What is ISO 14971 and who must comply?
ISO 14971:2019 · Third edition · Scope and applicability
The short answer
ISO 14971:2019 is the international standard for risk management of medical devices. Any manufacturer placing a medical device on the market — hardware, software (SaMD), IVD, or accessory — must apply a documented risk management process that satisfies ISO 14971.
Definition and purpose
ISO 14971 specifies a process by which manufacturers identify hazards associated with medical devices, estimate and evaluate the associated risks, control those risks, and monitor the effectiveness of the controls throughout the device lifecycle. The standard does not prescribe specific risk acceptability criteria — manufacturers must define their own criteria in a Risk Management Plan before the assessment begins.
The third edition (2019) introduced more explicit requirements for the benefit-risk determination, clarified the probability of harm model (P1 × P2 = probability of hazardous situation × probability of leading to harm), and added explicit production and post-production obligations.
Scope: who and what is covered
| Device type | Covered by ISO 14971? | Notes |
|---|---|---|
| Hardware medical devices (EU MDR Class I–III) | Yes | Full lifecycle, all risk classes |
| Software as a Medical Device (SaMD) | Yes | Including apps, cloud AI, decision support |
| In vitro diagnostic devices (IVDs) | Yes | Via EN ISO 14971:2019 / IVDR Annex I |
| Accessories to medical devices | Yes | Risk management required per accessory |
| Combination products (drug-device) | Partially | Device component requires ISO 14971; drug component has separate requirements |
| General wellness apps (non-medical) | No | No medical intended purpose means no regulatory obligation |
Regulatory basis: why it is mandatory
EU MDR / IVDR
Annex I of Regulation (EU) 2017/745 sets out the general safety and performance requirements, risk management among them. EN ISO 14971:2019, as amended by EN ISO 14971:2019/A11:2021, is listed as a harmonised standard under the MDR: complying with it creates a presumption of conformity — but only for the requirements its Annex ZA (informative) says it covers, and only as far as it covers them. Which those are for your device is something you read in your own licensed copy; we do not reproduce the content here.
FDA (21 CFR Part 820)
The FDA Design Controls regulation (21 CFR 820.30) requires risk analysis as part of design and development planning. FDA recognizes ISO 14971 as a consensus standard and accepts declarations of conformity in 510(k) and PMA submissions. The FDA Software Guidance and de Novo Decision Summary documents routinely reference ISO 14971 compliance.
Key concepts
| Term | ISO 14971:2019 definition |
|---|---|
| Hazard | Potential source of harm |
| Hazardous situation | Circumstance in which people, property, or the environment is exposed to one or more hazards |
| Harm | Physical injury or damage to health of people, or damage to property or the environment |
| Risk | Combination of the probability of occurrence of harm and the severity of that harm |
| Risk management file (RMF) | Set of records and other documents produced by the risk management process |
| Risk management plan (RMP) | Document defining scope, responsibilities, and risk acceptability criteria for the device |
The risk management lifecycle
ISO 14971 describes risk management as a lifecycle activity — not a one-time documentation exercise. The process has five phases:
- Risk management planning — define scope, team, criteria
- Risk analysis — identify hazards and estimate probability/severity
- Risk evaluation — compare to acceptability criteria
- Risk control — implement measures, verify effectiveness
- Residual risk and overall evaluation — assess remaining risks, benefit-risk
Post-production surveillance feeds new field data back into the risk management file, making risk management a continuous loop rather than a discrete project phase.
EN ISO 14971:2019 vs. ISO 14971:2019
EN ISO 14971:2019 is the European adoption of the international standard, published by CEN/CENELEC. The difference from the international version lies in the European annexes: Annex ZA (Regulation (EU) 2017/745) and Annex ZB (Regulation (EU) 2017/746), both informative. They set out how far the standard covers the general safety and performance requirements in Annex I of the respective Regulation — and where it does not. The presumption of conformity holds for as long as the standard's reference remains on the list published in the Official Journal. So check the list in force for which edition it carries — and which edition your technical documentation names.
Relationship to IEC 62304 and ISO 13485
ISO 14971 does not exist in isolation. IEC 62304 §7 explicitly requires software risk management activities to be integrated with the ISO 14971 process — the software safety class determination depends on the severity of harm identified in the ISO 14971 hazard analysis. ISO 13485 requires that risk management processes are embedded in the quality management system and documented in the design and development procedures.