Sedgwick’s US Recall Index counted 858 million defective units recalled in 2025, a 26% jump from 681 million the year before, spread across 3,295 separate recalls. The Consumer Product Safety Commission set its own record pace, logging 376 recalls and safety warnings before October.

Every one of those recalls is a risk assessment of products that failed somewhere: in design, in production, in a supplier’s file, or in the decision to ship anyway. The defense never changes, whichever door the failure used. Score failures early, map regulators to deadlines, and keep the file open across the lifecycle.

Six Takeaways on the Risk Assessment of Products
Sedgwick counted 3,295 US recalls and 858 million defective units in 2025, with units up 26% in a single year across five regulated sectors.
The CPSC logged a record 376 recalls and warnings before October 2025 and expects defect reports within 24 hours of knowledge.
The EU GPSR, applying since December 13, 2024, demands an Article 9 risk analysis, a ten-year technical file, and a named EU responsible person.
Match method to product: FMEA for hardware, ISO 14971 for devices, HACCP for food, ISO 12100 for machinery, fault trees for incidents.
Run the assessment at every lifecycle stage; supplier substitutions and complaint trends reopen the file, never just launch.
Score foreseeable misuse, validate detection claims, and route complaint data into monthly reviews to stay off next year’s index.

The rules tightened while the numbers climbed. The EU’s General Product Safety Regulation began applying on December 13, 2024, demanding a documented internal risk analysis and a ten-year technical file from anyone selling into Europe, including US brands shipping through marketplaces.

Why the Risk Assessment of Products Just Got Harder

Recall volume is not the alarming part; unit counts are. Sedgwick’s full-year data shows recall events up modestly, from 3,232 to 3,295, while affected units jumped 26%, meaning each failure now ships farther and multiplies faster before anyone catches it.

The Recall Math Behind Every Risk Assessment of Products

Risk Assessment of Products: From FMEA Scores to Recall Duties in 2026

Figure 1. Events rose 2%; defective units rose 26%. Source: Sedgwick US Recall Index, 2025.

Sector records fell across the board. Consumer products logged 414 recalls, the highest in more than a decade, FDA food recalls hit 517, a nine-year high, and USDA food recalls rose 20%, so the pressure lands on toys and toasters as much as tablets.

A risk assessment of products, then, is the discipline of catching those failures while they are still drawings and purchase orders. The general method in our guide to conducting a risk assessment applies, and this article adds the product-specific scoring, regulators, and lifecycle stages.

The Agencies Waiting on Your Risk Assessment of Products

Five US agencies divide the product world between them, and each expects assessment evidence in its own dialect. The CPSC polices roughly 15,000 consumer product types and expects firms to report defects within 24 hours of learning a product could create substantial hazard.

Authority Products covered What your file must show
CPSC Roughly 15,000 consumer product types 24-hour defect reporting, corrective action plans
FDA Food, drugs, medical devices, cosmetics HACCP or HARPC files; ISO 14971 device risk files
NHTSA Vehicles and motor vehicle equipment Defect investigations and recall remedy plans
USDA FSIS Meat, poultry, and egg products HACCP plans and tested recall procedures
EPA Chemical substances under TSCA Risk evaluations for regulated chemicals
EU: GPSR, ECHA, Safety Gate Consumer goods sold into the EU Article 9 risk analysis, ten-year technical file, responsible person

Europe applies its own rubric to the file. The GPSR’s Article 9 internal risk analysis is mandatory before placing product on the EU market, the trade.gov guidance walks US exporters through the responsible-person rule, and ECHA layers chemical duties on top for regulated substances.

Recalled EU products surface publicly on Safety Gate, the EU rapid alert system, within days, and a single listing follows a brand across every member state. Treat the technical file as the exhibit an EU inspector reads first, because that is how the regulation positions it.

Methods That Power a Risk Assessment of Products

Agencies set the deadlines; methods produce the evidence. FMEA remains the workhorse: score each failure mode for severity, occurrence, and detection, multiply into a risk priority number or map to an action priority, and attack the worst cells first, before tooling money gets spent. The AIAG-VDA handbook swapped raw RPN math for action priority tables back in 2019.

FMEA Scoring Inside the Risk Assessment of Products

Risk Assessment of Products: From FMEA Scores to Recall Duties in 2026

Figure 2. Three scores multiply into the priority that ranks the fix list. Sources: ASQ; AIAG-VDA FMEA handbook.

Method Where it fits Output that lands in the file
Design and process FMEA Hardware, automotive, electronics Scored failure modes with action priorities
ISO 14971 Medical devices Risk management file tied to design controls
HACCP and HARPC Food and beverage Critical control points with monitoring limits
ISO 12100 Machinery Task-based hazard analysis and safeguarding plan
Fault tree analysis Complex systems and incident follow-up Root-cause chains with probability estimates
NUDD screening New, unique, difficult, different features Early flags before DFMEA effort is committed

Match the method to the product, and borrow across sectors shamelessly. Our injection molding risk assessment shows FMEA scoring in action, the NUDD risk assessment screen catches novelty risk earlier, and the HACCP risk assessment matrix runs the food playbook.

Devices and machinery bring their own texts. ISO 14971:2019 governs medical device risk management with FDA’s blessing, ISO 12100 anchors machinery safety, and both expect the qualitative and quantitative risk assessment blend rather than a single scoring pass done once at launch.

The Risk Assessment of Products Across the Lifecycle

Methods only bite when they run at every stage, because hazards enter the product at different doors. A design flaw, a process drift, a substituted component, and a counterfeit part all need different questions asked at different moments in the build.

Lifecycle Stages of the Risk Assessment of Products

Risk Assessment of Products: From FMEA Scores to Recall Duties in 2026

Figure 3. Five checkpoints, one continuous file. Each stage can reopen every earlier score.

Stage Assessment focus Evidence produced
Design DFMEA, foreseeable misuse, standards mapping Scored design file and test plan
Production PFMEA, process validation, data integrity Control plans and validation records
Supply chain Supplier and component risk, substitutions Supplier scores, incoming inspection rules
Distribution Packaging, labeling, warnings, transport Label reviews, drop and transit tests
Post-market Complaints, incident triage, reporting duties Trend reports and corrective actions

Suppliers get a dedicated row because they quietly redesign your product one substitution at a time. Our supplier performance risk management guide and the critical supplier identification and tiering method keep component risk scored, and GMP risk assessment logic covers contract manufacturers.

Pharma shows what stage-linked assessment looks like at full depth. Nitrosamine work runs through the nitrosamine risk assessment checklist, and process validation risk approaches plus data integrity risk assessment keep the manufacturing evidence continuous from batch one to expiry, the way FDA reviewers expect to read it.

Post-Market Duties in the Risk Assessment of Products

Shipping does not close the file; it changes who reads it. Complaint trends, warranty claims, and injury reports feed back into the assessment, and US law converts what you learn into deadlines, starting with the CPSC’s 24-hour reporting clock for substantial hazards and NHTSA’s defect procedures for anything with wheels. Miss the clock and penalties follow.

Recall Records the Risk Assessment of Products Must Answer

Risk Assessment of Products: From FMEA Scores to Recall Duties in 2026

Figure 4. Three records set in one year. Sources: Sedgwick US Recall Index; CPSC, September 2025.

Signal Duty it triggers Deadline discipline
Injury or death report CPSC Section 15(b) report Within 24 hours of knowledge
Complaint trend crossing a limit Internal investigation and CAPA Per your quality system clock
Failed retention or audit sample Production hold and containment Before the next shipment leaves
Regulator inquiry Full technical file production GPSR file retained ten years
Vehicle defect pattern NHTSA defect report and remedy plan Per NHTSA defect procedures
Recall decision Corrective action plan, effectiveness checks Until effectiveness is proven

Manufacturing KRIs make the feedback loop visible before regulators do it for you. Complaint rates, first-pass yield, and supplier deviation counts from our manufacturing KRI examples, plus the food and beverage KRI set, give the assessment its post-market pulse between formal reviews.

Foreign material remains the classic post-market humiliation, findable in advance with the foreign material risk assessment and honest sampling. Quality risk management, run as our guide to quality risk management frames it, ties every one of these signals back to a scored decision.

Risk Assessment of Products FAQs: What Manufacturers Ask Us

What is a risk assessment of products?

A documented evaluation of how a product could harm users across design, production, and use, scored for likelihood and severity, with controls assigned to the unacceptable cells. Our definition of hazard and risk assessment covers the vocabulary, and the methods above supply the scoring machinery.

When is a risk assessment of products legally required?

Whenever a regulated regime touches the product: medical devices under FDA and ISO 14971, food under HACCP rules, machinery under OSHA and ISO 12100, and any consumer good sold into the EU after December 13, 2024 under the GPSR. For everything else, negligence law makes it required in practice.

Which method fits a risk assessment of products best?

FMEA for engineered hardware, ISO 14971 for devices, HACCP for food, ISO 12100 for machinery, and fault trees when a failure has already happened and needs a root cause. Small catalogs can start with our risk assessment templates and add method depth where volume justifies it.

How does the GPSR change the risk assessment of products for US sellers?

Three ways: a mandatory Article 9 internal risk analysis before EU sale, a technical file retained for ten years, and a named responsible person inside the EU. Marketplaces carry duties too, so drop-shipping through a platform no longer shields a US brand from the paperwork.

How often should a risk assessment of products be repeated?

On every design change, supplier change, process move, or complaint trend, and at a fixed interval besides; our guidance on how often risk assessments should be conducted defends the cadence to auditors. Recalls in your category are a free trigger most firms ignore.

Who should own the risk assessment of products?

Engineering owns design scores, quality owns process and post-market signals, and one named owner signs the whole file so accountability survives reorganizations. Consultants can run the workshops, but the sign-off has to sit with someone who can stop a shipment.

Risk Assessment of Products Failures That End in Recalls

Recall root causes repeat so reliably that Sedgwick’s quarterly index reads like a syllabus. The six failures below cover most of the entries we see, and each row names the correction that would have kept the product off the list.

Failure How it reaches the market Correction
Foreseeable misuse never scored Assessment covers intended use only Score the misuse scenarios the GPSR now demands
Supplier substitution unreviewed Component swap skips the change process Re-run affected FMEA lines on every substitution
Detection scores inflated Teams assume tests catch what they never exercise Validate detection claims against actual test coverage
Warnings doing design work Labels patch hazards engineering should remove Apply the hierarchy: design out, guard, then warn
Complaint data siloed Service sees trends the risk file never receives Route complaint codes into assessment reviews monthly
One assessment for every market US file assumed to satisfy EU duties Map the file to GPSR Article 9 before the first EU sale

Emerging Pressures on the Risk Assessment of Products: 2026-2028

GPSR enforcement moves from grace period to case law next. National authorities spent 2025 staffing up, Safety Gate listings keep climbing, and the first serious penalties against non-EU sellers will define how literally the ten-year file requirement gets read in practice.

Software is becoming a product hazard class of its own. Connected devices fail through updates as often as through hinges now, the GPSR explicitly pulls software into safety scope, and assessments that stop at the physical bill of materials are already obsolete.

Chemical scrutiny keeps widening under TSCA and state law. EPA risk evaluations and state-level PFAS restrictions are converging on consumer products, and the material declarations suppliers provide will have to enter the risk file as scored inputs rather than attachments.

The founding arithmetic survives every trend above: an hour of scoring at the drawing stage still beats a month of recall management. The 858 million units recalled in 2025 are the argument, and next year’s index grades who heard it.

Stress-Test Your Risk Assessment of Products With Risk Publishing

A file that has never been challenged fails its first hostile reading, usually in front of a regulator. Risk Publishing reviews product risk files against FMEA discipline, GPSR Article 9, and the recall data above; the scope lives on our services page, and the contact form reaches us directly.

Index