Medical device risk management

Risk management under ISO 14971 runs across the device lifecycle. At Perdigó Medical we author the risk management plan and carry out the analyses within it: hazard identification, design and process FMEA, fault tree analysis, use-related and software risk analysis, and the risk control tracing that follows.

All Capabilities

Risk management at Perdigó Medical

Risk management establishes what could go wrong with a device, how severe the resulting harm would be, how likely it is, and what in the design prevents it. ISO 14971 is the normative standard. ISO/TR 24971:2020 is its companion guidance, written to the same clause structure and numbering so that each piece of guidance sits against the requirement it explains.

The process exchanges information with the other engineering disciplines in both directions. Use-related hazards identified under IEC 62366-1 enter the risk analysis, and the resulting risk controls return as user interface requirements. Software hazards set the safety classification under IEC 62304, and the software requirements that follow trace back to the hazards that produced them.

Perdigó drafts the risk management plan and performs the analyses within it. The risk acceptability criteria and the severity and probability scales are applied as your quality system defines them.

Perdigó medical device engineer review device technical documentation

Risk management planning and hazard analysis

We draft the risk management plan around the elements ISO 14971 requires:

  • The scope of the planned activities
  • The device and the lifecycle phases each element applies to
  • The responsibilities and authorities
  • The requirements for reviewing the risk management activities
  • The activities that verify the implementation and effectiveness of each risk control measure

The plan is maintained as the design develops, and every analysis that follows is run against it.

A preliminary hazard analysis runs early in development, before the design details are settled. It identifies the hazards, the hazardous situations and the events capable of causing harm, and it informs decisions on architecture, materials and control strategy. Its output is the starting point for the full hazard analysis.

Hazard identification is run as a facilitated exercise with the design team, covering energy, biological, chemical, usability and information hazards. For each hazard we identify the hazardous situations it can lead to, the events that would bring them about, and the harm that could result. Severity and probability are estimated for each hazardous situation, and the risk is evaluated against the acceptability criteria.

FMEA and fault tree analysis

Failure modes and effects analysis works upward from the individual failure. Design FMEA is run at function and component level, taking each failure mode through to its local and system effect, its cause and the available means of detection, ranked by risk priority number or risk index.

Process FMEA covers the manufacturing and assembly processes whose specification we own, with each failure mode linked to the process control and inspection point that addresses it. Both are revised as the design and the process change.

Fault tree analysis works in the opposite direction. It begins from a defined top event, typically a safety-critical function failing or a single-fault condition, and decomposes it through qualitative logic gates to the basic events capable of producing it. We apply it to safety-critical functions where combinations of basic events, rather than any single failure, lead to the top event.

Use-related risk analysis

Use error is a cause of hazardous situations, and it enters the same risk analysis as any other cause. We identify use-related hazards and the hazardous situations they lead to, work each use error to its root cause in perception, cognition or action, and define the interface, labelling or training change that answers it. The analysis is conducted to ISO 14971 and IEC 62366-1, ranked by the severity of the harm a use error could cause, and its output feeds the usability engineering file.

Formative evaluation is run in-house, and its findings return to the analysis and to the user interface specification. Our usability engineering capability covers the full IEC 62366-1 process.

Risk control and verification tracing

Risk control measures are defined in the priority order ISO 14971 sets: inherently safe design and manufacture, then protective measures in the device itself or in the manufacturing process, then information for safety and, where appropriate, training for users. Options are considered in that order for every risk that requires control.

Each control measure becomes a requirement, and each requirement traces to the verification or validation evidence demonstrating that it has been implemented and that it is effective. We build that traceability and maintain it as controls are added, changed or removed.

Software and cybersecurity risk

Software risk analysis starts with classification. Under IEC 62304, the software safety class follows from the severity of the harm the software could contribute to, once the risk controls outside the software are accounted for. From that class we build the traceability from each hazard to the software item and the requirement that controls it. IEC 82304-1 applies to health software sold as a product in its own right.

Security risk is analysed within the same process. The threat model comes first, identifying the assets, the entry points and the threats against them. Each threat is then scored using the method AAMI TIR57 sets out for security risk management under ISO 14971, at the lifecycle stages IEC 81001-5-1 defines. Our embedded software page covers the lifecycle these analyses sit within.

Electrical safety, EMC and essential performance

For medical electrical equipment we analyse electrical, mechanical and thermal hazards, and single-fault conditions. The same analysis covers essential performance, meaning the performance whose loss or degradation would result in unacceptable risk.

Electromagnetic disturbance is analysed against IEC 60601-1-2, covering the emissions the device produces and the immunity it needs in its intended environment.

Each risk is traced to the clause and the test that addresses it, and the analysis defines what that test has to demonstrate. Testing is carried out at a partner facility.

medical device electronics team

Reliability and accelerated life analysis

Reliability and accelerated-life protocols are specified in-house. Each protocol defines what counts as a failure, the stress levels applied and their justification, the sample sizes and the acceptance criteria, with FMEA and FMECA conducted to IEC 60812.

Accelerated ageing, thermal cycling, vibration and environmental stress testing are run on our own climate chamber, thermal-cycling rigs, and vibration rigs. Specialised testing outside that scope is arranged externally.

Results feed back in two directions: into the probability estimates in the risk analysis, and into the reliability figures the design has to meet. A failure mode that occurs during testing returns to the design FMEA with measured data behind it.

accelerate aging chamber for medical devices

Materials and packaging risk

Biological safety hazards are captured in the risk analysis, covering the materials in patient contact, the nature and duration of that contact, and the biological risks arising from the device constituents and their interaction with tissue. ISO 10993-1 sets the requirements, within the same ISO 14971 process.

Chemical characterisation, toxicological assessment and biocompatibility testing are performed by an accredited laboratory, and the results return to the analysis.

For terminally sterilised devices, packaging risk covers the sterile barrier system and the device inside it. We analyse the hazards arising from a breach of the barrier, from handling and distribution, and from material degradation across the claimed shelf life.

For each we specify the validation: packaging system requirements to ISO 11607, distribution simulation to ASTM D4169, and accelerated ageing to ASTM F1980. The ageing and transit studies are executed by an external laboratory.

Perdigó medical device engineers

Developing a medical device?

Talk to our medical device engineers about your development programme. We take devices from concept to market, with risk management running alongside the mechanical, electronics, software and usability work.