<?xml version="1.0" encoding="UTF-8"?><toc><section id="sec_foreword"><title>FOREWORD</title></section><section id="sec_intro"><title>INTRODUCTION</title></section><section id="sec_1"><label>1</label><title>General</title><section id="sec_1.1"><label>1.1</label><title>Scope</title></section><section id="sec_1.2"><label>1.2</label><title>Normative references</title></section></section><section id="sec_2"><label>2</label><title>Terms and definitions</title></section><section id="sec_3"><label>3</label><title>General requirements for risk management</title><section id="sec_3.1"><label>3.1</label><title>Risk management process</title><section id="sec_3.1.1"><label>3.1.1</label><title>General</title></section><section id="sec_3.1.2"><label>3.1.2</label><title>Iteration</title></section><section id="sec_3.1.3"><label>3.1.3</label><title>Pro-active or reactive design approach to safety</title></section><section id="sec_3.1.4"><label>3.1.4</label><title>Characteristics of safe systems incorporating software</title></section></section><section id="sec_3.2"><label>3.2</label><title>Management responsibilities</title></section><section id="sec_3.3"><label>3.3</label><title>Qualification of personnel</title><section id="sec_3.3.1"><label>3.3.1</label><title>General</title></section><section id="sec_3.3.2"><label>3.3.2</label><title>Intended use/domain knowledge</title></section><section id="sec_3.3.3"><label>3.3.3</label><title>Programming experience and attitude</title></section></section><section id="sec_3.4"><label>3.4</label><title>Risk management plan</title><section id="sec_3.4.1"><label>3.4.1</label><title>General</title></section><section id="sec_3.4.2"><label>3.4.2</label><title>Relationship between risk management plan and software development plan</title></section><section id="sec_3.4.3"><label>3.4.3</label><title>Specific risk-related topics of the software development plan according to </title></section></section><section id="sec_3.5"><label>3.5</label><title>Risk management file</title></section></section><section id="sec_4"><label>4</label><title>Risk analysis</title><section id="sec_4.1"><label>4.1</label><title>Risk analysis process</title></section><section id="sec_4.2"><label>4.2</label><title>Intended use and identification of characteristics related to the safety of the medical device</title><section id="sec_4.2.1"><label>4.2.1</label><title>General</title></section><section id="sec_4.2.2"><label>4.2.2</label><title>User interface</title></section><section id="sec_4.2.3"><label>4.2.3</label><title>Medical device interconnection</title></section></section><section id="sec_4.3"><label>4.3</label><title>Identification of hazards</title></section><section id="sec_4.4"><label>4.4</label><title>Estimation of the risk(s) for each hazardous situation</title><section id="sec_4.4.1"><label>4.4.1</label><title>General</title></section><section id="sec_4.4.2"><label>4.4.2</label><title>Methods of identification</title></section><section id="sec_4.4.3"><label>4.4.3</label><title>Probability</title></section><section id="sec_4.4.4"><label>4.4.4</label><title>Severity</title></section></section></section><section id="sec_5"><label>5</label><title>Risk evaluation</title></section><section id="sec_6"><label>6</label><title>Risk control</title><section id="sec_6.1"><label>6.1</label><title>Risk reduction</title></section><section id="sec_6.2"><label>6.2</label><title>Risk control option analysis</title><section id="sec_6.2.1"><label>6.2.1</label><title>Choosing risk control options for complex systems</title><section id="sec_6.2.1.1"><label>6.2.1.1</label><title>General</title></section><section id="sec_6.2.1.2"><label>6.2.1.2</label><title>Inherent safety by design</title></section><section id="sec_6.2.1.3"><label>6.2.1.3</label><title>Protective measures</title></section><section id="sec_6.2.1.4"><label>6.2.1.4</label><title>Information for safety</title></section><section id="sec_6.2.1.5"><label>6.2.1.5</label><title>Which events need risk control measures?</title></section></section><section id="sec_6.2.2"><label>6.2.2</label><title>Risk control methods</title><section id="sec_6.2.2.1"><label>6.2.2.1</label><title>Overview</title></section><section id="sec_6.2.2.2"><label>6.2.2.2</label><title>Risk control measures and software architectural design</title><section id="sec_6.2.2.2.1"><label>6.2.2.2.1</label><title>Overview</title></section><section id="sec_6.2.2.2.2"><label>6.2.2.2.2</label><title>Inherently safe design by architecture features</title></section><section id="sec_6.2.2.2.3"><label>6.2.2.2.3</label><title>Fault tolerant architectures</title></section><section id="sec_6.2.2.2.4"><label>6.2.2.2.4</label><title>Segregation to reduce risk from software causes</title></section></section><section id="sec_6.2.2.3"><label>6.2.2.3</label><title>Details on protective measures</title></section><section id="sec_6.2.2.4"><label>6.2.2.4</label><title>Preventing and announcing hazardous situations promptly</title></section><section id="sec_6.2.2.5"><label>6.2.2.5</label><title>Risk control measures for software anomalies</title></section><section id="sec_6.2.2.6"><label>6.2.2.6</label><title>Process as a risk control measure</title></section></section><section id="sec_6.2.3"><label>6.2.3</label><title>Software of unknown provenance (soup) considerations</title></section></section><section id="sec_6.3"><label>6.3</label><title>Implementation of risk control measure(s)</title></section><section id="sec_6.4"><label>6.4</label><title>Residual risk evaluation</title></section><section id="sec_6.5"><label>6.5</label><title>Risk/benefit analysis</title></section><section id="sec_6.6"><label>6.6</label><title>Risks arising from risk control measures</title></section><section id="sec_6.7"><label>6.7</label><title>Completeness of risk control</title></section></section><section id="sec_7"><label>7</label><title>Evaluation of overall residual risk acceptability</title></section><section id="sec_8"><label>8</label><title>Risk management report</title></section><section id="sec_9"><label>9</label><title>Production and post-production information</title></section><section id="sec_A"><label>Annex A</label><title>Discussion of definitions (informative)</title></section><section id="sec_B"><label>Annex B</label><title>Examples of software causes (informative)</title></section><section id="sec_C"><label>Annex C</label><title>Potential software-related pitfalls (informative)</title></section><section id="sec_D"><label>Annex D</label><title>Life-cycle/risk management grid (informative)</title></section><section id="sec_E"><label>Annex E</label><title>Safety cases (informative)</title></section><section id="sec_bibl"><title>Bibliography</title></section></toc>