Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

IEC 31010 explained

IEC 31010: The Complete Guide to All 41 Risk Assessment Techniques

IEC 31010 is the companion to ISO 31000 that answers the question the guidelines standard deliberately leaves open: how, exactly, do you assess a risk? IEC 31010:2019, Risk management — Risk assessment techniques, is the second edition, published jointly by IEC and ISO in June 2019 to replace the 2009 edition, and it describes 41 techniques in Annex B — from brainstorming and checklists through HAZOP, FMEA, fault tree and bow tie analysis to Bayesian networks, Monte Carlo simulation and cost-benefit analysis — organised by what they are for: eliciting views, identifying risk, determining sources and causes, analysing controls, understanding consequences and likelihood, analysing dependencies, providing a measure of risk, evaluating significance, choosing between options, and recording and reporting. Its main clauses explain the core concepts, the uses of risk assessment, how to plan and implement an assessment and how to select a technique, and Annex A tabulates the techniques against the process step, the inputs they need and the outputs they produce. Like ISO 31000 it is a guidance document, not a requirement. This guide explains what IEC 31010 covers and what changed in 2019, sets out the technique categories with the techniques in each, describes how clause 7 says to choose, walks through the assessment process in clause 6, and names the techniques most organisations actually need.

IEC 31010:2019: 41 techniques in 10 categories
B.1 eliciting views · B.2 identifying risk · B.3 sources, causes and drivers · B.4 analysing controls · B.5 consequences and likelihood · B.6 dependencies and interactions · B.7 measures of risk · B.8 evaluating significance · B.9 selecting options · B.10 recording and reporting — chosen per clause 7 for the process step, the decision, the data and the resources.

What the standard is

ISO 31000:2018 IEC 31010:2019
Title Risk management — Guidelines Risk management — Risk assessment techniques
Role Principles, framework and process Techniques for the risk assessment step of the process (identification, analysis, evaluation) and for treatment selection
Length and form Sixteen pages; no techniques A substantial document; 41 technique descriptions with strengths, limitations, inputs and outputs
Status Guidance; not certifiable Guidance; not certifiable; IEC and ISO dual logo
Edition Second, 2018 Second, 2019 — replacing ISO/IEC 31010:2009, which described 31 techniques

The 2019 edition of the standard rewrote the main text around how to plan, implement and choose rather than around the process steps, added techniques for consequence and likelihood analysis, dependencies, and evaluation — Bayesian analysis, cross-impact analysis, value-at-risk, frequency-number diagrams, S-curves among them — and dropped or merged some 2009 entries. Our guide to ISO 31000 covers the process the techniques serve.

The ten IEC 31010 technique categories

Category (Annex B) Purpose Techniques
B.1 Eliciting views from stakeholders and experts Gathering knowledge and opinion Brainstorming; Delphi technique; nominal group technique; structured or semi-structured interviews; surveys
B.2 Identifying risk Finding what could happen and how Checklists, classifications and taxonomies; failure modes and effects analysis (FMEA) and FMECA; hazard and operability study (HAZOP); scenario analysis; structured what-if technique (SWIFT)
B.3 Determining sources, causes and drivers of risk Understanding why Cindynic approach; Ishikawa (fishbone) analysis
B.4 Analysing controls Testing what stands between cause and consequence Bow tie analysis; hazard analysis and critical control points (HACCP); layers of protection analysis (LOPA)
B.5 Understanding consequences and likelihood Estimating outcome and chance Bayesian analysis; Bayesian networks; business impact analysis; cause-consequence analysis; event tree analysis; fault tree analysis; human reliability analysis; Markov analysis; Monte Carlo simulation; privacy impact analysis
B.6 Analysing dependencies and interactions Seeing how risks connect Causal mapping; cross-impact analysis
B.7 Providing a measure of risk Expressing risk as a quantity Toxicological risk assessment; value at risk (VaR); conditional value at risk (CVaR) or expected shortfall
B.8 Evaluating the significance of risk Deciding what matters As low as reasonably practicable (ALARP) and so far as is reasonably practicable (SFAIRP); frequency-number (F-N) diagrams; Pareto charts; reliability-centred maintenance; risk indices
B.9 Selecting between options Choosing treatments Cost-benefit analysis; decision tree analysis; game theory; multi-criteria analysis
B.10 Recording and reporting Communicating the result Risk registers; consequence/likelihood matrix; S-curves

Annex B files each technique once, but Annex A’s table shows that most serve more than one process step — the consequence/likelihood matrix is used for evaluation as well as reporting, and a bow tie is as much a reporting tool as a control analysis. Our guides to bow tie analysis and risk criteria cover two of the most used.

How IEC 31010 says to choose a technique

Clause 7 of the standard sets out the selection considerations. The purpose of the assessment and the decision it informs come first; then the needs of stakeholders; then the characteristics of the risk — the nature of the uncertainty, the time frame, the availability and quality of data; then the resources — time, expertise, information; then whether the output has to be qualitative, semi-quantitative or quantitative; and finally the need for consistency with other assessments. The clause makes two points that matter more than the list: a technique’s output is only as good as its inputs, and combining techniques is normal — identification with one, analysis with another, evaluation with a third.

Need Techniques the standard points to Why
Find hazards in a process plant HAZOP, SWIFT, checklists Systematic, guideword-driven identification
Understand how a failure propagates FMEA/FMECA, fault tree, event tree, cause-consequence Cause and effect structure
Show which controls matter for a major event Bow tie, LOPA Controls on both sides of the top event
Put a number on a financial exposure Monte Carlo simulation, VaR, CVaR Distributions rather than point estimates
Decide between treatment options Cost-benefit analysis, decision trees, multi-criteria analysis Value of each option against criteria
Present risk to a board Consequence/likelihood matrix, risk register, S-curve Recording and reporting forms

The assessment process in clause 6

Step What the standard covers Output
6.1 Plan the assessment Define purpose and scope, understand the context, engage stakeholders, define objectives, consider human, organisational and social factors, review criteria, record and report requirements Assessment plan
6.2 Manage information and develop models Collect and analyse information; develop and validate models; select techniques Data and models fit for the technique
6.3 Apply the techniques Identify risk — sources, events, consequences; analyse — controls, consequences, likelihood, interactions, measures; evaluate against criteria Risk analysis results
6.4 Review the analysis Verify and validate results; sensitivity and uncertainty analysis; monitor and review Reviewed results with stated uncertainty
6.5 Apply the results to decision making Decisions about the significance of risk and the selection of options Decisions and their rationale
6.6 Record and report Recording, reporting to stakeholders, and the content of a report The record

The steps map onto ISO 31000’s clause 6: scope, context and criteria (6.3 of ISO 31000) into the plan; risk assessment (6.4) into applying the techniques; treatment selection (6.5) into applying the results; recording and reporting (6.7) into the record.

The techniques most organisations actually need

  1. A structured identification method. Checklists and taxonomies for the routine; SWIFT or scenario analysis for the unusual; HAZOP where there is a process to walk through.
  2. Bow tie analysis for the major risks. One diagram per top event that shows the threats, the barriers, the consequences and the recovery controls — the technique that turns a register line into something a board can question.
  3. A consequence/likelihood matrix with written criteria. Used for evaluation and for reporting; useless without the scales defined in the criteria document.
  4. FMEA where products or processes are designed. Engineering and manufacturing risk; the failure-mode structure that safety and quality standards expect.
  5. Monte Carlo or a simpler quantitative method for financial exposures. Where a distribution changes the decision — capital, insurance, project contingency.
  6. Cost-benefit or multi-criteria analysis for treatment options. The step most registers skip: a recorded reason for the option chosen.

Frequently asked questions

What is IEC 31010?
The 2019 edition of Risk management — Risk assessment techniques: the companion to ISO 31000 that describes 41 techniques for identifying, analysing and evaluating risk and selecting treatments, with guidance on planning an assessment and choosing techniques. It is a joint IEC/ISO guidance document, not a requirements standard.

How many techniques does it describe?
41 in the 2019 edition’s Annex B, grouped in ten categories by purpose, from eliciting views and identifying risk to recording and reporting; the 2009 edition described 31.

Do I have to use it to comply with ISO 31000?
Neither is a requirement. ISO 31000 says risk assessment should use techniques appropriate to the context; the techniques standard is where those techniques are described, and ISO 31000 refers to it in its bibliography.

Which technique should I start with?
Clause 7 of the standard says it depends on the decision, the stakeholders, the nature of the risk, the data and the resources. For most organisations: a structured identification method, a bow tie for major risks, a consequence/likelihood matrix with written criteria, and a cost-benefit or multi-criteria method for choosing treatments.

Is IEC 31010 the same as ISO 31010?
The 2009 edition was published as ISO/IEC 31010; the 2019 edition is IEC 31010:2019, published by IEC with ISO, and is the current one.

Where this leaves you

Use IEC 31010 the way its clause 7 intends: decide what the assessment is for, pick identification, analysis, evaluation and treatment-selection techniques that fit the decision, the data and the people, combine them, and record which you used and why — because ISO 31000 tells you to assess risk and IEC 31010 is the only standard that tells you how, and a register built without a named technique is an opinion in a grid.

References

More on ISO 31000

The risk assessment procedure with technique selection, the bow tie, FMEA and SWIFT worksheets, the consequence/likelihood matrix with criteria and the treatment option analysis template are in the ISO 31000 Risk Management Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.