Key risk management challenges identified by the interview participants, aligned with the relevant clauses of ISO 14971
| Clause of ISO 14971 | Related sub-clause(s) as applicable | Key issues identified during qualitative interviews |
|---|---|---|
| 3. Terms and definitions | N/A |
|
| 4. General requirements for risk management system | 4.2 Management responsibilities |
|
| 4.4 Risk Management Plan |
| |
| 4.5 Risk Management File |
| |
| 5 Risk analysis | 5.1 Risk analysis process |
|
| 5.2 Intended use and reasonably foreseeable misuse |
| |
| 7 Risk control | 7.2 Implementation of risk control measures |
|
| 8 Evaluation of overall residual risk | N/A |
|
| 10 Production and post-production activities | 10.1–10.4 |
|
| Clause of ISO 14971 | Related sub-clause(s) as applicable | Key issues identified during qualitative interviews |
|---|---|---|
| 3. Terms and definitions | N/A | Boarder definition of harm |
| 4. General requirements for risk management system | 4.2 Management responsibilities | Being able to demonstrate competence Risk Management Policy is confused with the risk acceptability criteria Criteria to support risk reduction as far as possible (AFAP), i.e. how to demonstrate risk controls are effective and sufficient |
| 4.4 Risk Management Plan | Stricter requirements per EU MDR 2017/745, per GSPR 2, “the reduction of risks as far as possible without adversely affecting the benefit–risk ratio.” How to document Risk Acceptability Criteria as part of the Risk Management Plan to satisfy Notified Bodies | |
| 4.5 Risk Management File | Ability to do risk analysis in a manner that provides traceability throughout the entire risk management cycle and as part of the risk management file | |
| 5 Risk analysis | 5.1 Risk analysis process | Overuse of a bottoms-up approach using FMEA as the only tool |
| 5.2 Intended use and reasonably foreseeable misuse | Understanding the boundaries of documenting reasonably foreseeable misuse More challenging for software devices Integration of usability requirements per IEC 62366–1 | |
| 7 Risk control | 7.2 Implementation of risk control measures | The verification of the effectiveness of risk control measures |
| 8 Evaluation of overall residual risk | N/A | The process is not clear in terms of what is required to address the disclosure of residual risk(s) Stricter requirements per EU MDR 2017/745, I.E per GSPR 1, “any risks which may be associated with their use constitute acceptable risks when weighed against the benefits to the patient …” This is also implied per GSPR 2 and GSPR 4 Per EU MDR, a benefit–risk analysis must be completed for both individual and overall residual risks Stricter requirements per EU MDR, i.e. GSPR 4, imply that “Manufacturers shall inform users of any residual risks.” The requirement per Clause 8 states that “the manufacturer shall inform users of significant residual risks.” More guidance is needed regarding the process of completing a benefit–risk analysis; it is currently subjective and dependent on expert opinion Ensuring production risks are captured as part of the benefit–risk analysis |
| 10 Production and post-production activities | 10.1–10.4 | Post-market surveillance is a more intense focus in the 2019 version of the standard Integration of risk management with post market and other elements of the QMS A mindset shift is required from reactive (Vigilance) to proactive monitoring and detection of signals before trends emerge How do we make these risk management systems rather than processes? |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.