ISO 14971 deliverable
What the risk management file is
ISO 14971:2019 does not ask for a risk analysis. It asks for a risk management process, applied across the whole product lifecycle, with a file that provides traceability from every identified hazard through to the verification that the control measure works and the evidence that the residual risk is acceptable.
Under EU MDR the file is not optional and it is not peripheral. GSPR 1 to 9 in Annex I are written in risk management language, and a notified body reads the risk file as the backbone that the rest of the technical documentation hangs from.
What the file contains
- Risk management plan — scope, responsibilities, risk acceptability criteria, and how the criteria were derived. The criteria come first, because risks cannot be judged acceptable against a standard that was written after the judgement.
- Intended use and reasonably foreseeable misuse, and identification of characteristics related to safety.
- Hazard identification covering normal use and fault conditions, with sequences of events leading to hazardous situations, not just a list of hazards.
- Risk estimation and evaluation for each hazardous situation, before and after controls.
- Risk control measures in the order the standard requires: inherently safe design first, then protective measures, then information for safety. Information for safety is the last resort, not the first reach.
- Verification of implementation and effectiveness of each control — two separate verifications, and the second is the one most often missing.
- Risks arising from control measures, which is where new hazards are introduced and frequently not reassessed.
- Overall residual risk evaluation and the benefit-risk analysis, aligned with the CER.
- Production and post-production information plan, connecting the file to PMS, PMCF and the PSUR.
Where risk files fail review
- A spreadsheet instead of a process. A populated FMEA is not a risk management file. The plan, the acceptability criteria, the effectiveness verification and the post-production loop are what make it one.
- Information for safety used to control design risks. A warning in the IFU does not reduce a risk that a design change could eliminate, and ISO 14971 does not permit that ordering.
- Acceptability criteria reverse-engineered. Criteria that happen to place every residual risk just inside the acceptable band invite scrutiny.
- No effectiveness verification. Implementation is documented; whether the control actually reduced the risk is not.
- Static after launch. Complaints and field data arrive and the file is never revisited, so the residual risk estimates no longer match reality.
- Disconnected from usability. IEC 62366-1 use-related hazards belong in the same file, not in a parallel document nobody reconciles.
How the work runs
For a new device we set up the plan and criteria first, then facilitate hazard identification with your design and clinical people, because the engineers know the failure modes and an external consultant writing alone will miss them. For an existing file we run a gap assessment against ISO 14971:2019 and Annex I of the MDR, and rebuild what does not hold — most often the acceptability criteria, the effectiveness verification and the post-production feedback loop.
Frequently asked questions
Is ISO 14971:2019 harmonised under the MDR?
EN ISO 14971:2019+A11:2021 carries the European annexes that map the standard to the MDR and IVDR requirements. Working to the EN version with the A11 amendment is what a notified body expects.
Is an FMEA enough?
No. FMEA is a useful technique for failure modes, but it starts from components and works up. ISO 14971 requires you to start from hazards and hazardous situations, which an FMEA alone will not cover, particularly for use-related and software hazards.
Can risk be reduced by a warning in the instructions?
Only after design and protective measures have been considered and shown to be impracticable. Information for safety is third in the required order.
Does the file need updating after launch?
Yes. The production and post-production activities in Clause 10 make it a living file, updated as complaints, incidents and PMCF findings arrive.
How does this relate to 21 CFR Part 820?
FDA expects risk management within design controls, and ISO 14971 is the recognised route. One well-built file serves both the EU and the US FDA 510(k) submission.
The risk management file is maintained inside your ISO 13485 quality system and underpins CE marking.
