Skip to content
CROSSWALK

ISO 14971 §5.4, 5.5

WHAT CARRIES OVER

Systematic hazard analysis — hazard, hazardous situation, harm chain — with probability and severity estimated for each hazardous situation using the categorization system recorded in the risk management file.

WHAT’S NEW

Normal-condition hazards must be included; “reasonably foreseeable misuse” is now a defined term requiring explicit hazard identification beyond fault conditions.

AUDIT FOCUS

Pre-control estimation — risk scores must reflect uncontrolled hazardous situations; estimates done after controls are applied are routinely rejected.

Maps to

ISO 14971: §5.4 Identification of hazards and hazardous situations, §5.5 Risk estimation

ISO 13485: §7.1 Planning of product realization

Pre-QMSR Part 820: §820.30(g) Design validation.

Requirement text

The manufacturer shall identify and document known and foreseeable hazards associated with the medical device based on the intended use, reasonably foreseeable misuse and the characteristics related to safety in both normal and fault conditions, then estimate the probability of harm occurrence and the severity of that harm for each hazardous situation.

ISO 14971:2019 — ISO catalogue

Why this clause exists

The conceptual distinction between a hazard, a hazardous situation, and a harm is not pedantic — it is the mechanism by which risk estimation becomes defensible rather than arbitrary. A manufacturer who conflates "needle" (hazard) with "needlestick injury" (harm) skips the intermediate step of the hazardous situation, and therefore cannot separately estimate the probability that the hazard leads to exposure versus the probability that exposure leads to injury. ISO 14971 clause 5.4 requires the full three-element chain because each link has a different probability that can be influenced by different control measures. The additional requirement to analyze normal-condition hazards reflects lessons drawn from incidents where devices performed as designed yet still caused harm — an inherently sharp edge or an electromagnetic emission that exists in normal operation presents a real hazard regardless of whether a fault has occurred. Without systematic analysis spanning both normal and fault conditions, hazard identification is structurally incomplete.

What changed

ISO 14971:2019 was a major revision reorganizing the standard from 9 to 10 clauses and moving extensive guidance material into a separate technical report (ISO/TR 24971:2020), making normative requirements clearer and more auditable.

Guidance on risk-acceptability policy moved into an informative NOTE: clause 4.2 NOTE 1 lists reducing risk as low as reasonably practicable (ALARP), as low as reasonably achievable (ALARA), and as far as possible (AFAP) without adversely affecting the benefit-risk ratio as approaches a manufacturer's policy can define. None of the three replaced the others, and the standard mandates no single one of them. Benefit-risk analysis became its own subclause (7.4) with a mandatory record, and three new definitions were added (benefit, reasonably foreseeable misuse, state of the art). Criteria for risk acceptability are a required element of the risk management plan (4.4 d)), and clause 6 evaluates risks against the criteria defined in that plan — though NOTE 4 to clause 4.4 states the plan or parts of it can be developed over time.

Post-production requirements (Clause 10) were substantially expanded into four sub-clauses (Establish, Collect, Review, Act), mandating active collection and review of post-market data rather than passive complaint handling. The overall residual risk evaluation (Clause 8) is a distinct step: the manufacturer evaluates the overall residual risk taking into account the contributions of all residual risks, in relation to the benefits of the intended use, against the method and criteria set in the plan. Clause 4.3 shifted emphasis from personnel qualifications to demonstrated competence. ISO/TR 24971:2020 (informative companion) adds Annex G (cybersecurity risk management) and Annex H (legacy device risk file remediation).

Common gaps (what we see in audits)

  • Hazard identification scope incompleteHazard identification must systematically cover design, materials, manufacturing, user interaction, environmental factors, intended use, AND reasonably foreseeable misuse. Teams often focus on technical failure modes and miss hazards arising from foreseeable human behavior, use environments, and normal-condition hazards where the device functions as designed but is inherently hazardous.
  • Risk estimation done after controls, not beforeTeams estimate risk in the context of their complete system with controls in place, rather than evaluating inherent risk first. Risk evaluation must be based on what could happen without controls — control effectiveness is evaluated separately during risk control verification.

Related clauses

Join the waitlist to check your documents against this clause →

Further reading

A free compliance scan is coming.

No credit card. No sales call. No consultants required.

We'll notify you when the scanner launches. No spam.