Medical Device FMEA

ISO 13485 DFMEA: Requirements, Templates, and Compliance Guide

Tacit AI · · 12 min read

If you manufacture medical devices, ISO 13485 is your quality management system standard. It requires risk management to be integrated throughout the product lifecycle. Design FMEA (DFMEA) is the most common structured method teams use to meet that requirement during design and development. With the FDA’s QMSR now incorporating ISO 13485 by reference, getting your DFMEA right is no longer just good practice. It is the regulatory baseline.

This guide covers the specific DFMEA requirements under ISO 13485, the template structure your DFMEA should follow, what auditors check, and the gaps that lead to findings. For the broader QMSR regulatory context, see our QMSR FMEA Requirements post.

Where DFMEA Fits in ISO 13485

ISO 13485:2016 does not mention “DFMEA” by name. It requires risk management as part of design and development (Clause 7.3), and it requires that risk management be applied across the product lifecycle. DFMEA is the structured method most manufacturers use to satisfy these requirements.

The relevant ISO 13485 clauses:

  • Clause 7.1 - Planning of product realization. Requires determining “actions needed for risk management” during product planning.
  • Clause 7.3.2 - Design and development planning. Requires defining activities for design verification, validation, and risk management.
  • Clause 7.3.3 - Design and development inputs. Requires inputs to include “applicable statutory and regulatory requirements” and “outputs from risk management.”
  • Clause 7.3.4 - Design and development outputs. Outputs must “provide appropriate information for purchasing, production and service provision” and must “specify the characteristics of the product that are essential for its safe and proper use.”
  • Clause 7.3.9 - Design and development changes. Changes must be evaluated for their effect on “constituent parts and delivered product” including “risk analysis and the results of risk management activities.”
  • Clause 8.2.1 - Feedback. The organization must gather and monitor information on whether the product meets user requirements, including complaint data that must be evaluated as part of risk management.

DFMEA addresses all of these by identifying design-related hazardous situations, evaluating their severity and probability, defining risk controls, and linking to verification evidence. It is the document that connects risk management intent to design execution.

ISO 13485 vs ISO 14971: How They Connect

ISO 13485 requires risk management. ISO 14971 defines how to do it for medical devices. DFMEA is one of the hazard identification techniques recommended in ISO 14971.

Standard What It Covers Role of DFMEA
ISO 13485:2016 QMS requirements for medical devices Requires risk management throughout the lifecycle
ISO 14971:2019 Risk management process for medical devices Defines hazard identification, risk estimation, risk evaluation, risk control
DFMEA Structured design failure mode analysis Identifies hazardous situations, evaluates severity/probability, defines controls

In practice, most medical device manufacturers use DFMEA as their primary hazard identification method for design risk analysis per ISO 14971. The DFMEA becomes the design risk analysis document in the risk management file. Some organizations maintain a separate risk analysis document (per ISO 14971 format) and a DFMEA. Others combine them. Either approach can be compliant if the required elements are present.

DFMEA Requirements Under ISO 13485

To satisfy ISO 13485 (and ISO 14971), your DFMEA must include:

  • Intended use and reasonably foreseeable misuse. The analysis must consider how the device will be used and how it could be misused. Failure modes should cover both scenarios.
  • Hazardous situations identified from design characteristics. Each design element that could create a hazard must be analyzed. Generic failure modes copied from templates without connection to your device do not meet the standard.
  • Severity based on patient harm. Medical device severity scales must reflect the impact on the patient, operator, or bystander. This is different from automotive severity scales. A severity of 9-10 means serious injury or death.
  • Probability of occurrence. ISO 14971 uses probability categories, not the 1-10 occurrence scale from AIAG-VDA. Your DFMEA should use probability terminology consistent with your risk management procedure.
  • Risk controls linked to verification/validation. Every risk control in the DFMEA must have corresponding verification or validation evidence. If you list “biocompatibility testing” as a control, the test report must exist and be traceable.
  • Residual risk evaluation. After risk controls, the remaining risk must be evaluated against your risk acceptability criteria. ISO 14971 requires explicit risk acceptability decisions, not just RPN thresholds.
  • Benefit-risk analysis. For risks that cannot be reduced further, ISO 14971 requires a benefit-risk analysis showing that the medical benefit outweighs the residual risk.
  • Post-market feedback integration. The DFMEA must be updated when complaint data, adverse events, or CAPA outcomes reveal new hazards or contradict existing risk assessments.

ISO 13485 DFMEA Template Structure

An ISO 13485-compliant DFMEA template should include these columns. The exact format varies by organization, but the content requirements are consistent:

Column Purpose ISO 14971 Mapping
Design element / function Component or function being analyzed Identifies the scope of analysis
Intended use context How the device is used, user population Clause 5.2 - Intended use
Hazardous situation How the design could create harm Clause 5.4 - Hazard identification
Failure mode How the function fails Annex C - FMEA technique
Failure effect (patient/user) Impact on patient, operator, or bystander Clause 5.5 - Risk estimation
Severity Severity category per ISO 14971 scales Clause 5.5 - Severity of harm
Cause / mechanism Design condition leading to failure Supports root cause identification
Probability of occurrence Likelihood category Clause 5.5 - Probability of occurrence
Risk level (before control) Severity × probability against acceptability matrix Clause 5.5 - Risk estimation
Risk control measure Design change, protective measure, or information for safety Clause 6 - Risk control
Verification / validation reference Test report, analysis, or evidence that control works Clause 6.3 - Verification of risk control measures
Residual risk level (after control) Re-evaluated risk after control implementation Clause 6.4 - Residual risk evaluation
Risk acceptability decision Acceptable, ALARP, or unacceptable Clause 5.5 and risk management plan criteria
Source / traceability Design input, spec, complaint, or test that identified the hazard Traceability required per ISO 13485 Clause 7.5.9

This is more detailed than a standard automotive DFMEA template. The additional columns (intended use, risk acceptability, benefit-risk) reflect ISO 14971’s requirements for medical device risk management.

Severity and Probability Scales for Medical Devices

Medical device DFMEA severity scales differ from automotive scales. The focus is patient harm, not manufacturing inconvenience.

Severity Category Description Example
Negligible Inconvenience or temporary discomfort Slight skin irritation from adhesive
Minor Temporary injury, no medical intervention Temporary redness requiring no treatment
Serious Injury requiring medical intervention Infection requiring antibiotics
Critical Life-threatening or permanent impairment Undetected misdiagnosis leading to delayed treatment
Catastrophic Death Air embolism from catheter failure

Probability scales should reflect the likelihood of the hazardous situation occurring during the product lifecycle. ISO 14971 does not prescribe a specific scale. It requires that the scale be defined in your risk management plan and applied consistently.

Using AIAG-VDA 1-10 scales for medical device DFMEA is not recommended. The automotive scales are calibrated for manufacturing defects per million, not patient harm probability. Define your own scales per ISO 14971 and document them in your risk management procedure.

What Auditors Check

Notified body auditors (for CE marking) and FDA investigators (under QMSR) will evaluate your DFMEA against these criteria:

  • Traceability from intended use to hazardous situations. Can the auditor trace from the device’s intended use to identified hazards? If your DFMEA lists failure modes without connecting them to how the device is actually used, that is a gap.
  • Verification evidence for risk controls. The auditor will pick a risk control from your DFMEA and ask for the test report or validation evidence. If the link is missing, expect a finding.
  • Post-market data integration. If you have complaints about a failure mode rated “improbable” in your DFMEA, the contradiction will be found. Probability ratings must reflect current field data.
  • Risk acceptability decisions. Every row should have an explicit acceptability decision, not just a risk score. Auditors check that your risk acceptability criteria (from your risk management plan) are applied consistently.
  • Design change impact. When design changes occur, auditors check whether the DFMEA was updated. A design change without a DFMEA review is a finding under Clause 7.3.9.

For real examples of FDA findings related to inadequate risk analysis, see our QMSR FMEA Requirements post.

Common Compliance Gaps

These are the gaps we see most often in medical device DFMEAs:

Using automotive FMEA templates without adaptation. AIAG-VDA templates do not include intended use, risk acceptability, or benefit-risk columns. Medical device DFMEAs require ISO 14971 alignment, not automotive FMEA formatting. Use a template designed for medical devices.

Severity scores without patient-harm context. Rating severity on a 1-10 scale with automotive criteria (“vehicle inoperable”) when your device can cause patient injury. Medical device severity must relate to patient harm categories.

No residual risk evaluation. The DFMEA shows risk controls but does not re-evaluate risk after implementation. ISO 14971 requires explicit residual risk assessment. Without it, you cannot demonstrate that risk has been reduced to an acceptable level.

Disconnected from post-market surveillance. The DFMEA was created during development and never updated with field data. Complaints, adverse events, and CAPA outcomes are not reflected. Under QMSR, this is a compliance failure.

Missing verification links. Risk controls listed without corresponding test reports or validation evidence. The DFMEA says “biocompatibility testing” but no one can produce the test report reference.

DFMEA vs ISO 14971 Risk Analysis: The Overlap

Some organizations maintain both a DFMEA and a separate ISO 14971 risk analysis document. Others use the DFMEA as their risk analysis. Both approaches can work:

Combined approach: The DFMEA serves as the design risk analysis in the risk management file. It includes all ISO 14971 required elements (hazard identification, risk estimation, risk evaluation, risk control). This avoids duplication but requires a more detailed DFMEA template.

Separate documents: The ISO 14971 risk analysis is a summary document that references the DFMEA for detailed failure mode analysis. The risk analysis provides the overall risk acceptability evaluation. The DFMEA provides the detailed engineering analysis. This can be cleaner for regulatory review but requires maintaining two documents in sync.

Either approach must ensure that all ISO 14971 requirements are met somewhere in the risk management file. The worst outcome is a gap where neither document covers a required element because each team assumed the other would handle it.

Post-Market Data Feeding Back to DFMEA

ISO 13485 Clause 8.2.1 requires that post-market data feed back into risk management. For your DFMEA, this means:

  • Complaints that reveal new hazardous situations must trigger a DFMEA review and potential addition of new failure modes.
  • Adverse event data that contradicts probability ratings must trigger probability re-evaluation. If your DFMEA says “improbable” but you have 10 adverse events, the rating is wrong.
  • CAPA outcomes that affect risk controls must be reflected in the DFMEA. If a corrective action changes a design control, the DFMEA row should be updated.
  • Trend data from complaint handling can reveal emerging failure modes before they become adverse events. Proactive DFMEA update based on trend data demonstrates the risk management maturity that auditors look for.

This feedback loop is what separates a living DFMEA from shelf-ware. Building the process to close this loop is more important than any specific template format.

How Tacit AI Approaches This

Tacit AI generates ISO 14971-aligned DFMEAs for medical devices and keeps them current as post-market data arrives.

ISO 14971 risk analysis from device specs. Provide your device description, intended use, and design inputs. Tacit AI generates a draft DFMEA with hazardous situations, severity and probability aligned to ISO 14971 categories, risk control recommendations, and residual risk evaluation. Engineers review and refine.

Template that meets the standard. Our DFMEA output includes intended use context, ISO 14971 severity/probability scales, risk acceptability decisions, verification references, and residual risk. Not automotive scales bolted onto a medical device.

Source traceability. Every hazardous situation and severity rating links to the source document, design input, or complaint record that generated it. When an auditor asks “why is this rated Serious?”, you can show the evidence chain.

Post-market loop closes automatically. Complaint data and CAPA records are semantically matched to DFMEA rows. When a complaint describes a failure the DFMEA did not predict, it appears as a gap. When probability ratings contradict field data, the discrepancy surfaces. The DFMEA stays current with reality.

Learn more about Tacit AI for medical devices or book a working session with your device DFMEA.

Frequently Asked Questions

Does ISO 13485 require DFMEA specifically?

ISO 13485 requires risk management during design and development but does not mandate DFMEA by name. DFMEA is the most common method used to satisfy this requirement because it provides the structured, documented hazard analysis that auditors expect. ISO 14971 Annex C identifies FMEA as one of several hazard identification techniques.

Can I use an automotive DFMEA template for medical devices?

Not directly. Automotive DFMEA templates (AIAG-VDA) do not include ISO 14971 required elements like risk acceptability decisions, residual risk evaluation, or patient-harm severity scales. You can use the automotive structure as a starting point but must add medical device-specific columns and adapt severity/probability scales for patient harm.

How often should the DFMEA be updated?

The DFMEA should be reviewed and updated when: (1) design changes occur, (2) new complaint or adverse event data is received, (3) CAPA outcomes affect risk controls, or (4) post-market surveillance reveals trends. There is no fixed schedule. The trigger is new information that could affect the risk assessment. ISO 13485 requires that risk management activities continue through the product lifecycle.

What is the difference between DFMEA and PFMEA for medical devices?

DFMEA analyzes design-related hazards (how the device design could fail to be safe or effective). PFMEA analyzes manufacturing process-related hazards (how the manufacturing process could produce a defective device). Both may be needed. DFMEA is required during design. PFMEA is required during process validation. See our DFMEA vs PFMEA comparison.



Bring one FMEA.
See what it’s missing.

Your engineers judge the output. 30 minutes.

Cookie settings
Necessary cookies keep the site working and are always on. Analytics and advertising cookies are only set if you allow them. You can change this at any time. Privacy policy
Necessary
Allow Necessary cookies.
Analytics
Allow Analytics cookies.
Advertising
Allow Advertising cookies.