What is ISO 14971 and who must comply?
ISO 14971:2019 · Third edition · Scope and applicability
The short answer
ISO 14971:2019 is the international standard for risk management of medical devices. Any manufacturer placing a medical device on the market — hardware, software (SaMD), IVD, or accessory — must apply a documented risk management process that satisfies ISO 14971.
Definition and purpose
ISO 14971 specifies a process by which manufacturers identify hazards associated with medical devices, estimate and evaluate the associated risks, control those risks, and monitor the effectiveness of the controls throughout the device lifecycle. The standard does not prescribe specific risk acceptability criteria — manufacturers must define their own criteria in a Risk Management Plan before the assessment begins.
The third edition (2019) introduced more explicit requirements for the benefit-risk determination, clarified the probability of harm model (P1 × P2 = probability of hazardous situation × probability of leading to harm), and added explicit production and post-production obligations.
Scope: who and what is covered
| Device type | Covered by ISO 14971? | Notes |
|---|---|---|
| Hardware medical devices (EU MDR Class I–III) | Yes | Full lifecycle, all risk classes |
| Software as a Medical Device (SaMD) | Yes | Including apps, cloud AI, decision support |
| In vitro diagnostic devices (IVDs) | Yes | Via EN ISO 14971:2019 / IVDR Annex I |
| Accessories to medical devices | Yes | Risk management required per accessory |
| Combination products (drug-device) | Partially | Device component requires ISO 14971; drug component has separate requirements |
| General wellness apps (non-medical) | No | No medical intended purpose means no regulatory obligation |
Regulatory basis: why it is mandatory
EU MDR / IVDR
EU MDR 2017/745 Annex I (General Safety and Performance Requirements), GSPR 8 requires manufacturers to reduce risks as far as possible and to document the risk management process. EN ISO 14971:2019 is the harmonized standard for this requirement — compliance with it creates a presumption of conformity with GSPR 8. The ZA annex of EN ISO 14971:2019 maps specific standard clauses to GSPR requirements.
FDA (21 CFR Part 820)
The FDA Design Controls regulation (21 CFR 820.30) requires risk analysis as part of design and development planning. FDA recognizes ISO 14971 as a consensus standard and accepts declarations of conformity in 510(k) and PMA submissions. The FDA Software Guidance and de Novo Decision Summary documents routinely reference ISO 14971 compliance.
Key concepts
| Term | ISO 14971:2019 definition |
|---|---|
| Hazard | Potential source of harm |
| Hazardous situation | Circumstance in which people, property, or the environment is exposed to one or more hazards |
| Harm | Physical injury or damage to health of people, or damage to property or the environment |
| Risk | Combination of the probability of occurrence of harm and the severity of that harm |
| Risk management file (RMF) | Set of records and other documents produced by the risk management process |
| Risk management plan (RMP) | Document defining scope, responsibilities, and risk acceptability criteria for the device |
The risk management lifecycle
ISO 14971 describes risk management as a lifecycle activity — not a one-time documentation exercise. The process has five phases:
- Risk management planning — define scope, team, criteria (§4)
- Risk analysis — identify hazards and estimate probability/severity (§5–§6.3)
- Risk evaluation — compare to acceptability criteria (§6.4)
- Risk control — implement measures, verify effectiveness (§6.5–§6.9)
- Residual risk and overall evaluation — assess remaining risks, benefit-risk (§7–§9)
Post-production surveillance (§10) feeds new field data back into the risk management file, making risk management a continuous loop rather than a discrete project phase.
EN ISO 14971:2019 vs. ISO 14971:2019
EN ISO 14971:2019 is the European adoption of the international standard, published by CEN/CENELEC. It is identical in technical content to ISO 14971:2019 but includes an additional ZA annex that documents the relationship between the standard's requirements and the EU MDR/IVDR GSPRs. Manufacturers targeting the CE mark should reference EN ISO 14971:2019 to benefit from the presumption of conformity. The standard has been harmonized under both EU MDR and IVDR.
Relationship to IEC 62304 and ISO 13485
ISO 14971 does not exist in isolation. IEC 62304 §7 explicitly requires software risk management activities to be integrated with the ISO 14971 process — the software safety class determination depends on the severity of harm identified in the ISO 14971 hazard analysis. ISO 13485 requires that risk management processes are embedded in the quality management system and documented in the design and development procedures.