What manual risk management really costs medtech teams
.png?width=860&height=430&name=Copy%20of%20Blog_Template%20(1).png)
Most pre-market programs duplicate every risk control across four documents: the design failure mode and effects analysis (FMEA), a separate hazard analysis file, the design verification matrix, and the risk management report. One change to a single control, from a software mitigation to a hardware interlock, requires four manual edits. And spreadsheets have no mechanism to confirm afterward that the four versions still agree.
Teams rarely price in that kind of reconciliation work when they choose to go with Google Drive or Sharepoint as their primary means of organizing their QMS. But that doesn’t mean the cost of that work is somehow impossible to pin down. So let’s take a look: what does running risk management on spreadsheet matrices and disconnected FMEA files actually cost a team (both initially and in rework) before a device reaches market?
Risk management feels manageable until it isn't
In the early days of a medtech company’s existence, it’s not crazy to use a spreadsheet for risk management. Small devices with short risk lists can fit in a single file, under a single owner, and someone can sit down and read it from start to finish in a single afternoon. Nothing about that arrangement is broken at that point.
The costs start to mount once the file has grown, the team has grown, and the design has gone through its first serious revisions. A risk list of 20 lines at concept will typically reach 80 to 120 lines by the start of verification, and be split across an FMEA, a hazard analysis, and a traceability matrix. Keeping all of that in sync starts to require near-constant maintenance, and the cost only grows as you get closer to submission.
Where the hours actually go
Consider a mid-development Class II device with roughly 80 line items across its FMEA and hazard analysis. That count is modest, and plenty of programs run well past 150. Across a typical 12 to 18 month development cycle, the design will change many times, and a meaningful share of those changes will touch a risk control, a mitigation, or a verification link.
Say 30 of those changes are significant enough to require updating the risk files. Each update requires opening the FMEA, the hazard analysis, the verification matrix, and the risk management report, confirming which rows are affected, editing them to agree, and leaving a note so the next reviewer can follow the logic. Two to four hours of careful reconciliation per change is not unusual once a file has any real size. Thirty changes at three hours each comes to 90 hours, none of which produces anything new. The whole investment goes to keeping four disconnected documents in agreement.
Submission and audit preparation add another layer on top of that. Traceability from risk to control to verification evidence has to be rebuilt by hand and proven end to end, and teams routinely lose days to that step alone, usually in the weeks before a deadline that was already tight. Added up, manual risk management costs a single pre-market program well over 100 engineering and quality hours per cycle, and that’s before counting the rework from an edit that was missed in one of the four files and caught by an auditor instead.
Why faster drafting doesn't lower the bill
There’s a reasonable (and simple) objection to all of this: we have AI now. AI can draft an FMEA in minutes, so surely the manual cost is falling just as fast, no? The thing is, drafting was always the cheap part and it was never where the hours slipped away. An AI drafted risk matrix sitting in a spreadsheet still has no live link to the design controls it’s meant to mitigate, no way to flag the three downstream rows affected by a single change, and no audit trail showing who assessed residual risk on what date. Faster typing does not create traceability.
The expensive work has always been the maintenance of a connected, provable record through design changes. A pile of documents cannot do that no matter how quickly it was generated. Teams still need a connected, validated, and auditable risk system, and the arrival of better drafting tools has not changed that in the slightest.
What a connected risk system changes
A connected system holds the FMEA, the hazard analysis, the controls, and their verification as one linked record rather than four files that happen to overlap. Editing one control propagates the change to every risk, requirement, and test tied to it, and mismatches are flagged instead of sitting undiscovered for months. Traceability accrues as the work happens, which leaves the submission package largely assembled rather than reconstructed under deadline pressure.
For pre-market teams, a connected system doesn’t have to mean a heavyweight enterprise rollout. Greenlight Guru gives early-stage device companies the eQMS they need to keep risk, design, and verification linked from the first FMEA, without the implementation drag that pushes so many teams to defer the decision and keep paying the manual tax instead.
The spreadsheet isn’t free. It’s a loan against your submission timeline, repaid with interest in reconciliation hours and audit scrambles. See what connected risk management looks like for a pre-market team with a personalized demo of Greenlight Guru.
Greenlight Guru is the leading cloud-based platform purpose-built for MedTech companies. The end-to-end solution streamlines product development, quality management, and clinical data management by integrating cross-functional teams, processes, and data throughout the entire product lifecycle. Greenlight Guru’s...
Related Posts
Can dFMEA and ISO 14971 Co-Exist in Medical Device Risk Management?
The Role of dFMEA in Risk Management for Medical Devices
ISO 14971 Risk Management for Medical Devices: The Definitive Guide
Get your free resource
Resource Bundle for Risk Managers




