Technical GuideAugust 27, 2026 · 18 min read · VEMERIX

How to Review a Supplier's ISO 14971 Risk Management File: What QMSR Actually Requires After 2 February 2026, EN ISO 14971:2019+A11:2021 for MDR, China's GB/T 42062-2022, and a Buyer Acceptance Checklist

A practical buyer's audit guide for medical device risk management files: separating ISO 13485 QMSR process mandates from ISO 14971 conformity, verifying EN ISO 14971:2019+A11:2021 for EU MDR, navigating China's GB/T 42062-2022, and executing a 7-point incoming acceptance protocol.

ISO 14971Risk Management FileQMSRSupplier Qualification
VEMERIX technical guide cover illustrating the 7-step buyer audit workflow for medical device ISO 14971 risk management files, QMSR requirements, EN ISO 14971:2019+A11:2021 for MDR, GB/T 42062-2022, and supplier acceptance checks.

What Is ISO 14971: A Living Process and File, Not a Certificate or FMEA Template?

When an international medical device distributor, hospital procurement committee, or private-label OEM buyer qualifies a sterile single-use device manufacturer, the supplier's commercial dossier frequently contains a slide declaring the product 'ISO 14971 certified' or attaches a standalone Failure Mode and Effects Analysis (FMEA) spreadsheet. Both presentations represent fundamental misunderstandings of medical device risk management.

ISO 14971:2019 (the third edition, published in December 2019 and confirmed without technical modification on 7 March 2025 at stage 90.93)1 is a standard that specifies a continuous, life-cycle process for medical device manufacturers. It establishes requirements to identify hazards associated with medical devices, estimate and evaluate the associated risks, control those risks, and monitor the effectiveness of the controls throughout total product life cycle—from initial concept through design, manufacturing, clinical use, and post-market decommissioning.1

Crucially, ISO 14971 differs from QMS management standards in three decisive ways:

  • No Third-Party Certificate Exists: ISO 14971 is not a certification standard. Accredited notified bodies, registrars, and certification bodies issue certificates of conformity for Quality Management Systems under ISO 13485, but they do not issue standalone accredited 'ISO 14971 Certificates'. Any certificate titled 'ISO 14971 Conformity Certificate' issued by an unaccredited commercial entity is marketing collateral with zero regulatory standing.
  • No Universally Acceptable Risk Thresholds: ISO 14971 explicitly does not specify acceptable risk levels.1 The manufacturer is required to establish its own risk acceptability policy based on applicable national or regional regulations, relevant international safety standards, the generally acknowledged state of the art, and known clinical stakeholder concerns.1,8
  • A Living File, Not a Design Milestone: A Risk Management File (RMF) is not an archived engineering document. It is a compilation of living records that must be actively updated whenever post-production complaints, vigilance reports, manufacturing nonconformities, supplier material changes, or clinical literature emerge.1,9

To establish clarity during supplier audits, buyers must understand what each quality and technical document actually demonstrates. Confusing a general quality system certificate with a product-specific risk file is the most frequent cause of qualification failure.

Document TypeGoverning Standard / AuthorityWhat It Actually ProvesWhat It Does NOT Prove / Common OverclaimsBuyer Audit Action
ISO 13485 CertificateISO 13485:2016 / Accredited Registrar (IAF MLA)The manufacturer operates an audited QMS covering the defined facility scope and product categories.Does NOT prove that a specific finished SKU has an acceptable risk profile, valid biocompatibility, or regulatory market clearance.Verify certificate authenticity via IAF CertSearch; confirm facility address and scope match the quoted SKU.
ISO 14971 Risk Management File (RMF)ISO 14971:2019 / EN ISO 14971:2019+A11:2021 / GB/T 42062-2022The legal manufacturer executed a systematic hazard analysis, implemented prioritized risk controls, verified control effectiveness, and documented acceptable overall residual risk.Does NOT constitute a third-party certificate; an unmaintained FMEA spreadsheet is NOT an RMF.Request the complete RMF index: Plan, Hazard Analysis, Risk Evaluation, Control Verifications, Overall Benefit-Risk, and signed Report.
Biological Evaluation Report (BER)ISO 10993-1 (edition recognized in the target market) / FDA guidance / GB/T 16886.1-2022Toxicological and biological evaluation of patient-contact materials in finished, sterilized form.Does NOT evaluate mechanical, electrical, thermal, software, or user-interface hazards.Confirm the BER conclusions and toxicological endpoints feed directly into the ISO 14971 Risk Management File.
Sterilization Validation ReportISO 11135 (EO) / ISO 11137 (Radiation)Sterility Assurance Level (SAL 10⁻⁶) achieved; biological indicator kill and residual limits verified.Does NOT address packaging shelf life, clinical efficacy, or transport integrity.Verify that sterilization failure modes and EO residual toxicities are evaluated in the hazard analysis.
Regulatory Clearance / CertificateUS FDA 510(k) / EU MDR CE Certificate / China NMPA RegistrationLegal authorization to market the medical device in the specific target jurisdiction.Does NOT relieve the buyer/importer from maintaining local post-market surveillance records or verifying supplier QMS compliance.Authenticate clearance numbers in public regulatory databases; cross-check device trade name and classification.
Table 1: Medical Device Quality & Technical Compliance Document Differentiation

Does FDA Require ISO 14971 Under QMSR, or Only ISO 13485 Process Records?

On 2 February 2026, the US FDA's Quality Management System Regulation (QMSR) took full legal effect, replacing the legacy 1996 Quality System Regulation (21 CFR Part 820) and retiring the Quality System Inspection Technique (QSIT) in favour of Inspection of Medical Device Manufacturers Compliance Program 7382.850.3

A widespread misconception in commercial discussions is that QMSR formally incorporates ISO 14971 into US federal law. The statutory reality is more nuanced and holds decisive implications for how FDA investigators conduct inspections:

  • Incorporation by Reference (IBR) Limits: As published in the Federal Register final rule (89 FR 9724, Document 2024-01709), FDA explicitly incorporates by reference only ISO 13485:2016 and clause 3 of ISO 9000:2015.4 FDA stated in the final rule preamble that aside from clause 3 of ISO 9000, it does not incorporate ISO 14971 or any other standards referenced by, or listed as a source in, ISO 13485.4 Notes in ISO 13485 referencing ISO 14971 are informative and do not create statutory requirements under 21 CFR Part 820.4
  • ISO 13485 Risk Management Mandate: Incorporating ISO 13485:2016 into 21 CFR Part 820 means documented risk-management processes are required in product realization.3 FDA town-hall officials noted that this is not limited to design and development: Class I devices exempt from design controls still need risk-management records for other product-realization processes, including purchasing, production and labelling as appropriate.10,14
  • FDA Consensus Standard Recognition: While ISO 14971 is not written into the text of 21 CFR 820, FDA completely recognizes ISO 14971:2019 (ANSI AAMI ISO 14971:2019) as a recognized consensus standard (Recognition Number 5-125, Recognition List 053).2 Conforming to ISO 14971:2019 is the usual, recognized method for presenting risk management in 510(k), De Novo, and PMA submissions; it is not, by itself, a QMSR incorporation.2
  • The Town Hall Clarification: At the FDA QMSR Town Hall on 14 January 2026, FDA CDRH officials explicitly clarified this boundary. Keisha Thomas stated: 'There is no QMSR requirement that calls out conformity to ISO 14971.'10 Manufacturers are legally permitted to utilize any appropriately validated risk management methodology. Furthermore, Kimberly Lewandowski-Walker clarified that Class I devices exempt from design-and-development requirements are still required to maintain documented risk-management records for other product-realization processes, including purchasing and production controls.10
There is no QMSR requirement that calls out conformity to ISO 14971.Keisha Thomas, FDA CDRH, 14 January 2026 town hall, as reported by QualityHub

That town-hall answer is not a licence to ignore ISO 14971. At MedCon on 28 April 2026, FDA investigator Laureen Geniusz, as reported by RAPS, noted that even though FDA does not require ISO 14971, inspectors will still hold a firm to the standard if it is written into the firm's procedure.9 The two statements are complementary: QMSR does not incorporate 14971; a self-imposed 14971 SOP is inspectable.

This brings us to the primary inspection trap uncovered in early 2026. At the MedCon conference on 28 April 2026, named FDA officials (including Laureen Geniusz, Christina Bigham, Katelyn Staub-Zamperini, and Jeffrey Wooley) reviewed the first two months of QMSR inspections conducted between 2 February and 31 March 2026 across approximately 100 medical device facilities.9

The officials reported that the highest number of Form 483 inspectional observations were issued in risk management, followed by outsourcing and purchasing controls.9 (Note: this reflects qualitative conference reporting of early inspection trends from named officials, not a published statistical incidence census across the device industry).9

The underlying compliance failure was straightforward: manufacturers copied clauses directly from ISO 14971 into their QMS procedures without implementing them in practice. When an investigator examined the actual risk files, they discovered:

  • Standard Operating Procedures (SOPs) that merely regurgitated standard definitions without establishing executable device-specific criteria.
  • Inconsistent risk scoring between the design risk file, nonconformity investigations, and customer complaint evaluations.
  • Vague risk controls such as 'operator training' or 'visual inspection' assigned 100% risk reduction credit without verification data.
  • Fundamental confusion between hazards, hazardous situations, and harms, resulting in distorted severity scoring.8,9

How Do You Match a Supplier's Risk-Management File to the Exact Device You Are Buying?

To prevent qualifying a supplier whose risk documentation will fail regulatory audits or hospital procurement screening, buyers should execute a structured 7-point incoming audit protocol. This protocol evaluates whether the Risk Management File covers the actual finished commercial SKU and adheres to current international standards.

Audit GateEvaluation Criteria & Required EvidenceDisqualifying Red Flag / GapRequired Buyer Action
1. Finished SKU Scope & Device IdentityThe RMF explicitly names the exact commercial catalog number, product model, sterile barrier configuration, and manufacturing site quoted in the supply contract.The file covers a generic precursor device, a raw material coupon, or an unsterilized sub-assembly without covering the finished SKU.Reject the file; require a product-specific Risk Management Plan and Report identifying the finished sterile device.
2. Standard Edition & Harmonization WrapperFile cites ISO 14971:2019 (confirmed 2025). EU files carry EN ISO 14971:2019/A11:2021; China files cite GB/T 42062-2022.File is built exclusively against the obsolete ISO 14971:2007 edition with no gap assessment to the 2019 requirements.Issue a documentation nonconformity; require updated risk analysis aligned with ISO 14971:2019 / EN A11 / GB/T 42062.
3. QMSR / SOP Policy AlignmentManufacturer's Risk Acceptability Policy establishes objective thresholds for probability and severity based on clinical state of the art.Risk acceptability matrices are arbitrary, inverted, or allow high-severity harms to be accepted without documented benefit-risk analysis.Audit the manufacturer's Risk Management SOP; verify that matrix scoring matches the corporate quality policy.
4. Vertical Life-Cycle TraceabilityEvery identified hazard traces downstream through risk estimation, control measures, verification tests, and final residual risk evaluation.Biocompatibility endpoints (ISO 10993), sterilization residuals (ISO 11135), or packaging failures (ISO 11607) are omitted from the hazard trace.Require a complete Risk Traceability Matrix linking design inputs, verification protocols, biological evaluations, and IFU warnings.
5. Three-Tier Risk Control HierarchyRisk controls follow the mandatory hierarchy: (1) Inherent design safety; (2) Protective measures; (3) Information for safety / IFU.The manufacturer relies primarily on user warnings, contraindications, or 'operator caution' while bypassing available design or protective controls.Reject risk controls that rely solely on labeling; require engineering justification why design or protective measures were unfeasible.
6. Residual Risk & Overall Benefit-RiskDocumented individual residual risk evaluations for all identified hazards, plus a formal, clinical-data-supported overall benefit-risk determination.Overall residual risk is asserted as 'acceptable' in a single blanket sentence without clinical benefit comparison or multi-hazard evaluation.Demand the complete Benefit-Risk Analysis chapter containing clinical literature citations and clinical expert evaluation.
7. Living Post-Production Loop & ProvenanceDocumented mechanism for collecting and reviewing post-market data (complaints, MDR/vigilance, recalls); signed Risk Management Report by legal manufacturer.Static document last revised at initial design release years prior; contract manufacturer draft not formally adopted by the legal brand owner.Require the latest annual Post-Market Surveillance (PMS) risk review update and confirmation of legal manufacturer ownership.
Table 2: 7-Point Incoming Risk Management File Acceptance Matrix

What Deliverables Belong in an Audit-Ready ISO 14971 Risk Management File?

An ISO 14971 Risk Management File is not a single document; it is a structured repository of interrelated deliverables generated across the product life cycle.1 When reviewing an incoming supplier submission, verify the presence and completeness of eight foundational sections:

  1. Risk Management Plan (RMP): Defines the scope of the device, describes the intended use and reasonably foreseeable misuse, identifies the life-cycle phases covered, assigns roles and responsibilities, establishes criteria for risk acceptability based on executive policy, and specifies verification activities.1
  2. Identification of Characteristics Related to Safety: Qualitative and quantitative characteristics that could affect the safety of the medical device (e.g., operating principles, patient contact materials, energy delivery, sterile barrier limits, environmental operating parameters).1,8
  3. Hazard Identification & Hazardous Situations: Systematic identification of known and foreseeable hazards under both normal and fault conditions, mapping the sequence of events that creates a hazardous situation exposing patient or operator to harm.1,8
  4. Risk Estimation & Risk Evaluation: Estimating the probability of occurrence of harm (P1 × P2) and the severity of that harm using defined semi-quantitative or qualitative scoring scales, followed by evaluation against the predefined acceptability criteria in the RMP.8
  5. Risk Control Option Analysis & Verification: Identifying risk control measures adhering to the three-tier hierarchy, verifying that each control is implemented in production specifications (DMR transfer), verifying that controls are effective in reducing risk, and analyzing whether controls introduce new hazards.1
  6. Residual Risk & Overall Benefit-Risk Analysis: Evaluating residual risk after control implementation. If an individual residual risk or the overall combination of residual risks exceeds the manufacturer's acceptability criteria, a documented benefit-risk analysis must show that clinical benefits outweigh residual risks.1,13
  7. Risk Management Report (RMR): A formal concluding report signed and approved by authorized technical, clinical, and quality management personnel. The RMR summarizes the execution of the plan, confirms all verification activities are complete, and concludes whether the overall residual risk is acceptable.1
  8. Production & Post-Production Information Loop: Documented procedures and periodic review records demonstrating that customer complaints, adverse events, published recall data (MAUDE / vigilance), and design/process change controls actively feed back into the risk file.1,9

Why Are FDA Inspectors Citing Confusion Between Hazard, Hazardous Situation, and Harm?

A primary finding highlighted by FDA officials during early QMSR inspections and CDRH educational forums is the widespread corruption of standard risk management terminology.8,9 When manufacturers conflate hazards, hazardous situations, and harms, risk estimation formulas become scientifically meaningless and fail regulatory audits.

ISO 14971:2019 and FDA educational guidance establish precise definitions that every file reviewer must enforce:1,8

  • Hazard: A potential source of harm (e.g., sharp surgical blade edge, 1470 nm laser energy, toxic ethylene oxide chemical residue, negative pressure vacuum of −450 mmHg, electrical leakage current).8
  • Hazardous situation: Circumstance in which people, property, or the environment are exposed to one or more hazards. A hazard alone does not cause injury until a sequence of events creates exposure.8
  • Harm: Injury or damage to the health of people, or damage to property or the environment (e.g., tissue laceration, vascular perforation, third-degree thermal burn, severe wound infection, sepsis, permanent disability, death).8
  • Probability estimation (P1 and P2): FDA's Risk Basics teaching deck, citing ISO 14971:2019 Annex C Figure C.1, splits the probability of harm (P) into P1 (probability of a hazardous situation occurring) and P2 (probability of that hazardous situation leading to harm). Conflating these distorts severity scoring.8
Medical Device CategoryIdentified Hazard (Potential Source)Sequence of Events / Hazardous Situation (Exposure)Actual Harm (Clinical Damage)Appropriate Risk Control Measure
Disposable Circumcision Stapler / RingSharp circular blade / titanium staple arraySurgeon misaligns bell housing or applies incomplete trigger squeeze; tissue is partially incised without complete staple formation.Acute arterial hemorrhage, foreskin laceration, prolonged operative time, emergency surgical revision.Inherent design: mechanical interlock preventing trigger release until full compression force is achieved; visual staple alignment window.
Endovenous Laser Fiber (1470 nm)Coherent optical laser radiation / fused silica tipFiber tip contacts vein wall at excessive linear fluence without tumescent anesthesia barrier; fiber tip fractures during withdrawal.Vascular wall perforation, severe perivascular tissue burn, retained foreign body requiring vascular surgery.Protective measure (illustrative, not a Medison console claim): tip visibility marking; confirm any energy cut-off or generator interlock against the actual source IFU. The partner-supplied NOVACURE console is out of scope for this file review.
NPWT Drainage Dressing KitPolyurethane / Polyvinyl foam contact materialFoam dressing remains in deep wound cavity beyond recommended dressing change interval (>72 hours); tissue ingrowth occurs.Severe pain during removal, bleeding, retained foreign body fragments, delayed wound healing, localized infection.Information & Design: non-adherent wound-contact layer; prominent counting tags; explicit IFU change schedule warnings.
Sterile Single-Use Consumable (General)Ethylene Oxide (EO) chemical residualsInadequate aeration cycle leaves residual EO / ECH above allowable toxicological limits in direct patient-contact polymer.Local tissue necrosis, severe chemical mucosal irritation, delayed systemic hypersensitivity reaction.Manufacturing control: validated aeration to the residual limits in ISO 10993-7; lot-release testing against those limits — not a universal 14-day recipe.
Table 3: Clinical Sequence of Events Chain: Hazard → Hazardous Situation → Harm

How Do Risk Management Requirements Differ Across FDA QMSR, EU MDR, and China NMPA?

A risk management file prepared for one regulatory jurisdiction cannot be blindly submitted to another without verifying regional harmonization and statutory overlays. The United States, European Union, and China each enforce distinct legal wrappers around ISO 14971.

Jurisdiction / AuthorityGoverning Standard / Legal InstrumentHarmonization & Recognition StatusCritical Regional Nuances & DeviationsBuyer / Importer Review Gate
United States (US FDA)21 CFR Part 820 (QMSR) / ISO 13485:2016 IBR; ISO 14971:2019 Consensus StandardISO 14971:2019 completely recognized (Rec# 5-125). Not incorporated by reference into Part 820.Risk management required across product realization. In inspections (CP 7382.850), FDA holds firms to ISO 14971 if cited in SOPs. Cybersecurity risk uses exploitability, not probability×severity.Verify documented risk management across purchasing and production; confirm FDA recognized standard declaration in 510(k) summary.
European Union (EU MDR)Regulation (EU) 2017/745 / EN ISO 14971:2019 + A11:2021Harmonised under Commission Implementing Decision (EU) 2022/757 (OJ L 138/27, 17.5.2022, Entry 16). Later amending decisions have added other standards; they have not deleted this entry.Presumption of conformity via Annex Z, only for the MDR requirements the standard covers. MDR Annex I GSPR 2 defines AFAP as reduction without adversely affecting the benefit-risk ratio; GSPR 4 requires the design / protective-measure / information-for-safety order and residual-risk disclosure; GSPR 8 requires overall residual risk to be acceptable against benefits. Where the standard and the MDR differ, the MDR prevails.Verify Annex Z mapping to MDR Annex I GSPRs 1–8; confirm residual risk is disclosed to users and that information for safety is not treated as a substitute for feasible design or protective controls.
China (China NMPA)GB/T 42062-2022 (National Standard) / YY/T 1437-2023 (Guide)Identical adoption (IDT) of ISO 14971:2019; implemented 1 November 2023. Competent department: NMPA.GB/T 42062-2022 is the current recommended national standard. YY/T 0316-2016 remains listed as current on SAMR industry-standard pages and was not on NMPA's 3 April 2023 six-item withdrawal list. A YY/T 0316 citation is a question, not an automatic fail.Record which document the Chinese technical dossier and Product Technical Requirement cite; prefer GB/T 42062-2022 for new packs; verify that local product standards incorporate risk-derived performance tests.
Table 4: Comparative Risk Management Regulatory Requirements: US vs EU vs China

In the European Union, the relationship between EN ISO 14971:2019 and Regulation (EU) 2017/745 (MDR) is governed by Amendment A11:2021, whose references were published in the Official Journal by Commission Implementing Decision (EU) 2022/757.5 Amendment A11 does not alter the normative body of ISO 14971; it adds EU-specific Annex Z mapping between clauses of the standard and the GSPRs of the MDR.11 The GSPRs themselves live in MDR Annex I, not in the implementing decision.13

Notified bodies evaluating MDR Technical Documentation enforce three fundamental principles where the MDR takes precedence over standard ISO 14971 practice:

  • Reduction as far as possible (AFAP): MDR Annex I GSPR 2 states that the requirement to reduce risks as far as possible means reduction without adversely affecting the benefit-risk ratio.13 The MDR text does not use the word ALARP. Treat 'economic cost justifies leaving a feasible design control unimplemented' as a conflict with GSPR 2/4, not as a sentence copied from Implementing Decision (EU) 2022/757.
  • Information for safety is last, and residual risk must be disclosed: GSPR 4 requires risk-control measures in this order: inherently safe design and manufacture; then protective measures; then information for safety (warnings, precautions, contraindications) and, where appropriate, training. Manufacturers shall inform users of any residual risks.13 An EU file that scores residual risk down solely because a warning was added should be sent back; GSPR 4 does not say that labelling mathematically reduces residual risk, and it does require disclosure of the residual that remains.
  • Overall residual risk versus benefit: GSPR 8 requires all known and foreseeable risks, and any undesirable side-effects, to be minimised and acceptable when weighed against evaluated benefits during normal conditions of use.13

In China, the State Administration for Market Regulation (SAMR) and the National Medical Products Administration (NMPA) issued GB/T 42062-2022 (Medical devices—Application of risk management to medical devices), which took effect on 1 November 2023 as an identical adoption (IDT) of ISO 14971:2019.6 While earlier registrations referenced industry standard YY/T 0316-2016, SAMR's live registry confirms GB/T 42062-2022 as the active national standard.6 (Note: YY/T 0316-2016 remains catalogued as current on SAMR databases and has not been formally declared withdrawn; buyers should record which edition is cited in the supplier's Product Technical Requirement (PTR) file).6

When Does ISO/TR 24971:2020 Apply, and Why Is ISO/AWI TS 24971-1 Not Yet a Requirement?

When evaluating the analytical techniques in a supplier's risk file, buyers frequently encounter references to technical guidance documents. Understanding what is published guidance versus what is an unpublished draft is essential to avoid issuing inappropriate audit findings.

ISO/TR 24971:2020 (Medical devices — Guidance on the application of ISO 14971) remains the authoritative, published international Technical Report providing practical guidance on implementing ISO 14971:2019.2,8 It offers detailed guidance on:

  • Establishing objective criteria for risk acceptability.
  • Selecting risk-analysis techniques (PHA, FMEA, FTA, HAZOP and others) appropriate to the device — the TR discusses technique selection; it does not make any one spreadsheet mandatory.
  • Differentiating the probability of a hazardous situation (P1) from the probability that the situation leads to harm (P2), consistent with FDA Risk Basics / ISO 14971:2019 Annex C Figure C.1.
  • Evaluating overall residual risk and feeding production and post-production information back into the file.

In July 2026, ISO Technical Committee ISO/TC 210 approved a new work item registered as ISO/AWI TS 24971-1 (Medical devices — Guidance on the application of ISO 14971 — Part 1: General) at stage 20.00.7 This project is intended to eventually replace the Technical Report format with a formal Technical Specification (TS). However, as of August 2026, TS 24971-1 is an unpublished draft under committee development.7 Buyers, distributors, and QA auditors must not demand compliance with TS 24971-1 or delay commercial RFQs pending its release; ISO/TR 24971:2020 remains the operative guidance benchmark.2,7

How Do Risk Management Requirements Apply to Circumcision, Laser, and NPWT Consumables?

To demonstrate how a buyer should evaluate technical risk files in practice, consider three clinical device categories from the sterile consumable portfolio:

1. Disposable Circumcision Stapler (Mucosal Contact & Mechanical Resection)

A single-use circumcision stapler or self-detaching circumcision ring involves transient to short-term mucosal and breached-surface contact.12 When auditing the supplier's ISO 14971 file:

  • Mechanical Resection & Anastomosis Hazards: The file must analyze mechanical cutting tolerances, incomplete staple closure, premature trigger release, and tissue entrapment. Controls must be verified by mechanical staple height testing and tissue burst pressure validation.
  • Traceability to ISO 10993 Biological Evaluation: The RMF must consume the ISO 10993 biological evaluation report for mucosal and breached-tissue contact (cytotoxicity, sensitization, intracutaneous irritation). Chemical extraction data must demonstrate that silicone rings or polymer handles do not release toxic leachables.
  • Sterilization Residuals: The hazard analysis must evaluate ethylene oxide (EO) residual toxicity, establishing traceability to ISO 11135 validation reports and confirming EO/ECH levels comply with ISO 10993-7.

2. Disposable Medical Laser Fiber (Circulating Blood Contact & 1470 nm Energy Delivery)

A single-use medical laser fiber designed for endovenous laser ablation (EVLA) of varicose veins operates in direct circulating blood contact and delivers thermal energy at 1470 nm.12 Critical risk file audit requirements include:

  • Fiber Tip Fracture & Foreign Body Retention: Inherent risk of fused silica distal tip detachment or degradation under high optical fluence. The file must record mechanical tensile strength verification, thermal degradation testing under maximum wattage, and echogenic tip visibility verification.
  • Thermal Damage & Vascular Perforation: Hazards associated with excessive local energy delivery. The file must evaluate energy transmission calibration, optical fiber numerical aperture (NA), and compatibility parameters when pairing with a diode laser generator.
  • Post-Market Surveillance Integration: The living post-production section must demonstrate review of adverse event databases (FDA MAUDE / vigilance recalls), verifying that reported clinical failure modes (e.g., fiber breakages during withdrawal) have been evaluated in the device hazard matrix.

3. Disposable NPWT Drainage Dressing Kit (Prolonged Breached-Skin Contact & Negative Pressure)

A negative pressure wound therapy (NPWT) dressing kit comprising polyurethane/polyvinyl foam, semi-permeable adhesive film, and drainage tubing operates in prolonged contact (>24 hours to 30 days) with breached skin and subcutaneous tissue.

  • Foam Retention & Tissue Ingrowth: Hazards associated with foam fragments tearing upon removal or granulation tissue growing into open-pore foam (400–600 µm). The risk file must evaluate tensile strength after fluid saturation and specify mandatory dressing change intervals in the IFU.
  • Pressure Distribution & Tube Occlusion: Fluid exudate blockage causing localized loss of therapeutic negative pressure (−50 to −450 mmHg) or fluid maceration. The file must record fluid drainage flow testing and verify multi-chamber suction cup anti-blockage designs.
  • Sterile Barrier & Shelf Life: Traceability to ISO 11607 packaging validation and real-time/accelerated aging protocols ensuring sterile barrier integrity throughout labeled shelf life.

Which Red Flags and Fatal Deficiencies Justify Rejecting a Supplier's File Immediately?

When an incoming supplier dossier contains any of the following six fatal defects, buyers and QA auditors should immediately return the file for remediation prior to signing commercial supply agreements or submitting regulatory dossiers:

  1. The 'FMEA Spreadsheet as the File' Trap: The supplier provides only an Excel Design FMEA (DFMEA) or Process FMEA (PFMEA). An FMEA is an engineering failure analysis tool; it lacks a Risk Management Plan, risk acceptability criteria, clinical benefit-risk evaluations, and post-market feedback mechanisms. A bare spreadsheet is not an ISO 14971 file.
  2. Obsolete 2007 Edition Citation: The file references ISO 14971:2007 without a gap analysis to ISO 14971:2019, EN A11:2021, or GB/T 42062-2022. A 2007-edition file is stale for benefit-risk, production and post-production, and (for the EU) A11 mapping. Do not treat the 2019 edition as a cybersecurity standard: FDA's SIS states that the 14971 probability×severity model does not apply to cybersecurity.
  3. Textbook Copied SOPs: The manufacturer's risk SOP copies the text of ISO 14971 verbatim without establishing actionable risk evaluation matrices, objective severity definitions, or defined escalation criteria. This is the exact failure mode driving QMSR Form 483 citations.
  4. Missing Traceability to Upstream Testing: The hazard analysis makes unsupported assertions regarding biocompatibility, sterility, or packaging without hyperlinking or cross-referencing specific GLP test reports (ISO 10993, ISO 11135/11137, ISO 11607).
  5. Static 'Frozen' File Without PMS Updates: The Risk Management Report was signed upon initial product release five years ago and has never been updated to reflect post-market customer complaints, CAPA investigations, or vigilance reporting.
  6. Unadopted Contract Manufacturer Draft: The file is an unapproved draft authored by an OEM/ODM factory that has never been formally reviewed, approved, and integrated into the legal brand owner's quality management system.1

What Acceptance Checklist and RFQ Contract Language Should Buyers Enforce?

To operationalize these requirements during procurement and contract manufacturing audits, insert the following standardized technical documentation clause into your Request for Quotation (RFQ) and Supplier Quality Agreement (SQA):

Contract Requirement ClauseMandatory Supplier DeliverablesVerification & Audit Standard
1. Risk Management System GovernanceDocumented risk management procedure establishing objective risk acceptability criteria approved by executive management.21 CFR 820 (QMSR) / ISO 13485:2016 Clause 7.1; ISO 14971:2019 Clause 4.
2. Product-Specific Risk Management FileComplete RMF for quoted finished SKU, including Risk Management Plan, Hazard Identification, Risk Estimation, and Traceability Matrix.ISO 14971:2019 Clauses 5–7; EN ISO 14971:2019/A11:2021 (EU) / GB/T 42062-2022 (China).
3. Life-Cycle Verification TraceabilityTraceability cross-referencing ISO 10993 Biological Evaluation Reports, Sterilization Validation (ISO 11135/11137), Packaging Validation (ISO 11607), and IFU warnings.ISO 14971:2019 risk-control option analysis; ISO 13485:2016 design and development verification (QMSR via 21 CFR 820.7 / 820.10 — do not cite reserved 21 CFR 820.30).
4. Risk Management Report & Benefit-RiskFormally signed Risk Management Report summarizing residual risk evaluations and clinical benefit-risk determinations.ISO 14971:2019 Clauses 8–9; MDR Annex I GSPRs 1–8.
5. Post-Production Data Integration & PMSAnnual PMS risk evaluation updates incorporating complaint trends, CAPAs, adverse events, and vigilance data into the live RMF.ISO 14971:2019 production and post-production activities; ISO 13485:2016 feedback / CAPA clauses (QMSR via 21 CFR 820.7 / 820.10 — do not cite reserved 21 CFR 820.100).
Table 5: Model Supplier Quality Agreement (SQA) Risk Management Clause

Where Does VEMERIX Fit in Risk Management Files—and Where Does Due Diligence Begin?

VEMERIX is the international brand of Weihai Medison Medical Equipment Co., Ltd., positioned as a Minimally Invasive Surgery Total Solution Platform serving urology, vascular surgery and perioperative care.12

Portfolio examples, not residual-risk conclusions: the public Circumcision Device page records NMPA Class II with CE; the Disposable Circumcision Stapler page records NMPA Class II with no CE flag; the Disposable Medical Laser Fiber is Medison's NMPA-registered single-use fiber for 1470 nm endovenous workflows, paired with a partner-supplied diode laser source, and carries no Medison CE claim; NPWT drainage dressing kits are the prolonged breached-skin worked example. None of those pages is an ISO 14971 certificate or an acceptable-residual-risk determination.12

When partnering with international distributors and OEM brand owners, VEMERIX can discuss a current risk-management pack for a quoted sterile SKU — plan, analysis covering normal and fault conditions, control records, residual and overall residual versus benefit, production and post-production review method, and a signed report — together with the sterilization, packaging and ISO 10993 traces that file should consume. That is an invitation to audit the pack, not a claim that every SKU is 'ISO 14971 certified' (no such certificate exists) and not a residual-risk conclusion.

Due diligence still begins with the buyer's seven checks. Run the acceptance matrix in this guide on whatever pack you receive, including one from us. Technical documentation requests can be initiated through the Quality & Regulatory Portal and contact pages.

Frequently Asked Questions

Is 'ISO 14971 certified' or 'ISO 14971 compliant' a meaningful supplier claim on its own?
No. ISO 14971 is a process standard, not a certification scheme. Accredited registrars certify Quality Management Systems against ISO 13485, but there is no accredited standalone 'ISO 14971 Certificate'. A meaningful supplier claim must be backed by a product-specific Risk Management File (Plan, Hazard Traceability Matrix, Risk Controls, Benefit-Risk Analysis, and signed Report) covering the exact quoted SKU.1

Does FDA require ISO 14971 now that QMSR is in force?
Under 21 CFR Part 820 (effective 2 February 2026), FDA incorporates ISO 13485:2016 by reference, which mandates documented risk management processes across product realization. However, FDA explicitly did not incorporate ISO 14971 by reference in the Federal Register final rule.4 While FDA fully recognizes ISO 14971:2019 as a consensus standard, QMSR permits any appropriately validated risk management process.2,10

If the supplier's procedure names ISO 14971, can FDA still cite them against it?
Yes. FDA officials have affirmed that while QMSR does not mandate ISO 14971 by name, if a manufacturer specifies in its internal Standard Operating Procedures (SOPs) that it follows ISO 14971, FDA investigators under Compliance Program 7382.850 will hold the firm to that standard during an inspection.9

What is the difference between ISO 13485 and ISO 14971?
ISO 13485 governs the overall Quality Management System (management responsibility, resource management, document control, corrective actions). ISO 14971 provides the specific, detailed technical framework for identifying hazards, evaluating risks, implementing controls, and determining benefit-risk ratios for medical devices.1,3

Does an FMEA spreadsheet satisfy ISO 14971?
No. An FMEA (Failure Mode and Effects Analysis) is an engineering analysis tool useful for evaluating component and sub-system failure modes. It does not satisfy ISO 14971 on its own because it lacks a Risk Management Plan, risk acceptability criteria, clinical hazard identification under normal use, overall benefit-risk determinations, and post-market feedback loops.1,8

Which edition should a US-bound, EU-bound, or China-bound file use in 2026?
For the US, ISO 14971:2019 (confirmed 2025). For the EU, EN ISO 14971:2019 + A11:2021 under Commission Implementing Decision (EU) 2022/757. For China, national standard GB/T 42062-2022 (identical adoption of ISO 14971:2019, implemented 1 November 2023).1,5,6

Can a contract manufacturer’s risk file be reused by a private-label legal manufacturer?
A private-label brand owner cannot simply place its logo on a contract manufacturer's risk file. The legal manufacturer named on the device label must review, approve, and formally adopt the file into its own QMS, including private-label packaging, branding, IFU and post-market vigilance. See who is the legal manufacturer of a private-label sterile device.1

Should I wait for ISO/AWI TS 24971-1 before writing the 2026 RFQ?
No. ISO/AWI TS 24971-1 is an approved draft project under development (stage 20.00 as of 6 July 2026). It is not a published standard. Buyers and manufacturers should continue using ISO/TR 24971:2020 as the operative guidance document for applying ISO 14971:2019.7

Sources

  1. International Organization for Standardization, ISO 14971:2019, Medical devices — Application of risk management to medical devices, third edition, published December 2019, 36 pages, ISO/TC 210. Catalog states the publication was last reviewed and confirmed in 2025 and therefore remains current (stage 90.93, confirmation dated 7 March 2025). The standard specifies a process to identify hazards, estimate and evaluate risks, control them and monitor the effectiveness of controls throughout the life cycle, and does not specify acceptable risk levels. The statement that ISO 14971 does not require a quality management system is from the FDA Recognized Consensus Standards SIS, not the public catalog abstract. Catalog fetched 2026-08-27; 7 March 2025 confirmation date re-checked on the ISO lifecycle listing 2026-08-27.
  2. US FDA, Recognized Consensus Standards Supplementary Information Sheet for ISO 14971 Third Edition 2019-12, FR Recognition Number 5-125, FR Recognition List 053, date of entry 23 December 2019, extent of recognition complete. Identical adoption ANSI AAMI ISO 14971:2019. SIS scope text: the standard does not specify acceptable risk levels and does not require that the manufacturer have a quality management system in place. Note: ISO 14971:2019 defines risk (3.18) as the combination of the probability of harm and its severity; FDA's premarket cybersecurity guidance states this probabilistic model does not apply to cybersecurity. Supportive publications listed include Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, issued February 2026, and ISO/TR 24971:2020. Page last updated 25 May 2026. Extracted 2026-08-27; re-checked 2026-08-27.
  3. US FDA, Quality Management System Regulation (QMSR). Content current as of 2 February 2026. The QMSR amends 21 CFR Part 820 and incorporates by reference ISO 13485:2016 and clause 3 of ISO 9000:2015. The page states that incorporating ISO 13485:2016 'now specifically requires risk management'. On 2 February 2026 FDA began using Inspection of Medical Device Manufacturers Compliance Program 7382.850 and no longer uses QSIT or inspection documents 7382.845 and 7383.001. The QMSR applies to finished-device manufacturers who intend to commercially distribute medical devices. Fetched 2026-08-27.
  4. Federal Register, Medical Devices; Quality System Regulation Amendments, 89 FR 9724 (2 February 2024), document 2024-01709, effective 2 February 2026. FDA states that aside from clause 3 of ISO 9000, it does not incorporate ISO 14971 or any other standards referenced by, or listed as a source in, ISO 13485, but acknowledges those other standards may be helpful in understanding application of ISO 13485. Notes in ISO 13485 do not set forth statutory or other legal requirements. Extracted 2026-08-27.
  5. Commission Implementing Decision (EU) 2022/757 of 11 May 2022 amending Implementing Decision (EU) 2021/1182 as regards harmonised standards for quality management systems, sterilisation and application of risk management to medical devices. OJ L 138, 17.5.2022, p. 27. Recital (6) and annex entry 16 publish the references of EN ISO 14971:2019 and EN ISO 14971:2019/A11:2021 in support of Regulation (EU) 2017/745. Devices in conformity with relevant harmonised standards whose references are published in the OJEU are presumed to conform with the MDR requirements covered by those standards (MDR Article 8(1), recited in the Decision). Extracted 2026-08-27.
  6. Standardization Administration of China / State Administration for Market Regulation, GB/T 42062-2022, Medical devices—Application of risk management to medical devices. Status 现行. Published 12 October 2022 (SAMR/SAC Announcement No. 13; openstd national-standard card dated 14 October 2022). Implemented 1 November 2023. Competent department: NMPA. The public openstd card confirms status, dates and NMPA as competent department and states that the standard adopts an ISO/IEC organization standard. Identical adoption of ISO 14971:2019 is the description used by the first drafting unit (CMD / SAC/TC 221). Fetched 2026-08-27; card re-checked 2026-08-27.
  7. ISO/AWI TS 24971-1, Medical devices — Guidance on the application of ISO 14971 — Part 1: General. Approved work item, stage 20.00 (new project registered in the TC/SC work programme 6 July 2026; new project approved 6 July 2026). Will replace ISO/TR 24971:2020. Catalog also notes that a working group has prepared a draft; it is still not a published specification. Catalog fetched 2026-08-27; re-checked 2026-08-27. Continue to treat ISO/TR 24971:2020 (https://www.iso.org/standard/74437.html) as the published application guidance until a TS is issued.
  8. US FDA, CDRH Division of Industry and Consumer Education, 'Risk Basics for Medical Devices' (Joseph Tartal). Official educational slide deck. Uses ISO 14971:2019 definitions for hazard, hazardous situation, harm, probability, severity, risk (3.18) and benefit (3.2); states CDRH has no statutory or regulatory definition of risk; illustrates P1 × P2 from ISO 14971:2019 Annex C Figure C.1; points to ISO/TR 24971 for selected risk-analysis techniques. Still discusses the 1996 21 CFR 820 preamble in places — vocabulary and teaching aid, not the current QMSR legal text. Fetched 2026-08-27; re-checked 2026-08-27.
  9. Jeff Craven, 'MedCon: FDA officials say risk management is biggest hurdle for inspections under QMSR', Regulatory Focus / RAPS, 28 April 2026. Named FDA officials (Laureen Geniusz, Christina Bigham, Katelyn Staub-Zamperini, Jeffrey Wooley) reported about 100 QMSR inspections between 2 February and 31 March 2026, with the most Form 483s in risk management, followed by outsourcing and purchasing. Inspection-practice comments: procedures that regurgitate the standard; inconsistent risk scores; vague risk controls; hazard/harm confusion; inspectors will hold a firm to ISO 14971 if it is in the procedure. Secondary conference reporting of named officials, not a published FDA 483 table. Fetched 2026-08-27.
  10. QualityHub, 'Risk Management & QMSR: 7 Questions Answered By FDA', reporting a 14 January 2026 FDA town hall with Kimberly Lewandowski-Walker, Karen Masley-Joseph, Keisha Thomas and Tonya Wilbon. Keisha Thomas: there is no QMSR requirement that calls out conformity to ISO 14971; manufacturers may use any appropriately validated risk-management process. Lewandowski-Walker: no required specific tools; Class I devices exempt from design-and-development still need risk-management records for other product-realization processes. Wilbon: no requirement for a quantitative description of risk. Secondary transcript of named officials. Legal incorporation claims stay on s3 and s4. Fetched 2026-08-27.
  11. ISO/TC 210 news note by Jos van Vroonhoven, 'Recognition of EN ISO 14971 as a harmonized standard in support of the European Medical Device Regulations'. Records that EN ISO 14971:2019 with amendment A11:2021 is cited in the OJEU via Commission Implementing Decisions 2022/757 (MDR) and 2022/729 (IVDR); A11 is EU-specific Annex Z mapping and does not modify the normative part of ISO 14971. Used only to explain A11's scope; the load-bearing legal citation is s5. Retrieved 2026-08-27.
  12. Public VEMERIX product pages used only as worked-example identity, not as residual-risk evidence: Circumcision Device (self-detaching ring; NMPA Class II; CE yes); Disposable Circumcision Stapler (NMPA Class II; no CE flag on the public product page); Disposable Medical Laser Fiber (NMPA Class II; no Medison CE claim). Do not treat the partner-supplied NOVACURE console CE flag as a Medison CE claim. Do not assign an ISO 14971 residual-risk conclusion to any SKU. Checked 2026-08-27.
  13. Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, Annex I, Chapter I, General Safety and Performance Requirements. GSPR 2 defines the requirement to reduce risks as far as possible as reduction without adversely affecting the benefit-risk ratio. GSPR 3 requires a documented, iterative risk-management system. GSPR 4 requires residual risk for each hazard and overall residual risk to be judged acceptable, and requires risk-control measures in this order: inherently safe design and manufacture; protective measures; then information for safety, with users informed of residual risks. GSPR 8 requires all known and foreseeable risks and undesirable side-effects to be minimised and acceptable when weighed against evaluated benefits. EUR-Lex HTML retrieved 2026-08-27. Where the MDR and EN ISO 14971 differ, the MDR prevails; Implementing Decision (EU) 2022/757 publishes the harmonised-standard references and does not itself enact these GSPRs.
  14. Electronic Code of Federal Regulations, 21 CFR Part 820, Quality Management System Regulation, page current as of the 2026-08-27 retrieval. QMSR incorporates ISO 13485:2016 by reference at 21 CFR 820.7 and sets quality-management-system requirements at 21 CFR 820.10. Legacy QSReg design-control and CAPA section numbers 21 CFR 820.30 and 21 CFR 820.100 are reserved and are not current QMSR citations. Retrieved 2026-08-27.

Talk to VEMERIX

VEMERIX is the international brand of Weihai Medison Medical Equipment Co., Ltd., positioned as a Minimally Invasive Surgery Total Solution Platform serving urology, vascular surgery and perioperative care.