Residual Risk Justification: What Auditors and Reviewers Expect (ISO 14971 Guide)
Residual risk justification under ISO 14971 requires clear evidence that remaining risks are acceptable based on defined criteria, supported by data, risk-benefit analysis where necessary, and full traceability to risk controls. Auditors expect documented rationale—not assumptions—when residual risks are accepted.
If you cannot justify why a risk is acceptable, your risk management file will fail review.
What Residual Risk Actually Means
Residual risk is the risk that remains after all risk control measures have been implemented.
This is not optional. Every medical device has residual risk.
The key requirement is:
You must demonstrate that residual risk is acceptable.
Related:
Fix Risk Management File Gaps
Why Residual Risk Justification Fails
Most failures are not technical—they are logical.
Common failure pattern:
- Risk is reduced
- Marked as “acceptable”
- No justification provided
This is one of the most common audit findings in ISO 14971 reviews.
What Auditors and Reviewers Actually Expect
1. Defined Risk Acceptability Criteria
You must define what “acceptable risk” means before performing risk analysis.
This includes:
- Risk matrices
- Severity and probability thresholds
Audit failure: Acceptability criteria defined after the fact.
2. Clear Residual Risk Evaluation
After controls are applied, you must:
- Reassess the risk
- Compare it against acceptability criteria
Audit failure: No reassessment after controls.
3. Justification of Acceptability
This is the critical step.
You must explain:
- Why the remaining risk is acceptable
- What evidence supports that decision
Weak justification:
“Risk is low and acceptable”
Strong justification:
“Risk reduced to low probability and moderate severity. This falls within defined acceptable region based on risk criteria. No further control is practicable without impacting device performance.”
4. Risk-Benefit Analysis (When Required)
If residual risk is not acceptable, you must:
- Perform risk-benefit analysis
- Demonstrate benefits outweigh risks
Audit failure: Skipping this step when required.
5. Traceability
You must show full linkage:
- Hazard → risk → control → residual risk
Audit failure: Residual risk not linked to controls.
Real Audit Findings on Residual Risk
Finding 1: Residual Risk Marked Acceptable Without Rationale
Fix:
- Provide written justification
- Reference risk criteria explicitly
Finding 2: No Risk-Benefit Analysis
Fix:
- Document benefit of device
- Compare against residual risk clearly
Finding 3: Inconsistent Risk Decisions
Fix:
- Apply criteria consistently
- Standardise evaluation approach
How to Justify Residual Risk Properly
Step 1: Define Acceptability Criteria
- Before risk analysis
- Based on standards and regulations
Step 2: Apply Risk Controls
- Follow hierarchy of controls
Step 3: Reassess Risk
- Update probability and severity
Step 4: Justify Acceptability
- Reference criteria
- Provide rationale
Step 5: Perform Risk-Benefit Analysis (if needed)
- Document clinical or functional benefits
How Residual Risk Links to Design and Testing
Residual risk justification must align with:
- Design controls
- Verification and validation
- Product performance
Related:
Fix Design Controls Gaps
How Residual Risk Links to Post-Market Data
Residual risk must be reassessed when:
- Complaints occur
- CAPAs are raised
- New data becomes available
This is where many systems fail—they do not close the loop.
Common Mistakes to Avoid
- Marking risks acceptable without explanation
- Not defining criteria upfront
- Ignoring risk-benefit analysis
- Failing to link to risk controls
These are major audit triggers.
Quick Residual Risk Checklist
- Is acceptability criteria defined?
- Is residual risk reassessed?
- Is justification documented?
- Is risk-benefit analysis performed where needed?
- Is traceability complete?
If not, your file is at risk.
When to Get Expert Support
You should take action if:
- Your risk file is being challenged
- Residual risk is not clearly justified
- You are preparing for regulatory submission
Next steps:
Final Thought
Residual risk justification is where your risk management system is truly tested.
You are not just documenting risk—you are defending your decisions.
If those decisions are not clear, consistent, and evidence-based, your file will not pass review.