Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.
risk-management-specialist
Security Scan Summary
Status: Safe
Source: Syntic Skills registry
Automated security scan completed with no high-risk patterns detected. Manual review is still required.
About This Skill
Use when the user mentions risk management, ISO 14971, risk analysis, FMEA, fault tree analysis, hazard identification, risk control, risk matrix, benefit-risk, or post-market risk.
Downloadable SKILL.md
Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.
---
name: risk-management-specialist
description: Use when the user mentions risk management, ISO 14971, risk analysis, FMEA, fault tree analysis, hazard identification, risk control, risk matrix, benefit-risk, or post-market risk.
category: Regulatory & Quality
version: 1.0.0
tools: []
---
# Risk Management Specialist
ISO 14971:2019 risk management implementation throughout the medical device lifecycle.
## Risk Management Planning Workflow
Establish the risk management process per ISO 14971:
1. Define scope — device identification, lifecycle stages covered, applicable standards/regulations
2. Establish risk acceptability criteria — probability categories (P1-P5), severity categories (S1-S5), risk matrix with acceptance thresholds
3. Assign responsibilities — risk management lead, subject matter experts, approval authorities
4. Define verification activities — methods for control verification, acceptance criteria
5. Plan production and post-production activities — information sources, review triggers, update procedures
6. Obtain plan approval
7. Establish the risk management file
8. Validate: plan approved; acceptability criteria defined; responsibilities assigned; file established
### Risk Acceptability Matrix (5×5)
| Probability \\ Severity | Negligible | Minor | Serious | Critical | Catastrophic |
|------------------------|------------|-------|---------|----------|--------------|
| **Frequent (P5)** | Medium | High | High | Unacceptable | Unacceptable |
| **Probable (P4)** | Medium | Medium | High | High | Unacceptable |
| **Occasional (P3)** | Low | Medium | Medium | High | High |
| **Remote (P2)** | Low | Low | Medium | Medium | High |
| **Improbable (P1)** | Low | Low | Low | Medium | Medium |
Risk-level actions: Low is acceptable (document and still reduce as far as possible under EU MDR); Medium and High require reduction as far as possible (AFAP) with documentation of why further reduction is impossible; Unacceptable mandates a design change.
**EU MDR — AFAP, not ALARP:** For CE-marked devices, risks must be reduced as far as possible (AFAP) without economic considerations (MDR Annex I, GSPR 1-4; EN ISO 14971:2019/A11:2021 Z-annexes deviation). ALARP ("as low as reasonably practicable"), which permits cost-benefit weighing, is not an acceptable criterion under EU MDR — a Notified Body will flag it. ISO 14971:2019 itself removed ALARP from the normative text. ALARP may persist in some non-EU jurisdictions (e.g. the UK HSE tradition); flag the deviation explicitly if used outside the EU.
## Risk Analysis Workflow
Identify hazards and estimate risks systematically:
1. Define intended use and reasonably foreseeable misuse — medical indication, patient population, user population, use environment
2. Select analysis method(s) — FMEA for component/function analysis, FTA for system-level analysis, HAZOP for process deviations, Use Error Analysis for user interaction, Software FMEA for software behavior, PHA for early design phase
3. Identify hazards by category — energy (electrical, mechanical, thermal), biological (bioburden, biocompatibility), chemical (residues, leachables), operational (software, use errors)
4. Determine hazardous situations — sequence of events, foreseeable misuse scenarios, single fault conditions
5. Estimate probability of harm (P1-P5)
6. Estimate severity of harm (S1-S5)
7. Document in the hazard analysis worksheet
8. Validate: all hazard categories addressed; all hazards documented; probability and severity assigned
Hazard categories to check: electrical (shock, burns, interference), mechanical (crushing, cutting, entrapment), thermal (burns, tissue damage), radiation (ionizing, non-ionizing), biological (infection, biocompatibility), chemical (toxicity, irritation), software (incorrect output, timing), use error (misuse, perception, cognition), environment (EMC, mechanical stress).
### Probability Criteria
| Level | Name | Frequency |
|-------|------|-----------|
| P5 | Frequent | >10⁻³ |
| P4 | Probable | 10⁻³ to 10⁻⁴ |
| P3 | Occasional | 10⁻⁴ to 10⁻⁵ |
| P2 | Remote | 10⁻⁵ to 10⁻⁶ |
| P1 | Improbable | <10⁻⁶ |
### Severity Criteria
| Level | Name | Harm |
|-------|------|------|
| S5 | Catastrophic | Death |
| S4 | Critical | Irreversible injury |
| S3 | Serious | Reversible injury requiring intervention |
| S2 | Minor | Temporary discomfort, no treatment needed |
| S1 | Negligible | No injury |
## Risk Evaluation Workflow
Evaluate risks against acceptability criteria:
1. Calculate the initial risk level from probability × severity
2. Compare to risk acceptability criteria
3. Determine per risk: Acceptable (document and accept, still AFAP under EU MDR), Reduction required (AFAP, proceed to risk control), or Unacceptable (mandatory risk control)
4. Document the evaluation rationale
5. Identify risks requiring benefit-risk analysis
6. Complete benefit-risk analysis if applicable
7. Compile a risk evaluation summary
8. Validate: all risks evaluated; acceptability determined; rationale documented
Evaluation logic: Low risk → accept and document. Medium risk → reduce AFAP; if further reduction is possible, implement a control, otherwise document the AFAP rationale (no economic considerations). High risk → risk reduction required, implement a control, verify residual risk. Unacceptable → design change mandatory, cannot proceed without control.
AFAP demonstration requires: analysis of every feasible control per the hierarchy (design, protective measures, information); evidence each remaining option is technically infeasible or doesn't further reduce risk; comparison to state-of-the-art similar devices and current standards; and clinical/user stakeholder input. Economic considerations must never enter the EU acceptability decision (MDR Annex I GSPR 2; EN ISO 14971:2019/A11:2021) — cost may inform whether to market the device, never whether a risk is acceptable.
Benefit-risk analysis is required when residual risk remains high, no feasible risk reduction exists, the device is novel, or an unacceptable risk carries clinical benefit; not required when all risks are low.
## Risk Control Workflow
Implement and verify risk control measures:
1. Identify risk control options in priority order — inherent safety by design (Priority 1), protective measures in the device (Priority 2), information for safety (Priority 3)
2. Select the optimal control following the hierarchy
3. Analyze the control for new hazards it might introduce
4. Document the control in design requirements
5. Implement the control in the design
6. Develop a verification protocol
7. Execute verification and document results
8. Evaluate residual risk with the control in place
9. Validate: control implemented; verification passed; residual risk acceptable; no unaddressed new hazards
A risk control option analysis records: the hazard ID and description, initial risk (P×S), each control option considered (type, new hazards introduced, feasibility, selected/not), the selected control and rationale, the implementing requirement/design document, and the verification method/protocol/acceptance criteria.
Verification methods: Test (quantifiable performance, evidenced by a test report), Inspection (physical presence, inspection record), Analysis (design calculation, analysis report), Review (documentation check, review record).
Residual risk outcomes: Acceptable → document and proceed. Reduced AFAP → document rationale (no economic considerations), proceed. Still unacceptable → additional control or design change. New hazard introduced → analyze and control the new hazard.
## Post-Production Risk Management
Monitor and update risk management throughout the lifecycle:
1. Identify information sources — customer complaints, service reports, vigilance/adverse events, literature monitoring, clinical studies
2. Establish collection procedures
3. Define review triggers — new hazard identified, increased frequency of a known hazard, serious incident, regulatory feedback
4. Analyze incoming information for risk relevance
5. Update the risk management file as needed
6. Communicate significant findings
7. Conduct periodic risk management review
8. Validate: information sources monitored; file current; reviews completed per schedule
Review cadence by source: complaints continuous, service reports monthly, vigilance immediate, literature quarterly, regulatory feedback as received, clinical/PMCF data per plan. File-update response times: serious incident → immediate full risk review; new hazard identified → 30 days for a risk analysis update; trend increase → 60 days for trend analysis; design change → impact assessment before implementation; standards update → gap analysis per the transition period.
Periodic review requirements: risk management file completeness and risk control effectiveness reviewed annually; post-market information analysis quarterly; risk-benefit conclusions annually or on new data.
## Decision Frameworks
Risk control selection: for Unacceptable risk, first check whether the hazard can be eliminated by design; if not, check whether a protective measure can reduce it; if not, fall back to warnings and training. For High/Medium risk, apply the control hierarchy starting at Priority 1 (inherent safety).
New-hazard analysis after adding a control: if the control introduces a new hazard, analyze it; if the new risk is higher than the original, reject that control option; otherwise it may be an acceptable trade-off, subject to the new hazard also being controlled or accepted through the same evaluation process.
Bundle Download
Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.
Install Targets
Syntic App
- 1. Create a dedicated folder for this skill in your local skills library.
- 2. Place SKILL.md into that folder.
- 3. Restart Syntic and invoke this skill on matching tasks.
Syntic Code (CLI)
- 1. Save SKILL.md in your local Syntic Code skills directory.
- 2. Keep related files in the same skill folder.
- 3. Run in a safe environment and validate outputs.
Source
https://github.com/alirezarezvani/claude-skills/blob/main/ra-qm-team/skills/risk-management-specialist/SKILL.md
Open Source LinkRelated Skills
agent-decision-receipts
Use when an autonomous agent takes a consequential, side-effecting action (deploy, delete, pay, grant-access...
Regulatory & Qualitycapa-officer
Use when running CAPA investigations, 5-Why or fishbone root cause analysis, corrective action planning and...
Regulatory & Qualityeu-ai-act-specialist
Use when classifying an AI system's EU AI Act risk tier, planning Article 43 conformity assessment for a...
Regulatory & Qualityfda-consultant-specialist
Use when handling FDA submission pathway selection (510(k)/PMA/De Novo), QMSR/ISO 13485 compliance, medical...