SlideShare a Scribd company logo
Risk Management and IEC 62304
Applying IEC 62304 Risk Management in Aligned Elements
February 2015
Elements
Medical Devices and Risk Management
 Workflows and functions drives
Risk Management
 Risk Management drives Design
 Design and Risk Management
are interdependent
 Traceability connects Design and
Risk Management
Workflows
&
Functions
Hazardous
Situation
Risk
Risk
Control
Design
Elements
Risk Management and Regulations
ISO 13485
QMS
ISO 14971
Risk
Management
IEC 62304
Software
Lifecycle
IEC 60601-1
Security in
Electromedical
devices
IEC 62366
Usability
Refers to
Refers to
Refers to
Elements
Risk Management and Regulations
ISO 13485
QMS
ISO 14971
Risk
Management
IEC 62304
Software
Lifecycle
Design &
Maintenance of
software in MD
IEC 60601-1
Security in
Electromedical
devices
IEC 62366
Usability
Affects
Affects
Affects
Elements
General Concepts of Risk Assessments
 Identify Hazards
 Evaluate Risks (likelihood &
consequences)
 Perform Risk Reduction
 Evaluate residual Risks
Elements
Risk Management in IEC 62304
 Risk drives the level of
documentation required
 Software Safety Classification of
architectural artifacts
 Risk inheritance in architecture
 Systematic risks => 100% probability
of occurrence
 Affects not only development, also
affects maintenance
Software System
Class C
Software Item
Class C
Software Unit
Class C
Software Unit
Class B
Software Item
Class A
Software Item
Class A
Elements
Documenting Medical Device Development
 Increasing number of regulations
 Development documentation is difficult,
complex and resource intensive to manage
 Aligned Elements helps you “build” a
consistent and complete documentation
 Free up valuable resources from
cumbersome administrative tasks
Elements
Aligned Elements – a medical device ALM
 Manages the DHF Design Control Items
 Version Control + Traceability + Documents
 Integrated Risk Management
 Real-time quality checks on content
 Ensures completeness and consistency
Elements
FMEA
 Concerns Safety & “Business”
 Widely adopted technique
 Versatile usage
 Probability x Severity x
Visibility
Preliminary Hazard Analysis
 Concerns Safety / Harm only
 In the early design phase
 Full device implementation is
not required
 Aligned with ISO 14971
Risk Assessments in Aligned Elements
Elements
Preliminary Hazard Analysis (PHA) Overview
Cause
(with probability)
Harm
(with severity)
Hazardous
Situation
Risk Control
Measure
Hazard
Elements
Risk Analysis Element
PHA in Aligned Elements
Cause
Harm
(with severity)
Hazardous
Situation
Risk Control
Measure
Reusable Elements
Probability of
Harm
Potential
Hazard
Elements
PHA in Aligned Elements
Elements
Aligned Elements PHA in Word
Elements
Risk Analysis
PHA and Traceability
Cause 1
Measure 1
Cause 2
Cause 3
Measure 2
Measure 3
SW Use Case
HW Function
SW Item
SW
Requirement
Instructions
For Use
HW
Specification
Potential
Hazards
Elements
Aligned Elements as Risk Management Tool
 Automatic calculation of RPN
 Automatic checks of RPN against
thresholds
 Reuse of Harms, Causes and Measures
 Measures grouped and sorted according
to Risk Reduction Type
 Highlighting of insufficiently controlled
risks
 Highlighting of unimplemented Measures
 Risk elements integrated with Design
trace landscape
Elements
Risk Management in IEC 62304
Cause
Hazardous
Situation
Risk Reduction
Measure
Hazard Software Item
Software
Requirement
Verification
IEC 62304 – 7.3.3 Document Traceability
Elements
Risk Analysis
IEC 62304 PHA in Aligned Elements
Cause
Measure
Software Item
(with classification)
SW
Requirement
Verification
Harm
Does classification
match Harms in the
Risk Analysis?
Hazardous
Situation
Are Risk Control
Measures implemented
and verified?
Elements
Software Safety Classification (SSC) in Aligned
Automatic Rule Checks:
 Is SSC consistent with severity of
(implicitly) linked Harms?
 Is SSC consistent with classification
of dependent Software Items?
Specify Rules:
 SSC inheritance of Software Items
 Software Item must trace to Cause
 Connect Severity of Harm with SSC
Severity of Harm Classification
5 or 4 C
3 or 2 B
1 A
Elements
Risk Analysis
SSC example in Aligned Elements
Cause
Software Item
(Class B)
SW Unit
(Class C)
Harm
Severity: 5
Not OK!
Not OK!
Severity of Harm Classification
5 or 4 C
3 or 2 B
1 A
Elements
IEC 62304 and Probability in Risk Management
 Software error probability is difficult
to estimate
 Software errors are systematic
 IEC 62304 claims that Software
Safety Classification shall not
depend on probability, only on harm
 Assume Probability of software
error = 100% (section 4.3. a)
 Can we reduce the probability with
our Risk Control Measures?
Elements
Use two probabilities:
 Probability of Hazardous Situation (P1)
 Probability of Harm (P2)
Usage:
 P2 can be estimated by professional (e.g.
a Medical Doctor)
 Adapt risk policy and thresholds
 Risk Control Measures affect P1 and P2
Using two probabilities
Software
Error
Hazardous
Situation
Harm
P1
P2
Elements
Two probabilities in Aligned Elements
Elements
Two probabilities in Aligned Elements
Elements
Architecture vs. Functional Usage
 Architecture: Hierarchical
decomposition of Software
into Items and Units
 Software risk emanates from
how we use the software
i.e. in which functional
context we use the software
items
 Functional use cuts across
the architecture
Use Case
1
(high risk)
Use Case
2
(mid risk)
Use Case
3
(low risk)
SW Item 1
SW Item
2
SW Item 4
SW Item
3
SW Unit
1
SW Unit
2
SW Unit
3
Elements
The Matrix Model in IEC 62304
Elements
Matrix Model in Aligned Elements
 Write Use Cases from SW Reqs
 Perform Risk Analysis on Use Cases
 Generate Causes from Use Cases
where applicable
 Create Architecture
 Map Use Cases to Software Items by
connecting Software Items to existing
Causes
 If applicable, generate new Causes
from Software Items and map back to
User CasesRisk Analysis
Causes
Software
Requirements
Harm
Hazardous
Situation
Software
Items
Elements
Software Problem Resolution Process
 Record Problem Report
 Identify Causes and perform risk
analysis
 Evaluate Risk
 Create Change Request (if
applicable)
 Verify Change
Risk AnalysisCause
Measure
Problem
Report
Change
Request
Verification
Harm Hazardous
Situation
Elements
Aligned Elements IEC 62304 Package
 Full template set for all IEC 62304 Artifacts
 Includes clear references to applicable sections in IEC 62304
 Full usage of Aligned Elements automatic consistency checks
 Integrated Checklists and Review Generators
 Preconfigured Word reports
 Preconfigured Trace Tables
 Preconfigured Queries
Elements
Maximal results, minimal effort
Thank You!Aligned AG
Binzmühlstrasse 210
CH-8050 Zürich
Switzerland
t +41 (0)44 312 50 20
f +41 (0)44 312 50 20
m info@aligned.ch
w www.aligned.ch

More Related Content

PDF
IEC 62304 Action List
PDF
IEC 62304: SDLC Conformance and Management
PDF
Understanding IEC 62304
PDF
Medical Device Software
PDF
Risk Management for Medical Devices - ISO 14971 Overview
PPTX
Iso 14971 2019
PPTX
ISO 62304 & TIR 45
PDF
Compliance with medical standards iec 62304, iso 14971, iec 60601, fda title ...
IEC 62304 Action List
IEC 62304: SDLC Conformance and Management
Understanding IEC 62304
Medical Device Software
Risk Management for Medical Devices - ISO 14971 Overview
Iso 14971 2019
ISO 62304 & TIR 45
Compliance with medical standards iec 62304, iso 14971, iec 60601, fda title ...

What's hot (20)

PPTX
Bi-dimensional risk analysis - safety&security -software medical device
PPTX
ISO Standard 13485
PDF
Usability Testing Medical Devices
PPTX
An Overview for Software as a Medical Device (SaMD)
PDF
Fda quality system regulation 21 CFR820_Medical devices_k_trautman
PPTX
Ce marking and methods to apply presentation
PPTX
Medical device design guidlines
PPTX
US FDA Medical Device or Equipment
PDF
Classification of In Vitro Diagnostic Devices per FDA and IVDR Rules
PPTX
ISO 13485:2016 QMS
PPTX
Iso 13485:2016
PPTX
EU MDR
PDF
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
PPTX
ISO: 14971 Quality risk management of medical devices
PDF
FDA Design Controls: What Medical Device Makers Need to Know
PPTX
Medical Devices Regulation (MDR) 2017/745 - Classification of devices
PDF
15 Steps to get Approval to IEC 60601-1
PPTX
Quality Control for Medical Device Software - It Arena Lviv Presentation
PPTX
Software as a Medical Device (SaMD).pptx
PPTX
ISO 13485: Quality Management System for Medical Device
Bi-dimensional risk analysis - safety&security -software medical device
ISO Standard 13485
Usability Testing Medical Devices
An Overview for Software as a Medical Device (SaMD)
Fda quality system regulation 21 CFR820_Medical devices_k_trautman
Ce marking and methods to apply presentation
Medical device design guidlines
US FDA Medical Device or Equipment
Classification of In Vitro Diagnostic Devices per FDA and IVDR Rules
ISO 13485:2016 QMS
Iso 13485:2016
EU MDR
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
ISO: 14971 Quality risk management of medical devices
FDA Design Controls: What Medical Device Makers Need to Know
Medical Devices Regulation (MDR) 2017/745 - Classification of devices
15 Steps to get Approval to IEC 60601-1
Quality Control for Medical Device Software - It Arena Lviv Presentation
Software as a Medical Device (SaMD).pptx
ISO 13485: Quality Management System for Medical Device
Ad

Viewers also liked (20)

PDF
QAdvis - software risk management based on IEC/ISO 62304
PDF
Death by documentation - Medical Device Development Challenges
PDF
ISO 14971 Risk Management - how others do it
PPTX
Create Your Company Page
PDF
Build Features, Not Apps
PDF
Risk management in-60601-1
PDF
Abbott overview medical device human factors standards
PPTX
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
PDF
Product Safety Testing Reduces the Risk of Shock, Fire, Explosions
PDF
Human factor standards and usability (by Ed Israelski)
PDF
Death to project documentation with eXtreme Programming
PDF
TÜV SÜD on functional safety for multi-core architectures
PDF
ZMPCZM016000.13.03 Certificate of compliance
PDF
Building your credibility with LinkedIn
PDF
Home Healthcare, IEC 60601-1-11
PPTX
What Is SEO? A Guide to Search Engine Optimization
PPTX
IMAGE SEGMENTATION.
PPT
Image segmentation ppt
PDF
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
PPTX
The 7 Biggest Trends in SEO: 2016
QAdvis - software risk management based on IEC/ISO 62304
Death by documentation - Medical Device Development Challenges
ISO 14971 Risk Management - how others do it
Create Your Company Page
Build Features, Not Apps
Risk management in-60601-1
Abbott overview medical device human factors standards
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
Product Safety Testing Reduces the Risk of Shock, Fire, Explosions
Human factor standards and usability (by Ed Israelski)
Death to project documentation with eXtreme Programming
TÜV SÜD on functional safety for multi-core architectures
ZMPCZM016000.13.03 Certificate of compliance
Building your credibility with LinkedIn
Home Healthcare, IEC 60601-1-11
What Is SEO? A Guide to Search Engine Optimization
IMAGE SEGMENTATION.
Image segmentation ppt
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
The 7 Biggest Trends in SEO: 2016
Ad

Similar to Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM (20)

PPTX
SENG Module 6sdfsdfdfsdfsdfsdf Slides.pptx
PPT
Pragmatic Device Risk Management
PPTX
Critical Steps in Software Development: Enhance Your Chances for a Successful...
PPT
Concepts in Software Safety
PPT
Practical Application Of System Safety For Performance Improvement
PPTX
Safety and security in distributed systems
PPTX
Safety and security in distributed systems
PDF
Risk Analysis
PDF
2016-05-30 risk driven design
DOC
Critical systems specification
PPT
Mats Grindal - Risk-Based Testing - Details of Our Success
PPTX
Modeling application risk at scale @ netflix
PDF
Kostogryzov 10.12.2009
PPTX
Spm unit iii-risk-intro
PPT
PPTX
Rethinking Risk-Based Project Management in the Emerging IT initiatives.pptx
PPT
Kost for china-2011
PPTX
Increasing the Impact of Risk Assessment
PPT
Risk management in development of life critical systems
PPTX
Оксана Вей “To risk or not to risk?”
SENG Module 6sdfsdfdfsdfsdfsdf Slides.pptx
Pragmatic Device Risk Management
Critical Steps in Software Development: Enhance Your Chances for a Successful...
Concepts in Software Safety
Practical Application Of System Safety For Performance Improvement
Safety and security in distributed systems
Safety and security in distributed systems
Risk Analysis
2016-05-30 risk driven design
Critical systems specification
Mats Grindal - Risk-Based Testing - Details of Our Success
Modeling application risk at scale @ netflix
Kostogryzov 10.12.2009
Spm unit iii-risk-intro
Rethinking Risk-Based Project Management in the Emerging IT initiatives.pptx
Kost for china-2011
Increasing the Impact of Risk Assessment
Risk management in development of life critical systems
Оксана Вей “To risk or not to risk?”

Recently uploaded (20)

PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Encapsulation theory and applications.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
Cloud computing and distributed systems.
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Empathic Computing: Creating Shared Understanding
PDF
KodekX | Application Modernization Development
PDF
Approach and Philosophy of On baking technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
A Presentation on Artificial Intelligence
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
Encapsulation_ Review paper, used for researhc scholars
Encapsulation theory and applications.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Cloud computing and distributed systems.
Mobile App Security Testing_ A Comprehensive Guide.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Empathic Computing: Creating Shared Understanding
KodekX | Application Modernization Development
Approach and Philosophy of On baking technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
NewMind AI Monthly Chronicles - July 2025
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
The Rise and Fall of 3GPP – Time for a Sabbatical?
A Presentation on Artificial Intelligence
MYSQL Presentation for SQL database connectivity
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Per capita expenditure prediction using model stacking based on satellite ima...

Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM

  • 1. Risk Management and IEC 62304 Applying IEC 62304 Risk Management in Aligned Elements February 2015
  • 2. Elements Medical Devices and Risk Management  Workflows and functions drives Risk Management  Risk Management drives Design  Design and Risk Management are interdependent  Traceability connects Design and Risk Management Workflows & Functions Hazardous Situation Risk Risk Control Design
  • 3. Elements Risk Management and Regulations ISO 13485 QMS ISO 14971 Risk Management IEC 62304 Software Lifecycle IEC 60601-1 Security in Electromedical devices IEC 62366 Usability Refers to Refers to Refers to
  • 4. Elements Risk Management and Regulations ISO 13485 QMS ISO 14971 Risk Management IEC 62304 Software Lifecycle Design & Maintenance of software in MD IEC 60601-1 Security in Electromedical devices IEC 62366 Usability Affects Affects Affects
  • 5. Elements General Concepts of Risk Assessments  Identify Hazards  Evaluate Risks (likelihood & consequences)  Perform Risk Reduction  Evaluate residual Risks
  • 6. Elements Risk Management in IEC 62304  Risk drives the level of documentation required  Software Safety Classification of architectural artifacts  Risk inheritance in architecture  Systematic risks => 100% probability of occurrence  Affects not only development, also affects maintenance Software System Class C Software Item Class C Software Unit Class C Software Unit Class B Software Item Class A Software Item Class A
  • 7. Elements Documenting Medical Device Development  Increasing number of regulations  Development documentation is difficult, complex and resource intensive to manage  Aligned Elements helps you “build” a consistent and complete documentation  Free up valuable resources from cumbersome administrative tasks
  • 8. Elements Aligned Elements – a medical device ALM  Manages the DHF Design Control Items  Version Control + Traceability + Documents  Integrated Risk Management  Real-time quality checks on content  Ensures completeness and consistency
  • 9. Elements FMEA  Concerns Safety & “Business”  Widely adopted technique  Versatile usage  Probability x Severity x Visibility Preliminary Hazard Analysis  Concerns Safety / Harm only  In the early design phase  Full device implementation is not required  Aligned with ISO 14971 Risk Assessments in Aligned Elements
  • 10. Elements Preliminary Hazard Analysis (PHA) Overview Cause (with probability) Harm (with severity) Hazardous Situation Risk Control Measure Hazard
  • 11. Elements Risk Analysis Element PHA in Aligned Elements Cause Harm (with severity) Hazardous Situation Risk Control Measure Reusable Elements Probability of Harm Potential Hazard
  • 14. Elements Risk Analysis PHA and Traceability Cause 1 Measure 1 Cause 2 Cause 3 Measure 2 Measure 3 SW Use Case HW Function SW Item SW Requirement Instructions For Use HW Specification Potential Hazards
  • 15. Elements Aligned Elements as Risk Management Tool  Automatic calculation of RPN  Automatic checks of RPN against thresholds  Reuse of Harms, Causes and Measures  Measures grouped and sorted according to Risk Reduction Type  Highlighting of insufficiently controlled risks  Highlighting of unimplemented Measures  Risk elements integrated with Design trace landscape
  • 16. Elements Risk Management in IEC 62304 Cause Hazardous Situation Risk Reduction Measure Hazard Software Item Software Requirement Verification IEC 62304 – 7.3.3 Document Traceability
  • 17. Elements Risk Analysis IEC 62304 PHA in Aligned Elements Cause Measure Software Item (with classification) SW Requirement Verification Harm Does classification match Harms in the Risk Analysis? Hazardous Situation Are Risk Control Measures implemented and verified?
  • 18. Elements Software Safety Classification (SSC) in Aligned Automatic Rule Checks:  Is SSC consistent with severity of (implicitly) linked Harms?  Is SSC consistent with classification of dependent Software Items? Specify Rules:  SSC inheritance of Software Items  Software Item must trace to Cause  Connect Severity of Harm with SSC Severity of Harm Classification 5 or 4 C 3 or 2 B 1 A
  • 19. Elements Risk Analysis SSC example in Aligned Elements Cause Software Item (Class B) SW Unit (Class C) Harm Severity: 5 Not OK! Not OK! Severity of Harm Classification 5 or 4 C 3 or 2 B 1 A
  • 20. Elements IEC 62304 and Probability in Risk Management  Software error probability is difficult to estimate  Software errors are systematic  IEC 62304 claims that Software Safety Classification shall not depend on probability, only on harm  Assume Probability of software error = 100% (section 4.3. a)  Can we reduce the probability with our Risk Control Measures?
  • 21. Elements Use two probabilities:  Probability of Hazardous Situation (P1)  Probability of Harm (P2) Usage:  P2 can be estimated by professional (e.g. a Medical Doctor)  Adapt risk policy and thresholds  Risk Control Measures affect P1 and P2 Using two probabilities Software Error Hazardous Situation Harm P1 P2
  • 22. Elements Two probabilities in Aligned Elements
  • 23. Elements Two probabilities in Aligned Elements
  • 24. Elements Architecture vs. Functional Usage  Architecture: Hierarchical decomposition of Software into Items and Units  Software risk emanates from how we use the software i.e. in which functional context we use the software items  Functional use cuts across the architecture Use Case 1 (high risk) Use Case 2 (mid risk) Use Case 3 (low risk) SW Item 1 SW Item 2 SW Item 4 SW Item 3 SW Unit 1 SW Unit 2 SW Unit 3
  • 26. Elements Matrix Model in Aligned Elements  Write Use Cases from SW Reqs  Perform Risk Analysis on Use Cases  Generate Causes from Use Cases where applicable  Create Architecture  Map Use Cases to Software Items by connecting Software Items to existing Causes  If applicable, generate new Causes from Software Items and map back to User CasesRisk Analysis Causes Software Requirements Harm Hazardous Situation Software Items
  • 27. Elements Software Problem Resolution Process  Record Problem Report  Identify Causes and perform risk analysis  Evaluate Risk  Create Change Request (if applicable)  Verify Change Risk AnalysisCause Measure Problem Report Change Request Verification Harm Hazardous Situation
  • 28. Elements Aligned Elements IEC 62304 Package  Full template set for all IEC 62304 Artifacts  Includes clear references to applicable sections in IEC 62304  Full usage of Aligned Elements automatic consistency checks  Integrated Checklists and Review Generators  Preconfigured Word reports  Preconfigured Trace Tables  Preconfigured Queries
  • 30. Thank You!Aligned AG Binzmühlstrasse 210 CH-8050 Zürich Switzerland t +41 (0)44 312 50 20 f +41 (0)44 312 50 20 m info@aligned.ch w www.aligned.ch