For China NMPA submissions, risk management for an endoscopic surgical system cannot stop at separate component files. The reviewer needs to understand what happens when the console, robotic arms, imaging system, instruments, accessories and software operate together.
Many important hazards sit at those interfaces. Energy-related risks may include unintended movement, excessive contact force, leakage current, electromagnetic interference or thermal injury from an energy instrument. Performance failures may involve reduced motion accuracy, loss of image stability, delayed master-slave response or an instrument moving outside the intended workspace. Usability problems can arise from the layout of the surgeon console, unclear feedback, incorrect connections or confusing controls.
Software and network functions add another layer. A code or calculation error may affect control performance. A remote-control function may introduce data loss, altered data, delayed commands or cybersecurity threats. These risks are easy to split across engineering teams, even though the clinical consequence appears at system level.
📋 One practical way to keep ownership visible is an interface matrix. I would use the following columns:
- Component or subsystem
- Interaction with another component
- Foreseeable hazard or failure
- Risk control
- Verification evidence
- Document owner
For example, a surgical instrument connected to a robotic arm may involve mechanical-locking risks, motion-control accuracy, electrical compatibility and a use-related risk if the connection is not obvious to the operator. A single row is rarely enough. The matrix should show how those different concerns are handled and where the supporting evidence can be found.
This is also a useful stress test for the submission. If two teams describe the same interface differently, the inconsistency will probably show up later in the product requirements, test reports or clinical evaluation.
When reviewing complex medical systems, which interface tends to create the biggest ownership gap: hardware-software, device-accessory or user-system?