Medical device risk management is ISO 14971: find the harms, estimate them, decide if they are acceptable, control what is not, and keep the file alive after launch. It is the safety method. It is not the QMS, and it is not the 510(k) tree.
If you meant QMS / ISO 13485 → medical device quality management system. If you meant PMS → medical device post-market surveillance. If you meant design V&V → medical device verification and validation.
If the device is imaging software, PYCAD is the imaging stack (viewer / model), not the regulatory agent / QMS vendor / GTM shop.
The ISO 14971 loop
| Step | Question | Output |
|---|---|---|
| Analysis | What can go wrong, across the whole life | Hazards, hazardous situations, foreseeable harms |
| Evaluation | Severity × probability vs the plan’s acceptability line | Accept / reduce |
| Control | Design it out, add a guard, then inform — in that order | Implemented controls, ALARP |
| Residual + benefit | What is left, and does the clinical benefit still win | Residual-risk file; benefit–risk if needed |
| Living file | Did the field agree with the estimate | Updates from PMS |
The QMS is the container. QMSR and MDR both expect this loop; they are not a second risk method. Costume chapters about “navigating global frameworks” belong on QMS and FDA approval.
Analysis, then evaluation
Walk the life: make, ship, use, misuse, service, dispose. For a connected AI chest-X-ray reader the list is not only “wrong pixel.” False positive (needless workup). False negative (missed disease). Bias if the training mix is not the catchment. A breach of the study. A lock-up mid-read.
Each hazard gets a severity and a probability. Your Risk Management Plan already said what “unacceptable” means. Evaluation is that comparison, not a new workshop. If it is over the line, you do not ship a warning sticker and call it done.
Control, ALARP, residual
Hierarchy: inherent safety by design, then protective measures, then information for safety. Redesign the sharp edge. Then the interlock. Then the IFU sentence. ALARP means as low as reasonably practicable — zero is not a claim you get to make.
On the chest-X-ray reader: human-in-the-loop before a positive is treated as a diagnosis; a validation set that actually includes the groups you will see; encryption and access control that are tested, not promised. V&V is how you prove a control works — design V&V.
What is left is residual risk. Document it. If it is still high and you cannot design further, write the benefit–risk: why the clinical gain still wins, with evidence. That paragraph is what a reviewer reads when they do not trust a matrix colour.
The file stays open
A complaint, a PMCF signal, a service spike — each one is a chance the probability was wrong. Update the estimate or the control. That feed is PMS. Production and software changes go through the same file, not a side spreadsheet.
FAQ
Is FMEA the same as ISO 14971?
FMEA is a tool you can use inside analysis. 14971 is the process: acceptability criteria, residual risk, benefit–risk, production and post-production information. A spreadsheet of failure modes is not a risk file.
Do we run a separate cyber risk process?
Cyber is a hazard source in the same file (availability, integrity, confidentiality that can harm a patient). You can use a security method to find the issues. You still evaluate and control them here.
If the device is imaging software, PYCAD is the imaging stack (viewer / model), not the regulatory agent / QMS vendor / GTM shop. Case studies.