Overview
IEC 62198:2025 - Managing risk in projects - Application guidelines is the third edition (technical revision) from IEC TC 56. It provides principles and generic guidelines for project risk management, describing a systematic approach based on ISO 31000 and aligned with ISO 21502. The standard updates leadership and risk-management principles to reflect modern project environments and sponsor oversight. This edition cancels and replaces IEC 62198:2013.
Key topics and requirements
IEC 62198:2025 covers the full project risk lifecycle and the organizational framework needed to apply it. Key technical topics include:
- Principles for managing risk in projects - foundational risk management concepts adapted to project contexts.
- Project risk management framework - leadership and commitment, policy, accountability, resources, integration into project management, and internal/external communication.
- Project risk management process - planning, communication & consultation, establishing scope and context, risk identification, risk analysis, risk evaluation, and risk treatment.
- Monitoring, review and continual improvement - performance review, management meetings, and updating the framework and process.
- Recording and reporting - documentation, record retention and the project risk register as a central tool.
- Practical guidance and examples - Annex A contains sector examples (e.g., energy, infrastructure, defence) and worksheets for scales, matrices and treatment plans.
Requirements are presented as application guidelines to help design and implement a project-specific risk management plan and to integrate risk activities across project phases.
Applications
IEC 62198:2025 is designed for practical use in project risk management across industries:
- Establishing a project risk management framework in alignment with corporate governance and sponsor oversight.
- Designing and executing risk assessments (identification, analysis, evaluation) and producing risk treatment plans.
- Creating and maintaining a project risk register, communication and reporting mechanisms.
- Integrating risk management into project lifecycle phases and decision points as recommended by ISO 21502.
- Supporting continual improvement and leadership-driven risk culture within projects.
Typical use cases: major construction, energy projects, technology development, systems upgrades, and public-sector programmes.
Who should use it
- Project managers and programme/portfolio managers
- Project risk managers and risk officers
- Project sponsors and steering committees
- Risk consultants, auditors and compliance teams
- Organisations aligning project controls with ISO 31000 and ISO 21502
Related standards
- ISO 31000 - Risk management - Guidelines
- ISO 21502 - Project, programme and portfolio management - Guidance on project management
Keywords: IEC 62198:2025, managing risk in projects, project risk management, risk management framework, ISO 31000, ISO 21502, project risk register.