ISO 24971 for IVDs: Risk Management When the Harm Is Indirect

Introduction

ISO 24971 is the document that explains how to do what ISO 14971 requires, and for in vitro diagnostic medical devices it carries something the standard itself does not: an annex written specifically for IVDs, prepared with the technical committee that writes the clinical laboratory standards. That annex exists because the risk management process was designed around devices that act on a patient, and an IVD does not act on a patient. It produces a number, and somebody else acts on the number.

That single structural difference is what makes an IVD risk file hard to write and easy to write badly. This guide works through ISO/TR 24971:2020 from an IVD perspective: what the document is, how the chain from an incorrect result to a patient harm is built and estimated, what the Annex A hazard questions are for when half of them do not apply, and where the file has to connect to the performance evaluation and to post-market surveillance. For the regulatory frame the risk file sits inside, start with the IVDR guide; for the process itself, the ISO 14971 risk management guide covers the standard end to end.

Table of Contents

What ISO 24971 is, and what it cannot do for you

ISO/TR 24971:2020 is a Technical Report titled Medical devices — Guidance on the application of ISO 14971. It is the second edition, published in June 2020, running to 87 pages, and it replaced the 2013 first edition entirely rather than amending it. It was prepared by ISO/TC 210 together with IEC/SC 62A, and it is available in Europe as CEN ISO/TR 24971. The ISO catalogue entry is the authoritative record of its status.

Two facts about its status matter before anything else. First, it contains no requirements, which means you cannot claim conformity to it. There is nothing to declare, nothing to certify, and no clause to reference in a declaration of conformity. Second, and in tension with the first, notified bodies read it. Where ISO 14971 says a thing must be done and says nothing about how, ISO/TR 24971 is the only internationally agreed statement of what a reasonable method looks like — so a file that departs from it is not non-compliant, but it is carrying an explanation it will have to give.

The structure is deliberately parallel. Clauses 3 to 10 of the Technical Report carry the same numbers as the clauses of ISO 14971:2019, so guidance on hazardous situations sits at 5.4 in both documents. What used to be scattered through the informative annexes of ISO 14971:2007 has been pulled into the annexes here, which is why manufacturers who learned risk management on the 2007 edition often cannot find material they remember: it moved.

The indirect harm chain for an in vitro diagnosticAn IVD does not act on the patient. Severity belongs to the clinical decision the resultfeeds, not to the analytical failure that produced it.DEVICEIncorrect orabsent resultFalse negative, falsepositive, biased value,wrong sample, invalidrun.P1HazardoussituationThe result is reportedand reaches a clinicaldecision point withoutbeing caught.P2Decision takenor withheldTreatment started,withheld or delayed.Donor unit released.Further testing notordered.HARMPatient harmSeverity is estimatedhere, against theclinical consequence —never against thefailure mode.Probability of harm = P1 × P2. P1 is an analytical quantity the performance work has already measured. P2 is a claimabout the clinical pathway, and it needs evidence — not the assumption that a clinician will notice, and not adefault of 1 for every hazard.
Figure 1 — The indirect harm chain, and where P1 and P2 sit in the probability estimate

Annex H is the one that concerns IVD manufacturers most, and it did not come from the medical device committee. It was prepared in cooperation with ISO/TC 212, Clinical laboratory testing and in vitro diagnostic test systems — the committee behind ISO 20916 on clinical performance studies and the CLSI-adjacent body of analytical performance standards. That provenance shows in its content, and it is the reason Annex H reads like a laboratory document rather than a risk document.

The indirect harm chain, and why an IVD file starts at the result

ISO 14971 defines harm as injury or damage to the health of people, or damage to property or the environment. For an infusion pump the path to harm is short: the pump over-delivers, the patient receives too much drug, the patient is harmed. For an IVD the path runs through a person who is not the manufacturer and an act the manufacturer does not control.

The chain has four links, and each one is a place where the risk file has to say something specific:

  • The device produces an incorrect or unavailable result. False positive, false negative, a value biased outside the stated limits, a result reported for the wrong sample, or no result at all because the run failed.
  • The result reaches a clinical decision. Somebody reads it, in a context, with or without other information that would contradict it.
  • A decision is taken or not taken. A treatment starts, a treatment is withheld, a diagnosis is delayed, a donor unit is released, a further test is not ordered because this one appeared to settle the question.
  • The patient is harmed. Or is not, because something downstream caught it.

Severity is a property of the decision, not of the failure

This is what the literature calls indirect harm, and it is the default case for an IVD rather than an exception. The consequence for the risk file is precise: the severity of harm is not a property of the device failure. It is a property of the clinical decision the result feeds. The same analytical bias in a screening assay and in a confirmatory assay for the same analyte produces different severities, because in the first case a second test stands between the error and the patient and in the second case nothing does.

Manufacturers frequently resolve this by writing severity against the failure rather than against the harm — a false negative is scored as major because a false negative sounds serious. That is not an estimate, it is a label. The estimate requires a stated clinical pathway: who receives this result, what they do with it, what else they have, and what happens to the patient when the chain runs to the end without interruption.

Reasonably foreseeable misuse is a laboratory workflow question

ISO/TR 24971 gives a lot of space to reasonably foreseeable misuse, and the examples in the general clauses are device examples. For an IVD the category is real but it looks different. It is the specimen type used outside the validated matrix because the validated one was not available. It is the calibration interval stretched over a weekend. It is the result read at forty minutes on a lateral flow device whose instructions for use specify a fifteen-minute read window. It is a sample run on an analyser with a reagent lot the laboratory has not verified.

None of these are misuse in the sense of a user being careless. They are the predictable behaviour of a busy laboratory under pressure, and the standard's test is foreseeability rather than blame. A risk file that treats deviation from the instructions for use as out of scope has assumed away the largest single source of IVD hazardous situations.

Annex A, the 46 questions, and the ones that do not apply

Annex A of ISO/TR 24971:2020 is the hazard identification questionnaire — the successor to Annex C of ISO 14971:2007, restructured and expanded. It works through the characteristics related to safety as a series of questions about the device: what it is intended for, what it contacts, what energy it delivers, what materials it uses, whether it is sterile, whether it is single-use, whether software is involved, how it is disposed of.

Run those questions against a typical reagent kit and a large proportion of them return nothing. There is no energy delivery to a patient, no biocompatibility question at the patient interface, no implantation, no sterilisation of the patient-contacting element, no delivered dose. Manufacturers meet this and do one of two things, both wrong. Some delete the inapplicable questions, which produces a hazard analysis with no record of what was considered. Others answer them defensively with paragraphs of text about why the question does not apply, which produces forty pages of nothing.

The correct handling is neither. Each question is answered, briefly, with an applicability determination and a one-line reason, and the answered questionnaire is retained as evidence that hazard identification was systematic rather than selective. Not applicable, with a reason, is a finding. A missing question is a gap.

Two hazard sources, and only one of them is Annex AThe 46-question checklist is the floor. The hazards that matter for an IVD come out of theanalytical performance work.HAZARD SOURCETYPICAL IVD FINDINGWHERE IT COMES FROMAnalytical performanceCross-reactivity with a related analyte;interference from haemoglobin, bilirubinor lipaemia at realistic concentrations.Specificity and interference studies. Notvisible to the Annex A questions.Specimen andpre-analyticsMatrix used outside the validated specimentype; stability limit exceeded intransport or storage.Stability programme under ISO 23640, plusforeseeable laboratory workflow.Lot and calibrationLot-to-lot shift in a critical reagent;calibration interval stretched; unverifiedreagent lot in routine use.Manufacturing controls and post-marketdata. Partly Annex A.Software and reportingRounding behaviour at the clinicalcut-off; result attached to the wrongsample identifier; flag suppressed.Software risk analysis under IEC 62304.Annex A raises the question only.Cut-off and claimsCut-off placement trading false positivesagainst false negatives; a claim theperformance data does not fully support.Clause 7.4 benefit-risk. Belongs in therisk file, not only in a validationreport.Device characteristicsSharps, biological material, single use,disposal, transport and storageconditions, user competence assumptions.Annex A questionnaire. This is what the46 questions are actually for.Not applicable, with a one-line reason, is a finding and should be recorded as one. A deleted question is a gap, andit invites the reviewer to ask what else was removed.
Figure 2 — Six hazard sources for an IVD, and which of them the Annex A questionnaire actually finds

What the questionnaire will not do for an IVD is find the hazards that matter, because they are not device characteristics. Interference from haemoglobin, cross-reactivity with a related analyte, a specimen stability limit exceeded in transport, a lot-to-lot shift in a critical reagent, a software rounding behaviour at a clinical cut-off — these come out of the analytical performance work, not out of the questionnaire. Annex A is the floor, not the method. Both have to run.

✦ EU IVDR Technical Documentation Kit

The Annex II file your risk analysis has to agree with.

The risk file is not a standalone deliverable. Its probability estimates come out of the analytical performance section and its residual risks are weighed in the performance evaluation — which means the three documents have to quote the same numbers. The kit covers the Annex II technical documentation as one coordinated set, so the figures line up instead of drifting.

✓ Word templates · Regulation (EU) 2017/746 Annex II and Annex III

✓ Analytical and clinical performance sections cross-referenced to the risk file

See the EU IVDR Technical Documentation Kit →

Estimating probability when the device is one link in a chain

ISO 14971 asks for risk as a combination of the probability of occurrence of harm and the severity of that harm, and ISO/TR 24971 is explicit that the probability of harm is not the probability of the failure. For an IVD the difference is large enough to change conclusions.

The guidance describes splitting probability into two parts: P1, the probability of the hazardous situation arising, and P2, the probability that the hazardous situation leads to harm. For a diagnostic result this maps cleanly. P1 is the analytical event — the false negative rate at the clinical decision point, the interference rate at realistic interferent concentrations, the frequency of the software condition. P1 is measurable, and if the analytical performance work has been done properly it is already measured. P2 is everything downstream: the probability that the incorrect result is acted on without correction, given the clinical pathway, the other information available, and any confirmatory step that exists.

P2 is where the argument happens, and where files fall down in two opposite directions. The optimistic failure claims a low P2 on the strength of a confirmatory test that the instructions for use recommend but do not require, or on the assumption that a clinician will notice a result inconsistent with the presentation. The pessimistic failure sets P2 to one for every hazard, which makes the risk estimate a restatement of the analytical failure rate and makes risk control impossible to evaluate. Either way the number needs a stated basis: literature, the clinical evidence assembled for the performance evaluation, published practice guidelines, or expert elicitation that is recorded as such.

Risk acceptability, AFAP, and what the Z annexes actually say

ISO 14971 requires the manufacturer to establish a policy for determining criteria for risk acceptability, and note 1 to clause 4.2 offers several approaches, including reducing risk as low as reasonably practicable and reducing risk as far as possible without adversely affecting the benefit-risk ratio. The European position narrows that choice.

EN ISO 14971:2019/A11:2021 was published at the end of 2021 and listed in the Official Journal in May 2022, harmonised under both the MDR and the IVDR. The current lists of harmonised standards are maintained on the European Commission site. The amendment adds two informative annexes: Annex ZA maps the standard to the MDR, Annex ZB maps it to the IVDR. A point worth stating plainly, because the opposite is widely believed: these Z annexes contain no content deviations. The seven content deviations that made EN ISO 14971:2012 notorious are gone. What the annexes contain instead are explanatory notes about requirements of the Regulations that override the latitude the standard allows.

Two of those matter for every IVD file. Risk must be reduced as far as possible, which excludes economic considerations from the decision — the practicability trade-off that as low as reasonably practicable permits is not available. And the risk control options in clause 7.1 are written as a list the manufacturer may use one or more of, in priority order, which under the Regulations has to be read as all three being attempted in order rather than the first sufficient one being selected.

What the European amendment changesEN ISO 14971:2019/A11:2021 adds Annex ZA for the MDR and Annex ZB for the IVDR. Neithercontains a content deviation — but both constrain the latitude the standard allows.TOPICISO 14971:2019 ALLOWSTHE IVDR REQUIRESAcceptabilityapproachClause 4.2 note 1 offers several: as lowas reasonably practicable, as low asreasonably achievable, or as far aspossible.As far as possible. The practicabilitytrade-off is not available.EconomicconsiderationsPracticability approaches permit cost toenter the decision on what is reasonable.Excluded from the risk reduction decision.Cost is not a reason a residual risk stands.Risk controloptionsClause 7.1 lists three options in priorityorder and says one or more shall be used.All three considered in order. Design first,protective measures second, information forsafety last.Information forsafetyCounted as a risk control measure in itsown right.Legitimate, but never a substitute for acontrol that was available higher in thehierarchy.Disclosure of riskResidual risks that are significant aredisclosed to the user.The Regulation's information obligations arebroader than the standard's significancetest.The seven content deviations of EN ISO 14971:2012 are gone. A file still carrying a deviation table copied from theold amendment is citing a document that no longer exists.
Figure 3 — Where the European amendment narrows the latitude ISO 14971 allows

For an IVD the second point has a specific consequence. Information for safety is the third and weakest control, and it is the one an IVD manufacturer reaches for most naturally, because the instructions for use are the device's main interface with the user. A limitation stated in the instructions for use is a legitimate control measure and it is not a substitute for the two above it. If a cross-reactivity can be reduced by reformulating the antibody, reformulating comes first; if a misread can be prevented by a procedural control in the assay itself or by a flag the software raises, that comes before a sentence in section 12 of the instructions for use.

Risk control for a device whose output is information

The hierarchy applies, but its content has to be translated. Inherent safety by design, for an IVD, is the assay: antibody selection, target sequence choice, buffer composition, sample preparation chemistry, the cut-off itself. Protective measures are the elements that catch a failure before the result leaves the system — internal process controls, invalid-run rules, sample integrity checks for haemolysis or clotting, software plausibility checks and flags, lot-specific calibration requirements. Information for safety is everything in the instructions for use, the labelling and the summary of safety and performance.

Two categories deserve individual attention because they are routinely misclassified.

A control material or internal control is a protective measure, not information for safety, and it only counts as one if it is required rather than recommended. An instruction that a control should be run daily is information. A run that will not report a result unless the control passed is a protective measure. The distinction determines what residual risk you are entitled to claim.

The cut-off is a design decision with a risk consequence and it is frequently documented only in the analytical performance report. Moving a cut-off trades false positives against false negatives, which trades one harm pathway against another. That trade is a benefit-risk decision under clause 7.4 and it belongs in the risk management file with its rationale, not only in a validation report where the reviewer has to reconstruct why the number is where it is.

✦ Hazard Analysis template · €69

All 46 Annex A questions, answered rather than deleted.

A Word template implementing the full ISO/TR 24971:2020 Annex A questionnaire, with an applicability determination and a reason against every question — so the questions that do not apply to a reagent kit are on the record as considered instead of missing from it. Available on its own, or inside the Risk Management Kit with the Risk Management Plan, the Risk Management Report and the two active FMEA worksheets.

✓ 46 questions · applicability and rationale columns · Word

✓ Feeds the Design and Use-related FMEA without re-entry

Get the Hazard Analysis template → €69

Where the risk file has to touch the rest of the technical documentation

An IVD risk file that stands alone is incomplete by construction, because the quantities it depends on are generated elsewhere and the conclusions it reaches are consumed elsewhere.

Analytical performance supplies P1. Sensitivity, specificity, interference, cross-reactivity, precision, trueness, measuring interval, detection limit and the stability data covered in ISO 23640 are not just Annex II content; they are the numerical inputs to the risk estimate. Where the risk file quotes a rate that does not appear in the analytical performance report, or quotes it with a different value, a reviewer has found a contradiction inside the same technical documentation.

Clinical performance and the performance evaluation supply the pathway that justifies P2, and receive back the residual risks that the benefit-risk determination has to weigh. The relationship is circular by design, and both documents have to reflect the same version of it.

Post-market surveillance closes the loop and, under the IVDR, is where the risk file is tested against reality. The indicators and threshold values that MDCG 2025-10 requires to be set in the pre-market phase have to be derived from something, and the only place they can honestly come from is the risk analysis: the occurrence estimates, the acceptability criteria, and the expected rate of erroneous results that the benefit-risk determination accepted. A risk file with no quantity a surveillance plan can monitor and a surveillance plan with thresholds that appear from nowhere are the same finding, seen from two sides.

Where IVD risk files fail

The recurring findings are not exotic. They are the predictable result of applying a device-shaped process to a device that produces information, and each one is visible on reading the file rather than on auditing the process.

Where IVD risk files failSix findings, all visible on reading the file rather than on auditing the process.CRITICALSeverity scored on thefailureA false negative marked majorbecause it sounds serious.Severity belongs to the harm theclinical decision produces, andneeds the pathway written out.CRITICALP2 assumed, notjustifiedEither a low P2 resting on aconfirmatory test the IFU onlyrecommends, or P2 fixed at 1everywhere, which makes riskcontrol impossible to evaluate.MAJORAnnex A questionsdeletedInapplicable questions removedinstead of answered. The recordof what was considered goes withthem, and the reviewer sees itin thirty seconds.MAJORControls counted asprotectiveA control material the IFUrecommends is information forsafety. Only a required controlthat blocks reporting is aprotective measure.MAJORCut-off rationaleoutside the fileThe cut-off trades falsepositives against falsenegatives. That is a clause 7.4benefit-risk decision, not avalidation report footnote.MINORRates that disagreeacross the fileThe risk analysis quotes aninterference or false-negativerate that the analyticalperformance report does notcarry, or carries differently.
Figure 4 — Six ways an IVD risk file fails, and what each one looks like on the page

The severity failure and the P2 failure are the two that change conclusions. Both come from the same root: the chain from result to harm was never written down, so severity got attached to the failure mode and probability got attached to the assay. Writing the chain out, once, for each hazard category, fixes both and takes less time than defending either.

The Annex A failure is cosmetic by comparison but it is the one most likely to be raised, because it is visible in thirty seconds. A questionnaire with deleted rows invites the question of what else was deleted.

Frequently asked questions

What is ISO 24971?

ISO/TR 24971:2020 is a Technical Report giving guidance on the application of ISO 14971:2019, the risk management standard for medical devices. It is the second edition, published in June 2020, and it uses the same clause numbering as ISO 14971:2019 so that guidance can be found against each requirement. It contains no requirements of its own.

Can you claim conformity to ISO 24971?

No. It is a Technical Report and contains guidance rather than requirements, so there is nothing to conform to and nothing to certify. You conform to ISO 14971 — in Europe, EN ISO 14971:2019/A11:2021 — and you use ISO/TR 24971 to decide how. Notified bodies nonetheless expect a risk management approach consistent with it, particularly on benefit-risk analysis and hazard identification.

Does ISO 24971 cover in vitro diagnostic devices?

Yes. Annex H of ISO/TR 24971:2020 is dedicated to in vitro diagnostic medical devices and was prepared in cooperation with ISO/TC 212, the committee for clinical laboratory testing and in vitro diagnostic test systems. The main clauses also apply to IVDs throughout, since the scope covers active, non-active, implantable and non-implantable devices, software as a medical device and IVDs.

What is indirect harm for an IVD?

Harm that reaches the patient through a clinical decision rather than through contact with the device. An incorrect or unavailable result leads to a treatment being given, withheld or delayed, and the patient is harmed by that action rather than by the device itself. It is the normal case for an IVD, and it means severity has to be estimated against the clinical decision the result feeds, not against the analytical failure.

How many questions are in ISO 24971 Annex A?

The Annex A questionnaire on characteristics related to safety runs to 46 questions in the 2020 edition. For an IVD a substantial proportion will not be applicable. The expected handling is to answer each one with an applicability determination and a short reason, and to retain the completed questionnaire, rather than deleting the questions that do not apply.

Do the Z annexes of EN ISO 14971:2019/A11:2021 contain content deviations?

No. Unlike EN ISO 14971:2012, which carried seven, the Z annexes of the A11:2021 amendment contain none. Annex ZA maps the standard to the MDR and Annex ZB to the IVDR, and both carry explanatory notes about requirements of the Regulations that take precedence over the latitude the standard allows — principally the reduction of risk as far as possible, without economic considerations.

What is the difference between P1 and P2?

P1 is the probability that the hazardous situation occurs and P2 is the probability that, having occurred, it leads to harm. Their product is the probability of harm required by ISO 14971. For an IVD, P1 is normally an analytical quantity that the performance work has already measured, and P2 is a statement about the clinical pathway that has to be justified from evidence rather than assumed.

Conclusions

ISO/TR 24971:2020 does not add requirements and cannot be certified against, and it is still the most useful document an IVD risk manager can have open, because it is where the general process is translated into methods and where Annex H says out loud that IVDs behave differently.

Three things carry most of the value. Severity belongs to the harm the clinical decision produces, not to the analytical failure, which means the chain from result to patient has to be written down before any number is assigned. Probability splits into an analytical part that the performance work has already measured and a clinical part that has to be justified from evidence. And in Europe the acceptability policy is constrained: risk is reduced as far as possible, economic considerations are excluded, and all three risk control options are attempted in order rather than the first adequate one being chosen.

The EU IVDR Technical Documentation Kit covers the Annex II file the risk management documentation has to sit inside, so that the analytical performance figures, the risk estimates and the post-market thresholds are consistent across the documents that quote each other.