News|Events|September 15, 2026

The Risk File Was Never Meant to Be a Once-a-Year Exercise

Author(s)Plarent Ymeri
Fact checked by: Zachary Zubulake
Listen
0:00 / 0:00

AI can turn medical device risk management into a continuous signal.

Risk management in medical devices carries 2 identities. ISO 14971 defines a lifecycle process for identifying hazards, estimating and evaluating risk, controlling risk, and monitoring whether controls remain effective.1 In practice, however, the risk file may still be revisited through periodic, manually assembled reviews. By the time a review is approved, some of the evidence behind it may already have changed.

The mechanics explain why. A risk review asks a team to reconcile hazards and hazardous situations against production and post-production information, including complaints, incidents, nonconformances, service records, and other post-market evidence.1,2 Where reliable denominator data are available, event counts can be considered against sales volume, the size of the exposed population, or device use to determine whether an observed occurrence rate remains consistent with the risk estimate.3

At scale, this becomes difficult to sustain. The evidence may sit across complaint handling systems, vigilance databases, corrective and preventive action and quality systems, service platforms, and enterprise resource planning or sales systems. Teams then spend substantial time finding, cleaning, aligning, and classifying data before they can interpret what it means for risk.

How a Once-A-Year Cycle Delays the Response to Real Risk

The larger issue is latency. If a device's real-world failure rate begins drifting above the threshold assumed in the risk file in February, but the formal review happens in November, the organization may not connect that change to the existing risk estimate for months.

This delay is at odds with the direction of current post-market requirements. The European Union’s Medical Device Regulation requires manufacturers to actively and systematically gather, record, and analyze relevant data throughout a device's lifetime and use those data to update the benefit-risk determination, risk management, design and manufacturing information, and other safety actions.2 It also requires trend reporting for statistically significant increases in the frequency or severity of certain incidents.2 Signal detection and risk review may still run as separate workstreams, but they depend on the same evidence.

The Strain of Classifying Hazards by Hand

The heaviest work often sits in classification. Complaint and nonconformance narratives are unstructured, yet they must be connected to device problems, causes, health effects, harms, failure modes, and the hazards already defined in the risk file. The International Medical Device Regulators Forum maintains a standardized terminology for categorized medical device adverse event reporting, with 2026 updates to its coding annexes, to support consistent categorization and reporting.4

Natural language processing can reduce part of this workload. Studies using medical device adverse event reports and field safety notices have shown that natural language processing models can identify, classify, and aggregate unstructured safety text.5-7 Those results demonstrate feasibility, not universal accuracy. Performance depends on the device, dataset, taxonomy, labeling quality, and validation method.

Where Combination Products Make the Problem Harder

Nowhere is this strain more visible than in combination products. A prefilled syringe, an autoinjector, a drug-eluting stent, or a metered-dose inhaler carries a drug constituent and a device constituent, and each constituent brings its own risk framework.

Those frameworks were not written to speak to each other. ISO 14971 governs risk management for the device constituent, structured around hazards, hazardous situations, harms, and risk control.1 The drug constituent sits under quality risk management principles described in the International Council for Harmonisation’s Q9(R1) guideline, which is organized around product quality and patient risk in pharmaceutical manufacturing.8 The 2 use different vocabularies, different severity concepts, and different criteria for what counts as acceptable residual risk.

Post-market reporting is similarly doubled. In the United States, 21 Code of Federal Regulations Part 4 Subpart B requires combination product applicants to submit safety reports aligned to both constituent types, so an applicant holding a drug application may also owe device-type malfunction reporting.9 In the EU, integral drug-device combinations are subject to a notified body opinion on the device part under Article 117 of Regulation (EU) 2017/745.2

The practical consequence sits in the same place as before, at classification. A single narrative describing a failed injection may reflect a device malfunction, a drug quality defect, a use error, and the distinction often cannot be resolved without investigation. That 1 record may need to be mapped into 2 taxonomies, feed 2 reporting obligations, and update 2 risk assessments.

Denominator data can diverge as well. Device exposure may be counted in units distributed, while drug exposure may be expressed in doses administered or patient-days of therapy. An occurrence rate calculated against the wrong denominator can misstate risk in either direction.

For manufacturers of combination products, therefore, the periodic review cycle carries twice the assembly burden and twice the opportunity for a signal to sit unrecognized between reviews.

The 2 Layers That Can Make Continuous Risk Assessment Possible

Artificial intelligence (AI) can help close the gap, but only within a controlled architecture. That architecture has 2 layers.

The first is an orchestration layer that connects to the systems where post-market evidence lives: complaint handling, adverse event reporting, nonconformance and corrective and preventive action systems, service records, and enterprise resource planning or sales systems that hold denominator data. Instead of relying on periodic spreadsheet exports, the layer can retrieve current data, align it to the product hierarchy, and preserve traceability back to each source.

The second is assisted classification. A natural language processing or language model can propose how a record maps to a defined taxonomy and to hazards or hazardous situations in the risk file. For combination products, that mapping must be explicit about which regulatory framework each classification feeds, because the same record may serve more than one.

The model should not be treated as correct by default. Before operational use in a quality management process, the software needs a documented intended use, risk-based assurance, and objective evidence that it performs as intended.10 Ambiguous or low-confidence records should be routed to qualified reviewers.

Put the two layers together and the risk assessment no longer must wait for a scheduled data-assembly exercise. Occurrence rates can be recalculated as validated complaints, nonconformances, and denominator data are added.

The result is not an autonomous risk decision. It is a more current evidence set for the people responsible for that decision.

Why A Continuously Updated Risk File Can Strengthen Signal Detection

When an observed rate approaches or exceeds the probability assumed in the risk file, the system can surface the change with the underlying records attached. That gives reviewers a direct path from a potential signal to the hazard, harm, control, and benefit-risk questions that require attention.

This approach does not replace required post-market surveillance, vigilance, or trend-reporting processes. It can reduce duplication between them by feeding each process from the same governed evidence base, which matters most where a single record carries obligations under 2 frameworks. FDA guidance recognizes that relevant and reliable real-world data can support regulatory decision-making for medical devices, including post-market uses.11

That can shorten the path from detection to decision, whether the next step is a corrective and preventive action, a design change, a labeling update, a field action, or continued monitoring.

None of this removes people from the loop. Decisions about risk acceptability, benefit-risk, and mitigation strategy remain with qualified personnel under the manufacturer's risk management process.1 What AI can reduce is the time spent retrieving data, normalizing it, and performing first-pass classification, provided the system is assured for its intended use and its outputs remain reviewable.10

For quality leaders in both device and combination product organizations, the practical question is not whether to automate the risk file in 1 step. It is which parts of evidence collection, classification, and rate calculation can be automated safely, validated, and kept under human oversight. The goal is a risk file that responds to new evidence sooner without weakening the judgment and governance that patient safety requires.

References

1. International Organization for Standardization. ISO 14971:2019 Medical devices–Application of risk management to medical devices. December 2019. Reviewed and confirmed 2025. Accessed September 15, 2026. https://www.iso.org/standard/72704.html

2. European Parliament and Council of the European Union. Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices. Consolidated text, July 19, 2026. Accessed September 15, 2026. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02017R0745-20260719

3. Medical Device Coordination Group. MDCG 2022-21: Guidance on Periodic Safety Update Report (PSUR) According to Regulation (EU) 2017/745 (MDR). December 2022. Accessed September 15, 2026. https://health.ec.europa.eu/document/download/a7df24c3-d4a3-4218-a8e0-726febfa01c2_en?filename=mdcg_2022-21_en.pdf

4. International Medical Device Regulators Forum. Terminologies for Categorized Adverse Event Reporting (AER): Terms, Terminology and Codes. IMDRF/AE WG/N43 FINAL:2020; Updated Annexes Release No. 2026. March 2026. Accessed September 15, 2026. https://www.imdrf.org/documents/terminologies-categorized-adverse-event-reporting-aer-terms-terminology-and-codes

5. Luschi A, Nesi P, Iadanza E. Evidence-based clinical engineering: health information technology adverse events identification and classification with natural language processing. Heliyon. 2023;9(11):e21723. doi:10.1016/j.heliyon.2023.e21723. Accessed September 15, 2026. https://pmc.ncbi.nlm.nih.gov/articles/PMC10638042/

6. Ren Y, Caiani EG. Leveraging natural language processing to aggregate field safety notices of medical devices across the EU. NPJ Digit Med. 2024;7:352. doi:10.1038/s41746-024-01337-9. Accessed September 15, 2026. https://pmc.ncbi.nlm.nih.gov/articles/PMC11618595/

7. Li T, Zhu W, Xia W, et al. Research on adverse event classification algorithm of da Vinci surgical robot based on Bert-BiLSTM model. Front Comput Neurosci. 2024;18:1476164. doi:10.3389/fncom.2024.1476164. Accessed September 15, 2026. https://pmc.ncbi.nlm.nih.gov/articles/PMC11682881/

8. International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use. ICH Q9(R1) Quality Risk Management. Step 5 version, January 2023. Accessed September 15, 2026. https://www.ich.org/page/quality-guidelines

9. US Food and Drug Administration. Postmarketing Safety Reporting for Combination Products. 21 CFR Part 4, Subpart B. Guidance for Industry and FDA Staff. July 2029. Accessed September 15, 2026. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/postmarketing-safety-reporting-combination-products

10. US Food and Drug Administration. Computer Software Assurance for Production and Quality Management System Software: Guidance for Industry and Food and Drug Administration Staff. February 2026. Accessed September 15, 2026. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/computer-software-assurance-production-and-quality-management-system-software

11. US Food and Drug Administration. Use of Real-World Evidence to Support Regulatory Decision-Making for Medical Devices: Guidance for Industry and Food and Drug Administration Staff. December 18, 2025. Accessed September 15, 2026. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/use-real-world-evidence-support-regulatory-decision-making-medical-devices