BioDeviceHub
Engineer's Guide/General Practice

Risk Management

ISO 14971's severity × probability logic, the risk matrix, ALARP, and residual-risk communication in practical BMET terms.

ISO 14971 is the standard manufacturers use to manage medical-device risk across the entire product lifecycle, from design through post-market surveillance. A BMET doesn't need to run a full ISO 14971 process, but the underlying logic is directly useful for prioritizing your own work every single day.

Severity × probability

Risk isn't just how bad an outcome could be - it's how bad, multiplied by how likely. A low-probability fault with catastrophic severity (a defibrillator failing to deliver energy) gets prioritized well above a high-probability, low-severity nuisance fault (a cosmetic display flicker), even though the nuisance fault might generate ten times as many complaint tickets. This is why a well-run biomed program tracks failure severity, not just failure count, when deciding where to invest PM and inspection effort.

As Low As Reasonably Practicable (ALARP)

The practical standard for "how much risk reduction is enough" is not zero risk - zero risk isn't achievable for any real device - but risk reduced to the point where further reduction costs more (in time, money, or usability) than the benefit gained. This concept explains why a device ships with documented residual risks rather than being redesigned indefinitely, and it's the same logic a biomed department applies when deciding, say, that a fully-redundant backup power supply isn't justified for a low-acuity accessory device the way it is for a ventilator.

Residual risk communication

A known limitation that can't be fully engineered out - a battery that degrades with age, a sensor with a known drift characteristic - has to be communicated to the people using and maintaining the device, not just accepted silently by whoever happens to know about it. In practice this means: labeling, training materials, and PM checklist items that specifically call out the known limitation, so it stays visible to every technician who touches the device after you, not just the one who originally discovered it.

Applying this to your own prioritization

When triaging a backlog of work orders, a rough severity × probability mental model - even without formally scoring every ticket - will usually put you in the right order: address anything touching life-support function or direct patient contact first, regardless of how the ticket queue happened to sort itself by submission time.