ISO 13485 risk management is not a clause you satisfy once. The standard threads
risk through product realization, and the companion standard
ISO 14971 supplies the method. Getting the relationship between the two right is
what separates a system that passes audit from one that generates findings.
Where ISO 13485 risk management appears in the standard
Clause 7.1 requires the organisation to document one or more processes for risk management in
product realization, and to retain the resulting records. From there it recurs throughout:
- Design and development (7.3) — risk management outputs feed design inputs,
and design changes must be evaluated for their risk impact. - Purchasing (7.4) — supplier controls are to be proportionate to the risk the
purchased product presents to the finished device. - Production and process validation (7.5) — the extent of validation is a
risk decision. - Feedback and complaint handling (8.2) — post-production information feeds
back into the risk file, which is where many systems break down. - CAPA (8.5) — corrective actions must be proportionate to the risk
encountered. - Competence (6.2) — training needs are themselves risk-informed.
How ISO 14971 fits
ISO 13485 says risk management must happen; ISO 14971 defines how.
Its process runs: risk management plan, hazard identification, risk estimation and evaluation, risk
control, evaluation of overall residual risk acceptability, the risk management report, and
production and post-production information. The output is a risk management file
per device.
The two standards are complementary, not alternatives. An auditor assessing clause 7.1 will
usually be reading a file structured to ISO 14971.
Risk management documentation, ready to adapt.
The ISO 13485 Toolkit includes the risk management plan, hazard analysis, risk assessment and risk management report templates, structured to ISO 14971 and cross-referenced to clause 7.1.
The ISO 13485 risk management mistake auditors find most often
Risk treated as a document rather than a process. A risk assessment produced at
design freeze, filed, and never revisited will fail. The standard is explicit that post-production
information must flow back: complaints, servicing data, field performance and regulatory reports all
have to be reviewed for whether they change your risk estimates.
The tell an auditor looks for is simple. They will pick a complaint from the last twelve months
and ask to see where it was considered in the risk file. If the answer is “it was handled under
CAPA”, the loop is not closed.
The feedback loop, worked through
Here is the chain an auditor traces, and where it usually breaks.
A hospital reports that a connector on your device separated during use. Under clause 8.2.2 that
is a complaint, so it is logged and investigated. The investigation finds the connector met
specification but the retention force sits at the low end of tolerance when the device is used at an
angle the design team had not anticipated.
Most systems stop here, raise a CAPA, tighten the tolerance and close it. That
satisfies clause 8.5.2 and fails clause 7.1.
The complete loop continues: the risk management file is reopened. Was “connector separation
during use” identified as a hazardous situation? If not, it is added. If it was, does the observed
occurrence rate still support the probability originally estimated? The residual risk is
re-evaluated, the tolerance change is recorded as a new risk control, and its effectiveness is
verified — not merely its implementation. If the re-evaluation moves the risk outside the
acceptability criteria, that triggers a field action decision under clause 8.3.
The audit test is short: pick a complaint, ask to see where it touched the risk file. If nothing
in the risk file changed and nothing records why it did not need to, the loop is not closed.
Risk-based decisions you must be able to justify
ISO 13485 uses risk as the justification for how much control is proportionate. Expect to explain,
with records:
- Why a given supplier was subject to the controls you applied, and not more or fewer
- Why a process was validated rather than verified
- Why the level of design verification chosen was sufficient
- Why training for a critical operation was adequate
- Why a nonconformity did or did not warrant a field action
Each of these is a defensible decision if the reasoning was recorded at the time, and very hard
to reconstruct afterwards.
A practical ISO 13485 risk management sequence
Write the risk management plan before design inputs are fixed. Identify hazards from intended use
and foreseeable misuse, not only from component failure. Record risk control decisions where they
are made rather than gathering them later. Feed complaints and servicing data back on a defined
cycle. Then produce the risk management report as a summary of work already done, rather than as a
document written to satisfy the auditor.
References
- ISO 13485:2016 — the standard itself on iso.org.
- FDA Quality Management System Regulation (QMSR) — the rule that incorporated ISO 13485 into 21 CFR Part 820.
More on ISO 13485
- ISO 13485 certification
- ISO 13485 mandatory documents
- ISO 13485 risk management — you are here
- ISO 13485 vs ISO 9001
- ISO 13485 internal audit
- ISO 13485 risk assessment template
All of these are covered by the ISO 13485 Toolkit, or try the free ISO 13485 templates first.