Systematic hazard analysis — hazard, hazardous situation, harm chain — with probability and severity estimated for each hazardous situation using the categorization system recorded in the risk management file.
Normal-condition hazards must be included; “reasonably foreseeable misuse” is now a defined term requiring explicit hazard identification beyond fault conditions.
Pre-control estimation — risk scores must reflect uncontrolled hazardous situations; estimates done after controls are applied are routinely rejected.
Maps to
ISO 14971: §5.4 Identification of hazards and hazardous situations, §5.5 Risk estimation
ISO 13485: §7.1 Planning of product realization
Pre-QMSR Part 820: §820.30(g) Design validation.
Requirement text
The manufacturer shall identify and document known and foreseeable hazards associated with the medical device based on the intended use, reasonably foreseeable misuse and the characteristics related to safety in both normal and fault conditions, then estimate the probability of harm occurrence and the severity of that harm for each hazardous situation.
Why this clause exists
The conceptual distinction between a hazard, a hazardous situation, and a harm is not pedantic — it is the mechanism by which risk estimation becomes defensible rather than arbitrary. A manufacturer who conflates "needle" (hazard) with "needlestick injury" (harm) skips the intermediate step of the hazardous situation, and therefore cannot separately estimate the probability that the hazard leads to exposure versus the probability that exposure leads to injury. ISO 14971 clause 5.4 requires the full three-element chain because each link has a different probability that can be influenced by different control measures. The additional requirement to analyze normal-condition hazards reflects lessons drawn from incidents where devices performed as designed yet still caused harm — an inherently sharp edge or an electromagnetic emission that exists in normal operation presents a real hazard regardless of whether a fault has occurred. Without systematic analysis spanning both normal and fault conditions, hazard identification is structurally incomplete.
What changed
ISO 14971:2019 was a major revision reorganizing the standard from 9 to 10 clauses and moving extensive guidance material into a separate technical report (ISO/TR 24971:2020), making normative requirements clearer and more auditable.
Guidance on risk-acceptability policy moved into an informative NOTE: clause 4.2 NOTE 1 lists reducing risk as low as reasonably practicable (ALARP), as low as reasonably achievable (ALARA), and as far as possible (AFAP) without adversely affecting the benefit-risk ratio as approaches a manufacturer's policy can define. None of the three replaced the others, and the standard mandates no single one of them. Benefit-risk analysis became its own subclause (7.4) with a mandatory record, and three new definitions were added (benefit, reasonably foreseeable misuse, state of the art). Criteria for risk acceptability are a required element of the risk management plan (4.4 d)), and clause 6 evaluates risks against the criteria defined in that plan — though NOTE 4 to clause 4.4 states the plan or parts of it can be developed over time.
Post-production requirements (Clause 10) were substantially expanded into four sub-clauses (Establish, Collect, Review, Act), mandating active collection and review of post-market data rather than passive complaint handling. The overall residual risk evaluation (Clause 8) is a distinct step: the manufacturer evaluates the overall residual risk taking into account the contributions of all residual risks, in relation to the benefits of the intended use, against the method and criteria set in the plan. Clause 4.3 shifted emphasis from personnel qualifications to demonstrated competence. ISO/TR 24971:2020 (informative companion) adds Annex G (cybersecurity risk management) and Annex H (legacy device risk file remediation).
Common gaps (what we see in audits)
- Hazard identification scope incomplete — Hazard identification must systematically cover design, materials, manufacturing, user interaction, environmental factors, intended use, AND reasonably foreseeable misuse. Teams often focus on technical failure modes and miss hazards arising from foreseeable human behavior, use environments, and normal-condition hazards where the device functions as designed but is inherently hazardous.
- Risk estimation done after controls, not before — Teams estimate risk in the context of their complete system with controls in place, rather than evaluating inherent risk first. Risk evaluation must be based on what could happen without controls — control effectiveness is evaluated separately during risk control verification.
Related clauses
Join the waitlist to check your documents against this clause →