ISO 14971 · Risk

ISO 14971 risk management software connected to your evidence

ISO 14971 risk management software helps manufacturers run the process defined in ISO 14971:2019: plan risk management, identify hazards and hazardous situations, estimate and evaluate risks, implement and verify risk controls, evaluate overall residual risk and keep the risk file updated with production and post-production information. MDR Annex I Sections 1 to 9 make this process mandatory for every device. In MDRpilot the risk file sits next to the GSPR matrix and the evidence files, so a verified test report can close a risk control directly.

Who it is for

  • Risk managers and design engineers
  • Quality teams maintaining risk files for several devices
  • Manufacturers whose risk file was written once and never updated

Key capabilities

  • Risk management plan

    Scope, responsibilities, acceptability policy and review frequency, drafted from your company and product data.

  • Risk items

    Hazard, hazardous situation, harm, severity, probability, risk level and controls in an FMEA-style table.

  • Verification of control

    A passing test report confirmed against a risk item is recorded as verification of that control.

  • Link to post-market

    Complaints and CAPA records sit in the same workspace, so post-production information can be reviewed against the risk file.

  • XLSX export

    Export the risk file for review and submission.

The ISO 14971:2019 process in short

ClauseActivity
4Risk management process, management responsibilities, competence, risk management plan and file
5Risk analysis: intended use, safety characteristics, hazards, hazardous situations, risk estimation
6Risk evaluation against the acceptability criteria in the plan
7Risk control: option analysis, implementation, verification, residual risk, benefit-risk, new risks
8Evaluation of overall residual risk
9Risk management review before release
10Production and post-production activities

Where risk files usually fail an audit

  • Risk controls listed without evidence that they were implemented and verified
  • Acceptability criteria missing from the plan, or applied inconsistently
  • No link between complaints, PMS data and risk estimates
  • IFU warnings used as the only risk control for risks that could be reduced by design

How the workflow runs

  1. 1

    Plan

    Set acceptability criteria and responsibilities.

  2. 2

    Analyse

    Record hazards and hazardous situations from the intended use.

  3. 3

    Control

    Add controls and link the evidence that verifies them.

  4. 4

    Review

    Evaluate overall residual risk and benefit-risk.

  5. 5

    Monitor

    Feed complaints and PMS findings back into the file.

Connected to the rest of the file

MDRpilot is not a stand-alone document generator. Requirements, evidence and documents share one product record.

  1. Requirements
  2. Evidence
  3. Documents
  4. Risk
  5. Clinical
  6. PMS
  7. QMS
  8. Audit

Each step reads from the same product record. A test report linked to a GSPR row can verify a risk control, a change to the device class flags the documents that depend on it, and the audit readiness view counts what is still open across all of them.

Limitations

  • MDRpilot does not set your acceptability criteria; ISO 14971 requires the manufacturer to define them.
  • Probability and severity estimates are your team's judgement; AI suggestions must be reviewed.
  • ISO 14971 is a copyrighted standard. MDRpilot refers to its structure but does not reproduce its text.

MDRpilot is documentation and workflow software. It is not a medical device, not a notified body and not a regulatory authority. It does not certify devices or guarantee compliance; AI-generated drafts must be reviewed and approved by qualified people in the manufacturer's organisation.

Frequently asked questions

Is ISO 14971 mandatory under MDR?

MDR requires a risk management system (Article 10 and Annex I). EN ISO 14971:2019 with amendment A11:2021 is the harmonised standard most manufacturers use to demonstrate it.

Does MDRpilot support FMEA?

Yes. Risk items can be recorded in an FMEA-style table with severity, probability and controls.

Can a test report close a risk control?

A passing test report that you confirm against a risk item is recorded as verification of the control. A failing report is not linked.

Does MDRpilot calculate risk acceptability?

It calculates a risk level from low to critical using severity multiplied by probability. Whether a residual risk is acceptable is decided by your team against the criteria in your risk management plan.

How does risk management connect to PMS?

ISO 14971 clause 10 and MDR Article 83 require post-production information to be fed back. In MDRpilot complaints, CAPA and PMS documents are in the same workspace as the risk file.

References

  1. ISO 14971:2019 Medical devices — Application of risk management to medical devices — International Organization for Standardization.
  2. Regulation (EU) 2017/745 on medical devices (MDR) — EUR-Lex, Publications Office of the European Union.

Always check the consolidated text of the regulation and the current version of each guidance document before relying on it.

See it with your own device

Create an account, add your company and one real device. The Suite demo runs for 3 days and the first procedure opens straight away, not an empty dashboard.