ISO 14971 is the international standard that defines a process for applying risk management to medical devices, including in vitro diagnostic (IVD) devices and software as a medical device (SaMD). It specifies how manufacturers identify hazards, estimate and evaluate risks, control them, and monitor risk throughout the product lifecycle.
What is ISO 14971?
ISO 14971 is the recognized standard for medical device risk management, published by the International Organization for Standardization (ISO). The current third edition, ISO 14971:2019, was reviewed and confirmed as current in 2025. It works with ISO/TR 24971, which provides practical guidance for applying the standard.
The standard defines risk as the combination of the probability of harm occurring and its severity. It does not set an acceptable risk level for you. The manufacturer sets that threshold in a risk management policy, then follows the prescribed process to document risk-based decisions. It applies from early design through post-market activities, so the risk picture remains active across the device’s entire life.
Why ISO 14971 matters in medical device development
Regulators expect a risk management system built on ISO 14971. The EU Medical Device Regulation (MDR 2017/745) and IVDR require manufacturers to plan, document, and maintain risk management throughout the lifecycle. EN ISO 14971:2019/A11:2021 adds Annexes ZA and ZB, which map the standard’s clauses to those regulations and support a presumption of conformity. This regulatory context makes the process below essential.
The consequences of weak risk management are concrete. Notified bodies and FDA auditors scrutinize the risk management file, and gaps there can stall a submission or trigger findings. Weakly characterized risks appear later as field failures or recalls, when they cost far more to fix. A disciplined process catches hazards early, when a design change still costs little.
The ISO 14971 risk management process
ISO 14971 defines connected activities, not a one-time checklist. The core stages are:
Risk management planning
Define scope, responsibilities, the risk acceptability policy, and how risk management ties into the design and development plan.
Risk analysis
State the intended use and reasonably foreseeable misuse, identify hazards and hazardous situations, then estimate the associated risks.
Risk evaluation
Compare each estimated risk against the acceptability criteria to decide whether control is needed.
Risk control
Reduce risk by prioritizing inherent safety by design, protective measures, and safety information, such as labeling. Verify each control works and check for new risks it introduces.
Overall residual risk evaluation
Judge total residual risk against the criteria, including a benefit-risk analysis where risk is not acceptable.
Risk management review
Confirm the plan was executed and the risk file is complete before release.
Production and post-production activities
Review production, market, and field data and update the risk file as needed.
All of this evidence resides in the risk management file (RMF), the traceable record auditors request. Support the process with failure modes and effects analysis (FMEA), fault tree analysis (FTA), preliminary hazard analysis (PHA), and HAZOP studies as needed. The standard mandates no single technique; choose the method that fits the hazard.
Common challenges and best practices
The most frequent mistake is treating risk management as paperwork generated near the end of a project. By then, design choices are locked in, and the file reads as a justification rather than a tool that shaped the device. Start the risk file at concept and update it at each design milestone.
A second gap is the confusion between FMEA and a full ISO 14971 analysis. FMEA is failure-driven and bottom-up. It misses hazards that arise without a component failing, such as foreseeable misuse or normal-condition energy hazards. Use FMEA as one input, not the full analysis.
Traceability is where many files break down. Every hazard should trace to a hazardous situation, a harm, a risk estimate, a control measure, and verification that the control works. Link controls back to design inputs and verification records so the chain holds under audit. After launch, post-market data, complaints, and CAPA outcomes should update risk estimates rather than remain in a separate system.
How SJML helps with ISO 14971
SJML builds ISO 14971 risk management into device programs from concept through design transfer, rather than bolting it on at the end. The engineering teams integrate risk management with usability engineering under IEC 62366 and with software lifecycle work under IEC 62304, so that hazards, controls, and verification remain connected. On the compliance side, SJML supports risk management file creation and remediation as part of QMS and technical documentation work aligned to ISO 13485, FDA 21 CFR Part 820, and EU MDR/IVDR, including maintaining risk files through post-market surveillance. Talk to SJML’s QARA team.
Frequently asked questions
ISO 14971 itself is a voluntary standard, but conformity is effectively expected. EU MDR and IVDR require a documented risk management process, and EN ISO 14971:2019/A11:2021 is the harmonized route to show it. ISO 13485 and FDA expectations also assume risk management consistent with ISO 14971, so most manufacturers treat it as required.
ISO 13485 is the quality management system standard for medical devices, covering the full scope of the QMS. ISO 14971 is narrower and specifies the risk management process for device safety. ISO 13485 requires risk-based thinking and references ISO 14971, so use them together: the QMS sets the framework, and ISO 14971 governs how risk is handled within it.
The risk management file (RMF) is the documented record of all risk management activities for a device. It collects the risk plan, hazard analyses, risk estimates and evaluations, control measures and their verification, the overall residual risk evaluation, and post-production data. Use it as the primary evidence that ISO 14971 was applied.
The current edition is ISO 14971:2019, the third edition, reviewed and confirmed as current in 2025. It is supported by ISO/TR 24971:2020, a guidance technical report. In Europe, EN ISO 14971:2019/A11:2021 adds Annexes ZA and ZB that map the standard to the EU MDR and IVDR.
Related terms
ISO 13485 | Risk Management File | IEC 62366-1 | IEC 62304 | DFMEA | EU MDR 2017/745