What is ISO 14971?
ISO 14971 ("Medical devices — Application of risk management to medical devices") is a standard published by the International Organization for Standardization, developed jointly with the IEC. The current, third edition dates from December 2019; it is accompanied by the ISO/TR 24971 guidance document with practical application advice. In Europe the standard exists as EN ISO 14971 and is harmonised with the MDR and IVDR regulations, providing a presumption of conformity with the corresponding requirements of those regulations.
Unlike ISO 27001 or ISO 13485, ISO 14971 is not a management system standard — it is a process standard. It contains no control catalogue like Annex A and no high-level structure (Annex SL). Its requirements are the mandatory activities of the process (clauses 4-10) and evidence artefacts, above all the risk management plan and the risk management file. A defining feature is that it imposes no risk matrix and no acceptability thresholds — the manufacturer defines its own criteria in a top management policy and in the plan, and must then apply them consistently.
Who is it for?
The standard is addressed to manufacturers of medical devices of every kind — equipment, implants, in vitro diagnostic devices and standalone medical software. It is formally voluntary, but in practice unavoidable: the MDR requires the manufacturer to operate a risk management system per Annex I chapter I, and ISO 14971 is the harmonised, widely recognised way to meet that requirement. Regulators outside the EU have analogous expectations — the US FDA recognises ISO 14971 as a consensus standard.
For companies building medical software ISO 14971 is particularly important, because it is the "risk engine" directly referenced by IEC 62304 (the medical device software life cycle — software safety classification is based on 14971 risk analysis) and ISO 13485 (the quality management system). One well-maintained risk management file therefore simultaneously feeds MDR conformity, the ISO 13485 audit and the software life cycle documentation.
What does the risk management process look like?
The process forms a loop spanning the entire device life cycle. Clause 4 lays the foundations: a documented process, a risk acceptability criteria policy approved by top management, competent personnel, a risk management plan for each device, and a risk management file providing traceability for every hazard.
Clause 5 is risk analysis: defining the intended use and reasonably foreseeable misuse, identifying safety-related characteristics, identifying hazards and hazardous situations, and estimating risk. Clause 6 evaluates risks against the plan criteria. Clause 7 is risk control with a mandatory hierarchy of measures: inherently safe design first, then protective measures, and information for safety last; it also covers benefit-risk analysis for unacceptable risks, analysis of risks introduced by the control measures themselves, and a completeness check. Clause 8 requires evaluating the overall residual risk of the device as a whole, clause 9 a risk management review before commercial release, and clause 10 closes the loop: actively collecting production and post-production data, reviewing it for safety relevance and acting on it.
Relationship to the MDR, ISO 13485 & IEC 62304
ISO 14971 rarely stands alone — it is the link connecting the medical device regulatory ecosystem:
- MDR (EU) 2017/745 — Annex I chapter I requires a life cycle risk management system; a risk management file per ISO 14971 is the standard evidence. Mind the difference: the MDR does not allow information given to users to reduce the estimated risk, and a benefit-risk analysis is required for every risk, not only unacceptable ones.
- ISO 13485 — the quality management system requires risk management in product realisation (clause 7.1) and refers directly to ISO 14971; the ISO 13485 auditor assesses the risk management file during the QMS audit.
- IEC 62304 — the software safety classification (classes A/B/C), which sets the rigour of the entire software life cycle, follows directly from the risk analysis performed per ISO 14971.
- ISO/TR 24971 — the official guidance for applying ISO 14971, with example questions for identifying safety characteristics and advice on acceptability criteria.
How is conformity assessed?
ISO 14971 has no standalone certification scheme — organisations do not receive an "ISO 14971 certificate" the way they receive an ISO 27001 or ISO 13485 certificate. Conformity is assessed indirectly but very thoroughly: the certification body auditor during the ISO 13485 audit, and notified body reviewers during the MDR conformity assessment, examine the risk management plan and file, checking process completeness and hazard traceability.
In practice assessors perform a trace: they pick several hazards and follow the trail from identification, through estimation and evaluation, to control measures, their verification evidence (implementation and effectiveness — two separate proofs) and the residual risk evaluation. The most frequent findings are: no distinct overall residual risk evaluation (reinforced in the 2019 edition), control measures without effectiveness verification, acceptability criteria changed mid-project, and a dead post-production loop — complaint data that never returns to the risk analysis.
How does Guardiso help?
Guardiso turns the ISO 14971 process requirements into a step-by-step system — with a risk register, evidence and a post-production loop that do not drift apart across Excel files.
- Clause 4-10 requirements seeded as controls when you enable the framework — from the policy and plan, through risk analysis and control, to the review and the post-production phase — with statuses and owners.
- A free maturity self-assessment of the risk management process, with hints on what the auditor looks for in the risk management file.
- A risk register with a configurable methodology: your own severity and likelihood scales and acceptability thresholds — in line with the philosophy of the standard, which imposes no matrix.
- Traceability hazard → evaluation → control measure → verification → residual risk, exactly the loop the auditor will trace through the file.
- Recurring tasks for the post-production loop — production and market data reviews at planned intervals, with evidence of execution.
- Cross-mapping to the MDR, ISO 13485, IEC 62304 and ISO 27001 — one risk process feeds multiple frameworks at once.
