The gap this closes
ISO 14971 does not ask for failure modes. It asks for hazardous situations — the circumstance in which a person is exposed to a hazard — and for the sequence of events that produces one. A file full of failure modes does not contain the analysis a notified body is looking for.
A complete, editable ISO 13485:2016 Clause 7.1 risk management procedure built on ISO 14971:2019 — written as a finished working document, not an outline.
Most device risk procedures are a design FMEA with a different cover sheet. A hazard with no sequence written out cannot be estimated, and an assessment that lists what can fail has not yet said who is exposed, doing what, and what harm follows. Those are different documents, and only one of them is the analysis.
The requirement sits at the top of Clause 7, in the planning subclause, so it governs everything beneath it rather than living as a design deliverable. Product realization is the whole of Clause 7 — customer-related processes at 7.2, design at 7.3, purchasing at 7.4, production and service provision at 7.5, and monitoring and measuring equipment at 7.6.
That is why this procedure includes a section devoted to the routes it does not own. Contract review, the supplier change-notification agreement, and the retrospective assessment triggered by an out-of-tolerance instrument each carry a risk decision, each is executed inside another procedure, and each is named here with its trigger, its record and its owner. A risk practice confined to design projects satisfies part of one subclause and leaves the rest of Clause 7 unevidenced.
ISO 13485 requires seven decisions to be made in proportion to risk: supplier evaluation criteria at 7.4.1, verification of purchased product at 7.4.3, outsourcing controls and quality agreements at 4.1.5, three separate software validation requirements, and the extent of design verification.
Each is decided competently in most organizations and recorded as a risk-based decision in almost none. When an investigator asks for the risk basis of your software validation approach, most organizations have the right answer and no evidence of it. Section 7.11 and Appendix A.4 make it producible.
The Quality Management System Regulation took effect on 2 February 2026, incorporating ISO 13485:2016 into 21 CFR Part 820 by reference. The exclusion that kept management review records, internal audit reports and supplier audit reports out of routine review was not carried forward. Risk records are expected across production, purchasing and labeling — including for Class I devices exempt from design controls, where organizations most often conclude risk management does not apply to them.
| Standard | ISO 13485:2016, Clause 7.1 |
|---|---|
| Method | ISO 14971:2019 (referenced, not reproduced) |
| Also covers | Clauses 4.1.2 b), 4.1.5, 4.1.6, 7.3, 7.4, 7.5.6, 7.6, 8.2.1 |
| Length | 40 pages |
| Format | Microsoft Word (.docx), fully editable |
| Delivery | Instant download |
| License | Perpetual, non-exclusive license for your organization to edit, rebrand and adopt across your own sites |
| Regulatory | Appendix F covers the QMSR, in force since 2 February 2026. Purchase of the applicable standards remains the user's responsibility |
Quality and regulatory professionals at medical device manufacturers, contract manufacturers and component suppliers working to ISO 13485:2016, and consultants supporting them. Particularly useful for organizations preparing for their first inspection under the QMSR, for anyone whose risk file has not been revised since design transfer, and for Class I manufacturers exempt from design controls who have concluded risk management does not reach them.
Written from what repeats. Diana Lynn has attended more than 200 certification and surveillance audits across 28 years, supporting more than 80 certifications and training more than 600 professionals. These templates encode the structural weaknesses that show up again and again, not one organization's approach generalized. Management Systems International is veteran-owned and female-owned. Questions: 760-434-9141.
Prefer to be invoiced? If your organization buys on a purchase order rather than by card, email [email protected] or call 760-434-9141 and we will raise an invoice. Tell us which templates or package you need and we will send payment terms the same working day.
Every variant covers one certification combination, so you buy the one document that matches your certificates rather than assembling it from singles.
This procedure is one document in a wider system. If you are building or rebuilding the whole documentation set rather than filling a single gap, the packages below collect the procedures and guides, and work out considerably cheaper than buying them individually.
Notifications