Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
alirezarezvani avatar

Risk Management Specialist

  • 831 installs
  • 23.5k repo stars
  • Updated July 17, 2026
  • alirezarezvani/claude-skills

risk-management-specialist is a medical-device compliance skill that generates ISO 14971:2019 risk management artifacts for developers and engineers building regulated health software or hardware.

About

risk-management-specialist is an implementation guide skill from alirezarezvani/claude-skills for medical device risk management per ISO 14971:2019. It structures seven workflow areas: risk management planning, risk analysis, risk evaluation, risk control, overall residual risk evaluation, risk management report, and production plus post-production activities. Each section maps required elements such as scope, hazard identification, control measures, and documentation tables engineers need for design controls. Teams building FDA or EU MDR-bound devices reach for this skill to produce audit-ready risk files instead of assembling fragmented spreadsheets during design reviews.

  • Implements the full 7-stage ISO 14971:2019 risk management process
  • Delivers ready-to-use templates for Risk Management Plan, Risk Analysis, Risk Evaluation, Risk Control, and Post-Product
  • Produces Risk Management Report with traceability matrices and residual risk summaries
  • Includes RACI charts, acceptability criteria matrices, and verification plans
  • Hard-gate: requires approved scope before proceeding to implementation planning

Risk Management Specialist by the numbers

  • 831 all-time installs (skills.sh)
  • +7 installs in the week ending Jul 29, 2026 (Skillselion tracking)
  • Ranked #564 of 3,282 Productivity & Planning skills by installs in the Skillselion catalog
  • Security screen: MEDIUM risk (skills.sh audit)
  • Data as of Jul 31, 2026 (Skillselion catalog sync)
npx skills add https://github.com/alirezarezvani/claude-skills --skill risk-management-specialist

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs831
repo stars23.5k
Security audit2 / 3 scanners passed
Last updatedJuly 17, 2026
Repositoryalirezarezvani/claude-skills

How do you document medical device risk per ISO 14971?

Generate complete ISO 14971:2019 compliant risk management artifacts for medical device projects.

Who is it for?

Engineers on medical device or health-software projects who must produce ISO 14971:2019 documentation during design and validation.

Skip if: Non-medical software with no regulatory risk-file requirements or teams needing ISO 27001 security incident response instead.

When should I use this skill?

A medical device project needs ISO 14971 risk planning, hazard analysis, risk controls, or residual risk documentation.

What you get

ISO 14971 risk management plan, analysis records, control documentation, residual risk evaluation, and management report.

  • Risk management plan
  • Hazard analysis
  • Risk management report

By the numbers

  • Covers 7 ISO 14971:2019 workflow sections from planning through post-production

Files

SKILL.mdMarkdownGitHub ↗

Risk Management Specialist

ISO 14971:2019 risk management implementation throughout the medical device lifecycle.

---

Table of Contents

---

Risk Management Planning Workflow

Establish risk management process per ISO 14971.

Workflow: Create Risk Management Plan

1. Define scope of risk management activities:

  • Medical device identification
  • Lifecycle stages covered
  • Applicable standards and regulations

2. Establish risk acceptability criteria:

  • Define probability categories (P1-P5)
  • Define severity categories (S1-S5)
  • Create risk matrix with acceptance thresholds

3. Assign responsibilities:

  • Risk management lead
  • Subject matter experts
  • Approval authorities

4. Define verification activities:

  • Methods for control verification
  • Acceptance criteria

5. Plan production and post-production activities:

  • Information sources
  • Review triggers
  • Update procedures

6. Obtain plan approval 7. Establish risk management file 8. Validation: Plan approved; acceptability criteria defined; responsibilities assigned; file established

Risk Management Plan Content

SectionContentEvidence
ScopeDevice and lifecycle coverageScope statement
CriteriaRisk acceptability matrixRisk matrix document
ResponsibilitiesRoles and authoritiesRACI chart
VerificationMethods and acceptanceVerification plan
Production/Post-ProductionMonitoring activitiesSurveillance plan

Risk Acceptability Matrix (5x5)

Probability \ SeverityNegligibleMinorSeriousCriticalCatastrophic
Frequent (P5)MediumHighHighUnacceptableUnacceptable
Probable (P4)MediumMediumHighHighUnacceptable
Occasional (P3)LowMediumMediumHighHigh
Remote (P2)LowLowMediumMediumHigh
Improbable (P1)LowLowLowMediumMedium

Risk Level Actions

LevelAcceptableAction Required
LowYesDocument and accept; still reduce as far as possible (EU MDR)
MediumAfter reduction AFAPReduce as far as possible; document why further reduction is impossible
HighAfter reduction AFAPReduction required; demonstrate all further options exhausted
UnacceptableNoDesign change mandatory
EU MDR — AFAP, not ALARP: For CE-marked devices, risks must be reduced as far as possible (AFAP) without economic considerations (MDR Annex I, GSPR 1–4; EN ISO 14971:2019/A11:2021 Z-annexes deviation). ALARP ("as low as reasonably practicable"), which permits cost-benefit weighing in acceptability decisions, is not an acceptable criterion under the EU MDR — a notified body will flag it. ISO 14971:2019 itself removed ALARP from the normative text. ALARP may persist in some non-EU jurisdictions (e.g., the UK HSE tradition); if used outside the EU, flag the deviation from EU requirements explicitly.

---

Risk Analysis Workflow

Identify hazards and estimate risks systematically.

Workflow: Conduct Risk Analysis

1. Define intended use and reasonably foreseeable misuse:

  • Medical indication
  • Patient population
  • User population
  • Use environment

2. Select analysis method(s):

  • FMEA for component/function analysis
  • FTA for system-level analysis
  • HAZOP for process deviations
  • Use Error Analysis for user interaction

3. Identify hazards by category:

  • Energy hazards (electrical, mechanical, thermal)
  • Biological hazards (bioburden, biocompatibility)
  • Chemical hazards (residues, leachables)
  • Operational hazards (software, use errors)

4. Determine hazardous situations:

  • Sequence of events
  • Foreseeable misuse scenarios
  • Single fault conditions

5. Estimate probability of harm (P1-P5) 6. Estimate severity of harm (S1-S5) 7. Document in hazard analysis worksheet 8. Validation: All hazard categories addressed; all hazards documented; probability and severity assigned

Hazard Categories Checklist

CategoryExamplesAnalyzed
ElectricalShock, burns, interference
MechanicalCrushing, cutting, entrapment
ThermalBurns, tissue damage
RadiationIonizing, non-ionizing
BiologicalInfection, biocompatibility
ChemicalToxicity, irritation
SoftwareIncorrect output, timing
Use ErrorMisuse, perception, cognition
EnvironmentEMC, mechanical stress

Analysis Method Selection

SituationRecommended Method
Component failuresFMEA
System-level failureFTA
Process deviationsHAZOP
User interactionUse Error Analysis
Software behaviorSoftware FMEA
Early design phasePHA

Probability Criteria

LevelNameDescriptionFrequency
P5FrequentExpected to occur>10⁻³
P4ProbableLikely to occur10⁻³ to 10⁻⁴
P3OccasionalMay occur10⁻⁴ to 10⁻⁵
P2RemoteUnlikely10⁻⁵ to 10⁻⁶
P1ImprobableVery unlikely<10⁻⁶

Severity Criteria

LevelNameDescriptionHarm
S5CatastrophicDeathDeath
S4CriticalPermanent impairmentIrreversible injury
S3SeriousInjury requiring interventionReversible injury
S2MinorTemporary discomfortNo treatment needed
S1NegligibleInconvenienceNo injury

See: references/risk-analysis-methods.md

---

Risk Evaluation Workflow

Evaluate risks against acceptability criteria.

Workflow: Evaluate Identified Risks

1. Calculate initial risk level from probability × severity 2. Compare to risk acceptability criteria 3. For each risk, determine:

  • Acceptable: Document and accept (EU MDR: still reduce as far as possible)
  • Reduction required (AFAP): Proceed to risk control
  • Unacceptable: Mandatory risk control

4. Document evaluation rationale 5. Identify risks requiring benefit-risk analysis 6. Complete benefit-risk analysis if applicable 7. Compile risk evaluation summary 8. Validation: All risks evaluated; acceptability determined; rationale documented

Risk Evaluation Decision Tree

Risk Estimated
      │
      ▼
Apply Acceptability Criteria
      │
      ├── Low Risk ──────────► Accept and document
      │
      ├── Medium Risk ───────► Reduce as far as possible (AFAP)
      │   │                    Document why further reduction impossible
      │   ▼
      │   Further reduction possible?
      │   │
      │   Yes──► Implement control
      │   No───► Document AFAP rationale (no economic considerations)
      │
      ├── High Risk ─────────► Risk reduction required
      │   │                    Must demonstrate reduction AFAP
      │   ▼
      │   Implement control
      │   Verify residual risk
      │
      └── Unacceptable ──────► Design change mandatory
                               Cannot proceed without control

AFAP Demonstration Requirements (EU MDR)

CriterionEvidence Required
All control options consideredAnalysis of every feasible control per the hierarchy (design, protective measures, information)
Further reduction impossibleEvidence each remaining option is technically infeasible or does not further reduce risk
State of the artComparison to similar devices and current standards
Stakeholder inputClinical/user perspectives
Economic considerations (cost of further risk reduction) must not enter the EU acceptability decision (MDR Annex I GSPR 2; EN ISO 14971:2019/A11:2021). Cost may inform business decisions about whether to market the device — never whether a risk is acceptable.

Benefit-Risk Analysis Triggers

SituationBenefit-Risk Required
Residual risk remains highYes
No feasible risk reductionYes
Novel deviceYes
Unacceptable risk with clinical benefitYes
All risks lowNo

---

Risk Control Workflow

Implement and verify risk control measures.

Workflow: Implement Risk Controls

1. Identify risk control options:

  • Inherent safety by design (Priority 1)
  • Protective measures in device (Priority 2)
  • Information for safety (Priority 3)

2. Select optimal control following hierarchy 3. Analyze control for new hazards introduced 4. Document control in design requirements 5. Implement control in design 6. Develop verification protocol 7. Execute verification and document results 8. Evaluate residual risk with control in place 9. Validation: Control implemented; verification passed; residual risk acceptable; no unaddressed new hazards

Risk Control Hierarchy

PriorityControl TypeExamplesEffectiveness
1Inherent SafetyEliminate hazard, fail-safe designHighest
2Protective MeasuresGuards, alarms, automatic shutdownHigh
3InformationWarnings, training, IFULower

Risk Control Option Analysis Template

RISK CONTROL OPTION ANALYSIS

Hazard ID: H-[XXX]
Hazard: [Description]
Initial Risk: P[X] × S[X] = [Level]

OPTIONS CONSIDERED:
| Option | Control Type | New Hazards | Feasibility | Selected |
|--------|--------------|-------------|-------------|----------|
| 1 | [Type] | [Yes/No] | [H/M/L] | [Yes/No] |
| 2 | [Type] | [Yes/No] | [H/M/L] | [Yes/No] |

SELECTED CONTROL: Option [X]
Rationale: [Justification for selection]

IMPLEMENTATION:
- Requirement: [REQ-XXX]
- Design Document: [Reference]

VERIFICATION:
- Method: [Test/Analysis/Review]
- Protocol: [Reference]
- Acceptance Criteria: [Criteria]

Risk Control Verification Methods

MethodWhen to UseEvidence
TestQuantifiable performanceTest report
InspectionPhysical presenceInspection record
AnalysisDesign calculationAnalysis report
ReviewDocumentation checkReview record

Residual Risk Evaluation

After ControlAction
AcceptableDocument, proceed
Reduced AFAPDocument rationale (no economic considerations), proceed
Still unacceptableAdditional control or design change
New hazard introducedAnalyze and control new hazard

---

Post-Production Risk Management

Monitor and update risk management throughout product lifecycle.

Workflow: Post-Production Risk Monitoring

1. Identify information sources:

  • Customer complaints
  • Service reports
  • Vigilance/adverse events
  • Literature monitoring
  • Clinical studies

2. Establish collection procedures 3. Define review triggers:

  • New hazard identified
  • Increased frequency of known hazard
  • Serious incident
  • Regulatory feedback

4. Analyze incoming information for risk relevance 5. Update risk management file as needed 6. Communicate significant findings 7. Conduct periodic risk management review 8. Validation: Information sources monitored; file current; reviews completed per schedule

Information Sources

SourceInformation TypeReview Frequency
ComplaintsUse issues, failuresContinuous
ServiceField failures, repairsMonthly
VigilanceSerious incidentsImmediate
LiteratureSimilar device issuesQuarterly
RegulatoryAuthority feedbackAs received
ClinicalPMCF dataPer plan

Risk Management File Update Triggers

TriggerResponse TimeAction
Serious incidentImmediateFull risk review
New hazard identified30 daysRisk analysis update
Trend increase60 daysTrend analysis
Design changeBefore implementationImpact assessment
Standards updatePer transition periodGap analysis

Periodic Review Requirements

Review ElementFrequency
Risk management file completenessAnnual
Risk control effectivenessAnnual
Post-market information analysisQuarterly
Risk-benefit conclusionsAnnual or on new data

---

Risk Assessment Templates

→ See references/risk-assessment-templates.md for details

Decision Frameworks

Risk Control Selection

What is the risk level?
        │
        ├── Unacceptable ──► Can hazard be eliminated?
        │                    │
        │                Yes─┴─No
        │                 │     │
        │                 ▼     ▼
        │            Eliminate  Can protective
        │            hazard     measure reduce?
        │                           │
        │                       Yes─┴─No
        │                        │     │
        │                        ▼     ▼
        │                   Add       Add warning
        │                   protection + training
        │
        └── High/Medium ──► Apply hierarchy
                            starting at Level 1

New Hazard Analysis

QuestionIf YesIf No
Does control introduce new hazard?Analyze new hazardProceed
Is new risk higher than original?Reject control optionAcceptable trade-off
Can new hazard be controlled?Add controlReject control option

Risk Acceptability Decision

ConditionDecision
All risks LowAcceptable
Medium risks reduced AFAPAcceptable
High risks reduced AFAP, documentedAcceptable if benefits outweigh
Any Unacceptable residualNot acceptable - redesign

---

Tools and References

Scripts

ToolPurposeUsage
risk_matrix_calculator.pyCalculate risk levels and FMEA RPNpython risk_matrix_calculator.py --help

Risk Matrix Calculator Features:

  • ISO 14971 5x5 risk matrix calculation
  • FMEA RPN (Risk Priority Number) calculation
  • Interactive mode for guided assessment
  • Display risk criteria definitions
  • JSON output for integration

References

DocumentContent
iso14971-implementation-guide.mdComplete ISO 14971:2019 implementation with templates
risk-analysis-methods.mdFMEA, FTA, HAZOP, Use Error Analysis methods

Quick Reference: ISO 14971 Process

StageKey ActivitiesOutput
PlanningDefine scope, criteria, responsibilitiesRisk Management Plan
AnalysisIdentify hazards, estimate riskHazard Analysis
EvaluationCompare to criteria, AFAP assessment (EU)Risk Evaluation
ControlImplement hierarchy, verifyRisk Control Records
ResidualOverall assessment, benefit-riskRisk Management Report
ProductionMonitor, review, updateUpdated RM File

---

Related Skills

SkillIntegration Point
quality-manager-qms-iso13485QMS integration
capa-officerRisk-based CAPA
regulatory-affairs-headRegulatory submissions
quality-documentation-managerRisk file management

Related skills

How it compares

Use risk-management-specialist for ISO 14971 medical risk files; use information-security-manager-iso27001 for security incident response.

FAQ

Which standard does risk-management-specialist implement?

risk-management-specialist follows ISO 14971:2019 for medical device risk management, covering planning, analysis, evaluation, controls, residual risk, reports, and post-production activities.

What artifacts does ISO 14971 documentation include?

risk-management-specialist produces risk management plans, hazard analyses, risk evaluations, control measures, overall residual risk assessments, and formal risk management reports per ISO 14971:2019.

Is Risk Management Specialist safe to install?

skills.sh reports 2 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Productivity & Planningagentsautomation

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.