Skip to main content

Risk Management

Framework: ISO 14971

Indonesia's device registration requirements align with ISO 14971 (Medical devices — Application of risk management to medical devices) as the accepted standard for risk management documentation. Your risk management file should follow the ISO 14971 process:

  1. Risk analysis
  2. Risk evaluation
  3. Risk control
  4. Evaluation of overall residual risk
  5. Risk management review
  6. Production and post-production activities

Risk Management File Requirements

The dossier must include at minimum a Risk Analysis and Control Summary — a document that provides an overview of:

ElementContent
Intended use and reasonably foreseeable misuseDefined in risk analysis
Hazard identificationAll identified hazards associated with the device
Hazard situations and harmsAnalysis of hazard sequences leading to harm
Severity and probability of harmRisk estimation per ISO 14971
Risk control measuresDesign, protective, and information-for-safety measures
Residual risksRemaining risks after controls, with acceptability determination
Risk–benefit analysisFor Class C/D: formal analysis that benefits outweigh residual risks
Completeness checkConfirmation that all known device hazards have been addressed

Class-Specific Requirements

ClassRisk Management Depth
ABasic risk summary; simpler hazard/harm analysis acceptable
BFull risk analysis per ISO 14971; risk control measures documented
CFull risk management file; residual risk justification; post-market risk monitoring plan
DFull risk management file; formal risk–benefit analysis mandatory; traceability to FSCA plan; PSUR commitment for ongoing risk review

Common Evaluator Queries on Risk Management

Kemenkes evaluators frequently raise clarification queries on:

  • Insufficient hazard coverage — evaluators may note that specific foreseeable misuse scenarios have not been addressed
  • Residual risk acceptability — the basis for accepting a residual risk must be documented; "no incidents reported to date" is generally insufficient
  • Risk control effectiveness — evidence that risk control measures actually reduce risk as claimed

ISO 14971:2019 vs Earlier Versions

Indonesia does not mandate a specific edition of ISO 14971, but the 2019 revision is the current applicable standard. If your existing risk management documentation was prepared to ISO 14971:2007, a gap assessment and update to 2019 requirements may be needed before submission.