Risk Management Plan Template - ISO 14971:2007 Compliant

Marcelo

Inactive Registered Visitor
Hello all.

Some time ago someone asked me about a risk management plan template.

I´ve compiled a first version of a template in english with some guidance, with a focus on being compliant with ISO 14971 requirements. it´s a first version so it´s really ugly :p.

Please note that I generally have concerns related to templates because people usually think that these activities and processes are like a cake recipe. They are not. This template will be compliant with ISO 14971 requirements if you:

1 - correctly understand ISO 14971 requirements
2 - use the template as a guidance for compiling a risk management plan
3 - create the correct, expected information
4 - review the plan you created against ISO 14971 to verify if there´s a need to add any other information due to your medical devices/processes

I think I will also create some other templates to documents required by medical device standards, but it will take some time.

Comments are welcome!
 

Attachments

  • Risk Management Plan Template - ISO 14971 - TEM-SQR-001-Version1.doc
    180 KB · Views: 5,118
L

louis6161

One comment: I Think the Management responsibilities should be one part of the risk managment plan.
 

Marcelo

Inactive Registered Visitor
Hello Louis 6161 and welcome to the Cove.

Thanks for your comment.

The risk management plan is for a device, meaning, it´s device-specific.

The management responsibilities requirements of ISO 14971 (3.2) is for the general risk management process, not directly linked to any device. This is also true to 3.1 and 3.3.
 

sagai

Quite Involved in Discussions
First of all thank you for the template.
However, i should note, this template indicates me that it based on some organizational and cultural pre-assumption and as such could give an impression for the Reader coming from different organizational and cultural background, that his/her way is not appropriate.
But it could be absolutely okay, regardless this template far not applicable to his/her recent practice as regard to Risk Management.
Regards!
 

Marcelo

Inactive Registered Visitor
Hello Sagai

No, it's not based on any organizational or cultural background, I created it from scract following the requiremens of the standard.

And yes, I'm pretty sure that a lot of poeple will think it's different from their recent practice in risk management (that's exactly why I crrated it :))
 

sagai

Quite Involved in Discussions
:cool:
What if, there is no named Risk Manager?
What if there is no named Risk Management Process Team?
What if there is no communication between RM team and others, because there is no such distinction?
What if Risk Acceptable Criteria is really can not be set universally for the total product?

So if there is a company not having such elements (and have passed several audits over the years), than ... we should have just to comply with this template?

Regards!
 

Marcelo

Inactive Registered Visitor
What if, there is no named Risk Manager?
This is a filled example.
What if there is no named Risk Management Process Team?
Not the name, but the standard requires that you define people which performs risk management activities - this is what I called the RM Team (which can be 1 person)

What if there is no communication between RM team and others, because there is no such distinction?
So you are saying the risk management process is the only proces in the manufacturer? Didn't understand your comment.

What if Risk Acceptable Criteria is really can not be set universally for the total product?
The standard requires that you define the risk acceptability criteria for the product under the plan.

So if there is a company not having such elements (and have passed several audits over the years),

Passing an audit does not mean that you comply with the standard - this is a common general misconception. In the case of risk management, this is so true that a lot of research has showed that, in the EU, most of the manufacturers do not comply with ISO 14971 (alghouth claiming compliance).
 
Last edited:
M

Mor628

Dear Marcelo,

I've been following your posts, searching for answers regarding the risk management process. In our recent audit, we had a minor NC for risk management process flow and residual risk.

From what the auditor asked me, I understand that a customer complaint (or any post-production information) should feed back into the risk management process.

My question is where does it feedback to? Back to Residual risk, where I assess whether the failures identified in the complaint have been covered in the residual risk? And if they have what would be my next step?

What if it is not covered in the residual risk?

Please help me. I've been at this for days and no where near a complete understanding of the process.
 

rob73

looking for answers
Hi Mor628
The way we treat PMS is to evaluate the failure and see if it it covered by any hazard identified during the initial RM (4.3 ISO 14971:2012), if not the the risk management report requires updating with the new hazard introduced, following through risk estimation, risk evaluation, risk control etc etc. Now this might mean a design change if the risk is deemed to be severe in which case we would start a new risk management process for the new design.
If there is no new hazard or risk posed, the information is noted in the RM file and a justification for no further RM action is placed in the CAPA (or complaint) file.
I hope this helps.
 
M

Mor628

Thank you so much Rob!!!! That's really helpful.

What if instead of product complaint, it's about final inspections or receiving & incoming inspections from suppliers? Does that also feedback into the RM process? At the moment none of my potential risks cover anything other than the product itself. Will I need to create a RM file just for inspections?
 
Thread starter Similar threads Forum Replies Date
M Risk Management Plan ISO 14971 - Medical Device Risk Management 13
H Risk Management Plan in agile process ISO 14971 - Medical Device Risk Management 14
adir88 MDR requirement: Risk Management Plan for "each device" ISO 14971 - Medical Device Risk Management 5
J Differences between a Risk Management Plan vs. Production Part Approval Process AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 3
N Non conformance Report to Risk Management-Plan ISO 14971 - Medical Device Risk Management 16
U Product Level Software Risk Management Plan and Report ISO 14971 - Medical Device Risk Management 2
E How to write a Validation Risk Management Plan for Equipment ISO 14971 - Medical Device Risk Management 5
T Medical Device Risk Management Plan ISO 14971 - Medical Device Risk Management 11
T Developing the Risk Management Plan - Risk Management Policy and Objectives ISO 14971 - Medical Device Risk Management 25
Y Risk Management Plan for Medical Device - ISO 14971 ISO 14971 - Medical Device Risk Management 1
T Risk Management Plan for a Mature Product - ISO 14971 ISO 14971 - Medical Device Risk Management 2
Q Risk Management Plan for a Class III Medical Device (Bone Void Filler) ISO 13485:2016 - Medical Device Quality Management Systems 5
Q Risk Management ISO 14971 - Probability of Occurrence ISO 14971 - Medical Device Risk Management 8
Z Risk Management SOP ISO 14971 ISO 14971 - Medical Device Risk Management 1
thisby_ Installation Related Issues and Risk Management ISO 14971 - Medical Device Risk Management 5
Doninina Risk management file according MDR or ISO 14971:P2019 ? EU Medical Device Regulations 2
G Help:Risk Management - Accessories US Food and Drug Administration (FDA) 1
N Writing Risk Management procedure for small manufacturing and we don't know where to start. Manufacturing and Related Processes 9
M Clinical evaluation interface with the risk management process EU Medical Device Regulations 9
J ISO 10993-1:2018 Format to Perform Risk Management Process US Food and Drug Administration (FDA) 1
B Risk Management Procedure updates needed for 14971:2019 ISO 14971 - Medical Device Risk Management 11
M Intended Use vs Actual Use and Scope of Risk Management EU Medical Device Regulations 8
S IDCB 0129/0160 Clinical Risk Management ISO 14971 - Medical Device Risk Management 2
A Risk Management Team IEC 60601 - Medical Electrical Equipment Safety Standards Series 11
S Risk Management File - Procedure Packs ISO 14971 - Medical Device Risk Management 3
G Risk Management for IEC 60601-1 and IEC 60601-1-2 IEC 60601 - Medical Electrical Equipment Safety Standards Series 15
K Do you have separate clinical risk management group or experts in your manufactures? EU Medical Device Regulations 4
Sidney Vianna ISO Practical Guide on ISO 31000:2018 - Risk Management Other ISO and International Standards and European Regulations 0
T Risk Assessment and Management [Deleted] Misc. Quality Assurance and Business Systems Related Topics 1
J HELP NEEDED ! Risk Management Exercise ISO 14971 - Medical Device Risk Management 12
O Should a Covid vaccine and testing policy be included as part of ISO9001 or AS9100 risk management? ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 6
Melissa Risk Management Process, How far do I need to go? ISO 14971 - Medical Device Risk Management 13
D Does Risk Management apply to re-labeler (MDR) EU Medical Device Regulations 1
U Supply risk management Manufacturing and Related Processes 4
T Biological Evaluation (10993) & Risk Management ISO 14971 - Medical Device Risk Management 9
D Cybersecurity and Risk Management: Loss of confidentiality IEC 62304 - Medical Device Software Life Cycle Processes 5
S Risk Management Review ISO 14971 - Medical Device Risk Management 4
S Risk Management and other Files ISO 14971 - Medical Device Risk Management 8
silentmonkey Overall Benefit/Risk Analysis - Risk Management VS Clinical Evaluation ISO 14971 - Medical Device Risk Management 3
Aymaneh Medical Device Cybersecurity Risk Management IEC 27001 - Information Security Management Systems (ISMS) 2
A 21 CFR 820 - Risk Management - Looking for some guidance US Food and Drug Administration (FDA) 3
Sravan Manchikanti Software Risk Management & probability of occurrence as per IEC 62304 IEC 62304 - Medical Device Software Life Cycle Processes 9
R Identify Medical Device characterstics as Annex C of ISO 14971 Risk Management ISO 14971 - Medical Device Risk Management 5
N Device Labeling - Medtronic Ventilator Files (Risk Management documents) Coffee Break and Water Cooler Discussions 2
T How do you define your Hazards? <a Risk Management discussion> ISO 14971 - Medical Device Risk Management 16
Dobby1979 Risk Analysis & Technical File - What detail goes in the Risk Management Report ISO 14971 - Medical Device Risk Management 5
C AS9100 Rev D 8.1.1 & APQP - Operational risk management process AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 3
B ATP 5-19 "Risk Management" Misc. Quality Assurance and Business Systems Related Topics 2
N Risk Management besides mandated FDA requirements 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 1
M Identifying Hazards - Risk management process ISO 14971 - Medical Device Risk Management 6

Similar threads

Top Bottom