The release of ISO 14155:2026 signals an important evolution in the conduct of medical device clinical investigations. While many organizations are focused on updating procedures, templates, and definitions, the more significant change lies in how clinical safety is managed.
The new standard reinforces the expectation that safety oversight be integrated, risk-based, and proactive, linking clinical risk assessment to study operations, monitoring activities, vendor oversight, and governance processes throughout the investigation lifecycle.
At Hart Clinical Consultants, we partner with MedTech sponsors to build safety oversight frameworks that meet evolving regulatory expectations while ensuring that the documentation and evidence generated throughout the study tell a clear, complete, and defensible safety story.
The fourth edition of ISO 14155 introduces important updates for medical device clinical investigations. For MedTech sponsors the real safety implications go beyond updating templates or refreshing definitions.
ISO 14155:2026 marks a fundamental shift: safety oversight can no longer sit in a silo. It must become a structured, risk-based, and integrated model that connects clinical risk assessment directly to operational workflows, monitoring strategies, and governance decisions. If documentation does not clearly tell the safety story of your study from protocol design through final reporting, your trial integrity and inspection readiness are at risk.
As they begin to implement the new standards, most sponsors are focused on the visible, checklist-style changes: tighter Data Monitoring Committee (DMC) expectations, formal recognition of Clinical Event Committees (CECs), clearer stopping rules, and more defined adverse event (AE) reporting pathways. Those updates matter. But assuming this is just a standard safety reporting refresh is a high-stakes operational mistake. Our team at Hart Clinical Consultants specializes in aligning safety oversight models with evolving standards, ensuring your documentation effectively tells the true safety story of your study.
1. Safety Oversight Is Expanding Beyond the Patient
Safety oversight should extend beyond enrolled participants. Sponsors must now explicitly consider users and anyone else exposed to device-related hazards, malfunctions, use errors, or procedural risks.
WHY THIS MATTERS: Device risk does not always present as a traditional participant adverse event. Risk frequently arises from device handling, usability issues, training gaps, workflow integration, or procedural interactions. Safety planning must account for the full environment in which the device is operated.
DRIVING STRATEGY WITH CLINICAL RISK ASSESSMENTS
A clinical risk assessment must be a roadmap, not a static copy of the manufacturer’s risk management file. It should demonstrate exactly how known and residual risks apply to the specific investigation by evaluating:
• The intended patient population, users, and clinical setting
• The study procedures, sample size, and follow-up duration
• The expected event profile and safety monitoring model
• Whether the study is early feasibility, pivotal, or post-market
The same device risk may require entirely different oversight depending on the population, procedure burden, or intended use. For example, a vascular closure device used in an elective, stable patient population presents a different safety profile than the same device used in an emergent, anticoagulated critical care setting. A study-specific risk assessment must drive the safety strategy—informing monitoring intensity, medical monitoring, AE strategy, DMC/CEC need, stopping criteria, and escalation thresholds—rather than simply supporting the study file.
2. Structuring Procedure Risk, AE Oversight, and Safety Surveillance
Device investigations often include procedures required for the study that are not part of normal clinical practice, such as additional imaging, invasive assessments, or extended follow-up visits. Sponsors must clearly distinguish between device-related risks, standard-of-care risks, and risks introduced by protocol-required procedures. This distinction matters because procedure-related risks can affect informed consent, AE collection, monitoring expectations, escalation rules, and decisions to pause or terminate a study.
MOVING BEYOND CASE-BY-CASE REVIEWS
Reactive, case-by-case review of adverse events is no longer sufficient. Sponsors need a structured way to evaluate whether the overall safety profile remains acceptable as data accumulates. This requires defining specific triggers for escalation based on expected event rates, observed trends, severity, and device deficiency patterns.
Furthermore, your mathematical denominator also matters. Is your event rate based on enrolled subjects, treated subjects, attempted device uses, successful implants, procedure exposure, or time in follow-up? Without this clarity, aggregate safety reviews become subjective and difficult to defend during FDA review or inspection. Sponsors must be able to explain not only what safety events occurred, but precisely how they evaluated the observed pattern.
CONNECTING AES AND DEVICE DEFICIENCIES
In device trials, an AE may be directly associated with a malfunction, use error, labeling issue, usability concern, or performance problem. Consider a scenario where an investigator struggles with a delivery system deployment mechanism. If the data workflows operate in silos, the technical issue might be logged as an isolated device deficiency, while the resulting vessel dissection is logged separately as an SAE. When these workflows operate independently, critical safety signals are missed.
Sponsors must ensure AE, SAE, device deficiency, and UADE/USADE processes are connected, reconciled, and fully traceable to generate genuine safety intelligence rather than just cleaner documentation.
3. Clear and Defensible Governance Decisions
The new standard increases scrutiny on DMC and CEC governance, demanding explicitly defined stopping criteria and event classification. Crucially, the decision not to use a committee is just as important. If a committee isn't necessary (for instance, in a low-risk, post-market study of a mature technology) that decision must be deliberate, formally documented, and backed by a robust risk-based rationale, not a passive omission.
COMMITTEE ASPECT - REQUIREMENTS & OVERSIGHT EXPECTATIONS
DMC Governance - Clearly defined stopping criteria and study modification rules.
CEC Governance - Consistent event classification criteria and clear documentation of adjudication decisions.
Non-Use Rationale - Documented, risk-based justification explaining why a committee is not required.
Independence Management - Active tracking of financial, institutional, intellectual, competitive, and operational conflicts.
Committee independence cannot be a passive, startup checklist item. Collecting conflict-of-interest forms and filing them away is no longer enough. Sponsors must proactively define how independence is managed, sponsor interactions are governed, and blinded data access is controlled throughout the study lifecycle.
4. Tailored Planning for Post-Market and Digital Health Studies
For some low-risk post-market investigations, ISO 14155:2026 supports a more proportionate, streamlined AE collection and reporting approach, provided it is appropriately justified. This does not mean less discipline; it requires strict upfront planning to prospectively define which events are exempt from routine collection and which must always be reported.
For Software as a Medical Device (SaMD) and digitally enabled products, safety risks rarely look like traditional, physical AEs. Strategies must be designed to capture and evaluate:
• Incorrect software outputs or corrupted data algorithms
• Delayed critical alerts, false positives, and false negatives
• System usability issues and workflow integration failures
• Cybersecurity vulnerabilities and data integrity concerns
Post-market and digital health studies require highly tailored safety strategies, those strategies still demand a clear rationale and rigorous execution.
ARE YOU READY FOR AUDIT DAY?
Before activating your next study under ISO 14155:2026, ensure your project teams can confidently answer these five questions:
1. Can we defend exactly why our safety oversight model is appropriate for this specific study design and population?
2. Can we clearly demonstrate how both device-related and procedure-related risks are being monitored and distinguished?
3. Are our AE data, device deficiency data, and potential UADE/USADE pathways operationally connected and reconciled?
4. Can we show a clear, documented pathway for how safety issues will be escalated and acted upon?
5. Can we support our choice to use—or not use—a DMC or CEC with a transparent, risk-based rationale?
Ultimately, ISO 14155:2026 serves as a definitive reminder that safety oversight must be operationally integrated. Studies that proactively manage these operational connections will benefit from cleaner execution, faster issue identification, stronger governance, and superior inspection readiness.
If you are evaluating your current safety workflows, updating your clinical protocols, or establishing defensible committee governance, Hart Clinical Consultants can help. Our team specializes in aligning safety oversight models with evolving standards, ensuring your documentation effectively tells the true safety story of your study.
Contact Hart Clinical Consultants today to review your upcoming clinical investigation strategy.
.avif)





