ra-qm-team/skills/risk-management-specialist/SKILL.md
Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and post-production information analysis. Use when user mentions risk management, ISO 14971, risk analysis, FMEA, fault tree analysis, hazard identification, risk control, risk matrix, benefit-risk analysis, residual risk, risk acceptability, or post-market risk.
npx skillsauth add alirezarezvani/claude-skills risk-management-specialistInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
ISO 14971:2019 risk management implementation throughout the medical device lifecycle.
Establish risk management process per ISO 14971.
| Section | Content | Evidence | |---------|---------|----------| | Scope | Device and lifecycle coverage | Scope statement | | Criteria | Risk acceptability matrix | Risk matrix document | | Responsibilities | Roles and authorities | RACI chart | | Verification | Methods and acceptance | Verification plan | | Production/Post-Production | Monitoring activities | Surveillance plan |
| Probability \ Severity | Negligible | Minor | Serious | Critical | Catastrophic | |------------------------|------------|-------|---------|----------|--------------| | Frequent (P5) | Medium | High | High | Unacceptable | Unacceptable | | Probable (P4) | Medium | Medium | High | High | Unacceptable | | Occasional (P3) | Low | Medium | Medium | High | High | | Remote (P2) | Low | Low | Medium | Medium | High | | Improbable (P1) | Low | Low | Low | Medium | Medium |
| Level | Acceptable | Action Required | |-------|------------|-----------------| | Low | Yes | Document and accept; still reduce as far as possible (EU MDR) | | Medium | After reduction AFAP | Reduce as far as possible; document why further reduction is impossible | | High | After reduction AFAP | Reduction required; demonstrate all further options exhausted | | Unacceptable | No | Design change mandatory |
EU MDR — AFAP, not ALARP: For CE-marked devices, risks must be reduced as far as possible (AFAP) without economic considerations (MDR Annex I, GSPR 1–4; EN ISO 14971:2019/A11:2021 Z-annexes deviation). ALARP ("as low as reasonably practicable"), which permits cost-benefit weighing in acceptability decisions, is not an acceptable criterion under the EU MDR — a notified body will flag it. ISO 14971:2019 itself removed ALARP from the normative text. ALARP may persist in some non-EU jurisdictions (e.g., the UK HSE tradition); if used outside the EU, flag the deviation from EU requirements explicitly.
Identify hazards and estimate risks systematically.
| Category | Examples | Analyzed | |----------|----------|----------| | Electrical | Shock, burns, interference | ☐ | | Mechanical | Crushing, cutting, entrapment | ☐ | | Thermal | Burns, tissue damage | ☐ | | Radiation | Ionizing, non-ionizing | ☐ | | Biological | Infection, biocompatibility | ☐ | | Chemical | Toxicity, irritation | ☐ | | Software | Incorrect output, timing | ☐ | | Use Error | Misuse, perception, cognition | ☐ | | Environment | EMC, mechanical stress | ☐ |
| Situation | Recommended Method | |-----------|-------------------| | Component failures | FMEA | | System-level failure | FTA | | Process deviations | HAZOP | | User interaction | Use Error Analysis | | Software behavior | Software FMEA | | Early design phase | PHA |
| Level | Name | Description | Frequency | |-------|------|-------------|-----------| | P5 | Frequent | Expected to occur | >10⁻³ | | P4 | Probable | Likely to occur | 10⁻³ to 10⁻⁴ | | P3 | Occasional | May occur | 10⁻⁴ to 10⁻⁵ | | P2 | Remote | Unlikely | 10⁻⁵ to 10⁻⁶ | | P1 | Improbable | Very unlikely | <10⁻⁶ |
| Level | Name | Description | Harm | |-------|------|-------------|------| | S5 | Catastrophic | Death | Death | | S4 | Critical | Permanent impairment | Irreversible injury | | S3 | Serious | Injury requiring intervention | Reversible injury | | S2 | Minor | Temporary discomfort | No treatment needed | | S1 | Negligible | Inconvenience | No injury |
See: references/risk-analysis-methods.md
Evaluate risks against acceptability criteria.
Risk Estimated
│
▼
Apply Acceptability Criteria
│
├── Low Risk ──────────► Accept and document
│
├── Medium Risk ───────► Reduce as far as possible (AFAP)
│ │ Document why further reduction impossible
│ ▼
│ Further reduction possible?
│ │
│ Yes──► Implement control
│ No───► Document AFAP rationale (no economic considerations)
│
├── High Risk ─────────► Risk reduction required
│ │ Must demonstrate reduction AFAP
│ ▼
│ Implement control
│ Verify residual risk
│
└── Unacceptable ──────► Design change mandatory
Cannot proceed without control
| Criterion | Evidence Required | |-----------|-------------------| | All control options considered | Analysis of every feasible control per the hierarchy (design, protective measures, information) | | Further reduction impossible | Evidence each remaining option is technically infeasible or does not further reduce risk | | State of the art | Comparison to similar devices and current standards | | Stakeholder input | Clinical/user perspectives |
Economic considerations (cost of further risk reduction) must not enter the EU acceptability decision (MDR Annex I GSPR 2; EN ISO 14971:2019/A11:2021). Cost may inform business decisions about whether to market the device — never whether a risk is acceptable.
| Situation | Benefit-Risk Required | |-----------|----------------------| | Residual risk remains high | Yes | | No feasible risk reduction | Yes | | Novel device | Yes | | Unacceptable risk with clinical benefit | Yes | | All risks low | No |
Implement and verify risk control measures.
| Priority | Control Type | Examples | Effectiveness | |----------|--------------|----------|---------------| | 1 | Inherent Safety | Eliminate hazard, fail-safe design | Highest | | 2 | Protective Measures | Guards, alarms, automatic shutdown | High | | 3 | Information | Warnings, training, IFU | Lower |
RISK CONTROL OPTION ANALYSIS
Hazard ID: H-[XXX]
Hazard: [Description]
Initial Risk: P[X] × S[X] = [Level]
OPTIONS CONSIDERED:
| Option | Control Type | New Hazards | Feasibility | Selected |
|--------|--------------|-------------|-------------|----------|
| 1 | [Type] | [Yes/No] | [H/M/L] | [Yes/No] |
| 2 | [Type] | [Yes/No] | [H/M/L] | [Yes/No] |
SELECTED CONTROL: Option [X]
Rationale: [Justification for selection]
IMPLEMENTATION:
- Requirement: [REQ-XXX]
- Design Document: [Reference]
VERIFICATION:
- Method: [Test/Analysis/Review]
- Protocol: [Reference]
- Acceptance Criteria: [Criteria]
| Method | When to Use | Evidence | |--------|-------------|----------| | Test | Quantifiable performance | Test report | | Inspection | Physical presence | Inspection record | | Analysis | Design calculation | Analysis report | | Review | Documentation check | Review record |
| After Control | Action | |---------------|--------| | Acceptable | Document, proceed | | Reduced AFAP | Document rationale (no economic considerations), proceed | | Still unacceptable | Additional control or design change | | New hazard introduced | Analyze and control new hazard |
Monitor and update risk management throughout product lifecycle.
| Source | Information Type | Review Frequency | |--------|------------------|------------------| | Complaints | Use issues, failures | Continuous | | Service | Field failures, repairs | Monthly | | Vigilance | Serious incidents | Immediate | | Literature | Similar device issues | Quarterly | | Regulatory | Authority feedback | As received | | Clinical | PMCF data | Per plan |
| Trigger | Response Time | Action | |---------|---------------|--------| | Serious incident | Immediate | Full risk review | | New hazard identified | 30 days | Risk analysis update | | Trend increase | 60 days | Trend analysis | | Design change | Before implementation | Impact assessment | | Standards update | Per transition period | Gap analysis |
| Review Element | Frequency | |----------------|-----------| | Risk management file completeness | Annual | | Risk control effectiveness | Annual | | Post-market information analysis | Quarterly | | Risk-benefit conclusions | Annual or on new data |
→ See references/risk-assessment-templates.md for details
What is the risk level?
│
├── Unacceptable ──► Can hazard be eliminated?
│ │
│ Yes─┴─No
│ │ │
│ ▼ ▼
│ Eliminate Can protective
│ hazard measure reduce?
│ │
│ Yes─┴─No
│ │ │
│ ▼ ▼
│ Add Add warning
│ protection + training
│
└── High/Medium ──► Apply hierarchy
starting at Level 1
| Question | If Yes | If No | |----------|--------|-------| | Does control introduce new hazard? | Analyze new hazard | Proceed | | Is new risk higher than original? | Reject control option | Acceptable trade-off | | Can new hazard be controlled? | Add control | Reject control option |
| Condition | Decision | |-----------|----------| | All risks Low | Acceptable | | Medium risks reduced AFAP | Acceptable | | High risks reduced AFAP, documented | Acceptable if benefits outweigh | | Any Unacceptable residual | Not acceptable - redesign |
| Tool | Purpose | Usage |
|------|---------|-------|
| risk_matrix_calculator.py | Calculate risk levels and FMEA RPN | python risk_matrix_calculator.py --help |
Risk Matrix Calculator Features:
| Document | Content | |----------|---------| | iso14971-implementation-guide.md | Complete ISO 14971:2019 implementation with templates | | risk-analysis-methods.md | FMEA, FTA, HAZOP, Use Error Analysis methods |
| Stage | Key Activities | Output | |-------|----------------|--------| | Planning | Define scope, criteria, responsibilities | Risk Management Plan | | Analysis | Identify hazards, estimate risk | Hazard Analysis | | Evaluation | Compare to criteria, AFAP assessment (EU) | Risk Evaluation | | Control | Implement hierarchy, verify | Risk Control Records | | Residual | Overall assessment, benefit-risk | Risk Management Report | | Production | Monitor, review, update | Updated RM File |
| Skill | Integration Point | |-------|-------------------| | quality-manager-qms-iso13485 | QMS integration | | capa-officer | Risk-based CAPA | | regulatory-affairs-head | Regulatory submissions | | quality-documentation-manager | Risk file management |
development
Use when someone wants to run a weekly review, close open loops, audit stalled projects and commitments, get their system back to trusted, restart a lapsed review habit, or says "/cs:weekly-review". Walks David Allen's three-phase loop — GET CLEAR, GET CURRENT, GET CREATIVE — with deterministic scripts that inventory open loops, gate the checklist with named gaps, and score commitment health 0-100.
development
Use when someone wants to decide whether a meeting is worth calling, price a meeting in dollars, build a timeboxed agenda with desired outcomes, or turn messy meeting notes into owned action items — or says "should this be a meeting", "/cs:meeting-prep", or "/cs:meeting-actions". Runs a cost gate (ASYNC / NOT-READY / MEET), builds a decision-first agenda, and extracts an owner + due-date checklist that flags every orphan.
development
Convert a rambling description of a desired outcome into one polished, autonomous /goal prompt ready to paste into a fresh session. Use when the user says "/fable-goal", "turn this into a goal prompt", "write me a fable prompt", "write the prompt that builds X", or rambles about something they want made and asks for the prompt that makes it happen. The output is a single copy-paste prompt, never the build itself. Do NOT use when the user wants the thing built right now in this session — only when they want the PROMPT that will make it happen in a fresh session.
development
Use when someone wants to plan a deep work day, time-block their calendar or task list, budget or cut shallow work, protect focus hours, track deep-work sessions and streaks, run an end-of-day shutdown ritual, or says "/deep-work" or "/time-block". Classifies tasks deep vs shallow, builds an energy-first time-blocked schedule that refuses deep demand past the 4-hour ceiling, batches shallow work into at most two windows, and logs focus sessions against a weekly target.