MSI's ISO Risk Management Procedure Template

Combined ISO 9001 and 13485 Integrated Risk Management Procedure Template

$249

One risk management procedure covering quality management system risk and medical device product risk — with the two scopes determined, the two registers kept apart, and every divergence between the standards decided and recorded in an integration decision record.

The gap this closes

Organizations holding both certificates usually run two risk systems that never speak to each other — a register owned by quality, a risk management file owned by design or regulatory, different vocabulary, different scales, and the same exposure sitting in both, rated differently, with neither owner aware of the other entry.

One risk management procedure covering quality management system risk and medical device product risk — written as a finished working document, not an outline.

Combining them is not a matter of merging two spreadsheets, because the standards genuinely differ in more places than the obvious one.

ISO 9001 requires opportunities to be determined. ISO 13485 has no opportunity concept anywhere in the standard. ISO 9001 requires actions proportionate to the impact on conformity; ISO 14971 requires risk reduced as far as possible and then judged against benefit. Those are different tests and they can produce different answers about the same exposure.

Scope determination comes first

Section 2.0 resolves, per product line, whether you are in general scope, device scope, or uncertain — with uncertain defaulting to device scope pending a documented determination. That last category is where most contract manufacturers, component suppliers and software providers actually sit, and it is usually resolved in about an hour once somebody asks the question.

The interface separate systems do not have

A process risk that could reach a device should change a probability estimate in a risk management file. In two disconnected systems there is no route by which it ever does. Section 7.13 is that route, running in both directions, and it is one field on a form.

The procedure also keeps the two records apart. A notified body reviewing a risk management file will not accept it interleaved with business risk. Share the process; keep the records separate; link them with a flag.

Appendix D is why this variant exists

Eleven genuine divergences, each with what ISO 9001 says, what ISO 13485 and ISO 14971 say, which position was adopted as the house standard, and what was rejected and why — followed by a sign-off table of decisions to confirm before adoption. It is the part a buyer cannot easily assemble alone, and it is what a certification body will ask about.

What is in it

  • Section 2.0 — scope determination first, three-way per product line, with uncertain defaulting to device scope pending a documented determination.
  • Two distinct rating scales, deliberately different in length so a rating cannot be transcribed between them by accident.
  • Section 7.13 — the device-reach flag, the single interface two separate systems do not have, running in both directions.
  • Section 7.12 — risk routes owned by other procedures, covering contract review, the supplier change-notification agreement, and the retrospective product assessment, with both standards' clauses cited.
  • The seven risk-based determinations ISO 13485 requires in proportion to risk, indexed with their rationales.
  • Hazardous situation analysis on the device side — hazard, sequence of events, hazardous situation and harm kept distinct.
  • Opportunity applied across the quality scope, held in the register and never in the risk management file, because ISO 13485 has no opportunity concept.
  • Benefit-risk and overall residual risk, judged for the device as a whole rather than summed from the parts.
  • Figure 1 — process interaction map covering both scopes.
  • A records table with no blanks, with device retention set separately from quality management system retention.
  • Appendix A — the registers and the file, kept separate and linked by flag. Appendix B — treatment plan with a cross-system field. Appendix C — desk-level work instruction with a worked example following one exposure through both systems.
  • Appendix D — the integration decision record: eleven divergences, eleven decisions, one sign-off table.
  • Appendix E — criteria and plan worksheet. Appendix F — the QMSR and the regulatory overlay.

Buying ahead of the ISO 9001:2026 launch

ISO has confirmed that ISO 9001:2026 launches on Wednesday 16 September 2026, with a three-year transition expected. Buy this template now and the aligned revision is sent to you free when MSI issues it. You get a working procedure today and the updated one when it matters, without buying twice.

Specification

StandardsISO 9001:2015 and ISO 13485:2016
MethodISO 14971:2019 (referenced, not reproduced)
ClausesISO 9001 Clauses 6.1 and 4.4.1; ISO 13485 Clause 7.1, with 4.1.2 b), 4.1.5, 4.1.6, 7.2 to 7.6 and 8.2.1
Length56 pages
FormatMicrosoft Word (.docx), fully editable
DeliveryInstant download
LicensePerpetual, non-exclusive license for your organization to edit, rebrand and adopt across your own sites
UpdatesFree update to the ISO 9001:2026 alignment when MSI issues it

Who it is for

Quality and regulatory leaders at organizations holding both ISO 9001 and ISO 13485, contract manufacturers running general industrial and device lines on shared assets, and consultants supporting dual-certified clients. Particularly useful for suppliers who sit inside a customer's device quality system by contract and are not certain whether they are in device scope.

Written from what repeats. Diana Lynn has attended more than 200 certification and surveillance audits across 28 years, supporting more than 80 certifications and training more than 600 professionals. These templates encode the structural weaknesses that show up again and again, not one organization's approach generalized. Management Systems International is veteran-owned and female-owned. Questions: 760-434-9141.

Prefer to be invoiced? If your organization buys on a purchase order rather than by card, email [email protected] or call 760-434-9141 and we will raise an invoice. Tell us which templates or package you need and we will send payment terms the same working day.


Other options in this family

If this is not the right combination

Every variant covers one certification combination, so you buy the one document that matches your certificates rather than assembling it from singles.

The full documentation package

This procedure is one document in a wider system. If you are building or rebuilding the whole documentation set rather than filling a single gap, the packages below collect the procedures and guides, and work out considerably cheaper than buying them individually.