skills/iso-standards-readiness/references/iso-14971.md
Research basis: 2026-07-26, building on the 2026-07-23 device-lane baseline. This reference summarizes a preparation process and evidence architecture for medical device risk management. It does not reproduce requirements and is not a substitute for the standard.
ISO publications are copyrighted. Obtain ISO 14971 and ISO/TR 24971 from ISO, an ISO national member, or another authorized source; see ISO copyright. Do not ask an agent to retrieve, transcribe, summarize clause-by-clause, or store proprietary text.
There is no ISO 14971 certificate. A body cannot certify a risk-management system to ISO 14971 the way it certifies a QMS to ISO 13485. Risk management is instead assessed inside other lanes:
Any claim of "ISO 14971 certification" is a category error. Report risk-management readiness as evidence supporting a named lane, never as its own assurance result.
This skill and its files cannot:
Use outputs as a list of evidence questions for accountable human review. Completeness of hazard identification cannot be established by any check in this skill — a zero-finding structural result says the declared links are present, not that the analysis found everything.
The iso-14971 profile carries these domain labels for manifests and gap reports.
They are workflow topics, not clause references:
risk-management-plan, risk-management-file, competence-and-authority,
intended-use-and-characteristics, hazard-identification,
risk-estimation-and-evaluation, risk-control-option-analysis,
risk-control-implementation-and-verification, risk-control-side-effects-review,
residual-risk-evaluation, benefit-risk-analysis,
overall-residual-risk-evaluation, risk-management-review-and-report,
production-and-postproduction-information, change-control.
Each domain needs an owner, status, evidence IDs, source/version reference, recorded approval, and links to open gaps.
Risk-management evidence is judged as a connected chain, not as a set of documents. For each analysed item, the following must be traceable in both directions:
intended use and reasonably foreseeable misuse → characteristics related to safety → hazard → foreseeable sequence of events → hazardous situation → harm with severity → probability basis → risk evaluation against declared criteria → risk-control option analysis and decision → implemented control → verification that the control was implemented → verification of its effectiveness → review for new or increased risks introduced by the control → residual risk evaluation → benefit-risk analysis where residual risk is not acceptable → contribution to overall residual risk → disclosure of residual risk → production and post-production information feeding back.
Break any one link and the file stops being evidence. The two links most often missing are verification of control effectiveness (distinct from verifying the control exists) and review of risks introduced by the control itself.
Build the traceability register with:
PYTHONDONTWRITEBYTECODE=1 python3 scripts/check_traceability.py \
/path/to/traceability-matrix.json
That check links intended use, hazard or signal, risk evaluation, risk control, design input and output, verification, validation, production control, and post-market source. It verifies declared linkage, not analytical adequacy.
ISO 14971 work is not separable from the device QMS. Keep these joins explicit and evidenced:
scripts/check_supplier_controls.py.scripts/check_capa.py.The production and post-production feedback loop is the single most common structural gap: files that were complete at design transfer and never updated by field experience.
Acceptability criteria belong in the risk-management plan, are set by authorized humans with a documented rationale, and must be applied consistently. Recurring failure modes to look for, none of which this skill can adjudicate:
Flag these as blockers for authorized review. Do not resolve them.
scripts/validate_scope_intake.py --standard iso-14971 — declared scope, product
families, intended use references, and applicability owners.scripts/check_traceability.py — the risk/design/production/post-market chain.scripts/check_capa.py — corrective action with effectiveness evidence.scripts/check_supplier_controls.py — controls that depend on external providers.scripts/validate_evidence_manifest.py and scripts/gap_analyzer.py with
--standard iso-14971.references/iso-13485.md — the QMS lane this evidence usually supportsreferences/source-ledger.md — dated baseline and provenance limitationsreferences/assurance-lanes.md — why this standard has no certification lane