Key concepts & terminology
Risk management has a vocabulary that looks like ordinary English and is not. A hazard is not a risk, a hazardous situation is not a harm, and the app keeps them in separate fields because the standard keeps them separate. This page defines the terms, then explains scoring, control, and the statuses.
The vocabulary
The four kinds of safety risk
Every safety risk carries a Category, and the category decides which fields the app requires. The four categories are four ways of looking at the same product, and they are usually run in this order, because each one has something to hand to the next.
| Category | Method | What it examines |
|---|---|---|
| Hazard | Hazard analysis | Top-down, run early. Starts from the hazard lists in the standards and works forward to what could go wrong. Its risk controls become inputs to the design and the architecture. |
| Design | Design FMEA | Bottom-up. Starts from a failure mode in a part or a component and asks how that failure contributes to a hazardous situation. |
| Process | Process FMEA | Bottom-up. Starts from a failure mode in a process step, usually a manufacturing work instruction, and asks how that error contributes to a hazardous situation. |
| Use | Use-related risk assessment | Bottom-up. Starts from a use error in a use scenario and asks how that error contributes to a hazardous situation. |
Changing the category partway through an assessment can move the work item backwards. Each category requires a different set of fields, so the app re-checks the item against the new category and reopens the assessment if anything the new category needs is still empty.
How a risk is scored
ISO 14971 splits the probability of harm in two, and the app scores both separately.
You enter P1 and P2. The app computes the overall probability from them, then reads the risk level off the matrix using that probability and the severity. All four of those values are read-only on the work item: two because they are calculated, and severity because it belongs to the harm. The bands, the matrix, and the acceptability criteria are set per space. See Set up Safety Risks.
Every risk is scored twice, once before controls (the initial score) and once after (the residual score), using the same P1, P2, and severity.
A worked example
Billy goes surfing. The example is not medical, which is the point: it separates the terms cleanly enough that you can see which field each piece of the story belongs in.
| Field | Billy |
|---|---|
| Hazard | A shark in the water. |
| Sequence of events | Billy enters the ocean without checking for hazards, then swims near the shark. |
| Hazardous situation | Billy is swimming in an area where a shark is nearby. |
| Harm | Shark bite. |
| Severity | Catastrophic, from the harm. |
| Initial P1 | Remote. The probability of Billy entering an area where a shark is present. |
| Initial P2 | Occasional. The probability of the shark attacking once Billy is near. |
| Initial risk level | Remote against catastrophic, which the matrix scores as medium. |
| Risk controls | A warning sign, teaching Billy what to look for, a lifeguard watching for shark activity, and closing the water at peak times all reduce P1. A deterrent device and swimming in a group reduce P2. |
| Residual P1 | Unlikely. |
| Residual P2 | Remote. |
| Residual risk level | Unlikely against catastrophic, which the matrix still scores as medium. |
| Acceptable | Yes. Surfing benefits Billy’s physical and mental health, and the residual risk is accepted for experienced surfers with the controls in place. |
Notice that the severity never moved. Controls change how likely the harm is, not how bad it is, which is why a catastrophic harm can stay catastrophic through a successful mitigation and still end up acceptable.
How risk control is chosen
ISO 14971 puts the three kinds of control in a fixed order of preference, and you are expected to work down the list rather than pick whichever is easiest.
ISO 14971 requires risk to be reduced as far as possible (AFAP), and deliberately avoids the word practicable. Cost and commercial considerations are not an acceptable reason to leave a control unimplemented. The only acceptable reasons to stop are that further reduction is not technically feasible, or that the control would introduce new risks or worsen the overall benefit and risk balance. ALARP, as low as reasonably practicable, permits a cost and benefit trade-off and is the wrong test here. The EU MDR mirrors ISO 14971 on this point.
How a safety risk work item is laid out
A safety risk carries more fields than one screen holds, so its Key details are split across seven tabs that follow the assessment in order: Details, Analysis, FMEA, Initial Risk, Control, Residual Risk, and Acceptability. The tab you need is usually the one named after the status the risk is in.
The statuses a safety risk moves through
The app validates each transition against the category, not just against the status. A design risk and a use risk leaving Analysis need different fields filled, and the app tells you which are missing rather than letting the item move. The required set for each transition is listed in Analyze and score a safety risk.
The statuses a characteristic, hazard, or harm moves through
Safety characteristics, hazards, and harms are all rulings on applicability, so they share one short lifecycle. Each starts undetermined, stays editable while you gather the evidence, then moves to whichever of the two answers applies, and locks.
An item in Applicable or Not applicable cannot be edited. To change one, move it to Outdated, revise it, then rule on it again. Nothing is edited in place after a ruling, which is what keeps the register defensible.
