Operator’s Guides — ISO 14971 · Module 7 of 12

In ISO 14971, 'Acceptable Risk' Is a Decision You Make Before You Analyze

Risk evaluation is where a color on the matrix becomes a verdict. Here's how to draw the acceptability line, demonstrate ALARP, and be honest about the gray zone most companies fudge.

All ISO 14971 modules
Module 07 32:07 video + article

Watch this module

Module 7 of the video course. The article below covers the same ground in written form, so you can watch, read, or both.

# In ISO 14971, "Acceptable Risk" Is a Decision You Make Before You Analyze

ISO 14971 defines a safe device in five words: freedom from unacceptable risk. Not freedom from risk. Freedom from unacceptable risk. Read it carefully and that one word, unacceptable, hands you the hardest question in the whole standard, because the standard never tells you what unacceptable means. It can't. What's unacceptable for a wearable insulin pump is different from what's unacceptable for a tongue depressor. Somebody has to decide where the line sits, and when they decide it turns out to matter as much as where.

Back in Module 6, every one of WearPump's eleven hazards got a probability, a severity, and a place on the five-by-five matrix. Every hazard got a color. But a color doesn't tell you what to do about it. Green, yellow, and red describe where a risk sits; they aren't yet decisions. Risk evaluation, ISO 14971 Clause 6, is the step that turns a color into a verdict. Each hazard walks in with a position on the matrix and walks out with a decision: acceptable, ship it. Or tolerable, but only if you've done something specific first. Or unacceptable, and this device does not go out the door until you fix it.

The trap: you don't draw the line now

Here's the trap I've watched sink more risk files than any other. You do not get to decide where the acceptability line sits right now, looking at your results. You had to have drawn it earlier, back in the risk management plan from Module 3, before you had a single number in hand. Draw the line after you see the results, and you've built a circular argument an auditor takes apart in about a minute.

The reason the order matters is human. Finish your analysis, and suppose one nasty hazard lands just inside the unacceptable zone. If you're allowed to redraw the line now, under deadline pressure, the line moves. Just a little. Just enough. And now your criteria aren't a safety judgment, they're a rationalization of whatever results you happened to get. Reviewers have seen that move a hundred times, and they look for it specifically. The single most common version, which I've watched happen at more than one young company, is setting the risk matrix after seeing the analysis. It feels efficient. It's fatal.

I'm Dave Saunders. I've spent more than 30 years commercializing technology, almost 20 of them in medical devices and regulatory affairs, including several surgical robots, a good part of it in audit rooms watching these decisions get defended, or fall apart. Clause 6 itself is short, almost anticlimactically so: compare each hazard's estimated risk against the criteria defined in your plan; if it's acceptable it becomes a residual risk, and if it's not, you go to risk control. The entire weight of the clause rests on four words, defined in your plan. The clause has no opinion of its own. It just says: compare against the criteria you already wrote down.

Those criteria come from a hierarchy. Top management sets a policy, a written commitment to how the company approaches acceptable risk, and that policy has to rest on real anchors: regulations, international standards, the generally acknowledged state of the art, and known stakeholder concerns. The policy drives the criteria for a specific device, written into the plan. And the criteria drive the evaluation, applied to each hazard. Policy, then criteria, then evaluation, all three consistent and traceable. The policy also has to name which reduction principle you're committing to, ALARP, ALARA, or SFAIRP, because the choice changes how hard you're obligated to push in the tolerable zone. Name it on purpose, before you need it.

Three zones, not two

The criteria carve the matrix into three zones, not two, and the third one is where evaluation stops being paperwork. On a five-by-five, it's a coloring rule: every one of the twenty-five cells is pre-assigned to a zone, so when a hazard lands on a cell, its verdict is already written.

The acceptable zone, usually the green cells, needs no further reduction. You record the result and carry the risk forward as a residual risk. Even here, though, acceptable is not the same as ignore it. An empty row in a file doesn't read as "this was fine." It reads as "nobody looked." The unacceptable zone, the red cells, stops the line. You cannot ship, you go to risk control, and you re-evaluate whatever residual is left. Some companies draw only these two zones, a hard line with fix above and ship below. It's simpler, and it's quietly worse, because it lets a genuinely uncomfortable risk fall just under the line and get waved through with no obligation to reduce it.

The middle zone, the yellow band, is the tolerable zone, and tolerable is not acceptable. It means the risk may be allowed to remain, but only if you have first reduced it as far as reasonably practicable. That's ALARP, and it's one of the most misunderstood ideas in the field. You keep reducing until the cost and effort of reducing further becomes grossly disproportionate to the safety you'd gain. The part people get exactly backwards: ALARP is not a synonym for "good enough." The default assumption is that more reduction is required. Stopping is the exception, and stopping requires justification. You don't prove you should keep going; you prove you were allowed to stop. And "grossly" is doing a lot of work, a deliberately high bar, because the whole point is to push manufacturers past the cheap, comfortable stopping points. There's no clean dollars-per-risk formula for it, and anyone selling you one is overselling. It's a judgment, and the answer to that discomfort isn't a fake formula, it's documentation good enough that your judgment is legible to a stranger.

Four natural-sounding justifications are simply not valid ALARP arguments. It would be too expensive, with no evidence of gross disproportion. We already meet the regulatory minimum, when regulations are floors, not ceilings. Other devices have the same risk, when the state of the art can still require you to do better. And the probability is low, when severity still matters and a rare catastrophic outcome is a serious concern.

The table an auditor actually asks for

So what does count? Demonstrating ALARP comes down to four things you do and four things you write down, because ALARP that lives only in your head is worth nothing. Document every option you considered, not just the ones you used. Implement every measure whose cost isn't grossly disproportionate to the benefit, all of them. Document why you rejected the ones you didn't. And compare what's left against the state of the art. That third step, the rejections, is where the real defensibility lives; anybody can list the controls they added, but the honest record of the ones you considered and chose not to add, with reasons a stranger could evaluate, is the evidence you actually thought about it.

Put the four together and you get a table. Here's a real one, for WearPump's skin reaction at the adhesive site, which scored probable on probability and moderate on severity, landing it in the yellow zone.

Risk control optionCostRisk reductionDecision
Switch to silicone adhesive+ $0.80 / unitP: 4 to 3Implemented
Add app skin-check reminder+ $15k one-timeP: 3 to 2Implemented
Add real-time skin sensor+ $45 / unit, 6 moP: 2 to 2 (marginal)Rejected, grossly disproportionate
Drop adhesive for mechanical clipredesign, 18 mo, new hazardnet negativeRejected, introduces a greater risk

Two implemented, two rejected with documented reasons. The residual, after the silicone and the reminder, sits at probability three, severity two: green, acceptable. That table is a demonstrated ALARP argument. Not a shrug, not "we did our best," but a specific, auditable record. Compare it to what most files contain for a yellow hazard: a single line, "risk reduced, acceptable." No options, no costs, no rejections. That's not ALARP. That's the word ALARP written next to a decision nobody can check.

The floor that moves

That fourth step, state of the art, deserves its own moment, because it quietly raises the bar on everyone. State of the art, in ISO 14971, is what is currently and generally accepted as good practice, not the most advanced thing anyone has built. And it sets the floor for what counts as acceptable. If a safer design already exists and is in common use across your field, your design has to match it or justify, in writing, why it doesn't. Which means a competitor can raise your bar: if another pump solves a hazard you're still living with, their solution can redefine what reasonably practicable means for you. Their good idea just became your new minimum. This is exactly why meeting the regulatory minimum isn't a valid argument; standards are floors, and they lag the state of the art because codification takes years.

You find the state of the art in consensus standards like 60601 and 62366, in clinical practice guidelines, in the safety features standard on comparable pumps, in FDA design guidance, and in the incident databases. That last one is the most humbling: the FDA's public MAUDE record is a searchable history of exactly how pumps like yours have hurt people in the real world. If you haven't read what's already gone wrong in your category, you can't credibly claim your analysis reflects the state of the art. And because it moves, this isn't a one-time check; the 2019 standard requires you to keep monitoring it. A device built to the state of the art of ten years ago can quietly fall out of acceptability without a single thing about it changing. The world moved. The device didn't.

There's one honest path out of the yellow zone for a risk you can't reduce any further: benefit-risk analysis, Clause 7.4. It asks whether the clinical benefits, for this patient, outweigh the residual risk that's left. If they do, the risk may be judged acceptable on those grounds, documented with clinical evidence. But it's not a rubber stamp and not a way around ALARP; you get there after reducing as far as reasonably practicable, not instead of it, and if the benefit doesn't outweigh the risk, the device can't ship.

Every hazard, a verdict

With the machinery in hand, WearPump's eleven hazards each get a verdict. The connectivity hazard, probability three and severity four, is red: unacceptable, blocked until controlled. The motor driver stuck on, probability two and severity five, lands in the elevated amber band, because a severity-five hazard never sits quietly; it needs control and a documented ALARP argument on the residual. The yellow cluster, the silenced-alarm combination, the reservoir seal, the Bluetooth lockup, each needs the full ALARP table we just built for the adhesive site. The acceptable ones, the moisture combination and the adhesive site after its ALARP work, get recorded and carried forward.

I promised the honest part, so here it is. The yellow zone is where real companies fudge. With a tolerable-zone hazard it's tempting to write "acceptable" and move on, because technically it's in a band the plan allows, and at the end of a long project with a deadline looming the pressure is enormous. That's the move that turns a risk file from a safety document into a liability waiting to be discovered. Because a yellow hazard you waved through, with no ALARP table behind it, is fine right up until someone is harmed and a lawyer or regulator pulls the file. Then the question is simple and devastating: you called this tolerable, so show me what you did to reduce it. If the answer is a blank space, tolerable becomes negligent, in front of exactly the audience you least want to explain it to.

If you take one thing from this, take this. Acceptable risk is not a discovery you make at the end, looking at your numbers. It's a line you commit to at the beginning, before the numbers exist, and then honor hazard by hazard, even when it's inconvenient. And tolerable is not a synonym for acceptable. It's a promise that you reduced the risk as far as you reasonably could, and can prove it.

Module 8 takes every hazard we just marked red or amber, and every unfinished yellow, and engineers it down, using the three-tier risk control hierarchy in the order the standard requires. More on product strategy, roadmaps, and fractional CPO work at baserealitygroup.com, and I write more broadly for founders too, in a newsletter called The Build, at davesaunders.net.

Get the next guide

ISO 14971 is the first Operator’s Guide. ISO 13485, IEC 60601, and the GHG Protocol are in the queue. Leave your email and each new guide lands in your inbox the day it ships. Nothing else, no drip sequence.

Done. You’ll get the next guide when it ships.

The standard is free. So is this course. Building the product is the work.

Work With Dave

Prefer a smaller first step? Book a $500 one-hour working session →

Dave Saunders

Dave Saunders is the founder of Base Reality Group and a Fractional CPO for hard-tech founders. He was a founder and operator at Galen Robotics, where the surgical-robotics platform earned FDA De Novo authorization in 2023, and he managed a 35-patent portfolio licensed from Johns Hopkins. He wrote Founders Who Finish and publishes The Build. More about Dave →