Skip to main content

Risk Management Use Case

Risk management is a critical aspect of medical device development. The Risk Management Use Case implements ISO 14971 methodology to help you create and maintain a comprehensive risk management process throughout your product lifecycle.

Understanding Risk Management

The Risk Management Use Case provides a structured approach to identifying, analyzing, and controlling risks associated with your medical device. It ensures compliance with ISO 14971 while maintaining clear traceability throughout the risk management process.

KU/KTs

Risk Management KTs

The Risk Management use case in CertHub includes the following key components:

  • Failure Modes – Possible ways a system or component can fail.
  • Hazards – Potential sources of harm.
  • Hazardous Situations – Circumstances where people, property, or the environment are exposed to hazards.
  • Harms – The actual injury or damage that can occur.
  • Risks - The actual risk that can be identified.
  • Risk Analysis – Evaluation of risks based on probability and severity.
  • Risk Control Measures – Actions taken to reduce or eliminate risks.
  • Residual Risks – Risks that remain after applying control measures.
  • Risk Management Team – Responsible for assessing and managing risks.

Defining Relationships in Risk Analysis

Risk Management KTs

Each Knowledge Topic (KT) can have different relationships defined within the use case configuration.

Source Knowledge TopicRelation NameTarget Knowledge TopicAllow MultipleDescriptionAdditional Field
RisksRelates ToHarmYesSelect the possible Harm resulting from this Risk.
Mitigated ByRisk Control MeasuresYesSelect the Risk Control Measure that mitigates this Risk.
Managed ByRisk Management TeamNoSelect the responsible Risk Management Team.
Failure ModesCausesHazardYesSelect the Hazard that the Failure Mode causes.
Residual RisksRelates ToRisksYesSelect the underlying Risk that was mitigated by the Risk Control Measure.
HazardAssociated WithHazardous SituationYesSelect the Hazardous Situation related to this Hazard.
Hazardous SituationCaused ByHazardYesSelect the Hazard associated with this Hazardous Situation.
HarmCaused byHazardous SituationYesSelect the Hazardous Situation that could lead to this Harm.
Risk Control MeasuresMitigatesRisksYesSelect the Risks mitigated by this Risk Control Measure.
Risk Management TeamManagesRisksYesSelect the Risks managed by this Risk Management Team.
Responsible forRisk Control MeasuresYesSelect the Risk Control Measure this team is responsible for.
Risks AnalysisAnalyzedRisksNoSelect the Risk being analyzed.
Identified Failure ModesFailure ModesNoSelect the Failure Mode identified in this analysis.Probability of Occurrence
Identified HazardHazardNoSelect the Hazard identified in this analysis.Probability p1
Identified SituationHazardous SituationNoSelect the Hazardous Situation identified in this analysis.Probability p2
Identified HarmHarmNoSelect the Harm identified in this analysis.Probability p1xp2
Identified RCMRisk Control MeasuresNoSelect the Risk Control Measure determined for this analysis.
Identified RMTRisk Management TeamNoSelect the Risk Management Team responsible for this risk analysis.

Concrete Example

A specific identified Risk is saved like this:

Specific Risk Instance

This, for example, is a concrete instance that can have a relationship to a specific Harm, Risk Control Measure and Riks Management Team Member.

Risk Relationship

Risk Analysis Process

The Risk Analysis is a central part of the Risk Management Use Case.

A key example is the Risk Analysis, which connects:
Failure Modes → Hazards → Hazardous Situations → Harms → Risks → Risk Control Measures → Residual Risks

Based on the relationships set between the KT data, one can now trace exactly what caused a risk and evaluate based on all data, whether the risk is Accepted or Not Accepted and what Rsk Control mEasure, if any, needs to be implemented and further, what Residual Risk remains.

Through automatic table completion, the Risk Analysis Table is generated. This table is unique because, unlike other KTs, it does not require additional manual form input fields.

Risk Analysis Table

Additional Fields in Risk Analysis

The Risk Analysis includes specific fields that are automatically identified through the key of a field defined in the respective KT form:

Relation NameTarget Knowledge TopicAdditional Field
Identified Failure ModesFailure ModesProbability of Occurrence
Identified HazardHazardProbability p1
Identified SituationHazardous SituationProbability p2
Identified HarmHarmProbability p1 × p2

These additional fields are displayed automatically in the table as long as the key in the respective form is correctly set.

warning

The selected trace relationship maps to the respective KT and its name. In order to specify a custom name for a KT, it needs to have a field with the key "name". Additional fields in use cases need the key conststing of the name connected by '*' in the respective form, e.g. "Probability of Occurence" needs the key "Probability_of_Occurence".
For more details, see Introduction to Use Cases.

With this structured approach, the Risk Analysis process is effectively documented, ensuring transparency and traceability. 🚀

Templates

The Risk Management use case includes two key templates:

  • Risk Management Plan – Outlines the strategy, responsibilities, and methods for risk management throughout the product lifecycle.
  • Risk Management Report – Summarizes the identified risks, analysis results, applied risk controls, and final risk evaluation.

These templates help ensure a structured and compliant risk management process.

Risk Relationship

SOPs

Risk Management in CertHub is structured around three essential processes:

  1. Risk Management Review and Reporting Process – Ensures regular assessment and documentation of risk management activities.
  2. Risk Evaluation Process – Defines how risks are identified, assessed, and categorized based on severity and probability.
  3. Risk Management Plan Process – Establishes the framework, responsibilities, and approach for managing risks throughout the product lifecycle.

These processes provide a structured approach to identifying, assessing, and mitigating risks effectively.

Risk Relationship

Regulatory Compliance

The Risk Management Use Case helps satisfy key regulatory requirements:

  • ✅ ISO 14971:2019 Medical Devices - Risk Management
  • ✅ EU MDR Article 10 General Obligations
  • ✅ FDA Design Controls Risk Management

By following the structured approach provided by this Use Case, you can demonstrate comprehensive risk management during regulatory audits.

Integration with Other Use Cases

The Risk Management use case connects with the Requirements Engineering use case through Risk Control Measures.

This connection is established by including the Risk Control Measure knowledge topic (KT) in both use cases.

By reusing shared KTs, CertHub makes integrating different use cases seamless and efficient, ensuring smooth traceability across processes.

Have a look at the Requirements Use Case for more information on how the Risk Control Measure is used.