Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 13485 Risk Management — ISO 13485:2016 medical device quality management

ISO 13485 Risk Management and ISO 14971 Explained

ISO 13485 risk management is not a clause you satisfy once. The standard threads
risk through product realization, and the companion standard
ISO 14971 supplies the method. Getting the relationship between the two right is
what separates a system that passes audit from one that generates findings.

Where ISO 13485 risk management appears in the standard

Clause 7.1 requires the organisation to document one or more processes for risk management in
product realization, and to retain the resulting records. From there it recurs throughout:

  • Design and development (7.3) — risk management outputs feed design inputs,
    and design changes must be evaluated for their risk impact.
  • Purchasing (7.4) — supplier controls are to be proportionate to the risk the
    purchased product presents to the finished device.
  • Production and process validation (7.5) — the extent of validation is a
    risk decision.
  • Feedback and complaint handling (8.2) — post-production information feeds
    back into the risk file, which is where many systems break down.
  • CAPA (8.5) — corrective actions must be proportionate to the risk
    encountered.
  • Competence (6.2) — training needs are themselves risk-informed.

How ISO 14971 fits

ISO 13485 says risk management must happen; ISO 14971 defines how.
Its process runs: risk management plan, hazard identification, risk estimation and evaluation, risk
control, evaluation of overall residual risk acceptability, the risk management report, and
production and post-production information. The output is a risk management file
per device.

The two standards are complementary, not alternatives. An auditor assessing clause 7.1 will
usually be reading a file structured to ISO 14971.

Risk management documentation, ready to adapt.

The ISO 13485 Toolkit includes the risk management plan, hazard analysis, risk assessment and risk management report templates, structured to ISO 14971 and cross-referenced to clause 7.1.

Explore the ISO 13485 Toolkit →

The ISO 13485 risk management mistake auditors find most often

Risk treated as a document rather than a process. A risk assessment produced at
design freeze, filed, and never revisited will fail. The standard is explicit that post-production
information must flow back: complaints, servicing data, field performance and regulatory reports all
have to be reviewed for whether they change your risk estimates.

The tell an auditor looks for is simple. They will pick a complaint from the last twelve months
and ask to see where it was considered in the risk file. If the answer is “it was handled under
CAPA”, the loop is not closed.

The feedback loop, worked through

Here is the chain an auditor traces, and where it usually breaks.

A hospital reports that a connector on your device separated during use. Under clause 8.2.2 that
is a complaint, so it is logged and investigated. The investigation finds the connector met
specification but the retention force sits at the low end of tolerance when the device is used at an
angle the design team had not anticipated.

Most systems stop here, raise a CAPA, tighten the tolerance and close it. That
satisfies clause 8.5.2 and fails clause 7.1.

The complete loop continues: the risk management file is reopened. Was “connector separation
during use” identified as a hazardous situation? If not, it is added. If it was, does the observed
occurrence rate still support the probability originally estimated? The residual risk is
re-evaluated, the tolerance change is recorded as a new risk control, and its effectiveness is
verified — not merely its implementation. If the re-evaluation moves the risk outside the
acceptability criteria, that triggers a field action decision under clause 8.3.

The audit test is short: pick a complaint, ask to see where it touched the risk file. If nothing
in the risk file changed and nothing records why it did not need to, the loop is not closed.

Risk-based decisions you must be able to justify

ISO 13485 uses risk as the justification for how much control is proportionate. Expect to explain,
with records:

  • Why a given supplier was subject to the controls you applied, and not more or fewer
  • Why a process was validated rather than verified
  • Why the level of design verification chosen was sufficient
  • Why training for a critical operation was adequate
  • Why a nonconformity did or did not warrant a field action

Each of these is a defensible decision if the reasoning was recorded at the time, and very hard
to reconstruct afterwards.

A practical ISO 13485 risk management sequence

Write the risk management plan before design inputs are fixed. Identify hazards from intended use
and foreseeable misuse, not only from component failure. Record risk control decisions where they
are made rather than gathering them later. Feed complaints and servicing data back on a defined
cycle. Then produce the risk management report as a summary of work already done, rather than as a
document written to satisfy the auditor.

References

More on ISO 13485

All of these are covered by the ISO 13485 Toolkit, or try the free ISO 13485 templates first.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.