ISO 14971 and ISO 13485
Many manufacturers initially view ISO 14971 and ISO 13485 as separate regulatory requirements. In practice, they are designed to operate together. Risk management should not exist as a standalone activity; it must be embedded within the Quality Management System so that safety considerations influence every stage of the medical device lifecycle.
ISO 14971 provides the methodology for identifying hazards, estimating and evaluating risks, implementing risk control measures and monitoring residual risks. ISO 13485 ensures these activities are planned, documented, implemented, monitored and continually improved through structured quality processes such as design controls, supplier management, CAPA, internal audits, management review and Post-Market Surveillance.
This article explains how the two standards complement one another, highlights where they overlap throughout the product lifecycle and demonstrates how manufacturers can integrate risk-based thinking into everyday quality management activities.
Need an Introduction to ISO 14971?
This article explains how ISO 14971 and ISO 13485 work together to support medical device compliance. If you're looking for a complete overview of ISO 14971, including risk management planning, hazard identification, risk analysis, risk controls, residual risk evaluation and post-market monitoring, read our Complete Guide to ISO 14971.
Understanding the Relationship Between ISO 14971 and ISO 13485
Although ISO 14971 and ISO 13485 are separate international standards, they are designed to work together. ISO 14971 provides the framework for managing risks associated with medical devices, while ISO 13485 establishes the Quality Management System (QMS) that ensures those risk management activities are consistently planned, implemented, documented and maintained throughout the product lifecycle.
Rather than operating as independent compliance requirements, the two standards are closely interconnected. Every stage of the Quality Management System—from product design and development to supplier management, manufacturing, complaint handling, Post-Market Surveillance (PMS) and continual improvement—either generates information for the Risk Management File or relies upon risk management decisions to ensure patient safety and regulatory compliance.
For example, hazards identified during design feed into design controls, while supplier evaluations consider risks associated with outsourced processes and purchased components. Complaint investigations, vigilance reports and Post-Market Surveillance activities provide real-world evidence that may require manufacturers to reassess risks, update risk control measures or revise the benefit-risk analysis. Likewise, management reviews use quality and safety data to ensure that the Quality Management System remains effective and that risk management activities continue to support the intended purpose of the device.
Understanding this relationship helps manufacturers move beyond treating ISO 14971 as a standalone document. Instead, risk management becomes an integral part of the Quality Management System, influencing decisions throughout the medical device lifecycle and supporting compliance with the EU MDR, UK Medical Devices Regulations and the IVDR.
Comparison Table
| ISO 14971 | ISO 13485 |
|---|---|
| Defines the process for identifying, evaluating and controlling medical device risks. | Defines the Quality Management System that supports those activities. |
| Focuses on patient safety and product risk. | Focuses on organisational processes and quality controls. |
| Produces the Risk Management File. | Produces documented procedures and quality records. |
| Requires continual review of production and post-production information. | Requires complaint handling, CAPA, internal audits and management review. |
| Supports benefit-risk evaluation and residual risk assessment. | Ensures risk management activities are implemented consistently across the organisation. |
Ready to Implement ISO 14971?
Understanding how ISO 14971 and ISO 13485 work together is only the first step. Learn how to develop a Risk Management Plan, identify hazards, perform risk analysis, implement risk controls, maintain a Risk Management File and integrate risk management with your Quality Management System in our ISO 14971 Risk Management Implementation Guide.
How ISO 14971 Integrates with the ISO 13485 Quality Management System
Risk management is not a standalone activity performed only during product development. Under ISO 13485, risk-based thinking should be embedded throughout the Quality Management System, ensuring that decisions affecting the safety, performance and regulatory compliance of a medical device are consistently informed by risk management principles.
Every major QMS process either contributes information to the Risk Management File or relies upon risk assessments to determine appropriate controls. As new information becomes available through design activities, manufacturing, supplier monitoring, customer feedback and Post-Market Surveillance, manufacturers should review whether existing risk evaluations remain valid and update documentation where necessary.
By integrating ISO 14971 into everyday quality processes, manufacturers create a continuous feedback loop that supports patient safety, regulatory compliance and continual improvement throughout the medical device lifecycle.
How the Standards Work Together
| ISO 13485 Process | How ISO 14971 Supports It |
|---|---|
| Design and Development | Identifies hazards, estimates risks and verifies that risk controls are effective before product release. |
| Supplier Management | Evaluates risks associated with purchased components, outsourced processes and critical suppliers. |
| Manufacturing | Uses production data, process validation and quality controls to minimise manufacturing-related risks. |
| Complaint Handling | Investigates customer complaints to determine whether previously identified risks have changed or new hazards have emerged. |
| CAPA | Implements corrective and preventive actions that reduce risk and prevent recurrence of safety issues. |
| Internal Audits | Confirms that risk management activities are implemented in accordance with documented procedures. |
| Management Review | Reviews complaints, PMS data, audit findings and quality metrics to ensure the Risk Management System remains effective. |
| Post-Market Surveillance | Uses production and post-production information to reassess risks, update the Risk Management File and identify opportunities for continual improvement. |
New to ISO 13485?
This article explains how ISO 14971 integrates with an ISO 13485 Quality Management System. If you're looking for a complete introduction to ISO 13485, including Quality Management System requirements, certification, design controls, document control, supplier management, internal audits, CAPA, management review and regulatory compliance, read our Complete Guide to ISO 13485.
Design Controls: Embedding Risk Management into Product Development
Risk management begins long before a medical device reaches the market. During design and development, ISO 14971 provides the structured process for identifying hazards, estimating and evaluating risks, implementing risk control measures and verifying that those controls effectively reduce risks to acceptable levels. ISO 13485 complements these activities by requiring manufacturers to establish documented design control procedures that ensure risk management is embedded throughout product development.
As the device evolves, design inputs, intended purpose, user needs and regulatory requirements all influence the risk management process. Hazards identified during design reviews are documented within the Risk Management File and considered alongside usability engineering, biological evaluation, software development, clinical evaluation and other evidence required to demonstrate the safety and performance of the device.
The relationship between the two standards is particularly important during design verification and validation. ISO 14971 requires manufacturers to confirm that risk control measures are effective and that any residual risks remain acceptable when weighed against the expected clinical benefits. ISO 13485 ensures these activities are planned, documented, independently reviewed where appropriate and incorporated into the Design History File or Technical Documentation.
By integrating risk management into design controls from the earliest stages of development, manufacturers can identify potential safety issues before they become costly design changes, reduce the likelihood of regulatory non-conformities and build stronger evidence to support conformity assessment under the EU MDR, IVDR and UK Medical Devices Regulations.
How ISO 14971 Supports Design Controls
| Design Activity | Integration of ISO 14971 |
|---|---|
| Design Planning | Risk management activities are planned alongside design and development activities. |
| Design Inputs | Intended purpose, user needs, applicable standards and known hazards inform product requirements. |
| Design Reviews | Risk assessments are reviewed as the design matures and new hazards are identified. |
| Design Verification | Confirms that implemented risk control measures perform as intended. |
| Design Validation | Demonstrates that the finished device is safe, effective and suitable for its intended purpose. |
| Design Changes | Any modification is assessed for its impact on existing hazards, residual risks and overall device safety. |
Learn More About IEC 62366-1 Usability Engineering
Effective risk management extends beyond technical performance to how users interact with a medical device. Discover how IEC 62366-1 helps manufacturers identify and reduce use-related risks through human factors engineering, formative evaluations, summative validation and the Usability Engineering File in our IEC 62366-1 Usability Engineering Guide.
Supplier Management and Outsourced Processes
Medical device manufacturers rarely design, manufacture and test every component themselves. Raw materials, electronic assemblies, sterile barrier systems, software development, sterilisation services and laboratory testing are frequently supplied or performed by external organisations. ISO 13485 requires manufacturers to establish robust supplier management processes to ensure that outsourced activities and purchased products consistently meet specified requirements, while ISO 14971 ensures that the risks associated with those suppliers are identified, assessed and appropriately controlled.
Supplier management should begin with a risk-based evaluation of each supplier. Critical suppliers whose products or services could directly affect the safety, performance or regulatory compliance of a medical device should receive greater oversight than suppliers providing low-risk goods or services. Factors such as supplier competence, manufacturing capability, previous performance, certification status and the potential impact of supplier failures should all be considered when determining the level of control required.
Risk management continues throughout the supplier relationship. Manufacturers should monitor supplier performance using objective evidence such as incoming inspection results, non-conformities, delivery performance, audit findings, complaint trends and corrective actions. Where supplier issues could introduce new hazards or increase existing risks, manufacturers should review the Risk Management File and determine whether additional risk control measures or design changes are necessary.
Outsourced processes require the same level of oversight. Although activities such as sterilisation, software development, biological testing or contract manufacturing may be performed by external organisations, the legal responsibility for product safety and regulatory compliance remains with the medical device manufacturer. Effective supplier management therefore forms an essential link between ISO 14971 and ISO 13485, ensuring that quality risks are proactively managed throughout the supply chain and across the entire medical device lifecycle.
How ISO 14971 Supports Supplier Management
| Supplier Management Activity | Integration of ISO 14971 |
|---|---|
| Supplier Selection | Assess suppliers based on the potential impact of their products or services on device safety and performance. |
| Supplier Qualification | Evaluate competence, certifications, capabilities and quality systems before approval. |
| Supplier Monitoring | Review delivery performance, non-conformities, complaints, audits and corrective actions. |
| Outsourced Processes | Identify and control risks associated with sterilisation, software development, testing and contract manufacturing. |
| Supplier Changes | Assess the impact of material, component or process changes on existing hazards and residual risks. |
| Corrective Actions | Investigate supplier-related issues and update risk assessments where necessary. |
Discover Biological Evaluation Under ISO 10993
Biological safety is a key element of medical device risk management. Learn how Biological Evaluation Plans (BEPs), Biological Evaluation Reports (BERs), material characterisation, toxicological risk assessments and ISO 10993 help manufacturers identify and control biological risks throughout the medical device lifecycle in our Biological Evaluation of Medical Devices guide.
Corrective and Preventive Action (CAPA): Driving Continual Risk Improvement
One of the greatest strengths of integrating ISO 14971 with ISO 13485 is the ability to continually improve product safety through an effective Corrective and Preventive Action (CAPA) process. While ISO 14971 requires manufacturers to collect and review production and post-production information, ISO 13485 provides the structured framework for investigating quality issues, implementing corrective actions and preventing similar problems from occurring in the future.
CAPA activities are often triggered by customer complaints, non-conformities, supplier issues, internal audit findings, Post-Market Surveillance (PMS) data, vigilance reports or manufacturing process deviations. Each of these events provides valuable information that may indicate previously unidentified hazards, changes to the probability of harm or the need to reassess the effectiveness of existing risk control measures.
When a safety-related issue is identified, manufacturers should investigate the root cause to determine whether it represents an isolated quality problem or a broader risk that could affect patient safety. The findings should be considered alongside the existing Risk Management File to establish whether the identified hazard has already been assessed, whether residual risks remain acceptable and whether additional risk control measures are required.
Effective CAPA does more than resolve individual issues. Lessons learned should be incorporated into product design, manufacturing processes, supplier management, training programmes and quality procedures so that improvements are sustained across the organisation. This continual feedback loop ensures that risk management evolves as new information becomes available and supports ongoing compliance with ISO 14971, ISO 13485, the EU MDR, IVDR and UK Medical Devices Regulations.
How ISO 14971 Supports CAPA
| CAPA Activity | Integration of ISO 14971 |
|---|---|
| Complaint Investigation | Determines whether reported issues introduce new hazards or alter existing risk assessments. |
| Root Cause Analysis | Identifies the underlying cause of quality or safety issues before corrective actions are implemented. |
| Risk Assessment Review | Reassesses the probability and severity of harm based on new evidence. |
| Corrective Actions | Introduces design, manufacturing or process changes to reduce identified risks. |
| Effectiveness Checks | Verifies that implemented corrective actions have successfully reduced risk without introducing new hazards. |
| Risk Management File Updates | Documents revised hazard analyses, residual risk evaluations and benefit-risk assessments where required. |
Why CAPA Is Critical to Risk Management
An effective CAPA system transforms real-world experience into meaningful improvements. Rather than treating complaints or non-conformities as isolated events, manufacturers use them to strengthen both their Quality Management System and their Risk Management File. This integration helps demonstrate to regulators and notified bodies that risk management remains active throughout the medical device lifecycle and that safety decisions are supported by objective evidence.
Learn More About Post-Market Surveillance (PMS)
Post-Market Surveillance is a vital source of production and post-production information under ISO 14971. Discover how PMS Plans, PMS Reports, PSURs, vigilance, trend analysis and real-world evidence help manufacturers monitor device safety, update Risk Management Files and maintain ongoing compliance with the EU MDR, IVDR and UK MDR in our Post-Market Surveillance for Medical Devices guide.
Management Review: Ensuring Risk Management Remains Effective
Management review is one of the key mechanisms that links ISO 14971 and ISO 13485. While ISO 14971 requires manufacturers to continually evaluate whether identified risks remain acceptable throughout the medical device lifecycle, ISO 13485 requires top management to periodically review the performance of the Quality Management System and ensure that appropriate resources, objectives and improvement activities remain in place.
An effective management review should consider far more than quality metrics alone. Senior management should review complaints, non-conformities, supplier performance, internal audit findings, Post-Market Surveillance (PMS) data, vigilance activities, CAPA effectiveness and regulatory changes to determine whether existing risk assessments remain valid. This information enables manufacturers to identify emerging trends, reassess benefit-risk profiles and prioritise improvements that enhance patient safety and product performance.
Management review also provides an opportunity to evaluate whether the Risk Management File remains current. Where new hazards have been identified, complaint trends have increased or product changes have been introduced, manufacturers should confirm that the risk management process has been updated appropriately and that any new risk control measures have been implemented and verified.
Perhaps most importantly, management review demonstrates leadership commitment to risk-based thinking. By regularly reviewing quality and safety data together, organisations can ensure that risk management is embedded within strategic decision-making rather than being treated as a standalone regulatory activity. This supports continual improvement, strengthens regulatory compliance and helps maintain confidence that medical devices continue to achieve their intended purpose throughout their lifecycle.
Management Review Inputs Supporting ISO 14971
| Management Review Input | Contribution to Risk Management |
|---|---|
| Customer Complaints | Identifies potential new hazards and changes in risk trends. |
| CAPA Performance | Confirms corrective actions have effectively reduced identified risks. |
| Internal Audits | Verifies that risk management procedures are being followed consistently. |
| Supplier Performance | Identifies supplier-related issues that could affect product safety or quality. |
| Post-Market Surveillance | Provides real-world evidence for updating the Risk Management File. |
| Regulatory Changes | Ensures risk management activities remain aligned with current legislation and standards. |
| Product Changes | Confirms modifications have been assessed for their impact on existing and residual risks. |
Why Management Review Matters
Management review brings together information from across the organisation to ensure that risk management remains effective as products, processes and regulations evolve. Rather than simply reviewing historical performance, it enables leadership to make informed decisions that strengthen the Quality Management System, improve patient safety and support continual compliance with ISO 14971, ISO 13485, the EU MDR, IVDR and UK Medical Devices Regulations.
Production and Post-Production Information: Closing the Risk Management Loop
One of the defining principles of ISO 14971 is that risk management does not end when a medical device is placed on the market. Manufacturers are expected to actively collect, review and evaluate production and post-production information throughout the device lifecycle to determine whether previously identified risks remain acceptable and whether new hazards have emerged.
ISO 13485 supports this requirement by establishing documented processes for collecting quality data from across the organisation. Information generated through manufacturing records, customer complaints, service reports, supplier performance, internal audits, vigilance activities and Post-Market Surveillance (PMS) provides valuable evidence that can be used to reassess product risks and verify the continued effectiveness of existing risk control measures.
This continual feedback process enables manufacturers to identify trends that may not have been apparent during product development. For example, increasing complaint rates, recurring manufacturing deviations or changes in supplier performance may indicate that the probability of harm has increased or that additional risk control measures are required. Where appropriate, manufacturers should update the Risk Management File, revise benefit-risk evaluations and implement corrective actions to maintain product safety and regulatory compliance.
By integrating production and post-production information into both the Quality Management System and the risk management process, organisations create a continuous learning cycle that supports safer medical devices, more effective quality management and ongoing compliance with ISO 14971, ISO 13485, the EU MDR, IVDR and UK Medical Devices Regulations.
Sources of Production and Post-Production Information
| Information Source | Contribution to Risk Management |
|---|---|
| Manufacturing Records | Identify production trends, process variability and recurring quality issues. |
| Customer Complaints | Detect previously unidentified hazards or changes in the frequency of known risks. |
| Service and Maintenance Data | Highlight long-term reliability issues and component failures. |
| Supplier Performance | Monitor material quality, supplier changes and outsourced process performance. |
| Internal Audits | Verify that risk management procedures continue to operate effectively. |
| Post-Market Surveillance | Collect real-world evidence on device safety and performance. |
| Vigilance Reporting | Identify serious incidents and support updates to risk assessments and corrective actions. |
Why Production and Post-Production Information Matters
Manufacturers that actively use production and post-production information can identify safety issues earlier, strengthen regulatory compliance and continually improve both their Quality Management System and their Risk Management File. Rather than treating risk management as a static document, ISO 14971 encourages organisations to use real-world evidence to ensure that medical devices continue to perform safely and effectively throughout their lifecycle.
Explore Risk Management Throughout the Device Lifecycle
Risk management does not end once a medical device reaches the market. Discover how ISO 14971 supports every stage of the medical device lifecycle, from concept and design through manufacturing, market launch, Post-Market Surveillance, product changes and end-of-life in our Role of Risk Management Throughout the Medical Device Lifecycle guide.
What ISO 14971 Risk Management Requires
ISO 14971 is both procedural and analytical. It requires manufacturers to create and maintain a documented process covering:
- Risk management plan: defines scope, responsibilities, and review frequency.
- Hazard identification – systematic listing of potential device harms.
- Risk analysis – estimation of probability × severity.
- Risk evaluation and control – deciding acceptability and applying mitigations.
- Verification of control effectiveness – ensuring mitigations actually work.
- Post-market surveillance (PMS) – feeding field data back into risk analysis.
A risk file is never finished. It evolves with design changes, CAPA findings, complaints, and regulatory updates. The best systems integrate risk with design controls, CAPA tracking, and production data, not as a document to file, but as an active decision-support tool.
How ISO 13485 Embeds Risk Management into the QMS
ISO 13485 doesn’t treat risk as a standalone activity. It embeds it in nearly every clause:
- Clause 4.1.2: requires a risk-based approach to process validation and change control.
- Clause 7: links design and development directly to risk identification and control.
- Clause 8: expects CAPA, internal audits, and post-market data to be risk-driven.
Risk influences supplier selection, production validation, complaint handling, and even management reviews. A strong QMS ensures risk files are referenced, reviewed, and continually updated.
That’s the link between ISO 14971 and ISO 13485: risk data becomes the backbone of quality evidence, demonstrating to regulators that every process decision has a safety justification.
See also: Patient Guard’s ISO 13485 Internal Audit and CAPA Services
Certification insight: For new MDR certificates, 44% took 13–18 months and 31% took 6–12 months from application to issuance. Companies with traceable integration between ISO 14971 and ISO 13485 avoid most of these extended review cycles (Team-NB 2024).
Integrating Risk Management into the Quality-Management System
Step 1: Align Risk Procedures and QMS Documentation
Reference the risk-management procedure directly in your QMS manual. Map cross-links between clauses, for example, design controls → risk file, supplier evaluation → risk assessment. This ensures auditors can follow risk logic across documents.
Step 2: Create a Shared Risk Register
Replace siloed spreadsheets with a single risk log used across engineering, production, and quality. Include fields for hazard ID, mitigation status, residual-risk rating, and owner. One version of the truth prevents conflicting data during audits.
Step 3: Feed Risk Outputs into CAPA and Audits
Each CAPA should ask: Was this risk foreseen? If not, why? CAPA effectiveness checks should re-evaluate risk severity and likelihood.
Likewise, internal audit schedules should prioritise high-risk processes and suppliers.
Step 4: Leverage Technology for Traceability
Modern digital QMS tools can link risk controls directly to SOPs, training records, and design-history files. Automation reduces transcription errors and strengthens traceability, both of which are key expectations for compliance with medical-device standards.
According to Team-NB 2024, members reported 19,634 valid ISO 13485 certificates across their EU client base — a clear sign that quality management and risk management are no longer optional but foundational to EU market access.
Common Gaps Between ISO 14971 and ISO 13485 (and How to Fix Them)
Typical Gap | Why It Happens | How to Fix It |
Risk file created once, never updated | Treated as a design deliverable, not a living process | Tie risk reviews to the management-review cycle and post-market data |
No link between risk controls and production | Risk managed only by design teams | Include process engineers in risk-review boards |
CAPA system not connected to risk register | Separate ownership of CAPA vs risk | Add risk ID field in CAPA forms |
Design reviews miss risk evidence | Poor traceability | Add risk summary to every design-review template |
Supplier risk ignored | Purchasing focuses on cost, not safety | Introduce supplier-risk rating in qualification forms |
How Regulators Expect You to Demonstrate Compliance
Notified Bodies and regulators don’t just check that you have both standards; they check how they interact. Expect auditors to look for:
- A traceability matrix linking risk controls to QMS procedures and technical-file sections.
- Documented evidence that risk evaluation influences design, production, and CAPA.
- Management-review records showing risk-based decision-making.
- Supplier and process-risk assessments as part of purchasing controls.
An auditor’s checklist will include:
- Risk-management plan and updates?
- CAPA linked to risk files?
- Supplier-risk evaluation recorded?
- Risk-acceptability criteria defined and justified?
See also: Patient Guard blog article – ISO 13485 Audit Readiness for Medical Device Manufacturers.
Building a Harmonised Risk-Quality Framework
A harmonised system fuses risk thinking into every quality activity. Benefits include:
- Proactive hazard identification and fewer late-stage CAPAs.
Shorter audit preparation times. - Stronger data for management decisions and vigilance reporting.
Patient Guard’s integrated QMS and Risk Management framework helps manufacturers close gaps between ISO 14971 and ISO 13485, from procedure alignment to risk-culture training.
Post-market challenge: A 2024 MedTech Europe survey found that ~70% of manufacturers take up to 4 months to update post-market surveillance (PMS) reports and feed findings back into risk files, proof that closing the PMS → risk feedback loop remains a central industry pain point.
Contact Patient Guard to integrate your risk and quality systems for seamless compliance →
Wrapping Up
ISO 14971 and ISO 13485 are not competing standards—they are complementary frameworks that work together to help manufacturers develop safer medical devices and maintain regulatory compliance throughout the product lifecycle. While ISO 14971 provides the methodology for identifying, evaluating and controlling risks, ISO 13485 establishes the Quality Management System that ensures those activities are consistently planned, implemented, monitored and continually improved.
By integrating risk management into design controls, supplier management, manufacturing, CAPA, management review and Post-Market Surveillance, manufacturers create a continuous feedback loop that supports informed decision-making and ongoing product safety. Rather than viewing risk management as a standalone regulatory requirement, organisations should embed risk-based thinking into everyday business processes so that quality and safety remain central to every stage of the medical device lifecycle.
This integrated approach not only helps organisations meet the requirements of ISO 14971, ISO 13485, the EU MDR, IVDR and UK Medical Devices Regulations, but also strengthens product quality, improves operational efficiency and increases confidence among regulators, notified bodies, healthcare professionals and patients. Manufacturers that successfully align risk management with their Quality Management System are better positioned to respond to changing technologies, evolving regulations and real-world performance data while delivering safe, effective and compliant medical devices.
Frequently Asked Questions Relating to ISO 14971 and ISO 13485
ISO 14971 provides the framework for identifying, evaluating and controlling risks associated with medical devices, while ISO 13485 establishes the Quality Management System (QMS) that ensures those risk management activities are consistently implemented, documented and maintained. Together, the two standards help manufacturers develop safe, effective and compliant medical devices throughout their lifecycle.
Although ISO 14971 is a separate standard, ISO 13485 requires manufacturers to apply risk management throughout many aspects of their Quality Management System. Demonstrating compliance with ISO 14971 is widely recognised as the most effective way of meeting these risk management expectations for medical devices.
ISO 13485 does not explicitly require a Risk Management File by name. However, compliance with the EU MDR, IVDR, UK Medical Devices Regulations and ISO 14971 generally requires manufacturers to maintain documented evidence showing how risks have been identified, evaluated, controlled and monitored throughout the product lifecycle.
During product development, ISO 14971 helps manufacturers identify potential hazards, estimate and evaluate risks, implement risk control measures and verify that those controls are effective. These activities integrate closely with the design control requirements of ISO 13485.
Corrective and Preventive Action (CAPA) provides a structured process for investigating quality issues and implementing improvements. Information generated through CAPA may require manufacturers to reassess hazards, update residual risk evaluations and revise the Risk Management File where appropriate.
Suppliers and outsourced processes can directly affect the safety and performance of a medical device. ISO 14971 helps manufacturers assess supplier-related risks, while ISO 13485 requires supplier qualification, monitoring and ongoing performance evaluation to ensure product quality and regulatory compliance.
Post-Market Surveillance (PMS) provides real-world evidence about device performance after market launch. Complaint trends, vigilance reports, customer feedback and production data help manufacturers determine whether existing risks remain acceptable and whether the Risk Management File requires updating.
Risk management is a cross-functional responsibility involving engineering, regulatory affairs, quality assurance, clinical specialists, manufacturing, supplier management and senior leadership. ISO 13485 also requires top management to ensure sufficient resources and oversight are provided to maintain an effective Quality Management System.
Risk assessments should be reviewed whenever significant new information becomes available. This may include design changes, manufacturing modifications, supplier changes, customer complaints, vigilance reports, Post-Market Surveillance findings or updates to applicable regulations and standards.
Yes. Integrating ISO 14971 into an ISO 13485 Quality Management System creates clear links between design controls, supplier management, CAPA, management review and Post-Market Surveillance. This structured approach helps manufacturers demonstrate compliance during notified body, UK Approved Body and certification audits.
Both standards provide the framework needed to demonstrate compliance with the EU Medical Device Regulation (MDR), In Vitro Diagnostic Regulation (IVDR) and UK Medical Devices Regulations. ISO 14971 addresses risk management, while ISO 13485 ensures these activities are embedded within an effective Quality Management System.
Integrating the two standards helps manufacturers make better risk-based decisions, improve patient safety, strengthen product quality, support continual improvement and maintain ongoing regulatory compliance. It also reduces the likelihood of non-conformities by ensuring that risk management is embedded throughout the entire medical device lifecycle rather than being treated as a standalone regulatory activity.
References
This guide is based on the following legislation, international standards and official regulatory guidance relating to the integration of quality management and risk management for medical devices.
| Organisation | Reference | Why it's relevant |
|---|---|---|
| International Organization for Standardization (ISO) | ISO 13485:2016 – Medical Devices – Quality Management Systems – Requirements for Regulatory Purposes | Defines the internationally recognised Quality Management System requirements for medical device manufacturers and establishes the framework within which risk management activities are planned, implemented and maintained. |
| International Organization for Standardization (ISO) | ISO 14971:2019 – Medical Devices – Application of Risk Management to Medical Devices | Defines the internationally recognised process for identifying hazards, evaluating risks, implementing risk controls and monitoring risk throughout the medical device lifecycle, complementing the Quality Management System requirements of ISO 13485. :contentReference[oaicite:0]{index=0} |
| European Union | Regulation (EU) 2017/745 on Medical Devices (MDR) | Requires manufacturers to operate an appropriate Quality Management System and implement lifecycle risk management processes, demonstrating how ISO 13485 and ISO 14971 support MDR compliance. |
| U.S. Food and Drug Administration (FDA) | FDA Recognized Consensus Standard – ISO 14971:2019 | Confirms that the FDA recognises ISO 14971:2019 as a consensus standard supporting medical device risk management within U.S. regulatory submissions and quality systems. |
| European Commission | MDCG Endorsed Documents and Other Guidance | Provides official Medical Device Coordination Group guidance supporting implementation of the MDR and IVDR, where effective Quality Management Systems and documented risk management processes are fundamental expectations. |
Quality management and risk management are complementary disciplines that underpin medical device regulatory compliance. Manufacturers should always consult the latest published legislation, recognised standards and official guidance when integrating ISO 13485 and ISO 14971 within their Quality Management System.
David Small BSc (Hons), MSc, MTOPRA
Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs, MDR/IVDR compliance and quality systems.
Patient Guards Recent Posts

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance
Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up
Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers
Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.
Patient Guards Related Services
Patient Guards Regulatory Tools
Need Training?
Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.
Posted on Google![]()
Munna P52 days agoTrustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.Posted on Google![]()
Peter Reeve79 days agoTrustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.Posted on Google![]()
Derek Timm79 days agoTrustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South LımıtedPosted on Google![]()
BMSCriticalCare116 days agoTrustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,Posted on Google![]()
Thomson Software787 days agoTrustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.Verified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more