
Introduction
A patient lying on an operating table trusts an infusion pump to deliver the right dose, at the right time, without failure. They never see the hazard analysis behind that pump, the failure mode testing, or the years of post-market data feeding back into design changes.
That invisible work is risk management, and for medical devices, it has a name: ISO 14971.
Many manufacturers struggle to translate this standard from a compliance checkbox into a working process. ISO 14971 is the internationally recognized standard for applying risk management to medical devices across the total product lifecycle, and regulators such as the FDA and EU MDR authorities expect conformance to it.
This article covers the standard's definition and scope, its key terminology, the risk management process itself, the current version, and how it connects to ISO 13485 and other frameworks.
Key Takeaways
- Defines the global process for identifying, evaluating, and controlling risk in medical devices, including SaMD and IVDs.
- Current edition is ISO 14971:2019, with EU-harmonized amendment A11:2021 for MDR/IVDR alignment.
- Risk combines the probability of harm occurring with the severity of that harm.
- Technically voluntary, but FDA, EU regulators, Health Canada, TGA, and MHLW all expect manufacturers to apply it.
- Works with ISO 13485 for QMS structure and differs fundamentally from generic ISO 31000.
What Is ISO 14971?
ISO 14971 is the international standard for applying risk management to medical devices across the full product lifecycle.
Its full title is "Medical devices — Application of risk management to medical devices." The unified standard first appeared in 2000 (building on earlier risk-analysis work from 1998) and is now in its third edition, published in December 2019, reconfirmed by ISO in 2025.
The standard defines risk as the combination of the probability of occurrence of harm and the severity of that harm. That framing matters: risk isn't a static number you calculate once during design and file away.
Probability and severity both shift as a device moves through manufacturing changes, new use environments, and real-world field data. Risk management under ISO 14971 is therefore a continuous discipline.
ISO 14971 covers the total product lifecycle:
- Design and development
- Manufacturing and production
- Distribution
- Post-market use, monitoring, and eventual decommissioning
This scope explicitly extends to software as a medical device (SaMD) and in vitro diagnostics (IVDs), not just traditional hardware.

Who Needs to Follow ISO 14971
The compliance audience is broad: medical device manufacturers, SaMD developers, and IVD makers selling into any regulated market. Regulatory bodies don't always mandate it outright, but they build their expectations around it.
| Authority | Position on ISO 14971 |
|---|---|
| FDA | Recognizes ISO 14971:2019 as a consensus standard usable in declarations of conformity |
| EU MDR/IVDR | Lists the EN-harmonized version as satisfying relevant general safety and performance requirements |
| Health Canada | Includes ISO 14971 on its recognized-standards list; guidance recommends applying its principles throughout the device lifecycle |
| TGA (Australia) | Requires risk analysis under ISO 14971:2019 "or an equivalent or better standard" |
| MHLW (Japan) | Accepted ISO 14971:2019 as the source standard, transitioning to JIS T 14971:2020 |
Recognition isn't the same as a blanket legal mandate everywhere. But in practice, a device manufacturer with no documented ISO 14971 process will struggle to clear any of these markets.
What ISO 14971 Does Not Cover
The standard is specific about its boundaries. ISO 14971 explicitly excludes:
- Decisions about whether to use a device in a particular clinical procedure
- General business risk management (financial, reputational, or operational risk unrelated to patient/user harm)
One point trips up a lot of teams: ISO 14971 does not itself require a quality management system. Its process can run independently. In practice, though, it's almost always implemented inside a QMS such as ISO 13485, since that's where design controls, document control, and CAPA already live.
Key ISO 14971 Definitions You Need to Know
Getting these terms right isn't academic. Auditors read risk files line by line, and sloppy terminology signals sloppy analysis. Here's the vocabulary that matters most.
The three H's:
- Hazard — a potential source of harm
- Hazardous situation — a circumstance where people, property, or the environment are exposed to one or more hazards
- Harm — injury or damage to health, property, or the environment
Notice the chain: a hazard exists in theory, a hazardous situation is exposure to it, and harm is the actual damage that results. A sharp needle tip is a hazard. A clinician's ungloved hand near that tip is a hazardous situation. A needlestick injury is harm.
Process terms:
| Term | What it means |
|---|---|
| Risk analysis | Systematic use of available information to identify hazards and estimate risk |
| Risk evaluation | Comparing estimated risk against acceptability criteria set in the risk management plan |
| Risk assessment | Risk analysis plus risk evaluation, combined |
| Risk control | Measures implemented to reduce or maintain risk within specified levels |
| Residual risk | Risk that remains after control measures are implemented |
In day-to-day practice, teams often blur these terms:
- Using "risk assessment" and "risk analysis" interchangeably
- Calling a hazard a "risk" without distinguishing the two
That imprecision creates gaps in audit-ready documentation. A reviewer expects a clear line from hazard → hazardous situation → estimated risk → control → residual risk.
The ISO 14971 Risk Management Process
ISO 14971 organizes risk management into seven process elements that apply across the entire device lifecycle, not just during development. The elements cover planning, risk analysis, risk evaluation, risk control, evaluation of overall residual risk, risk management review, and production/post-production activities.
Below, they're grouped into five practical stages.
Risk Management Planning
Before any hazard identification begins, manufacturers must establish a documented, executive-approved risk management plan. This plan defines:
- The scope of the devices and lifecycle phases covered
- Roles and responsibilities for the risk management team
- Criteria for risk acceptability
- Which lifecycle activities require ongoing risk review
Skipping this step, or treating it as a formality, is one of the most common findings auditors write up.
Risk Analysis and Evaluation
This is where hazard identification happens. Teams identify hazards and hazardous situations tied to the device's intended use and reasonably foreseeable misuse, then estimate the probability and severity for each. Common techniques include preliminary hazard analysis (PHA), fault tree analysis (FTA), and failure mode and effects analysis (FMEA).
Once estimated, each risk is evaluated against the acceptability criteria set in the risk management plan. Anything above the acceptable threshold moves into risk control.
Risk Control and Residual Risk
ISO 14971 mandates a strict hierarchy for risk control options, in this order:
- Inherent safety by design: eliminate or reduce risk through the design and manufacturing process itself
- Protective measures: build safeguards into the device or manufacturing process
- Information for safety: warnings, contraindications, and instructions for use
Information for safety is the last resort, not a shortcut around design fixes. After implementing controls, teams must verify their effectiveness and re-evaluate the residual risk that remains.

Overall Risk Acceptability and Benefit-Risk Analysis
Individual risks aren't the whole picture. Manufacturers must also evaluate the acceptability of the overall residual risk for the device as a whole. When individual or overall risk remains elevated despite controls, the standard requires a documented benefit-risk analysis, weighing the clinical benefit against the residual risk that couldn't be eliminated.
Production and Post-Production Monitoring
Risk management doesn't end at launch. The standard requires a feedback loop that pulls in:
- Customer complaints
- CAPAs and nonconformances
- Post-market surveillance data
This information feeds back into a living risk management file, not a document you finish and shelve. A device cleared five years ago with a clean risk file can develop new hazardous situations as usage patterns or components change.
ISO 14971 Versions and Regulatory Recognition
The standard has moved through three main versions:
- 1998 — Predecessor document (ISO 14971-1), limited to risk analysis only
- 2007 — Second edition, now withdrawn
- 2019 — Third edition, current, reconfirmed by ISO in 2025
For manufacturers selling into Europe, the relevant version is EN ISO 14971:2019+A11:2021. This amendment, harmonized under EU Decision 2022/757, adds Annex Z tables mapping the standard's clauses to MDR and IVDR general safety and performance requirements. It does not change the underlying technical content. It only documents how the standard satisfies specific regulatory articles.
One more document worth knowing: ISO/TR 24971, published in 2020, is a companion guidance report. It's non-mandatory, but it helps manufacturers interpret ISO 14971's requirements and select appropriate risk analysis techniques. Use it when you need practical interpretation of what the standard requires and which risk analysis techniques fit.
How ISO 14971 Fits Into Your Broader QMS
ISO 14971 doesn't operate in isolation. It sits inside a larger compliance ecosystem, and understanding the boundaries between these frameworks saves teams from duplicating effort or missing requirements.
ISO 14971 vs. ISO 13485: ISO 13485 defines quality management system requirements and explicitly calls for a risk-based approach throughout design, production, and post-market controls. ISO 14971 supplies the actual risk management process that ISO 13485 references. They're complementary, not interchangeable. Conformance to one doesn't automatically prove conformance to the other.
ISO 14971 vs. ISO 31000: ISO 31000 offers generic risk management guidance for any organization, regardless of industry. It's not sector-specific and isn't built to produce evidence for regulatory submissions. ISO 14971, by contrast, is medical-device-specific, focused squarely on patient and user safety, and structured to generate the documentation regulators actually recognize.

Reading the standard is one thing. Applying it under real audit pressure, with a hazard analysis a reviewer can actually follow, is another.
That gap is what QMS Learning's upcoming Medical Device & Life Sciences QMS pathway is built to close. It bundles ISO 13485, FDA 21 CFR Part 820, ISO 14971 risk management, and HIPAA privacy and security into one program.
The ISO 14971 course walks teams through:
- Hazard identification and risk evaluation
- Risk control and residual-risk acceptability
- Maintaining a living risk file through post-market surveillance
The AI Workbench is trained to help build risk management plans along the way. The pathway is open for a pilot cohort ahead of its Q3 2026 launch.
Frequently Asked Questions
What is ISO 14971?
ISO 14971 is the international standard for applying risk management to medical devices across their entire lifecycle. It covers everything from hazard identification during design through post-market monitoring after the device ships.
What are ISO 13485 and ISO 14971?
ISO 13485 governs the overall quality management system for medical device organizations. ISO 14971 defines the specific risk management process that ISO 13485 references and requires throughout design, production, and post-market activity.
What is the difference between ISO 31000 and ISO 14971?
ISO 31000 is generic risk management guidance applicable to any organization or industry. ISO 14971 is medical-device-specific, focused on patient and user safety, and structured to produce evidence accepted in regulatory submissions.
What is the current version of ISO 14971?
The current version is ISO 14971:2019. Manufacturers selling into the EU should reference the harmonized EN ISO 14971:2019+A11:2021 amendment, which aligns the standard with MDR and IVDR requirements.
Is ISO 14971 mandatory?
Technically, it's a voluntary consensus standard rather than a law. In practice, regulators including the FDA, EU authorities, Health Canada, TGA, and MHLW all expect manufacturers to demonstrate conformance to it.
What is a risk management file?
A risk management file is the living collection of records documenting hazard identification, risk evaluation, control measures, and post-market monitoring for a device. It's updated continuously, not compiled once and closed.


