NEW SERIES: ISO 14971 Practical Masterclass
Medical Device Insights - Issue #41 June 14, 2026
Hi There, 👋
After completing our ISO 13485, ISO 14971, and EU MDR series, we're back with something different. Not another clause-by-clause theory series. This time: Pure Practical Implementation. Welcome to the ISO 14971 Practical Masterclass!
Why this series?
ISO 14971 risk management is mandatory for every medical device worldwide. It's the difference between audit-ready files and major non-conformities, between defensible decisions and regulatory rejection, between knowing the standard and actually implementing it.
📚 Series Progress: ISO 14971 Practical Masterclass
📍 Issue #41 (Today): Risk Management Planning That Actually Works
⬜ Issue #42: Hazard Identification - Finding Every Risk
⬜ Issue #43: FMEA Done Right
⬜ Issue #44: Risk Evaluation - Making Defensible Decisions
⬜ Issue #45: Risk Controls - Design Safety In
⬜ Issue #46: Residual Risk & Benefit-Risk Analysis
⬜ Issue #47: Post-Production Risk Management
⬜ Issue #48: Building Your Complete Risk Management File
📌 Why Most Risk Management Plans Fail
The uncomfortable truth:
Walk into most medical device companies and ask:
“Can I see your risk management plan?”
What you’ll find:
Generic template downloaded from the internet.
Company name changed, nothing else.
Severity scale copied from another device.
The probability scale nobody understands.
Nobody follows the acceptability criteria.
Nobody has read it since it was approved.
Result:
Risk management = paper exercise.
Auditors find gaps immediately.
Real risks missed.
Devices recalled.
Patients harmed.
This week: Build a risk management plan that actually works.
🎯 What Makes a Risk Management Plan WORK?
The difference:
Paper plan (fails):
Generic
Not specific to your device
Criteria nobody agrees on
Nobody owns it
Never updated
Working plan (succeeds):
Device-specific
The criteria team understands and uses.
Clear ownership
Living document
Actually followed
Simple test:
Ask your risk management team:
“What’s our severity level 3?”
If they can’t answer in 5 seconds → Your plan isn’t working.
🎯 Step 1: Define Your Scope (The Right Way)
What most companies write:
“This plan applies to Device X throughout its lifecycle.”
Why it fails:
What IS Device X exactly?
Which variants?
Which lifecycle phases?
Which markets?
What’s excluded?
What actually works:
Scope must answer 5 questions:
1. What device(s)?
Be specific:
✗ BAD: "Infusion pump"
✓ GOOD: "CardioFlow Infusion Pump Models CF-2000-S
(single channel), CF-2000-D (dual channel), and
CF-2000-P (pediatric). Hardware revision 3.x,
Software versions 2.0-2.x"Why it matters:
Model changes may need separate plans.
Software versions matter for risk.
Hardware revisions may affect hazards.
2. Which lifecycle phases?
✗ BAD: "All lifecycle phases"
✓ GOOD: "Concept through product retirement including:
- Design and development
- Manufacturing and process validation
- Clinical evaluation
- Post-market surveillance
- Product modifications
- Product retirement/disposal"Why it matters:
Each phase has different risk activities.
Missing phases = missed requirements.
Auditors will ask phase-by-phase.
3. What’s IN scope?
✓ GOOD scope inclusions:
- Infusion pump hardware (all models)
- Embedded software (version 2.x)
- IV tubing sets (Models IVT-100, IVT-200)
- Pole mounting bracket (PMB-50)
- User interface and alarm system
- Cleaning and maintenance activities
- Disposal at end of life4. What’s OUT of scope (with rationale)?
✓ GOOD scope exclusions:
- Commercial operating system: Covered by
supplier risk assessment (Supplier RA-001)
- Hospital IT infrastructure: Outside
manufacturer control, addressed in IFU
- Medications infused: Pharmaceutical
responsibility, not device riskCritical: Exclusions need RATIONALE. Not just “we excluded it.”
5. Which markets?
✓ GOOD: "Global markets including EU (MDR 2017/745),
USA (FDA 21 CFR Part 820), and Canada
(CMDR SOR/98-282)"Why it matters:
Different markets have different risk requirements
Benefit-risk may differ by market
Post-market obligations differ
🎯 Step 2: Build Severity Levels That Make Sense
The most common mistake:
Companies copy severity scales from templates without thinking:
✗ GENERIC (doesn't work):
Level 5: Catastrophic
Level 4: Critical
Level 3: Serious
Level 2: Marginal
Level 1: NegligibleProblem: What does “marginal” mean? What makes something “serious” vs “critical”? Nobody agrees.
Build YOUR severity scale:
Three requirements for good severity levels:
1. Clear definitions
2. Specific examples from YOUR device
3. Team agreement
Practical severity scale example:
For infusion pump:
Key principles:
Severity = WORST CREDIBLE OUTCOME (not most likely).
Examples must be YOUR device, YOUR patient population.
The team must agree before starting the analysis.
Clinical experts must validate definitions.
Special consideration: Patient population
Same harm = different severity for different patients:
Example: Loss of device function
Adult ICU patient:
Backup systems available
Staff immediately available
Severity: Serious (3)
Pediatric home patient:
No backup, parents may not notice immediately
Severity: Critical (4)
Your severity scale must reflect YOUR intended patient population
🎯 Step 3: Build Probability Levels That Work
The most common mistake:
Using qualitative probability without numbers:
✗ GENERIC (causes arguments):
Frequent - Will occur often
Probable - Will occur several times
Occasional - May occur
Remote - Unlikely
Improbable - Very unlikelyProblem: “Often” means different things to different people. Arguments during analysis. Inconsistent results.
The fix: Anchor with numbers
Choose what makes sense for your device:
Single-use device → per device lifetime.
Reusable device (used many times) → per procedure.
Implant → per patient lifetime.
How to estimate probability:
Sources (in priority order):
1. Your own data (best):
Field complaint rates
Service call data
Manufacturing defect rates
Test failure rates
Clinical investigation data
2. Similar device data:
Literature on similar devices
FDA MAUDE database
Published clinical data
Industry standards data
3. Expert judgment (when no data):
Cross-functional team assessment
Clinical expert opinion
Engineering analysis
Conservative assumption if uncertain
Document your source:
Probability estimate: Remote (2)
Rationale: Based on component failure rate data
from accelerated life testing (Report ALT-2026-01).
Relay failure rate: 2.3 per million hours =
approximately 1/5,000 over device 10-year lifetime.
Conservative estimate used: Remote (1/10,000)
to account for real-world conditions.🎯 Step 4: Build Your Risk Matrix
Creating your acceptability criteria:
The ALARP principle in practice:
┌─────────────────────────────────────────────┐
│ UNACCEPTABLE (Must reduce, no exceptions) │
├─────────────────────────────────────────────┤
│ ALARP (Reduce if reasonably practicable) │
├─────────────────────────────────────────────┤
│ ACCEPTABLE (May accept with rationale) │
└─────────────────────────────────────────────┘Building your risk matrix:
Step 1: Create 5×5 grid (Severity × Probability)
Step 2: Assign risk levels to each cell
Step 3: Define which levels are acceptable/ALARP/unacceptable
Example risk matrix:
PROBABILITY →
1 2 3 4 5
S 5 │ M │ H │ VH │ VH │ VH │
E 4 │ L │ M │ H │ VH │ VH │
V 3 │ L │ L │ M │ H │ VH │
E 2 │ VL │ L │ L │ M │ H │
R 1 │ VL │ VL │ L │ L │ M │
I
T
Y
↓
VL = Very Low
L = Low
M = Medium
H = High
VH = Very HighAcceptability:
Justifying your matrix:
You must justify WHY you placed acceptability boundaries where you did.
Example justification:
“The risk acceptability criteria have been established considering:
1. Device intended use: Life-sustaining therapy in hospital setting.
2. Patient population: Critically ill adults and pediatric patients.
3. Regulatory requirements: EU MDR Annex I Section 2-3.
4. State of the art: Similar infusion pumps on market.
5. Clinical benefit: Enables precise medication delivery essential for patient outcomes.
Very High risks (Severity 4-5 with Probability 3-5) are unacceptable because potential patient harm (death or permanent injury with significant probability) cannot be justified regardless of benefit.
High risks are in ALARP zone because harm is serious but less certain or less severe, requiring careful evaluation of risk reduction practicability.
Low and Very Low risks are broadly acceptable because combination of low severity and/or low probability represents negligible contribution to overall risk.“
🎯 Step 5: Define Responsibilities (The Right Way)
Most plans fail here:
✗ BAD:
"The Risk Management Team is responsible for
conducting risk management activities."
Who is on the team? What exactly do they do?
Nobody knows.What actually works:
Define specific roles with specific responsibilities:
🎯 Step 6: Plan Your Reviews
When reviews happen:
During development:
Post-production:
🎯 Step 7: Plan Post-Production Activities
What most plans miss:
Plan must define UPFRONT how you’ll manage risks post-launch
Minimum required:
Information sources to monitor:
Decision criteria for risk file update:
Define WHEN risk file must be updated:
Risk file MUST be updated when:
□ New hazard identified not in current analysis
□ Probability estimate changes significantly
(e.g., complaint rate 2x expected)
□ Severity worse than estimated
(e.g., incident more serious than anticipated)
□ Risk control proven ineffective
□ New risk control needed
□ Overall residual risk no longer acceptable
□ Benefit-risk changes significantly
Risk file SHOULD be reviewed (may not need update) when:
□ Minor complaints consistent with known risks
□ Literature confirms existing knowledge
□ No new safety signals identified📊 Series Tracker
📍 Issue #41: Risk Management Planning That Actually Works (Today!)
⬜ Issue #42: Hazard Identification - Finding Every Risk
⬜ Issue #43: FMEA Done Right
⬜ Issue #44: Risk Evaluation - Making Defensible Decisions
⬜ Issue #45: Risk Controls - Design Safety In
⬜ Issue #46: Residual Risk & Benefit-Risk Analysis
⬜ Issue #47: Post-Production Risk Management
⬜ Issue #48: Building Your Complete Risk Management File
👉 Master PMS Interview Topics
This question trips up candidates because it combines multiple expertise areas:
👉 Master PMS Interview Topics
This question trips up candidates because it combines multiple expertise areas:
✅ FDA 21 CFR
✅ EU MDR
✅ ISO 13485
✅ ISO 14971
✅ CAPA & Complaint Handling
✅ Real Case Sudies + Dumy Audit Preperation + Free Podcase
Options:
🟦 eBook only – ₹199
🟥 Live Class + Free eBook – ₹149/hr
💬 DM me on WhatsApp to get your copy of the eBook.
Thanks for reading! Reply and tell me your worst audit finding story - let's learn from each other.
See you next Sunday ✨
– Akash Das
Let’s Connect on LinkedIn ☺️












