SlideShare ist ein Scribd-Unternehmen logo
1 von 30
Downloaden Sie, um offline zu lesen
Risk Management and IEC 62304
Applying IEC 62304 Risk Management in Aligned Elements
February 2015
Elements
Medical Devices and Risk Management
 Workflows and functions drives
Risk Management
 Risk Management drives Design
 Design and Risk Management
are interdependent
 Traceability connects Design and
Risk Management
Workflows
&
Functions
Hazardous
Situation
Risk
Risk
Control
Design
Elements
Risk Management and Regulations
ISO 13485
QMS
ISO 14971
Risk
Management
IEC 62304
Software
Lifecycle
IEC 60601-1
Security in
Electromedical
devices
IEC 62366
Usability
Refers to
Refers to
Refers to
Elements
Risk Management and Regulations
ISO 13485
QMS
ISO 14971
Risk
Management
IEC 62304
Software
Lifecycle
Design &
Maintenance of
software in MD
IEC 60601-1
Security in
Electromedical
devices
IEC 62366
Usability
Affects
Affects
Affects
Elements
General Concepts of Risk Assessments
 Identify Hazards
 Evaluate Risks (likelihood &
consequences)
 Perform Risk Reduction
 Evaluate residual Risks
Elements
Risk Management in IEC 62304
 Risk drives the level of
documentation required
 Software Safety Classification of
architectural artifacts
 Risk inheritance in architecture
 Systematic risks => 100% probability
of occurrence
 Affects not only development, also
affects maintenance
Software System
Class C
Software Item
Class C
Software Unit
Class C
Software Unit
Class B
Software Item
Class A
Software Item
Class A
Elements
Documenting Medical Device Development
 Increasing number of regulations
 Development documentation is difficult,
complex and resource intensive to manage
 Aligned Elements helps you “build” a
consistent and complete documentation
 Free up valuable resources from
cumbersome administrative tasks
Elements
Aligned Elements – a medical device ALM
 Manages the DHF Design Control Items
 Version Control + Traceability + Documents
 Integrated Risk Management
 Real-time quality checks on content
 Ensures completeness and consistency
Elements
FMEA
 Concerns Safety & “Business”
 Widely adopted technique
 Versatile usage
 Probability x Severity x
Visibility
Preliminary Hazard Analysis
 Concerns Safety / Harm only
 In the early design phase
 Full device implementation is
not required
 Aligned with ISO 14971
Risk Assessments in Aligned Elements
Elements
Preliminary Hazard Analysis (PHA) Overview
Cause
(with probability)
Harm
(with severity)
Hazardous
Situation
Risk Control
Measure
Hazard
Elements
Risk Analysis Element
PHA in Aligned Elements
Cause
Harm
(with severity)
Hazardous
Situation
Risk Control
Measure
Reusable Elements
Probability of
Harm
Potential
Hazard
Elements
PHA in Aligned Elements
Elements
Aligned Elements PHA in Word
Elements
Risk Analysis
PHA and Traceability
Cause 1
Measure 1
Cause 2
Cause 3
Measure 2
Measure 3
SW Use Case
HW Function
SW Item
SW
Requirement
Instructions
For Use
HW
Specification
Potential
Hazards
Elements
Aligned Elements as Risk Management Tool
 Automatic calculation of RPN
 Automatic checks of RPN against
thresholds
 Reuse of Harms, Causes and Measures
 Measures grouped and sorted according
to Risk Reduction Type
 Highlighting of insufficiently controlled
risks
 Highlighting of unimplemented Measures
 Risk elements integrated with Design
trace landscape
Elements
Risk Management in IEC 62304
Cause
Hazardous
Situation
Risk Reduction
Measure
Hazard Software Item
Software
Requirement
Verification
IEC 62304 – 7.3.3 Document Traceability
Elements
Risk Analysis
IEC 62304 PHA in Aligned Elements
Cause
Measure
Software Item
(with classification)
SW
Requirement
Verification
Harm
Does classification
match Harms in the
Risk Analysis?
Hazardous
Situation
Are Risk Control
Measures implemented
and verified?
Elements
Software Safety Classification (SSC) in Aligned
Automatic Rule Checks:
 Is SSC consistent with severity of
(implicitly) linked Harms?
 Is SSC consistent with classification
of dependent Software Items?
Specify Rules:
 SSC inheritance of Software Items
 Software Item must trace to Cause
 Connect Severity of Harm with SSC
Severity of Harm Classification
5 or 4 C
3 or 2 B
1 A
Elements
Risk Analysis
SSC example in Aligned Elements
Cause
Software Item
(Class B)
SW Unit
(Class C)
Harm
Severity: 5
Not OK!
Not OK!
Severity of Harm Classification
5 or 4 C
3 or 2 B
1 A
Elements
IEC 62304 and Probability in Risk Management
 Software error probability is difficult
to estimate
 Software errors are systematic
 IEC 62304 claims that Software
Safety Classification shall not
depend on probability, only on harm
 Assume Probability of software
error = 100% (section 4.3. a)
 Can we reduce the probability with
our Risk Control Measures?
Elements
Use two probabilities:
 Probability of Hazardous Situation (P1)
 Probability of Harm (P2)
Usage:
 P2 can be estimated by professional (e.g.
a Medical Doctor)
 Adapt risk policy and thresholds
 Risk Control Measures affect P1 and P2
Using two probabilities
Software
Error
Hazardous
Situation
Harm
P1
P2
Elements
Two probabilities in Aligned Elements
Elements
Two probabilities in Aligned Elements
Elements
Architecture vs. Functional Usage
 Architecture: Hierarchical
decomposition of Software
into Items and Units
 Software risk emanates from
how we use the software
i.e. in which functional
context we use the software
items
 Functional use cuts across
the architecture
Use Case
1
(high risk)
Use Case
2
(mid risk)
Use Case
3
(low risk)
SW Item 1
SW Item
2
SW Item 4
SW Item
3
SW Unit
1
SW Unit
2
SW Unit
3
Elements
The Matrix Model in IEC 62304
Elements
Matrix Model in Aligned Elements
 Write Use Cases from SW Reqs
 Perform Risk Analysis on Use Cases
 Generate Causes from Use Cases
where applicable
 Create Architecture
 Map Use Cases to Software Items by
connecting Software Items to existing
Causes
 If applicable, generate new Causes
from Software Items and map back to
User CasesRisk Analysis
Causes
Software
Requirements
Harm
Hazardous
Situation
Software
Items
Elements
Software Problem Resolution Process
 Record Problem Report
 Identify Causes and perform risk
analysis
 Evaluate Risk
 Create Change Request (if
applicable)
 Verify Change
Risk AnalysisCause
Measure
Problem
Report
Change
Request
Verification
Harm Hazardous
Situation
Elements
Aligned Elements IEC 62304 Package
 Full template set for all IEC 62304 Artifacts
 Includes clear references to applicable sections in IEC 62304
 Full usage of Aligned Elements automatic consistency checks
 Integrated Checklists and Review Generators
 Preconfigured Word reports
 Preconfigured Trace Tables
 Preconfigured Queries
Elements
Maximal results, minimal effort
Thank You!Aligned AG
Binzmühlstrasse 210
CH-8050 Zürich
Switzerland
t +41 (0)44 312 50 20
f +41 (0)44 312 50 20
m info@aligned.ch
w www.aligned.ch

Weitere ähnliche Inhalte

Was ist angesagt?

THE FDA and Medical Device Cybersecurity Guidance
THE FDA and Medical Device Cybersecurity GuidanceTHE FDA and Medical Device Cybersecurity Guidance
THE FDA and Medical Device Cybersecurity Guidance
Pam Gilmore
 
Medical Device Development Lifecycle
Medical Device Development LifecycleMedical Device Development Lifecycle
Medical Device Development Lifecycle
Tim Blair
 

Was ist angesagt? (20)

An Overview for Software as a Medical Device (SaMD)
An Overview for Software as a Medical Device (SaMD)An Overview for Software as a Medical Device (SaMD)
An Overview for Software as a Medical Device (SaMD)
 
THE FDA and Medical Device Cybersecurity Guidance
THE FDA and Medical Device Cybersecurity GuidanceTHE FDA and Medical Device Cybersecurity Guidance
THE FDA and Medical Device Cybersecurity Guidance
 
ISO 13485:2016 QMS
ISO 13485:2016  QMSISO 13485:2016  QMS
ISO 13485:2016 QMS
 
mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...
mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...
mHealth Israel_The New Regulatory Challenges in Europe The Clinical Evaluatio...
 
Breakout Session: Cybersecurity in Medical Devices
Breakout Session: Cybersecurity in Medical DevicesBreakout Session: Cybersecurity in Medical Devices
Breakout Session: Cybersecurity in Medical Devices
 
Clinical evaluation: Supporting medical device product life-cycle. Applicable...
Clinical evaluation: Supporting medical device product life-cycle. Applicable...Clinical evaluation: Supporting medical device product life-cycle. Applicable...
Clinical evaluation: Supporting medical device product life-cycle. Applicable...
 
Presentation: Software as a Medical Device: Regulatory insights and Q & A
Presentation: Software as a Medical Device: Regulatory insights and Q & APresentation: Software as a Medical Device: Regulatory insights and Q & A
Presentation: Software as a Medical Device: Regulatory insights and Q & A
 
Medical Device Development Lifecycle
Medical Device Development LifecycleMedical Device Development Lifecycle
Medical Device Development Lifecycle
 
Building a QMS for Your SaMD
Building a QMS for Your SaMDBuilding a QMS for Your SaMD
Building a QMS for Your SaMD
 
CyberSecurity Medical Devices
CyberSecurity Medical DevicesCyberSecurity Medical Devices
CyberSecurity Medical Devices
 
validation and verification of medical device.pptx
validation and verification of medical device.pptxvalidation and verification of medical device.pptx
validation and verification of medical device.pptx
 
Fda quality system regulation 21 CFR820_Medical devices_k_trautman
Fda quality system regulation 21 CFR820_Medical devices_k_trautmanFda quality system regulation 21 CFR820_Medical devices_k_trautman
Fda quality system regulation 21 CFR820_Medical devices_k_trautman
 
ISO: 14971 Quality risk management of medical devices
ISO: 14971 Quality risk management  of medical devicesISO: 14971 Quality risk management  of medical devices
ISO: 14971 Quality risk management of medical devices
 
Iso 14971 2019
Iso 14971 2019Iso 14971 2019
Iso 14971 2019
 
Cybersecurity in medical devices
Cybersecurity in medical devicesCybersecurity in medical devices
Cybersecurity in medical devices
 
The European Medical Device Regulations - analysis of the final text
The European Medical Device Regulations - analysis of the final textThe European Medical Device Regulations - analysis of the final text
The European Medical Device Regulations - analysis of the final text
 
Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...
Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...
Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...
 
ISO 62304 & TIR 45
ISO 62304 & TIR 45ISO 62304 & TIR 45
ISO 62304 & TIR 45
 
Cybersecurity in Medical Devices
Cybersecurity in Medical DevicesCybersecurity in Medical Devices
Cybersecurity in Medical Devices
 
Medical Device Regulation (MDR) overview for Technion, May 25, 2021
Medical Device Regulation (MDR) overview for Technion, May 25, 2021Medical Device Regulation (MDR) overview for Technion, May 25, 2021
Medical Device Regulation (MDR) overview for Technion, May 25, 2021
 

Andere mochten auch

Abbott overview medical device human factors standards
Abbott overview medical device human factors standardsAbbott overview medical device human factors standards
Abbott overview medical device human factors standards
Jones Wu
 
ZMPCZM016000.13.03 Certificate of compliance
ZMPCZM016000.13.03 Certificate of complianceZMPCZM016000.13.03 Certificate of compliance
ZMPCZM016000.13.03 Certificate of compliance
painezeeman
 
Image segmentation ppt
Image segmentation pptImage segmentation ppt
Image segmentation ppt
Gichelle Amon
 

Andere mochten auch (20)

QAdvis - software risk management based on IEC/ISO 62304
QAdvis - software risk management based on IEC/ISO 62304QAdvis - software risk management based on IEC/ISO 62304
QAdvis - software risk management based on IEC/ISO 62304
 
Death by documentation - Medical Device Development Challenges
Death by documentation - Medical Device Development ChallengesDeath by documentation - Medical Device Development Challenges
Death by documentation - Medical Device Development Challenges
 
Compliance with medical standards iec 62304, iso 14971, iec 60601, fda title ...
Compliance with medical standards iec 62304, iso 14971, iec 60601, fda title ...Compliance with medical standards iec 62304, iso 14971, iec 60601, fda title ...
Compliance with medical standards iec 62304, iso 14971, iec 60601, fda title ...
 
ISO 14971 Risk Management - how others do it
ISO 14971 Risk Management - how others do itISO 14971 Risk Management - how others do it
ISO 14971 Risk Management - how others do it
 
Create Your Company Page
Create Your Company PageCreate Your Company Page
Create Your Company Page
 
Build Features, Not Apps
Build Features, Not AppsBuild Features, Not Apps
Build Features, Not Apps
 
Risk management in-60601-1
Risk management in-60601-1Risk management in-60601-1
Risk management in-60601-1
 
Abbott overview medical device human factors standards
Abbott overview medical device human factors standardsAbbott overview medical device human factors standards
Abbott overview medical device human factors standards
 
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability MatrixBeyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
Beyond FDA Compliance Webinar: 5 Hidden Benefits of Your Traceability Matrix
 
Product Safety Testing Reduces the Risk of Shock, Fire, Explosions
Product Safety Testing Reduces the Risk of Shock, Fire, ExplosionsProduct Safety Testing Reduces the Risk of Shock, Fire, Explosions
Product Safety Testing Reduces the Risk of Shock, Fire, Explosions
 
Human factor standards and usability (by Ed Israelski)
Human factor standards and usability (by Ed Israelski)Human factor standards and usability (by Ed Israelski)
Human factor standards and usability (by Ed Israelski)
 
Death to project documentation with eXtreme Programming
Death to project documentation with eXtreme ProgrammingDeath to project documentation with eXtreme Programming
Death to project documentation with eXtreme Programming
 
TÜV SÜD on functional safety for multi-core architectures
TÜV SÜD on functional safety for multi-core architecturesTÜV SÜD on functional safety for multi-core architectures
TÜV SÜD on functional safety for multi-core architectures
 
ZMPCZM016000.13.03 Certificate of compliance
ZMPCZM016000.13.03 Certificate of complianceZMPCZM016000.13.03 Certificate of compliance
ZMPCZM016000.13.03 Certificate of compliance
 
Building your credibility with LinkedIn
Building your credibility with LinkedInBuilding your credibility with LinkedIn
Building your credibility with LinkedIn
 
Home Healthcare, IEC 60601-1-11
Home Healthcare, IEC 60601-1-11Home Healthcare, IEC 60601-1-11
Home Healthcare, IEC 60601-1-11
 
What Is SEO? A Guide to Search Engine Optimization
What Is SEO? A Guide to Search Engine OptimizationWhat Is SEO? A Guide to Search Engine Optimization
What Is SEO? A Guide to Search Engine Optimization
 
IMAGE SEGMENTATION.
IMAGE SEGMENTATION.IMAGE SEGMENTATION.
IMAGE SEGMENTATION.
 
Image segmentation ppt
Image segmentation pptImage segmentation ppt
Image segmentation ppt
 
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
Twitter Kaepernicked by Google Plus? | Should You Use Google Plus?
 

Ähnlich wie Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM

Risk management in development of life critical systems
Risk management in development of life critical systemsRisk management in development of life critical systems
Risk management in development of life critical systems
Scott Althouse
 
Application Threat Modeling
Application Threat ModelingApplication Threat Modeling
Application Threat Modeling
Marco Morana
 

Ähnlich wie Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM (20)

Concepts in Software Safety
Concepts in Software SafetyConcepts in Software Safety
Concepts in Software Safety
 
Online Training Information Security Management
Online Training Information Security ManagementOnline Training Information Security Management
Online Training Information Security Management
 
Elements to Consider for Risk Assessment in SaMDs
Elements to Consider for Risk Assessment in SaMDsElements to Consider for Risk Assessment in SaMDs
Elements to Consider for Risk Assessment in SaMDs
 
Hazard assessment and risk management techniques
Hazard assessment and risk management techniquesHazard assessment and risk management techniques
Hazard assessment and risk management techniques
 
Risk management in development of life critical systems
Risk management in development of life critical systemsRisk management in development of life critical systems
Risk management in development of life critical systems
 
Security assessment isaca sv presentation jan 2016
Security assessment isaca sv presentation jan 2016Security assessment isaca sv presentation jan 2016
Security assessment isaca sv presentation jan 2016
 
risk-management-121021125051-phpapp02 (1).pdf
risk-management-121021125051-phpapp02 (1).pdfrisk-management-121021125051-phpapp02 (1).pdf
risk-management-121021125051-phpapp02 (1).pdf
 
Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...
 
Unit 7
Unit 7Unit 7
Unit 7
 
Risk Assessment
Risk AssessmentRisk Assessment
Risk Assessment
 
Application Threat Modeling
Application Threat ModelingApplication Threat Modeling
Application Threat Modeling
 
MBA_Project_Presentation
MBA_Project_PresentationMBA_Project_Presentation
MBA_Project_Presentation
 
Ch9
Ch9Ch9
Ch9
 
An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...
An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...
An Extended Notation of FTA for Risk Assessment of Software-intensive Medical...
 
Risk management(software engineering)
Risk management(software engineering)Risk management(software engineering)
Risk management(software engineering)
 
Software Security Initiatives
Software Security InitiativesSoftware Security Initiatives
Software Security Initiatives
 
Risk-management
 Risk-management Risk-management
Risk-management
 
Risk Assessment Model and its Integration into an Established Test Process
Risk Assessment Model and its Integration into an Established Test ProcessRisk Assessment Model and its Integration into an Established Test Process
Risk Assessment Model and its Integration into an Established Test Process
 
06 overview of_ra1
06 overview of_ra106 overview of_ra1
06 overview of_ra1
 
Software testing-and-risk-analysis
Software testing-and-risk-analysisSoftware testing-and-risk-analysis
Software testing-and-risk-analysis
 

Kürzlich hochgeladen

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Kürzlich hochgeladen (20)

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 

Applying IEC 62304 Risk Management in Aligned Elements - the medical device ALM

  • 1. Risk Management and IEC 62304 Applying IEC 62304 Risk Management in Aligned Elements February 2015
  • 2. Elements Medical Devices and Risk Management  Workflows and functions drives Risk Management  Risk Management drives Design  Design and Risk Management are interdependent  Traceability connects Design and Risk Management Workflows & Functions Hazardous Situation Risk Risk Control Design
  • 3. Elements Risk Management and Regulations ISO 13485 QMS ISO 14971 Risk Management IEC 62304 Software Lifecycle IEC 60601-1 Security in Electromedical devices IEC 62366 Usability Refers to Refers to Refers to
  • 4. Elements Risk Management and Regulations ISO 13485 QMS ISO 14971 Risk Management IEC 62304 Software Lifecycle Design & Maintenance of software in MD IEC 60601-1 Security in Electromedical devices IEC 62366 Usability Affects Affects Affects
  • 5. Elements General Concepts of Risk Assessments  Identify Hazards  Evaluate Risks (likelihood & consequences)  Perform Risk Reduction  Evaluate residual Risks
  • 6. Elements Risk Management in IEC 62304  Risk drives the level of documentation required  Software Safety Classification of architectural artifacts  Risk inheritance in architecture  Systematic risks => 100% probability of occurrence  Affects not only development, also affects maintenance Software System Class C Software Item Class C Software Unit Class C Software Unit Class B Software Item Class A Software Item Class A
  • 7. Elements Documenting Medical Device Development  Increasing number of regulations  Development documentation is difficult, complex and resource intensive to manage  Aligned Elements helps you “build” a consistent and complete documentation  Free up valuable resources from cumbersome administrative tasks
  • 8. Elements Aligned Elements – a medical device ALM  Manages the DHF Design Control Items  Version Control + Traceability + Documents  Integrated Risk Management  Real-time quality checks on content  Ensures completeness and consistency
  • 9. Elements FMEA  Concerns Safety & “Business”  Widely adopted technique  Versatile usage  Probability x Severity x Visibility Preliminary Hazard Analysis  Concerns Safety / Harm only  In the early design phase  Full device implementation is not required  Aligned with ISO 14971 Risk Assessments in Aligned Elements
  • 10. Elements Preliminary Hazard Analysis (PHA) Overview Cause (with probability) Harm (with severity) Hazardous Situation Risk Control Measure Hazard
  • 11. Elements Risk Analysis Element PHA in Aligned Elements Cause Harm (with severity) Hazardous Situation Risk Control Measure Reusable Elements Probability of Harm Potential Hazard
  • 14. Elements Risk Analysis PHA and Traceability Cause 1 Measure 1 Cause 2 Cause 3 Measure 2 Measure 3 SW Use Case HW Function SW Item SW Requirement Instructions For Use HW Specification Potential Hazards
  • 15. Elements Aligned Elements as Risk Management Tool  Automatic calculation of RPN  Automatic checks of RPN against thresholds  Reuse of Harms, Causes and Measures  Measures grouped and sorted according to Risk Reduction Type  Highlighting of insufficiently controlled risks  Highlighting of unimplemented Measures  Risk elements integrated with Design trace landscape
  • 16. Elements Risk Management in IEC 62304 Cause Hazardous Situation Risk Reduction Measure Hazard Software Item Software Requirement Verification IEC 62304 – 7.3.3 Document Traceability
  • 17. Elements Risk Analysis IEC 62304 PHA in Aligned Elements Cause Measure Software Item (with classification) SW Requirement Verification Harm Does classification match Harms in the Risk Analysis? Hazardous Situation Are Risk Control Measures implemented and verified?
  • 18. Elements Software Safety Classification (SSC) in Aligned Automatic Rule Checks:  Is SSC consistent with severity of (implicitly) linked Harms?  Is SSC consistent with classification of dependent Software Items? Specify Rules:  SSC inheritance of Software Items  Software Item must trace to Cause  Connect Severity of Harm with SSC Severity of Harm Classification 5 or 4 C 3 or 2 B 1 A
  • 19. Elements Risk Analysis SSC example in Aligned Elements Cause Software Item (Class B) SW Unit (Class C) Harm Severity: 5 Not OK! Not OK! Severity of Harm Classification 5 or 4 C 3 or 2 B 1 A
  • 20. Elements IEC 62304 and Probability in Risk Management  Software error probability is difficult to estimate  Software errors are systematic  IEC 62304 claims that Software Safety Classification shall not depend on probability, only on harm  Assume Probability of software error = 100% (section 4.3. a)  Can we reduce the probability with our Risk Control Measures?
  • 21. Elements Use two probabilities:  Probability of Hazardous Situation (P1)  Probability of Harm (P2) Usage:  P2 can be estimated by professional (e.g. a Medical Doctor)  Adapt risk policy and thresholds  Risk Control Measures affect P1 and P2 Using two probabilities Software Error Hazardous Situation Harm P1 P2
  • 22. Elements Two probabilities in Aligned Elements
  • 23. Elements Two probabilities in Aligned Elements
  • 24. Elements Architecture vs. Functional Usage  Architecture: Hierarchical decomposition of Software into Items and Units  Software risk emanates from how we use the software i.e. in which functional context we use the software items  Functional use cuts across the architecture Use Case 1 (high risk) Use Case 2 (mid risk) Use Case 3 (low risk) SW Item 1 SW Item 2 SW Item 4 SW Item 3 SW Unit 1 SW Unit 2 SW Unit 3
  • 26. Elements Matrix Model in Aligned Elements  Write Use Cases from SW Reqs  Perform Risk Analysis on Use Cases  Generate Causes from Use Cases where applicable  Create Architecture  Map Use Cases to Software Items by connecting Software Items to existing Causes  If applicable, generate new Causes from Software Items and map back to User CasesRisk Analysis Causes Software Requirements Harm Hazardous Situation Software Items
  • 27. Elements Software Problem Resolution Process  Record Problem Report  Identify Causes and perform risk analysis  Evaluate Risk  Create Change Request (if applicable)  Verify Change Risk AnalysisCause Measure Problem Report Change Request Verification Harm Hazardous Situation
  • 28. Elements Aligned Elements IEC 62304 Package  Full template set for all IEC 62304 Artifacts  Includes clear references to applicable sections in IEC 62304  Full usage of Aligned Elements automatic consistency checks  Integrated Checklists and Review Generators  Preconfigured Word reports  Preconfigured Trace Tables  Preconfigured Queries
  • 30. Thank You!Aligned AG Binzmühlstrasse 210 CH-8050 Zürich Switzerland t +41 (0)44 312 50 20 f +41 (0)44 312 50 20 m info@aligned.ch w www.aligned.ch