1. Learn
  2. Align
  3. Perform
  4. Review

Review9 min read

Should Security Investigators Play a Larger Role in Risk Management Audits in Global MedTech?

By J Damien Scott, Trusted Advisor

A mature security function should not be judged only by how well it prevents theft, violence, or data loss. In a global medical device company, the stronger test is whether it facilitates the mission. This article makes the case for the Office of Security Risk Management as an enterprise capability that strengthens ISO 14971 compliance and audit follow-through.

The Strategic Case

The case for using OSRM in risk management investigations and audits is not that it replaces quality, regulatory, or clinical leadership. The case is that it strengthens those functions where organizations often struggle most: fact-finding under pressure, detection of hidden failure drivers, cross-border consistency, third-party scrutiny, and closure discipline.

This argument is especially strong in medical device operations that depend on custom product configurations, multi-country distribution, third-party relationships, supply chain resilience, and sustained regulatory credibility. An OSRM should not be treated as a peripheral guard function. It should be treated as an enterprise capability.

A trained investigator does not simply ask whether a control exists. The trained investigator asks whether the control is real, whether it is functioning, and what will happen if it fails at scale.

Where OSRM Creates Return on Investment

ISO 14971 describes a comprehensive process for identifying hazards, estimating and evaluating associated risks, and monitoring the effectiveness of controls across the entire medical device life cycle. Effective risk management depends not only on design engineering and quality assurance, but also on disciplined investigation, escalation, intelligence collection, evidence handling, and cross-functional coordination. Those are core strengths of a well-led OSRM.

The ROI Case: Mission Facilitation and Support

A mature security function should not be judged only by how well it prevents loss. In a global medical device company, the stronger test is whether it facilitates the mission. An effective OSRM creates value when it improves the organization's ability to design, manufacture, distribute, audit, investigate, and recover with discipline in a regulated international environment.

GRC & Risk ManagementISO 14971MedTech riskOSRM

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes

Related reading

All articles

Review · 11 September 2026

Post Coverage Is a Protective Audit, Not a Finance Task

An unfilled post is an unprotected site, and the record that proves the post was filled is the same record that bills the client. Redesigning timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and exception review cut revenue leakage by 95% at a 127-account security enterprise. The finance result was real. The protective result was larger, and it is the one most security leaders never claim.

5 min read

Review · 10 September 2026

The After-Action Review Is Where Review Happens

Exercises produce findings. After-action reviews produce change, and only when the corrective action has an owner, a date, and a place in the next plan. Four conflict-affected operating environments, two country evacuations, and a post-earthquake recovery taught what a rigorous after-action review looks like, who has to own what comes out of it, and how findings feed threat intelligence rather than a filing cabinet.

5 min read

Review · 9 September 2026

Three Numbers a Protective Program Must Report

Activity counts are not measures. A protective program that reports patrols completed and alerts reviewed is describing effort, and effort is not what leadership is paying for. Three numbers describe effectiveness: detection time, response time, and mitigation effectiveness. Each needs a defined clock and a defined denominator, or the number is theatre. This article sets out how each was defined and moved in practice.

5 min read