---
title: "ISO 14971 - Application of risk management to medical device"
description: "ISO · Foundational risk management standard. AAMI TIR57 extends it specifically for security risk management."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "name": "The Medical Device Cybersecurity Crosswalk",
      "alternateName": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "description": "Compare FDA, EU MDR, MHRA, PMDA, NMPA, TGA, MFDS and Health Canada medical device cybersecurity requirements across 29 jurisdictions."
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "name": "MDC Crosswalk",
      "url": "https://mdccrosswalk.com/",
      "logo": "https://mdccrosswalk.com/favicon.png",
      "sameAs": [
        "https://bluegoatcyber.com"
      ],
      "description": "An editorial reference comparing global medical-device cybersecurity regulations. Maintained by Blue Goat Cyber."
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "ISO 14971 - Application of risk management to medical devices",
      "description": "Foundational risk management standard. AAMI TIR57 extends it specifically for security risk management.",
      "author": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "publisher": {
        "@type": "Organization",
        "name": "MDC Crosswalk"
      },
      "image": "https://mdccrosswalk.lovable.app/favicon.png",
      "datePublished": "2026-05-28",
      "dateModified": "2026-05-28",
      "about": "ISO",
      "mainEntityOfPage": "https://mdccrosswalk.lovable.app/frameworks/iso-14971"
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://mdccrosswalk.lovable.app/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Frameworks"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "ISO 14971"
        }
      ]
    }
  ]
---

[

The Crosswalk



](/)

[Overview](/)[Playbook](/playbook)CompareReference

[New Per-page social previews and this changelog ](/changelog "Per-page social previews and this changelog") Search⌘K

1.  [Home ](/)
2.  Frameworks 
3.  ISO 14971 

ISO

# ISO 14971

[Source](https://www.iso.org/standard/72704.html)

Application of risk management to medical devices

Last updated · July 25, 2026 

Share Copy link X LinkedIn Email

## What it is

Foundational risk management standard. AAMI TIR57 extends it specifically for security risk management.

## Why it matters

Universally required. Cybersecurity risks must be integrated into the same ISO 14971 risk file the rest of your safety risks live in, separate files are a red flag in audits.

## Adopted or referenced by

FDA  EU MDR  PMDA  Health Canada  TGA  All MDSAP regulators 

## Key clauses

Risk-benefit

Security mitigations must not erode clinical benefit.

Residual risk

Communicated via labelling and IFU.

Production & post-production

Risk file is living, not a one-shot exercise.

[Previous IEC 62443-4-1 ](/frameworks/iec-62443-4-1)[Next  AAMI TIR57 ](/frameworks/aami-tir57)

The Crosswalk

An independent reference for global medical device cybersecurity standards. A field guide for MedTech innovators and RA/QA teams charting an international path.

Resource

-   [Comparison matrix](/compare)
-   [Global playbook](/playbook)
-   [Glossary](/glossary)
-   [FAQ](/faq)

Sponsored by

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

Editorially independent. Sponsorship keeps it free.

© 2026 The Crosswalk. Not legal advice.

Validate every requirement against current regulator publications.