Risk Analysis Methods
Systematic techniques for hazard identification and risk analysis in medical device development.
Table of Contents
Method Selection Guide
Method Application Matrix
| Method |
Best For |
Standard |
Complexity |
| FMEA |
Component/process failures |
IEC 60812 |
Medium |
| FTA |
System-level failure analysis |
IEC 61025 |
High |
| HAZOP |
Process deviations |
IEC 61882 |
Medium |
| PHA |
Early hazard screening |
- |
Low |
| Use FMEA |
Use-related hazards |
IEC 62366-1 |
Medium |
| STPA |
Software/system interactions |
- |
High |
Selection Decision Tree
What is the analysis focus?
│
├── Component failures → FMEA
│
├── System-level failure → FTA
│
├── Process deviations → HAZOP
│
├── User interaction → Use Error Analysis
│
└── Software behavior → Software FMEA/STPA
When to Use Each Method
| Project Phase |
Recommended Methods |
| Concept |
PHA, initial FTA |
| Design |
FMEA, detailed FTA |
| Development |
Use Error Analysis, Software HA |
| Verification |
FMEA review, FTA validation |
| Production |
Process FMEA |
| Post-Market |
Trend analysis, FMEA updates |
FMEA - Failure Mode and Effects Analysis
FMEA Overview
| Aspect |
Description |
| Purpose |
Identify potential failure modes and their effects |
| Approach |
Bottom-up analysis from component to system |
| Output |
Failure mode list with severity, occurrence, detection ratings |
| Standard |
IEC 60812 |
FMEA Process Workflow
- Define scope and system boundaries
- Develop functional block diagram
- Identify failure modes for each component/function
- Determine effects of each failure mode (local, next level, end)
- Assign severity rating
- Identify potential causes
- Assign occurrence rating
- Identify current controls (detection)
- Assign detection rating
- Calculate Risk Priority Number (RPN) or use risk matrix
- Determine actions for high-priority items
- Validation: All components analyzed; RPNs calculated; actions assigned for high risks
FMEA Worksheet Template
FMEA WORKSHEET
Product: [Device Name]
Subsystem: [Subsystem]
FMEA Lead: [Name]
Date: [Date]
| ID | Item/Function | Failure Mode | Effect (Local) | Effect (End) | S | Cause | O | Controls | D | RPN | Action |
|----|---------------|--------------|----------------|--------------|---|-------|---|----------|---|-----|--------|
| FM-001 | [Item] | [Mode] | [Local Effect] | [End Effect] | [1-10] | [Cause] | [1-10] | [Detection] | [1-10] | [S×O×D] | [Action] |
S = Severity (1=None, 10=Catastrophic)
O = Occurrence (1=Remote, 10=Frequent)
D = Detection (1=Certain, 10=Cannot Detect)
RPN = Risk Priority Number
Severity Rating Scale
| Rating |
Severity |
Criteria |
| 10 |
Hazardous |
Death or regulatory non-compliance |
| 9 |
Serious |
Serious injury, major function loss |
| 8 |
Major |
Significant injury, major inconvenience |
| 7 |
High |
Minor injury, significant inconvenience |
| 6 |
Moderate |
Discomfort, partial function loss |
| 5 |
Low |
Some performance loss |
| 4 |
Very Low |
Minor performance degradation |
| 3 |
Minor |
Noticeable effect, no function loss |
| 2 |
Very Minor |
Negligible effect |
| 1 |
None |
No effect |
Occurrence Rating Scale
| Rating |
Occurrence |
Probability |
| 10 |
Almost Certain |
>1 in 2 |
| 9 |
Very High |
1 in 3 |
| 8 |
High |
1 in 8 |
| 7 |
Moderately High |
1 in 20 |
| 6 |
Moderate |
1 in 80 |
| 5 |
Low |
1 in 400 |
| 4 |
Very Low |
1 in 2,000 |
| 3 |
Remote |
1 in 15,000 |
| 2 |
Very Remote |
1 in 150,000 |
| 1 |
Nearly Impossible |
<1 in 1,500,000 |
Detection Rating Scale
| Rating |
Detection |
Likelihood of Detection |
| 10 |
Absolute Uncertainty |
Cannot detect |
| 9 |
Very Remote |
Very remote chance |
| 8 |
Remote |
Remote chance |
| 7 |
Very Low |
Very low chance |
| 6 |
Low |
Low chance |
| 5 |
Moderate |
Moderate chance |
| 4 |
Moderately High |
Moderately high chance |
| 3 |
High |
High chance |
| 2 |
Very High |
Very high chance |
| 1 |
Almost Certain |
Will detect |
RPN Action Thresholds
| RPN Range |
Priority |
Action |
| >200 |
Critical |
Immediate action required |
| 100-200 |
High |
Action plan required |
| 50-100 |
Medium |
Consider action |
| <50 |
Low |
Monitor |
FTA - Fault Tree Analysis
FTA Overview
| Aspect |
Description |
| Purpose |
Determine combinations of events leading to top event |
| Approach |
Top-down deductive analysis |
| Output |
Fault tree diagram with cut sets |
| Standard |
IEC 61025 |
FTA Process Workflow
- Define top event (undesired system state)
- Identify immediate causes using logic gates
- Continue decomposition to basic events
- Draw fault tree diagram
- Identify cut sets (combinations causing top event)
- Calculate probability if quantitative analysis required
- Identify single points of failure
- Validation: All branches complete; cut sets identified; single points documented
Fault Tree Symbols
| Symbol |
Name |
Meaning |
| Rectangle |
Intermediate Event |
Event resulting from other events |
| Circle |
Basic Event |
Primary event, no further development |
| Diamond |
Undeveloped Event |
Not analyzed further |
| House |
House Event |
Event expected to occur (condition) |
| AND Gate |
AND |
All inputs required for output |
| OR Gate |
OR |
Any input causes output |
FTA Worksheet Template
FAULT TREE ANALYSIS
Top Event: [Description of undesired state]
System: [System name]
Analyst: [Name]
Date: [Date]
BASIC EVENTS:
| ID | Event | Description | Probability | Control |
|----|-------|-------------|-------------|---------|
| BE-001 | [Event] | [Description] | [P] | [Control] |
CUT SETS:
| Cut Set | Events | Order | Probability |
|---------|--------|-------|-------------|
| CS-001 | BE-001 | 1 | [P] |
| CS-002 | BE-001, BE-002 | 2 | [P] |
SINGLE POINTS OF FAILURE:
| Event | Risk | Mitigation |
|-------|------|------------|
| [Event] | [Risk assessment] | [Mitigation strategy] |
Cut Set Analysis
| Cut Set Order |
Meaning |
Criticality |
| First Order |
Single event causes top event |
Highest - single point of failure |
| Second Order |
Two events required |
High |
| Third Order |
Three events required |
Moderate |
| Higher Order |
Four+ events required |
Lower |
HAZOP - Hazard and Operability Study
HAZOP Overview
| Aspect |
Description |
| Purpose |
Identify deviations from intended operation |
| Approach |
Systematic examination using guide words |
| Output |
Deviation analysis with consequences and safeguards |
| Standard |
IEC 61882 |
HAZOP Guide Words
| Guide Word |
Meaning |
Example Application |
| NO/NOT |
Complete negation |
No flow, no signal |
| MORE |
Quantitative increase |
More pressure, more current |
| LESS |
Quantitative decrease |
Less flow, less voltage |
| AS WELL AS |
Qualitative increase |
Extra component, contamination |
| PART OF |
Qualitative decrease |
Missing component |
| REVERSE |
Logical opposite |
Reverse flow, reverse polarity |
| OTHER THAN |
Complete substitution |
Wrong material, wrong signal |
| EARLY |
Time-related |
Early activation |
| LATE |
Time-related |
Delayed response |
HAZOP Process Workflow
- Select study node (process section or component)
- Describe design intent for the node
- Apply guide words to identify deviations
- Determine causes of each deviation
- Assess consequences
- Identify existing safeguards
- Recommend actions if needed
- Validation: All nodes analyzed; all guide words applied; actions assigned
HAZOP Worksheet Template
HAZOP WORKSHEET
System: [System Name]
Node: [Node Description]
Design Intent: [What the node is supposed to do]
Team Lead: [Name]
Date: [Date]
| Guide Word | Deviation | Causes | Consequences | Safeguards | Actions |
|------------|-----------|--------|--------------|------------|---------|
| NO | [No + parameter] | [Causes] | [Consequences] | [Existing] | [Recommendations] |
| MORE | [More + parameter] | [Causes] | [Consequences] | [Existing] | [Recommendations] |
| LESS | [Less + parameter] | [Causes] | [Consequences] | [Existing] | [Recommendations] |
Use Error Analysis
Use Error Analysis Overview
| Aspect |
Description |
| Purpose |
Identify use-related hazards and mitigations |
| Approach |
Task analysis combined with error prediction |
| Output |
Use error list with risk controls |
| Standard |
IEC 62366-1 |
Use Error Categories
| Category |
Description |
Examples |
| Perception Error |
Failure to perceive information |
Missing alarm, unclear display |
| Cognition Error |
Failure to understand |
Misinterpretation, wrong decision |
| Action Error |
Incorrect physical action |
Wrong button, slip, lapse |
| Memory Error |
Failure to recall |
Forgotten step, omission |
Use Error Analysis Process
- Identify user tasks and subtasks
- Identify potential use errors for each task
- Determine consequences of each use error
- Estimate probability of use error
- Identify design features contributing to error
- Define risk control measures
- Verify control effectiveness
- Validation: All critical tasks analyzed; errors identified; controls defined
Use Error Worksheet Template
USE ERROR ANALYSIS
Device: [Device Name]
Task: [Task Description]
User: [User Profile]
Analyst: [Name]
Date: [Date]
| Step | User Action | Potential Use Error | Error Type | Cause | Consequence | S | P | Risk | Control |
|------|-------------|--------------------| -----------|-------|-------------|---|---|------|---------|
| 1 | [Action] | [Error] | [Type] | [Cause] | [Harm] | [S] | [P] | [Level] | [Control] |
Error Types: Perception (P), Cognition (C), Action (A), Memory (M)
Human Factors Risk Controls
| Control Type |
Examples |
| Design |
Forcing functions, constraints, affordances |
| Feedback |
Visual, auditory, tactile confirmation |
| Labeling |
Clear instructions, warnings, symbols |
| Training |
User education, competency verification |
| Environment |
Adequate lighting, noise reduction |
Software Hazard Analysis
Software Hazard Analysis Overview
| Aspect |
Description |
| Purpose |
Identify software contribution to hazards |
| Approach |
Analysis of software failure modes and behaviors |
| Output |
Software hazard list with safety requirements |
| Standard |
IEC 62304 |
Software Safety Classification
| Class |
Contribution to Hazard |
Rigor Required |
| A |
No contribution possible |
Basic |
| B |
Non-serious injury possible |
Moderate |
| C |
Death or serious injury possible |
High |
Software Hazard Categories
| Category |
Description |
Examples |
| Omission |
Required function not performed |
Missing safety check |
| Commission |
Incorrect function performed |
Wrong calculation |
| Timing |
Function at wrong time |
Delayed alarm |
| Value |
Function with wrong value |
Incorrect dose |
| Sequence |
Functions in wrong order |
Steps reversed |
Software FMEA Worksheet
SOFTWARE FMEA
Software Item: [Module/Function Name]
Safety Class: [A/B/C]
Analyst: [Name]
Date: [Date]
| ID | Function | Failure Mode | Cause | Effect on System | Effect on Patient | S | P | Risk | Mitigation |
|----|----------|--------------|-------|------------------|-------------------|---|---|------|------------|
| SW-001 | [Function] | [Mode] | [Cause] | [System effect] | [Patient effect] | [S] | [P] | [Level] | [Control] |
Failure Mode Types: Omission, Commission, Timing, Value, Sequence
Software Risk Controls
| Control Type |
Implementation |
| Defensive Programming |
Input validation, range checking |
| Error Handling |
Exception handling, graceful degradation |
| Redundancy |
Dual channels, voting logic |
| Watchdog |
Timeout monitoring, heartbeat |
| Self-Test |
Power-on diagnostics, runtime checks |
| Separation |
Independence of safety functions |
Traceability Requirements
| From |
To |
Purpose |
| Software Hazard |
Software Requirement |
Hazard addressed |
| Software Requirement |
Architecture |
Requirement implemented |
| Architecture |
Code |
Design realized |
| Code |
Test |
Verification coverage |
| Test |
Hazard |
Control verified |
1---2name: risk-analysis-methods3description: Systematic techniques for hazard identification and risk analysis in medical device development.4---5# Risk Analysis Methods67Systematic techniques for hazard identification and risk analysis in medical device development.89---1011## Table of Contents1213- [Method Selection Guide](#method-selection-guide)14- [FMEA - Failure Mode and Effects Analysis](#fmea---failure-mode-and-effects-analysis)15- [FTA - Fault Tree Analysis](#fta---fault-tree-analysis)16- [HAZOP - Hazard and Operability Study](#hazop---hazard-and-operability-study)17- [Use Error Analysis](#use-error-analysis)18- [Software Hazard Analysis](#software-hazard-analysis)1920---2122## Method Selection Guide2324### Method Application Matrix2526| Method | Best For | Standard | Complexity |27|--------|----------|----------|------------|28| FMEA | Component/process failures | IEC 60812 | Medium |29| FTA | System-level failure analysis | IEC 61025 | High |30| HAZOP | Process deviations | IEC 61882 | Medium |31| PHA | Early hazard screening | - | Low |32| Use FMEA | Use-related hazards | IEC 62366-1 | Medium |33| STPA | Software/system interactions | - | High |3435### Selection Decision Tree3637```38What is the analysis focus?39 │40 ├── Component failures → FMEA41 │42 ├── System-level failure → FTA43 │44 ├── Process deviations → HAZOP45 │46 ├── User interaction → Use Error Analysis47 │48 └── Software behavior → Software FMEA/STPA49```5051### When to Use Each Method5253| Project Phase | Recommended Methods |54|---------------|---------------------|55| Concept | PHA, initial FTA |56| Design | FMEA, detailed FTA |57| Development | Use Error Analysis, Software HA |58| Verification | FMEA review, FTA validation |59| Production | Process FMEA |60| Post-Market | Trend analysis, FMEA updates |6162---6364## FMEA - Failure Mode and Effects Analysis6566### FMEA Overview6768| Aspect | Description |69|--------|-------------|70| Purpose | Identify potential failure modes and their effects |71| Approach | Bottom-up analysis from component to system |72| Output | Failure mode list with severity, occurrence, detection ratings |73| Standard | IEC 60812 |7475### FMEA Process Workflow76771. Define scope and system boundaries782. Develop functional block diagram793. Identify failure modes for each component/function804. Determine effects of each failure mode (local, next level, end)815. Assign severity rating826. Identify potential causes837. Assign occurrence rating848. Identify current controls (detection)859. Assign detection rating8610. Calculate Risk Priority Number (RPN) or use risk matrix8711. Determine actions for high-priority items8812. **Validation:** All components analyzed; RPNs calculated; actions assigned for high risks8990### FMEA Worksheet Template9192```93FMEA WORKSHEET9495Product: [Device Name]96Subsystem: [Subsystem]97FMEA Lead: [Name]98Date: [Date]99100| ID | Item/Function | Failure Mode | Effect (Local) | Effect (End) | S | Cause | O | Controls | D | RPN | Action |101|----|---------------|--------------|----------------|--------------|---|-------|---|----------|---|-----|--------|102| FM-001 | [Item] | [Mode] | [Local Effect] | [End Effect] | [1-10] | [Cause] | [1-10] | [Detection] | [1-10] | [S×O×D] | [Action] |103104S = Severity (1=None, 10=Catastrophic)105O = Occurrence (1=Remote, 10=Frequent)106D = Detection (1=Certain, 10=Cannot Detect)107RPN = Risk Priority Number108```109110### Severity Rating Scale111112| Rating | Severity | Criteria |113|--------|----------|----------|114| 10 | Hazardous | Death or regulatory non-compliance |115| 9 | Serious | Serious injury, major function loss |116| 8 | Major | Significant injury, major inconvenience |117| 7 | High | Minor injury, significant inconvenience |118| 6 | Moderate | Discomfort, partial function loss |119| 5 | Low | Some performance loss |120| 4 | Very Low | Minor performance degradation |121| 3 | Minor | Noticeable effect, no function loss |122| 2 | Very Minor | Negligible effect |123| 1 | None | No effect |124125### Occurrence Rating Scale126127| Rating | Occurrence | Probability |128|--------|------------|-------------|129| 10 | Almost Certain | >1 in 2 |130| 9 | Very High | 1 in 3 |131| 8 | High | 1 in 8 |132| 7 | Moderately High | 1 in 20 |133| 6 | Moderate | 1 in 80 |134| 5 | Low | 1 in 400 |135| 4 | Very Low | 1 in 2,000 |136| 3 | Remote | 1 in 15,000 |137| 2 | Very Remote | 1 in 150,000 |138| 1 | Nearly Impossible | <1 in 1,500,000 |139140### Detection Rating Scale141142| Rating | Detection | Likelihood of Detection |143|--------|-----------|------------------------|144| 10 | Absolute Uncertainty | Cannot detect |145| 9 | Very Remote | Very remote chance |146| 8 | Remote | Remote chance |147| 7 | Very Low | Very low chance |148| 6 | Low | Low chance |149| 5 | Moderate | Moderate chance |150| 4 | Moderately High | Moderately high chance |151| 3 | High | High chance |152| 2 | Very High | Very high chance |153| 1 | Almost Certain | Will detect |154155### RPN Action Thresholds156157| RPN Range | Priority | Action |158|-----------|----------|--------|159| >200 | Critical | Immediate action required |160| 100-200 | High | Action plan required |161| 50-100 | Medium | Consider action |162| <50 | Low | Monitor |163164---165166## FTA - Fault Tree Analysis167168### FTA Overview169170| Aspect | Description |171|--------|-------------|172| Purpose | Determine combinations of events leading to top event |173| Approach | Top-down deductive analysis |174| Output | Fault tree diagram with cut sets |175| Standard | IEC 61025 |176177### FTA Process Workflow1781791. Define top event (undesired system state)1802. Identify immediate causes using logic gates1813. Continue decomposition to basic events1824. Draw fault tree diagram1835. Identify cut sets (combinations causing top event)1846. Calculate probability if quantitative analysis required1857. Identify single points of failure1868. **Validation:** All branches complete; cut sets identified; single points documented187188### Fault Tree Symbols189190| Symbol | Name | Meaning |191|--------|------|---------|192| Rectangle | Intermediate Event | Event resulting from other events |193| Circle | Basic Event | Primary event, no further development |194| Diamond | Undeveloped Event | Not analyzed further |195| House | House Event | Event expected to occur (condition) |196| AND Gate | AND | All inputs required for output |197| OR Gate | OR | Any input causes output |198199### FTA Worksheet Template200201```202FAULT TREE ANALYSIS203204Top Event: [Description of undesired state]205System: [System name]206Analyst: [Name]207Date: [Date]208209BASIC EVENTS:210| ID | Event | Description | Probability | Control |211|----|-------|-------------|-------------|---------|212| BE-001 | [Event] | [Description] | [P] | [Control] |213214CUT SETS:215| Cut Set | Events | Order | Probability |216|---------|--------|-------|-------------|217| CS-001 | BE-001 | 1 | [P] |218| CS-002 | BE-001, BE-002 | 2 | [P] |219220SINGLE POINTS OF FAILURE:221| Event | Risk | Mitigation |222|-------|------|------------|223| [Event] | [Risk assessment] | [Mitigation strategy] |224```225226### Cut Set Analysis227228| Cut Set Order | Meaning | Criticality |229|---------------|---------|-------------|230| First Order | Single event causes top event | Highest - single point of failure |231| Second Order | Two events required | High |232| Third Order | Three events required | Moderate |233| Higher Order | Four+ events required | Lower |234235---236237## HAZOP - Hazard and Operability Study238239### HAZOP Overview240241| Aspect | Description |242|--------|-------------|243| Purpose | Identify deviations from intended operation |244| Approach | Systematic examination using guide words |245| Output | Deviation analysis with consequences and safeguards |246| Standard | IEC 61882 |247248### HAZOP Guide Words249250| Guide Word | Meaning | Example Application |251|------------|---------|---------------------|252| NO/NOT | Complete negation | No flow, no signal |253| MORE | Quantitative increase | More pressure, more current |254| LESS | Quantitative decrease | Less flow, less voltage |255| AS WELL AS | Qualitative increase | Extra component, contamination |256| PART OF | Qualitative decrease | Missing component |257| REVERSE | Logical opposite | Reverse flow, reverse polarity |258| OTHER THAN | Complete substitution | Wrong material, wrong signal |259| EARLY | Time-related | Early activation |260| LATE | Time-related | Delayed response |261262### HAZOP Process Workflow2632641. Select study node (process section or component)2652. Describe design intent for the node2663. Apply guide words to identify deviations2674. Determine causes of each deviation2685. Assess consequences2696. Identify existing safeguards2707. Recommend actions if needed2718. **Validation:** All nodes analyzed; all guide words applied; actions assigned272273### HAZOP Worksheet Template274275```276HAZOP WORKSHEET277278System: [System Name]279Node: [Node Description]280Design Intent: [What the node is supposed to do]281Team Lead: [Name]282Date: [Date]283284| Guide Word | Deviation | Causes | Consequences | Safeguards | Actions |285|------------|-----------|--------|--------------|------------|---------|286| NO | [No + parameter] | [Causes] | [Consequences] | [Existing] | [Recommendations] |287| MORE | [More + parameter] | [Causes] | [Consequences] | [Existing] | [Recommendations] |288| LESS | [Less + parameter] | [Causes] | [Consequences] | [Existing] | [Recommendations] |289```290291---292293## Use Error Analysis294295### Use Error Analysis Overview296297| Aspect | Description |298|--------|-------------|299| Purpose | Identify use-related hazards and mitigations |300| Approach | Task analysis combined with error prediction |301| Output | Use error list with risk controls |302| Standard | IEC 62366-1 |303304### Use Error Categories305306| Category | Description | Examples |307|----------|-------------|----------|308| Perception Error | Failure to perceive information | Missing alarm, unclear display |309| Cognition Error | Failure to understand | Misinterpretation, wrong decision |310| Action Error | Incorrect physical action | Wrong button, slip, lapse |311| Memory Error | Failure to recall | Forgotten step, omission |312313### Use Error Analysis Process3143151. Identify user tasks and subtasks3162. Identify potential use errors for each task3173. Determine consequences of each use error3184. Estimate probability of use error3195. Identify design features contributing to error3206. Define risk control measures3217. Verify control effectiveness3228. **Validation:** All critical tasks analyzed; errors identified; controls defined323324### Use Error Worksheet Template325326```327USE ERROR ANALYSIS328329Device: [Device Name]330Task: [Task Description]331User: [User Profile]332Analyst: [Name]333Date: [Date]334335| Step | User Action | Potential Use Error | Error Type | Cause | Consequence | S | P | Risk | Control |336|------|-------------|--------------------| -----------|-------|-------------|---|---|------|---------|337| 1 | [Action] | [Error] | [Type] | [Cause] | [Harm] | [S] | [P] | [Level] | [Control] |338339Error Types: Perception (P), Cognition (C), Action (A), Memory (M)340```341342### Human Factors Risk Controls343344| Control Type | Examples |345|--------------|----------|346| Design | Forcing functions, constraints, affordances |347| Feedback | Visual, auditory, tactile confirmation |348| Labeling | Clear instructions, warnings, symbols |349| Training | User education, competency verification |350| Environment | Adequate lighting, noise reduction |351352---353354## Software Hazard Analysis355356### Software Hazard Analysis Overview357358| Aspect | Description |359|--------|-------------|360| Purpose | Identify software contribution to hazards |361| Approach | Analysis of software failure modes and behaviors |362| Output | Software hazard list with safety requirements |363| Standard | IEC 62304 |364365### Software Safety Classification366367| Class | Contribution to Hazard | Rigor Required |368|-------|------------------------|----------------|369| A | No contribution possible | Basic |370| B | Non-serious injury possible | Moderate |371| C | Death or serious injury possible | High |372373### Software Hazard Categories374375| Category | Description | Examples |376|----------|-------------|----------|377| Omission | Required function not performed | Missing safety check |378| Commission | Incorrect function performed | Wrong calculation |379| Timing | Function at wrong time | Delayed alarm |380| Value | Function with wrong value | Incorrect dose |381| Sequence | Functions in wrong order | Steps reversed |382383### Software FMEA Worksheet384385```386SOFTWARE FMEA387388Software Item: [Module/Function Name]389Safety Class: [A/B/C]390Analyst: [Name]391Date: [Date]392393| ID | Function | Failure Mode | Cause | Effect on System | Effect on Patient | S | P | Risk | Mitigation |394|----|----------|--------------|-------|------------------|-------------------|---|---|------|------------|395| SW-001 | [Function] | [Mode] | [Cause] | [System effect] | [Patient effect] | [S] | [P] | [Level] | [Control] |396397Failure Mode Types: Omission, Commission, Timing, Value, Sequence398```399400### Software Risk Controls401402| Control Type | Implementation |403|--------------|----------------|404| Defensive Programming | Input validation, range checking |405| Error Handling | Exception handling, graceful degradation |406| Redundancy | Dual channels, voting logic |407| Watchdog | Timeout monitoring, heartbeat |408| Self-Test | Power-on diagnostics, runtime checks |409| Separation | Independence of safety functions |410411### Traceability Requirements412413| From | To | Purpose |414|------|------|---------|415| Software Hazard | Software Requirement | Hazard addressed |416| Software Requirement | Architecture | Requirement implemented |417| Architecture | Code | Design realized |418| Code | Test | Verification coverage |419| Test | Hazard | Control verified |