Reference guide

IEC 62366-1 Usability Engineering

IEC 62366-1 defines a safety-focused usability engineering process for medical devices. It connects what users do with a device to risk management, design decisions, evaluation and the evidence used to show that use-related risks have been controlled.

This guide explains the process and its practical regulatory context. It is an independent interpretation, not a substitute for the licensed standard, and it does not guarantee conformity, clearance or approval.

In this guide

  1. 1. Scope and purpose
  2. 2. The process at a glance
  3. 3. Relationship to ISO 14971
  4. 4. Formative evaluation and validation
  5. 5. Legacy user interfaces
  6. 6. FDA and EU context
  7. 7. Usability Engineering File
  8. 8. Practical implementation checklist

What IEC 62366-1 covers

The current consolidated publication is IEC 62366-1:2015+A1:2020, edition 1.1. It specifies a process for a manufacturer to analyse, specify, develop and evaluate the usability of a medical device as it relates to safety. The emphasis matters: this is not a general customer-experience standard. Its concern is whether the user interface supports safe and effective use by the intended users, for the intended uses, in the intended use environments.

The process addresses normal use, including correct use and use error. It may help identify abnormal use, but deliberate misuse and other abnormal-use risks are not assessed or controlled through this process in the same way. The precise definitions and requirements must always be checked in the licensed standard.

IEC 62366-2 is a companion technical report containing broader explanatory guidance and methods. It helps teams interpret and apply usability engineering, but it should not be confused with the normative requirements in IEC 62366-1.

The usability engineering process at a glance

The work is iterative rather than a sequence completed once. Information about users and use environments informs risk analysis. Risk analysis focuses design requirements and evaluation. Evaluation findings then refine the user interface and the risk controls.

  1. 1. Define the use specification

    Describe the medical indication, intended patient population, intended users, use environments and operating principle. Avoid demographic labels alone: users also differ in experience, training, health literacy, sensory capability, dexterity and workload.

  2. 2. Identify user-interface characteristics related to safety

    Examine the device, packaging, labels, instructions, accessories, setup, maintenance and every interaction through which a user perceives information or acts. Identify characteristics that could influence use error and patient or user harm.

  3. 3. Identify hazards and hazard-related use scenarios

    Connect foreseeable sequences of user actions, perceptions and use errors to hazardous situations and possible harms. This is where usability engineering and risk management must share the same logic rather than maintain separate, inconsistent lists.

  4. 4. Select scenarios for summative evaluation

    Use risk, not convenience, to determine what the final evaluation must cover. The resulting critical tasks and hazard-related scenarios should remain traceable to harms, risk controls and the final test protocol.

  5. 5. Specify and develop the user interface

    Translate the use specification and risk analysis into user-interface requirements. Prefer risk control through design where practicable; information for safety and training should not compensate automatically for avoidable interface problems.

  6. 6. Evaluate, learn and validate

    Use formative evaluation throughout development to expose problems and improve the design. When the interface is sufficiently final, use summative evaluation to assess whether the remaining use-related risks are acceptable.

How IEC 62366-1 relates to ISO 14971

IEC 62366-1 provides the usability-engineering process; ISO 14971 provides the overall medical-device risk-management framework. They are complementary. Use-related hazards, sequences of events, hazardous situations, harms, risk controls and residual-risk decisions should connect to the same risk-management logic used for other sources of risk.

A strong programme therefore maintains traceability in both directions. A hazard-related use scenario should point to the relevant risk analysis and interface control. Formative findings should update both the design and the risk analysis when they reveal a new sequence of events or a faulty assumption. Summative results should support the final residual-risk evaluation, not sit as an isolated usability report.

Following a defined process creates evidence; it does not make contradictory post-market evidence disappear. Complaints, adverse events and observed workarounds can show that an earlier safety conclusion needs to be revisited.

Formative evaluation and usability validation

Formative evaluation

Formative work is for learning and design improvement. It can begin with early concepts and continue through prototypes of increasing fidelity. The method should match the question: expert review, contextual inquiry, cognitive walkthrough and simulated-use sessions answer different questions.

Its value is not the number of studies completed. Its value is the design and risk decisions made from credible evidence before the interface becomes difficult to change.

Summative evaluation

Summative evaluation, often called Human Factors validation in FDA-facing work, assesses the final or production-equivalent user interface with representative users under representative conditions. It focuses on the tasks and scenarios connected to serious harm and tests the effectiveness of the implemented controls.

Every use error, close call and difficulty needs investigation. Counting events is not enough; the root-cause analysis must explain whether the interface, information, environment, training or study design contributed and what that means for residual risk.

Legacy user interfaces

IEC 62366-1 includes a route for a user interface or part of one that was developed before the current process was applied. This is not a blanket exemption from usability engineering. The manufacturer still needs a documented evaluation using available design history, complaints, incidents, post-market data and risk information, and must address evidence of unacceptable use-related risk.

Changes to an established interface also need careful boundary setting. A change that looks small to the engineering team may alter perception, action sequences, training transfer or interactions elsewhere in the system. Consult the exact legacy-interface provisions in the licensed edition rather than relying on a generic checklist.

Relationship to FDA guidance and EU requirements

United States

FDA recognizes IEC 62366-1 edition 1.1, the 2015 edition consolidated with Amendment 1:2020, as a consensus standard under recognition number 5-129. A declaration of conformity can support a submission, but it does not replace FDA's own recommendations for Human Factors planning, validation and submission content.

In practice, teams should use IEC 62366-1 to structure the lifecycle process and use the applicable FDA guidance to shape the evidence and presentation expected in a US premarket submission. Check FDA's live recognized-standards database because recognition status and transition arrangements can change.

European Union

Under the EU Medical Device Regulation, usability evidence contributes to demonstrating that risks arising from use error have been reduced as far as possible and that the device is suitable for its intended users and environment. IEC 62366-1 is widely used as a state-of-the-art framework for that evidence.

Formal harmonisation and presumption-of-conformity status depend on the references published in the Official Journal at the relevant time. Verify the current European Commission list rather than assuming that an IEC or EN designation automatically provides presumption of conformity for a particular regulation and edition.

What belongs in the Usability Engineering File

The Usability Engineering File is the body of records demonstrating how the process was planned, performed and connected to risk management. It may reference controlled records held elsewhere; it does not need to duplicate the entire design history.

  • The usability engineering plan and responsibilities.
  • The use specification and the rationale for representative user groups and environments.
  • Safety-related user-interface characteristics and use-related risk analysis.
  • Hazard-related use scenarios, critical tasks and their selection rationale.
  • User-interface requirements and traceability to implemented risk controls.
  • Formative evaluation plans, results, observed problems and resulting decisions.
  • The summative evaluation protocol, deviations, results and root-cause analyses.
  • Residual-risk conclusions and links to the ISO 14971 risk-management file.

Completeness is not the same as coherence. Reviewers need to follow why a risk was identified, how the interface controls it, how that control was evaluated and how the result supports the final conclusion.

A practical implementation checklist

  1. Start before the design is fixed.

    Plan Human Factors alongside system engineering, design controls and risk management.

  2. Define users precisely.

    Describe capabilities, limitations, experience and training, not just job titles.

  3. Study real use conditions.

    Account for noise, lighting, protective equipment, interruptions, storage and time pressure.

  4. Keep risk analysis alive.

    Update it when research or evaluation reveals a new use error or sequence of events.

  5. Use formative studies to change the design.

    Do not treat them as rehearsals whose purpose is merely to de-risk the final study.

  6. Freeze the right interface before validation.

    Device, packaging, instructions and training should represent what users will receive.

  7. Investigate every meaningful observation.

    Use errors, close calls and difficulties can expose the same underlying design weakness.

  8. Maintain traceability.

    Make the path from harm to scenario, control, evaluation and conclusion easy to audit.

Common misunderstandings

“Usability means ease of use.”

In IEC 62366-1, usability engineering is focused on safe use, including effectiveness and efficiency where they affect safety.

“Instructions can control any use-related risk.”

Information for safety can be necessary, but risk-control priorities require teams to consider safer interface design before relying on labelling or training.

“Validation is a pass/fail test at the end.”

Validation is the culmination of the process. Unexpected observations still require causal analysis and a risk-based conclusion.

“Compliance with the standard guarantees approval.”

No standard removes the need for device-specific evidence, sound risk decisions and satisfaction of the applicable regulator's requirements.

Authoritative sources

Standards and regulatory references change. Confirm the applicable edition, recognition status and jurisdictional requirements for each device and submission.

Continue reading

Explore the full Human Factors insights library, browse the questions and concise answers in Questions answered, or read more about the author's experience and standards work.