What is ISO 14971 and who must comply?

ISO 14971:2019 · Third edition · Scope and applicability

The short answer

ISO 14971:2019 is the international standard for risk management of medical devices. Any manufacturer placing a medical device on the market — hardware, software (SaMD), IVD, or accessory — must apply a documented risk management process that satisfies ISO 14971.

Definition and purpose

ISO 14971 specifies a process by which manufacturers identify hazards associated with medical devices, estimate and evaluate the associated risks, control those risks, and monitor the effectiveness of the controls throughout the device lifecycle. The standard does not prescribe specific risk acceptability criteria — manufacturers must define their own criteria in a Risk Management Plan before the assessment begins.

The third edition (2019) introduced more explicit requirements for the benefit-risk determination, clarified the probability of harm model (P1 × P2 = probability of hazardous situation × probability of leading to harm), and added explicit production and post-production obligations.

Scope: who and what is covered

Device typeCovered by ISO 14971?Notes
Hardware medical devices (EU MDR Class I–III)YesFull lifecycle, all risk classes
Software as a Medical Device (SaMD)YesIncluding apps, cloud AI, decision support
In vitro diagnostic devices (IVDs)YesVia EN ISO 14971:2019 / IVDR Annex I
Accessories to medical devicesYesRisk management required per accessory
Combination products (drug-device)PartiallyDevice component requires ISO 14971; drug component has separate requirements
General wellness apps (non-medical)NoNo medical intended purpose means no regulatory obligation

Regulatory basis: why it is mandatory

EU MDR / IVDR

Annex I of Regulation (EU) 2017/745 sets out the general safety and performance requirements, risk management among them. EN ISO 14971:2019, as amended by EN ISO 14971:2019/A11:2021, is listed as a harmonised standard under the MDR: complying with it creates a presumption of conformity — but only for the requirements its Annex ZA (informative) says it covers, and only as far as it covers them. Which those are for your device is something you read in your own licensed copy; we do not reproduce the content here.

FDA (21 CFR Part 820)

The FDA Design Controls regulation (21 CFR 820.30) requires risk analysis as part of design and development planning. FDA recognizes ISO 14971 as a consensus standard and accepts declarations of conformity in 510(k) and PMA submissions. The FDA Software Guidance and de Novo Decision Summary documents routinely reference ISO 14971 compliance.

Key concepts

TermISO 14971:2019 definition
HazardPotential source of harm
Hazardous situationCircumstance in which people, property, or the environment is exposed to one or more hazards
HarmPhysical injury or damage to health of people, or damage to property or the environment
RiskCombination of the probability of occurrence of harm and the severity of that harm
Risk management file (RMF)Set of records and other documents produced by the risk management process
Risk management plan (RMP)Document defining scope, responsibilities, and risk acceptability criteria for the device

The risk management lifecycle

ISO 14971 describes risk management as a lifecycle activity — not a one-time documentation exercise. The process has five phases:

  1. Risk management planning — define scope, team, criteria
  2. Risk analysis — identify hazards and estimate probability/severity
  3. Risk evaluation — compare to acceptability criteria
  4. Risk control — implement measures, verify effectiveness
  5. Residual risk and overall evaluation — assess remaining risks, benefit-risk

Post-production surveillance feeds new field data back into the risk management file, making risk management a continuous loop rather than a discrete project phase.

EN ISO 14971:2019 vs. ISO 14971:2019

EN ISO 14971:2019 is the European adoption of the international standard, published by CEN/CENELEC. The difference from the international version lies in the European annexes: Annex ZA (Regulation (EU) 2017/745) and Annex ZB (Regulation (EU) 2017/746), both informative. They set out how far the standard covers the general safety and performance requirements in Annex I of the respective Regulation — and where it does not. The presumption of conformity holds for as long as the standard's reference remains on the list published in the Official Journal. So check the list in force for which edition it carries — and which edition your technical documentation names.

Relationship to IEC 62304 and ISO 13485

ISO 14971 does not exist in isolation. IEC 62304 §7 explicitly requires software risk management activities to be integrated with the ISO 14971 process — the software safety class determination depends on the severity of harm identified in the ISO 14971 hazard analysis. ISO 13485 requires that risk management processes are embedded in the quality management system and documented in the design and development procedures.

Free ISO 14971 Risk Management File Tool

Estimate initial and residual risk for your hazards in minutes.

Assess my risk →