Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Post-production information under ISO 14971

Post-Production Information: A Clear ISO 14971 Guide

Post-production information is the clause that decides whether an ISO 14971 risk management file stays true. Everything before it is prediction: estimated probabilities, assumed use, expected performance. Clause 10 is where the device meets reality and the estimates get corrected — and it is the part of the file most often left empty after certification.

This guide covers what has to be collected, what has to be done with it, the three outcomes a review can produce, and how the loop connects to your other regulatory obligations.

Post-production information under ISO 14971: collect, review, act
Collect, review against what you assumed, then act on the file — not just on the complaint.

What ISO 14971 asks for

The standard requires a system to actively collect and review information about the device in production and post-production, to decide whether that information affects the risk management outputs, and to act where it does. It is a planned activity: the risk management plan has to say how the information will be gathered, who reviews it and when.

The word to notice is actively. Waiting for post-production information to arrive as complaints to arrive is passive, and passive collection systematically underestimates risk — most use errors and near-misses never generate a complaint at all.

What counts as post-production information

Source What it tells you that the file assumed
Complaints and service records Whether the failure modes you predicted are the ones occurring
Production and in-process data Whether manufacturing controls hold the assumptions the analysis rests on
Vigilance and field safety actions Harm that actually occurred, to you or to comparable devices
Regulatory databases and literature State of the art, and hazards recognised since you filed
Training, support and usability feedback Whether the device is used the way the file assumed it would be
Supplier and component change notices Whether something under the device changed without you

The last row is the quiet one. A component substituted by a supplier can invalidate a risk control the file still claims is in place.

The three outcomes of a post-production information review

  1. Nothing changes. The information is consistent with the file’s estimates. Record that conclusion — a review that produced no change is evidence, and an empty file is not.
  2. The file was wrong about probability or severity. Update the estimate, re-evaluate acceptability, and if the risk is no longer acceptable, treat it. A revised estimate that does not flow through to the risk evaluation is the most common half-finished version of this clause.
  3. A new hazard or hazardous situation appears. Add it, analyse it, control it, and check whether it affects the overall residual risk conclusion and the benefit-risk position.

All three should also prompt one further question: does the information change the information for safety — the instructions, warnings and training that sit at the bottom of the control hierarchy?

The trigger nobody defines

Most systems say the data will be reviewed periodically and never say what would cause action between reviews. Write the thresholds down: a complaint rate above a stated level, any complaint involving harm, any use error in a category the file assumed was controlled, any field safety action on a comparable device. Without triggers, the loop runs at whatever pace the calendar allows, and serious signals wait for the next quarterly meeting.

How post-production information connects to everything else

Post-production information is one activity feeding several regimes. Under the EU MDR the same data serves post-market surveillance, the PMS report or PSUR, and post-market clinical follow-up; in the US it feeds complaint handling and reporting obligations. The mistake is to run them as separate systems with separate data — one collection process with different outputs is both cheaper and more defensible, because the numbers cannot then disagree.

The risk management file remains the master record for risk. Our guides to the risk management file and the risk management plan cover what the file has to hold and what the plan has to commit to, and the EU MDR covers the surveillance obligations that sit alongside.

Where files break at clause 10

Complaints handled, file untouched. The corrective action closes, the customer is satisfied, and the risk estimate that the complaint contradicted is still in the file unchanged.

Only your own data. The clause expects information about similar devices and the state of the art too. Regulatory databases and literature are part of the collection, not optional enrichment.

No downward revision. Estimates only ever move up. If a hazard has not materialised across a large installed base over years, that is also information — and revising probability downward with evidence is legitimate.

Reviews with no output. A meeting with no record of what was reviewed, what was concluded and what was decided leaves nothing for an auditor to test.

Frequently asked questions

What is post-production information under ISO 14971?
Information collected about the device once it is in production and in use — complaints, service data, vigilance, production data, literature and state of the art — reviewed to determine whether the risk management outputs need to change.

How often should it be reviewed?
At intervals defined in the risk management plan, plus immediately on defined triggers. Annual review with event-driven triggers is the common pattern; the plan has to state both.

Is it the same as post-market surveillance?
No, though they share data. Post-market surveillance is a regulatory obligation with its own outputs; post-production information is the ISO 14971 activity that keeps the risk management file current.

Who should perform the review?
A cross-functional group — risk management, quality, regulatory, clinical and engineering. Complaint handling alone cannot judge whether a risk estimate is still valid.

Does a change always require a file update?
No, but the conclusion has to be recorded. “Reviewed, no impact on the risk management file” with the evidence behind it is a valid and necessary output.

Where this leaves you

Plan the collection rather than waiting for it: name the sources, set the review interval, and write the triggers that force action in between. Take every review to one of three explicit conclusions and record it, let estimates move down as well as up when the evidence supports it, and run one collection process feeding both ISO 14971 and your post-market surveillance obligations. A risk management file that has not changed since approval is not stable — it is unmaintained.

References

More on medical device risk

Review templates, trigger definitions and the risk management file structure are in the ISO 14971 Risk Management Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.