What does an auditor check for ISO 14971?

Notified body audits, FDA inspections, and common Risk Management File gaps

The short answer

Auditors focus on completeness, traceability, and timing. The most common finding is not that risks were missed, but that the process was not followed correctly — criteria set after the fact, controls not verified, or post-market feedback not connected to the Risk Management File.

What auditors request on day one

A notified body auditor conducting a technical documentation review will typically request the following documents from the Risk Management File at the start of the assessment:

  • Risk Management Plan — signed, dated, device-specific
  • Risk acceptability criteria — must be in the RMP, approved before the assessment
  • Hazard register / FMEA — all identified hazards with estimates
  • Risk control records — implementation and verification evidence for each control
  • Risk Management Report — summary conclusions on overall residual risk
  • Post-market surveillance references — evidence that field data feeds back into RMF

Top 10 ISO 14971 audit findings

FindingWhat is missingCorrective action
1. No Risk Management PlanNo document defining scope, responsibilities, or risk acceptability criteriaCreate device-specific RMP signed before risk assessment starts
2. Post-hoc risk criteriaAcceptability matrix modified after risks were estimated to make them appear acceptableVersion-control RMP; demonstrate criteria were set before assessment date
3. Incomplete hazard coverageAnnex C hazard categories not systematically addressed (e.g., software hazards missing for SaMD)Add Annex C coverage table to hazard identification record
4. Controls not verifiedRisk controls listed but no test or evaluation evidence that they are effectiveLink each control to a verification record (test report, usability study, etc.)
5. No re-estimation after controlsInitial risk scores never updated after controls were appliedAdd residual risk columns to FMEA; document updated probability/severity
6. Missing overall residual riskIndividual residual risks evaluated but no §7 overall assessment documentAdd Overall Residual Risk Evaluation section to Risk Management Report
7. No benefit-risk justification for ALARP risksRisks in ALARP region declared acceptable without any ALARP or benefit-risk reasoningAdd explicit ALARP justification or benefit-risk analysis for each ALARP-region risk
8. Post-market data not integratedPost-market surveillance reports exist but are not connected to the Risk Management FileEstablish documented procedure for PMS data review and RMF update
9. Controls introduce new risks — not analyzedRisk controls added without checking whether they create new hazardsAdd §6.8 "new risks from controls" review to each control record
10. Residual risks not in IFUKnown residual risks requiring user awareness not disclosed in Instructions for UseCross-reference each residual risk requiring disclosure to the corresponding IFU section

Notified body (NB) audit focus — EU MDR

Notified bodies conducting EU MDR technical documentation assessments pay particular attention to:

  • ZA annex compliance: Evidence that all R1–R8 requirements from EN ISO 14971:2019 are met
  • Benefit-risk ratio: Consistency between the clinical evaluation report and the risk management benefit-risk conclusion
  • State of the art: Whether the acceptable risk level is consistent with similar devices currently on the market
  • PMS integration: Whether periodic safety update reports (PSURs) demonstrate actual feedback into the RMF
  • Serious incidents: Whether any post-market serious incidents have triggered RMF updates

FDA inspection focus

FDA investigators conducting Design Control (21 CFR 820.30) inspections typically look for:

  • Risk analysis document in the Design History File
  • Traceability from risk analysis outputs to design requirements and verification testing
  • Risk analysis review as part of design transfer and design changes
  • Complaint handling procedures that link field complaints to the risk management process
  • Design change records showing risk impact assessment for each change

CAPA triggers from risk management gaps

ISO 14971 findings can trigger Corrective and Preventive Action (CAPA) processes. Common triggers:

  • Post-market complaint reveals an unidentified hazard → hazard analysis must be updated
  • Field CAPA reveals a risk control was ineffective → control must be re-evaluated and re-verified
  • Design change introduces a new component → risk analysis must be updated for changed scope
  • New clinical data changes understanding of harm severity or probability → RMF review required
  • Regulatory guidance update (e.g., new MDCG guidance) changes interpretation of requirements → RMP review

Documentation traceability that auditors test

Auditors frequently perform trace exercises — starting from a hazard in the hazard log and tracing through:

  1. Hazard identification record (source: FMEA, Annex C coverage)
  2. Risk estimate (initial severity × probability → risk score)
  3. Risk control(s) implemented
  4. Verification evidence for each control
  5. Residual risk re-estimate
  6. Acceptability decision documented
  7. If residual risk requires disclosure → corresponding IFU section

If any link in this chain is broken or undocumented, it is a finding — regardless of whether the actual device design is safe.

Generate audit-ready risk assessment records

Use the risk matrix tool to create structured risk estimates with required actions.

Assess my risk →