Build the risk management file
The risk management file is the document an auditor asks for. It is not a copy of the register: it is the controlled document that plans the risk management activity, references the register, and reports the result. This guide covers building it and keeping it current.
What the file holds
Create the file
- In Confluence, open the Draft Documents space and create a document of type Risk Management File for your product. See Create a document or template.
- Complete the document, following the instructions written into the template.
- Take it through approval in Document Control. See Review and approve a document.
- Link the approved file to the products it applies to, through Document Control.
Export the register to Excel
Click Export to Excel in the safety risk table to take the register out as a spreadsheet. Use it for a review that has to happen outside Jira, for a supplier or a notified body who cannot be given site access, and as the attachment an auditor can be handed directly.
The export is a point-in-time copy, so it stops reflecting the register the moment either changes. Where the copy has to stay valid, put it through Document Control, which is what versions it and records who approved it.
Reference the register rather than importing it
The register changes far more often than the plan or the report. Referencing it, rather than pulling the risk content into the file directly, means a revision to the register does not force a revision of the whole file.
- Export the register with Export to Excel from the safety risk table, or bring it into Confluence with the Risk Register template.
- Approve that risk register document in Document Control.
- Reference the approved register from the risk management file.
Where a document uses the Static Jira content macro, the macro also writes a CSV of the same content and attaches it to the page, so the data behind an approved document stays recoverable without going back to Jira.
Keep the file current after release
Risk management does not finish when the product ships. Once a product is out of development, its lifecycle triggers the post-production activity that feeds the register: complaints, field data, design changes, and post-market surveillance all reopen risks that were closed. Each of those updates goes back through Document Control for review and approval.
When the file is complete
- Every safety characteristic has been reviewed, documented, and approved.
- Every hazard has been reviewed for applicability, and the list is documented and approved.
- Every harm has been defined, and the list is documented and approved.
- Every safety risk has been analyzed, evaluated, mitigated as far as possible, reviewed, and approved.
- All of that activity is documented in the risk management file, and the file itself is reviewed and approved.
