ISO 14971 risk management built for you
ISO 14971 defines how medical device risks are identified, evaluated and controlled throughout the life cycle. We build the process and prepare the risk management file for your device.
You receive a risk management plan, risk analysis, residual risk evaluation and post-production information collection as one coherent whole, directly linked to your technical documentation and MDR requirements.
Fixed project price and a clear schedule - you know the cost before work begins.
How it works
Assessment of the current state and device
Risk management plan
Risk management file prepared for you
Ready for assessment
- No empty risk tables
- No disconnected Excel file
- No inconsistencies between documents
What is ISO 14971?
ISO 14971 is the international standard defining the risk management process for medical devices. It does not specify which risks are acceptable, but how manufacturers identify hazards, evaluate risks, implement control measures and monitor their effectiveness throughout the product life cycle. The standard is harmonised with the MDR and has become the established practical way to demonstrate compliance with the Regulation's risk management requirements.
A process, not a document
The standard requires an ongoing process: risk management starts during design and does not end when the product is placed on the market.
Justified acceptability
Every residual risk must be evaluated and justified in relation to the clinical benefit of the device - not simply assigned a numerical rating.
Coverage throughout the life cycle
Information gathered from production and the market feeds back into the risk analysis and updates it regularly.
ISO 14971 is not a risk table, but a controlled procedure that must also be reflected in device design and instructions for use.
We build risk management that stands up to assessment
Risk management most often fails because the analysis has been carried out separately from product development and other documentation. We create the process and documents so that they reflect the actual device and connect with your other documentation.
We prepare the risk management plan and risk acceptability criteria
We carry out hazard analysis and risk assessment for your device
We prepare the risk management file and report
We support you with notified body questions and requests for additional information
You do not need to interpret the standard yourself or guess whether the analysis is sufficient for assessment.
What ISO 14971 requires in practice
Risk management in accordance with the standard progresses in stages, and each stage must leave evidence in the risk management file. Below are the areas every manufacturer needs to address.
Risk management plan
The plan defines the scope, responsibilities, risk acceptability criteria and how the process is monitored. Without documented criteria, risk assessment cannot be justified.
- Scope, device description and life cycle stages
- Risk acceptability criteria and assessment scales
- Roles, responsibilities and review procedure
The plan is prepared before the analysis - not afterwards to justify it.
Hazard identification and risk assessment
Hazards associated with the device, its use and its use environment are identified, and the probability and severity of resulting harm are evaluated.
- Intended purpose, reasonably foreseeable misuse and safety characteristics
- Systematic review of hazardous situations and chains of harm
- Risk assessment using agreed criteria
Use errors and software operation are also within the scope of the analysis.
Risk control measures
Risks are reduced according to the standard's order of priority: first inherently safe design, then protective measures, and only lastly information provided to the user.
- Selection and justification of control measures according to the order of priority
- Verification of implementation and evaluation of effectiveness
- Review of new or transferred risks
A warning in the instructions for use alone is not sufficient as a control measure if the risk can be addressed through design.
Residual risks and benefit-risk ratio
Risks remaining after control measures are evaluated both individually and collectively, and weighed against the clinical benefit of the device.
- Evaluation and justification of individual residual risks
- Evaluation and acceptance of overall residual risk
- Information provided to users about remaining risks
The benefit-risk justification must be consistent with the clinical evaluation.
Production and post-market monitoring
Risk management continues after the device is placed on the market. Information from production, feedback and incidents is evaluated and fed back into the risk analysis.
- Information collection procedures and sources
- Evaluation of collected information against the risk assessment
- Updating the risk management file and control measures
The same information also supports the post-market surveillance required by the MDR.
We build these stages into a coherent file in which every risk is traceable to a control measure and verification.
What effective risk management delivers for you
Risk management is not only a requirement, but a tool that improves your product and speeds up assessment.
Meeting MDR requirements
ISO 14971 covers the MDR risk management requirements and produces the documentation that a notified body expects to see.
A safer product
A systematic review of hazards reveals design flaws when they can still be corrected cost-effectively.
Smoother assessment
A traceable and justified risk management file reduces requests for additional information and shortens assessment lead times.
When risk management is in order, it also supports clinical evaluation, usability engineering and product development.
Who is our risk management service for?
Our service is designed for manufacturers of medical devices and software that need to demonstrate compliance with risk management requirements.
It is particularly suitable when:
We help both start-ups certifying their first device and manufacturers with multiple product families.
How we build your risk management
We take risk management through clear stages, so you always know where things stand and what we need from you.
Assessment
We review the device, its intended purpose and existing documentation, and define what risk management requires in your case.
“A clear view of requirements and gaps.”
Analysis and documentation
We prepare the plan, identify hazards together with your experts, and write the risk management file and justifications for control measures.
“We write it, you confirm it.”
Review and implementation
We review the complete package, link it to the technical documentation and agree on monitoring procedures after placing the device on the market.
“A complete package that stands up to scrutiny.”
We also agree on how the risk management file will be kept up to date as the product changes and feedback is received.
The most common mistakes in risk management
The same shortcomings recur in assessments year after year. They can be avoided when the process is designed correctly from the outset.
Risk analysis as an afterthought
The analysis is carried out only after design has been completed, so it no longer guides the product but merely justifies choices already made.
Warnings as control measures
Risks are addressed with warnings in the instructions for use, even though the standard primarily requires inherently safe design.
A disconnected risk management file
The risk analysis does not correspond with the clinical evaluation, instructions for use or technical documentation, which almost certainly leads to a request for additional information.
Traceability from risk to control measure and verification is just as important as the content of the analysis.
Fixed price, predictable project
We price risk management as a project based on the device classification and scope. You know the cost before work begins.
Fixed project price for the agreed scope
Clearly defined scope and delivery schedule
Scope tailored to the device risk class
Maintenance and updates agreed separately
You receive a quotation showing what will be done, by when and what it will cost.
Why MDRpankki?
We combine regulatory expertise with ready-made structures, so your risk management is developed faster than starting from scratch.
Regulatory expertise
We understand ISO 14971, the MDR and notified body expectations in practical terms.
Turnkey delivery
We are responsible for the outcome, not just the hours worked: an assessment-ready risk management file.
Practical approach
We make risk management something that guides product development rather than remaining on a shelf.
Your team focuses on the product, while we take care of risk management documentation.
Talk to a risk management expert
Together, we will assess the current state of your device risk management and what ISO 14971 specifically requires for your product.

Frequently asked questions about ISO 14971
- ISO 14971 is a standard that defines the risk management process for medical devices. In practice, this means that the manufacturer identifies hazards associated with the device, evaluates the resulting risks, implements control measures, justifies remaining risks against clinical benefit and monitors the situation after the device is placed on the market. All of this must leave documented evidence in the risk management file.
- The standard itself is voluntary, but the MDR requires documented risk management throughout the life cycle. ISO 14971 is a harmonised standard, so following it is the established and notified body-expected way to demonstrate that this requirement has been met. It is possible to use another approach, but its equivalence must then be justified separately.
- ISO 14971:2019 clarified, among other things, the evaluation of the benefit-risk ratio, the treatment of overall residual risk, and requirements for production and post-production information collection. Guidance was moved to a separate publication, ISO/TR 24971. Analyses prepared according to an earlier version usually require updating, particularly regarding residual risk justifications and monitoring procedures.
- ISO 13485 describes the quality management system and requires risk management to be part of it. ISO 14971, in turn, explains how risk management is implemented in practice. They complement each other: the quality management system defines the existence of the procedure and responsibilities, while the risk management standard defines its content.
- Typically, from a few weeks to a few months. The schedule is affected by the device risk class and complexity, the role of software, and how much analysis has already been completed. We need time from your experts to identify hazards; we do the rest for you.
- Yes. We prepare the plan, analysis and risk management report for you. We need information from you about the device and its use, as well as your experts' participation in hazard identification, because product knowledge is invaluable in this work. You review and approve the outcome, and we also support you throughout the assessment.
What does ISO 14971 mean in practice?+
Is ISO 14971 mandatory?+
What changed in the 2019 version?+
How does ISO 14971 relate to ISO 13485?+
How long does it take to build risk management?+
Can you manage the entire risk management process for us?+
Explore also
MDR requirements, quality management, risk management and clinical evidence form one whole. Learn more about each element.
ISO 13485 quality management system
The quality management system required by MDR in practice: processes, documentation and audit readiness.
Read more →MDR regulation (2017/745)
What the regulation requires from manufacturers, how devices are classified and which route demonstrates conformity.
Read more →MDR documentation
Technical documentation, the GSPR matrix and the documentation required under Annexes II-III as one whole.
Read more →Clinical evaluation
Collection of clinical evidence, the CER report and PMCF as part of the technical documentation.
Read more →