ISO 14971:2019 Audit Checklist
Objective Evidence
- Risk management procedure document
- Risk management process flowchart with decision points
- Integration points with QMS processes
- Process owner assignments and responsibilities
- Risk management training records
- Process review and update records
- Risk management effectiveness metrics and trending reports
Common Nonconformities
- Process not fully documented
- Missing monitoring effectiveness procedures
- No clear process ownership
- Inadequate training on the process
- Process not regularly reviewed or updated
- Poor integration with change management
- Risk management process not aligned with current regulatory requirements
Auditor Tips
A risk management process must cover the full device lifecycle: identifying hazards across all reasonably foreseeable use scenarios, estimating risk against defined scales and criteria, evaluating risk against approved acceptability thresholds, implementing risk controls in the established priority order, and monitoring control effectiveness using production and post-market data. The process can sit within the existing quality management system and should connect to product-realization activities such as the design and production controls in ISO 13485. Auditors should confirm the process is actually maintained in practice, not documented once and shelved.
Objective Evidence
- Resource allocation documentation
- Budget approvals for risk management
- Personnel assignments and job descriptions
- Training budget and records
- Management review minutes
- Organizational charts showing risk roles
- Risk management policy signed by CEO or executive leadership
Common Nonconformities
- No documented resource allocation
- Insufficient personnel for workload
- Lack of management involvement
- No evidence of commitment
- Inadequate training resources
- Management review minutes show no discussion of risk management topics
Auditor Tips
Top management must show active commitment through real resource allocation and personnel assignment, not just a signed policy. ISO/TR 24971 stresses that this commitment should be visible and measurable. Operational responsibility can be delegated, but accountability remains with top management, so look for evidence of genuine engagement (budget, headcount, participation in risk reviews) rather than a policy statement alone.
Objective Evidence
- Competency matrices for risk roles
- Training records and certificates
- Education and experience documentation
- Job descriptions with requirements
- Competency assessments
- Cross-functional team composition
- Annual competency review records for risk management personnel
Common Nonconformities
- No defined competency requirements
- Missing training records
- Inadequate cross-functional expertise
- No ongoing competency assessment
- Single person doing all risk work
- Risk management team lacks clinical or medical expertise representation
Auditor Tips
Organizations must define competency requirements for risk management roles, ensure personnel meet these requirements, and maintain evidence of competence. ISO/TR 24971 identifies key competency areas: risk management principles and methods, medical device technology, clinical application and use environment, regulatory requirements, statistical methods, human factors/usability engineering, manufacturing processes, and quality system requirements.
Objective Evidence
- Risk management plan document
- Plan approval records
- Device family justification
- Plan version control
- Plan stored in risk management file
- Risk management plan template with standardized sections
- Plan completeness checklist used before approval
Common Nonconformities
- Plan created after activities begin
- Generic plan not tailored to device
- Plan not formally approved
- Missing from risk management file
- Inadequate device family justification
- Plan scope does not match actual device configurations or variants
Auditor Tips
A documented plan must be created before risk management activities begin, either for individual devices or device families where appropriate. The plan establishes the scope, methodology, and acceptance criteria for all subsequent risk management activities. Device family plans must include a clear justification for grouping and analysis of common versus unique hazards. The plan must be formally approved, version-controlled, and stored in the risk management file. It serves as the foundational roadmap ensuring systematic and consistent risk management execution.
Objective Evidence
- Risk management file structure
- Traceability matrices
- Document control procedures
- File organization system
- Cross-reference mechanisms
- Electronic or physical filing system
- Risk management file index with document location references
Common Nonconformities
- Incomplete traceability
- Missing documents
- Poor organization
- No clear structure
- Inadequate cross-referencing
- Mixed device families inappropriately
Auditor Tips
A risk management file must hold all risk management documentation with clear traceability from hazard identification through final risk acceptance. ISO/TR 24971 recommends a standardized structure spanning the risk management plan, analysis reports, evaluation documentation, control documentation, overall residual-risk evaluation, the risk management review, and post-production information. The file does not have to be a single binder; it can be assembled by reference from other QMS or regulatory records, in any suitable medium, as long as the traceability holds together.
Objective Evidence
- Risk management procedure or standard operating procedure
- Risk management process flowchart
- Risk management policy statement
- Integration with quality management system documentation
- Risk management training curriculum and attendance records
- Cross-functional risk team charter and meeting schedule
- Risk management software or tool validation records
Common Nonconformities
- Process not covering entire product lifecycle
- Missing integration with QMS processes
- Lack of ongoing maintenance procedures
- No clear process ownership or responsibilities
- Risk management activities conducted by a single individual without cross-functional input
- No periodic effectiveness review of the risk management process
Auditor Tips
A comprehensive risk management process must be established that covers the entire product lifecycle from initial concept through design, manufacturing, distribution, use, and final disposal. This process must be systematic, documented, and continuously maintained with defined roles, cross-functional participation, and integration into the quality management system. The process should address both foreseeable and emerging hazards using structured techniques such as FMEA, fault tree analysis, and severity-probability matrices.
Objective Evidence
- Risk management activities in design phase
- Manufacturing risk assessments
- Post-market surveillance risk reviews
- Field action risk assessments
- End-of-life risk considerations
- Decommissioning risk assessment for end-of-life planning
- Change management procedure requiring risk re-assessment
- Supply chain disruption risk evaluation records
Common Nonconformities
- Risk management stops at product release
- No post-market risk management activities
- Missing risk assessment for changes
- No consideration of disposal risks
- Field safety corrective actions not triggering risk file updates
- No defined process for incorporating post-market vigilance data
Auditor Tips
Risk management must be an ongoing process from initial concept through final disposal, not just during design and development. Each lifecycle phase introduces unique hazards: design decisions may create latent failure modes, manufacturing variations can affect safety margins, distribution and storage conditions can degrade device integrity, clinical use exposes patients to residual risks, and disposal may involve biohazard or environmental concerns. The process must have defined triggers for re-assessment at each phase transition.
Objective Evidence
- Risk acceptability policy document
- Policy approval by top management
- Reference to regulations and standards
- State of the art considerations
- Stakeholder input documentation
- Regulatory landscape analysis informing acceptability criteria
- Periodic policy review and revision records
Common Nonconformities
- No formal policy documented
- Policy not approved by management
- Missing regulatory alignment
- No state of the art consideration
- Stakeholder concerns not addressed
- Risk acceptability criteria not updated when regulations change
Auditor Tips
Management must establish a formal policy that defines how risk acceptability criteria are determined, considering regulatory requirements and state of the art. The policy should include clear statement of risk philosophy, reference to applicable regulations, process for determining acceptability levels, consideration of similar devices, and benefit-risk framework.
Objective Evidence
- Clinical use training documentation
- Regulatory training certificates
- Technical device training
- Risk methodology training
- Experience with similar devices
- Cross-functional team composition chart showing expertise areas
- Regulatory affairs training completion certificates
Common Nonconformities
- Missing clinical perspective
- Inadequate regulatory knowledge
- No risk methodology training
- Lack of device-specific knowledge
- No team member with hands-on experience with the device type
- Regulatory training not updated after major regulatory changes
Auditor Tips
Competence must cover both technical device knowledge and broader contextual understanding including clinical use and regulatory environment. Not every person needs all competencies, but the team collectively should cover all areas including clinical/medical expertise, engineering/design expertise, manufacturing expertise, quality/regulatory expertise, service/field experience, and human factors expertise.
Objective Evidence
- Scope statement with device description
- Responsibility matrix or RACI chart
- Review schedule and criteria
- Risk acceptability matrix
- Overall residual risk criteria
- Verification plan
- Post-production monitoring plan
Common Nonconformities
- Incomplete scope definition
- Vague responsibility assignments
- Missing acceptability criteria
- No criteria for unknown probabilities
- Inadequate post-production planning
- Verification activities not linked to specific risk control measures
Auditor Tips
The plan must comprehensively address all aspects of how risk management will be conducted, with specific required elements covering scope, responsibilities, review requirements, acceptability criteria, overall residual risk evaluation methodology, verification activities, and post-production information collection. Each element should be sufficiently detailed to guide execution without ambiguity. The scope must clearly identify the device, lifecycle phases covered, and any exclusions. Responsibility assignments should use a RACI or equivalent framework.
Objective Evidence
- Complete risk management plan
- All risk analysis worksheets/reports
- Risk evaluation decisions
- Risk control verification records
- Risk management review reports
- Post-production surveillance data
- Table of contents with document references for each required element
Common Nonconformities
- Missing post-production information
- Incomplete risk control verification
- No risk management review
- Poor reference management
- Outdated information
- Risk management review report missing from file
Auditor Tips
The file must contain all key risk management deliverables either directly or through clear references to their locations. ISO/TR 24971 provides content details: risk management plan (version-controlled, approved), risk analysis (all worksheets, FMEAs, FTAs, use error analysis), risk evaluation (decisions with rationale, meeting minutes), risk control (specifications, verification/validation reports), residual risk (final risk levels, benefit-risk analyses), risk review (management review with actions), and post-production (complaint data, field experience, updates).
Objective Evidence
- Lifecycle phase documentation in risk management plan
- Risk management activities mapped to development phases
- Post-production risk management procedures
- Decommissioning risk assessments
- Change management risk assessment procedure
- Post-production risk monitoring metrics dashboard
- Risk management file update log showing lifecycle updates
Common Nonconformities
- Risk management ending at product release
- No post-market risk management activities
- Missing risk assessment for disposal/decommissioning
- Inadequate change management risk assessment
- No documented triggers for risk re-assessment during lifecycle changes
- Post-market surveillance data not linked to risk management file
Auditor Tips
Risk management is not a one-time activity but must be maintained from initial conception through design, production, distribution, clinical use, servicing, and final disposal of the device. Each lifecycle phase introduces unique hazards that require identification and control. Design changes, manufacturing process modifications, and post-market field data must all trigger risk re-assessment activities to ensure ongoing safety throughout the device's commercial life.
Objective Evidence
- Procedures for each element
- Templates for each activity
- Decision criteria documentation
- Element interconnection documentation
- Review and approval requirements
- Completed risk analysis worksheets for current product
- Risk evaluation decision log with rationale
- Post-production information collection and review records
Common Nonconformities
- Weak or missing risk evaluation criteria
- Inadequate post-production procedures
- Poor linkage between elements
- Missing feedback loops
- Risk control implemented without documented risk evaluation
- Post-production monitoring plan absent or generic
Auditor Tips
The process must systematically address all four core elements of risk management in a coordinated manner: risk analysis to identify and estimate hazards, risk evaluation to judge acceptability, risk control to reduce unacceptable risks, and production/post-production activities for ongoing monitoring. These elements form an iterative cycle where post-production data feeds back to refine risk analysis. Each element must have defined inputs, outputs, decision criteria, and documentation requirements to ensure a complete and auditable risk management record.
Objective Evidence
- Management review schedule
- Review meeting minutes
- Process effectiveness metrics
- Action items and follow-up
- Process improvement decisions
- Risk management process effectiveness trend analysis reports
- Corrective actions arising from management review of risk process
Common Nonconformities
- No planned review intervals
- Reviews not documented
- No effectiveness measures
- Actions not tracked to completion
- Process never updated
- Management review agenda does not include risk management process assessment
Auditor Tips
Management must conduct periodic reviews of the risk management process effectiveness, not just individual risk assessments. ISO/TR 24971 recommends at least annual reviews, or when significant changes occur. Reviews should assess effectiveness indicators such as field issues, process timeliness, quality of assessments, and regulatory findings.
Objective Evidence
- Training database or files
- Competency assessment records
- Qualification certificates
- Experience summaries
- Annual competency reviews
- Electronic training management system reports
- Competency gap analysis with remediation action plans
Common Nonconformities
- Incomplete records
- No retention policy
- Missing update procedures
- No periodic review
- Training records not accessible for regulatory audit
- No procedure for updating competency records when roles change
Auditor Tips
Competence records must be documented, controlled, and retained per quality system and regulatory requirements. Records should demonstrate not only that training was completed but that competence was assessed and confirmed through objective means such as examinations, practical demonstrations, or supervised work products. Records must be maintained throughout employment and updated when roles change, new competency requirements emerge, or periodic reassessments are conducted.
Objective Evidence
- Device name and model numbers
- Intended use statement
- Lifecycle phase coverage
- Exclusions clearly stated
- Configuration/variant coverage
- Regulatory classification justification linked to scope
- Accessory and component coverage documentation
Common Nonconformities
- Ambiguous device identification
- Missing lifecycle phases
- Unclear variant coverage
- No intended use statement
- Scope does not mention software components or cybersecurity aspects
- No documentation of lifecycle phase boundaries and transitions
Auditor Tips
The plan must clearly define what device(s) it covers and which lifecycle phases are addressed, including any exclusions with documented justification. The scope should reference the device name, model numbers, intended use statement, regulatory classification, applicable standards, and all variants or configurations covered. Lifecycle phase coverage must explicitly address design, manufacturing, distribution, clinical use, maintenance, and disposal phases. Any narrowing of scope must be justified and approved.
Objective Evidence
- File update procedures
- Change control records
- Post-market update logs
- Periodic review documentation
- File revision history
- Annual risk management file review schedule and completion records
- Trigger list for unscheduled file updates with responsible owners
Common Nonconformities
- File not updated post-launch
- No maintenance procedures
- Missing change control
- Outdated risk assessments
- Risk management file has not been updated since initial product release
- No procedure defining when and how the file should be updated
Auditor Tips
The file is a living document that must be updated with new information throughout the entire device lifecycle. ISO/TR 24971 identifies update triggers: design changes, manufacturing process changes, new clinical data, adverse events, regulatory changes, new standards, complaint trends, and audit findings. Best practices include annual file review minimum, clear update procedures, version control system, archiving superseded documents, and maintaining file integrity.
Objective Evidence
- Process documents showing all four elements
- Risk analysis reports
- Risk evaluation criteria and decisions
- Risk control measures and verification
- Post-production monitoring procedures
- Procedure interrelationship diagram showing element linkages
- Training records demonstrating understanding of all four elements
Common Nonconformities
- Missing or weak risk evaluation criteria
- Inadequate post-production activities
- Poor linkage between elements
- Incomplete risk control verification
- Risk control measures implemented without prior risk evaluation
- No feedback loop from post-production back to risk analysis
Auditor Tips
The risk management process must systematically address all four key elements to ensure comprehensive risk management: risk analysis identifies hazards and estimates risks, risk evaluation determines acceptability, risk control reduces unacceptable risks, and production/post-production activities provide ongoing monitoring. These elements must be interconnected with clear feedback loops, not treated as isolated sequential steps, to maintain a living risk profile throughout the device lifecycle.
Objective Evidence
- Design control procedures with risk management
- Project plans showing risk deliverables
- Gate reviews including risk assessments
- Risk-based validation planning
- Change control risk requirements
- Process FMEA records linked to product risk management
- Supplier qualification risk assessment documentation
- Design review meeting minutes showing risk discussion agenda items
Common Nonconformities
- Separate, uncoordinated processes
- Risk management as add-on activity
- No risk-based decision gates
- Missing from change control
- Design outputs do not reference risk control requirements
- Verification and validation plans lack risk-based test case derivation
Auditor Tips
Risk management must be integrated into existing development processes, not run in parallel as a separate administrative exercise. Product realization activities such as design input definition, design verification, design validation, process validation, and change control should each incorporate risk management deliverables. Gate reviews must include risk status as a mandatory criterion for progression. This ensures risk considerations actively drive design decisions rather than merely documenting them after the fact.
Objective Evidence
- RACI matrix for risk activities
- Role descriptions
- Approval authority matrix
- Cross-functional team charter
- Competency requirements
- Succession planning for critical risk management roles
- Conflict of interest disclosure for risk team members
Common Nonconformities
- Unclear approval authorities
- Missing competency requirements
- No backup assignments
- Inadequate cross-functional representation
- Same person both performs and approves risk management activities
- No succession plan for key risk management personnel
Auditor Tips
Clear assignment of who is responsible and has authority for each risk management activity is essential for accountability and efficient execution. The plan should use a RACI matrix or equivalent to define responsibility, accountability, consultation, and information roles for each major activity. Authority levels for risk acceptance decisions, the composition and charter of the cross-functional risk team, competency requirements for each role, and backup or succession assignments should all be documented.
Objective Evidence
- Design control procedures with risk management integration
- Manufacturing process risk assessments
- Risk-based validation protocols
- Risk management deliverables in project plans
- Process FMEA integrating manufacturing risk with product risk
- Gate review checklists with mandatory risk deliverables
- Supplier qualification risk assessments
Common Nonconformities
- Parallel but disconnected processes
- Risk management as afterthought
- Missing risk-based decision points
- No risk management in change control
- Design reviews proceeding without risk management deliverables
- No risk-based input into verification and validation planning
Auditor Tips
Risk management must be integrated into existing product development and realization processes rather than operating as a separate parallel system. Design reviews, verification planning, validation protocols, and change control procedures should all include risk management deliverables as mandatory inputs. This integration ensures risk considerations drive design decisions in real time and that design changes trigger immediate risk re-assessment rather than periodic batch updates.
Objective Evidence
- Review schedule and milestones
- Review criteria and checklists
- Review meeting requirements
- Approval requirements
- Review meeting agenda templates for risk activities
- Independent reviewer qualification criteria
- Review escalation procedures for unresolved issues
Common Nonconformities
- No defined review points
- Unclear review criteria
- Missing review schedule
- Review meetings not documented with attendees and decisions
- No independent review of risk acceptability decisions
- Review outcomes not tracked through corrective action system
Auditor Tips
The plan must define when and how risk management activities will be reviewed, including the frequency, participants, criteria, and escalation procedures for review activities. Reviews should occur at planned milestones aligned with design control phases, when significant new information becomes available, and at defined intervals during the post-production phase. Review criteria should be objective and testable, reviewer qualifications should be specified, and review outcomes must be documented with action items tracked to closure.
Objective Evidence
- Risk management file
- Risk management plan
- Risk analysis reports
- Risk management review records
- Traceability matrices
- Document control procedure governing risk management records
- Internal audit findings related to risk management documentation
Common Nonconformities
- Incomplete documentation
- Missing approval signatures
- Poor document control
- Inadequate record retention
- Risk management records not controlled under the document control system
- No internal audit coverage of risk management documentation completeness
Auditor Tips
All risk management activities must be documented to demonstrate compliance with the standard through objective evidence. Documentation must be sufficient for an independent reviewer or auditor to reconstruct the risk management rationale, trace each hazard from identification through control and residual risk acceptance, and verify that the process was followed systematically. Records must be controlled, retained, and readily accessible for regulatory inspection.
Objective Evidence
- Risk acceptability matrix
- Probability and severity scales
- Criteria for unknown probabilities
- Benefit-risk criteria
- State of the art considerations
- Semi-quantitative risk matrix with defined probability and severity scales
- Rationale documentation for acceptability threshold selection
Common Nonconformities
- No criteria for unknown probabilities
- Subjective acceptability criteria
- Missing benefit-risk considerations
- Criteria not aligned with regulations
- Risk matrix thresholds not justified by regulatory or clinical evidence
- No guidance for evaluators on borderline risk decisions
Auditor Tips
The plan must define how to determine if risks are acceptable, including special cases where probability cannot be determined. Criteria must include clearly defined probability and severity scales with unambiguous category boundaries, a risk acceptability matrix showing acceptable, ALARP, and unacceptable zones, specific criteria for handling risks where probability of occurrence cannot be estimated, guidance on benefit-risk considerations for borderline decisions, and alignment with applicable regulatory requirements and state of the art.
Objective Evidence
- Overall risk evaluation methodology
- Benefit-risk analysis approach
- Acceptability criteria for overall risk
- Decision-making framework
- Overall residual risk evaluation template and procedure
- Risk-benefit analysis framework documentation
- Criteria for distinguishing individual from overall residual risk
Common Nonconformities
- No overall risk evaluation method
- Missing acceptability criteria
- No benefit-risk framework
- Overall residual risk treated as simple sum of individual risks
- No procedure for evaluating synergistic effects of multiple residual risks
- Benefit-risk framework absent for overall residual risk evaluation
Auditor Tips
The plan must define how all remaining risks will be evaluated collectively and what makes the overall residual risk acceptable. The overall residual risk evaluation must consider not just individual residual risks in isolation but their cumulative and synergistic effects on patient safety. The methodology should address how individual residual risks are aggregated, how interactions between residual risks are evaluated, and how the benefit-risk balance is assessed when overall residual risk exceeds normal thresholds.
Objective Evidence
- Verification plan
- Testing protocols
- Verification acceptance criteria
- Validation requirements
- Verification protocol templates for risk control measures
- Acceptance criteria linked to risk reduction targets
- Verification method selection rationale documentation
Common Nonconformities
- No verification planning
- Unclear verification methods
- Missing acceptance criteria
- Verification activities not linked to specific risk control measures
- No acceptance criteria defined for verification testing
- Verification limited to design verification without clinical validation
Auditor Tips
The plan must define how risk control measures will be verified to ensure they are effective, including both implementation verification and effectiveness verification. Verification planning should specify methods such as testing, analysis, inspection, or demonstration; acceptance criteria derived from risk reduction targets; sample sizes and statistical rationale where applicable; and the relationship between risk verification activities and QMS design verification and validation activities.
Objective Evidence
- Post-market surveillance plan
- Complaint monitoring procedures
- Field data review process
- Feedback loops to risk management
- Complaint trend analysis procedures linked to risk management
- Adverse event reporting and risk assessment workflow
- Clinical follow-up data collection and review protocol
Common Nonconformities
- No post-production planning
- Missing data collection methods
- No feedback mechanism
- Post-market surveillance plan does not reference risk management file
- No defined criteria for when field data triggers risk re-assessment
- Complaint handling procedure isolated from risk management process
Auditor Tips
The plan must define how production and post-market data will be collected and reviewed for risk implications, including sources such as complaint data, adverse event reports, field service records, clinical follow-up studies, and literature monitoring. The plan should specify data collection methods, review frequency, criteria for triggering risk re-assessment, responsible personnel, and feedback mechanisms to update the risk management file. This element ensures risk management remains a living process.
Objective Evidence
- Plan revision history
- Review triggers defined
- Update approval records
- Change justifications
- Review meeting minutes
- Plan change approval workflow documentation
- Trigger criteria for unscheduled plan reviews
Common Nonconformities
- Plan never updated after initial approval
- No defined review triggers
- Updates not documented
- No version control
- Plan version history shows no updates since initial approval
- No documented criteria for when plan updates are required
Auditor Tips
The plan must be actively maintained and updated throughout the risk management process as new information becomes available. This requires defined criteria for when updates are necessary, a formal change control process for plan modifications, management approval of significant changes, and distribution of updated plans to all stakeholders. The plan should be reviewed at minimum when significant design changes occur, when post-market data reveals new hazards, when regulatory requirements change, or when process improvements are identified.
Objective Evidence
- Risk analysis procedure
- Risk analysis plan
- Cross-functional team records
- Information sources used
- Analysis methodology documentation
- Completeness verification
- Independent audit records confirming compliance with this requirement
Common Nonconformities
- Incomplete scope definition
- Missing team expertise
- Inadequate information gathering
- No systematic approach
- Poor documentation structure
- No evidence of periodic review or update of this activity
Auditor Tips
Risk analysis is a comprehensive process that systematically identifies and estimates all risks associated with a medical device throughout its lifecycle. This is the foundation of risk management and must be systematic and comprehensive.
Objective Evidence
- Risk analysis report
- Intended use and misuse documentation
- Safety characteristics checklist
- Hazard identification worksheets
- Risk estimation matrices
- FMEAs, FTAs, or other analysis tools
- Use error analysis
Common Nonconformities
- Missing reasonably foreseeable misuse
- Incomplete hazard identification
- No systematic approach to identification
- Risk estimation without data
- Missing use error considerations
- Inadequate cross-functional input
Auditor Tips
A comprehensive risk analysis must be performed that systematically identifies and estimates all risks associated with the device, including both intended use and foreseeable misuse scenarios.
Objective Evidence
- Intended use statement in risk management plan
- Medical indication documentation
- Patient population definition
- User profile descriptions
- Use environment specifications
- Operating principle documentation
- Anatomical interaction areas
- Use error analysis documentation
- Task analysis showing error points
- Known misuse from similar devices
Common Nonconformities
- Vague or incomplete intended use
- Missing user profile information
- No use environment consideration
- Patient population not defined
- Operating principle not documented
- Only considering use errors
- Missing intentional misuse
- No systematic misuse analysis
Auditor Tips
A comprehensive definition of intended use must be documented, covering all aspects of how, where, by whom, and for what purpose the device will be used. Additionally, potential misuse scenarios including both unintentional use errors and intentional misuse must be documented.
Objective Evidence
- Safety characteristics checklist
- Design specifications with safety limits
- Material properties documentation
- Performance parameters and tolerances
- Software characteristics
- Energy output specifications
- Biocompatibility data
Common Nonconformities
- Incomplete characteristic identification
- Missing quantitative limits
- No systematic approach
- Software characteristics overlooked
- Aging/degradation not considered
- No evidence of periodic review or update of this activity
Auditor Tips
All device characteristics that could potentially impact safety must be systematically identified, documented, and where applicable, have defined limits. This includes physical, chemical, electrical, biological, and software characteristics.
Objective Evidence
- Hazard identification worksheets
- Brainstorming session records
- Hazard checklists (ISO 14971 Annex C)
- User task analysis
- Failure mode analysis
- Environmental condition analysis
- Similar device incident data
Common Nonconformities
- Missing use error hazards
- Incomplete fault condition analysis
- No environmental considerations
- Single method used
- Late lifecycle hazards missed
- No team-based identification
Auditor Tips
All potential hazards must be systematically identified considering normal use, fault conditions, use errors, and environmental factors throughout the device lifecycle. Use multiple identification methods including top-down, bottom-up, and experiential.
Objective Evidence
- Risk estimation matrices
- Probability calculations
- Severity classifications
- Risk scoring worksheets
- Statistical analyses
- Clinical data supporting estimates
- Independent audit records confirming compliance with this requirement
Common Nonconformities
- Missing risk estimates for some hazards
- Probability without data support
- Inconsistent severity assignments
- No documented estimation method
- Mixing probability concepts
- No evidence of periodic review or update of this activity
Auditor Tips
Risk must be estimated for every hazardous situation by combining probability of occurrence and severity of potential harm. Define clear probability and severity scales. Use available data for estimates. Document estimation rationale.
Objective Evidence
- Risk analysis scope statement
- Reference to risk management plan
- Coverage of all plan elements
- Lifecycle phase coverage
- Variant/configuration coverage
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Scope mismatch with plan
- Missing lifecycle phases
- Incomplete variant coverage
- Undocumented scope changes
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
The risk analysis must cover the scope defined in the risk management plan, ensuring consistency and completeness across all planned areas. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Intended use statement in risk management plan
- Medical indication documentation
- Patient population definition (age, condition, capacity)
- User profile descriptions (training, experience, limitations)
- Use environment specifications (home, hospital, ambulance)
- Part of body/tissue interaction
- Duration and frequency of use
- Operating principle and technology
Common Nonconformities
- Vague or incomplete intended use
- Missing user profile information
- No use environment consideration
- Patient population not defined
- Operating principle not documented
- No evidence of periodic review or update of this activity
Auditor Tips
ISO/TR 24971:2020 A.2.5.2 states: 'The intended use of the medical device is an important aspect and is the starting point of the risk analysis. The manufacturer should consider the intended user(s) of the medical device, e.g., whether a lay user or a trained medical professional will use the medical device.'
Objective Evidence
- Safety characteristics checklist
- Design specifications with safety limits
- Material properties documentation
- Performance parameters and tolerances
- Software characteristics
- Energy output specifications
- Biocompatibility data
Common Nonconformities
- Incomplete characteristic identification
- Missing quantitative limits
- No systematic approach
- Software characteristics overlooked
- Aging/degradation not considered
- No evidence of periodic review or update of this activity
Auditor Tips
Use ISO 14971 Annex C questions systematically. Document all characteristics with clear limits where applicable. Consider full lifecycle including degradation. Categories include: physical, chemical, electrical, biological, and software.
Objective Evidence
- Hazard identification worksheets
- Brainstorming session records
- Hazard checklists (ISO 14971 Annex C)
- User task analysis
- Failure mode analysis (FMEA/FMECA)
- Fault tree analysis (FTA)
- Environmental condition analysis
- Similar device incident data
Common Nonconformities
- Missing use error hazards
- Incomplete fault condition analysis
- No environmental considerations
- Single method used
- Late lifecycle hazards missed
- No team-based identification
Auditor Tips
Use multiple identification methods. Include diverse team members. Consider all lifecycle phases. Document all hazards even if later deemed not applicable. Methods include: FMEA, FTA, HAZOP, PHA, incident analysis, and expert consultation.
Objective Evidence
- Risk estimation matrices
- Probability calculations (P1 × P2)
- Severity classifications
- Risk scoring worksheets
- Statistical analyses
- Clinical data supporting estimates
- Independent audit records confirming compliance with this requirement
Common Nonconformities
- Missing risk estimates for some hazards
- Probability without data support
- Inconsistent severity assignments
- No documented estimation method
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
Risk estimation combines P1 (probability of hazardous situation occurring) × P2 (probability of hazardous situation leading to harm). Severity considers type of injury, number affected, duration, reversibility, and impact on quality of life.
Objective Evidence
- Completed analysis for each element
- Integration between elements
- Sequential flow documentation
- Review checkpoints
- Approval records
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Skipping elements
- Poor integration
- No review points
- Inadequate documentation
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
All five sub-elements must be completed systematically and documented for comprehensive risk analysis. Each element builds on the previous one. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Literature review documentation
- Standards reviewed list
- Similar device analysis
- Field data analysis reports
- Clinical evidence review
- Expert consultation records
- Database search results
Common Nonconformities
- Limited information sources
- No similar device analysis
- Missing field data review
- Inadequate literature search
- No expert consultation
- No evidence of periodic review or update of this activity
Auditor Tips
Risk analysis must be evidence-based, using all available relevant information sources to ensure comprehensive hazard identification and accurate risk estimation. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Use error analysis documentation
- Task analysis showing error points
- Known misuse from similar devices
- Usability test findings
- Field experience reports
- Intentional misuse scenarios
- Independent audit records confirming compliance with this requirement
Common Nonconformities
- Only considering use errors
- Missing intentional misuse
- No systematic misuse analysis
- Not learning from similar devices
- Ignoring off-label use potential
- No evidence of periodic review or update of this activity
Auditor Tips
ISO/TR 24971:2020 A.2.5.2 clarifies: 'This analysis should consider that the medical device can also be used in situations other than those intended by the manufacturer and in situations other than those foreseen when the idea for a medical device was first conceived. It is important that the manufacturer tries to look into the future to see the hazards due to potential uses of their medical device and also the reasonably foreseeable misuse.'
Objective Evidence
- Hazardous situation worksheets
- Event sequence diagrams
- Cause-and-effect analyses
- Scenario descriptions
- Use case analyses
- Combination event matrices
- Bow-tie diagrams
Common Nonconformities
- Direct hazard-to-harm jumps
- Missing intermediate events
- No combination events considered
- Incomplete scenario analysis
- Missing reasonably foreseeable sequences
- No evidence of periodic review or update of this activity
Auditor Tips
The analysis must identify how hazards lead to hazardous situations through various event sequences, considering the chain of events from hazard to potential harm. Document clear event sequences from hazard to hazardous situation. Consider multiple pathways and combination events.
Objective Evidence
- Statistical analysis of field data
- Failure rate calculations
- Clinical trial adverse event rates
- Database search results
- Expert consensus documentation
- Reliability testing data
- Independent audit records confirming compliance with this requirement
Common Nonconformities
- No data to support probabilities
- Over-reliance on expert opinion
- Not using available databases
- Ignoring uncertainty
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
Probability estimates should be based on objective data where available, with multiple information sources considered. Prioritize quantitative data. Document all sources used. Address uncertainty explicitly. Use conservative estimates when data is limited.
Objective Evidence
- Analysis update procedures
- Revision history
- Update triggers defined
- Change impact assessments
- Post-market updates
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- One-time analysis only
- No update procedures
- Missing revision control
- Ignoring new information
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
Risk analysis is not a one-time activity but must be maintained and updated as the device and knowledge evolve. Updates should occur when design changes, new clinical data emerges, post-market events occur, or regulations change.
Objective Evidence
- Hazard identification procedure
- Structured analysis techniques (FMEA, FTA, HAZOP)
- Checklists and templates used
- Team composition and training
- Multiple identification methods
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Ad hoc identification approach
- Single identification method
- No documented methodology
- Inadequate team diversity
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
Hazard identification must follow a structured, repeatable methodology to ensure consistency and completeness. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Specification documents with tolerances
- Acceptable range definitions
- Statistical process control limits
- Alert and action limits
- Safety margins documentation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Limits not defined for critical characteristics
- Limits without scientific basis
- No safety margins
- Missing statistical considerations
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
For quantitative characteristics, specific acceptable limits must be defined based on safety requirements. Limits should be based on scientific evidence, standards, and clinical requirements.
Objective Evidence
- Lifecycle phase analysis
- Transport/storage hazard analysis
- Installation hazard assessment
- Maintenance procedure review
- Disposal hazard evaluation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Focus only on use phase
- Missing disposal hazards
- No transport considerations
- Inadequate maintenance analysis
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
Hazard identification must systematically address every lifecycle phase, not just the use phase. Create lifecycle phase checklist. Analyze each phase systematically. Consider phase-specific standards.
Objective Evidence
- Clinical consequence descriptions
- Severity scale definitions
- Medical literature on injuries
- Professional medical opinions
- Regulatory guidance on severity
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Underestimating severity
- Not considering worst credible case
- Inconsistent severity scales
- No medical input on consequences
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
Severity must be estimated based on the worst credible consequence that could result from the hazardous situation. Define clear severity categories with medical input. Consider worst credible outcomes. Be consistent across similar harms.
Objective Evidence
- Risk estimation worksheets
- Probability and severity assignments
- Risk matrices or calculations
- Consequences lists for unknown probabilities
- Estimation rationale documentation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Missing risk estimates
- No approach for unknown probabilities
- Inconsistent estimation methods
- Inadequate estimation rationale
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
Every hazardous situation must have an associated risk estimate, even when probability cannot be determined. In such cases, list all possible consequences. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Intended use document in risk file
- Misuse analysis in risk file
- Traceability to hazard identification
- Use in risk analysis worksheets
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
Common Nonconformities
- Not including in risk file
- No link to hazard identification
- Static documents not used
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
- Activities performed without documented procedure or work instruction
Auditor Tips
Both intended use and misuse documentation must be included in the risk management file and actively used in the hazard identification process. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Characteristics list in risk file
- Specification documents referenced
- Limit justification documentation
- Updates and revisions tracked
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
Common Nonconformities
- Characteristics not in risk file
- Limits documented elsewhere only
- No revision control
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
- Activities performed without documented procedure or work instruction
Auditor Tips
All identified characteristics and defined limits must be formally documented and maintained in the risk management file with clear traceability. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Master hazard list
- Hazardous situation register
- Supporting analysis documentation
- Team review records
- Approval signatures
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Incomplete documentation
- Poor traceability
- Missing approval records
- No revision control
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
All identified hazards and hazardous situations must be documented comprehensively with clear traceability. Maintain comprehensive hazard log with unique identifiers. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Risk estimation procedure
- Standardized worksheets
- Training records on method
- Quality review of estimates
- Consistency checks
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Ad hoc estimation approaches
- Inconsistent methods used
- Insufficient detail for high risks
- No quality checks
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
A consistent, systematic method must be applied to all risk estimations, with appropriate detail based on device complexity and risk level. Document standard estimation method. Train all participants. Implement peer review. Scale detail to risk level.
Objective Evidence
- Risk analysis report
- Supporting data and references
- Meeting minutes and decisions
- Review and approval records
- Traceability to requirements
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Incomplete documentation
- Missing supporting data
- No approval records
- Poor traceability
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
All risk analysis activities, methods, data, and results must be documented and maintained in the risk management file. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Risk estimation worksheets
- Supporting data and references
- Method documentation
- Review and approval records
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
Common Nonconformities
- Missing supporting data
- No method documentation
- Incomplete records
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
- Activities performed without documented procedure or work instruction
Auditor Tips
All risk estimations including probability, severity, methods used, and supporting data must be documented. Create comprehensive estimation records. Include all supporting information. Maintain clear audit trail.
Objective Evidence
- Risk evaluation worksheets
- Risk acceptability decisions
- Application of criteria from plan
- Risk matrices with acceptability zones
- Evaluation meeting minutes
- Decision rationale documentation
- Independent audit records confirming compliance with this requirement
Common Nonconformities
- Inconsistent application of criteria
- Missing evaluation for some risks
- Criteria not from approved plan
- No documented rationale
- Subjective decisions without criteria
- No evidence of periodic review or update of this activity
Auditor Tips
Every identified risk must be evaluated against pre-defined acceptability criteria to determine if risk reduction is needed. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- List of acceptable risks
- Justification for acceptability
- Documentation in risk management file
- Communication to stakeholders
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
Common Nonconformities
- Not documenting acceptable risks
- Missing justification
- No disclosure consideration
- Acceptable risks not tracked
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
Risks that meet acceptability criteria do not require risk control measures but still need to be documented and communicated. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- List of unacceptable risks
- Risk control requirements
- Action plans for reduction
- Priority assignments
- Resource allocation
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Some unacceptable risks not addressed
- Delayed risk control implementation
- No clear prioritization
- Inadequate resource allocation
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
Any risk that does not meet acceptability criteria must proceed to risk control to reduce the risk to acceptable levels. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Risk disclosure matrix
- Disclosure decisions and rationale
- Information for safety documents
- Labeling and IFU content
- Regulatory submission disclosures
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- No systematic disclosure process
- Missing non-disclosure justification
- Inconsistent disclosure decisions
- Not aligned with regulations
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
A deliberate decision process must determine which residual risks are disclosed to users, with documented rationale for non-disclosure decisions. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Risk evaluation reports
- Decision records
- Meeting minutes
- Approval signatures
- Traceability to criteria
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
Common Nonconformities
- Incomplete documentation
- Missing decision rationale
- No approval records
- Poor traceability
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
All risk evaluation activities, decisions, and rationales must be documented in the risk management file. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Objective Evidence
- Consistent application evidence
- Review of evaluation consistency
- Training on criteria application
- Quality checks on evaluations
- Independent audit records confirming compliance with this requirement
- Cross-functional team review and sign-off documentation
- Periodic effectiveness assessment reports for this activity
Common Nonconformities
- Inconsistent criteria application
- Subjective interpretations
- Criteria drift over time
- Different evaluators using different approaches
- No evidence of periodic review or update of this activity
- Documentation incomplete or missing key elements required by the standard
Auditor Tips
The same criteria must be applied uniformly to all risks, ensuring objectivity and consistency in evaluation. This requirement must be addressed through documented procedures with clear responsibilities, objective acceptance criteria, and evidence maintained in the risk management file. Compliance verification should confirm both the existence and effectiveness of the documented approach.
Get the Full 137-Item Checklist
Download the complete ISO 14971:2019 audit checklist with all 137 expert items, objective evidence requirements, common nonconformities, auditor tips, and a professional scoring rubric.
This checklist is an educational resource for audit preparation. It does not constitute professional regulatory advice. Always consult qualified auditors for certification decisions.