What does an auditor check for ISO 14971?
Notified body audits, FDA inspections, and common Risk Management File gaps
The short answer
Auditors focus on completeness, traceability, and timing. The most common finding is not that risks were missed, but that the process was not followed correctly — criteria set after the fact, controls not verified, or post-market feedback not connected to the Risk Management File.
What auditors request on day one
A notified body auditor conducting a technical documentation review will typically request the following documents from the Risk Management File at the start of the assessment:
- Risk Management Plan — signed, dated, device-specific
- Risk acceptability criteria — must be in the RMP, approved before the assessment
- Hazard register / FMEA — all identified hazards with estimates
- Risk control records — implementation and verification evidence for each control
- Risk Management Report — summary conclusions on overall residual risk
- Post-market surveillance references — evidence that field data feeds back into RMF
Top 10 ISO 14971 audit findings
| Finding | What is missing | Corrective action |
|---|---|---|
| 1. No Risk Management Plan | No document defining scope, responsibilities, or risk acceptability criteria | Create device-specific RMP signed before risk assessment starts |
| 2. Post-hoc risk criteria | Acceptability matrix modified after risks were estimated to make them appear acceptable | Version-control RMP; demonstrate criteria were set before assessment date |
| 3. Incomplete hazard coverage | Annex C hazard categories not systematically addressed (e.g., software hazards missing for SaMD) | Add Annex C coverage table to hazard identification record |
| 4. Controls not verified | Risk controls listed but no test or evaluation evidence that they are effective | Link each control to a verification record (test report, usability study, etc.) |
| 5. No re-estimation after controls | Initial risk scores never updated after controls were applied | Add residual risk columns to FMEA; document updated probability/severity |
| 6. Missing overall residual risk | Individual residual risks evaluated but no §7 overall assessment document | Add Overall Residual Risk Evaluation section to Risk Management Report |
| 7. No benefit-risk justification for ALARP risks | Risks in ALARP region declared acceptable without any ALARP or benefit-risk reasoning | Add explicit ALARP justification or benefit-risk analysis for each ALARP-region risk |
| 8. Post-market data not integrated | Post-market surveillance reports exist but are not connected to the Risk Management File | Establish documented procedure for PMS data review and RMF update |
| 9. Controls introduce new risks — not analyzed | Risk controls added without checking whether they create new hazards | Add §6.8 "new risks from controls" review to each control record |
| 10. Residual risks not in IFU | Known residual risks requiring user awareness not disclosed in Instructions for Use | Cross-reference each residual risk requiring disclosure to the corresponding IFU section |
Notified body (NB) audit focus — EU MDR
Notified bodies conducting EU MDR technical documentation assessments pay particular attention to:
- ZA annex compliance: Evidence that all R1–R8 requirements from EN ISO 14971:2019 are met
- Benefit-risk ratio: Consistency between the clinical evaluation report and the risk management benefit-risk conclusion
- State of the art: Whether the acceptable risk level is consistent with similar devices currently on the market
- PMS integration: Whether periodic safety update reports (PSURs) demonstrate actual feedback into the RMF
- Serious incidents: Whether any post-market serious incidents have triggered RMF updates
FDA inspection focus
FDA investigators conducting Design Control (21 CFR 820.30) inspections typically look for:
- Risk analysis document in the Design History File
- Traceability from risk analysis outputs to design requirements and verification testing
- Risk analysis review as part of design transfer and design changes
- Complaint handling procedures that link field complaints to the risk management process
- Design change records showing risk impact assessment for each change
CAPA triggers from risk management gaps
ISO 14971 findings can trigger Corrective and Preventive Action (CAPA) processes. Common triggers:
- Post-market complaint reveals an unidentified hazard → hazard analysis must be updated
- Field CAPA reveals a risk control was ineffective → control must be re-evaluated and re-verified
- Design change introduces a new component → risk analysis must be updated for changed scope
- New clinical data changes understanding of harm severity or probability → RMF review required
- Regulatory guidance update (e.g., new MDCG guidance) changes interpretation of requirements → RMP review
Documentation traceability that auditors test
Auditors frequently perform trace exercises — starting from a hazard in the hazard log and tracing through:
- Hazard identification record (source: FMEA, Annex C coverage)
- Risk estimate (initial severity × probability → risk score)
- Risk control(s) implemented
- Verification evidence for each control
- Residual risk re-estimate
- Acceptability decision documented
- If residual risk requires disclosure → corresponding IFU section
If any link in this chain is broken or undocumented, it is a finding — regardless of whether the actual device design is safe.