Skip to content
site-logo

FEDIP Job Profiles

  • Home
  • About
  • All Job Roles
  • Submit Feedback
  • News
  • FAQs

SFIA Skills: Risk management (BURM)

Risk management of software as a medical device (BURM) (Level 6)

Assesses software products to determine whether they meet the criteria for classification as Software as a Medical Device (SaMD). Conducts hazard identification and risk assessments in accordance with ISO 14971. Produces and maintains documentation to demonstrate compliance with the UK Medical Device Regulation (MDR), including the creation and maintenance of the Risk Management File and supports the regulatory lead in the production and ongoing integrity of the technical file and Quality Management System. Manages updates to documentation and safety cases throughout the device lifecycle, ensuring post-market surveillance, incident reporting and change control processes are embedded to maintain ongoing regulatory compliance.

Risk management (BURM) (Level 6)

Plans and manages the implementation of organisation-wide processes and procedures, tools and techniques for clinical risk management associated with digital systems. Manages clinical safety risk assessment activities within the organisation. Develops clinical risk management processes and procedures, and identifies and deploys appropriate tools and techniques (e.g. SWIFT, FMEA).

Patient safety risk (BURM) (Level 6)

Appraises patient safety risk in the procurement, design, development, deployment and decommissioning of information systems and technologies and ensures that all risk is assessed and managed appropriately to minimise or avoid harm.

Implementation and resources (BURM) (Level 6)

Plans and manages the implementation of organisation-wide processes and procedures, tools and techniques for the identification, assessment, and management of clinical risk inherent in the operation of processes and of potential risks arising from planned IT-enabled change.

Guidance (BURM) (Level 6)

Provides clinical safety leadership across the organisation, guiding the development and implementation of clinical risk management strategies. Advises on the design and operation of the organisation-wide clinical risk management system.

Risk strategy, processes and monitoring (BURM) (Level Six)

Identifies and categorises organisation-wide strategic and operational risks. Breaks down risks by sub-categories, such as compliance, architecture, environment, financial etc. and considers mitigation activities in the context of organisational risk appetite.

Risk countermeasures and response (BURM) (Level Six)

Advises on the evaluation of identified risks (including probability/frequency of occurrence, impact and severity). Advises on appropriate action, including contingency planning, and countermeasures.

Risk strategy, processes and monitoring (BURM) (Level 5)

Monitors status of risks, and reports status and need for action to key stakeholders.

Risk countermeasures and response (BURM) (Level 5)

Coordinates response to quantified risks, which may involve acceptance/retention, transfer, reduction or avoidance/elimination. Coordinates the development of countermeasures and contingency plans.

Financial awareness (BURM) (Level 5)

Demonstrates financial awareness as a part of risk management (e.g. cost-effectiveness analysis of proposed counter measures).

Risk strategy, processes and monitoring (BURM) (Level 4)

Monitors status of risks, and reports status and need for action to senior colleagues.

Risk countermeasures and response (BURM) (Level 4)

Assists with development of agreed countermeasures and contingency plans.

Financial awareness (BURM) (Level 4)

Demonstrates financial awareness as a part of risk management (e.g. cost-effectiveness analysis of proposed counter measures).

Risk strategy, processes and monitoring (BURM) (Level 3)

Maintains documentation of risks, threats, vulnerabilities and mitigation actions.

Job Families

  • IT Operations (47)
    • Application Operations Engineer (6)
    • Infrastructure Engineer (5)
    • Infrastructure Operations Engineer (5)
    • End User Computing Engineer (5)
    • Service Transition Manager (4)
    • IT Service Manager (4)
    • Service Desk Manager (4)
    • Command and Control Centre Manager (4)
    • Business Relationship Manager (3)
    • Change and Release Manager (3)
    • Incident Manager (2)
    • Problem Manager (2)
  • User Centred Design (37)
    • Content Designer (6)
    • Interaction Designer (6)
    • Graphic Designer (6)
    • Service Designer (6)
    • User Researcher (6)
    • Accessibility Specialist (4)
    • Technical Writer (2)
    • Content Strategist (1)
  • Architecture (27)
    • Technical Architect (5)
    • Solutions Architect (5)
    • Enterprise Architect (4)
    • Business Architect (4)
    • Data Architect (3)
    • Security Architect (3)
    • Network Architect (3)
  • Data (25)
    • Data Engineer (5)
    • Data Analyst (5)
    • Analytics Engineer (4)
    • Data Scientist (4)
    • Data Governance Manager (3)
    • Machine Learning Engineer (2)
    • Data Ethicist (2)
  • Software Development (24)
    • Software Developer (9)
    • Development Operations Engineer​​ (9)
    • Frontend ​Developer​ (6)
  • Product and Delivery (21)
    • Business Analyst (6)
    • Product Manager (5)
    • Delivery Manager (4)
    • Digital Portfolio Manager (4)
    • Programme Delivery Manager (1)
    • Service Owner (1)
  • Patient Services (18)
    • Clinical Coder (7)
    • Records and Information Manager​​ (4)
    • Patient Access​ Manager​ (4)
    • Data Quality​ Officer​ (3)
  • Quality Assurance Testing (10)
    • Quality Assurance Testing (QAT) Analyst (4)
    • Test Engineer (4)
    • Test Manager (2)
  • Cyber Security (10)
    • Cyber Security Specialist (Governance Risk and Compliance) (4)
    • Cyber Security Specialist (Operations) (4)
    • Cyber Security Analyst (2)
  • Digital Leadership Roles (9)
    • Chief Technology Officer (1)
    • Chief Information Officer (1)
    • Chief Audit Officer (1)
    • CxIO (1)
    • Chief Information Security Officer (1)
    • Chief Analytics Officer (1)
    • Caldicott Guardian (1)
    • Chief Data Officer (1)
    • Chief Pharmacy Information Officer (1)
  • Knowledge, Library and Information Management (16)
    • Library Manager (10)
      • Digital Systems Librarian (1)
      • Evidence Specialist (1)
      • Patient Information Librarian (1)
      • Primary Care Librarian (1)
      • Apprentice Library Assistant (1)
      • Outreach Librarian (1)
      • Embedded Specialist Librarian (1)
    • Knowledge Manager (5)
    • Information Manager (1)
  • Information Governance (6)
    • Information Governance Officers​ (3)
    • Information Governance Manager​​s (2)
    • Data Protection Officer​​ (1)
  • Digital Education Services (6)
    • Digital Education Specialist (2)
    • Digital Education Manager (2)
    • Digital Education Administration (1)
    • Digital Education Trainer​ (1)
  • Clinical Informatics (3)
    • Clinical Informatician​ (2)
    • Clinical Safety Officer (1)
FEDIP logo

The Federation for Informatics Professionals in Health and Care

Registered in England and Wales No. 10639143

email: info@fedip.org

Copyright © 2026 All Rights Reserved FEDIP | Use of cookies | Legal notices
Registered in England and Wales No. 10639143

website by Sarah Scriven