Announcing AI-Native Market Access Product for Regulated Products

Learn More

Blogs

MedTech

ISO 14971: risk management for medical device manufacturers

By

Wendy Levine

May 31, 2022

4 min read

What is ISO 14971?

ISO 14971 is the globally accepted international risk management standard for medical devices. This article discusses the most current version of this standard, ISO 14971:2019, currently considered the state-of-the-art standard. 

ISO 14971:2019, provides the processes for identifying, evaluating, and mitigating hazards associated with the use of medical devices. While not mandatory, it is the most commonly used, industry-recognized standard to demonstrate conformity to when addressing product safety requirements. This article provides an overview of the standard, but should not be used as a substitute for the actual text of the standard. 

As in the case of a quality management system, a risk management system addresses the full lifecycle of a medical device; including the design, manufacture, and use of the device. Also, while ISO 14971:2019 does not, itself, require the implementation of a quality management system, risk management is most often an important part of a strong quality management system.

Compliance with ISO 14971:2019 requires that a risk management system be established and maintained throughout the product lifecycle, and that all processes and results are stored in a risk management file. The risk management system will include processes for risk analysis, evaluation, and control. It is important to note that the standard does not define acceptable levels of risk for medical devices - this is left to the manufacturer to determine as part of their risk management processes. However, the guidance document, ISO TR 24971:2020, provides significant clarity and direction in interpreting the standard and developing a risk management system consistent with ISO 14971:2019.

EN ISO 14971:2019: EU harmonized standard 

In the European Union, as of May 11, 2022, the specific version of the standard which has been  officially recognized as a harmonized standard with current Medical Devices Regulation (MDR) ((EU) 2017/745 ) and In vitro Diagnostic Medical Devices Regulation (IVDR) ((EU) 2017/746), is EN ISO 14971:2019 and the amendment EN ISO 14971:2019+A11:2021. The amended  version includes two Annexes, Annex ZA and ZB, which demonstrate the relationship between the standard and the risk management process required in the MDR and IVDR. The technical content of the two versions are identical and does not included any content deviations, unlike EN ISO 14971:2012, the version of the standard which is harmonized with the previous EU MDD and IVDD regulations.

Risk analysis

Under ISO 14971:2019 a manufacturer is required to document risk analysis activities and the results of those activities in a risk management file. These should include:

  • Intended use and “reasonably foreseeable” misuse, along with all device characteristics which impact the safety of the device.
  • Hazards (a potential source of harm*), both known and foreseeable.
  • Estimation of risk for each hazard, based on the probability of occurrence of the hazard and possible consequences.

*Note:  ISO 14971:2019 revises the definition of harm by excluding the word “physical” injury from the ISO 14971:2007 definition. The resulting ISO 14971:2019 definition of harm is “Injury or damage to the health of people, or damage to property or the environment” 

Risk evaluation 

Risk evaluation involves the determination of whether a risk reduction is required for a particular hazard. Manufacturers should weigh the combination of the probability that a hazard occurs with the severity level of the hazard. A risk evaluation matrix, such as the following example, is often used to to visualize risk acceptability.

It is important to note that ISO 14971:2019 and TR 24971:2020 added significant emphasis and clarity regarding the evaluation of risk and establishment of risk acceptability criteria. Under the previous versions of the standard (both ISO 14971:2007 and EN ISO 14971:2012), there was confusion and a lack of guidance around defining acceptable risk. It was common to use a two-dimensional matrix showing severity of harm along one axis and probability of harm along the other, but with little guidance there were multiple interpretations of how to establish these criteria and these matrices were often used to define policy. The latest version of the standard and guidance, however, emphasize that the matrix should be the output of the risk management policy, which would define the criteria for risk evaluation.

Risk control 

When a hazard is found to have an unacceptable risk level, risk control activities are put in place to mitigate the risk. ISO 14971:2019 requires that “state-of-the-art” best practices that are used for similar devices be employed. State-of-the-art does not necessarily mean the most advanced processes and technical features, but rather those that are generally accepted in the industry. Risk control options should include, in order of importance:

  • Inherent safety by design and manufacture
  • Protective measures built into the device or into the manufacturing process
  • Provided safety information, and where appropriate, training to users

Risk/benefit analysis should be performed and where benefit is determined to outweigh risk, the manufacturer will need to decide what safety information is necessary to disclose.

Relevant standards should be applied as part of the risk control process whenever applicable. Some of the standards which reference ISO 14971:2019 include ISO 13485 (quality management systems), IEC 60601-1 (electrical safety), IEC/EN 62366 (usability of medical devices), and IEC 62304 (medical device software). This makes ISO 14971:2019 essential for manufacturers seeking market approval for a medical device in the U.S., European Union, Japan, Australia and many other major markets.

Production and post-production information

A substantial change in ISO 14971:2019 standard is the expansion of requirements for production and post-production activities. The manufacturer will need to perform a full review of the risk management process prior to commercial distribution. The review should ensure that the risk management plan has been appropriately implemented, the overall risk is acceptable, and that procedures are in place to gather and maintain risk data during production and post-production of the medical device. ISO 14971:2019 aligns closely with the ISO 13485:2016 section 8 requirements for feedback, analysis of data and CAPA. Information collected and reported should include any newly identified hazards, changes that affect risk analysis calculations, and results of regular reviews of the risk management file. 

Management responsibilities

Medical device manufacturers who wish to demonstrate compliance with ISO 14971:2019 must have a management team that is dedicated to and supportive of the risk management system. This includes ensuring that adequate resources are assigned to support the system and that the personnel assigned are qualified for their respective responsibilities. In addition to enabling the implementation and maintenance of the risk management system, management is responsible for reviewing the system periodically to ensure continued effectiveness.

For more information about technical documentation/compliance for medical devices, check out our comprehensive ebook, The ultimate guide to EU MDR and IVDR general safety and performance requirements (GSPR).

‍

Similar posts

AI

From Regulatory Knowledge to Better Market Decisions: A Conversation with Steve Gens and James Gianoutsos

October 1, 2026

4 min read

‍

AI is moving quickly from experimentation to implementation across life sciences. For regulatory teams, that raises a bigger question than where AI can automate a task:

How can organizations use AI to make better decisions while maintaining the traceability, expert oversight, and confidence regulatory work demands?

That was a central theme when James Gianoutsos, Founder and CEO of Rimsys, joined Steve Gens, Founder and Managing Partner of Gens & Associates, on the Regulatory Executive Podcast.

Their conversation explored the changing role of regulatory intelligence, the introduction of Rimsys Market Access, the importance of transparency in regulatory AI, and what these changes could mean for regulatory teams.

Regulatory knowledge has been difficult and costly to scale

For global medtech organizations, regulatory knowledge has traditionally been highly dependent on people.

A company may have specialists responsible for particular countries or regions, along with local representatives, distributors, consultants, and other experts. Those people develop deep knowledge of local regulations, pathways, and expectations.

The problem is that the knowledge often remains distributed across the organization. And maintaining that market-by-market expertise can become expensive as a company expands its portfolio and geographic footprint.

As James described during the podcast, large manufacturers may rely on dozens or even hundreds of internal employees, third-party distributors, local representatives, and other specialists to understand what it takes to bring products into different markets. Smaller organizations may rely more heavily on outside consultants and partners. Either way, the model can be costly and difficult to scale. 

But the cost isn't limited to what companies spend on expertise.

Steve described the workflow as a series of “start, stop” cycles: ask a local expert, verify whether the regulation is current, gather more information, and repeat. Each cycle consumes regulatory capacity and extends the time it takes to give the business a confident answer.

That creates another potentially more consequential expense: the cost of waiting.

When it takes months to understand what entering a market will require, commercial and product teams have less visibility into when revenue might begin, what resources will be needed, or whether the opportunity is worth pursuing. Regulatory teams spend valuable capacity assembling and validating information rather than applying their expertise to more strategic work.

Ultimately, scaling regulatory knowledge isn't simply an efficiency problem. It affects how quickly and confidently the business can decide where to invest.

The bigger question: Should we enter this market?

That challenge is central to Rimsys Market Access.

Most market-entry research begins with questions such as: How is the product classified? What's the regulatory pathway? What are the requirements?

Those questions establish whether a company can enter a market. But they don't necessarily tell the business whether it should.

Market Access is designed to help regulatory and commercial teams develop an earlier view of what market entry could involve, including classification, regulatory pathway, timeline, cost considerations, requirements and potential gaps. 

For commercial and product leaders, that provides greater predictability before committing budget and resources.

For regulatory leaders, it means starting with a structured plan rather than assembling every market assessment from scratch.

Moving regulatory knowledge from individuals into a shared system

During the conversation, James described one of AI's most significant opportunities as moving knowledge that has historically lived in people's heads into software.

The goal isn't to eliminate regulatory expertise. It's to make that expertise more scalable.

Market Access works from a curated regulatory corpus, allowing market-specific knowledge to be applied across workflows without requiring every initial question to go through the individual who happens to know that jurisdiction. Outputs are designed to trace back to the underlying regulation, guidance, or law. 

That can also change where regulatory professionals spend their time. Rather than focusing as heavily on finding information and assembling initial assessments, they can focus on reviewing the evidence, identifying gaps, applying judgment, and advising the business.

Steve described the concept as a subject-matter-expert assistant. James called it a workforce multiplier. 

Trust requires opening the regulatory AI “black box”

Speed isn't enough when the information is being used to inform regulatory decisions.

James and Steve returned repeatedly to the importance of knowing where an AI-generated answer comes from. As Steve summarized it during the discussion, transparency builds trust.

Market Access is designed around that principle. Its outputs are grounded in a curated regulatory corpus and traceable to the specific regulations, guidance, or laws supporting them. That gives regulatory professionals the ability to verify an answer rather than simply accept it. 

Human judgment remains essential as well. Market Access provides an upfront assessment, not a guarantee of a regulatory outcome. Reviewer interpretation and other factors can still affect what happens during the regulatory process.

The objective isn't to make uncertainty disappear. It's to make what is known, what the sources say, and where uncertainty remains much easier to see.

Connecting the market decision to execution

The discussion also pointed to a broader evolution in regulatory technology: moving from systems that primarily store regulatory information toward systems that help teams act on it.

That's where Market Access and Rimsys RIM play distinct but complementary roles.

Market Access is the planning layer. It helps teams determine whether, when, and how to enter a market.

Rimsys RIM is the execution layer. It manages the registrations, submissions, regulatory changes, and ongoing regulatory work required to act on that plan. 

Together, they create a path from the initial market decision through regulatory execution rather than leaving planning and execution disconnected.

A new role for AI in regulatory work

One of the most interesting themes from Steve and James's conversation was that AI's impact may ultimately be less about replacing individual tasks and more about expanding what regulatory teams can accomplish.

Better access to market-specific knowledge can help professionals work across more markets, spend less time gathering information, and devote more capacity to the judgment and strategic work that requires their expertise.

The technology is changing quickly, but the fundamentals of regulatory work remain: reliable information, domain expertise, transparency, and human judgment.

The opportunity is to apply those fundamentals at greater scale while giving the business a clearer answer to the question that comes before execution:

Not simply, “Can we enter this market?”

But, “Should we?”

Listen to the full conversation

Hear the complete discussion between Steve Gens, Founder and Managing Partner of Gens & Associates, and James Gianoutsos, Founder and CEO of Rimsys, on the Regulatory Executive Podcast for more on regulatory AI, market-entry planning, transparency, and the changing role of regulatory teams.

‍

AI

How Market Access Builds Trust in Regulatory Intelligence

By

Bethaney Lentz

September 18, 2026

4 min read

Why source traceability, regulatory specificity, and human judgment matter when AI informs a market-entry decision.

Regulatory professionals are not short on AI options. General-purpose tools can answer questions quickly and often sound convincing. But in medtech, a convincing answer is not the same thing as a decision you can defend.

That distinction matters most before a company commits to a new market. Teams need to understand how a product is classified, which pathway applies, how long entry may take, what it may cost, where the important gaps are, and what uncertainty still remains. Commercial leaders need that visibility to decide whether the opportunity is worth pursuing. Regulatory leaders need to know that the assessment is grounded in sources they can verify.

That is the trust standard behind Rimsys Market Access. It is not simply about producing regulatory information faster. It is about helping medtech teams decide whether, when, and how to enter a market before committing budget and resources, with outputs linked back to the regulations, guidance, and laws behind them.

Why fluency is not enough for regulatory work

A general AI tool can be useful for brainstorming, summarizing, and exploring a topic. The challenge comes when an answer has real regulatory consequences. A plausible response may still be incomplete, based on the wrong designation, or disconnected from the current source that should govern the decision.

Medtech makes this especially difficult because the same product can be treated differently across markets and product designations. Medical device, IVD, cosmetic, consumer, OTC, and combination-product considerations can change the regulatory read. A market-entry assessment has to account for that context rather than assume one answer travels cleanly from one jurisdiction to another.

For regulatory teams, the natural next question is: Where did this answer come from? If the system cannot show the underlying authority, the expert still has to rebuild the research before trusting the result. That limits the value of the speed AI was supposed to create in the first place.

Trust starts with a decision you can verify

Market Access is designed around a different outcome. The goal is not to give teams another stream of regulatory information to interpret. It is to provide a source-linked market plan that helps them answer the bigger business question: should we enter this market, not just can we?

For a market assessment, that can include classification, regulatory pathway, timeline, cost considerations, key requirements and potential gaps. The output is designed to give commercial and product leaders an earlier, more defensible view of the opportunity while giving regulatory professionals the detail they need to review the basis for the assessment.

Trust comes from being able to inspect that basis. Market Access works from a curated regulatory corpus spanning more than 200 markets rather than relying on the open web. Answers are linked to the specific regulation, guidance, or law behind them, so a regulatory professional can verify the source instead of being asked to accept an AI-generated conclusion on faith.

Three things make regulatory intelligence more defensible

1. Source traceability

A regulatory answer is more useful when the person reviewing it can follow the evidence. Market Access links outputs back to their underlying regulatory sources. That changes the review process from “Do I trust the AI?” to a more practical question: “Does the cited source support this conclusion for our product and situation?”

That is an important shift for regulatory teams. Instead of assembling every market assessment from a blank page, they can review a structured, sourced plan, challenge assumptions, and focus their expertise on the places where judgment matters most.

2. Regulatory specificity

Trust also depends on context. Market Access is purpose-built for medtech regulatory complexity and supports cross-designation classification. The objective is to evaluate the product in the context of the market and the applicable regulatory framework, then carry that context into the pathway, requirements, timeline, cost considerations, and gaps that shape the market-entry decision.

This is where a purpose-built market-planning platform differs from a generic chat experience. The value is not an impressive answer in isolation. It is a connected assessment that helps the team understand what entering the market is likely to require and whether the opportunity still makes sense once those requirements are visible.

3. Human judgment stays in control

No system can remove every area of uncertainty from regulatory work. Reviewer interpretation and expert judgment still affect outcomes, and Market Access is not designed to promise approval.

Instead, Market Access is designed to make uncertainty more manageable. Regulatory professionals review and validate the work before it moves into execution. They can verify sources, assess the gaps, and apply company and product context that software cannot fully replace. The technology accelerates the research and planning. The regulatory professional remains responsible for the judgment.

What trust looks like in a market-entry decision

Imagine a team evaluating several markets for a new product. The commercial question is not simply whether registration is technically possible. The team needs to know which markets deserve investment now, which may require more evidence or resources, and which could put the revenue window at risk because the pathway is longer or more complex than expected.

Regulatory has a different, but connected, need. They have to understand the classification and pathway, identify the requirements most likely to slow the submission, and confirm that the plan reflects the relevant regulatory sources.

Market Access brings those views together. Commercial and product leaders get earlier visibility into timing, cost considerations, requirements, and risk so they can build a stronger business case. Regulatory teams get a source-linked plan they can review rather than a collection of unsupported conclusions. Both groups are working from the same market-entry picture before significant resources are committed.

Trust is not the end goal. Better decisions are.

It is easy for a conversation about regulatory AI to become a conversation about models, agents, or architecture. Those details matter, but they are not the business outcome.

The real value of trustworthy regulatory intelligence is what it lets a team do next. It can help a commercial leader defend a market investment. It can help regulatory surface issues earlier. It can give both groups a more predictable view of the work ahead before budget, R&D capacity, or launch timing is locked in.

And once the decision is made, the work does not have to stop at an intelligence report. Market Access is the market-planning layer. Rimsys RIM is the execution layer for registrations, submissions, regulatory changes, and ongoing regulatory work. Each can stand on its own, and together they create a path from the market-entry decision into controlled execution.

A more useful standard for regulatory AI

The question for medtech teams should not be whether AI can produce a regulatory answer. It can. The better question is whether that answer is specific enough, traceable enough, and reviewable enough to support a real decision.

Market Access is built around that standard: a defensible view of whether, when, and how to enter a market, grounded in curated regulatory sources and kept under human review. Because when the decision affects revenue, resources, and regulatory strategy, sounding right is not enough. Teams need to see why the answer is right, where uncertainty remains, and what it means for the decision in front of them.

Company

Product Updates

Rimsys Announces AI-Native Market Access for Regulated Products

By

Bethaney Lentz

September 1, 2026

4 min read

New software gives regulatory and commercial leaders a source-linked, actionable view of market viability, requirements, timing, and risk before committing resources

PITTSBURGH, PA, September 1, 2026 - Rimsys, the heart of medtech regulatory operations, today announced Market Access, a new AI-native product designed to help companies determine whether a market is worth entering and what it will take to get there. Market Access will be available in beta beginning September 1, 2026, with general availability to be announced separately.

Market Access replaces what can be a 6-to-9-month research and assessment process with a same-day, actionable read on market viability. It gives regulatory and commercial leaders the classification, pathway, timeline, cost considerations, and potential regulatory gaps they need to make a more defensible investment decision before committing budget and resources.

Predictability is at the core of Market Access. Rather than simply identifying a regulatory pathway, it helps teams understand what to expect, which requirements or gaps are most likely to slow down a submission, and where uncertainty remains. Every answer traces back to the specific regulation, guidance, or law behind it, allowing regulatory professionals to verify the underlying source rather than simply trust an AI-generated response.

Key features and benefits include:

  • Same-day market assessment: Provides an actionable read on whether a market is worth entering, replacing research and assessment that can take 6 to 9 months.
  • Cross-designation classification: Evaluates products across medical device, IVD, cosmetic, consumer, and OTC designations, so the same product receives the appropriate regulatory read regardless of how a given market classifies it.
  • Clear market-entry requirements: Provides classification, regulatory pathway, timeline, cost considerations, and key requirements before teams commit resources.
  • Earlier visibility into regulatory gaps: Surfaces the specific requirements and gaps most likely to slow down a submission and helps teams understand their potential severity.
  • Greater predictability: Provides visibility into anticipated regulatory response windows, risks, and areas of uncertainty so teams can better plan for what lies ahead.
  • Source-linked intelligence: Traces answers to the underlying regulations, guidance, and laws so regulatory professionals can verify the basis for an assessment.
  • AI with human oversight: Uses Rimsys AI and Market Manager Agents to accelerate complex regulatory research while keeping regulatory professionals in control of review and validation.
  • Connected planning and execution: Complements RIM, connecting market-entry decisions with the registrations, submissions, regulatory changes, and ongoing compliance required to execute them.

“Regulatory knowledge has traditionally been highly dependent on individual expertise and market-by-market research,” said James Gianoutsos, Founder and CEO of Rimsys. “Market Access gives companies greater predictability before they make a market investment. Teams can understand whether an opportunity is worth pursuing, what it will take to enter, where regulatory challenges are likely to emerge, and what uncertainty remains. And because every answer is tied to its regulatory source, experts can verify the recommendation rather than simply trust the AI.”

Market Access is powered by Rimsys AI, which works from a curated regulatory corpus spanning more than 200 markets, not the open web. Its Market Manager Agents are AI agents with market-specific regulatory knowledge, including pathways, requirements, and documentation, that support market assessments and global launch planning. The product is also designed to acknowledge areas where reviewer interpretation and expert judgment can affect regulatory outcomes rather than presenting those outcomes as more predictable than they are.

Market Access expands the Rimsys product portfolio from regulatory execution into market planning. Market Access helps regulatory and commercial leaders determine where to compete, while RIM manages the registrations, submissions, regulatory changes, product data, and ongoing compliance required to enter and remain in those markets. Together, they turn regulatory intelligence into coordinated action, helping regulatory teams accomplish more in every hour while giving business leaders greater visibility into opportunities, risk, and the work required to protect and grow revenue.

Beta Availability

Market Access will be available in beta beginning September 1, 2026. During the beta period, Rimsys will continue validating product capabilities and refining workflows ahead of broader commercial availability. 

Organizations interested in learning more about Market Access or participating in the beta program can visit rimsys.io/products/market-access.

About Rimsys

Rimsys is the heart of regulatory operations, connecting AI-native market planning with AI-embedded regulatory execution, giving medtech manufacturers one living system from market-entry decision to execution. 

Rimsys Market Access is the planning layer, answering not just whether a market can be entered, but whether it should be, returning classification, pathway, timeline, and cost before a team commits budget or resources to finding out. Rimsys RIM is the execution layer, managing registrations, submissions, regulatory changes, and compliance so teams can act on that plan with confidence.

Trusted by 6 of the top 12 global MedTech manufacturers and certified to ISO 27001 and SOC 2, with ISO 42001 certification for AI management systems underway, Rimsys keeps regulatory intelligence, product data, approvals, and change management continuously connected so teams can enter new markets with speed and assurance. Learn more at rimsys.io.

Media Contact
letschat@rimsys.io

I agree to the privacy policy including to Rimsys using my contact details to contact me for marketing purposes.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Hand holding smartphone showing email app with 12 unread messages notification.