MSI's ISO Risk Management Procedure Template

ISO 13485 Risk Management Procedure Template

$149

A complete, editable ISO 13485 Clause 7.1 risk procedure — written as a working document, not an outline. Includes the criteria-setting worksheet, the process interaction map, and the opportunity route almost no register has.

The gap this closes

ISO 14971 does not ask for failure modes. It asks for hazardous situations — the circumstance in which a person is exposed to a hazard — and for the sequence of events that produces one. A file full of failure modes does not contain the analysis a notified body is looking for.

A complete, editable ISO 13485:2016 Clause 7.1 risk management procedure built on ISO 14971:2019 — written as a finished working document, not an outline.

Most device risk procedures are a design FMEA with a different cover sheet. A hazard with no sequence written out cannot be estimated, and an assessment that lists what can fail has not yet said who is exposed, doing what, and what harm follows. Those are different documents, and only one of them is the analysis.

Clause 7.1 is not a design clause

The requirement sits at the top of Clause 7, in the planning subclause, so it governs everything beneath it rather than living as a design deliverable. Product realization is the whole of Clause 7 — customer-related processes at 7.2, design at 7.3, purchasing at 7.4, production and service provision at 7.5, and monitoring and measuring equipment at 7.6.

That is why this procedure includes a section devoted to the routes it does not own. Contract review, the supplier change-notification agreement, and the retrospective assessment triggered by an out-of-tolerance instrument each carry a risk decision, each is executed inside another procedure, and each is named here with its trigger, its record and its owner. A risk practice confined to design projects satisfies part of one subclause and leaves the rest of Clause 7 unevidenced.

The seven determinations almost nobody records

ISO 13485 requires seven decisions to be made in proportion to risk: supplier evaluation criteria at 7.4.1, verification of purchased product at 7.4.3, outsourcing controls and quality agreements at 4.1.5, three separate software validation requirements, and the extent of design verification.

Each is decided competently in most organizations and recorded as a risk-based decision in almost none. When an investigator asks for the risk basis of your software validation approach, most organizations have the right answer and no evidence of it. Section 7.11 and Appendix A.4 make it producible.

Since February 2026 these records are federally inspectable

The Quality Management System Regulation took effect on 2 February 2026, incorporating ISO 13485:2016 into 21 CFR Part 820 by reference. The exclusion that kept management review records, internal audit reports and supplier audit reports out of routine review was not carried forward. Risk records are expected across production, purchasing and labeling — including for Class I devices exempt from design controls, where organizations most often conclude risk management does not apply to them.

What is in it

  • Complete Clause 7.1 procedure — 40 pages, built on ISO 14971:2019, with the risk management plan, file and report structure.
  • Hazardous situation analysis — hazard, sequence of events, hazardous situation and harm kept distinct, so an estimate has something to rest on.
  • Section 5.0 — Developing this process in your organization, including the acceptability policy top management is required to set.
  • Severity and probability anchors on a device scale, judged against harm, with probability stated as a rate rather than an adjective.
  • Risks arising from risk control measures captured as new entries — the step most often missed.
  • Both verifications, implementation and effectiveness, recorded separately.
  • Benefit-risk analysis and overall residual risk, judged for the device as a whole rather than summed from the parts.
  • Section 7.11 — the seven risk-based determinations, each with what its rationale must state, indexed at Appendix A.4.
  • Section 7.12 — risk routes owned by other procedures, covering contract review at 7.2, the supplier change-notification agreement at 7.4.2, and the retrospective product assessment at 7.6.
  • Production and post-production loop under Clause 8.2.1, with named routes, owners and frequencies.
  • Figure 1 — process interaction map across the device lifecycle, showing how risk reaches purchasing, production and servicing.
  • A records table with no blanks, with device retention set against regulatory requirement rather than a general policy.
  • Appendix A — risk records including the hazard and hazardous situation table. Appendix B — risk control record carrying both verifications. Appendix C — desk-level work instruction with worked examples.
  • Appendix E — risk management plan and acceptability criteria worksheet. Appendix F — the QMSR and the regulatory overlay.

Specification

StandardISO 13485:2016, Clause 7.1
MethodISO 14971:2019 (referenced, not reproduced)
Also coversClauses 4.1.2 b), 4.1.5, 4.1.6, 7.3, 7.4, 7.5.6, 7.6, 8.2.1
Length40 pages
FormatMicrosoft Word (.docx), fully editable
DeliveryInstant download
LicensePerpetual, non-exclusive license for your organization to edit, rebrand and adopt across your own sites
RegulatoryAppendix F covers the QMSR, in force since 2 February 2026. Purchase of the applicable standards remains the user's responsibility

Who it is for

Quality and regulatory professionals at medical device manufacturers, contract manufacturers and component suppliers working to ISO 13485:2016, and consultants supporting them. Particularly useful for organizations preparing for their first inspection under the QMSR, for anyone whose risk file has not been revised since design transfer, and for Class I manufacturers exempt from design controls who have concluded risk management does not reach them.

Written from what repeats. Diana Lynn has attended more than 200 certification and surveillance audits across 28 years, supporting more than 80 certifications and training more than 600 professionals. These templates encode the structural weaknesses that show up again and again, not one organization's approach generalized. Management Systems International is veteran-owned and female-owned. Questions: 760-434-9141.

Prefer to be invoiced? If your organization buys on a purchase order rather than by card, email [email protected] or call 760-434-9141 and we will raise an invoice. Tell us which templates or package you need and we will send payment terms the same working day.


Other options in this family

If this is not the right combination

Every variant covers one certification combination, so you buy the one document that matches your certificates rather than assembling it from singles.

The full documentation package

This procedure is one document in a wider system. If you are building or rebuilding the whole documentation set rather than filling a single gap, the packages below collect the procedures and guides, and work out considerably cheaper than buying them individually.