Benefit-Risk Analysis under EU MDR: Requirements, Methods and Common Mistakes
Introduction
The benefit-risk determination is the conclusion the whole technical file exists to support. Every risk control, every clinical study, every piece of post-market data feeds one judgement: that the benefits of this device, for this intended purpose, outweigh the residual risks in light of the state of the art.
Under the EU MDR that judgement is not a document you write once. It appears in six places across the Regulation, it is owned jointly by risk management and clinical evaluation, and it has to be re-made whenever post-market data change the inputs. The most common structural failure in a technical file is not a weak analysis — it is three different versions of the same analysis, in the risk management report, the clinical evaluation report and the PSUR, that no longer agree with one another.
This guide covers where the benefit-risk determination is required, what the Regulation actually asks for, the methods available for weighing benefits against risks and when each one is appropriate, and the mistakes that Notified Bodies raise most.
Table of Contents
- The two definitions everything rests on
- Where the benefit-risk determination is required
- Who owns it: risk management or clinical evaluation?
- The analysis, step by step
- 1 — Scope and intended purpose
- 2 — State of the art
- 3 — Identify and evidence the benefits
- 4 — Characterise the risks in clinical terms
- 5 — Define the comparison parameters
- 6 — Perform the comparison
- 7 — Write the justification
- 8 — Feed post-market data back in
- The methods, and when each one fits
- The benefit-risk determination outside the EU
- The findings that recur
- Frequently asked questions
- Conclusions
The two definitions everything rests on
Article 2 of the EU MDR defines benefit-risk determination as the analysis of all assessments of benefit and risk of possible relevance for the use of the device for the intended purpose, when used in accordance with the intended purpose given by the manufacturer.
The operative words are for the intended purpose. Benefits and risks are not properties of a device; they are properties of a device used in a particular way, on a particular population, by a particular kind of user. Change any of those and the determination changes with it. This is why a benefit-risk analysis that opens with a technical description rather than with the intended purpose has started in the wrong place.
The second definition is clinical benefit: the positive impact of a device on the health of an individual, expressed in terms of a meaningful, measurable, patient-relevant clinical outcome, including outcomes related to diagnosis, or a positive impact on patient management or public health.
| Is it a clinical benefit? | Claim | Why |
|---|---|---|
| Yes | Reduces time to diagnosis by a measured interval | Measurable, patient-relevant, affects patient management |
| Yes | Lowers the reintervention rate at 12 months | A clinical outcome with a defined endpoint and timeframe |
| No, on its own | Easier for the surgeon to handle | A performance characteristic. It becomes a benefit only where it is shown to change a clinical outcome, such as procedure time or complication rate |
| No | Higher resolution than the predecessor | A technical specification. Resolution is a benefit only if better images change what is diagnosed or how the patient is managed |
| No | Lower cost per procedure | An economic benefit. It belongs in the value dossier, not in the benefit-risk determination |
Most weak benefit-risk analyses fail here, not in the weighing. They list device characteristics under the heading “benefits” and then weigh technical specifications against clinical harms, which is not a comparison of like with like. If a claimed benefit cannot be expressed as an outcome experienced by a patient, it is not a clinical benefit and it cannot carry a risk.
Where the benefit-risk determination is required
The Regulation does not put the benefit-risk determination in one place, which is precisely why it drifts out of alignment. It is required in six.
| Location | What it requires | Which document holds it |
|---|---|---|
| Annex I, Chapter I, section 1 | Devices shall achieve the performance intended and be safe, with risks acceptable when weighed against the benefits and compatible with a high level of health protection | The GSPR checklist entry for requirement 1 |
| Annex I, Chapter I, section 8 | All known and foreseeable risks and undesirable side-effects shall be minimised and acceptable when weighed against the evaluated benefits | The GSPR checklist entry for requirement 8, pointing to the risk management file |
| Annex II, section 5 | The technical documentation shall contain the benefit-risk analysis and the risk management outputs | Annex II section 5 of the technical file |
| Annex III, PMS plan | The PMS plan shall define indicators and threshold values for the continuous reassessment of the benefit-risk analysis | The post-market surveillance plan |
| Annex XIV, Part A | The clinical evaluation shall establish the acceptability of the benefit-risk ratio | The clinical evaluation report |
| Annex XIV, Part B | The PMCF plan shall describe how the continued acceptability of the benefit-risk ratio will be evaluated | The PMCF plan and report |
Six locations, one determination. The Regulation does not require six analyses, and producing six is the most reliable way to end up with inconsistencies a reviewer can find by reading two documents side by side. The workable structure is a single benefit-risk analysis, held in the risk management file, that the other five locations reference rather than restate.
Who owns it: risk management or clinical evaluation?
Both, and that is the source of most of the trouble. The risk management process under ISO 14971 produces the residual risks and evaluates overall residual risk acceptability. The clinical evaluation produces the benefits, the state of the art and the clinical context in which those risks land. Neither can complete the determination alone.
The practical arrangement that survives review is this: the benefit-risk analysis is a section of the risk management report, written jointly, and the clinical evaluation report references it rather than duplicating it. The risk management report holds the risks; it imports the benefits and the state of the art from the CER by reference, with document and revision numbers. When the CER is updated, the reference is checked and the analysis is revisited.
The arrangement that fails is a benefit-risk section written independently in each document. It fails slowly: at issue they agree, and then the CER is updated in year two, the risk file in year three, and by the first surveillance audit the two documents state different residual risks against different benefits.
✦ Audit-ready kit · Risk Management
One benefit-risk analysis, in the file the other five locations reference.
Risk Management Plan, Risk Management Report with the benefit-risk determination inside it, Hazard Analysis built on the ISO/TR 24971 Annex A questions, and Design and Use-related FMEA as active Excel worksheets with auto-calculated residual risk.
✓ 6 coordinated templates · Word and Excel
✓ Aligned with EN ISO 14971:2019/A11:2021
✓ Buying the 6 templates individually costs €414
The analysis, step by step
1 — Scope and intended purpose
Everything downstream is scoped by the intended purpose, so it is stated first and stated precisely: the indications, the target patient population, the clinical or procedural setting, the intended user profile, and whether the device diagnoses, treats, monitors or supports another clinical function.
This is not preamble. It determines which clinical evidence is relevant, which risks are in scope, and which benefit parameters can be measured. An analysis scoped to “adult patients” when the device is used in paediatric care has excluded the population where the balance is most likely to differ.
2 — State of the art
The state of the art is the benchmark against which acceptability is judged, and it has to be established independently of the device — not assembled from evidence selected because it is favourable. It covers comparable devices, alternative therapeutic options including pharmacological and surgical ones, how outcomes are measured in current practice, and what level of performance counts as adequate.
It has to be documented in the clinical evaluation plan and carried into the report. A state of the art built only from the manufacturer’s own comparator set will be challenged, because it defines the acceptability threshold and a threshold chosen by the party being measured against it is not a benchmark.
3 — Identify and evidence the benefits
Benefits are categorised and each is tied to evidence. Direct clinical benefits are outcomes experienced by the patient: improved survival, symptom relief, reduced complication rate. Indirect benefits reach the patient through the process: shorter procedure time, reduced hospital stay, fewer reinterventions. Broader impacts include quality of life and reduced caregiver burden.
Each requires clinical evidence — literature, clinical investigation, registry or real-world data — and each requires a magnitude and a probability. “Improves outcomes” is not a benefit that can be weighed. “Reduces reintervention at 12 months from a rate of X to a rate of Y, in the population studied” is.
4 — Characterise the risks in clinical terms
The risks come from the ISO 14971 file, but they arrive expressed in engineering terms and have to be restated clinically. A failure mode is not a risk to a patient until someone has said what happens to the patient when it occurs.
Three families are considered: device-specific risks such as material reactions and failure modes; procedure-related risks such as surgical complications or misinterpretation of an algorithm output; and user-related risks including use error and training deficiencies. For each, the analysis records severity, probability and clinical relevance — the last of which is what the risk file usually does not contain and the benefit-risk analysis must add.
5 — Define the comparison parameters
Benefits and risks cannot be compared until there is a common frame. Four parameters make the comparison structured rather than rhetorical:
- Frequency — the incidence of the benefit against the incidence of the harm, in the same population.
- Magnitude — the clinical significance of the benefit against the severity of the harm.
- Duration — how long the benefit persists against how long the risk exposure lasts.
- Distribution — how the balance differs across subgroups, since a favourable average can conceal an unfavourable subgroup.
These parameters are defined before the data are examined. Chosen afterwards, they select themselves to support the conclusion already reached.
6 — Perform the comparison
The comparison answers four questions explicitly, in the document, rather than implying the answers through a summary: do the benefits meaningfully outweigh the risks; are the residual risks acceptable in the context of the benefit; how does the device compare with the alternatives identified in the state of the art; and are there subgroups in which the balance differs.
The fourth is the one most often skipped and the one most often asked about. A device whose balance is favourable overall and unfavourable in a subgroup either restricts its intended purpose or justifies why the subgroup is nonetheless served.
7 — Write the justification
The output is a reasoned conclusion, not a summary of the inputs. It references the clinical evidence and the state of the art, sets the benefits against the contextualised risks, shows how Annex I requirements 1 and 8 are satisfied, addresses residual uncertainty and data gaps openly, and concludes on acceptability.
The section on uncertainty is the one that distinguishes a credible analysis. Every device has data gaps; an analysis that presents none has either not looked or not said. Naming the gaps and explaining why they do not change the conclusion is stronger than omitting them, and it is what the PMCF plan is then built to close.
8 — Feed post-market data back in
The determination is re-made whenever the inputs change. The PMS plan defines the indicators and the threshold values that trigger the reassessment, and those thresholds are derived from the risk file rather than chosen for convenience — a threshold set above any level the analysis would react to is a threshold that will never fire.
Three things reopen the determination: a threshold breached in post-market surveillance data, new PMCF evidence on sustained benefit, and a shift in the state of the art. The third is the one manufacturers miss: a competing device that improves outcomes changes the benchmark, and a balance that was acceptable against the old state of the art may not be acceptable against the new one, with nothing having changed about your device at all.
✦ Audit-ready kit · EU MDR
The Annex II file, structured to the Regulation’s own order.
One document per Annex II section, with the benefit-risk analysis in section 5 and cross-referenced from the GSPR checklist entries for requirements 1 and 8 — which is where a reviewer looks for it first.
✓ Word templates · full Annex II and Annex III coverage
✓ GSPR checklist in Word and Excel, with the evidence column
✓ One-time purchase, fully editable
The methods, and when each one fits
The Regulation does not prescribe a method. It requires that the determination be documented and justified, which leaves the choice to the manufacturer — and makes the choice itself something to justify. Four approaches are in general use, and they are not alternatives so much as increasing levels of rigour.
| Method | How it works | Best suited to | Limitation |
|---|---|---|---|
| Structured qualitative narrative | Benefits and risks tabulated against the four comparison parameters, with a reasoned conclusion | Most Class IIa and IIb devices, and any device where outcome data are sparse | Reproducibility depends entirely on how disciplined the parameters are. Weak parameters make it an opinion with a table around it |
| Semi-quantitative matrix | Benefits and risks scored on defined scales and plotted against one another | Devices with several distinct benefits and hazards where relative weight matters | The scoring scales are chosen by the manufacturer, so the method’s objectivity is only as good as its pre-defined criteria |
| NNT and NNH | Number needed to treat set against number needed to harm, from clinical data | Devices with a single dominant benefit and a single dominant harm, both with incidence data | Requires comparable incidence data for both. Rarely available for a new device; usually derived from the state of the art |
| Multi-criteria decision analysis | Explicit weights assigned to each outcome, with a composite score | Class III and implantable devices, or where a regulator has asked for a quantitative approach | Heavy, and the weights are themselves a judgement. Makes the judgement explicit rather than removing it |
Two points about choosing. The method should be proportionate to the risk class and to the quality of the data available — a quantitative method applied to data that cannot support it produces a number with false authority, which is worse than a well-argued narrative. And whichever method is chosen, the choice and its rationale belong in the risk management plan, before the analysis is performed, for the same reason acceptance criteria are set before the data arrive.
No method removes the judgement. NNT and NNH produce two numbers and someone still has to say whether that ratio is acceptable for this population against this state of the art. What the methods do is make the judgement visible and reviewable, which is what the Regulation is actually asking for.
The benefit-risk determination outside the EU
The concept is not confined to the MDR, and a manufacturer preparing for more than one market can build one analysis rather than several. The FDA applies a benefit-risk framework in its premarket decision-making, including for 510(k) submissions where differences from the predicate raise questions that testing alone does not settle, and for De Novo requests where the classification decision rests on it. The factors are recognisably the same: the extent of the benefit, its probability, the severity and probability of the harm, the duration of both, and the availability of alternatives.
What differs is the vehicle rather than the reasoning. The MDR requires the determination inside the technical documentation and re-made continuously through post-market surveillance; the FDA embeds it in the submission decision. In an MDSAP audit the benefit-risk determination itself is not a chapter, but the risk management process that produces it is sampled under design and development, and the post-market data that reopen it under measurement, analysis and improvement.
The findings that recur
Technical characteristics presented as benefits. Resolution, weight, handling and battery life are performance characteristics. They become benefits only through a demonstrated effect on a clinical outcome. An analysis that weighs specifications against harms is not comparing like with like.
Three versions of the determination. One in the risk management report, one in the CER, one in the PSUR, drafted independently and updated on different cycles. By the second update they disagree, and the disagreement is visible from reading any two of them.
A state of the art built from favourable comparators. The benchmark that sets the acceptability threshold, assembled by selecting the evidence that makes the threshold easy to meet.
Risks left in engineering language. The benefit-risk analysis restates the hazard table without translating any of it into what happens to a patient. Severity assigned without reference to clinical consequence cannot be weighed against a clinical benefit.
No subgroup analysis. A favourable overall balance with no examination of whether it holds for the paediatric, elderly or comorbid population within the intended purpose.
PMS thresholds that cannot fire. Indicators defined in the PMS plan with threshold values set so high that no realistic signal would reach them. The plan satisfies Annex III on paper and the reassessment loop never runs.
Uncertainty not stated. An analysis presenting no data gaps and no limitations. Every device has them, and their absence from the document reads as an analysis that did not look rather than one that found nothing.
✦ Complete catalogue
Find the documentation you need — instantly.
Whether you need a complete kit or just one specific SOP, the catalogue has it. Individual process packages and complete bundles, all instantly downloadable and fully editable.
✓ Complete bundles or individual packages
✓ Individual process packages from €69 each
✓ EU MDR · EU IVDR · ISO 13485 · MDSAP
Frequently asked questions
What is a benefit-risk determination under the EU MDR?
Article 2 defines it as the analysis of all assessments of benefit and risk of possible relevance for the use of the device for its intended purpose, when used in accordance with the intended purpose given by the manufacturer. It is not a property of the device but of the device used in a defined way, on a defined population, by defined users.
Where does the benefit-risk analysis go in the technical documentation?
Annex II section 5, alongside the risk management outputs. It is also required at Annex I Chapter I sections 1 and 8 through the GSPR checklist, in the Annex III post-market surveillance plan as the basis for indicators and thresholds, in the clinical evaluation report under Annex XIV Part A, and in the PMCF plan under Annex XIV Part B. One analysis, referenced from all six locations.
Is a benefit-risk analysis the same as risk management?
No. Risk management under ISO 14971 identifies hazards, estimates and controls risk, and evaluates overall residual risk acceptability. The benefit-risk determination weighs that residual risk against the clinical benefits established by the clinical evaluation. Risk management supplies one half of the input; the clinical evaluation supplies the other.
What counts as a clinical benefit?
A meaningful, measurable, patient-relevant clinical outcome — including outcomes related to diagnosis — or a positive impact on patient management or on public health. Technical characteristics such as resolution, weight or ease of handling are not clinical benefits in themselves; they qualify only where a demonstrated effect on a clinical outcome is shown.
Which method should be used to weigh benefits against risks?
The Regulation does not prescribe one. A structured qualitative narrative against defined comparison parameters is adequate for most devices; a semi-quantitative matrix suits devices with several distinct benefits and hazards; NNT and NNH work where incidence data exist for a dominant benefit and harm; multi-criteria decision analysis suits Class III and implantable devices. The choice and its rationale belong in the risk management plan, before the analysis is performed.
How often must the benefit-risk analysis be updated?
Whenever the inputs change. Three triggers reopen it: a threshold breached in post-market surveillance data, new PMCF evidence on the sustained benefit, and a shift in the state of the art. For Class III and implantable devices the PSUR is annual, which sets a floor; for other devices the cadence is defined in the PMS plan.
Can a change in the state of the art make an acceptable device unacceptable?
Yes, and this is the trigger most often missed. Acceptability is judged against the state of the art, so a competing device or therapy that improves outcomes raises the benchmark. The balance may become unacceptable with nothing having changed about your own device, which is why monitoring the state of the art is part of post-market surveillance rather than a pre-market exercise.
What are the most common Notified Body findings on benefit-risk analysis?
Technical characteristics presented as clinical benefits; separate and divergent versions of the determination in the risk management report, the clinical evaluation report and the PSUR; a state of the art assembled from favourable comparators; risks left in engineering language without clinical consequence; no subgroup analysis; PMS thresholds set so high they cannot fire; and no statement of residual uncertainty.
Conclusions
The benefit-risk determination is where the technical file states its conclusion, and it is judged on whether the comparison is genuine. Two failures account for most of the findings, and neither is about the quality of the underlying evidence.
The first is comparing the wrong things: technical specifications set against clinical harms, because the benefits were never expressed as patient outcomes. The second is producing the determination more than once — in the risk file, in the CER, in the PSUR — and letting the copies drift apart. One analysis, held in one place and referenced from the other five, removes an entire category of finding.
The third point is the one the MDR added and that pre-market thinking still resists: the determination has a shelf life. It is judged against the state of the art, and the state of the art moves whether or not your device does.
If you are building the file, the Risk Management Documentation Kit holds the benefit-risk analysis inside the risk management report where the other locations can reference it, and the EU MDR Technical Documentation Kit covers the Annex II section 5 placement and the GSPR entries that point to it.