• Decrease font size
  • Return font size to normal
  • Increase font size
U.S. Department of Health and Human Services

Recognized Consensus Standards: Medical Devices

  • Print
  • Share
  • E-mail
-
Super Search Devices@FDA
510(k) | DeNovo | Registration & Listing | Adverse Events | Recalls | PMA | HDE | Classification | Standards
CFR Title 21 | Radiation-Emitting Products | X-Ray Assembler | Medsun Reports | CLIA | TPLC
 

New Search Back To Search Results
Part B: Supplementary Information Sheet (SIS)
FR Recognition List Number 053 Date of Entry 12/23/2019 
FR Recognition Number 5-125
Standard
ISO  14971 Third Edition 2019-12
Medical devices - Application of risk management to medical devices
Identical Adoption
ANSI AAMI ISO 14971: 2019
Medical devices - Applications of risk management to medical devices
Scope/Abstract
This International Standard specifies a process for a manufacturer to identify the hazards associated with medical devices, including in vitro diagnostic (IVD) medical devices, to estimate and evaluate the associated risks, to control these risks, and to monitor the effectiveness of the controls.
The requirements of this International Standard are applicable to all stages of the life-cycle of a medical device.
This International Standard does not apply to clinical decision making.
This International Standard does not specify acceptable risk levels.
This International Standard does not require that the manufacturer have a quality management system in place. However, risk management can be an integral part of a quality management system.
Extent of Recognition
Complete standard
Rationale for Recognition
This standard is relevant to medical devices and is recognized on its scientific and technical merit and/or because it supports existing regulatory policies.

Note: ISO 14971:2019 defines risk (3.18) as the combination of the probability of harm and its severity. FDA's Premarket Cybersecurity Guidance (See Ref #1 below) explicitly states this probabilistic model does not apply to cybersecurity, substituting exploitability - the feasibility and technical means by which a vulnerability can be exploited - as the operative basis for security risk estimation. Standards referencing risk for cybersecurity purposes should reflect this distinction.
Public Law, CFR Citation(s) and Procode(s)*
21 USC 360n-2: Ensuring cybersecurity of devices
Relevant FDA Guidance and/or Supportive Publications*
1. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, Guidance for Industry and Food and Drug Administration Staff, issued February 2026.

2. ISO/TR 24971 Second edition 2020-06 Medical devices - Guidance on the application of ISO 14971

3. AAMI/ISO TIR24971: 2020 Medical devices - Guidance on the application of ISO 14971

4. Appropriate Use of Voluntary Consensus Standards in Premarket Submissions for Medical Devices - Guidance for Industry and Food and Drug Administration Staff, issued September 2018.
FDA Technical Contacts
 Wil Vargas
  FDA/OC/CDRH/OCD/
  --
  wil.vargas@fda.hhs.gov
 Melissa Burns
  CDRH/OPEQ
  301-796-5616
  melissa.burns@fda.hhs.gov
Standards Development Organization
ISO International Organization for Standardization https://www.iso.org/
FDA Specialty Task Group (STG)
General I (QS/RM)
*These are provided as examples and others may be applicable.
-
-