FREE Includes the ISO 14971 risk plan & matrix templates

Medical device risk management software

ISO 14971 risk management lives or dies on traceability: from hazard to requirement to test to post-market data. Here's what the process requires, what software should actually do for it, and how the tool categories compare.

Free, 99€ or 499€ / month · no credit card · free migrations
Formwork ISO 14971 risk acceptance matrix with severity and probability categories
A real Formwork risk matrix: teams define probability and severity categories, then record which combinations are acceptable.

The ISO 14971 process your tool has to carry

Whatever you use — spreadsheets, an eQMS, or a lifecycle platform — the risk management file has to document each of these stages, and keep them consistent as the device changes.

  1. PLAN & CRITERIA

    A risk management plan with a defined risk acceptance matrix — severity and probability levels agreed before any analysis starts.

  2. HAZARD IDENTIFICATION

    Hazards and hazardous situations across intended use and reasonably foreseeable misuse.

  3. ESTIMATION & EVALUATION

    Severity and probability for each risk, judged against the acceptance criteria from the plan.

  4. RISK CONTROLS

    Controls in the required order — safe design first, protective measures second, information for safety last — each one traced to a requirement, implemented, and verified. This is where traceability becomes the whole game.

  5. RESIDUAL & BENEFIT-RISK

    Residual risk evaluated after controls; an overall benefit-risk conclusion documented in the risk management report.

  6. PRODUCTION & POST-PRODUCTION

    Complaints, nonconformances, and post-market data flow back into the analysis. Risk management doesn't end at release — and neither should your tool's involvement.

Why traceability decides the tool question

Every audit of a risk file asks the same connecting questions: which requirement implements this risk control? Which test verifies it? Did the complaint you received last quarter feed back into this analysis? In a spreadsheet, those links live in people's heads and break silently on every design change.

That's the honest software criterion: not prettier risk tables, but links that survive change. When a mitigation's requirement changes, the tool should show you the affected risks and stale verifications — not leave you to rediscover them in an audit.

The tool categories, honestly compared

Spreadsheets and templates. Free, auditable, and fine for a first device with a small risk table — our risk plan, FMEA table, and risk report templates are exactly this. The cost is manual traceability, which grows with every requirement and change.

eQMS platforms with risk modules. Risk lives next to documents, CAPAs, and training, so these platforms can connect feedback and approvals when those integrations are actually implemented. Formwork is in this category: ISO 14971 risk tables with a risk matrix, linked to requirements and tests, with the templates built in. Depth varies a lot between vendors — check whether risk links to requirements or just sits in its own table.

Lifecycle/ALM platforms. Requirements-first tools with deep traceability, strongest for complex SaMD and large engineering teams. They handle the design side well but usually need a separate QMS for documents, training, and CAPA — two systems to validate and keep in sync.

Choosing risk management software: what to look for

  • Risk tables that follow ISO 14971's structure, with your acceptance matrix built in
  • Traceability from hazard to risk control to requirement to verification
  • Change impact: touching a requirement flags the affected risks and tests
  • Post-production feedback: complaints and nonconformances link back into the analysis
  • Approvals and e-signatures on the risk plan and report
  • Audit-ready export of the complete risk management file
  • Templates or examples so you don't start from a blank matrix
  • Pricing you can find without talking to sales

Frequently asked questions

Does ISO 14971 require software?
No — it requires a documented risk management process with a plan, analysis, evaluation, controls, and a report, maintained across the device lifecycle. Software earns its place by keeping the risk table, requirements, tests, and post-market data connected as the design changes — the part spreadsheets handle worst.
Can we do ISO 14971 risk management in a spreadsheet?
Yes, and many companies pass audits that way — our free risk templates are exactly that. The pain arrives with change: when a requirement or mitigation changes, nothing in a spreadsheet tells you which risks, tests, and documents are now stale. That's the moment teams move to a tool.
What's the difference between FMEA and ISO 14971?
FMEA is one analysis technique — bottom-up, failure-mode driven — that can feed an ISO 14971 process. ISO 14971 is the whole lifecycle framework: plan, hazard identification, risk estimation and evaluation, controls, residual and benefit-risk analysis, and production/post-production feedback. An FMEA table alone is not an ISO 14971 file.
What is a risk acceptance matrix?
The matrix your risk management plan defines for combining severity and probability into acceptable or unacceptable risk levels. It has to be defined before you analyze risks, not fitted afterwards to make the results acceptable — auditors notice.
Does this apply to software as a medical device (SaMD)?
Fully. SaMD hazards flow through the same ISO 14971 process; the difference is that most risk controls are software controls, which makes traceability from hazard to requirement to test even more central — and spreadsheets even less pleasant.

Keep reading

Risk Management Plan & Acceptance Matrix
The free ISO 14971 plan template.

FMEA Risk Table
The working risk table, free.

Risk Management Report
Close out the process with the report template.

QMS software comparison
The broader comparison across full eQMS platforms.

Sources: ISO 14971:2019 (official ISO page, no reproduced text) · ISO 13485:2016 clause 7.1 · FDA Quality Management System Regulation.
Written and reviewed by Dr. Oliver Eidel · Last reviewed August 19, 2026 · Next review August 2027.