Hazard related Use Scenarios

How to identify hazard‑related use scenarios and perform a use‑related risk analysis

What manufacturers need to know about the IEC 62366‑1 requirements

April 2026

Executive Summary

Kopie von auditive Visual Haptical Feedback 3

Hazard-related use scenarios according to IEC 62366‑1 translate use and use errors into a structured and testable form and are therefore a core element of the use-related risk analysis.
The starting point is a systematic task analysis to identify safety‑critical user interface characteristics and potential use errors. Building on this, foreseeable and known hazardous situations are consolidated to cover risks arising from both plausible interaction paths and known problem areas. Hazard-related use scenarios describe sequences of events, including potential use errors, that may lead to hazardous situations. Methodologically, a sufficient level of detail in the description and a clear derivation from the identified use scenarios are essential. For the summative evaluation, a justified, risk‑based selection of the relevant scenarios is required.

The foundation: Identification of foreseeable and known hazardous situations

Use-related risk analysis establishes the connection between the user interface and risk management. It should systematically integrate two sources:

  • Foreseeable hazardous situations: Situations that may plausibly result from potential use errors.
  • Known hazardous situations: Situations known from existing data (e.g., literature, databases, post‑market information).

 

Combining both perspectives is essential: An analysis based solely on internal project knowledge may overlook typical error patterns, while research without an interaction model often leads to vague statements that are difficult to test.

From a methodological standpoint, it is advisable to compare both sources early in the process: Known hazardous situations can serve as a “reality check” (do typical patterns observed in the field correspond to similar UI or workflow structures?), while foreseeable hazardous situations help translate known risks into product‑specific, verifiable event chains. What is crucial is that hazardous situations are not treated as abstract labels but as concrete situations in which a hazard becomes effective — for example, due to incorrect parameter combinations, wrong patient association, missing monitoring response, or delayed alarm perception.

Identification of potential use errors: Systematically describing interaction as a factor contributing to risk

While the identification of known hazardous situations is more similar to a diligence task, a methodical approach is essential when developing the foreseeable hazardous situations. This involves first identifying potential use errors that could lead to hazardous situations, systematically evaluating them, and controlling them through appropriate measures. Methodologically, it is crucial that risks are not formulated in abstract terms but become traceable through concrete interaction sequences and use contexts.
The starting point, therefore, is a systematic description of use as a factor contributing to risk:
Which user groups perform which tasks, with which objectives, under which conditions, based on which information, and under which temporal or organizational constraints?

Risk Analysis

Only once this use situation is described in concrete terms can relevant use errors be derived in a reliable manner. This includes not only what is being done, but how the interaction unfolds:
Which displays are read, which controls are actuated, which decisions are made, which feedback is expected, and which system states are critical in this context. Interaction steps that appear trivial under normal circumstances can, under realistic conditions (e.g., stress, interruption, gloves, limited visibility, noise, time pressure, or concurrent tasks), lead to systematic use errors.

Task analysis as the basis for the use scenarios

A structured starting point is a task analysis based on anticipated tasks. The human–machine interaction is analyzed step by step in order to identify safety‑critical UI characteristics and potential use errors. A robust task analysis considers not only what is being done, but also under which conditions and with which cognitive demands.

To derive safety‑relevant statements, it is helpful to translate tasks into a consistent structure. This makes it possible to identify points at which users rely on critical information (e.g., status indications, limit values, warnings), where values are entered or confirmed, or where similar options may be confused. Typical risk‑contributing factors particularly arise where

  • multiple pieces of information must be integrated,

  • actions are irreversible,

  • time pressure or interruptions occur, or

  • user interfaces allow multiple states without clear state visibility.

A solid task analysis therefore explicitly incorporates existing use environment conditions and cognitive demands. This can be facilitated, for example, by applying the PCA (Perception, Cognition, Action) methodology.

When creating the analysis, consider the following questions:

  • Which work steps are performed, and which actions do they require?
  • What level of attention is necessary (e.g., monitoring in parallel with an intervention)?
  • What memory load arises (e.g., remembering parameter values before entering them)?
  • What level of interpretation is required (e.g., trend curves versus single values)?
  • What perceptual conditions apply (e.g., glare, limited visibility, gloves)?
  • Which team or handover situations are typical (e.g., shift changes, handovers in the OR)?

 

In addition, deviations should systematically be considered as “anticipated” variations:

Which steps are typically shortened in practice, which workarounds are plausible, which routines develop among experienced users — and which risks are facilitated as a result?

Developing hazard‑related use scenarios

The derivation of hazard‑related use scenarios serves to translate use‑related risks into a verifiable form.

A use scenario describes the interaction of a user with the medical device in order to achieve an outcome within a specific use environment.

A hazard‑related use scenario expands this representation by adding a sequence of events, including potential use errors, that may lead to a hazardous situation. In short:

A hazard‑related use scenario according to IEC 62366‑1 is a use scenario that can lead to a hazardous situation, particularly as a result of a use error or a reasonably foreseeable misuse (as defined in ISO 14971).

 

Essential quality criteria include:

  • Perspective: Formulation from the viewpoint of the user and the use context.

  • Level of detail: Sufficiently detailed to allow the underlying causal chains and interaction requirements to be understood.

  • Methodological sequence: First define correct use scenarios, then derive hazard‑related use scenarios from them. This makes it clear where the deviation path emerges and which UI characteristics or contextual factors are contributing.

A hazard‑related use scenario should be structured in a way that it can be directly transferred into test design and risk documentation. In practical terms, this means: 

  • clear starting conditions (system state, user role),
  • the expected correct interaction,
  • the underlying use errors and the related UI characteristics,
  • the resulting hazardous situation, hazards, and harms,
  • the assessment of the severity level in consultation with risk management,
  • the existing and additionally required risk control measures.

This results in a scenario format that is both defensible (for ISO 14971) and testable (for IEC 62366‑1).

Selection of hazard‑related use scenarios for the summative evaluation

Not every hazard‑related use scenario must necessarily be included in the summative evaluation. What matters is a transparent, risk‑based selection process with documented rationale. The selection must demonstrate that the scenarios addressed are those that are critical to the safety of use. IEC 62366‑1 specifies three permissible selection pathways:

  1. All hazard‑related use scenarios are selected for the summative tests.
  2. A subset of hazard‑related use scenarios is selected based on the severity level of the expected harm.
  3. A subset of hazard‑related use scenarios is selected based on the severity level and on additional circumstances specific to the medical device and the manufacturer.

The importance of the severity of harm becomes evident. Its classification is performed in accordance with ISO 14971. In the most recent revision, the standard developers have allowed substantial flexibility for comprehensive justification. A robust selection process makes explicit why a scenario is included in the summative evaluation. What is essential is that the selection is transparently documented and clearly demonstrates that the safety‑critical use scenarios have been covered in the summative testing, thereby aligning with the usability engineering process for medical devices.

Disclaimer

The information presented in this technical article regarding standards and regulations has been prepared to the best of the author’s knowledge and expertise. It solely reflects the author’s opinion. No guarantee can be given for the completeness, currency, or accuracy of the information provided. Standards and regulations are subject to regular revisions and changes, which may not always be reflected here immediately. This article does not constitute binding advice and does not replace the review of the applicable standards and regulations by qualified professionals or official bodies. For the application and interpretation of standards and regulations, the currently valid original documents and the respective competent organizations are always authoritative.

Contact e1749215510462

As usability engineering specialists, we at USE‑Ing. are happy to support you in the planning, execution, and documentation of use‑related risk analyses. Do you have any questions? Feel free to contact us.

The USE-Ing. Compass

Stay on course with our newsletter