AsteronAsteron

    ISO 14971 risk management for European medical software

    Asteron builds the risk-management process that connects intended use, hazards, hazardous situations, risk controls, verification and post-market information throughout the medical device lifecycle. The service is designed for European medical device, SaMD and IVD software manufacturers preparing products for the Netherlands, Germany and wider MDR or IVDR markets.

    View Medical Device Track pricing
    • Product risks traced from hazard to control
    • Risk acceptability defined before evaluation
    • Software, safety and cybersecurity connected
    • Lifecycle and post-market evidence prepared

    Medical Device Track from €30,000

    What is ISO 14971?

    ISO 14971:2019 is the international standard for applying risk management to medical devices, including software as a medical device and in vitro diagnostic medical devices.

    It establishes a lifecycle process for identifying hazards, estimating and evaluating associated risks, implementing and verifying risk controls and monitoring whether those controls remain effective after the product is released.

    The standard does not define one universally acceptable level of risk. The manufacturer must establish objective risk-acceptability criteria appropriate to its policy, products and regulatory context and apply them consistently.

    ISO 14971 is a product risk-management standard. It is not an enterprise risk register, an information-security risk assessment or automatic proof of MDR or IVDR conformity.

    ISO 14971:2019 remains the current confirmed edition. ISO/TR 24971:2020 provides supporting guidance but does not replace the requirements of the standard.

    Who needs ISO 14971?

    Medical device software manufacturers

    Software with an intended medical purpose may create or contribute to risks through incorrect outputs, unavailable functions, delayed information, user interaction, data integrity or other product-specific failure conditions.

    IVD software manufacturers

    IVD software may introduce risks affecting diagnostic or treatment decisions, specimen or patient association, data interpretation and communication of results.

    Manufacturers of connected devices

    Products combining software, hardware, cloud services, mobile applications and external integrations require one risk process that reflects the complete system and its intended environment.

    Teams bringing an existing health product into regulation

    A company may already have a technical product but lack a defensible connection between intended use, hazards, requirements, tests, residual risks and post-market activities.

    Not every product risk can be identified from a generic template. The scope must follow intended use, users, operating environment, product architecture, interfaces and foreseeable use conditions.

    How the ISO 14971 risk process works

    Risk management is a continuous product process, not a workshop performed once before an audit. Decisions must remain traceable as the design changes and new production or post-market information becomes available.

    1. Risk-management planning

    Define the product scope, responsibilities, review points, risk-acceptability criteria, verification expectations and the records required throughout the lifecycle.

    The plan should connect risk work to design, software development, usability, cybersecurity, clinical or performance activities and post-market processes.

    2. Intended use and reasonably foreseeable misuse

    Document who uses the device, for what purpose, in which environment and under which operating conditions. Consider foreseeable ways the product may be used incorrectly or outside the ideal workflow.

    This context determines which hazards and hazardous situations are relevant.

    3. Hazard and risk analysis

    Identify product characteristics, hazards, sequences of events, hazardous situations and possible harms. Estimate the associated risks using the approved criteria and available information.

    For software, analysis may include incorrect or delayed outputs, unavailable functions, data integrity, interoperability, cybersecurity and user-interface contributions to hazardous situations.

    4. Risk evaluation

    Compare estimated risks with the manufacturer’s predefined acceptance criteria. Decisions should not be adjusted after the result simply to make an existing design appear acceptable.

    Risks requiring control must be carried into documented treatment and verification.

    5. Risk control and verification

    Select appropriate controls and connect them to product requirements, design decisions, protective measures and information provided for safe use.

    The manufacturer must verify that each control was implemented and that it achieved the intended effect without introducing unacceptable new risks.

    6. Residual risk and benefit-risk evaluation

    Evaluate remaining risks after controls have been applied. Where required, assess whether the anticipated benefits of the product justify the residual risks and whether the overall residual-risk position is acceptable.

    Residual risks that require communication must connect to product information and the wider regulatory documentation.

    7. Production and post-production feedback

    Collect and review relevant information from complaints, incidents, vigilance, cybersecurity vulnerabilities, supplier issues, product monitoring and other post-market sources.

    New information should trigger timely evaluation and, where necessary, updates to the risk analysis, controls, product or user information.

    The resulting risk-management file should show how decisions were made, which evidence supports them and how the process remains current throughout the product lifecycle.

    What belongs in the risk-management file?

    The risk-management file is the controlled set of records demonstrating the process for the included product. It may reference records held elsewhere rather than duplicate every document.

    Foundation and analysis

    • Risk-management plan
    • Intended use and relevant product characteristics
    • Risk-acceptability criteria
    • Hazard and hazardous-situation analysis
    • Risk estimates and evaluation decisions
    • Links to applicable regulatory and product requirements

    Controls and lifecycle evidence

    • Selected risk controls and implementation evidence
    • Verification of control effectiveness
    • Residual-risk evaluations
    • Benefit-risk analysis where required
    • Risk-management review or report
    • Production and post-production information
    • Updates arising from changes or new information

    The exact structure should support traceability and assessment without becoming a static spreadsheet disconnected from requirements, tests and post-market processes.

    Relevance for the Netherlands and Germany

    Netherlands

    Medical device and IVD software manufacturers entering the Netherlands follow the applicable MDR or IVDR risk-management requirements. Dutch healthcare customers may also expect evidence concerning information security, availability and health-data processing.

    ISO 14971 addresses product risk. It does not replace NEN 7510 or other Dutch healthcare information-security requirements.

    Germany

    German medical software and DiGA teams may need ISO 14971 evidence where the product qualifies as a medical device. The risk file may need to connect with IEC 62304, IEC 81001-5-1, usability, cybersecurity and the applicable BfArM or notified-body route.

    ISO 14971 implementation alone does not create DiGA approval or reimbursement eligibility.

    Asteron builds one European product-risk process and connects country-specific Dutch, German and other market evidence where required.

    How Asteron implements ISO 14971

    1. Confirm product and regulatory context

      Asteron reviews intended use, users, operating environment, product qualification and classification, architecture, target markets and the existing quality and development processes.

    2. Assess existing risk evidence

      Current risk files, analyses, requirements, tests, complaints and post-market records are reviewed for consistency, traceability and coverage.

      Useful evidence is retained. Missing or unsupported decisions are documented in one prioritised implementation plan.

    3. Establish the risk-management system

      Asteron defines the agreed plan, responsibilities, acceptability criteria, methods, review points and lifecycle interfaces.

      The process is connected to ISO 13485, IEC 62304, IEC 81001-5-1 and other included product activities.

    4. Apply the process to the included product

      Workshops identify and evaluate relevant product risks and connect the agreed controls to requirements, design and verification evidence.

      Product and engineering actions remain assigned to named client owners.

    5. Review readiness

      Asteron reviews the risk-management file, residual-risk position, benefit-risk evidence and post-market interfaces and prepares the team for the intended external assessment.

      The independent assessor determines whether the evidence is sufficient for the selected regulatory route.

    Asteron designs the agreed risk-management process, facilitates the included analysis, prepares the documentation structure and coordinates assessment readiness.

    The manufacturer approves intended use, risk criteria and product decisions; supplies technical and clinical knowledge; implements controls; verifies effectiveness; and remains legally accountable for product risks and benefit-risk decisions.

    What Asteron delivers

    The final deliverables depend on product complexity, classification, existing evidence and the agreed Medical Device Track scope. They may include:

    Process and governance

    • ISO 14971 applicability and scope record
    • Risk-management procedure
    • Product risk-management plan
    • Roles and responsibilities
    • Risk-acceptability framework
    • Lifecycle review and escalation points
    • Production and post-production feedback process

    Product readiness

    • Existing risk-file review
    • Hazard-analysis structure
    • Risk-control and traceability model
    • Residual-risk and benefit-risk approach
    • Risk-management review preparation
    • Prioritised remediation plan
    • Assessment-readiness review

    Creation or reconstruction of the complete product-specific risk analysis, clinical evidence, usability files, software requirements or verification records is included only when explicitly stated in the proposal.

    ISO 14971 is delivered through the Medical Device Track

    Asteron does not publish a generic standalone ISO 14971 price because the effort depends on the product, intended use, classification, architecture, number of hazardous situations, existing risk evidence and required regulatory pathway.

    The approved starting point is Medical Device Track from €30,000.

    The track may combine
    • ISO 13485
    • ISO 14971
    • IEC 62304
    • IEC 81001-5-1
    • MDR or IVDR pathway support
    • Specialist coordination and co-delivery

    Larger, multi-product, higher-class or documentation-recovery engagements are scoped individually.

    Payment terms (fixed-scope)
    • 40% at signing
    • 40% when audit-ready
    • 20% after certification

    Prices exclude VAT where applicable.

    View full pricing

    Independent assessment boundaries

    Asteron implements the agreed risk-management process, prepares the included evidence and supports readiness. Asteron does not act as the notified body, certification body, competent authority or legal manufacturer.

    ISO 14971 does not normally create a standalone accredited product certificate. Its evidence may be reviewed during:

    • ISO 13485 certification
    • MDR or IVDR conformity assessment
    • Technical-documentation review
    • Customer or partner assessment
    • Another independent medical-device review

    External assessment and notified-body fees are separate and are contracted and paid directly by the client.

    The external decision remains independent. Asteron’s contracted outcome guarantee applies to Asteron deliverables within the agreed scope: if the agreed outcome is not reached because of those deliverables, Asteron corrects the work at no additional cost within that scope.

    What remains separate

    Unless explicitly included in the proposal, the following remain separate:

    • Formal qualification and classification decisions
    • Legal or regulatory opinions
    • Clinical or performance evaluation
    • Usability engineering and validation
    • Software development or technical remediation
    • Complete reconstruction of legacy product evidence
    • Penetration testing
    • Notified-body and certification-body fees
    • Regulatory authority fees

    Frequently asked questions

    What is ISO 14971?

    ISO 14971:2019 is the international standard defining the lifecycle risk-management process for medical devices, including SaMD and IVD software.

    Which version is current?

    ISO 14971:2019 is the current confirmed edition. ISO/TR 24971:2020 provides supporting implementation guidance.

    Does ISO 14971 apply to medical device software?

    Yes. The standard applies to medical devices including standalone medical software and IVD software.

    Is ISO 14971 the same as an ISO 27001 risk assessment?

    No. ISO 14971 addresses risks associated with a medical device and possible harm. ISO 27001 addresses organisational information-security risks.

    Does the standard define acceptable risk levels?

    No. The manufacturer establishes objective risk-acceptability criteria appropriate to its policy, product and regulatory context.

    Is risk management completed before product release?

    No. Production and post-production information must continue to feed the process throughout the supported product lifecycle.

    Does ISO 14971 guarantee MDR or IVDR compliance?

    No. It supports medical-device risk-management evidence, but the full applicable regulation and conformity route must still be addressed.

    Is it relevant in the Netherlands and Germany?

    Yes, when the product qualifies as a medical device or IVD for those markets. Country-specific healthcare, security or reimbursement requirements may apply in addition.

    How much does implementation cost?

    Asteron delivers ISO 14971 through the Medical Device Track, starting from €30,000. Final scope depends on the product and existing evidence.

    Are notified-body fees included?

    No. Independent notified-body, certification-body and assessment fees are contracted and paid directly by the client.

    Official references

    • – ISO — ISO 14971:2019
    • – ISO — ISO/TR 24971:2020
    • – European Commission — MDR and IVDR
    • – ISO — ISO 13485 medical-device quality management
    • – IEC — IEC 62304 medical device software lifecycle
    • – IEC — IEC 81001-5-1 health-software cybersecurity lifecycle

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with ISO, IEC, the European Commission, any competent authority or notified body.

    Build one traceable risk process around the product

    Share the intended use, architecture, regulatory position and existing risk evidence. Asteron will determine what can be reused and define the right ISO 14971 implementation scope.

    View Medical Device Track pricing