Explicit acceptable/unacceptable determination for each hazardous situation, compared against the Risk Management Plan acceptance matrix — unacceptable risks mandate control.
Clause 6 is explicit that once a risk is judged acceptable, clauses 7.1 to 7.5 need not be applied to it and the estimated risk is treated as residual risk. A manufacturer whose own policy adopts an as-far-as-possible approach (one of three options in clause 4.2 NOTE 1) takes on that further-reduction expectation from its policy, not from clause 6.
Device-specific risk matrix — generic company-wide matrices without clinical-context calibration are a common rejection point for notified bodies.
Maps to
ISO 14971: §6 Risk evaluation
ISO 13485: §7.1 Planning of product realization
Pre-QMSR Part 820: §820.30(g) Design validation.
Requirement text
The manufacturer shall compare the estimated risk for each hazardous situation against the acceptability criteria established in the risk management plan. If the risk is acceptable, it is not required to apply risk control measures to this hazardous situation and the estimated risk shall be treated as residual risk. If the risk is not acceptable, the manufacturer shall perform risk control activities.
Why this clause exists
Risk evaluation is the decision gate that converts numerical estimates into action obligations — without an explicit acceptable/unacceptable determination for each hazardous situation, a risk analysis remains a descriptive exercise rather than a driver of design decisions. Manufacturers who skip formal risk evaluation or record only risk scores without acceptability conclusions leave auditors with no evidence that the risk management process actually governed design choices. What makes the determination auditable is that it runs against criteria fixed in advance: clause 6 evaluates each risk against the acceptability criteria defined in the risk management plan, and those criteria derive from the risk-acceptability policy top management is required to define and document under clause 4.2. An acceptability call with no traceable criterion behind it is the gap auditors find.
What changed
ISO 14971:2019 was a major revision reorganizing the standard from 9 to 10 clauses and moving extensive guidance material into a separate technical report (ISO/TR 24971:2020), making normative requirements clearer and more auditable.
Guidance on risk-acceptability policy moved into an informative NOTE: clause 4.2 NOTE 1 lists reducing risk as low as reasonably practicable (ALARP), as low as reasonably achievable (ALARA), and as far as possible (AFAP) without adversely affecting the benefit-risk ratio as approaches a manufacturer's policy can define. None of the three replaced the others, and the standard mandates no single one of them. Benefit-risk analysis became its own subclause (7.4) with a mandatory record, and three new definitions were added (benefit, reasonably foreseeable misuse, state of the art). Criteria for risk acceptability are a required element of the risk management plan (4.4 d)), and clause 6 evaluates risks against the criteria defined in that plan — though NOTE 4 to clause 4.4 states the plan or parts of it can be developed over time.
Post-production requirements (Clause 10) were substantially expanded into four sub-clauses (Establish, Collect, Review, Act), mandating active collection and review of post-market data rather than passive complaint handling. The overall residual risk evaluation (Clause 8) is a distinct step: the manufacturer evaluates the overall residual risk taking into account the contributions of all residual risks, in relation to the benefits of the intended use, against the method and criteria set in the plan. Clause 4.3 shifted emphasis from personnel qualifications to demonstrated competence. ISO/TR 24971:2020 (informative companion) adds Annex G (cybersecurity risk management) and Annex H (legacy device risk file remediation).
Common gaps (what we see in audits)
- Generic risk acceptability matrices used across all products — Risk acceptability criteria are rejected when they are generic matrices used identically across all products without adjustment for clinical context, device class, or current state of the art. Auditors expect risk criteria tailored to the specific device's intended use, patient population, and clinical environment.
Related clauses
Join the waitlist to check your documents against this clause →