Risk Management

Risk Management Services

Harmonized multi-scheme compliance, audit-ready documentation built to ISO 14971:2019, ISO/TR 24971:2020, FDA QMSR, EU MDR 2017/745, MDSAP across all five jurisdictions, and UK MDR 2002.

Why Risk Management Matters

Risk management is the backbone of every medical device quality management system. It is not a standalone activity — it is a process integrated into design, manufacturing, supplier management, post-market surveillance, and every decision that affects patient safety. It also remains one of the most frequently cited areas of nonconformity across regulatory frameworks.

Common Regulatory Nonconformities

Regulatory Landscape

ISO 14971:2019. Clauses 4–10 mandate the complete risk management process: risk management plan (4.4), risk analysis including hazard identification (5), risk evaluation (6), risk control with priority order per Clause 7.1 (7), evaluation of overall residual risk (8), risk management review (9), and production/post-production monitoring (10). Requires documented risk acceptability criteria and traceability throughout.

ISO/TR 24971:2020. Guidance on implementing ISO 14971. Covers benefit-risk analysis methodology, risk management for IVDs, cybersecurity risks, biological hazards, and QMS integration.

FDA QMSR (21 CFR 820, as amended, effective February 2, 2026). Incorporates ISO 13485:2016 by reference. ISO 13485 integrates risk-based requirements throughout the QMS — product realization, design and development, purchasing, production, monitoring, nonconforming product, and improvement. ISO 14971 remains the internationally recognized framework for medical-device product risk management, and enters the QMS through ISO 13485's risk-based requirements rather than by direct incorporation into QMSR.

EU MDR 2017/745, Annex I (GSPR). GSPR 1–9 mandate risk management throughout the device lifecycle. Requires risk-benefit analysis per Annex I §1. Annex II requires a risk management file in technical documentation. Annex XIV Part B requires PMCF data to feed the risk management file.

MDSAP (5 jurisdictions). MDSAP evaluates risk-management activities across its applicable audit processes, including Management, Design and Development, Production and Service Controls, Purchasing, and Measurement, Analysis and Improvement. Within the Design and Development process, risk-management activities are specifically reviewed as part of design controls, across all five participating authorities (FDA, Health Canada, TGA, ANVISA, MHLW/PMDA).

UK MDR 2002 (UKCA). Schedule 1 Essential Requirements mandate risk-benefit analysis consistent with EU MDR principles. MHRA requires risk management integrated with conformity assessment.

Regulatory update: FDA QMSR (effective February 2, 2026)

The Quality Management System Regulation incorporates ISO 13485:2016 by reference, replacing standalone 21 CFR 820 design control language with ISO-aligned, risk-based QMS requirements. ISO 14971 remains the recognized standard for medical device product risk management, integrated through ISO 13485's risk-based requirements rather than incorporated into QMSR directly.

Our Services

Risk Management System Development

Risk Management File Review & Remediation

Risk-Based Process Integration

Training & Competency Development

Complete Document Package — 14 Deliverables

Every engagement produces audit-ready documentation satisfying requirements across all applicable regulatory markets.

Engagement Models

Why SA Quality Solutions

Experience and Methodology

SAQMS services are developed and delivered based on applicable medical-device regulatory requirements, recognized international standards, audit practices, and practical quality-system implementation experience.

Our approach is grounded in:

Each engagement is structured around the client's products, processes, intended markets, regulatory obligations, quality-system maturity, and identified compliance risks.

SAQMS provides independent consulting, internal audits, supplier audits, readiness assessments, remediation support, documentation development, and implementation guidance. Services are performed against defined criteria and documented evidence, with findings and recommendations linked to applicable requirements.

SAQMS does not issue accredited certifications, regulatory approvals, or guarantees of audit or submission outcomes. Certification, regulatory decisions, laboratory testing, and conformity-assessment determinations remain the responsibility of the applicable authorized organizations and regulatory authorities.

Our Commitment

SAQMS delivers technically rigorous, objective, and practical support designed to help medical-device organizations:

All services are conducted with appropriate confidentiality, independence, professional judgment, and conflict-of-interest controls.

Ready to strengthen your risk management system?

Contact us for a complimentary initial assessment of your current risk management documentation.

Schedule a Consultation →