Overview
IEC 31010:2019 - Risk management - Risk assessment techniques (published as a double‑logo IEC/ISO standard) provides practical guidance on selecting and applying a wide range of risk assessment techniques to support decision‑making under uncertainty. The second edition (2019) replaces the 2009 edition and is a technical revision that expands the number and range of techniques, adds more detail on planning, implementation, verification and validation, and no longer repeats concepts covered in ISO 31000. The standard summarizes methods and points to further sources where techniques are described in more depth.
Key topics and technical content
- Purpose and scope: Guidance on how to define assessment objectives, context and stakeholder engagement.
- Implementing assessments: Planning the assessment; collecting and managing information; developing and validating models.
- Application of techniques: Identifying risks; determining sources, causes and drivers; analysing controls; estimating likelihood and consequences; exploring interactions and dependencies.
- Review and use of results: Verification, validation, sensitivity and uncertainty analysis; monitoring, reporting and applying results to decisions.
- Selecting techniques: Criteria and categorization to choose methods appropriate to scope, data quality and decision needs.
- Annexes with technique descriptions: Summaries of many methods, including (but not limited to) FMEA/FMECA, HAZOP, Bow‑tie, LOPA, FTA/ETA, Bayesian analysis and networks, Monte Carlo simulation, Markov analysis, human reliability analysis (HRA), scenario analysis, ALARP/SFAIRP, value‑at‑risk (VaR/CVaR), cost–benefit analysis, multi‑criteria analysis, risk registers and risk matrices.
Practical applications
IEC 31010 is designed to be applied wherever structured risk assessment is needed to support decisions under uncertainty:
- Safety engineering and process safety reviews (HAZOP, LOPA, FMEA).
- Environmental and ecological risk modelling (Bayesian networks, Monte Carlo).
- Financial and operational risk analysis (VaR, CVaR, scenario analysis).
- Cybersecurity and privacy impact assessments (DPIA/PIA techniques).
- Business continuity and resilience planning (business impact analysis, consequence/likelihood matrices).
- Project risk assessments and regulatory compliance.
Who should use this standard
- Risk managers and enterprise risk teams
- Safety, reliability and process engineers
- Compliance officers and auditors
- Environmental scientists and cybersecurity/privacy practitioners
- Project managers and consultants who need to select and apply appropriate risk assessment methods
Related standards and keywords
- Related: ISO 31000 (risk management framework and principles) - IEC 31010 focuses specifically on assessment techniques and omits ISO 31000 conceptual material.
- SEO keywords: risk assessment techniques, risk management, uncertainty, ISO 31000, risk matrix, FMEA, HAZOP, Bow‑tie, Monte Carlo, Bayesian networks, ALARP.
IEC 31010:2019 is a practical reference for selecting, applying and validating risk assessment techniques to produce robust, transparent information for decision‑making under uncertainty.