
Sign up to save your podcasts
Or


Summary
“Just having a policy in place is one thing. Having a QMS that aligns to it is the next.”
In this Let’s Talk Risk! conversation, host Naveen Agarwal speaks with Sherita Black about one of the most challenging and often misunderstood topics in ISO 14971: creating a policy for risk acceptability. The conversation goes beyond the standard’s wording and gets into the practical questions that many teams struggle with: who top management really is, how to involve them, and how to turn policy into something that actually drives decisions.
Sherita brings a strong cross-functional perspective shaped by years of experience in pharmaceutical validation, medical device design quality, complaint handling, and enterprise risk management. In her current role as Risk Management Business Process Owner at BD, she focuses on maintaining risk management procedures, aligning stakeholders, and supporting an effective risk management program across the organization.
Listen to the full 30-minute podcast or jump to a section of interest listed below.
Chapters
00:00 – Introduction02:48 – What ISO 14971 expects from top management03:54 – Why a risk management policy matters05:56 – Three approaches to risk control and acceptability08:44 – How to identify the right top management group14:32 – Risk management policy vs. quality policy18:10 – What evidence auditors expect to see24:31 – Why strong risk management can become competitive advantage
If you enjoyed this podcast, consider subscribing to the Let’s Talk Risk! newsletter.
Suggested links:
LTR: ISO 14971 Fundamentals - Risk Acceptability Policy
LTR: Top Management Responsibility for Risk Management.
LTR: LTR Risk Coach - AI-Powered Decision Support Tool.
Key Takeaways
* A risk management policy sets the framework for how an organization defines, controls, and monitors risk across the device lifecycle.
* Top management in the context of ISO 14971 should be close enough to understand the device and senior enough to allocate resources and make decisions.
* Risk acceptability is not one-size-fits-all; the policy should reflect device context, intended use, and the nature of the risks involved.
* A risk management policy may sit within the broader quality framework, but it should remain explicit and focused on safety and benefit-risk decisions.
* Auditors will look beyond the written policy and expect evidence that it is actually being executed through design controls, standards compliance, monitoring, and management review.
* Strong risk management is not just about compliance; it can improve device quality, customer trust, and long-term business performance.
Keywords
ISO 14971, risk acceptability, risk management policy, top management, medical device safety, QMSR, design controls, benefit-risk, audit readiness, risk governance
About Sherita Black
Sherita Black is a quality and regulatory leader with experience across the medical device and pharmaceutical industries. She currently serves as Risk Management Business Process Owner at Beckton-Dickinson, where she is responsible for risk management procedures and cross-functional alignment to support an effective enterprise risk management program. Her background includes design quality assurance, complaint handling, post-market surveillance, regulatory compliance, and global standards implementation, with prior roles at Philips, Regulatory and Quality Solutions, and Boehringer Ingelheim. She holds degrees in biomedical engineering and industrial and human factors engineering.
Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn.
Disclaimer
Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards.
By Where MedTech professionals gain clarity and confidence to navigate complex decisions.5
22 ratings
Summary
“Just having a policy in place is one thing. Having a QMS that aligns to it is the next.”
In this Let’s Talk Risk! conversation, host Naveen Agarwal speaks with Sherita Black about one of the most challenging and often misunderstood topics in ISO 14971: creating a policy for risk acceptability. The conversation goes beyond the standard’s wording and gets into the practical questions that many teams struggle with: who top management really is, how to involve them, and how to turn policy into something that actually drives decisions.
Sherita brings a strong cross-functional perspective shaped by years of experience in pharmaceutical validation, medical device design quality, complaint handling, and enterprise risk management. In her current role as Risk Management Business Process Owner at BD, she focuses on maintaining risk management procedures, aligning stakeholders, and supporting an effective risk management program across the organization.
Listen to the full 30-minute podcast or jump to a section of interest listed below.
Chapters
00:00 – Introduction02:48 – What ISO 14971 expects from top management03:54 – Why a risk management policy matters05:56 – Three approaches to risk control and acceptability08:44 – How to identify the right top management group14:32 – Risk management policy vs. quality policy18:10 – What evidence auditors expect to see24:31 – Why strong risk management can become competitive advantage
If you enjoyed this podcast, consider subscribing to the Let’s Talk Risk! newsletter.
Suggested links:
LTR: ISO 14971 Fundamentals - Risk Acceptability Policy
LTR: Top Management Responsibility for Risk Management.
LTR: LTR Risk Coach - AI-Powered Decision Support Tool.
Key Takeaways
* A risk management policy sets the framework for how an organization defines, controls, and monitors risk across the device lifecycle.
* Top management in the context of ISO 14971 should be close enough to understand the device and senior enough to allocate resources and make decisions.
* Risk acceptability is not one-size-fits-all; the policy should reflect device context, intended use, and the nature of the risks involved.
* A risk management policy may sit within the broader quality framework, but it should remain explicit and focused on safety and benefit-risk decisions.
* Auditors will look beyond the written policy and expect evidence that it is actually being executed through design controls, standards compliance, monitoring, and management review.
* Strong risk management is not just about compliance; it can improve device quality, customer trust, and long-term business performance.
Keywords
ISO 14971, risk acceptability, risk management policy, top management, medical device safety, QMSR, design controls, benefit-risk, audit readiness, risk governance
About Sherita Black
Sherita Black is a quality and regulatory leader with experience across the medical device and pharmaceutical industries. She currently serves as Risk Management Business Process Owner at Beckton-Dickinson, where she is responsible for risk management procedures and cross-functional alignment to support an effective enterprise risk management program. Her background includes design quality assurance, complaint handling, post-market surveillance, regulatory compliance, and global standards implementation, with prior roles at Philips, Regulatory and Quality Solutions, and Boehringer Ingelheim. She holds degrees in biomedical engineering and industrial and human factors engineering.
Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn.
Disclaimer
Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards.

92 Listeners

20 Listeners