RI

risk-management-specialist

This tool manages the risk assessment process for medical devices following ISO 14971 standards from planning through documentation.

Install

mkdir -p .claude/skills/risk-management-specialist && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/805" && unzip -o skill.zip -d .claude/skills/risk-management-specialist && rm skill.zip

Installs to .claude/skills/risk-management-specialist

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Senior Risk Management specialist for medical device companies implementing ISO 14971 risk management throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and post-production information analysis. Use for risk management planning, risk assessments, risk control verification, and risk management file maintenance.
345 chars✓ has a “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Advanced

Key capabilities

  • Develop risk management plans
  • Identify device hazards and hazardous situations
  • Perform risk estimation and evaluation
  • Implement risk control measures
  • Maintain risk management files

How it works

It applies the ISO 14971 framework to systematically analyze, evaluate, and control risks throughout the medical device lifecycle.

Inputs & outputs

You give it
Medical device design and usage data
You get back
Risk management documentation and analysis reports

When to use risk-management-specialist

  • Create risk management plan
  • Identify device hazards
  • Document risk evaluations
  • Conduct risk control verification

About this skill

Senior Risk Management Specialist

Expert-level medical device risk management implementing ISO 14971 throughout the complete product lifecycle with comprehensive risk analysis, evaluation, control, and post-production monitoring capabilities.

Core Risk Management Competencies

1. Risk Management Process Implementation (ISO 14971)

Establish and maintain comprehensive risk management processes integrated throughout the product development and lifecycle.

Risk Management Process Framework:

ISO 14971 RISK MANAGEMENT PROCESS
├── Risk Management Planning
│   ├── Risk management plan development
│   ├── Risk acceptability criteria definition
│   ├── Risk management team formation
│   └── Risk management file establishment
├── Risk Analysis
│   ├── Intended use and reasonably foreseeable misuse
│   ├── Hazard identification and analysis
│   ├── Hazardous situation evaluation
│   └── Risk estimation and documentation
├── Risk Evaluation
│   ├── Risk acceptability assessment
│   ├── Risk benefit analysis
│   ├── Risk control necessity determination
│   └── Risk evaluation documentation
├── Risk Control
│   ├── Risk control option analysis
│   ├── Risk control measure implementation
│   ├── Residual risk evaluation
│   └── Risk control effectiveness verification
└── Production and Post-Production Information
    ├── Information collection and analysis
    ├── Risk management file updates
    ├── Risk benefit analysis review
    └── Risk control measure adjustment

2. Risk Analysis and Hazard Identification

Conduct systematic risk analysis identifying all potential hazards and hazardous situations throughout device lifecycle.

Risk Analysis Methodology:

  1. Intended Use and Context Analysis

    • Medical indication and patient population
    • Use environment and conditions
    • User characteristics and training
    • Decision Point: Define scope of risk analysis
  2. Hazard Identification Process

    • For Hardware Components: Mechanical, electrical, thermal, chemical hazards
    • For Software Components: Software failure modes per IEC 62304
    • For Combination Products: Drug-device interaction risks
    • For Connected Devices: Cybersecurity and data privacy risks
  3. Hazardous Situation Analysis

    • Sequence of events leading to hazardous situations
    • Foreseeable misuse and use error scenarios
    • Single fault condition analysis
    • Multiple fault condition evaluation

3. Risk Estimation and Evaluation

Apply systematic risk estimation methodologies ensuring consistent and defensible risk assessments.

Risk Estimation Framework:

  • Probability Assessment: Statistical data, literature, expert judgment
  • Severity Assessment: Clinical outcome evaluation and classification
  • Risk Level Determination: Risk matrix application and documentation
  • Risk Acceptability Evaluation: Criteria application and justification

Risk Evaluation Decision Tree:

RISK EVALUATION PROCESS
├── Is Risk Acceptable? (per criteria)
│   ├── YES → Document acceptable risk
│   └── NO → Proceed to risk control
├── Risk Control Implementation
│   ├── Inherent safety by design
│   ├── Protective measures
│   └── Information for safety
└── Residual Risk Evaluation
    ├── Is residual risk acceptable?
    ├── Risk benefit analysis
    └── Final risk acceptability decision

4. Risk Control Implementation and Verification

Implement comprehensive risk control measures following the hierarchy of risk control per ISO 14971.

Risk Control Hierarchy:

  1. Inherent Safety by Design

    • Design modifications eliminating hazards
    • Fail-safe design implementation
    • Redundancy and diversity application
    • Human factors engineering integration
  2. Protective Measures in the Medical Device

    • Alarms and alert systems
    • Automatic shut-off mechanisms
    • Physical barriers and shields
    • Software safety functions
  3. Information for Safety

    • User training and education
    • Labeling and instructions for use
    • Warning systems and alerts
    • Contraindications and precautions

Risk Control Verification:

  • Risk control effectiveness testing and validation
  • Verification protocol development and execution
  • Test results analysis and documentation
  • Risk control performance monitoring

Advanced Risk Management Applications

Software Risk Management (IEC 62304 Integration)

Integrate software lifecycle processes with risk management ensuring comprehensive software safety assessment.

Software Risk Management Process:

  • Software Safety Classification: Class A, B, or C determination
  • Software Hazard Analysis: Software contribution to hazardous situations
  • Software Risk Control: Architecture and design safety measures
  • Software Risk Management File: Integration with overall risk management file

Cybersecurity Risk Management

Implement cybersecurity risk management per FDA guidance and emerging international standards.

Cybersecurity Risk Framework:

  1. Cybersecurity Threat Modeling

    • Asset identification and vulnerability assessment
    • Threat source analysis and attack vector evaluation
    • Impact assessment on patient safety and device functionality
    • Cybersecurity risk estimation and prioritization
  2. Cybersecurity Controls Implementation

    • Preventive Controls: Authentication, authorization, encryption
    • Detective Controls: Monitoring, logging, intrusion detection
    • Corrective Controls: Incident response, recovery procedures
    • Compensating Controls: Additional safeguards and mitigations

Human Factors and Use Error Risk Management

Integrate human factors engineering with risk management addressing use-related risks.

Use Error Risk Management:

  • Use-Related Risk Analysis: Task analysis and use scenario evaluation
  • Use Error Identification: Critical task and use error analysis
  • Use Error Risk Estimation: Probability and severity assessment
  • Use Error Risk Control: Design controls and user interface optimization

Risk Management File Management

Risk Management Documentation

Maintain comprehensive risk management files ensuring traceability and regulatory compliance.

Risk Management File Structure:

  • Risk Management Plan: Objectives, scope, criteria, and responsibilities
  • Risk Analysis Records: Hazard identification, risk estimation, evaluation
  • Risk Control Records: Control measures, verification, validation results
  • Production and Post-Production Information: Surveillance data, updates
  • Risk Management Report: Summary of risk management activities and conclusions

Risk Management File Maintenance

Ensure risk management files remain current throughout product lifecycle.

File Maintenance Protocol:

  • Design Change Impact Assessment: Risk analysis updates for design changes
  • Post-Market Information Integration: Surveillance data incorporation
  • Risk Control Effectiveness Review: Ongoing effectiveness verification
  • Periodic Risk Management Review: Systematic file review and updates

Cross-functional Integration

Quality Management System Integration

Ensure seamless integration of risk management with quality management system processes.

QMS-Risk Management Interface:

  • Design Controls: Risk management integration in design and development
  • Document Control: Risk management file configuration management
  • CAPA Integration: Risk assessment for corrective and preventive actions
  • Management Review: Risk management performance reporting

Regulatory Submission Integration

Coordinate risk management documentation with regulatory submission requirements.

Regulatory Integration Points:

  • FDA Submissions: Risk analysis and risk management summaries
  • EU MDR Technical Documentation: Risk management file integration
  • ISO 13485 Certification: Risk management process compliance
  • Post-Market Requirements: Risk management in post-market surveillance

Clinical and Post-Market Integration

Integrate risk management with clinical evaluation and post-market surveillance activities.

Clinical-Risk Interface:

  • Clinical Risk Assessment: Clinical data integration with risk analysis
  • Clinical Investigation: Risk management in clinical study design
  • Post-Market Surveillance: Risk signal detection and evaluation
  • Clinical Evaluation Updates: Risk-benefit analysis integration

Resources

scripts/

  • risk-assessment-automation.py: Automated risk analysis workflow and documentation
  • risk-matrix-calculator.py: Risk estimation and evaluation automation
  • risk-control-tracker.py: Risk control implementation and verification tracking
  • post-production-risk-monitor.py: Post-market risk information analysis

references/

  • iso14971-implementation-guide.md: Complete ISO 14971 implementation framework
  • software-risk-management.md: IEC 62304 integration with risk management
  • cybersecurity-risk-framework.md: Medical device cybersecurity risk management
  • use-error-risk-analysis.md: Human factors risk management methodologies
  • risk-acceptability-criteria.md: Risk acceptability frameworks and examples

assets/

  • risk-templates/: Risk management plan, risk analysis, and risk control templates
  • risk-matrices/: Standardized risk estimation and evaluation matrices
  • hazard-libraries/: Medical device hazard identification libraries
  • training-materials/: Risk management training and competency programs

When not to use it

  • When the device is not subject to ISO 14971 standards

Prerequisites

ISO 14971 documentation standards

Limitations

  • Requires continuous maintenance throughout product lifecycle
  • Must integrate with existing QMS processes

How it compares

It provides a structured, standards-compliant lifecycle approach rather than informal hazard tracking.

Compared to similar skills

risk-management-specialist side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
risk-management-specialist (this skill)37moReviewAdvanced
gdpr-dsgvo-expert87moReviewAdvanced
data-privacy-compliance47moNo flagsIntermediate
juicebox-data-handling026dReviewIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

software-architecture

davila7

Guide for quality focused software architecture. This skill should be used when users want to write code, design architecture, analyze code, in any case that relates to software development.

333868

planning-with-files

davila7

Implements Manus-style file-based planning for complex tasks. Creates task_plan.md, findings.md, and progress.md. Use when starting complex multi-step tasks, research projects, or any task requiring >5 tool calls.

233106

telegram-bot-builder

davila7

Expert in building Telegram bots that solve real problems - from simple automation to complex AI-powered bots. Covers bot architecture, the Telegram Bot API, user experience, monetization strategies, and scaling bots to thousands of users. Use when: telegram bot, bot api, telegram automation, chat bot telegram, tg bot.

106130

scroll-experience

davila7

Expert in building immersive scroll-driven experiences - parallax storytelling, scroll animations, interactive narratives, and cinematic web experiences. Like NY Times interactives, Apple product pages, and award-winning web experiences. Makes websites feel like experiences, not just pages. Use when: scroll animation, parallax, scroll storytelling, interactive story, cinematic website.

101142

humanizer

davila7

Remove signs of AI-generated writing from text. Use when editing or reviewing text to make it sound more natural and human-written. Based on Wikipedia's comprehensive "Signs of AI writing" guide. Detects and fixes patterns including: inflated symbolism, promotional language, superficial -ing analyses, vague attributions, em dash overuse, rule of three, AI vocabulary words, negative parallelisms, and excessive conjunctive phrases. Credits: Original skill by @blader - https://github.com/blader/humanizer

90175

game-development

davila7

Game development orchestrator. Routes to platform-specific skills based on project needs.

70195

You might also like

gdpr-dsgvo-expert

davila7

Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance. Provides EU GDPR and German DSGVO expertise, privacy impact assessments, data protection auditing, and compliance verification. Use for GDPR compliance assessments, privacy audits, data protection planning, and regulatory compliance verification.

831

data-privacy-compliance

davila7

Data privacy and regulatory compliance specialist for GDPR, CCPA, HIPAA, and international data protection laws. Use when implementing privacy controls, conducting data protection impact assessments, ensuring regulatory compliance, or managing data subject rights. Expert in consent management, data minimization, and privacy-by-design principles.

418

juicebox-data-handling

jeremylongshore

Implement Juicebox data privacy and handling. Use when managing personal data, implementing GDPR compliance, or handling sensitive candidate information. Trigger with phrases like "juicebox data privacy", "juicebox GDPR", "juicebox PII handling", "juicebox data compliance".

011

ra-qm-skills

alirezarezvani

12 production-ready regulatory affairs and quality management skills for HealthTech/MedTech: ISO 13485 QMS, MDR 2017/745, FDA 510(k)/PMA, ISO 27001 ISMS, GDPR/DSGVO compliance, risk management (ISO 14971), CAPA, document control, and internal auditing. Python tools included (all stdlib-only). Works with Claude Code, Codex CLI, and OpenClaw.

13

arckit-au-ai-assurance

tractorjuice

[COMMUNITY] Generate an AI assurance assessment for Australian Government / regulated-sector AI systems covering DTA AI Policy v2.0, ISO 42001, AU AI Ethics Principles, and Privacy Act AI-decision notification (Dec 2026).

00

compliance-auditor

qa-aman

|

00

Search skills

Search the agent skills registry