIREMENTS: - Develop comprehensive collection plan - Include both active and passive sources - Standardize collection methods - Consider automation where appropriate
10.2 (Information Sources) Are diverse information sources monitored (manufacturing deviations, complaints, adverse events, literature, similar devices)?
- Source mapping documentation
- Supplier feedback systems
- User survey programs
- Service data collection procedures
- Literature monitoring program
- Regulatory correspondence tracking
- Manufacturing data monitoring
- Installed base monitoring system
- Missing key sources from the seven categories
- No supply chain monitoring
- Limited user feedback mechanisms
- No literature surveillance
- Inadequate service data collection
- Regulatory authority communications not systematically tracked
Multiple diverse information sources must be monitored to ensure comprehensive risk information gathering. ISO/TR 24971 GUIDANCE - SOURCE DETAILS: a) MANUFACTURING: Deviations, yields, quality trends b) SUPPLY CHAIN: Component issues, changes, shortages c) INSTALLED BASE: Performance data, utilization patterns d) USERS: Complaints, satisfaction, off-label use e) SERVICE: Failure modes, maintenance issues f) PUBLIC: Literature, databases, competitors g) REGULATORY: Safety communications, recalls IMPLEMENTATION: - Map all potential sources - Establish collection mechanism for each - Include global sources - Ensure regular updates
10.2 (Similar Devices) Is information from similar devices monitored to identify risks that may not yet have manifested?
- Competitor surveillance program
- Recall database monitoring (FDA, MHRA, etc.)
- Literature on similar devices
- Standards updates tracking
- Professional society alerts
- Similar device definition documentation
- Adverse event database query results for equivalent device classifications
- Not monitoring similar devices
- Narrow definition of 'similar' (too restrictive)
- No systematic approach to surveillance
- Missing recall monitoring
- Predicate device field safety corrective actions not tracked
- Conference proceedings and industry alerts not included in surveillance scope
Learning from similar devices helps identify potential risks that may not yet have manifested in your device. ISO/TR 24971 GUIDANCE - SIMILARITY CRITERIA: - Same intended use - Similar technology - Same patient population - Similar risk profile - Common components - Equivalent principles of operation SURVEILLANCE SOURCES: - FDA MAUDE database - EU EUDAMED - Recall databases - Scientific literature - Conference proceedings - Industry alerts IMPLEMENTATION: - Define 'similar device' criteria broadly - Monitor multiple sources - Include predicate and competitor devices - Track recalls systematically
10.3 Is collected information systematically reviewed for safety implications - new hazards, changed risk levels, or invalidated assumptions?
- Information review procedure
- Periodic surveillance review reports
- Risk management file updates triggered by information review
- Major NC: Collected information is filed but never reviewed for safety implications, so changes in the risk profile are missed.
- Minor NC: Review happens but does not assess whether new hazards exist or whether prior risk estimates remain valid.
- Minor NC: Review intervals are undefined or not risk-based.
- Observation: Reviews occur but conclusions and any required risk-file updates are not documented.
Collected production and post-production information must be systematically reviewed to determine if it has safety implications — including whether new hazards exist, whether previously estimated risks are still acceptable, and whether the benefit-risk balance remains valid.
10.3 (Review Competence) Do reviews involve qualified people who can assess the technical, clinical, and regulatory implications?
- Review team composition documentation
- Competency records
- Training documentation
- Expert consultation records
- Cross-functional involvement evidence
- External specialist engagement records for novel hazard assessment
- Competency gap analysis and mitigation plans
- Single person reviews only
- Lacking clinical expertise on team
- No technical representation
- Missing regulatory knowledge
- No documented competency requirements for review team members
- External expertise not sought for novel or complex safety issues
Reviews must involve qualified individuals who can properly assess technical, clinical, and regulatory implications of the data. ISO/TR 24971 GUIDANCE - REVIEW TEAM EXPERTISE: - Risk management expertise - Clinical/medical knowledge - Engineering/technical understanding - Regulatory affairs knowledge - Quality assurance - Statistical analysis skills COMPETENCY AREAS: - Device technology understanding - Clinical application knowledge - Risk assessment methods - Data analysis skills - Regulatory requirements IMPLEMENTATION: - Form multidisciplinary review team - Include clinical, technical, and regulatory expertise - Document competencies - Consider external experts when needed
10.3 (Review Documentation) Are review activities, findings, decisions, and rationale formally documented?
- Review reports
- Decision documentation
- No-action rationales
- Meeting minutes
- Approval signatures
- Supporting data and analyses
- Participant attendance and competency records per review session
- Incomplete documentation
- Missing rationales for decisions
- No approval records
- Poor traceability
- Review participants and their qualifications not recorded
- Supporting data referenced but not attached to review records
All review activities, findings, decisions, and rationales must be formally documented and maintained. ISO/TR 24971 GUIDANCE - DOCUMENTATION ELEMENTS: - Review date and participants - Information reviewed - Analysis methods used - Findings and observations - Decisions and rationale - Actions assigned - Approval signatures IMPLEMENTATION: - Create comprehensive review reports - Document all decisions with rationale - Include supporting data - Obtain appropriate approvals
10.3 (Review Frequency) Are review intervals risk-based and justified for the device type?
- Review schedule documentation
- Frequency justification
- Risk-based review intervals
- Triggered review criteria
- Review calendar
- Examples of triggered reviews
- Frequency adjustment log after safety signal escalation
- No defined frequency documented
- Arbitrary intervals without justification
- Not risk-based
- No trigger criteria defined
- Inconsistent reviews
- Serious adverse events not triggering immediate out-of-cycle review
Review intervals must be risk-based and appropriate to the device type, with clear justification for the chosen frequency. ISO/TR 24971 GUIDANCE - FREQUENCY DETERMINATION: - Device risk classification - Market history - Technology maturity - Volume of data collected - Regulatory requirements TYPICAL INTERVALS: - High risk, new devices: Monthly or quarterly - High risk, established: Quarterly or semi-annually - Moderate risk: Semi-annually - Low risk: Annually IMMEDIATE REVIEW TRIGGERS: - Serious adverse events - Multiple similar complaints - Regulatory alerts - Significant literature findings - Major recall of similar device IMPLEMENTATION: - Set risk-based review frequency - Define trigger events for immediate review - Document rationale - Maintain review schedule
10.3 (Review Outcomes) Does each review reach clear conclusions on safety implications and necessary actions, including file updates?
- Review conclusions documentation
- Action recommendations
- Risk file update decisions
- Safety determinations
- No-action justifications
- Labeling and IFU update recommendations based on review findings
- Enhanced surveillance recommendations for emerging signals
- Unclear conclusions
- No action decisions documented
- Risk file not updated when needed
- Missing justifications for no-action
- Review outcomes not communicated to responsible action owners
- Labeling updates not initiated despite changed risk profile
Each review must reach clear conclusions about safety implications and necessary actions, including risk management documentation updates. ISO/TR 24971 GUIDANCE - POTENTIAL OUTCOMES: - No action required - risk profile unchanged - Update risk management file - Implement new risk controls - Modify existing controls - Initiate field action - Update labeling/IFU - Enhance surveillance IMPLEMENTATION: - Document clear conclusions - Make explicit action decisions - Update risk file as needed - Justify no-action decisions
10.3 (Review Process) Is collected information analyzed to identify changes in the risk profile or new safety concerns?
- Review procedures
- Analysis reports
- Safety assessment documentation
- Risk profile updates
- State of art evaluations
- Review meeting minutes
- Multidisciplinary review team records
- No systematic review process
- Missing review criteria
- Inadequate analysis depth
- No state of art monitoring
- Delayed reviews
- Single person conducting reviews
Collected information must be systematically analyzed to identify changes in the device's risk profile or new safety concerns. ISO/TR 24971 GUIDANCE - REVIEW OBJECTIVES: - Identify new hazards - Detect risk level changes - Assess cumulative effects - Evaluate risk control effectiveness - Monitor state of art evolution REVIEW INDICATORS: NEW HAZARDS: - Unexpected failure modes - Novel use errors - Emerging misuse patterns - New clinical findings RISK CHANGES: - Increased occurrence rates - Higher severity outcomes - Broader affected populations - Cumulative effects observed STATE OF ART: - New standards published - Advanced technologies available - Updated clinical guidelines - Regulatory expectations evolution IMPLEMENTATION: - Establish structured review process - Define clear review criteria - Include multidisciplinary expertise - Document all findings and decisions
10.3 (Trend Analysis) Are statistical and trend analyses performed to detect subtle changes or patterns over time?
- Trend analysis reports
- Statistical analyses
- Control charts
- Pattern recognition studies
- Signal detection and trending records
- Comparative analyses with baselines
- Geographic and demographic cluster analysis reports
- No trending performed
- Only individual event review
- Missing statistical analysis
- No baseline comparisons
- Complaint rate normalization not performed against installed base size
- Temporal and geographic clustering not investigated
Statistical and trend analyses must be performed to detect subtle changes or patterns in the data over time. ISO/TR 24971 GUIDANCE - TRENDING METHODS: - Run charts - Control charts - Pareto analysis - Time series analysis - Regression analysis - Pattern recognition algorithms TREND INDICATORS: - Increasing complaint rates - Shifting failure modes - Geographic clusters - Temporal patterns - User group variations IMPLEMENTATION: - Implement statistical trending methods - Establish baselines for comparison - Use appropriate analytical tools - Look for subtle patterns
10.4 When information indicates a safety impact, does the manufacturer take risk-proportionate action (more data, new controls, or risk re-assessment)?
- Action initiation records
- CAPA records linked to post-production surveillance findings
- Risk management file updates following information review
- Major NC: Information indicating a safety impact (new hazard, changed risk, invalidated benefit-risk) triggers no action.
- Minor NC: Actions are taken but are not risk-proportionate, or the risk management file is not updated to reflect them.
- Minor NC: Field actions do not follow defined regulatory/internal procedures or appropriate urgency.
- Observation: Action effectiveness is not verified (no check that the action worked or introduced no new risk).
When production or post-production information indicates a safety impact — such as a new hazard, changed risk level, or invalid benefit-risk assessment — the manufacturer must take timely and proportionate action, which may include risk management file updates, corrective actions, or field safety corrective actions.
10.4 (Action Requirements) Are actions risk-proportionate, ranging from gathering more data to new controls or full re-assessment?
- Action plans with timelines
- Risk re-assessments
- New control implementations
- Additional data collection plans
- Updated risk evaluations
- Corrective action records
- Proportionality justifications
- Actions not proportionate to risk
- Delayed implementation
- Incomplete follow-through
- No effectiveness verification
- Missing re-assessments when needed
- Risk-proportionality rationale not documented for selected action level
Actions must be risk-proportionate and may range from gathering more data to implementing new controls or conducting comprehensive risk re-assessment. ISO/TR 24971 GUIDANCE - ACTION HIERARCHY: 1. Immediate safety actions if needed 2. Additional information gathering 3. Detailed risk analysis 4. Risk control implementation 5. Overall risk re-evaluation PROPORTIONALITY FACTORS: - Severity of potential harm - Probability of occurrence - Number of devices affected - Vulnerable populations involved - Availability of alternatives ACTION EXAMPLES BY RISK LEVEL: - Minor risk increase: Enhanced monitoring, documentation update - Moderate risk: Label updates, user notification, training - Significant risk: Design modification, recall, cessation IMPLEMENTATION: - Develop risk-based action criteria - Create action plans with timelines - Implement through established processes - Verify effectiveness
10.4 (Additional Information) Where initial review reveals information gaps, are they filled before deciding actions?
- Information gap analyses
- Additional study protocols
- Enhanced surveillance plans
- Expert consultation records
- Literature search expansions
- Interim risk mitigation measures
- Root cause investigation reports for unresolved safety signals
- Acting without complete information
- Not identifying information needs
- Inadequate follow-up studies
- Missing expert input when needed
- No interim risk mitigation while awaiting additional data
- Timelines for obtaining additional information not established
Sometimes initial review reveals information gaps that must be filled before appropriate actions can be determined. ISO/TR 24971 GUIDANCE - INFORMATION SOURCES: - Focused clinical studies - Enhanced field surveillance - Root cause investigations - Expert panels - Usability assessments - Comparative effectiveness research IMPLEMENTATION: - Identify information gaps systematically - Plan targeted data collection - Set timelines for obtaining information - Document interim risk mitigation if needed
10.4 (Documentation) Is there a complete documentation trail for post-production actions from decision through effectiveness verification?
- Action decision records
- Implementation documentation
- Effectiveness reports
- Approval records
- Closure documentation
- Complete audit trail
- Timeline tracking records from initiation through closure
- Incomplete documentation
- Missing rationales for decisions
- No closure records
- Poor traceability
- Actions closed without documented effectiveness verification
- Audit trail gaps between decision and implementation phases
Complete documentation trail must exist for all post-production actions from decision through effectiveness verification. ISO/TR 24971 GUIDANCE - DOCUMENTATION REQUIREMENTS: - Action trigger and rationale - Risk assessment basis - Implementation plan and timeline - Resources allocated - Effectiveness criteria and results - Closure approval IMPLEMENTATION: - Document all action decisions and rationales - Track implementation progress - Record effectiveness verification - Maintain complete audit trail
10.4 (Effectiveness Verification) Are actions verified for effectiveness, including checking for unintended consequences or new risks?
- Effectiveness verification plans
- Post-action monitoring data
- Risk reduction confirmation
- New risk assessments
- Verification reports
- Success criteria documentation
- Long-term follow-up data confirming sustained risk reduction
- No effectiveness verification performed
- Not checking for new risks introduced
- Inadequate monitoring period
- Missing success criteria
- Monitoring duration not justified relative to failure mode characteristics
- Success criteria defined retrospectively rather than before action implementation
All actions must be verified for effectiveness, including checking for unintended consequences or new risks. ISO/TR 24971 GUIDANCE - VERIFICATION METHODS: - Complaint rate monitoring - Field performance data - Clinical outcome tracking - User feedback surveys - Audit observations SUCCESS INDICATORS: - Reduced incident rates - Improved performance metrics - User satisfaction increase - No new safety signals - Regulatory acceptance IMPLEMENTATION: - Define success criteria upfront - Plan verification methods - Monitor for sufficient duration - Check for new risks introduced
10.4 (Field Actions) Do field actions follow regulatory and internal procedures, with urgency matched to risk?
- Field action procedures
- Recall documentation
- Advisory notices issued
- Regulatory notifications (FDA, competent authorities)
- Customer communications
- Effectiveness checks
- Distribution verification
- Delayed field actions
- Inadequate customer reach
- Poor effectiveness tracking
- Incomplete regulatory reporting
- Missing regulatory timelines
- Distribution verification not performed to confirm all affected units reached
Field actions must follow regulatory requirements and internal procedures, with appropriate urgency based on risk level. ISO/TR 24971 GUIDANCE - FIELD ACTION TYPES: - Product recall - Field correction - Product modification - Safety advisory - Software update - Enhanced monitoring REGULATORY CONSIDERATIONS: - Notification timelines (FDA, EU, etc.) - Content requirements - Distribution verification - Effectiveness checks - Periodic status reports IMPLEMENTATION: - Follow established field action procedures - Meet all regulatory timelines - Ensure comprehensive customer notification - Verify effectiveness
10.4 (Management Review) Is management informed of significant post-production actions to ensure resources and alignment?
- Management review inputs
- Executive summaries of actions
- Resource allocation records
- Strategic decision documentation
- Management approvals
- Risk-based escalation criteria defining which actions require top management review
- Board-level safety governance meeting minutes
- No management visibility of significant actions
- Inadequate resource allocation
- Missing strategic alignment
- No executive oversight
- Escalation criteria not defined for determining management involvement threshold
- Resource requests for safety actions delayed or deprioritized without justification
Management must be informed of significant post-production actions to ensure appropriate resources and strategic alignment. ISO/TR 24971 GUIDANCE - MANAGEMENT CONSIDERATIONS: - Resource requirements - Business impact - Regulatory implications - Reputation considerations - Strategic alignment IMPLEMENTATION: - Include in management review process - Provide clear executive summaries - Request necessary resources - Obtain strategic approval for significant actions
10.4 (Risk File Update) Is the risk management file kept current, reflecting changes from post-production findings and actions?
- Updated risk analyses in risk file
- Revised risk matrices
- New control documentation
- Updated residual risk evaluations
- Change control records
- Traceability to post-production findings
- Version comparison showing specific changes to risk assessment content
- Risk file not updated after changes
- Incomplete updates
- No revision control
- Missing traceability to triggering events
- Overall residual risk not re-evaluated after significant control measure changes
- Change history not maintained showing what was modified and why
The risk management file must remain current, reflecting all changes resulting from post-production findings and actions. ISO/TR 24971 GUIDANCE - UPDATE REQUIREMENTS: - New hazards added - Risk levels revised - Control measures modified - Residual risks updated - Overall risk re-assessed - Benefit-risk analyses revised IMPLEMENTATION: - Update risk file promptly - Use revision control - Maintain change history - Ensure traceability to triggering information
Each item shows its evidence, common nonconformities and auditor tips. The PDF holds the same content, formatted for a clipboard.