LIVE — Last crawled: 2026-08-13 17:29 JST
Vol.1 — August 13, 2026
MSC Portal Regulatory Watch All Entries (13)
Standards, Guidance & Notices
Showing 1–10 of 13
ISO
ISO/TS 24971-2:2026
Medical devices — Guidance on the application of ISO 14971 — Part 2: Machine learning in artificial intelligence
PUBLISHED NEW Risk Management
Provides guidance on risks specific to artificial intelligence and machine learning, and on how to apply the risk management process of ISO 14971 to machine learning-enabled medical devices (MLMD). Intended to be used in conjunction with ISO 14971 and does not alter its requirements.
Published: 2026-06-17
NIST
CSWP
CSWP 34
Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration
PUBLISHED Risk Management
In-patient service demands have increased during a time when patients have experienced reduced access to hospital care. Hospital-at-Home (HaH) solutions are a form of telehealth that provide an in-patient care experience in patients’ homes, offering the potential for improved outcomes. While these are desirable benefits, HaH involves privacy and cybersecurity risks by introducing hospital-grade medical or biometric devices and information systems outside the hospital’s direct control (i.e., the patient’s home). Patient homes increasingly feature Internet of Things (IoT) devices, such as voice assistants (e.g., smart speakers), as part of a broader “smart home” ecosystem. These devices may not have capabilities that support privacy and security practices and may be used as pivot points for attackers to gain access to a hospital’s information system. This paper introduces a notional high-level smart home integration reference architecture to better un
Published: 2025-12-17
IMDRF
IMDRF/GRRP WG/N47 FINAL:2024 (Edition 2)
Essential Principles of Safety and Performance of Medical Devices and IVD Medical Devices
PUBLISHED Risk Management
Defines the internationally agreed essential principles of safety and performance that medical devices and IVD medical devices are expected to meet. Covers baseline requirements across the product life cycle, including design, manufacture, verification and risk management, with the aim of protecting patient safety and public health.
Published: 2024-04-26
CEN/
CENELEC
EN ISO 14971:2019
Medical devices - Application of risk management to medical devices (ISO 14971:2019)
PUBLISHED Risk Management
Regulation: MDR (EU) 2017/745 | Legislation: 2017/745 - Medical Devices | ESO: CEN | Amendments/Corrigenda: EN ISO 14971:2019/A11:2021 | Publication Decision: 2022/757 | Publication OJ: OJ L 138 | Start of legal effect: 17.05.2022
Published: 2022-05-17
NIST
SP
SP 800-53A Rev. 5
Assessing Security and Privacy Controls in Information Systems and Organizations
PUBLISHED NEW Risk Management
This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk management framework. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to provide organizations with the needed flexibility to conduct security and privacy control assessments that support organizational risk management processes and are aligned with the stated risk tolerance of the organization. Information on building effective security and privacy assessment plans is also provided with guidance on analyzing assessment results.
Published: 2022-01-25
NIST
SP
SP 800-53 Rev. 5
Security and Privacy Controls for Information Systems and Organizations
PUBLISHED NEW Risk Management
This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk. The controls address diverse requirements derived from mission and business needs, laws, executive orders, directives, regulations, policies, standards, and guidelines. Finally, the consolidated control catalog addresses security and privacy from a functionality perspective (i.e., the strength of functions and mechanisms provided by the controls) and from an assurance perspective (i.e., the measure of confidence in the security or privacy capability provided by the controls). Addressing functionalit
Published: 2020-12-10
JIS
Std
TR T 24971:2020
ISO/TR 24971:2020 Medical devices - Guidance on the application of ISO 14971
PUBLISHED Risk Management
This technical report provides practical guidance on developing, implementing, and maintaining medical device risk management systems in accordance with JIS T 14971:2020 and its parent standard ISO 14971:2019. Published concurrently with JIS T 14971:2020 on October 1, 2020, the document offers detailed explanations and examples to support manufacturers in applying risk management principles effectively. The guidance clarifies the relationship between ISO 14971 requirements and other standards such as IEC 62304 and IEC 62366-1, demonstrating how risk management integrates with software lifecycle and usability engineering processes. Manufacturers should consult this technical report to understand implementation best practices, including hazard analysis methodologies, risk estimation approaches, risk control strategies, and residual risk evaluation techniques. The document addresses sector-specific considerations applicable to various medical device types and provides case studies demonstrating risk management in practice. This non-normative guidance helps organizations establish robust risk management culture and documentation while ensuring compliance with both Japanese regulatory requirements and international standards.
Published: 2020-10-01
JIS
Std
JIS T 14971:2020
JIS T 14971:2020 Medical devices - Application of risk management to medical devices (equivalent to ISO 14971:2019)
PUBLISHED Risk Management
This JIS standard specifies terminology, principles, and processes for applying risk management to medical devices, including Software as a Medical Device (SaMD) and In Vitro Diagnostic devices (IVD), corresponding to ISO 14971:2019. The 2020 revision strengthens provisions for addressing security risks and aligns terminology with JIS T 0063:2020 (vocabulary for medical device risk management). Manufacturers must establish and maintain a risk management system that identifies hazards, estimates risks, implements controls, and verifies their effectiveness throughout the device lifecycle. The standard provides a structured approach to ensure patient safety by reducing risks to acceptable levels. As the foundational risk management framework under Japanese medical device regulations, this standard works in conjunction with other lifecycle standards such as JIS T 2304 and JIS T 62366-1. The document replaced JIS T 14971:2003 and represents Japan's adoption of evolving international risk management best practices.
Published: 2020-10-01
ISO
ISO/TR 24971:2020
Medical devices — Guidance on the application of ISO 14971
PUBLISHED Risk Management
Provides guidance on the application of ISO 14971:2019 for risk management of medical devices, including practical examples and clarifications.
Published: 2020-06-01
ISO
ISO 14971:2019
Medical devices — Application of risk management to medical devices
PUBLISHED Risk Management
Specifies terminology, principles and a process for risk management of medical devices, including software-only medical devices. Confirmed as current in the 2025 systematic review.
Published: 2019-12-01
1 2