Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 14971 vs ISO 13485 explained

ISO 14971 vs ISO 13485: 5 Clear Differences Explained (2026)

ISO 14971 vs ISO 13485 is a comparison between a process standard and a management system standard that requires it. ISO 14971:2019 specifies terminology, principles and a process for applying risk management to medical devices — a single device at a time, from intended use through hazard identification, risk estimation, evaluation, control, overall residual risk and post-production — and produces a risk management file per device.

ISO 13485:2016 specifies requirements for a quality management system for organisations in the medical device life cycle, and it makes risk management a QMS obligation: clause 4.1.2 requires a risk-based approach to controlling QMS processes, clause 7.1 requires documented risk management throughout product realisation, and the design and purchasing clauses require risk management outputs as inputs.

Neither replaces the other; a manufacturer certified to ISO 13485 without ISO 14971 files has a QMS with a hole in it, and a manufacturer with excellent risk files and no QMS has no way to keep them current. This guide sets the two side by side on five differences, shows every place ISO 13485 points at ISO 14971, explains the regulatory position under EU MDR and FDA, and describes how the two run together in one documented system.

ISO 14971 vs ISO 13485: the process inside the QMS
ISO 14971:2019 — risk management process per device: plan, analysis, evaluation, control, overall residual risk, review, post-production; the risk management file · ISO 13485:2016 — QMS: 4.1.2 risk-based process control, 7.1 risk management in product realisation, 7.3 design, 7.4 purchasing, 8.2 feedback and complaints, 8.5 CAPA · certifiable; MDR and FDA point at both.

ISO 14971 vs ISO 13485: what each standard is

ISO 14971:2019 is the third edition, published December 2019 and confirmed unchanged by ISO in 2025. Its clauses 4 to 10 define the process: general requirements including the plan (4.4) and the file (4.5); risk analysis (5); risk evaluation (6); risk control including benefit-risk analysis (7); evaluation of overall residual risk (8); risk management review (9); and production and post-production activities (10). ISO/TR 24971:2020 is its guidance. It applies to any medical device including software as a medical device and IVDs, and it is not a management system standard — there is no certificate to ISO 14971; conformity is demonstrated by the file. Our guide to the ISO 14971 risk management file covers where files break.

ISO 13485:2016 is the medical device QMS standard, based on the ISO 9001:2008 structure with regulatory requirements built in: clauses 4 (QMS), 5 (management responsibility), 6 (resource management), 7 (product realisation) and 8 (measurement, analysis and improvement). It is certifiable by accredited bodies and is the QMS basis of EU MDR conformity assessment, MDSAP and, from 2 February 2026, the FDA’s Quality Management System Regulation, which incorporates it by reference. Our guide to ISO 13485 covers the standard.

ISO 14971 vs ISO 13485: the five differences

Difference ISO 14971:2019 ISO 13485:2016
1. What it governs The risk management process for a medical device The quality management system of the organisation
2. Unit of application One device (or a justified device family); one risk management file each One organisation and its QMS; one certificate
3. Output Risk management plan, risk analysis, evaluation, control records, overall residual risk evaluation, risk management report, post-production records — the file Quality manual, procedures, records, design history, device master record, CAPA — the QMS
4. Assurance No certification; the file is reviewed by notified bodies, FDA and auditors as part of technical documentation Accredited certification on a three-year cycle; MDSAP audits; notified body QMS audits under MDR
5. Who owns it Design and risk management engineers, with top management defining the risk acceptability policy (4.2) Quality management, with management responsibility in clause 5

ISO 14971 vs ISO 13485 clause by clause: every place ISO 13485 points at ISO 14971

ISO 13485:2016 clause Requirement ISO 14971 element that satisfies it
4.1.2 Apply a risk-based approach to the control of the appropriate processes needed for the QMS The risk-based thinking is QMS-level, not device-level; ISO 14971 principles are commonly applied by analogy, but this is not the device risk file
7.1 Establish documented requirements for risk management in product realisation; maintain records of risk management activities; a note references ISO 14971 The risk management process (clause 4.1) and the file (4.5) for each device
7.3.3 Design and development inputs include the outputs of risk management Risk control measures identified under 7.1 become design inputs
7.3.5 / 7.3.6 / 7.3.7 Design review, verification and validation Verification of implementation and effectiveness of risk control measures (7.2); overall residual risk evaluation (8)
7.3.9 Design and development changes evaluated for effect on risk management outputs Risk analysis updated for changes; file maintained
7.4.1 Purchasing controls proportionate to the risk associated with the purchased product Risks from purchased components identified in risk analysis
7.5.6 / 7.5.7 Validation of production and sterilisation processes Process risks and risk controls that depend on process validation
8.2.1 / 8.2.2 Feedback and complaint handling as input to risk management Production and post-production information (clause 10)
8.2.3 / 8.3 Regulatory reporting; control of nonconforming product Post-production actions (10.4); risk re-evaluation
8.5.2 / 8.5.3 Corrective and preventive action Risk management review and file update after actions

The ISO 14971 vs ISO 13485 pattern: ISO 13485 never says how to do risk management — it says that it must be documented, that its outputs feed design, purchasing and production, and that post-market information feeds back into it. ISO 14971 is the how. Our guide to ISO 13485 risk management covers the QMS side in more depth.

ISO 14971 vs ISO 13485: the regulatory position

Regime ISO 13485 ISO 14971
EU MDR 2017/745 The QMS required by Article 10(9); harmonised standard EN ISO 13485:2016 with amendments Annex I GSPR 3 requires a risk management system; Annex II requires the risk management plan and results in technical documentation; harmonised standard EN ISO 14971:2019/A11:2021, whose Annex ZA notes MDR requires risks reduced as far as possible, not merely to an acceptable level
FDA (US) Quality Management System Regulation, effective 2 February 2026, incorporates ISO 13485:2016 by reference into 21 CFR Part 820 Recognised consensus standard; risk management expected in design controls and premarket submissions
MDSAP (Australia, Brazil, Canada, Japan, US) The audit model is built on ISO 13485 Risk management assessed within the QMS audit
IEC 62304 software Software life cycle sits inside the QMS Clause 4.2 of IEC 62304 requires an ISO 14971 risk management process

Our guides to EU MDR and IEC 62304 risk management cover the two regimes that most often force the question.

Running ISO 14971 and ISO 13485 together

  1. Write one risk management procedure under clause 7.1. It defines the ISO 14971 process for the organisation — roles, competence, the risk acceptability policy from top management (4.2), the file structure, the review points — and every device plan inherits it.
  2. Make the device plan a design and development planning output. ISO 13485 7.3.2 planning produces the ISO 14971 4.4 plan for the device; the two documents reference each other.
  3. Route risk control measures into design inputs. Each measure identified under 7.1 of ISO 14971 becomes a 7.3.3 design input with a verification under 7.3.6 — which is how the file gets its evidence of implementation and effectiveness.
  4. Connect post-market to clause 10. Complaints (8.2.2), feedback (8.2.1), vigilance and PMS reports are the production and post-production information ISO 14971 clause 10 requires to be collected, reviewed and acted on; the QMS procedure names the file as a recipient.
  5. Audit the file in the internal audit. The ISO 13485 internal audit under 8.2.4 samples the risk management file for the device under review; a notified body auditor will do the same.
  6. Review at management review. Risk management review (ISO 14971 clause 9) results and post-production findings are inputs to ISO 13485 5.6 management review.

Frequently asked questions

What is the difference between ISO 14971 and ISO 13485?
ISO 14971:2019 defines the risk management process for a medical device and produces a risk management file per device; ISO 13485:2016 defines the quality management system for the organisation and requires documented risk management throughout product realisation (clause 7.1), with risk outputs feeding design, purchasing and post-market processes. ISO 13485 is certifiable; ISO 14971 is not.

Does ISO 13485 require ISO 14971?
ISO 13485 clause 7.1 requires documented risk management in product realisation and cites ISO 14971 in a note; it does not mandate the standard by name in the requirement, but regulators, notified bodies and auditors treat ISO 14971 as the expected method, and EU MDR harmonises it.

Can you be certified to ISO 14971?
No. There is no ISO 14971 certificate; conformity is shown by the risk management file, reviewed as part of technical documentation and within ISO 13485 QMS audits.

Which comes first?
In practice they are built together. A start-up usually writes the ISO 13485 risk management procedure and the first device’s ISO 14971 plan in the same month; the QMS provides the procedure, the device provides the file.

Is risk-based QMS thinking under 4.1.2 the same as ISO 14971?
No. Clause 4.1.2 applies risk-based thinking to QMS processes — supplier control, training, document control; ISO 14971 applies to the device and its users. The same vocabulary is often used, but the device file is a separate deliverable.

Where this leaves you

Treat ISO 14971 vs ISO 13485 as process inside system: write the risk management procedure under clause 7.1 once, plan each device’s risk management as a design planning output, route risk controls into design inputs and their verification, feed complaints and post-market data back into clause 10, and audit the file within the QMS — because a notified body reads the file as part of the QMS, and both standards expect it to be there.

References

More on ISO 14971

The risk management procedure, the device risk management plan and file templates, the hazard analysis worksheets and the risk management report are in the ISO 14971 Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.