Risk ID: where critical defects hide

Traditional V&V confirms the requirements were tested.

That’s necessary. It’s not always enough.

The defects that matter most often live outside the clean requirement. They show up when real users interact with the device in ways the team didn’t fully expect, or when the system behaves correctly by component but fails in the clinical workflow.

Keystone’s Risk ID process is designed to find those blind spots before they become verification gaps, field issues, complaint trends, recalls, or regulatory delays.

We look for two root-cause patterns:

Unexpected user interaction

Real clinicians do not use devices inside perfect workflows. They transport patients, repeat steps, override assumptions, respond to alarms, manage interruptions, and make reasonable decisions under pressure.

Abnormal system behavior

Software, hardware, sensors, robotics, AI, connectivity, accessories, and user interfaces can all behave acceptably in isolation while the combined system creates risk.

Risk-to-test traceability

Risk ID turns those scenarios into traceable V&V evidence: risk control, requirement, test case, setup, abnormal behavior, user decision point, expected response, recovery path, result, and residual risk.

01

Find the blind spots

We review the device, workflow, software behavior, user interaction, alarms, system states, accessories, clinical environment, and known risk assumptions.

The goal is not to create more paperwork. The goal is to find the scenarios most likely to expose hidden defects.

02

Convert scenarios into tests

Risk ID scenarios are translated into testable conditions.

That includes abnormal workflows, interrupted use, degraded inputs, user workarounds, recovery states, timing issues, AI or automation behavior, and system interactions that standard verification can miss.

03

Connect risk to evidence

Each scenario is tied back to design controls.

Risk. Requirement. Test case. Objective evidence. Result. Residual risk.

The output is practical V&V evidence your team can defend.

AI implementation without the fear

Many medical device teams know AI can improve productivity, but they hesitate to use it on regulated projects.

That hesitation is understandable.

Uncontrolled AI can create real problems: weak traceability, undocumented assumptions, unverifiable outputs, cybersecurity concerns, model drift, hallucinated content, and evidence that will not hold up in a design-control environment.

Keystone helps teams implement AI in a controlled, practical way.

Our process keeps humans in control, defines approved use cases, validates the workflow, protects traceability, and connects AI-assisted work back to risk controls, requirements, test evidence, and quality-system expectations.

The goal is not to replace engineering judgment.

The goal is to use AI where it actually helps: higher product quality, faster verification cycles, better test coverage, cleaner documentation, stronger regression analysis, and less manual rework.

01

Define safe AI use cases

We identify where AI can support the project without creating uncontrolled risk.

Examples include test-case generation, requirements review, traceability checks, anomaly review, documentation support, regression analysis, and V&V workflow acceleration.

02

Build controls into the workflow

We define human review, approved tools, prompt discipline, data boundaries, output verification, access controls, and documentation expectations.

AI is treated as a controlled workflow, not an informal shortcut.

03

Connect AI output to evidence

AI-assisted work still has to be reviewed, verified, and connected to objective evidence.

Keystone helps teams preserve traceability from risk to requirement to test case to result, so productivity improves without weakening compliance.

Verification built for speed, scale, and evidence.

Keystone Medical Device Partners combines risk-based verification strategy, scalable automation, AI-enabled workflows, and traceable evidence so software teams can move faster without sacrificing rigor.

Risk-based V&V strategy focused on the functions and failures that matter most.

Scalable automation and AI-enabled workflows reduce repetitive effort and accelerate feedback.

Traceable, submission-ready evidence supports confident FDA review.

Software verification works best when risk, automation, and submission evidence move together.

Designed for medical device teams that need more than test execution—they need risk-based verification leadership, scalable automation, AI-enabled workflows, complete traceability, and defensible evidence prepared for FDA review.

Risk-Based Verification Strategy

Focus verification effort on the functions, hazards, interfaces, and failure modes that carry the greatest product and patient risk.

  • Risk-based test planning
  • Critical-function coverage
  • Hazard and failure-mode traceability
  • Verification priority alignment

Scalable Test Automation & AI-Enabled Workflows

Use scalable automation and AI-enabled workflows to reduce repetitive effort, improve test coverage, accelerate feedback, and help teams focus on the highest-value verification work.

  • Automated test development
  • Reusable test frameworks
  • AI-assisted workflow acceleration
  • Continuous regression testing

Traceable Evidence & Submission Readiness

Build clear, review-ready evidence through disciplined traceability, anomaly management, test records, and reporting aligned with FDA expectations.

  • Requirements-to-test traceability
  • Objective test evidence
  • Anomaly and defect documentation
  • Submission-ready verification records

Software quality built into the release.

Our experts provided software quality assurance and testing support for Clarify Medical’s connected medical-device and physician/patient portal system.

Clarify Medical

Keystone provided software quality assurance and testing support for Clarify Medical’s connected medical-device and physician/patient portal system.

Software as a Medical Device (SaMD) Verification

As Software as a Medical Device (SaMD), the product required disciplined verification across software functions, system interfaces, and physician/patient portal workflows.

Successful, Reliable Release

Clarify Medical successfully released its connected product with the quality and reliability expected of a medical device solution.

Why Keystone leaders stand out.

Risk-based verification strategy, test planning, and critical-function coverage focused on the failures that matter most.

Scalable test automation, AI-enabled workflows, reusable frameworks, and faster feedback without sacrificing rigor.

Complete traceability, objective evidence, anomaly management, and submission-ready reporting aligned for FDA review.

FAQ

What is Risk ID for medical devices?

Risk ID is Keystone’s process for identifying hidden defect scenarios that may not appear in standard requirements-based testing.

When should Risk ID be used?

Risk ID is useful before formal V&V, before design freeze, after major software changes, before FDA submission, or when field issues suggest the test strategy may have missed real-use scenarios.

What does Risk ID look for?

Risk ID looks for unexpected user interaction, abnormal system behavior, workflow interruptions, recovery states, and gaps between risk controls and test evidence.

How does Risk ID support V&V?

Risk ID turns high-risk clinical and system scenarios into traceable test cases connected to risk controls, requirements, objective evidence, results, and residual risk.