A free risk analysis template built to the structure of ISO 14971:2019. It traces each hazard through a foreseeable sequence of events to a hazardous situation and then to harm, scores risk as severity multiplied by the probability of harm, and records the justification for any risk you don't reduce further. Five tabs, twenty-four columns, and five worked examples, in Excel format.

The worksheet follows the order you work in. Six stages, twenty-four columns.
Every row starts with an ID you can trace back to, the item or function the risk belongs to, and the hazard itself. Getting the hazard right matters more than it sounds. A hazard is the potential source of harm, not the failure that causes it, and starting in the wrong place bends everything downstream.
This is the part most templates leave out. The foreseeable sequence of events records how a hazard turns into a hazardous situation, including the ways people use the device incorrectly. The hazardous situation is the moment someone is exposed. The harm is what actually happens to them. These three columns are what an auditor follows when they pick one hazard and ask you to show the path.
Score severity and probability from 1 to 5 against definitions you set yourself on the Scales tab. The index and the level calculate automatically, returning acceptable, review required, or unacceptable. There is no detection factor, because a hazard you can detect is still a hazard to the patient.
Record the risk control measure and which level of the Clause 7.1 hierarchy it sits at in control option, since design controls come before protective measures and information for safety. Then two separate columns: verification of implementation for evidence the control was built, and verification of effectiveness for evidence it works. Most risk files hold the first and quietly skip the second.
Score severity prime and probability prime as they stand once the control is in place. Index prime and level prime calculate the residual risk. Some risks stay unacceptable after controls, and the file should say so rather than round down.
Reduced AFAP and AFAP justification are where you record whether the risk has been reduced as far as possible and, if not, why further reduction is not practicable. New hazard introduced covers Clause 7.4, because controls create problems of their own. Post-production reference links the entry to the complaint or field report that informed it, which is what keeps the file alive after launch. Owner and status close the row
Most risk templates available for download in medical devices are Failure Mode and Effects Analysis (FMEA) worksheets with an ISO 14971 label on them. They score risk as severity multiplied by occurrence multiplied by detection, producing a Risk Priority Number.
That method comes from automotive manufacturing. ISO 14971 does not use it.
Risk is severity and probability. The standard estimates risk as the probability of occurrence of harm combined with the severity of that harm. Detection does not appear, and there is a reason for that. A hazard the manufacturer is able to detect is still a hazard to the patient. Scoring it as lower risk because you would notice it does not make the device safer.
The chain matters more than the score. FMEA starts at a failure mode. ISO 14971 starts earlier, at the hazard, and asks you to write down the foreseeable sequence of events that turns that hazard into a hazardous situation and then into harm. A worksheet without those columns cannot show that chain, which means it cannot answer the question an auditor asks when they pick one hazard and ask you to trace it.
None of this makes FMEA useless. It is a reasonable design tool and many teams run both. The point is that an FMEA worksheet is not a risk management file, and a template that treats them as the same thing leaves you with a gap you will find during an audit rather than before one.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.