Medical Device Risk Management: ISO 14971 Explained

Photo of author
Written By Chris Ekai

On April 9, 2024, a federal court in the Western District of Pennsylvania entered a consent decree against Philips Respironics, three years after the company began recalling roughly 15 million ventilators, CPAP, and BiPAP machines over degrading sound-abatement foam. Twenty days later, Philips agreed to pay $1.1 billion to settle the related personal injury claims.

Strip away the litigation and it reads as a medical device risk management failure: a known material weakness that never travelled from complaint data back into risk analysis and design change. FDA logged more than 116,000 medical device reports tied to the recalled machines between April 2021 and October 2023, including 561 reported deaths.

Medical Device Risk Management: Key Takeaways
FDA’s QMSR took effect on February 2, 2026, incorporating ISO 13485:2016 into 21 CFR Part 820, which makes ISO 14971 risk management the working baseline for every US device manufacturer.
ISO 14971:2019 runs a six-stage loop: risk analysis, risk evaluation, risk control, overall residual risk evaluation, risk management review, and production and post-production activities.
The risk management file is the single evidence trail auditors pull first; it must trace every hazard to an estimated risk, a control, a verification record, and a post-market signal.
FMEA is a bottom-up analysis tool inside the system, never the system itself; a file built only on FMEA misses use error, systematic software faults, and overall benefit-risk.
Philips Respironics shows the cost of a broken loop: 116,000 medical device reports and 561 reported deaths logged by FDA, an April 2024 consent decree, and a $1.1 billion settlement.
Risk control options carry a mandatory order under Clause 7.1: inherently safe design first, protective measures second, information for safety last, never the reverse.

The stakes rose again on February 2, 2026, when FDA’s Quality Management System Regulation took effect and folded ISO 13485:2016 into 21 CFR Part 820 by incorporation. Every US manufacturer now defends its device risk management decisions against a harmonized standard FDA inspectors can quote clause by clause.

Why Medical Device Risk Management Changed on February 2, 2026

The QMSR replaced the 1996 Quality System Regulation and, per FDA’s own FAQ, made ISO 13485:2016 the core of US device quality requirements. Because ISO 13485 leans on ISO 14971 for risk, the standard moved from recognized-but-optional to the practical audit baseline.

AAMI, which co-administers the US ISO 13485 adoption, called the rule a global harmonization milestone. The practical effect for a device risk management program is broader scope. Risk-based thinking now formally reaches purchasing, supplier controls, training, and servicing rather than sitting inside design controls alone.

Manufacturers that already hold ISO 13485 certificates for EU or Canadian markets gain little breathing room. FDA kept supplemental records requirements, and inspectors arrive with recall history in hand, the way a quality risk management program should anticipate. The two-year transition that began in February 2024 is over.

Dimension QSR before Feb 2026 QMSR from Feb 2026
Core text 21 CFR 820 standalone, 1996 wording ISO 13485:2016 incorporated by reference plus FDA supplements
Risk anchor Risk analysis named once, in design validation Risk-based approach threaded through the whole QMS via ISO 14971
Scope of risk work Design controls centric Design, purchasing, supplier, production, servicing, post-market
Audit reference QSIT inspection guide Harmonized clauses FDA can cite against the risk management file
Global alignment US-specific Matches EU MDR, Health Canada, and MDSAP expectations

The Regulatory Timeline Behind Medical Device Risk Management in 2026

Medical Device Risk Management: ISO 14971 Explained

Figure 1. Five dates that moved medical device risk management from guidance to enforced baseline.

The Six Stages of the ISO 14971 Medical Device Risk Management Process

ISO 14971:2019, now in its third edition with the 2021 European amendment, defines risk as the combination of probability of harm and its severity. The device risk management process runs as a loop across the product lifecycle, not as a design-phase gate to clear once.

Its companion guidance, ISO/TR 24971:2020, carries the worked examples most teams borrow. The habit that separates strong files from weak ones is disciplined hazard identification up front: intended use, reasonably foreseeable misuse, and hazardous situations mapped before anyone scores a probability.

Stage Clause What an auditor expects to see
Risk analysis 5 Intended use, misuse, hazard list, and estimated risks with the estimation method named
Risk evaluation 6 Each risk compared against acceptability criteria fixed in the risk management plan
Risk control 7 Option order applied: safe design, protective measures, then information for safety
Overall residual risk 8 A whole-device benefit-risk judgement using the method the plan committed to
Risk management review 9 A signed risk management report confirming the plan was executed before release
Production and post-production 10 Complaints, MDRs, and field data feeding back into the file on a defined cycle

Setting Risk Acceptability Criteria in Medical Device Risk Management

Acceptability criteria belong in the risk management plan before analysis starts, which is where a documented risk assessment methodology earns its place. Teams that invent thresholds per project drift toward whatever makes the current design pass. The matrix below shows the three-zone structure most files use.

Probability estimation works best decomposed into P1, the probability of a hazardous situation arising, and P2, the probability that the situation leads to harm. Blending qualitative and quantitative estimates is acceptable under the standard so long as the plan says which applies where.

Medical Device Risk Management: ISO 14971 Explained

Figure 2. A three-zone acceptability matrix; ISO 14971 requires the zones be fixed in the plan before scoring begins.

Building the Medical Device Risk Management File

The risk management file is not one document but a traceable set: plan, analyses, evaluations, control verifications, the overall residual risk conclusion, and the report. Clause 4.5 demands traceability for each identified hazard through every stage, the same discipline a well-kept risk register enforces in enterprise programs.

Format is free; traceability is not. A notified body reviewer or FDA investigator will pick one hazard and walk it end to end. If the thread breaks between the FMEA line item and the verification record, the file fails the pull test regardless of its page count.

File record Produced during The question it must answer
Risk management plan Project start What scope, criteria, and review cadence did you commit to?
Hazard analysis Concept and design Which hazardous situations can this device create, for whom?
Risk estimates Design How likely, how severe, and by what estimation method?
Control verification Verification and validation Did each control work, and did it introduce new risks?
Overall residual risk evaluation Pre-release Is the whole device acceptable against its clinical benefit?
Risk management report Release Who reviewed the plan’s execution and signed the conclusion?
Post-production records Lifetime What field data arrived, and what did it change in the file?

What Auditors Pull From the Medical Device Risk Management File First

Inspectors start where the money is: the overall residual risk conclusion and the post-market loop. Watch complaint trend data before every file review; a file whose last update predates the newest complaint cluster is the fastest nonconformity an investigator can write. Review cadence guidance applies here with force.

Software-heavy devices add a second and sharper pull point. Expect questions that trace a software lifecycle risk through IEC 62304 classification into the file, and expect the same for any software development risk management plan a supplier maintains on your behalf.

FMEA and Medical Device Risk Management: Tool, Not System

FMEA remains the most used analysis technique in device work, and the most misused. It is a bottom-up tool that starts from component or process failure modes, while ISO 14971 starts top-down from harm to people. A device risk management file built only on FMEA has a structural blind spot.

The gap shows in three places: use error that occurs with no component failing, systematic software faults that RPN scoring handles badly, and the whole-device benefit-risk judgement FMEA never reaches. The hazard versus risk distinction sits underneath all three of those blind spots.

Dimension FMEA ISO 14971 process
Direction Bottom-up from failure modes Top-down from harm and hazardous situations
Trigger Component, function, or process fault Any cause, including use error and normal use
Metric RPN or criticality ranking Probability of harm combined with severity
Output Ranked failure list with actions Acceptability decision plus benefit-risk conclusion
Lifecycle reach Design and process snapshots Concept through post-production feedback
Regulatory status Supporting technique Recognized consensus standard behind QMSR and EU MDR

Used inside the system, FMEA earns real value feeding Clause 5 risk analysis, the way a process validation risk approach feeds manufacturing controls. The practical rule: every FMEA line that can reach a patient must map to a hazardous situation in the file, and orphan lines get closed or escalated.

FDA Expectations for Medical Device Risk Management Beyond the Standard

The Philips docket shows how FDA now reads risk files against field data. Reports analyzed in CHEST’s 2024 review of the decree trace the foam degradation signal back years before the June 2021 recall. The reporting curve below is the picture inspectors carry into every post-market discussion.

Medical Device Risk Management: ISO 14971 Explained

Figure 3. FDA’s cumulative MDR counts for the Philips recall; each bar is a missed chance to close the loop earlier.

Recall causes are shifting toward code. Sedgwick’s recall index counted 168 software-cited device recalls in Q2 2025, the highest quarterly total in six years, up 25.4% on the prior quarter. Trade coverage of the docket, from MedTech Dive to Fierce Biotech, tracked the same drift.

Cybersecurity now rides inside device risk management rather than beside it. Section 524B of the FD&C Act and FDA’s 2023 premarket cybersecurity guidance expect threat modelling that meshes with the 14971 file, which is where a mature cybersecurity risk management practice and an NIST-style assessment plug in.

Post-Market Medical Device Risk Management: Closing the Clause 10 Loop

Clause 10 obliges manufacturers to collect production and post-production information and push it back through the process. Healio reported in February 2024 that death reports tied to the Philips machines had passed 500, a figure that grew while the file sat still. The loop, not the binder, is the deliverable.

A working loop defines its inputs: complaints, service records, MAUDE signals, literature, and supplier changes routed through third-party risk controls. It also defines triggers, the thresholds at which a signal reopens risk analysis rather than closing as an isolated complaint.

Under the EU’s Medical Device Regulation 2017/745, the same loop feeds post-market surveillance plans and periodic safety update reports, with benefit-risk reassessed as far as possible rather than as low as reasonably practicable. Running one loop that satisfies both regimes is cheaper than running two.

Frequently Asked Questions About Medical Device Risk Management

What is medical device risk management under ISO 14971?

It is the lifecycle process of identifying hazards, estimating and evaluating risks, controlling them, and monitoring the controls for a medical device. ISO 14971:2019 structures it in six stages from risk analysis through post-production feedback, documented in a risk management file that regulators audit.

What goes into a medical device risk management file?

The file holds the risk management plan, hazard analyses, risk estimates and evaluations, risk control verification records, the overall residual risk evaluation, the signed risk management report, and post-production records. Clause 4.5 requires traceability from every hazard to its final disposition across those records.

Is FMEA enough for medical device risk management?

No. FMEA is a bottom-up analysis technique that feeds the process but cannot replace it. It misses use error without component failure, handles systematic software faults poorly, and never reaches the whole-device benefit-risk conclusion that ISO 14971 Clauses 7 and 8 demand.

How does the FDA QMSR change medical device risk management in 2026?

Since February 2, 2026, 21 CFR Part 820 incorporates ISO 13485:2016 by reference, and ISO 13485 relies on ISO 14971 for risk. US inspections now test risk-based thinking across design, purchasing, production, and servicing instead of design controls alone, with harmonized clauses cited directly.

How often should a medical device risk management file be updated?

On the cadence the risk management plan commits to, and immediately when a post-market signal crosses a defined trigger. In practice, high-volume or software-driven devices warrant quarterly reviews of complaint and MDR trends, with the overall residual risk conclusion revisited at least annually.

Who owns medical device risk management inside a manufacturer?

Top management owns the policy and acceptability criteria under Clause 4.2, a named cross-functional team executes the process, and quality typically curates the file. Design, clinical, software, and post-market surveillance each feed their stage; ownership fails when the file becomes one department’s archive.

Medical Device Risk Management Pitfalls and Remedies

Pitfall Root cause Remedy
File is a pile of FMEAs Tool mistaken for the system Map every FMEA line to a hazardous situation; add use-error and benefit-risk records
Acceptability criteria set per project No corporate risk policy Fix criteria in the plan from a top-management policy before analysis starts
Controls stop at warnings Option order applied backwards Enforce Clause 7.1: design first, protective measures second, labelling last
Post-market data never reopens the file Clause 10 loop unbuilt Define signal triggers that force risk analysis to reopen, then audit the loop
Single probability number hides optimism P1 and P2 conflated Decompose into P1 and P2 and state the estimation basis for each
File frozen at design transfer Risk seen as a premarket gate Schedule lifecycle reviews and tie them to complaint and MDR trend reports

Where Medical Device Risk Management Heads Through 2027

Watch the software curve first. With 168 software-cited recalls in a single quarter of 2025, per Sedgwick, code has become the dominant failure surface, and risk files that treat software as one hazard row among fifty will keep missing it. IEC 62304 alignment moves from nice-to-have to survival skill.

AI-enabled devices sharpen the same problem. FDA’s public list of authorized AI-enabled devices passed 1,000 entries in 2024, and adaptive algorithms stress the assumption that risk estimates hold constant post-market. Predetermined change control plans effectively drag Clause 10 monitoring into the approval itself.

Expect the first QMSR-era inspection findings to publish through 2026 and 2027, giving the industry its new case law. Manufacturers selling into Europe carry the parallel EU MDR clock, where legacy device certificates run out on staggered dates through 2027 and 2028 under Regulation 2023/607.

The through-line is convergence. QMSR, EU MDR, and MDSAP audits increasingly read the same file, so a single, current, traceable risk management lifecycle beats parallel paper regimes on cost and on inspection outcomes. Teams that mitigate risk once and evidence it everywhere win the decade.

Infographic: The ISO 14971 Medical Device Risk Management Process

Medical Device Risk Management: ISO 14971 Explained

Figure 4. The six-stage ISO 14971 loop that a compliant medical device risk management file must evidence end to end.

 

Strengthen Medical Device Risk Management With Risk Publishing

A device quality director staring down a first QMSR inspection needs the file audit-ready, not perfect. We pressure-test risk management files against ISO 14971 and the QMSR clause map, then hand back a gap list ranked by inspection exposure. Start with our services or contact us and bring the complaint trend with you.