The Workbench · Craft

What a risk management file has to prove, hazard by hazard

A risk management file is often built, and audited, as a spreadsheet of hazards with a residual-risk score in the last column. ISO 14971:2019 Clause 4.5 asks for something stricter: traceability, for each identified hazard, through the risk analysis, the risk evaluation, the risk control measures implemented and verified, and the evaluation of the residual risk left once those controls are in place. A file that shows the final score without the chain that produced it hasn't met the clause — it has recorded a conclusion, not the reasoning the standard actually asks to see.

The chain the file has to hold together

ISO 14971:2019 lays the risk management process out as a sequence of clauses, and the file's job is to make each hazard's path through all of them checkable: risk analysis (Clause 5) identifies the hazard and estimates the risk; risk evaluation (Clause 6) judges whether that risk needs reducing; risk control (Clause 7) implements and verifies the measures that reduce it; and residual risk gets evaluated again once those controls are in place. Clause 4.5 is what ties the chain together — it requires the file to provide traceability from the hazard through every one of those steps, not just a start point and an end point with the reasoning left out.

The step most files skip

Clause 8, evaluation of overall residual risk, is a separate requirement from the per-hazard residual evaluations in Clause 7, and it's the one files most often treat as redundant. It asks whether the combined residual risk from the complete set of identified hazards — not any one of them individually — is still acceptable when weighed against the benefits of the device's intended use. A file that clears every individual hazard row and never performs this holistic step has satisfied the easy half of the standard and skipped the judgment call it was building toward. Clause 9's risk management review then closes the file for release: a documented check that the plan was executed, every hazard's chain is complete, and the overall residual risk conclusion is the one being shipped.

The workaround that used to live in Europe alone

For years, the international standard and its European-harmonized version weren't quite the same document where it mattered most. The 2012 European harmonized edition carried content deviations from the international text — among them, language that struck out the option to weigh further risk reduction against economic cost, requiring risk instead to be reduced as far as possible. A device could satisfy the international standard's balancing test everywhere else in the world and still fail that stricter European bar. When the amendment EN ISO 14971:2019/A11:2021 was published, it carried none of those content deviations — the international and European texts of the risk-acceptability requirement are now the same document. What the amendment added instead were two new informative annexes, ZA and ZB, mapping the standard's clauses to the general safety and performance requirements of the MDR and IVDR respectively. A risk file that still treats “the European version” as a separately stricter test is citing a gap that closed in 2021.

What's left to build, and it isn't the risk math

The remaining EU-specific expectation isn't a different risk-acceptability rule — it's the requirement that the file also demonstrate, GSPR by GSPR, how the risk-management output satisfies MDR Annex I. That's the same crosswalk discipline a design file needs to answer to two regulators from one evidence set: build the index once, mapped in both directions, instead of maintaining two files that drift apart the next time either source revises. And a risk file is never really finished at that index either — Clause 10 requires production and post-production information to feed back into the same traceability chain, reopening a hazard's residual-risk conclusion when post-market data suggests it no longer holds, the same discipline that keeps any source-mapped document from going stale between reviews.

A risk management file structured around this chain — per-hazard traceability, the overall residual risk step, and an MDR/IVDR GSPR index built on top rather than as a second file — is previewed in the launch catalog. If your program has a rule for closing this file that ours is missing, the shelf takes that correction directly.

The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.

All Workbench notes