The apparent contradiction

Essential Performance is normally determined through risk management: performance is essential when its loss or degradation beyond specified limits would result in unacceptable risk. It is therefore reasonable to ask whether acceptable risk could lead to a conclusion that a device has no Essential Performance.

For medical electrical equipment in general, that can sometimes be the correct conclusion. The position is different, however, when the applicable particular requirements explicitly establish a minimum Essential Performance baseline for a defined product type.

Primary function and Essential Performance are not synonyms

ISO 11608-1 uses primary function to describe performance necessary for a needle-based injection system to fulfil its intended purpose. IEC 60601-1 uses Essential Performance for safety-significant clinical performance whose loss or degradation beyond specified limits would create unacceptable risk.

A primary function is therefore not automatically Essential Performance. A function can be central to intended use yet fail without creating unacceptable harm. But for an electronically driven injection system, the specific requirement concerning the electronically driven dose-delivery function establishes that function as the minimum Essential Performance starting point.

What remains risk-based

The mandatory baseline does not remove risk management. It changes the question. The engineering team should not ask whether electronically driven dose delivery can be excluded altogether; it should use the risk-management process to determine the exact characteristics, limits, operating conditions and fault conditions that make the function acceptably safe.

  • Which dose-delivery characteristics are safety-significant?
  • What measurable limits apply to dose accuracy, completeness, timing and interruption?
  • Which degraded or fault conditions could lead to unacceptable risk?
  • What protective behaviour is required when correct delivery cannot be assured?
  • Are other functions—such as detection, indication, alarms or control—also Essential Performance because they prevent unacceptable risk?

Turn the conclusion into engineering requirements

A statement that dose delivery is Essential Performance is not yet an implementable requirement. Engineers need a chain from the clinical context to measurable system behaviour and objective evidence.

  • Define the function and its clinical purpose.
  • Identify measurable performance characteristics and limits.
  • Analyse no dose, partial dose, overdose, delayed dose, interrupted dose, repeat dose and unintended dose.
  • Define the required response to loss, degradation and uncertainty.
  • Allocate controls across mechanics, electronics, software, user interaction and information supplied.
  • Specify verification methods, acceptance criteria, configurations and test conditions.

Fail safely when correct delivery cannot be assured

Where the system cannot assure correct delivery, the safe response is not simply to continue and report success. Depending on the risk analysis, the product may need to inhibit or stop delivery, prevent an unintended repeat action and give the user a clear indication that delivery was incomplete or uncertain.

The protective response must itself be specified and verified. An alarm, display message or logged event is useful only if it contributes effectively to controlling the identified risk in the intended use context.

Verify the system, not only the nominal function

Essential Performance should be verified at system level under normal conditions and under the risk-relevant fault, degraded, environmental and configuration conditions identified by the analysis. Dose accuracy testing alone is unlikely to demonstrate the full safety argument.

Traceability should show the clinical context, hazard, sequence of events, hazardous situation, risk control, Essential Performance requirement, design implementation, verification evidence and residual-risk conclusion.

A failed claim cannot be explained away

Language requiring a failure to be justified should not be treated as permission to rationalise a failed Essential Performance test. A failure should trigger investigation, assessment of the safety impact, correction where necessary, documented rationale and appropriate re-verification.

If the evidence does not demonstrate the claimed limits under the required conditions, the organisation must change the design, the limits, the risk-control strategy or the claim—and then reassess the complete safety argument.

The practical rule

For an electronically driven needle-based injection system, treat electronically driven dose delivery as the minimum Essential Performance. Use risk management to define its precise boundaries and evidence, not to remove it by concluding that the risk is already acceptable.

The broader learning treatment—including terminology, examples and verification strategy—belongs within MedTech Learning. The immediate project question remains firmly practical: what must this particular product continue to do, within what limits, so that loss or degradation does not expose the patient or user to unacceptable risk?

Key takeaways

  • For electronically driven injection systems, dose delivery is the minimum Essential Performance baseline.
  • Risk management defines the characteristics, limits, conditions, supporting controls and evidence—it is not a route to declaring none.
  • Specify and verify the complete system response to absent, degraded, interrupted, repeated or unintended delivery.
  • A failed Essential Performance claim requires investigation, correction and re-verification, not a retrospective explanation.
This article provides general educational information. Applicable requirements depend on the device, jurisdiction, lifecycle stage and current regulatory position.