Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 14971 risk management report infographic

ISO 14971 Risk Management Report: The Essential 2026 Guide to Clause 9 Review

The ISO 14971 risk management report is the short document that closes the loop on a medical device’s risk management before commercial release, and it is the one that auditors and notified bodies open when they want to know whether you actually finished the job. It is also one of the most commonly misunderstood deliverables, because teams confuse it with the risk management file or turn it into a copy of the hazard analysis.

This guide explains what the report is, what ISO 14971:2019 requires it to confirm, how it differs from the file, how to write it so it reads as a conclusion rather than a data dump and who should approve it. It is written for quality and regulatory professionals at medical device manufacturers. Always work from the standard itself and your own quality system; this article summarizes, it does not replace them.

Free gap assessment

How much of ISO 13485 could you evidence today?

Score clauses 4 to 8, free, with the FDA QMSR and EU MDR duties kept separate so you can see what is the standard and what is the regulator.

Run the free ISO 13485 gap assessment →  or  View premium report sample

What the ISO 14971 risk management report is

ISO 14971:2019 is the international standard for applying risk management to medical devices. Before commercial distribution of a device, the manufacturer must review the execution of the risk management plan. The result of that review is recorded, and this record is commonly called the risk management report.

The report is not the place to restate every hazard. Its job is to conclude. It answers whether the risk management plan was implemented, whether the overall residual risk is acceptable, and whether appropriate methods are in place to obtain relevant production and post-production information. Our general page on ISO 14971 covers the whole standard.

What the review must confirm

According to published guidance on clause 9, the review should confirm four things. First, that the risk management plan was appropriately executed. Second, that the overall residual risk is acceptable. Third, that methods to collect production and post-production information are in place. Fourth, that residual risks are communicated where needed, for example in instructions for use or labeling.

Each of those should be answerable with a short statement and a reference to the evidence in the risk management file. A reviewer should be able to read the report in a few minutes and know where to look for proof of each statement.

ISO 14971 risk management report vs risk management file

The file is the complete set of records produced by risk management. The report summarizes the conclusion and points to the file. Think of the file as the evidence locker and the report as the verdict. Mixing them creates two problems: a bloated report that nobody reads, and a file whose conclusion is hard to find.

A common gap is a report that is just a pasted FMEA table with no conclusion about plan execution or overall residual risk. Avoid that by writing the conclusions first and then adding only the references needed to support them. Keep the report stable and the file living, and update the report only when significant changes require a new review.

AspectRisk management fileRisk management report
DefinitionSet of records and documents produced by risk managementSummary confirming the risk management review
Standard referenceClause 4.4Clause 9, risk management review
TimingStarts at project start and lives throughout the life cycleCompleted before commercial distribution, updated when needed
ContentAll plans, analyses, controls, verification and evidenceConclusions: plan executed, residual risk acceptable, post-market methods in place
AudienceDesign team, auditors, reviewersApprovers, auditors, notified body reviewers
NatureRepositoryClosure document

Overall residual risk and benefit-risk

Clause 8 of the standard requires the manufacturer to evaluate overall residual risk using the method and criteria defined in the plan, which may differ from the criteria used for individual risks. The report records the outcome. Read our guides on risk acceptability criteria and benefit-risk analysis for how to set and apply those criteria.

If the overall residual risk is not acceptable, the manufacturer collects and reviews data and literature on the intended use and considers whether the medical benefits outweigh the risk. The report should state the decision, the reasoning and the evidence, because this is one of the most scrutinized parts of any review, especially under the EU regulations; see EU MDR and EU IVDR.

How to structure the report

A clear structure speeds review. The following outline works for most manufacturers, and you should adapt it to your quality system.

  • Device and scope: identification, version and intended use
  • Reference to the risk management plan and its version
  • Summary of execution: confirmation that plan activities were completed
  • Overall residual risk: method, criteria and conclusion
  • Benefit-risk statement where applicable
  • Production and post-production methods in place, see post-production information
  • Communication of residual risks in labeling and instructions
  • Conclusion, approver name, role, signature and date

Linking to the risk management plan and file

The report should reference, by version, the risk management plan it reviews. If the plan changed during development, list the versions and the reasons. The report should also point to the sections of the file that contain hazard identification, risk estimation, control measures and verification. Our pages on the risk management plan and the hazardous situation concept explain the inputs.

If you use the guidance in ISO/TR 24971, record that in the plan and in the report, since the technical report explains how to apply the standard but is not itself a set of requirements.

Who approves the report

The standard requires the review to be carried out by persons with appropriate authority. In practice, this means a cross-functional group such as quality, regulatory, engineering and clinical or medical input, and a named approver who can accept overall residual risk on behalf of the organization. Record the roles, not just the names, so the approval stands up to audit.

Note the difference from management review in your quality management system. That is a separate requirement; compare them in ISO 14971 vs ISO 13485.

When to update the report

The report is completed before commercial distribution, but the risk management process continues afterwards. When production or post-production information shows a new hazard, a changed risk estimate or a change in the state of the art, the manufacturer must assess whether the risk management file needs revision. If the change affects the overall residual risk conclusion, update the report or issue a new review.

Keep a change history. A dated log of revisions with reasons shows an auditor that the file is alive and that risk decisions follow data.

Templates for the report

A template keeps the report short and consistent. The ISO 14971 Toolkit includes editable templates for the plan, file, analysis and review, so the report links cleanly to the rest of the documentation. Use them as a structure and fill them with your own device data.

For a helpful comparison of the two documents, see the MedDeviceGuide comparison of the risk management file and report. Whichever format you use, make sure the report is approved and controlled under your document control procedure.

A short example of ISO 14971 risk management report wording

A strong report uses plain, checkable statements. For plan execution, it might say that all activities in version 2 of the risk management plan were completed, with no open actions, and list the file sections where results are stored. For residual risk, it might say that, using the overall residual risk method defined in the plan, the residual risk of the device is acceptable, and refer to the evaluation record. For post-production methods, it might say that complaint handling, service feedback and literature surveillance procedures are in place and named in the plan. Each sentence can be verified by a reviewer, which is the test of a good ISO 14971 risk management report. The wording here is illustrative; use your own facts.

Preparing the ISO 14971 risk management report for audits

Before an audit, read the report as a stranger would. Can you find the approval, the plan version and the conclusion in under a minute? Do the references resolve to real documents with the stated versions? Do the statements match the current file? Fix mismatches first, because an auditor who finds one broken reference will test many more. Keep the final report, the review meeting record and the approval in the same controlled location so they can be produced quickly when requested.

Common mistakes in the ISO 14971 risk management report

The common errors are producing a report that restates hazard tables, leaving out the overall residual risk conclusion, failing to confirm that post-production methods exist, using criteria in the report that differ from the plan without explanation, and signing the report without the authority to accept residual risk. Another is to treat the report as a one-time document and never revisit it when new information arrives. Fix these by using a short template and a standing review step in your change and complaint processes.

ISO 14971 Risk Management Report FAQ

Is the risk management report mandatory?

ISO 14971 requires a review of the execution of the risk management plan before commercial distribution and a record of the result. That record is commonly called the risk management report.

How long should the report be?

It should be short, typically a few pages, because it summarizes conclusions and refers to the risk management file for evidence.

What is the difference between the file and the report?

The file contains all risk management records. The report concludes that the plan was executed, overall residual risk is acceptable and post-market methods are in place.

Who signs the report?

A person or group with appropriate authority, who can accept the overall residual risk. Record their role as well as their name.

When must the report be updated?

When new information changes the overall residual risk conclusion or the risk management plan.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.