🏥 GHTF/SG3/N15R8 — Complete Interview-Ready Learning Breakdown
Risk Management Principles Within a Quality Management System
📖 SECTION 1 — FULL DOCUMENT BREAKDOWN
Module 1: What Is This Document and Why Does It Exist?
The Big Picture
Imagine you're a company that builds medical devices — say, an insulin
pump or a surgical robot. Two things are absolutely mandatory: you must
have a Quality Management System (QMS) (a set of organized processes to
ensure your product is consistently good) AND you must
manage risks (anything that could go wrong and harm a patient).
Historically, many companies ran these as two completely separate systems
— two sets of paperwork, two sets of procedures, two teams. This document
(published by the Global Harmonization Task Force, or GHTF, on May 20,
2005) essentially says: "Why not combine them? It saves money, reduces
duplication, and makes your overall system stronger."
Who is GHTF? The GHTF was a voluntary international group bringing
together medical device regulators and industry representatives
from Europe, the USA, Canada, Japan, and Australia. Their job was to
harmonize (make consistent) medical device rules across countries. This
document is non-binding — it's guidance, not law — but it is enormously
influential in shaping how companies think about risk management.
Module 2: Core Definitions (The Vocabulary Foundation)
Before going further, the document establishes precise definitions. These are
not casual words — in regulatory language, each word has an exact
meaning.
The Risk Chain: Think of it as a chain of events:
Hazard → Harm → Risk
A hazard is the potential source of danger (e.g., a sharp edge on a device)
Harm is the actual injury or damage that occurs (e.g., a cut to the user)
Risk is the combination of how likely harm is to occur AND how severe it
would be
Analogy: A wet floor in a hospital is the hazard. A nurse slipping and breaking
their wrist is the harm. The risk depends on: How often is this floor wet? How
bad would the injury typically be?
Module 3: The Four Phases of Risk Management
The document describes risk management as a life-cycle activity with four
interlocking phases:
Phase 1 — Establish Risk Acceptability Criteria Before you can say a risk is
"too high," you need to define what "too high" means. This is like setting a
speed limit before issuing speeding tickets. Companies look at similar
devices, regulatory expectations, and what patients/users consider
acceptable. This must be done first — everything else is measured against it.
Phase 2 — Risk Analysis Systematically ask: "What could go wrong?" Identify
every hazard (from device characteristics, intended use, foreseeable misuse,
manufacturing methods). Then estimate: How likely is harm? How severe
would it be?
Phase 3 — Risk Evaluation Compare your estimated risks against your
acceptability criteria from Phase 1. Decide: Do we need to reduce this
risk? Risk Analysis + Risk Evaluation together = Risk Assessment.
Phase 4 — Risk Control and Monitoring Take action to eliminate or reduce
risks. The document specifies a hierarchy(order of preference):
Inherent safety by design (safest option — build the hazard out)
Protective measures in the device or manufacturing
Information for safety (warnings, labels — least preferred, because humans
can ignore warnings)
After market release, continue monitoring for new hazards or unacceptable
risks throughout the device's entire life.
Module 4: Documentation and Communication (Section 3)
Documentation Risk management records can live in various places — a
dedicated Risk Management File, or integrated into the Design History File
(DHF), Technical File, Device Master Record, etc. The document recommends
integration for simplicity: one document control system, easier access, better
traceability.
Key principle: Document controls for risk management must match those for
the QMS — same rigor, same change control processes.
Communication — Two Types:
Internal: All relevant staff must know about residual risks (risks that remain
even after controls are applied). Annex A shows a Risk Chart — a two-
dimensional grid plotting Severity of Harm (S-1 to S-5) against Probability of
Occurrence (O-0 to O-6), with three color-coded zones: LOW, MEDIUM, HIGH.
This is used as an internal communication tool so everyone speaks the same
risk language.
External: Warning labels, user manuals, advisory notices — communicating
risks to users and patients.
Module 5: Management Responsibilities (Section 4)
This section is critically important for interviews. Top management cannot
delegate risk management away — it is their responsibility to:
Establish risk management policies
Set safety objectives as part of overall quality objectives
Ensure adequate resources are provided
Assign qualified personnel with defined roles and authorities
Conduct internal quality audits to verify risk management activities are
working
Include risk management results in Management Reviews
Why this matters: Regulators look specifically at whether leadership is
genuinely engaged in safety — not just signing paperwork. A risk
management system that exists only on paper but is ignored by
management is a serious red flag in an audit.
Module 6: Outsourcing (Section 5)
When a manufacturer outsources processes (sterilization, testing, component
manufacturing, etc.), they cannot outsource responsibility. The manufacturer
remains fully accountable.
Before approving any change to an outsourced process or product, the
manufacturer must:
Review the change
Assess whether new risks have been introduced
Determine if residual risks remain acceptable
Risk control measures that apply to outsourced activities must be clearly
documented in purchasing data and communicated to the supplier.
Module 7: Design and Development (Section 7) — The Most Detailed Section
This is the heart of the document. The design phase is where risk
management has its greatest impact, because changes are cheapest and
easiest here.
The Core Principle: Risk management is not a one-time event during design
— it is an iterative loop embedded throughout the entire design control
process.
The Design Control / Risk Management Cycle:
Risk Evaluation → Risk Control Measures → Design Input → Design Output →
Verification → (loop back if residual risks unacceptable)
The cycle continues until all residual risks are acceptable, then Design
Validation confirms the overall result.
7.1 Design Planning: Coordinate risk activities with design activities. Identify
interrelationships and resource needs (who has the safety expertise
needed?).
7.2 Design Inputs: The starting point. Inputs include intended use, functional
requirements, safety requirements, regulatory requirements, and lessons
from previous similar devices. Risk analysis begins here — creating a
preliminary hazard list from standards, vigilance databases, test reports, etc.
7.3 Design Outputs: Three categories, all potentially containing risk control
measures:
Device characteristics (e.g., over-temperature alarm, redundant power
source, watchdog timer)
Requirements for purchasing/production/servicing (e.g., stringent process
controls, lot size limits)
Acceptance criteria (e.g., torque specs, sterility requirements, leakage
current limits)
7.4 Design Reviews: Formal checkpoints asking: Have all hazards been
found? Are controls effective? Is residual risk communicated to users? Are
risk/benefit decisions valid? Reviewers must be competent to assess risk
acceptability.
7.5 Design Verification: Generates objective evidence (test results, analysis)
that risk controls were implemented and are effective. Requires traceability:
hazard → control measure → requirement → test plan → test result. (Annex C
shows a Risk Management Summary Table demonstrating this traceability for
a hypothetical infusion pump.)
7.6 Design Validation: Confirms the device meets user needs and overall
residual risk is acceptable in real-world use. Must include sufficient user
populations and all intended uses. Importantly: risk controls must be in place
before clinical trials begin.
7.7 Design Change Control: One of the most important and often
underestimated sections. The document states clearly: "seemingly trivial
changes may have unforeseen and sometimes catastrophic consequences."
Examples of changes requiring risk reassessment:
Changing material (even from a different supplier of the "same" material)
Replacing one machine with another
Cumulative effects of seemingly minor process changes
Changing suppliers or intended use
Any change in a system component requiring evaluation of the whole system
7.8 Design Transfer: Moving design from development to production. Must
ensure risk controls are implemented and effective. New issues must be
resolved before production release.
Module 8: Traceability (Section 8)
Risk management data defines what needs to be traceable — which devices,
components, materials, and work environment conditions require tracking.
Factors driving traceability requirements include:
Origin of components/materials
Processing history
Distribution and location after delivery
Whether the device is life-sustaining, life-supporting, or implantable
Probability of failure
Need for safety updates (recalls, advisory notices)
Consequences of failure for patients/users
Module 9: Purchasing Controls (Section 9)
Risk management must reach into the supply chain. Supplier selection
criteria must be based on risk associated with hazards from their
products/services. Acceptance criteria for purchased items must reflect
identified hazards and their associated risk controls. Risk management roles
and responsibilities must be defined in purchasing requirements.
Module 10: Production and Process Controls (Section 10)
Manufacturing itself introduces hazards — from equipment, processes, work
environment, or personnel variability. These must be identified (preferably
during design, but can be found during production) and controlled through
documented procedures.
Risk Assessment Tools for Manufacturing:
FMEA (Failure Modes and Effects Analysis)
HAZOP (Hazard and Operability Study)
FTA (Fault Tree Analysis)
HACCP (Hazard Analysis and Critical Control Points)
PAT (Process Analytical Technology)
Production data (nonconformity rates, rework rates, scrap, yield) should be
evaluated against risk management outputs to confirm controls are
adequate.
Process Validation may be required based on risk management results. When
processes change, existing risk controls must be reviewed for continued
suitability.
Module 11: Servicing, Data Analysis, and CAPA (Sections 11–13)
Servicing: Repair and maintenance can be a risk control measure itself (e.g.,
mandatory part replacement intervals). Servicing processes may need the
same risk controls as manufacturing. Safety hazards to service personnel
require clear instructions and training.
Analysis of Data (Section 12): Post-market information feeds back into risk
assessments. Sources include: competitor device information, market
surveillance, published literature, recall databases, vigilance reports,
scientific literature.
CAPA (Section 13): Figure 1 in the document shows the CAPA-Risk
Management integration loop. CAPA data sources (service reports,
complaints, nonconformities, audit findings, supplier issues) flow into
investigation and data trending, which connects back to the risk
management process. CAPA results should reveal previously unrecognized
risks and assess whether existing controls are effective.
Classic example from the document: A service report reveals a safety issue →
investigation finds a manufacturing process change was made → this triggers
a revised risk assessment → new or revised controls become part of CAPA
actions.
Module 12: The Annexes
Annex A — Risk Chart: A 2D grid. X-axis: Severity of Harm (S-1 Negligible →
S-5 Catastrophic). Y-axis: Probability of Occurrence (O-0 None Observed → O-
6 Always). Three zones: LOW, MEDIUM, HIGH. Used as an internal
communication and decision-making tool.
Annex B — Design and Development Flowchart: Shows the iterative risk
management process overlaid on the design control process, with decision
diamonds at each stage (Is hazard assessment acceptable? Do residual risks
meet criteria? Does overall residual risk meet criteria? Do benefits outweigh
risks?). Negative answers at final stages lead to project cancellation or
redesign.
Annex C — Risk Management Summary Table: An infusion pump example
showing columns for Hazard ID, Contributing Factors, Risk Level Before
Control, Risk Level After Control, Risk Control Measure, Requirement ID, Test
ID, and Status. This demonstrates traceability in practice.
🔑 SECTION 2 — KEY TERMS GLOSSARY
Full Form (if Why It Matters in
Term Simple Definition
any) Medical Devices
International group Source of influential
Global
harmonizing medical device guidance
GHTF Harmonization
regulations across USA, EU, documents like this
Task Force
Canada, Japan, Australia one
Legal requirement
Quality Organized set of processes
in most markets;
QMS Management ensuring consistent product
ISO 13485 is the
System quality
primary standard
The central
Probability of harm × measurement used
Risk —
severity of harm to decide if a device
is safe enough
Must be
systematically
Any potential source of
Hazard — identified before
harm
risk can be
estimated
Full Form (if Why It Matters in
Term Simple Definition
any) Medical Devices
Actual physical injury,
The outcome we
health damage, or
Harm — are trying to
property/environmental
prevent
damage
Systematic identification of First step in
Risk
— hazards and estimation of knowing what
Analysis
risks you're dealing with
Risk Comparing estimated risk Determines if action
—
Evaluation to acceptability criteria is needed
Risk Risk Analysis + Risk The overall
—
Assessment Evaluation combined judgment process
Actions taken to reduce or The "doing
Risk Control — maintain risks at acceptable something about it"
levels phase
Must be
Residual Risk that remains after communicated to
—
Risk controls are applied users; must still be
acceptable
Systematic application of
Risk
policies and procedures to The overarching
Managemen —
analyze, evaluate, and umbrella process
t
control risk
Must be established
Risk Pre-defined thresholds for BEFORE analysis —
Acceptabilit — what level of risk is everything is
y Criteria tolerable measured against
this
Process to fix known Critical QMS tool;
Corrective and
problems (corrective) and integrates with risk
CAPA Preventive
prevent future ones management post-
Action
(preventive) market
DHF Design History Collection of records Where design-
Full Form (if Why It Matters in
Term Simple Definition
any) Medical Devices
related risk
describing the design
File documents often
history of a finished device
reside
Method analyzing all ways a Widely used in
Failure Modes
process/product could fail medical device
FMEA and Effects
and the impact of each manufacturing and
Analysis
failure design
Common in
Hazard and Structured technique to
pharmaceutical and
HAZOP Operability identify hazards in process
device
Study operations
manufacturing
Useful for complex
Top-down approach
Fault Tree systems with
FTA mapping causes that could
Analysis multiple failure
lead to a specific failure
paths
Hazard Risk-based approach Originally from food
Analysis and identifying critical points in safety; now used in
HACCP
Critical Control a process where hazards device
Points must be controlled manufacturing
Process Tools for measuring and
Enables risk-based
PAT Analytical controlling manufacturing
process control
Technology processes in real time
The primary risk
International standard for
management
application of risk
ISO 14971 — standard referenced
management to medical
throughout this
devices
document
The primary QMS
International standard for
standard for
ISO 13485 — QMS requirements specific
medical device
to medical devices
manufacturers
Vigilance — Regulatory database Source of risk data
Database tracking adverse events for hazard
Full Form (if Why It Matters in
Term Simple Definition
any) Medical Devices
and device failures identification
Inherent Designing out hazards at Highest priority in
Safety by — the source rather than the risk control
Design adding protective measures hierarchy
Risk Organized collection of all Central repository
Managemen — risk management records ensuring
t File for a device traceability
Code/reference used to Enables traceability
Hazard
HazID uniquely identify and track in risk management
Identification
a specific hazard tables
All phases of a device's Risk management
Life Cycle — existence: design through must span the
disposal entire life cycle
SECTION 3 — CONCEPT DEEP DIVES
Deep Dive 1: Risk Acceptability Criteria
Simple Explanation: Before playing any game, you agree on the rules. Risk
acceptability criteria are the rules that decide how much danger is "OK" for a
medical device. Without these rules set in advance, every risk decision
becomes subjective and inconsistent.
Technical Explanation: Risk acceptability criteria are predetermined
thresholds against which estimated risks are evaluated during risk
evaluation. They may be expressed qualitatively (High/Medium/Low regions
on a risk chart) or quantitatively (e.g., probability of harm < 1 in 10,000
uses). They should reflect the state-of-the-art in risk control, existing
regulatory expectations, and the benefit-risk profile of the device. They must
be established before risk analysis begins — otherwise there is a temptation
to adjust criteria to make a problematic risk "acceptable."
Real-World Example: For a pacemaker, the risk acceptability criteria might
specify that any hazard with a probability of causing catastrophic harm
(patient death) above a remote likelihood is categorically unacceptable,
regardless of benefit considerations.
Common Misconception: Misconception: Risk acceptability criteria are fixed
universal standards that every company must use. Reality: They are
company-defined and device-specific. A criterion appropriate for a tongue
depressor would be completely inadequate for an implantable cardiac
device. The key is that they must be justified, documented, and applied
consistently.
Deep Dive 2: The Risk Control Hierarchy
Simple Explanation: If you want to prevent kitchen fires, the best solution is
to build a kitchen that can't catch fire (inherent safety). Second best is a
sprinkler system (protective measure). Least effective is just putting up a
sign saying "Don't start fires." The hierarchy follows this same logic.
Technical Explanation: The hierarchy prescribed by many regulatory schemes
requires manufacturers to examine control options in this order:
Inherent safety by design: Eliminate the hazard entirely through design
choices (e.g., using non-toxic materials instead of toxic ones)
Protective measures: Guard against the hazard in the device or its
manufacture (e.g., physical guards, interlocks, alarms)
Information for safety: Warn users about the residual risk (e.g., warning
labels, training requirements)
Higher-order controls are preferred because they are more reliable — they
don't depend on human behavior. Warning labels are the least preferred
because humans can ignore, misread, or fail to act on them. Manufacturers
must justify why higher-order controls were not feasible before resorting to
lower-order ones.
Real-World Example: For an X-ray machine: inherent safety would be
shielding built into the cabinet; a protective measure would be an interlock
that stops X-ray emission when the door opens; information for safety would
be a warning label on the door.
Common Misconception: Misconception: Adding more warning labels is
always sufficient to address a risk. Reality:Labels are the last resort.
Regulators expect manufacturers to exhaust design-based and protective
measure options first. Heavy reliance on labels signals inadequate design
thinking.
Deep Dive 3: Residual Risk
Simple Explanation: No matter how many safety measures you add to a
device, some danger always remains — like how even the safest car can still
be involved in an accident. That remaining danger after all your safety
measures is called residual risk.
Technical Explanation: Residual risk is the risk remaining after all risk control
measures have been applied. It exists at two levels:
Individual residual risk: Remaining risk from each specific hazard
Overall residual risk: The combined total of all individual residual risks
Both must meet acceptability criteria. Even if each individual risk is
acceptable, the combined effect could be unacceptable. Residual risks must
be communicated to users through labeling, manuals, and training materials.
Design reviews and validation specifically assess whether residual risks have
been communicated and whether the overall benefit-risk determination is
valid.
Real-World Example: An infusion pump with a watchdog timer (which stops
the pump if the microprocessor locks up) still has a residual risk that the
watchdog itself might fail. This residual risk must be communicated in the
service manual and evaluated as part of overall risk.
Common Misconception: Misconception: If all individual residual risks are
acceptable, then the overall risk is automatically acceptable. Reality: The
overall residual risk must be separately evaluated. Multiple acceptable
individual risks can combine to create an unacceptable overall risk — this
must be explicitly assessed and documented.
Deep Dive 4: CAPA–Risk Management Integration
Simple Explanation: Think of CAPA as your "problems and fixes" system and
risk management as your "dangers and protections" system. This section
says these two systems must talk to each other constantly — what you find
in one must automatically inform the other.
Technical Explanation: The CAPA process receives inputs from complaints,
service reports, manufacturing nonconformities, internal and external audits,
and purchased part problems. When CAPA investigations identify previously
unrecognized risks or failures of existing risk controls, this information must
feed back into the risk management process to trigger a revised risk
assessment. Conversely, risk management outputs (new or revised risk
controls) become CAPA actions. This creates a closed-loop system essential
for post-market surveillance effectiveness.
Real-World Example: A complaint about unexpected device behavior after a
supplier changed their manufacturing process triggers a CAPA. Investigation
reveals the process change was not assessed for risk impact. A revised risk
assessment is initiated, new controls are implemented, and these controls
become CAPA corrective actions. The investigation also generates a
preventive action: update the supplier change control process to require
mandatory risk assessment.
Common Misconception: Misconception: CAPA is purely a quality system
process separate from risk [Link]: CAPA and risk management
are deeply integrated. Every significant CAPA has risk management
implications and vice versa. Auditors specifically look for evidence of this
integration.
Deep Dive 5: Design Change Control and Risk
Simple Explanation: Changing even one small part of a medical device is like
changing one ingredient in a complex recipe — it can affect everything else
in ways you never expected. This is why even "trivial" changes require
formal risk assessment.
Technical Explanation: Design change control requires that any proposed
change to a device or its manufacturing processes be evaluated for effects
on safety, based on existing risk management and design documentation.
Changes can introduce new hazards, eliminate existing ones, or alter risk
levels. The risk assessment must be reviewed and updated. The evaluation
must consider cumulative effects (multiple small changes together), system-
level effects (a change to one component in a system requires evaluation of
the entire system), and supplier-level effects (a supplier's change to their
process is a change that affects your risk profile). Prior to implementation,
individual and overall residual risks must be confirmed as acceptable.
Real-World Example: A manufacturer changes the adhesive used to bond a
catheter tip, from Supplier A to a nominally identical product from Supplier B.
Even though the adhesive specification appears identical, the bond strength,
curing behavior, and biocompatibility profile may differ slightly. If not risk-
assessed, this "trivial" change could result in tip separation inside a patient's
vasculature.
Common Misconception: Misconception: Only major changes (like
redesigning a core function) need risk [Link]: The document
explicitly states that "seemingly trivial changes may have unforeseen and
sometimes catastrophic consequences." Every change — including supplier
changes and process equipment replacements — requires evaluation.
Deep Dive 6: Traceability in Risk Management
Simple Explanation: Traceability means you can trace a thread from any
identified danger, all the way through the safety measure you designed, the
requirement it was captured in, the test that proved it works, and the test
result. If any link in that chain is missing, you can't prove your device is safe.
Technical Explanation: Traceability connects: Hazard → Risk Control Measure
→ Design Requirement (RqtID) → Test Plan/Procedure (TestID) → Test
Result/Status. This is demonstrated in Annex C's Risk Management Summary
Table for an infusion pump. Traceability must be maintained throughout the
device life cycle and is a key target of regulatory inspections. It provides
objective evidence that every identified hazard has been addressed and that
the addressing was verified to be effective.
Real-World Example: For the infusion pump in Annex C, Hazard 3.1.2
(unauthorized tampering with settings) is controlled by a keyboard lock. This
is traced to Software Requirements Document paragraph 7.2 (the
requirement) and System Test Procedure Section 17 (the test that verifies it
works). An auditor can follow this chain to confirm the control exists, is
specified, and was tested.
Common Misconception: Misconception: A risk management file is complete
if it lists all the hazards and [Link]: Without traceability to design
requirements and verification/validation evidence, the file is incomplete.
Regulators need to see the full chain of evidence, not just a list.
🎯 SECTION 4 — INTERVIEW PREPARATION
A. Basic Questions (Fresher Level)
Q1: What is risk management in the context of medical devices?
Risk management in medical devices is the systematic application of
policies, procedures, and practices to analyze, evaluate, and control risks
associated with a medical device throughout its entire life cycle. It involves
identifying what could go wrong (hazard identification), estimating how likely
and severe the harm could be (risk analysis), deciding if the risk is
acceptable (risk evaluation), and taking steps to reduce it (risk control). The
goal is not to eliminate all risk — which is often impossible — but to reduce
risk to an acceptable level while maintaining the device's clinical benefits
and functionality.
Q2: Define: hazard, harm, and risk. How are they related?
A hazard is any potential source of harm — for example, a sharp edge,
electrical current, or toxic material in a device. Harm is the actual physical
injury or health damage that occurs — for example, a laceration or electric
shock. Risk is the combination of two factors: the probability that the harm
will occur and the severity of that harm if it does occur. The relationship is: a
hazard has the potential to cause harm, and the actual risk depends on how
likely that harm is and how bad it would be. You can have a hazard that
poses very low risk (e.g., a sharp edge that is completely guarded and only
accessible by trained technicians during rare maintenance) or a moderate
hazard that poses high risk (e.g., if used frequently by untrained users).
Q3: What are the four phases of risk management described in this guidance
document?
The four phases are:
Establishing risk acceptability criteria — defining in advance what level of
risk is tolerable
Risk analysis — identifying hazards, estimating probability of harm and
severity of harm
Risk evaluation — comparing estimated risks to the acceptability criteria to
determine if risk reduction is needed
Risk control and monitoring — implementing measures to reduce risks and
continuously monitoring to ensure risks remain acceptable throughout the
device life cycle
Q4: What is the difference between risk analysis, risk evaluation, and risk
assessment?
Risk analysis is the process of identifying hazards and estimating the
associated risks. Risk evaluation is the judgment process of comparing those
estimated risks to pre-defined acceptability criteria to determine whether the
risk is acceptable. Risk assessment is the combination of both — it is the
overall process comprising risk analysis followed by risk evaluation. Think of
it this way: analysis tells you the risk level; evaluation tells you whether that
level is acceptable.
Q5: What is residual risk?
Residual risk is the risk that remains after all risk control measures have
been applied. No matter how many safety measures are incorporated into a
device, some level of risk will always remain — it is physically and practically
impossible to eliminate all risk. Residual risk must meet the manufacturer's
pre-defined acceptability criteria. It must also be communicated to users
through appropriate means such as warning labels, user manuals, and
training materials, so they can make informed decisions about using the
device.
Q6: Why should risk management start early in the design phase?
Risk management should start as early as possible in the design phase
because it is far easier and cheaper to address safety issues during design
than to fix them later. Design changes during early development may require
modifying drawings and documentation. The same change after regulatory
submission could require re-testing, re-submission, and potential device
recall. Additionally, early risk identification influences design inputs, meaning
safety requirements are built into the device from the beginning rather than
added as afterthoughts. The document states this directly: it is "easier to
prevent problems rather than correcting them later."
Q7: What is the hierarchy of risk control measures?
The hierarchy, from most preferred to least preferred, is:
Inherent safety by design — eliminate the hazard by design choices
Protective measures — add guards, interlocks, or safeguards to the device or
its manufacture
Information for safety — provide warnings, labels, training, and instructions
This hierarchy is important because higher-order controls are more reliable
and less dependent on human behavior. Warning labels (the lowest order)
are least preferred because humans can ignore or misunderstand them.
Q8: What documents can contain risk management records?
Risk management records can be maintained in or referenced from: the Risk
Management File, Design History File (DHF), Technical File/Technical
Documentation, Design Dossier, Device Master Record (DMR), Device History
Record (DHR), or Process Validation files. The document recommends
integrating risk management documentation directly into QMS
documentation for efficiency — creating a single document control system
with ease of access, review, and retention.
Q9: What is CAPA and how does it relate to risk management?
CAPA stands for Corrective and Preventive Action. Corrective actions fix
known problems; preventive actions prevent potential problems from
occurring. CAPA receives inputs from complaints, service reports,
manufacturing nonconformities, and audit findings. These inputs may reveal
previously unrecognized risks or indicate that existing risk controls are
failing. When this happens, the risk management process must be revisited
and updated. Conversely, when risk management identifies new risks, CAPA
actions may be needed to implement new controls. The two systems are
deeply integrated and must communicate continuously.
Q10: Who is responsible for risk management activities when a manufacturer
outsources processes?
The manufacturer remains fully responsible for risk management, even when
processes are outsourced. Outsourcing does not transfer risk management
responsibility to the supplier. The manufacturer must incorporate appropriate
risk management activities for all outsourced processes and products, ensure
risk control measures are communicated to suppliers in purchasing
documents, and review any changes to outsourced processes for new risk
implications. The document explicitly states: "Risk management activities
relating to any process within the quality management system are ultimately
the responsibility of the manufacturer."
B. Intermediate Questions (1–3 Years Experience)
Q1: How is risk management integrated into the design and development
process? Walk me through the cycle.
Risk management is deeply embedded in every stage of design control:
During design planning, risk management activities are scheduled alongside
design activities, and resources with appropriate safety expertise are
identified. During design input, hazard identification begins — drawing on
intended use, device characteristics, manufacturing methods, and post-
production data from similar devices. Risk evaluation determines which
hazards require control measures, and these requirements become part of
the design input.
During design output, risk control measures are incorporated into device
specifications, purchasing/production requirements, and acceptance criteria
(as shown in Table 1 of the document). During design verification, objective
evidence is generated that controls were implemented and are effective,
with full traceability from hazard to control to requirement to test result.
During design validation, the overall residual risk is confirmed as acceptable
in the context of real-world use with actual or representative users. Design
reviews at appropriate stages assess whether hazard identification is
complete, controls are effective, and residual risks are properly
communicated.
This cycle is iterative — if residual risks don't meet acceptability criteria, the
loop repeats until they do. Failure to achieve acceptable risk despite all
feasible controls leads to project cancellation or redesign.
Q2: What is the significance of design change control from a risk
management perspective?
Design change control is one of the most critical risk management activities
because seemingly minor changes can have unforeseen safety
consequences. From a risk management perspective, every proposed change
must be evaluated against the existing risk assessment to determine
whether it introduces new hazards, eliminates existing ones, or changes risk
levels.
The evaluation must consider: direct effects on the changed element,
system-level effects (if the device is part of a system), cumulative effects (if
multiple small changes have been made over time), and supplier changes (a
supplier changing their own process counts as a change that affects the
manufacturer's risk profile).
Before implementation, both individual and overall residual risks must be
confirmed as acceptable under the updated risk assessment. This is not
bureaucratic formality — the document cites historical examples where
trivial changes led to catastrophic outcomes.
Q3: Explain the Risk Management Summary Table in Annex C. What does it
demonstrate?
The Risk Management Summary Table in Annex C demonstrates traceable
risk management documentation using an infusion pump example. It
contains: HazID (a hierarchical hazard identifier, e.g., 3.1.2 = Dosage →
Overdose → Tampering with settings); Contributing Factors (specific
causes); Risk Level Before Control and After Control (using a
severity/likelihood coding scheme with color-coded acceptability zones); Risk
Control Measure (the specific action taken); RqtID (pointer to the design
requirement documenting the control); TestID (pointer to the test procedure
verifying the control works); and Status (tracking whether testing is
complete).
This table demonstrates traceability — the ability to follow a chain from any
hazard through its control, requirement, and verification evidence. This is
exactly what auditors look for, and it provides objective evidence that every
hazard has been addressed, specified, and tested.
Q4: How should risk management activities inform supplier selection and
purchasing controls?
Risk management activities must feed directly into purchasing controls.
When hazards have been identified that relate to purchased products or
components (e.g., biocompatibility of a material, dimensional accuracy of a
critical part, sterility of an accessory), the risk level associated with those
hazards should drive the rigor of supplier qualification.
High-risk supplier relationships require more stringent qualification criteria,
more frequent re-evaluation, and more detailed incoming acceptance
activities. Risk control measures applicable to purchased items must be
clearly specified in purchasing documents and communicated to suppliers.
Acceptance activities for incoming materials must be designed around the
identified hazards — not just general quality specifications.
Q5: What risk assessment tools are referenced in this document for
manufacturing processes?
The document references five tools: FMEA (Failure Modes and Effects
Analysis — analyzing how each step of a process could fail and what the
impact would be), HAZOP (Hazard and Operability Study — structured
technique using guidewords to identify deviations from design
intent), FTA (Fault Tree Analysis — top-down mapping of causes leading to a
top-level failure event), HACCP (Hazard Analysis and Critical Control Points —
identifying critical control points in a process where hazards must be
monitored and controlled), and PAT (Process Analytical Technology — real-
time measurement and control of manufacturing processes).
These tools help identify what can go wrong at each process step, the impact
of failures on the device, the likelihood of failures, and what controls can
detect or prevent them.
Q6: What is the difference between design verification and design validation
from a risk management perspective?
Design verification answers: "Did we build what we designed?" From a risk
management perspective, it generates objective evidence that specific risk
control measures were implemented as planned and are effective
individually. It is conducted through testing, analysis, and inspection against
defined requirements. Design validation answers: "Did we design the right
thing?" From a risk management perspective, it confirms that the overall
residual risk — the sum of all remaining risks — is acceptable in the context
of actual intended use by the intended user population.
Validation must include sufficient numbers of representative users and all
intended uses. Any new hazards discovered during validation must be
assessed. Crucially, risk controls must be finalized before clinical trials begin
(noted specifically in Section 7.6).
Q7: How does post-market surveillance data feed back into the risk
management process?
Post-market information — complaints, service reports, adverse events,
vigilance reports, competitor device information, scientific literature — must
be continuously monitored and analyzed. This data is evaluated against the
current risk assessment to determine if existing risk controls remain
adequate and if any new hazards have emerged.
If post-market data reveals that a previously acceptable risk has become
unacceptable (due to higher-than-expected occurrence rates or more severe-
than-expected outcomes), the risk assessment must be revised and risk
controls updated. This feeds into CAPA as well. The document emphasizes
this is not optional — it is an ongoing obligation throughout the device life
cycle.
Q8: What are the key elements a design review should assess from a risk
management perspective?
Design reviews from a risk management perspective should assess: whether
all hazards have been identified and risks properly assessed; the
effectiveness of risk control measures for individual risks; whether residual
risks are adequately communicated to users; the validity of benefit-risk
decisions regarding overall residual risk acceptance; and whether new risk-
related issues identified during design transfer were identified and
controlled. Reviewers must have competence to assess risk acceptability
decisions — not just general design competence.
Q9: What considerations does this document highlight for combination
devices or devices used with other equipment?
When a device is intended to be used in combination with, installed with, or
connected to another device or equipment, hazards and risk control
measures must be evaluated at two levels: for each individual device
separately, and for the combined system as a whole. System-level hazards
may emerge from the interaction of components that would each be safe in
isolation. This principle also applies to design changes: if any single
characteristic of a device that is part of a system changes, the entire system
must be evaluated.
Q10: Describe the role of management in risk management according to this
guidance.
Top management has direct responsibilities that cannot be delegated:
establishing risk management policies, setting safety objectives as part of
overall quality objectives, ensuring risk management is incorporated into
quality planning, providing sufficient resources, and assigning qualified
personnel with defined responsibilities.
Management must ensure internal quality audits include risk management
activities and that audit results feed into management reviews. The
document is explicit that management review of the QMS should include
information from risk management activities. This means risk management
performance is a board-level/executive concern, not just an engineering
function. During regulatory inspections, investigators specifically examine
whether management is genuinely engaged in risk management or simply
approving documents without understanding them.
C. Advanced / Tricky Questions (Senior / Expert Level)
Q1: How would you integrate risk management into a QMS that was
originally designed without it? What challenges would you anticipate?
Integration requires a systematic gap analysis across all QMS processes:
design control, purchasing, production, CAPA, management review, and
document control. For each QMS process, you identify where risk
management activities should be embedded (inputs, activities, outputs,
records) and update procedures accordingly.
Key challenges include: cultural resistance (staff accustomed to separate
systems), training gaps (risk management vocabulary and tools), document
control complexity (linking existing QMS documents to new risk management
records), and ensuring traceability is established retrospectively for existing
devices. The risk management file must index where each risk management
requirement is satisfied within the integrated system. Leadership
commitment is essential — risk management cannot be grafted onto a QMS
as a bureaucratic layer; it must genuinely inform design, manufacturing, and
monitoring decisions. Ongoing challenge is maintaining integration
discipline: ensuring each QMS process genuinely consults risk management
data rather than treating it as a parallel paper exercise.
Q2: Explain why the document states that "relying exclusively on design and
development processes to control risk is not sufficient." What does this imply
for the manufacturer?
This statement acknowledges a fundamental reality: even perfectly designed
devices can be manufactured imperfectly, used incorrectly, maintained
improperly, or cause harm through mechanisms not anticipated during
design. Manufacturing processes introduce their own hazards — equipment
variability, human error, material inconsistencies. Users may use devices in
ways not fully captured during validation. Devices change over time through
wear, sterilization cycles, or environmental exposure.
This implies manufacturers must maintain active risk management
throughout the entire life cycle: in production and process controls
(monitoring manufacturing hazards), in purchasing controls (managing
supplier-introduced risks), in servicing (ensuring maintenance doesn't
introduce new hazards), in post-market surveillance (capturing real-world
evidence of new or higher-than-expected risks), and in CAPA (using quality
system data to continuously update risk assessments). Risk management is
not a design-phase deliverable — it is a permanent operational function.
Q3: A design change involves replacing a component from Supplier A with a
nominally identical component from Supplier B. How would you approach the
risk assessment for this change?
This is a classic scenario where the document explicitly warns against
treating the change as trivial. The approach:
First, review the current risk assessment to identify all hazards associated
with that component and the risk controls in place. Second, evaluate
differences between Supplier A and Supplier B: material composition (even
trace differences), manufacturing processes, dimensional tolerances, surface
finishes, biocompatibility data, sterilization compatibility, and any historical
quality data. Third, consider the component's criticality: is it a life-sustaining
function? Does it interact with biological tissue? Is it a safety-critical part?
Fourth, determine whether existing risk controls remain adequate for the
new supplier's component, and whether new hazards have been introduced.
Fifth, update the risk assessment documentation and obtain necessary
verification/validation evidence (testing, certificates of compliance,
biocompatibility data). Finally, update the Design History File, purchasing
specifications, and communicate changes to affected parties. Even if the
conclusion is that risk levels are unchanged, this evaluation must be
documented.
Q4: How does this document address the tension between risk reduction and
device functionality/commercial feasibility?
The document acknowledges this tension explicitly: risk control measures
"can be influenced by technical and business feasibility considerations, as
well as considerations of device functionality." It states that "the objective of
risk management is rarely to eliminate all risk, but rather to reduce risk to an
acceptable level while maintaining feasibility and functionality."
The Annex B flowchart addresses this through the benefit-risk determination
step: "Do the benefits of providing the device outweigh the risks of using the
device?" This is where clinical benefit is weighed against residual risk. If it
does not, the project must be cancelled or redesigned.
The important implication: commercial pressure does not justify accepting
unacceptable risks. Risk acceptability criteria must be established objectively
before business pressures emerge, and must not be retroactively adjusted to
accommodate a device that fails to meet them. Senior professionals must be
prepared to escalate to management when commercial timelines are being
prioritized over genuine risk reduction.
Q5: What would an inadequate risk management system look like during a
regulatory inspection? What are the red flags?
Red flags that indicate an inadequate risk management system:
No traceability: Hazards listed without linkage to controls, requirements, or
test evidence
Pre-set acceptability criteria absent or established after-the-fact: Suggesting
criteria were adjusted to make unacceptable risks look acceptable
Risk management file not updated after design changes: Especially for
"minor" changes
No integration with CAPA: CAPA actions not feeding back into risk
assessments, and risk management updates not generating CAPA actions
Incomplete hazard identification: Only obvious hazards listed, with no
systematic analysis of misuse scenarios, combination use, or manufacturing
hazards
Labels as primary risk controls: Heavy reliance on warnings without evidence
that design-based and protective measure options were exhausted
Management not engaged: Risk management records signed without
evidence of substantive review; safety objectives not reflected in quality
objectives
Post-market data not feeding back: No evidence that complaint data, service
reports, or vigilance information was evaluated against the current risk
assessment
Q6: How does the document's guidance on traceability go beyond simply
keeping records?
True traceability, as described in the document, creates an interconnected
web of evidence that allows anyone — a new engineer, a regulator, a
defense attorney — to follow any safety decision from its origin (hazard
identification) through its implementation (design requirement) and proof of
effectiveness (verification test result). This is not just record-keeping; it is an
argument for safety.
Traceability failures are among the most commonly cited issues in regulatory
actions. They make it impossible to demonstrate that a specific risk was
addressed and that the addressing was confirmed effective. Traceability also
supports change control: when a change is proposed, traceability allows the
risk team to immediately identify all hazards, controls, requirements, and
tests that are potentially affected. Without this, change impact assessment is
incomplete by definition.
Q7: The document mentions that risk control measures must be established
before clinical trials. Why is this particularly important?
Clinical trials expose human subjects to the device under investigation. If risk
control measures are not finalized before trials begin, participants are
exposed to uncontrolled risks — both known and potentially unknown. This
creates ethical obligations (informed consent cannot be complete if risks are
not fully characterized), regulatory obligations (most regulatory frameworks
require risk assessment prior to first-in-human studies), and legal
implications.
Additionally, clinical trial data is generated under specific device
configurations. If risk controls change after trial completion, the safety and
performance data may no longer apply to the marketed version of the
device, potentially invalidating the trial results. From an operational
standpoint, this means the risk management file must be sufficiently mature
to support trial initiation, even though it will continue to be updated based
on trial findings.
Q8: How should process validation decisions be informed by risk
management?
Risk management determines which processes need validation and how
rigorous that validation must be. Processes whose variability is an identified
hazard — where the output cannot be fully verified by subsequent inspection
— are candidates for validation. The higher the risk associated with process
variability, the more comprehensive the validation must be.
Risk management tools (FMEA, HAZOP, FTA) should be used during validation
planning to identify worst-case scenarios and edge conditions that the
validation protocol must address. If process validation reveals that previously
estimated risk levels were inaccurate, the risk assessment must be updated.
When process changes occur, existing risk controls must be reviewed and
the need for revalidation assessed based on the risk implications of the
change.
Q9: How would you handle a situation where post-market data suggests a
risk was significantly underestimated during design?
This is a serious situation requiring immediate, structured response:
First, immediately escalate to management and initiate a formal risk
assessment revision. Second, evaluate whether the current risk level (based
on post-market evidence) still meets acceptability criteria, or whether it is
now unacceptable. If unacceptable, the device may need to be temporarily
restricted while additional controls are implemented.
Third, investigate root cause: Was the hazard identification incomplete? Were
probability estimates based on flawed assumptions? Were risk controls less
effective than expected? Fourth, implement revised or additional risk controls
— following the hierarchy. Fifth, if a field action (recall, advisory notice, field
upgrade) is needed to address devices already in use, initiate the
appropriate regulatory notification process.
Sixth, update all risk management documentation, CAPA records, and
communicate to users as appropriate. Seventh, conduct a broader review of
the risk management process to understand whether other risks may have
been similarly underestimated.
Q10: What is the significance of the phrase "state-of-the-art" in the context
of risk acceptability criteria?
"State-of-the-art" in medical device risk management refers to the current
level of risk that is generally accepted as achievable using existing
technology and knowledge. Risk acceptability criteria "should be reflective of
state-of-the-art in controlling risks."
This is significant because it means acceptability is not static — it evolves
with technology and knowledge. A risk level that was acceptable in 2000
when no better control existed may be unacceptable today if superior control
technology is now available and widely implemented. Manufacturers cannot
justify continued acceptance of a risk simply because it was previously
accepted.
During audits and regulatory reviews, demonstrating awareness of the
current state-of-the-art and actively monitoring for relevant advances in risk
control technology is an expectation. Post-market surveillance must include
monitoring published literature and competitor devices, in part to identify
improvements in risk control that the manufacturer may be obligated to
adopt.
D. Scenario-Based Questions
Scenario 1: A patient complaint is filed stating that an infusion pump
delivered an overdose. You are the risk manager. What do you do?
Step-by-step response:
Intake and triage: Enter the complaint into the complaint handling system.
Assess whether this is a serious adverse event requiring regulatory reporting
(based on jurisdiction-specific timelines — typically 30 days for serious
events, immediately if life-threatening).
Preliminary investigation: Gather all information: device serial number, lot
number, date of manufacture, service history, software version, user
information, and clinical context. Retrieve the device if possible for physical
inspection.
Risk assessment review: Pull the current risk management file for this device.
Identify existing hazards related to overdose (Section 3.0 in the Annex C
example). Review the risk controls in place and whether they appear to have
functioned as intended.
Investigation: Determine the root cause — was it user error, device
malfunction, software failure, a manufacturing defect, or a design issue? Was
any recent process change, software update, or component change made?
Risk reassessment: Based on investigation findings, update the risk
assessment. If the incident represents a previously unrecognized failure
mode or a higher-than-expected occurrence rate, revise risk levels
accordingly and determine if they still meet acceptability criteria.
CAPA initiation: If root cause reveals inadequate risk controls, failing controls,
or process failures, initiate CAPA. New or revised risk controls become CAPA
corrective actions. Preventive actions address systemic issues.
Field action determination: If the risk is now unacceptable and other devices
in the field may be similarly affected, escalate to evaluate whether a field
safety corrective action (recall, advisory notice, software update) is needed.
Documentation and closure: Document all findings, decisions, and actions.
Close the complaint with full documentation trail.
Scenario 2: Your company is about to release a new surgical robot. Two
weeks before release, a design engineer identifies a new potential hazard.
What is the process?
Step-by-step response:
Stop and assess: The identified hazard must be formally evaluated before
release. Release should be placed on hold pending this evaluation.
Hazard characterization: Define the hazard clearly. What is the potential
harm? Under what conditions (normal use, foreseeable misuse, fault
conditions) could it occur?
Risk estimation: Estimate probability of occurrence and severity of harm. Use
historical data, expert judgment, and relevant standards.
Risk evaluation: Compare to acceptability criteria. Is the risk acceptable as-
is, or does it require control measures?
Risk control: If control is needed, determine appropriate measures following
the hierarchy. Assess feasibility. If design-level controls are needed,
determine if the device can be modified before release or whether controls
through protective measures or information are feasible.
Verification: Confirm that any new controls implemented are effective — this
requires verification testing, which takes time. A release decision cannot be
made without this evidence.
Design review: Convene an emergency design review to assess the hazard,
controls, and verification evidence. Document the review findings and the
risk/benefit decision.
Update documentation: Update the risk management file, risk management
summary table, Design History File, and any relevant user/servicing
documentation.
Release decision: If all residual risks (including from the new hazard) meet
acceptability criteria and documentation is complete, proceed to release. If
not, delay release until controls are implemented and verified.
Scenario 3: During a management review, the quality manager presents data
showing your device's CAPA rate has been increasing significantly. As the risk
manager, what is your response?
Step-by-step response:
Analyze the CAPA data: What are the most common sources? Are they
clustered around specific components, processes, or use scenarios? Is the
trend new or has it been building?
Correlation with risk management: Map the CAPA sources against the current
risk assessment. Are the failures related to known hazards? Are they
occurring at rates higher than estimated? Are they revealing new hazards
not previously identified?
Assessment of control effectiveness: If CAPAs are repeatedly addressing the
same hazard, this suggests risk controls may be inadequate. The risk
assessment should be updated to reflect actual occurrence rates, and higher-
order risk controls should be evaluated.
Systemic risk management review: Consider whether the increasing CAPA
rate suggests a systemic gap in the risk management process — perhaps
hazard identification was incomplete, risk controls were insufficiently robust,
or post-market surveillance was not adequately capturing early warning
signals.
Present findings to management: Provide a clear analysis linking CAPA trends
to risk management implications. Recommend specific actions: updated risk
assessments, revised controls, additional supplier controls, or process
changes.
Resource allocation: Ensure management allocates adequate resources to
address the identified issues — both immediate CAPA resolutions and
systemic risk management improvements.
Scenario 4: You are reviewing a supplier who wants to change their
sterilization process for a component they provide to you. How do you
evaluate this from a risk management perspective?
Step-by-step response:
Request full change notification: Obtain detailed documentation of the
proposed change — what is changing, why, and what validation has the
supplier performed.
Review current risk assessment: Identify all hazards associated with
sterilization of this component and the current risk controls. What are the
critical parameters (sterility assurance level, material compatibility, residuals
limits)?
Gap analysis: Compare the current sterilization process parameters against
the proposed new process. Identify differences that could affect:
Sterility assurance (different D-value, bioburden variability)
Material compatibility (different temperature, pressure, or chemical
exposure)
Residuals (different sterilant, potentially different residual levels)
Packaging integrity
Risk assessment for the change: Determine if the change introduces new
hazards or changes risk levels for existing hazards.
Require supplier validation data: The supplier must provide evidence that the
new process achieves equivalent or better sterility assurance and that
material/packaging integrity is maintained.
Independent verification: Depending on risk level, consider requiring
independent testing of sterilized product before accepting the change.
Documentation: Update purchasing requirements, risk management file, and
communicate to relevant internal stakeholders before approving the change.
Scenario 5: An auditor asks you to demonstrate that your risk management
is truly integrated with your QMS, not just a parallel paper exercise. How do
you demonstrate this?
Step-by-step response:
To demonstrate genuine integration, I would walk the auditor through several
cross-functional evidence chains:
Design control integration: Show a specific hazard in the risk management
summary table and trace it to the design requirement (RqtID), then to the
test procedure (TestID), then to the actual test result in the DHF. Show that
this hazard-derived requirement appears in design inputs, outputs, and
verification records.
CAPA integration: Show a CAPA record and demonstrate that the
investigation consulted the risk management file, and that the CAPA
corrective action resulted in a documented update to the risk assessment.
Purchasing integration: Show a supplier qualification record and demonstrate
that the qualification criteria were informed by the risk assessment for that
component's associated hazards.
Management review integration: Show the management review minutes and
demonstrate that risk management status (audit findings, CAPA trends, post-
market data) was a standing agenda item.
Change control integration: Show a design or process change record and
demonstrate that a risk assessment review was conducted before the
change was approved.
Post-market integration: Show how complaint data and vigilance reports are
analyzed against the current risk assessment, and how this has resulted in
documented risk assessment updates.
This demonstrates that risk management is not a separate file that sits on a
shelf — it is consulted, updated, and acts as an input to real decisions across
all QMS processes.
E. Questions YOU Should Ask the Interviewer
"How is risk management currently integrated with your CAPA process —
specifically, what triggers a risk assessment revision from a CAPA finding,
and who has authority to make that determination?" (Shows you understand
the CAPA-risk management loop and think about process ownership.)
"What tools does the team currently use for risk assessment — FMEA,
HAZOP, FTA — and is there a standardized approach across product lines, or
does it vary by device type?" (Shows you're practically oriented and
interested in operational realities.)
"How does the organization handle the tension between design change
timelines and thorough risk re-assessment — particularly for supplier-
initiated changes that come in with short notice?" (Shows you understand
real-world pressures and are thinking about process robustness.)
"What is your current approach to post-market risk surveillance — how is
complaint and vigilance data formally evaluated against the current risk
assessment, and at what frequency?" (Shows you understand the life-cycle
dimension of risk management.)
"How does top management engage with risk management outcomes — are
risk acceptability criteria and residual risk decisions regularly reviewed at the
executive level, or does that happen primarily at the project team
level?" (Shows you understand the management responsibility dimension
and are assessing organizational maturity.)
🧩 SECTION 5 — COMPARISON TABLES
Table 1: Risk Analysis vs. Risk Evaluation vs. Risk Assessment
Aspect Risk Analysis Risk Evaluation Risk Assessment
Systematic
Judgment of whether Combined process:
Definitio identification of
estimated risk is Risk Analysis + Risk
n hazards and
acceptable Evaluation
estimation of risks
"What could go wrong "What are the risks
Key "Is this level of risk
and how bad/likely is and are they
Question acceptable?"
it?" acceptable?"
Complete picture of
List of hazards with Accept/reject/reduce
Output all risks and their
estimated risk levels decision for each risk
acceptability status
Input Device Risk analysis results + Both of the above
needed characteristics, pre-defined
intended use, failure acceptability criteria
Aspect Risk Analysis Risk Evaluation Risk Assessment
data
When Ongoing throughout After each risk analysis Continuous
done design cycle throughout life cycle
Table 2: Risk Control Hierarchy — Comparison
Lev
Type Example Reliability Preferred?
el
Using non-toxic
Inherent safety Highest — no human Most
1 materials instead of
by design action needed preferred
toxic
Protective Interlock switch, High — automatic Second
2
measures physical guard, alarm protection preferred
Information for Warning labels, Lowest — depends
3 Last resort
safety training, user manual on human behavior
Table 3: Design Verification vs. Design Validation
Aspect Design Verification Design Validation
"Did we build what we "Did we design what users
Core question
designed?" need?"
Individual requirements and risk Overall device performance
Focus
controls and residual risk
Testing against specifications, User studies, clinical
Method
inspection, analysis evaluation, simulated use
Risk Confirms overall residual
Confirms individual risk controls
management risk is acceptable in real
were implemented and effective
role use
Near end of design; before
Timing During design and development
clinical trials
Prerequisite Design validation Clinical trials and market
Aspect Design Verification Design Validation
for release
Table 4: QMS-Only vs. Integrated QMS + Risk Management System
Integrated QMS + Risk
Aspect QMS Only
Management
Risk documents
Separate risk
Documentation referenced/integrated into QMS
management file
records
Potential duplication Reduced redundancy, single
Efficiency
of effort document control system
CAPA may not CAPA explicitly linked to risk
CAPA connection
trigger risk updates management; mutual triggers
Risk activities may Risk activities embedded at each
Design control
be separate design control stage
Management Includes risk management results
Quality metrics only
review and safety metrics
Two separate Single integrated system with
Audit readiness
systems to audit cross-references
Recommended by No — not the
Yes — explicitly recommended
document? preferred approach
Table 5: Internal vs. External Risk Communication
Aspect Internal Communication External Communication
Employees, management, Users, patients, service personnel,
Audience
relevant personnel regulators
Ensure staff know about
Warn users about risks; enable
Purpose residual risks and risk control
informed use
responsibilities
Methods Risk charts (Annex A), Warning labels, user manuals,
Aspect Internal Communication External Communication
procedures, training advisory notices, service manuals
Must be understood by intended
Content Technical detail appropriate
user (may be a patient with no
tailoring for trained staff
technical background)
Design reviews, CAPA, Device labeling, post-market
Triggers
management review changes, field safety actions
Table 6: Key Risk Assessment Tools
Tool Full Name Primary Use How It Works
Failure Modes Design and Bottom-up: analyzes each
FMEA and Effects process risk component/step, asks "how could
Analysis assessment this fail?" and assesses impact
Uses guidewords (More, Less, No,
HAZO Hazard and Process risk
Reverse, etc.) to identify
P Operability Study assessment
deviations from design intent
Top-down: starts with undesired
Fault Tree Complex system
FTA event and maps all possible
Analysis failure analysis
causes using logic gates
Hazard Analysis Identifies critical control points
HACC Manufacturing
and Critical where hazards must be
P process control
Control Points controlled; sets monitoring limits
Process Real-time Uses measurement technology to
PAT Analytical manufacturing monitor and control process
Technology control parameters in real time
🧠 SECTION 6 — MEMORY AIDS
Mnemonic 1: The Four Phases of Risk Management
"AREC" — Accept, Recognize, Evaluate, Control
A — Accept criteria (establish risk acceptability criteria first)
R — Recognize hazards (risk analysis — identify and estimate)
E — Evaluate risks (compare to criteria)
C — Control and monitor (implement measures, monitor ongoing)
Remember it as: "Before you play ANY RISK, you need to AREC-ognize the
rules."
Mnemonic 2: Risk Control Hierarchy
"I-P-I" — Inside, Protect, Inform
Inherent safety by design (fix it inside the design)
Protective measures (protect against the hazard)
Information for safety (inform users)
Remember it as: "Fix it, fence it, flag it — in that order." The closer the fix is
to the source of danger, the better.
Mnemonic 3: Key Definitions — The "HPR Chain"
Hazard → Probability + Severity → Risk Story: "A HAZARD is hiding. How
PROBABLE is it to hurt you, and how SEVERE would it be? That combination
is the RISK."
Mnemonic 4: Design and Development Stages with Risk Integration
"PIOVVCT" — Plan, Input, Output, Verify, Validate, Change,
Transfer Remember it as: "Please Invite Our Very Valiant Clinical Team" —
each stage must incorporate risk management thinking.
Mnemonic 5: Risk Assessment Tools — "FH FHP"
FMEA
HAZOP
FTA
HACCP
PAT
Remember it as: "Five Heroes Fight Hazards in Production" — FMEA, HAZOP,
FTA, HACCP, PAT.
Mnemonic 6: Management Responsibilities — "RPRA"
Risk management policies established
Planning and resources provided
Roles and responsibilities assigned
Audits conducted and reviewed at management level
Remember it as: "Management must Really Personally Run Audits" on risk.
Memory Aid: Risk Chart (Annex A)
Picture a traffic light on a grid:
X-axis = How BAD (Severity: Negligible → Catastrophic)
Y-axis = How LIKELY (Occurrence: None Observed → Always)
Green zone (bottom left) = LOW risk
Yellow zone (middle) = MEDIUM risk
Red zone (top right) = HIGH risk
Mental image: You're driving. A small pothole ahead (low severity, happens
occasionally) = green light, keep going. A wall of water across the highway at
high speed = red light, stop immediately.
Memory Aid: CAPA-Risk Management Loop
Think of a washing machine cycle:
Dirty data comes in (complaints, service reports, nonconformities)
Goes through the CAPA cycle (investigation, root cause, actions)
If risk-related findings, spins into risk management (revised risk assessment)
Comes out clean: updated risk controls, updated CAPA actions
Repeat for every load
⚡ SECTION 7 — QUICK REVISION CHEAT SHEET
Top 20 Must-Know Facts
GHTF = Global Harmonization Task Force; members from EU, USA, Canada,
Japan, Australia
This document is non-binding guidance — educational, not for
audit/inspection compliance
Risk = Probability of Harm × Severity of Harm
Hazard = potential source of harm; Harm = actual injury/damage
Risk Assessment = Risk Analysis + Risk Evaluation
Four phases of risk management: (1) Set acceptability criteria, (2) Risk
analysis, (3) Risk evaluation, (4) Risk control & monitoring
Risk control hierarchy (in order): Inherent safety by design → Protective
measures → Information for safety
Residual risk must meet acceptability criteria AND be communicated to users
Individual AND overall residual risk must both be assessed
Risk management must span the entire device life cycle — not just design
Design change control: even "trivial" changes must be risk-assessed
Outsourcing does not transfer risk management responsibility —
manufacturer remains accountable
Risk controls must be finalized before clinical trials begin
Risk management file can be integrated into QMS documentation
(recommended approach)
CAPA and risk management must be bidirectionally linked
Risk assessment tools: FMEA, HAZOP, FTA, HACCP, PAT
Annex A = Risk Chart (2D grid: Severity vs. Occurrence, three zones)
Annex B = Design & Development Flowchart showing iterative risk
management loop
Annex C = Risk Management Summary Table demonstrating traceability for
an infusion pump
Management is responsible for: policies, resources, personnel assignment,
audits, and management review
All Key Terms in One Line Each
Risk: Probability × Severity of harm
Hazard: Potential source of harm
Harm: Actual physical injury or health damage
Residual Risk: Risk remaining after all controls applied
Risk Analysis: Identify hazards + estimate risks
Risk Evaluation: Compare risks to acceptability criteria
Risk Assessment: Risk Analysis + Risk Evaluation
Risk Control: Process to reduce risks to acceptable levels
Risk Management: Full systematic process of analyzing, evaluating,
controlling risk
CAPA: Corrective and Preventive Action — fix problems and prevent
recurrence
DHF: Design History File — records of how a device was designed
QMS: Quality Management System — organized processes for consistent
product quality
FMEA: Failure Modes and Effects Analysis — systematic process failure
analysis
HAZOP: Hazard and Operability Study — process deviation analysis using
guidewords
FTA: Fault Tree Analysis — top-down failure cause mapping
HACCP: Hazard Analysis Critical Control Points — critical process control
identification
HazID: Hazard Identification code — unique reference for tracking hazards
Critical Numbers and Thresholds
0 to 6 — Probability of Occurrence scale in Annex A (O-0: None Observed →
O-6: Always)
1 to 5 — Severity of Harm scale in Annex A (S-1: Negligible → S-5:
Catastrophic)
3 types of design output (device characteristics;
purchasing/production/servicing requirements; acceptance criteria)
3 levels in risk control hierarchy (inherent safety → protective measures →
information for safety)
3 regions on the Annex A risk chart (Low, Medium, High)
3 levels of hazard hierarchy in Annex C (major class → particular hazard →
contributing factor)
ISO 14971:2000 — Primary risk management standard for medical devices
ISO 13485:2003 — Primary QMS standard for medical devices
May 20, 2005 — Date of this GHTF document
Last 10 Minutes Before Your Interview — The Absolute Essentials
Risk = Probability × Severity. Hazard is the potential source; harm is
the actual injury.
Four phases: Set criteria → Analyze → Evaluate → Control & Monitor (AREC)
Control hierarchy: Design it out → Protect against it → Warn about it (Fix,
Fence, Flag)
Residual risk must be acceptable AND communicated to users. Both
individual AND overall.
Change control is critical — trivial changes can have catastrophic
consequences. Every change needs risk assessment.
CAPA and risk management are bidirectionally linked — each feeds into the
other.
Traceability = the chain from hazard → control → requirement → test → result.
Auditors follow this chain.
Management is responsible — not just engineers. Top management must
commit resources, set policies, and review results.
Risk management never stops — it continues through manufacturing,
servicing, and post-market surveillance.
Outsourcing doesn't transfer responsibility — the manufacturer is always
accountable.
You are now interview-ready on this topic. Here is what to revise 1 hour
before your interview:
The four phases of risk management and the AREC mnemonic — this will
anchor every other answer you give
The risk control hierarchy (Fix → Fence → Flag) — expect this in at least one
question at every level
The CAPA–Risk Management integration loop — a frequent senior-level topic
and scenario question
Traceability: hazard → control → requirement → test result — know the Annex
C infusion pump example
Management's specific responsibilities — being able to articulate that risk
management is a leadership obligation, not just an engineering task, will set
you apart from other candidates