Most ISO 14971 risk files start the same way: a blank spreadsheet and a lot of copying from the last project.
We put together a free ISO 14971 risk management template so your team can skip that step. It gives you a structured place to document hazards, estimate risk, and record the controls you put in place.
Download it, adapt it to your device, and put the hours into the analysis itself.
Get the free template; link in the comments 👇
#ISO14971#RiskManagement#MedicalDevices#MedTech#RegulatoryAffairs
Every Dreamforce has one theme that quietly takes over the floor. This year it was agents doing real work.
Our team spent the week in San Francisco watching that play out across sessions, demos and Campground conversations. Less "here's what AI could do." More "here's what it's already doing."
That's a useful signal for us. Smarteeva runs natively on Salesforce, and post-market quality is full of the repetitive, high-stakes work agents are getting good at.
Good week. Plenty to take back.
#Dreamforce2026#Salesforce#Agentforce#MedTech#RegulatoryAffairs
Day 1 at RAPS Convergence 2026. We are at Booth #902 for the next three days!
If you handle complaints, adverse events, or recalls and you want a straight conversation about what automation actually covers, Booth #902 is the place to be. Fifteen minutes, no pitch deck.
📍 Charlotte Convention Center.
#RAPSConvergence#RAPS2026#PostMarketSurveillance#RegulatoryAffairs#MedTech
Tomorrow, Booth 902.
If your team still moves complaint data between systems by hand, or reconciles FDA and Health Canada submissions from two different records, that is the conversation we want to have at RAPS.
We'll walk you through how decision trees, automated submissions, and field-level audit trails work on one platform: fifteen minutes, no slides.
Charlotte Convention Center, 15 to 17 September.
#RAPSConvergence#PostMarketSurveillance#FDA#MedicalDevices#QualityManagement
Five teams. One complaint. No shared system.
Quality, Regulatory, Customer Care, Product, and Risk each needed a different view of the same complaint data, with different access levels. Nothing was connecting them.
Here is how a SaMD manufacturer put all five on one platform, with submissions running to FDA and Health Canada from the same record.
Decision trees fire on intake. Regulatory submissions auto-populate from product registration. Every field-level change is audit-trailed.
Read the case study: smarteeva.com/case-studies/s…#PostMarketSurveillance#MedTech#FDA#SaMD#QualityManagementsmarteeva.com/case-studies/s…
Booth #902. Charlotte. 15 to 17 September.
We're exhibiting at RAPS Convergence 2026. Come and tell us where post-market surveillance is costing you time, and we'll show you what it looks like when complaints, adverse events, MDR filings, recalls, and risk sit in one Salesforce-native platform.
Jaime Castillo is at the booth all three days. Book a slot instead of hoping to catch us between sessions: calendly.com/jaime-castillo-…#RAPSConvergence#RegulatoryAffairs#MedicalDeviceslinkedin.com/events/75030607…
We're exhibiting at RAPS Convergence 2026 in Charlotte, North Carolina, 15 to 17 September.
Find us at Booth #902. If you work in regulatory affairs or post-market quality, come and say hello.
Preconference workshops run 14 and 15 September.
#RAPSConvergence#RegulatoryAffairs#MedTech#QualityManagement
Seven hundred hazards. Three hundred and twenty product categories.
A risk assessment built by hand in Excel, with the final report assembled in Word. Each one took several weeks of skilled quality engineering time, which meant roughly thirty reports a year across the whole portfolio.
That is not a resourcing failure. It is arithmetic. Checking one occurrence estimate means counting every complaint mapped to a specific hazard, then normalising that count against units in the field. Repeat across 700 hazards and the annual cycle explains itself.
A leading insulin delivery manufacturer now generates the same report in 8 minutes.
The new case study covers how: hazards held as records rather than spreadsheet rows, IMDRF Annex codes carrying the mapping from complaint to hazard, install base pulled from the systems that hold it, and nine orchestrations running more than 250 configured steps against their own risk file.
Two months from first workshop to production.
Download Case Study: smarteeva.com/case-studies/c…#RiskManagement#ISO14971#PostMarketSurveillance#MedTech#QualityManagementsmarteeva.com/case-studies/c…
Auditors have changed the question they ask about risk management.
It used to be "show me your risk management file." It is now closer to "show me how this complaint trend changed your risk file."
Those two questions need very different systems to answer well.
The second one requires three things to be true before a complaint counts as evidence about a hazard:
The complaint has to point at a specific hazard, not a product or a category.
The hazards have to be countable, which they are not if the risk file is a spreadsheet and the complaints live somewhere else.
The denominator has to be reachable, because occurrence is a rate and unit volumes sit in ERP rather than the quality system.
Most quality architectures deliver none of the three. The risk module and the complaint module were designed as neighbours rather than as one system.
New on the blog: what it takes to close that loop, and a five-minute exercise to find out whether it exists at your organisation.
Read here: smarteeva.com/blog/connectin…#RiskManagement#ISO14971#PostMarketSurveillance#MedTech#QualityManagementsmarteeva.com/blog/connectin…
A device's real-world failure rate starts drifting above what the risk file assumed in February.
The annual risk review happens in November.
That is nine months where the evidence sat in the complaint records, and nobody was looking.
Our CEO, Plarent Ymeri, wrote about that gap for The AI Innovator, and about why it exists. Reconciling every hazard against twelve months of complaints, adverse events and nonconformances, then normalising each count against units sold, is weeks of skilled quality engineering time. Do that across hundreds of hazards and dozens of product families and the annual cycle stops looking like a choice.
The piece makes a second point worth sitting with. Most companies run signal detection and risk management as two separate programmes. One hunts for trends. The other checks old assumptions on a schedule.
They are asking the same question in different words.
Read it: theaiinnovator.com/how-ai-is…#RiskManagement#ISO14971#MedTech#QualityManagement#PostMarketSurveillancetheaiinnovator.com/how-ai-is…
Two things go wrong when teams automate regulatory reporting.
⚠️ Hand everything to a language model and you inherit a problem with numerical accuracy, reproducibility and traceability. Those are the three properties a regulator examines first.
⚠️ Build it entirely from deterministic rules and you get a brittle system that breaks the moment a complaint narrative uses unfamiliar wording.
The answer is a boundary, not a choice.
Formulas and queries establish every quantitative fact: complaint counts, installed base, sales volumes, calculated rates. Same inputs, same result, every time, traceable back to source records.
Language models do the work that needs contextual reasoning. Classifying unstructured complaint narratives, characterising trends, drafting the analysis.
Deterministic controls then verify the totals before anything reaches the narrative. Qualified reviewers approve the conclusions.
We wrote up the architecture from a customer's risk assessment automation, including where we drew the line and why.
Click the link below to read 👇
#AIinMedTech#PostMarketSurveillance#MedTech#QualityManagement#RegulatoryAffairssmarteeva.com/blog/blog-hybr…
A chatbot waits for you to ask. An agent acts on the workflow.
That is the whole distinction, and it decides whether AI helps a quality team or adds a step.
With a chatbot, someone exports the complaint, pastes it in, reads the answer, and types the result back into the system of record. Two problems follow.
The documentation work doubles. And the reasoning never enters the audit trail, so when an auditor asks how a complaint was classified, there is no answer attached to the record.
An agent runs where the record already lives. It triggers when a complaint arrives, populates what it can, and logs every action against the record with a timestamp.
See how it works: smarteeva.com/platform/ai-au…#MedTech#PostMarketSurveillance#AgenticAI#QualityManagement
96% first-pass extraction accuracy on complaint field data.
That number means a quality investigator opens a complaint record and the fields are already right. No re-reading the PDF. No re-typing the lot number. No checking whether the unit conversion happened. Data validation on that account went from 2-3 hours per complaint to 15-20 minutes.
The 4% that isn't first-pass gets flagged for a human instead of guessed at.
Download Case Study: smarteeva.com/case-studies/t…#PostMarketSurveillance#MedTech#ComplaintManagement#AI
They had already tried AI. It didn't work.
Not because AI failed, but because generic AI does not understand MedTech compliance. What they got was keyword search and surface-level summaries nobody used for real decisions. The tool was available. Nobody trusted it enough to use it.
In their words: "We didn't need another AI tool that generates summaries nobody reads. We needed an embedded co-worker."
So we embedded agentic AI inside the complaint workflow instead of bolting it on. Agents that understand device-specific terminology, FDA 21 CFR Part 803, and EU MDR and IVDR frameworks.
What changed:
☑️ 66% more complaint throughput, no added headcount;
☑️ 96% first-pass extraction accuracy;
☑️ 60% less time on case research
☑️ Pre-submission error rate from 12-15% down to under 2%
☑️ Multi-case analysis from 3-4 days to 2-3 hours
Generic AI gave them autocomplete. This gave them capacity.
Read full case study 👇
#AgenticAI#AIinMedTech#MedTech#ComplaintManagement#QualityManagementsmarteeva.com/case-studies/t…
Most quality teams run risk management and post-market surveillance as two systems.
The complaint lands in one. The risk file lives in the other. Someone reconciles them on a schedule, usually quarterly.
EU MDR treats that as more than a workflow preference. Article 83(3) requires PMS data to be used to update the benefit-risk determination and improve risk management. When the two systems are separate, that feedback loop moves at whatever pace a person gets to it.
The gap shows up in audits as a risk file that hasn't changed since the last periodic review, sitting beside a complaint trend that shifted three months ago.
Smarteeva's Risk Management module runs FMEA, pFMEA, and dFMEA scoring, real-time dashboards, and AI risk analysis inside the same data model as Complaints and Adverse Events. No separate license, no second system.
Download Datasheet: smarteeva.com/downloads/smar…#MedTech#RiskManagement#PostMarketSurveillance#EUMDR
If you work in a health system supply chain, you have seen the range. Some recall notices arrive complete, with product codes, lot numbers, and a named contact. Others arrive as a scanned page with half the fields missing.
That difference is decided upstream, in how the notice was created.
Part 2 of our MedTech Recalls Gateway walkthrough shows the manufacturer side: how a recall letter gets built and published. Worth watching even though you will never create one, because it explains why notices coming through the Gateway land ready to act on.
Visit medtechrecalls.com/login?utm…#RecallManagement#HealthcareSupplyChain#MedTech#PatientSafetypiped.video/WKW7rQgqjeY?utm_sou…
ISO 14971 does not ask for an annual risk review. Clause 10 asks for ongoing review of production and post-production information, and reassessment when that information changes the picture.
Most teams still run it once a year. The reason is mechanical. Reconciling hundreds of hazards against a year of complaints, adverse events, and nonconformances, then normalizing each count against units sold and units produced to test whether the observed probability of occurrence still holds, takes weeks of engineering time.
Inefficiency is the smaller problem. Latency is the real one. A failure rate that starts drifting above its assumed threshold in February waits until the November review to surface.
Our new guide covers what changes when the risk file updates continuously. Read here: smarteeva.com/blog/how-smart…#ISO14971#RiskManagement#MedTech#QualityManagement#PostMarketSurveillancesmarteeva.com/blog/how-smart…