Biomedical engineering technicians testing and logging hospital equipment during a planned maintenance check

How to Build a Risk-Based Medical Equipment Maintenance Plan

A risk-based medical equipment maintenance plan directs inspection, preventive maintenance and technical resources towards the devices whose failure could cause the greatest clinical or operational harm. It starts with a trustworthy inventory, classifies risk consistently, selects effective tasks and intervals, defines corrective response, and uses maintenance data to improve the plan. It does not simply copy every manufacturer interval or apply one schedule to every asset.

This eight-step method is intended for clinical engineering leaders, biomedical technicians, hospital operations managers and governance teams. It supports a defensible plan, but it does not replace manufacturer instructions, applicable law, regulator requirements or competent engineering judgement.

What a risk-based maintenance plan should achieve

The plan should keep equipment safe and available while avoiding maintenance that adds cost or downtime without controlling a meaningful risk. The World Health Organization (WHO) medical equipment maintenance programme overview describes a maintenance strategy that includes performance and safety inspection, preventive maintenance and corrective maintenance. A hospital must organise these activities as one governed system.

The UK’s Medicines and Healthcare products Regulatory Agency (MHRA) guidance on managing medical devices similarly places maintenance within the full device lifecycle, alongside acquisition, use, incident management and disposal. Risk-based planning therefore connects engineering work orders to patient safety, service continuity, finance, procurement and replacement decisions.

Risk-based medical equipment maintenance plan at a glance

Step Main question Required output
1. Govern the plan Who owns policy, decisions and assurance? Approved scope, roles and escalation rules
2. Validate the inventory Which assets are in service and where? Complete, uniquely identified asset register
3. Classify risk What could happen if the device fails? Documented criticality and risk class
4. Select the strategy Which tasks control the relevant failure modes? Inspection, preventive, condition-based and corrective approach
5. Set intervals When should planned work occur? Evidence-based frequency and review trigger
6. Build the programme Can people, parts and access deliver the work? Scheduled workload, resources and contingencies
7. Control execution How is safe return to service demonstrated? Work-order evidence and acceptance decision
8. Review performance What do failures, delays and costs show? Improvement and replacement actions
Eight steps for building and reviewing a risk-based medical equipment maintenance plan, from governance to performance review
Performance evidence from the review step feeds back into risk scores, maintenance intervals and replacement decisions.

How to build the plan in eight steps

1. Define governance, scope and decision rights

Set the planning boundary: owned, leased, loaned and externally maintained devices; clinical areas; laboratories; connected systems; and supporting accessories. Name the accountable medical-device management group and the clinical engineering, user, procurement, infection-prevention, cybersecurity and finance roles that contribute evidence or approve decisions.

Define who may change a maintenance task or interval, who can remove an asset from service, and who accepts residual risk. Specify how recalls, adverse incidents, repeat faults and overdue work are escalated. The plan becomes auditable only when decisions have owners and records.

2. Establish a reliable equipment inventory

Give every maintainable asset a unique identifier and record its manufacturer, model, serial number, device type, location, owner, service status, acquisition date, warranty, supplier and maintenance responsibility. Add software or network information where it affects safe maintenance. Reconcile the register with physical checks, procurement records, finance data and clinical departments.

WHO’s introduction to medical equipment inventory management treats the inventory as a foundation for technology management. Unknown, duplicated or retired assets should not quietly remain in the active programme. Establish rules for commissioning new devices and decommissioning old ones so the register stays current.

3. Classify clinical and operational risk

Use a defined scoring method. At minimum, consider the clinical consequence of failure, the device’s function, likelihood or history of failure, whether failure is obvious or hidden, usage intensity, environment, redundancy and the availability of a safe substitute. A high purchase price does not automatically mean high clinical risk.

Document the scoring scale and examples. Apply it consistently to device groups, then review exceptions for individual assets with unusual use or condition. Validation by clinical users is important because engineering teams may not see how a device contributes to an actual care pathway.

4. Choose the right maintenance strategy

Match work to credible failure modes. Planned controls may include visual inspection, functional and safety testing, cleaning, calibration, lubrication, replacement of wear items, software checks or battery assessment. Condition-based maintenance may be suitable when a reliable measurement shows degradation. Corrective maintenance must remain available for faults that planned work cannot prevent.

A planned task should have a clear purpose. Ask which risk it controls, how the result is judged, what competence and tools are required, and what happens after a failed test. EPW’s supporting comparison of preventive and corrective maintenance for medical equipment explains when each approach fits the lifecycle.

5. Set evidence-based tasks and intervals

Start with manufacturer instructions and applicable legal, regulatory or accreditation requirements. Then consider risk, usage, environment, failure history, service notices and the effectiveness of previous tasks. Any alternative interval or task should have a documented rationale, competent approval and performance monitoring.

A shorter interval is not automatically safer. Unnecessary intervention can consume scarce capacity, create downtime or introduce faults. Conversely, repeated breakdowns, adverse trends or a new safety notice may justify more frequent work or immediate removal from service. Define these review triggers before the programme begins.

Risk matrix linking clinical consequence and failure detectability to maintenance priority and control strength
Higher-consequence and less detectable failures call for stronger planned controls and escalation.

6. Convert the strategy into a deliverable programme

Forecast the number and duration of planned tasks by month, risk class, location and skill requirement. Add corrective workload, travel, administration, supervision, quality checks, training and contingency capacity. Coordinate equipment access with clinical services and identify substitutes for devices that cannot remain in use during maintenance.

Confirm tooling, test equipment, calibration status, spare parts, technical documents and vendor support. Use service contracts selectively and define response time, evidence, parts, software access, data protection and acceptance responsibilities. A schedule that exceeds available capacity is a visible risk, not a completed plan.

7. Execute, document and control return to service

Every work order should identify the device, trigger, task, findings, measurements, parts, person performing the work and final status. When a fault or failed test is found, isolate or label the device according to policy and communicate with the responsible clinical team.

Return to service only after the required safety and performance acceptance criteria are met. Record unresolved limitations and escalation. WHO’s computerised maintenance management system guidance explains how structured maintenance information supports work control, history and reporting.

8. Measure performance and improve the plan

Review the programme by device family and risk class. Useful measures include planned work completed on time, failure between scheduled visits, response and repair time, repeat repairs, downtime, overdue high-risk work, no-fault-found jobs, parts delays, safety incidents and lifecycle cost.

Do not reward completion at the expense of effectiveness. A 100 per cent completion rate can coexist with repeat failures or weak acceptance evidence. Use trends to change tasks, intervals, training, vendor controls, spares or replacement priorities. Link significant findings to the hospital’s clinical governance and patient safety system.

A practical risk-priority method

EPW recommends separating the consequence decision from the maintenance decision. First, rate the consequence of unavailable or inaccurate performance. Second, assess failure detectability, usage and backup capacity. Third, identify the failure modes that a planned task can actually control. Only then assign the interval and service response.

Decision factor Low-priority pattern High-priority pattern
Clinical consequence Minor disruption with no direct patient harm Potential serious harm or loss of critical treatment
Failure detection Failure is obvious before use Degradation may remain hidden
Redundancy Safe substitute is immediately available No practical substitute or long transfer time
Failure evidence Stable history with low fault frequency Repeated faults, recalls or adverse trend
Task effectiveness Planned task does not change failure risk Inspection or replacement can detect or prevent failure

This produces a transparent rationale. It also prevents two common errors: over-maintaining low-risk equipment simply because it is on the inventory, and under-maintaining high-risk devices because they have not recently failed.

Worked example: patient monitor fleet

A hospital identifies its patient monitors as clinically important, widely used and partly dependent on battery, alarm and sensor performance. The team groups models, checks manufacturer requirements and reviews fault history. Planned work includes visual inspection, alarm verification, battery assessment and specified performance and safety tests.

The schedule gives higher priority to monitors in critical-care areas and units with poor backup capacity. Repeated battery failures trigger an interval and supplier review. A failed alarm test blocks return to service. Completion, repeat faults, downtime and battery replacement trends are reported together, allowing the plan to respond to evidence instead of remaining static.

Common planning mistakes

  • Using an incomplete inventory: unregistered or retired assets make compliance data unreliable.
  • Equating cost with risk: clinical function and failure consequence matter more than price alone.
  • Copying intervals without review: requirements, usage and local failure evidence must be considered.
  • Scoring risk without linking it to tasks: a score has little value unless it changes control, priority or response.
  • Ignoring corrective capacity: planned work does not eliminate faults.
  • Closing work orders without acceptance evidence: repair is not complete until safe function is demonstrated.
  • Measuring only completion: reliability, downtime, incidents and repeat faults show whether the programme works.

Risk-based maintenance planning checklist

  • The inventory is complete, reconciled and uniquely identified.
  • Risk criteria, examples and approval rules are documented.
  • Manufacturer and jurisdictional requirements are traceable.
  • Every planned task controls a defined failure or performance risk.
  • Intervals have evidence, owners and review triggers.
  • Resources, access, spares and backup equipment are realistic.
  • Corrective escalation and return-to-service criteria are clear.
  • Performance measures connect completion with safety, reliability and cost.
  • Repeated failures feed replacement and capital-planning decisions.

Develop the capability behind the plan

Teams that need to connect inventory governance, risk classification, preventive and corrective maintenance, testing, computerised maintenance management system data and replacement decisions can explore EPW’s Medical Equipment Maintenance and Technology Management course.

A strong plan is not a spreadsheet of dates. It is a controlled lifecycle decision system supported by reliable data and competent people. Review EPW’s Healthcare and Hospital Management Training Courses to develop related capabilities in governance, operations, risk and quality improvement.

Sources and References

  1. World Health Organization. Medical equipment maintenance programme overview. 31 December 2011.
  2. World Health Organization. Introduction to medical equipment inventory management. 2011.
  3. World Health Organization. Computerized maintenance management system. 2012.
  4. Medicines and Healthcare products Regulatory Agency. Managing medical devices. Published 25 February 2021.