how-to
ISO 14971 Risk Management Process: 7 Steps
Table of Contents
- Overview: The ISO 14971 Risk Management Process
- Step 1: Risk Management Planning and Plan Contents
- Step 2: Medical Device Hazard Analysis and Identification
- Step 3: Risk Estimation: Severity and Probability of Occurrence
- Step 4: Risk Evaluation Against Acceptability Criteria
- Step 5: ISO 14971 Risk Control Measures and Implementation
- Step 6: Verification and Residual Risk Assessment
- Step 7: Medical Device Risk Management File and Post-Market Monitoring
- Putting It Together: How E & E Medicals and Consulting Helps
- Frequently Asked Questions
Last Updated: October 10, 2026
Overview: The ISO 14971 Risk Management Process
The ISO 14971 risk management process is a structured approach that medical device manufacturers use to identify, evaluate, and control risks throughout a product's lifecycle. This standard defines how to find potential hazards, assess their impact, apply controls, and document everything for regulatory compliance.
The ISO 14971 risk management process is a regulatory requirement across FDA, EU MDR, and most global markets. Without it, your product won't pass inspection and submissions will be rejected.
The standard breaks into seven distinct steps, each building on the previous one. Skip a step and your risk management file becomes indefensible during an audit.
The process starts with planning, moves through hazard identification and risk assessment, then shifts to control implementation and verification, and ends with post-market monitoring. The entire cycle must be traceable and defensible.

Step 1: Risk Management Planning and Plan Contents
Your risk management plan defines the scope, assigns responsibility, and sets criteria for acceptable risk. Without it, your team will make inconsistent decisions and regulators will question your logic.
The plan must define product scope, establish roles and responsibilities (who approves decisions, documents findings, owns verification), and set risk acceptability criteria upfront to prevent later disputes.
Your plan must specify risk analysis methods (FMEA, fault tree analysis, or equivalent), identify lifecycle phases to analyze, and state how you'll handle post-market data and plan updates.
Defining Intended Use and Reasonably Foreseeable Misuse
Intended use defines what the device is supposed to do and who uses it. Reasonably foreseeable misuse describes how users might use it incorrectly in ways you should have anticipated. Both are essential because they shape which hazards you need to address.
Intended use must specify the clinical application, patient population, user type, environment, duration and frequency of use, and any contraindications or limitations.
Reasonably foreseeable misuse describes how users might use the device incorrectly in ways you should anticipate, such as off-label use, application to unintended patient populations, or use in unsuitable environments.
Document both explicitly in your risk management plan. This documentation becomes your legal and regulatory defense. When an auditor asks why you didn't address a particular hazard, you'll point to your intended use statement and explain why that hazard falls outside your scope.
Establishing Roles and Responsibilities
Assign specific roles: someone owns the overall process, someone approves risk control decisions, and someone verifies controls work.
Typical roles include risk management team lead, design engineers, quality manager, regulatory affairs, and clinical or field experts.
Document these roles in your plan. Clear role definitions prevent confusion and show regulators that qualified people made deliberate decisions.
Step 2: Medical Device Hazard Analysis and Identification
Hazard identification finds every potential problem. Miss a hazard here and you'll miss it throughout the entire risk management process.
A hazard is a potential source of harm; risk combines the hazard with the probability and severity of harm. For example, sharp edges (hazard) plus likelihood of contact plus severity of cut (risk).
Use systematic methods like FMEA or brainstorming with cross-functional teams. Structure ensures you don't miss categories; team diversity catches hazards individual experts would overlook.
Identifying Hazardous Situations and Sequences of Events
A hazardous situation occurs when a hazard could lead to harm. A sequence of events describes the chain linking hazard to harm, showing how the hazard reaches the patient or user.
Example: hazard is "battery overheating," hazardous situation is "device case reaches 65°C," sequence is user leaves device in sunlight → battery temperature rises → case heats up → user receives thermal burn.
Document each sequence explicitly. This documentation shows regulators that you understood the pathway from hazard to harm. It also helps you evaluate whether your controls actually interrupt the sequence at the right point.
Common sequences to consider:
- Manufacturing defects that escape quality control
- User error in setup or operation
- Environmental factors (temperature, humidity, electromagnetic interference)
- Degradation over the device's intended lifetime
- Interaction with other devices or medications
- Failure of a single component
Step 3: Risk Estimation: Severity and Probability of Occurrence
Risk estimation combines severity (how bad the harm could be) and probability (how likely it is to happen) to determine risk level.
Severity categories typically range from negligible (minor injury) to critical (death or permanent disability).
Probability of occurrence estimates how often the hazardous situation will arise. Use historical data from similar devices, expert judgment, or both.
When data are limited, document your assumptions and rationale for probability levels. This transparency shows regulators your decisions were reasoned.
Create a risk matrix that combines severity and probability. A high-severity, high-probability hazard is unacceptable and must be controlled. A low-severity, low-probability hazard might be acceptable as-is. Medium-level risks require evaluation against your acceptability criteria.
Step 4: Risk Evaluation Against Acceptability Criteria
Risk evaluation compares estimated risks against your acceptability criteria. Risks below the threshold are acceptable; those exceeding it require controls.
Acceptability criteria should reflect clinical context. Risks acceptable for life-saving devices may be unacceptable for cosmetic devices, and vice versa.
Document your rationale for each acceptability decision, including threshold justification and how you weighed severity against probability.
Regulators scrutinize arbitrary decisions or overly lenient thresholds. Undocumented criteria are indefensible during audits.
Step 5: ISO 14971 Risk Control Measures and Implementation
Risk control reduces unacceptable risks to acceptable levels through three approaches: inherent safety (design out the hazard), protective measures (add safeguards), or information for safety (warn users).
Inherent safety is preferred: eliminate the hazard through design. For example, round sharp edges rather than adding guards.
When inherent safety isn't possible, add protective measures like mechanical guards, software interlocks, or redundant systems. Information for safety (warnings, instructions) should be your last resort because it depends on user behavior.
Inherent Safety, Protective Measures, and Information for Safety
Inherent safety eliminates hazards through design: using non-toxic materials, designing components to prevent incorrect assembly, limiting electrical current, or using biocompatible materials.
Protective measures add layers of protection: mechanical guards, automatic shutoff systems, redundant monitoring, or fail-safe mechanisms.
Information for safety includes labels, warnings, instructions, and training. It's the weakest control because it relies on users reading and following guidance. Use it when other controls aren't feasible.
Document which control type you chose for each risk and why. Explain how it reduces risk (severity, probability, or both) and show it's effective without introducing new hazards.
Step 6: Verification and Residual Risk Assessment
Verification confirms controls work as intended. Test and document that controls perform in real conditions.
Residual risk is the risk remaining after controls are applied. Ensure it meets your acceptability criteria.
Verification methods vary by control type: test mechanical guards prevent access, software interlocks block unsafe operation, and warning labels are understood.
Document verification results thoroughly, including test protocols, results, and deviations. If a control failed, document what happened and how you fixed it.
After verification, re-evaluate residual risk against your criteria. If unacceptable, implement additional controls and verify again until residual risk is acceptable.
Step 7: Medical Device Risk Management File and Post-Market Monitoring
Your risk management file is the complete record of all risk management activities: plan, hazard analysis, risk estimates, control decisions, verification results, and residual risk assessment. Regulators review this during premarket review and inspections.
Documentation, Traceability, and Lifecycle Management
Traceability means you can trace each hazard from identification through analysis, control, verification, and post-market monitoring. Auditors should follow the chain and understand your logic at each step.
Your risk management file should include the plan, hazard analysis, risk estimation, evaluation decisions, control measures, verification results, residual risk assessment, and post-market surveillance plan.
Organize the file so it's easy to navigate. Use consistent terminology throughout. Cross-reference documents so connections are clear. When regulators ask about a specific hazard, they should be able to find it quickly and trace it through the entire file.
Post-Production Information and Risk Review
Post-market monitoring means you continue to watch for hazards and risks even after the device reaches the market. Collect data on adverse events, complaints, and failures. Analyze this data for patterns that might reveal previously unknown hazards.
If you discover new hazards or if controls prove ineffective in real use, update your risk management file. Document the new findings and any changes to your controls. This demonstrates that you're actively managing risk throughout the product lifecycle.
Schedule periodic risk reviews. Many manufacturers review risk management annually or whenever significant design changes occur. Some review after reaching certain sales milestones. Document when reviews occur and what was changed as a result.
| Phase | Key Activities | Documentation |
|---|---|---|
| Planning | Define scope, set criteria, assign roles | Risk management plan |
| Hazard Analysis | Identify hazards, sequences, hazardous situations | FMEA or equivalent |
| Risk Estimation | Assess severity and probability | Risk matrix, estimates |
| Risk Evaluation | Compare against acceptability criteria | Evaluation decisions |
| Risk Control | Design controls, implement measures | Control specifications |
| Verification | Test controls, assess residual risk | Test protocols, results |
| Post-Market | Monitor adverse events, update file | Surveillance reports |
Putting It Together: How E & E Medicals and Consulting Helps
The ISO 14971 risk management process is demanding, but it's non-negotiable for regulatory success. Many manufacturers struggle because they treat it as a compliance checkbox rather than a genuine safety exercise. That's a mistake.
At E & E Medicals and Consulting, we work with medical device companies to build risk management processes that are both compliant and defensible.
We've helped companies strengthen their Design History Files, improve traceability across risk controls and verification, and prepare for FDA inspections with confidence.
The difference between a weak risk management file and a strong one often comes down to clarity, completeness, and defensibility.
If your team is navigating ISO 14971 for the first time, or if you're strengthening an existing process, we can help.
Key Takeaways:
The ISO 14971 risk management process follows seven sequential steps: planning, hazard identification, risk estimation, risk evaluation, risk control, verification, and post-market monitoring. Each step builds on the previous one and must be thoroughly documented.
Clear planning and acceptability criteria prevent disputes later. Systematic hazard identification catches risks you'd otherwise miss. Thorough verification proves your controls work. Post-market monitoring ensures you catch emerging risks early.
Your risk management file is your regulatory defense. Organize it for traceability so regulators can follow your logic from hazard identification through control verification and post-market evidence.
The FDA's guidance on medical device risk management and ISO 14971:2019 standard requirements provide the regulatory framework. Understanding how your process aligns with these requirements is essential.
Frequently Asked Questions
What are the main steps in the ISO 14971 risk management process?
ISO 14971 defines seven key steps: (1) Risk Management Planning, (2) Hazard Identification, (3) Risk Estimation (severity and probability), (4) Risk Evaluation against acceptability criteria, (5) Risk Control implementation, (6) Verification and residual risk assessment, and (7) Post-market monitoring and risk review. Each step builds on the previous one and requires documented evidence for the medical device risk management file.
What should be included in an ISO 14971 risk management plan?
An ISO 14971 risk management plan must define the device's intended use and reasonably foreseeable misuse, establish roles and responsibilities, outline the risk analysis and evaluation methods, specify risk acceptability criteria, describe risk control strategies, and detail how post-market surveillance will occur. The plan should also identify the quality management system integration points and set timelines for risk review activities throughout the product lifecycle.
How do you identify hazards in medical device risk management?
Hazard identification under ISO 14971 involves systematically examining the device's intended use, foreseeable misuse, and product lifecycle stages to uncover potential hazardous situations. Methods include design review, failure mode analysis, historical data review, and expert consultation. Document each hazard, the sequence of events that could trigger it, and the potential harm. This forms the foundation for risk estimation and control in subsequent steps.
What is residual risk, and why does it matter in ISO 14971?
Residual risk is the risk remaining after risk control measures have been implemented and verified. ISO 14971 requires evaluating whether residual risk is acceptable based on your predefined acceptability criteria and benefit-risk analysis. Even after controls, some risk typically remains; the standard ensures you have documented evidence that this residual risk is justifiable and that overall benefit outweighs harm. This is critical for regulatory submissions and post-market compliance.