Direct answer: ISO 14971 is the international standard for risk management of medical devices. It establishes a systematic process for identifying hazards, estimating and evaluating risks, controlling risks, and monitoring the effectiveness of those controls across the device lifecycle. As of July 2026, the current edition is ISO 14971:2019. FDA recognizes ISO 14971:2019 in its recognized standards database. Compliance with ISO 14971 is voluntary in the United States, but risk management is required through FDA's design and development requirements (21 CFR 820.10(c), incorporating ISO 13485:2016 Clause 7.3, together with ISO 13485 Clause 7.1), and ISO 14971 is the framework almost universally used to satisfy that requirement.
Risk management is not a document you create to satisfy regulators. It is the systematic process of finding everything that could go wrong with your device before it reaches a patient, deciding whether the risk is acceptable, and controlling it if it is not. Done well, risk management is the intellectual backbone of a device development program. Done poorly, it becomes a paper exercise that gives you false confidence and leaves you exposed.
ISO 14971 is the standard that defines how to do it. This article explains the standard, how it connects to FDA requirements, and what a medical device risk management program looks like in practice.
What Is ISO 14971?
ISO 14971 is published by the International Organization for Standardization (https://www.iso.org). The current edition, ISO 14971:2019, replaced the previous ISO 14971:2007. The full title is "Medical devices: Application of risk management to medical devices."
The standard establishes requirements for a risk management process that:
- Identifies hazards associated with a medical device
- Estimates the risk arising from each hazard
- Evaluates whether each risk is acceptable
- Controls risks that are not acceptable
- Evaluates the overall residual risk
- Collects and reviews post-market information that may affect the risk evaluation
ISO 14971 covers the entire device lifecycle, from initial concept through post-market surveillance and device decommissioning.
FDA recognizes ISO 14971:2019 in its recognized standards database (https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfStandards/search.cfm). This means manufacturers can declare conformance with ISO 14971:2019 in their 510(k) submissions using FDA's Recognized Consensus Standards process, which can reduce the amount of detail required in the 510(k) for risk management.
ISO 14971:2019 vs. ISO 14971:2007: What Changed
The 2019 edition introduced several significant changes from the 2007 edition that device companies should understand, particularly if their risk management programs were built under the older standard.
State of the art. The 2019 edition shifted the basis for risk acceptability from a "generally accepted" threshold to "current state of the art," which is a more demanding standard. This affects how manufacturers justify the acceptability of residual risks.
Overall residual risk. The 2019 edition requires explicit evaluation of the overall residual risk, meaning the combined risk from all individual residual risks. A device can have individual risks that are each acceptable but still present an unacceptable overall risk profile if the combination of residual risks is too high.
Benefit-risk analysis. ISO 14971:2019 places more explicit emphasis on benefit-risk analysis, particularly for risks that cannot be reduced to an acceptable level by risk controls alone. The manufacturer must compare the benefits of the device's intended use to the residual risks when making acceptability determinations.
Post-production information. The 2019 edition strengthens requirements for monitoring and reviewing post-production information (complaint data, adverse events, literature) and feeding that information back into the risk management process.
An ISO Technical Report, ISO/TR 24971:2020, provides guidance on the application of ISO 14971:2019. It is not normative (not a standard) but is a useful reference for understanding how the standard's requirements are intended to be applied.
The Risk Management Process: Step by Step
ISO 14971 defines risk management as a process with specific, ordered activities. Here is what each step requires.
Step 1: Risk Management Plan
Before beginning risk analysis, the manufacturer must establish a risk management plan for the device (ISO 14971:2019, Clause 4). The plan defines:
- The scope of the risk management activities (what device, what lifecycle phases)
- Who is responsible for each activity
- How risk acceptability criteria will be established
- What methods will be used for risk estimation and evaluation
- How risk management will integrate with the design and development process
Risk acceptability criteria must be established before risk evaluation begins. Setting criteria after risks have been identified is a significant quality system finding.
Step 2: Hazard Identification
A hazard is a potential source of harm (ISO 14971 definition). Hazard identification is the process of systematically identifying all foreseeable hazards associated with the device and its use.
Hazard identification draws on multiple sources:
- The device's intended use and reasonably foreseeable misuse
- The use environment and the characteristics of the intended user population
- Known hazards from similar devices (predicate devices, MAUDE database, published literature)
- Failure modes of the device's components and subsystems
- Energy sources and materials used in the device
- User interface characteristics (ergonomics, alarm design, labeling)
Common structured methods for hazard identification in medical devices include Failure Mode and Effects Analysis (FMEA), Fault Tree Analysis (FTA), Hazard and Operability Study (HAZOP), and Preliminary Hazard Analysis (PHA). Most device programs use FMEA as the primary tool, with FTA applied to higher-complexity systems or critical safety functions.
Step 3: Risk Estimation
For each hazard identified, the manufacturer estimates the probability of harm and the severity of that harm. The risk estimate is a function of probability and severity, expressed using whatever scale the risk acceptability criteria defined in the risk management plan.
Probability of harm must consider both the probability that a hazardous situation occurs and the probability that the hazardous situation then leads to harm. These are not the same. A hazardous situation may arise frequently but lead to harm only rarely.
Severity is typically classified on a manufacturer-defined scale (one common example set is negligible, minor, serious, critical, catastrophic) based on the clinical consequences to the patient or user if harm occurs. The specific levels and definitions vary by manufacturer and by framework (for example AAMI TIR57), and must be defined in the risk management plan.
Risk estimation does not require precise statistical data in all cases. ISO 14971:2019 allows qualitative estimation where quantitative data is not available, with the important caveat that the basis for the estimate must be documented.
Step 4: Risk Evaluation
Risk evaluation is the comparison of estimated risk against the risk acceptability criteria defined in the risk management plan. Risks that are acceptable (within the criteria) do not require further risk control measures but must still be documented. Risks that are not acceptable require risk control.
Step 5: Risk Control
For risks that are not acceptable, the manufacturer must implement risk controls. ISO 14971:2019 specifies a priority order for risk controls (Clause 6.2):
- Inherent safety by design: Eliminate or reduce the hazard by design change. This is the most effective form of risk control because it does not depend on user behavior.
- Protective measures: Add protective measures in the device or manufacturing process (guards, alarms, interlocks, protective packaging) that reduce the probability of harm.
- Information for safety: Provide warnings, contraindications, and instructions for use that inform users of residual risks. This is the least effective form of risk control because it depends on the user reading and following the information.
Risk controls must be verified to confirm they were implemented correctly (this is design verification) and validated to confirm they are effective in actual use (this is design validation). New risks introduced by risk controls must also be evaluated.
Step 6: Residual Risk Evaluation
After risk controls are implemented, the residual risk for each hazard must be evaluated against the acceptability criteria. If the residual risk is still not acceptable, additional controls are required. If residual risk cannot be reduced further with practical controls, the manufacturer must conduct a benefit-risk analysis to determine whether the benefits of the device's intended use outweigh the residual risks.
The overall residual risk, the combined effect of all residual risks from all hazards, must also be evaluated under ISO 14971:2019. If the overall residual risk is not acceptable, even if individual residual risks are, the device may not be safe to release.
Step 7: Risk Management Review
Before releasing the device for commercial distribution, the manufacturer must conduct a risk management review that confirms:
- The risk management plan has been executed
- Overall residual risk is acceptable
- Appropriate methods are in place to collect post-production information
Step 8: Post-Production Information
Risk management does not end at market entry. Clause 9 of ISO 14971:2019 requires that manufacturers establish procedures to collect and review information generated in the post-production phase, including adverse event reports, complaint data, post-market surveillance data, and published scientific literature. This information must be fed back into the risk management process and may require updates to the risk management file.
The Risk Management File
The Risk Management File is the collection of records that documents the risk management process for a device. ISO 14971:2019 requires that the Risk Management File be maintained throughout the device lifecycle, including post-market.
Minimum Risk Management File contents:
- Risk management plan
- Hazard identification records and hazard analysis (typically the FMEA or equivalent)
- Risk estimation records
- Risk evaluation records and acceptability determinations
- Risk control measures implemented and verification evidence
- Residual risk evaluation records
- Benefit-risk analysis (where applicable)
- Risk management review records
- Post-production information collection and review records
The Risk Management File is not a single document. It is an organized collection of records. FDA inspectors and 510(k) reviewers who ask for risk management documentation are, in effect, asking to see the contents of the Risk Management File.
How ISO 14971 Connects to FDA Requirements
FDA does not have a regulation that directly mandates ISO 14971. FDA's design and development requirements (21 CFR 820.10(c), incorporating ISO 13485:2016 Clause 7.3) require design validation, and ISO 13485 Clause 7.1 requires risk management across product realization with reference to ISO 14971. ISO 14971 is the standard used to conduct that risk management for the overwhelming majority of device programs.
Beyond design validation, FDA's broader quality system requirement expects manufacturers to address risks through design and development controls, production and process controls, corrective and preventive action, and post-market surveillance. ISO 14971 provides the systematic framework that connects these requirements.
For 510(k) submissions, manufacturers can declare conformance with ISO 14971:2019 using FDA's Recognized Consensus Standards process. When a manufacturer declares conformance, FDA's review of risk management in the submission can be streamlined, because the standard has already been reviewed and accepted as adequate by FDA.
Common Risk Management Mistakes
Setting risk acceptability criteria after performing risk analysis. The criteria must be set before risks are evaluated. Setting them after is an integrity problem.
Risk management as a standalone document. Risk management must integrate with design and development controls, V&V, and post-market surveillance. A risk management file that was never updated after design changes is not current.
Incomplete hazard identification. Teams often focus on failure modes of the device's own components and miss hazards arising from foreseeable misuse, environmental conditions, or user interface design. Systematic methods (FMEA, HAZOP) help ensure completeness.
Risk controls without verification. Every risk control must be verified (confirmed it was implemented correctly) and evaluated for effectiveness. Risk controls that appear in the risk file but were never tested are paper controls.
Not updating the file post-market. ISO 14971:2019 requires post-production information to feed back into risk management. A file that was completed at launch and never touched again is not compliant with the 2019 standard.
Treating benefit-risk analysis as a formality. For devices with residual risks that exceed acceptability criteria, the benefit-risk analysis must be substantive. A one-line statement that benefits outweigh risks without supporting clinical evidence is not adequate.
From Risk Management to Commercial Confidence
A robust ISO 14971 risk management program does more than satisfy FDA. It is the evidence base for your product's clinical claims and your safety profile. When your risk management file documents that every identified hazard has been controlled, that residual risks have been evaluated against clinical benefits, and that post-market surveillance is in place to catch new signals, you have a foundation for credible, specific, defensible marketing.
Hospital purchasing committees ask about your adverse event history. Clinical champions ask about use error rates. Health system risk managers ask about your post-market commitment. The answers to those questions come from your risk management program.
Buzzbox Media builds medical device marketing programs grounded in the evidence that development generates. If you are working through risk management now and want to understand how it connects to your commercial story, a 30-minute conversation is a useful starting point. Book at https://www.buzzboxmedia.com/book.