Dear colleagues:
In recent TAI posts, we have challenged two assumptions in our risk files.
First, risk control effectiveness is more than showing that individual controls were implemented and verified. Second, FMEA may identify failure modes without fully revealing the failure trajectory that leads to a hazardous situation and harm.
Those issues become especially important after launch.
We are accustomed to analyzing failure modes one at a time: identify the failure, assign controls, verify them, and conclude that the associated “risk” has been reduced.
But under ISO 14971, we are managing risk of harm, not simply risk of failure.
A hazard–hazardous situation–harm combination may be reached through several failure trajectories. Different failures, use conditions, human actions, and other events may converge on the same hazardous situation. The relevant protection is therefore not just the control attached to one FMEA row, but the combination of risk control measures acting across those pathways.
Post-market experience can challenge that model in several ways. A known control may become less effective. The interaction among controls may change. Or a previously unidentified failure mode may reveal an entirely new pathway to the same hazardous situation.
In that last case, every control associated with the known failure modes could still be working exactly as intended—and yet the risk of harm has changed.
Post-market surveillance must be able to challenge the failure trajectory, not merely confirm the failure modes we already know.
This is why poor understanding of risk control effectiveness becomes a lifecycle problem. If we have not clearly linked the combined control strategy to the pathways leading to harm, it becomes difficult to define what deterioration would look like, what signals should be monitored, or when new information requires the risk analysis itself to change.
Monitoring complaints and failures remains important. But the deeper question is whether real-world evidence is showing that the pathway to harm—or our understanding of it—is changing.
So let’s think about the following question:
👉How would you know the pathway to harm has changed if known controls still appear effective?
As an example, consider the following prompt in the LTR Risk Coach:
Our team is conducting a post-market surveillance review for one significant hazard–hazardous situation–harm combination in the risk file. Help me review the available complaints, adverse events, service data, field observations, use-related issues, and other relevant post-market evidence. Look for signals that the pathway to harm may be changing, including declining effectiveness of known controls, changing interactions among controls, or a newly emerging failure mode or pathway not recognized in the original analysis. Then identify what the team should investigate further, what additional data should be monitored, and what findings should trigger reassessment of the risk analysis and control strategy.
You might also enjoy thinking about these ideas:

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.