Skip to content
Assyro AI
Back to Glossary
Medical Devices

ISO 14971

ISO 14971 is the international consensus standard for applying risk management to medical devices, covering the identification, evaluation, and control of risk to patients and users across the product lifecycle rather than at a single design stage.

Usage Examples

  • The risk management file per ISO 14971 goes in the 510(k), not in a folder we open the week before submission.
  • That complaint trend has to go back into the ISO 14971 analysis before we close the CAPA.
  • We declared conformity to ANSI/AAMI/ISO 14971, so the standard is now an inspection target, not a suggestion.

What is ISO 14971?

ISO 14971 is the international consensus standard for applying risk management to medical devices, covering the identification, evaluation, and control of risk to patients and users across the product lifecycle rather than at a single design stage.

ISO 14971 exists because the hazard that reaches a patient is usually not the one nobody imagined. It is the one somebody identified, judged acceptable, and never revisited after launch. ISO 14971 forces that judgement into a documented chain a reviewer can walk: hazard, foreseeable sequence of events, harm, estimated risk, control measure, residual risk, and the evidence behind each link.

ISO 14971 covers risk arising from the device itself to patients, users, and other persons, from hazard identification through risk control to what production and the field later reveal. ISO 14971 stops short of telling you what is acceptable. It mandates no particular analysis technique and supplies no numeric thresholds, so the manufacturer defines and justifies the acceptability criteria in the risk management plan.

ISO 14971 is applied as a live process inside the quality system, not a document assembled before a submission. FDA declined to incorporate ISO 14971 when it amended part 820, so conformity is voluntary even where the underlying risk obligation is not. ISO 14971 output still has to show hazards traced to controls, controls to verification evidence, and post-market data returning to the analysis.

Not to be confused with

ISO 13485
ISO 13485 is the quality management system standard FDA incorporated by reference into 21 CFR Part 820. ISO 14971 is the risk process for a specific device, and FDA deliberately left it out of that incorporation.
21 CFR Part 820 (QMSR)
the QMSR is the enforceable US rule; ISO 14971 is a voluntary consensus standard. An investigator writes an observation against Part 820, not against ISO 14971 itself.
FMEA
FMEA is a bottom-up failure-analysis technique used inside the process, not the process itself. It starts from component failure modes, so hazards that arise while the device works exactly as designed, such as use error, fall outside its reach.
ISO/TR 24971
a technical report offering guidance on applying ISO 14971. It carries no requirements, so there is nothing in it to certify or declare conformity against.

ISO 14971 is voluntary. The obligations it is used to discharge are not, and these are the anchors that make it enforceable in the US.

What you must do

  1. 1Operate a quality management system meeting the amended device CGMP requirements, which incorporate ISO 13485 by reference21 CFR Part 820
  2. 2Meet those amended part 820 requirements from the rule's effective date of 2 February 2026QMSR final rule, FR Doc. 2024-01709 (effective date)
  3. 3Carry risk management and risk-based decision making across the whole quality system rather than confining it to a design-phase deliverableQMSR final rule, FR Doc. 2024-01709 (risk management)
  4. 4Anchor the risk programme to the amended part 820 requirements rather than to ISO 14971 conformity, because FDA declined to incorporate the standard in that rulemakingQMSR final rule, FR Doc. 2024-01709 (ISO 14971 not incorporated)
  5. 5Provide a declaration of conformity certifying the device conforms to the standard whenever you elect to use an FDA-recognized standard to meet a premarket submission requirement21 U.S.C. 360d(c)

Common mistakes

  • Assuming the QMSR made ISO 14971 mandatory

    FDA stated in the final rule that it does not incorporate ISO 14971 or the other standards ISO 13485 references. Teams that cite the standard as their legal basis have the chain backwards, and they inherit an argument they cannot win in an inspection.

  • Freezing the risk file at clearance

    the QMSR spreads risk management throughout the quality system, so a file with no production or post-market input after launch contradicts the regulation you are actually held to. It also converts an ordinary complaint trend into a documented failure to act.

  • Declaring conformity casually

    a declaration of conformity is a certification to FDA under 21 U.S.C. 360d(c), and you may submit your own data instead. Declaring without a complete, current risk management file creates exposure that submitting that evidence would have avoided.

When This Matters

  • The risk management file per ISO 14971 goes in the 510(k), not in a folder we open the week before submission.
  • That complaint trend has to go back into the ISO 14971 analysis before we close the CAPA.
  • We declared conformity to ANSI/AAMI/ISO 14971, so the standard is now an inspection target, not a suggestion.

Frequently Asked Questions

No US regulation makes ISO 14971 mandatory. FDA stated in the QMSR final rule that it does not incorporate ISO 14971 or the other standards ISO 13485 references. Risk management itself is still required, because the QMSR carries it throughout the quality system, and EU MDR Article 10(2) requires a documented risk management system outright.

Related Use Cases

Related Regulatory Intelligence

Related Actions

Sources & References

Share this page
Agent CTA Background

Simplify ISO 14971 compliance