What is a Benefit-Risk Analysis & How To Do It?

March 17, 2023

The Benefit-Risk analysis (a.k.a. Benefit-Risk determination or Benefit-Risk ratio) is one of the most misinterpreted areas of the Risk Management process, in particular when coupled with the requirements of MDR / IVDR.

And consequently one of the preferred digging points for the Notified Bodies.

The spirit of the regulations and standards is “the benefit provided by the use of the device must outweigh the associated risk”.

That sounds simple doesn’t it?

Let’s take a step back.

The basic requirements are listed in ISO 14971 (EN ISO 14971:2019+A11:2021):

  1. Par. 7.1: “If, during risk control option analysis, the manufacturer determines that risk reduction is not practicable, the manufacturer shall conduct a benefit-risk analysis of the residual risk.”
  2. Par. 7.4: “If a residual risk is not judged acceptable using the criteria established in the risk management plan and further risk control is not practicable, the manufacturer may gather and review data and literature to
    determine if the benefits of the intended use outweigh this residual risk.”

What often slips through the cracks is that the ISO 14971 is usually supplemented by additional requirements in each region. In particular, when the EU adopts a standard, additional information is added to it. Unlike the 2012 version, the latest EN version of ISO 14971 does not contain detailed additional requirements in Annexes ZA and ZB.

But what was in ZA and ZB of the previous version still applies. In particular:

  1. A Benefit-Risk analysis is not a way out of an unacceptable risk. Unacceptable risks are unacceptable.
  2. A Benefit-Risk analysis must always be carried out:
    1. The Benefit of using the device vs the Overall residual risk.
    2. Each residual risk vs the benefit of that specific feature under analysis.

To summarize: ALWAYS carry out a Benefit-Risk analysis before a product is placed on the market, and include ALL risk items, regardless of their acceptability.

How to Conduct a Benefit-Risk Analysis

Benefit-(Overall residual) Risk Analysis in 3 Simple Steps:

  1. Summarize all risk items from all risk analysis documents;
    1. e.g. using diagrams, charts, statistics, etc.
  2. Summarize the traceability to risk mitigation actions;
  3. Arrange a review with the project team, management, Regulatory, Quality and ideally an external expert on the device / use (e.g. a doctor / specialist / surgeon):
    1. Agree that the risks have been mitigated As Far As Possible and additional risk controls do not significantly reduce the risk.
    2. Agree that each residual risk is acceptable.
    3. Agree that the overall residual risk is acceptable.
    4. Agree that the benefit of using the device outweigh the residual risk
  4. Summarize the outcome of the Review into the Risk Management Report.
    1. The Benefit-Risk assessment is only a part of the Risk Management Review / Report, don’t forget it!

To manage risks in Jira and automate risk traceability, make sure to check out the SoftComply Risk Management apps!

Table of Contents

Ready to get started?

Contact us to book a demo and learn how SoftComply can cover all your needs

Medical Device Compliance Guide
Picture of Marion Lepmets

Marion Lepmets

CEO
September 23, 2024

Introduction This medical device compliance guide focuses on the key requirements and strategies for navigating the regulatory landscape. We will cover the role of major regulatory bodies like the FDA, the classification of devices, and the importance of quality management. We will also discuss the challenges of global compliance and...

CVSS-FDA-cybersecurity-medical-devices-1712x599-c
Picture of Matteo Gubellini

Matteo Gubellini

Regulatory Affairs Manager
September 16, 2024

This case study describes the experience of a multinational medical device manufacturer meeting the FDA cybersecurity requirements. The company is operating in the MedTech sector developing a class 2/IIb device consisting of hardware and software. The company spent about 2 years working on the security risk management of the device....

Information Security Risk Management Guide
Picture of Marion Lepmets

Marion Lepmets

CEO
September 13, 2024

Keeping your data safe is vital for every business. One way to do this is by following ISO 27001. But how can we manage these information security risks with a tool like Jira? Let’s dive in! What is Information Security Risk Management Information Security Risk Management is all about identifying,...