Pre-release risk management review confirming all plan activities executed and all controls verified — Risk Management Report approval as mandatory release gate.
Overall residual risk is evaluated in relation to the benefits of the intended use, using a method and acceptance criteria set in the risk management plan — a distinct step from evaluating each residual risk on its own.
Whether the Risk Management Report evaluates the overall residual risk at all. Reports that conclude the overall risk is acceptable because every individual risk was acceptable skip the step.
Maps to
ISO 14971: §8 Evaluation of overall residual risk, §9 Risk management review
ISO 13485: §7.1 Planning of product realization
Pre-QMSR Part 820: §820.30(g) Design validation.
Requirement text
Before releasing the device, the manufacturer shall evaluate the overall residual risk posed by the medical device, taking into account the contributions of all residual risks, in relation to the benefits of the intended use, using the method and the criteria for acceptability of the overall residual risk defined in the risk management plan. When the overall residual risk is judged acceptable, the manufacturer shall inform users of significant residual risks through the accompanying documentation. A risk management review shall confirm all planned activities have been implemented, the overall residual risk is acceptable, and appropriate measures are in place to collect and review information in the production and post-production phases.
Why this clause exists
Individual residual risks can each be within the acceptable zone yet interact in ways that create a new, higher-order hazardous situation — multiple independent alarm conditions, each with tolerable probability, can combine under a single clinical scenario into a pattern that overwhelms a clinician's response capacity. ISO 14971 clause 8 exists precisely because risk management methods such as FMEA evaluate hazards row by row and have no built-in mechanism for detecting combinatorial effects across rows. The aggregate evaluation requirement was substantially strengthened in the 2019 edition after notified bodies repeatedly found that manufacturers' Risk Management Reports contained per-hazard analyses without any statement about the totality of residual risk — a gap that leaves the question every regulator cares about most (is this device safe enough to release?) technically unanswered in the risk file. The mandatory pre-release risk management review functions as the organizational checkpoint that prevents a device from entering distribution before the complete risk picture has been examined by a responsible person with authority to halt release.
What changed
ISO 14971:2019 was a major revision reorganizing the standard from 9 to 10 clauses and moving extensive guidance material into a separate technical report (ISO/TR 24971:2020), making normative requirements clearer and more auditable.
Guidance on risk-acceptability policy moved into an informative NOTE: clause 4.2 NOTE 1 lists reducing risk as low as reasonably practicable (ALARP), as low as reasonably achievable (ALARA), and as far as possible (AFAP) without adversely affecting the benefit-risk ratio as approaches a manufacturer's policy can define. None of the three replaced the others, and the standard mandates no single one of them. Benefit-risk analysis became its own subclause (7.4) with a mandatory record, and three new definitions were added (benefit, reasonably foreseeable misuse, state of the art). Criteria for risk acceptability are a required element of the risk management plan (4.4 d)), and clause 6 evaluates risks against the criteria defined in that plan — though NOTE 4 to clause 4.4 states the plan or parts of it can be developed over time.
Post-production requirements (Clause 10) were substantially expanded into four sub-clauses (Establish, Collect, Review, Act), mandating active collection and review of post-market data rather than passive complaint handling. The overall residual risk evaluation (Clause 8) is a distinct step: the manufacturer evaluates the overall residual risk taking into account the contributions of all residual risks, in relation to the benefits of the intended use, against the method and criteria set in the plan. Clause 4.3 shifted emphasis from personnel qualifications to demonstrated competence. ISO/TR 24971:2020 (informative companion) adds Annex G (cybersecurity risk management) and Annex H (legacy device risk file remediation).
Common gaps (what we see in audits)
- No aggregate overall residual risk assessment performed — Clause 8 requires the overall residual risk to be evaluated taking into account the contributions of all residual risks, in relation to the benefits of the intended use, against the method and acceptance criteria defined in the risk management plan. Many manufacturers evaluate residual risks individually but never assess whether the totality is acceptable — a report that infers overall acceptability from individually acceptable risks has not performed the clause 8 step.
Related clauses
Join the waitlist to check your documents against this clause →