An ISO 13485 risk assessment template has to do more than list hazards. Clause 7.1
requires risk management across product realization, and in practice auditors assess the output
against ISO 14971. This guide sets out what the document must contain to hold up.
ISO 13485 risk assessment template: the fields it needs
- Device and scope — which device or family, which variants, which lifecycle
stage the assessment covers. - Intended use and reasonably foreseeable misuse. Misuse is not optional; it is
where a large share of real hazards live. - Hazard, foreseeable sequence of events, hazardous
situation and harm as separate fields. Collapsing these into one “risk”
column is the most common structural weakness, because it hides the causal chain the auditor wants
to follow. - Severity and probability of occurrence of harm, scored against
criteria defined in your risk management plan — not invented per row. - Risk evaluation against your acceptability criteria.
- Risk control measure, with its type recorded: inherent safety by design,
protective measures, or information for safety. That order is the required hierarchy. - Verification of implementation and verification of effectiveness
— two separate checks, and templates routinely omit the second. - Residual risk after control, and whether any new hazard was introduced by the
control itself. - Traceability to design inputs, verification records and the risk management file.
- Post-production review — date, source of information, and whether the
estimate changed.
A risk assessment template that already has these fields.
The ISO 13485 Toolkit includes the risk management plan, hazard analysis and risk assessment workbook, and the risk management report — structured to ISO 14971 and cross-referenced to clause 7.1.
Scoring: keep it defensible, not elaborate
A five-by-five severity and probability matrix is conventional and sufficient. What matters is not
the granularity but that the scales are defined in advance in the risk management plan,
applied consistently, and that the acceptability boundary is stated. An elaborate scoring scheme
applied inconsistently is worse than a simple one applied well.
Resist the temptation to tune scores until everything lands in the acceptable band. Auditors read
for that pattern, and a file where no risk was ever unacceptable before control invites scrutiny.
The field templates most often get wrong
The post-production column. ISO 14971 requires production and post-production
information to feed back into the file, and ISO 13485 clause 8.2 supplies that information through
feedback and complaints. If your template has no place to record that a complaint was reviewed
against a hazard, the loop cannot be evidenced — and this is precisely what an auditor tests by
picking a recent complaint and asking where it landed.
ISO 13485 risk assessment template: a worked row
Abstract field lists are easy to agree with and hard to apply, so here is one row of a completed
assessment for an infusion device.
- Hazard: electrical energy.
- Foreseeable sequence of events: mains adapter is dropped during transport
between wards; the strain relief cracks; a conductor is exposed over time. - Hazardous situation: a clinician contacts an exposed live conductor while
repositioning the pump. - Harm: electric shock, potentially severe.
- Severity: 4 of 5, per the scale defined in the risk management plan.
- Probability before control: 3 of 5, based on field data from the predecessor
device. - Risk control: reinforced strain relief moulded into the housing. Type:
inherent safety by design — the top of the hierarchy, not a warning label. - Verification of implementation: drawing revision B, first article inspection
record. - Verification of effectiveness: drop test to the applicable standard, ten units,
report reference. - New hazard introduced? Stiffer moulding increases cable bend radius; assessed
separately, judged acceptable. - Residual probability: 1 of 5. Residual risk acceptable against the plan’s
criteria. - Post-production review: reviewed each quarter against complaint data; no
occurrences in the last four quarters.
Notice how much of that row is a reference to a record elsewhere. That is the point. The
assessment is an index into the evidence, not a substitute for it.
How the ISO 13485 risk assessment template connects to the QMS
The risk assessment is not standalone. Its outputs become design inputs under clause 7.3, justify
the extent of process validation under 7.5, set the proportionality of supplier controls under 7.4,
and determine whether a nonconformity warrants a field action under 8.3. A template that cannot be
traced into those records leaves each of those decisions unsupported.
For the wider picture, see our guides to
ISO 13485 risk management and
ISO 13485 mandatory documents. Sample documents are
available as free ISO 13485 templates.
References
- ISO 13485:2016 — the standard itself on iso.org.
- FDA Quality Management System Regulation (QMSR) — the rule that incorporated ISO 13485 into 21 CFR Part 820.
More on ISO 13485
- ISO 13485 certification
- ISO 13485 mandatory documents
- ISO 13485 risk management
- ISO 13485 vs ISO 9001
- ISO 13485 internal audit
- ISO 13485 risk assessment template — you are here
All of these are covered by the ISO 13485 Toolkit, or try the free ISO 13485 templates first.