Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 31010

Risk Assessment Techniques

Management Systems Published: 2019

ISO 31010:2019 at a glance

Current edition
IEC 31010:2019 - Risk management — Risk assessment techniques
Published
2019
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Previous edition
IEC 31010:2009
Official ISO page
View ISO 31010:2019 on iso.org
Last verified

Overview

A catalogue of risk assessment techniques with guidance on selecting and applying them. The second edition, IEC 31010:2019, replaces the 2009 edition and complements ISO 31000.

IEC 31010:2019, Risk management — Risk assessment techniques, is the companion document to ISO 31000. Published jointly by IEC and ISO, it is the second edition and cancels and replaces IEC 31010:2009. Where ISO 31000 sets out principles and a framework and process for managing risk, IEC 31010 answers the practical question that follows: which technique should be used to assess a given risk, and how.

The standard describes the process of assessing risk from end to end — defining the scope and purpose of an assessment, understanding the context and the decision it supports, selecting and applying techniques, verifying and validating the results, and reporting them. The 2019 edition gives considerably more detail on planning, implementing, verifying and validating the use of techniques than the first edition did, reflecting the observation that misapplied techniques produce confident but wrong answers.

The bulk of the document is a catalogue of techniques, each summarised with its purpose, inputs, method, outputs, strengths and limitations, together with references to the documents where the technique is described in full. The techniques span methods for eliciting views and information, for identifying risk, for analysing controls and consequences and likelihood, for understanding dependencies and interactions, and for evaluating the significance of risk and supporting decisions. The number and range of techniques covered was increased in the second edition.

Techniques are grouped so that selection can be driven by the question being asked rather than by familiarity. The standard is explicit that no technique is universally best: the choice depends on the complexity of the problem, the nature and degree of uncertainty, the resources and data available, whether the output needs to be qualitative or quantitative, and whether the result must be defensible to a regulator or a court.

IEC 31010 is guidance and is not certifiable. Neither it nor ISO 31000 contains requirements and neither is intended for certification. Organizations use them together as the reference for how risk assessment is done, and the techniques described are applied inside management systems built on certifiable standards — ISO 9001 risk and opportunity planning, ISO 14001 environmental aspects, ISO 45001 hazard identification, ISO/IEC 27001 information security risk assessment, ISO 22301 business impact analysis and risk assessment, and sector safety standards.

In practice the standard is most valuable when an organization has outgrown a single default method. Teams that assess every risk with the same matrix tend to under-analyse complex, low-frequency, high-consequence exposures; IEC 31010 provides the vocabulary and the shortlist for choosing something more appropriate and for explaining the choice.

Purpose

To provide guidance on the selection and application of techniques for assessing risk in a wide range of situations, so that the techniques used support sound decisions where there is uncertainty.

Key Benefits

  • Provides a structured basis for choosing a risk assessment technique rather than defaulting to one method
  • Describes the strengths, limitations, inputs and outputs of each technique
  • Covers the full assessment process including planning, verification and validation of results
  • Supports the risk assessment activities required by ISO 9001, 14001, 45001, 27001 and 22301
  • Complements ISO 31000 by turning its process into applicable methods
  • Helps make risk assessments defensible to regulators, customers and courts
  • Applicable across safety, environmental, financial, operational, security and project risk
  • Improves consistency of risk assessment practice across an organization

Key Requirements

  • Guidance only — IEC 31010 contains recommendations, not auditable requirements
  • Define the scope, purpose and context of the risk assessment and the decision it supports
  • Determine the nature and degree of uncertainty and the data available
  • Select techniques appropriate to the problem, the resources available and the form of output needed
  • Apply techniques with appropriate expertise and stakeholder involvement
  • Understand and document the assumptions and limitations of the techniques used
  • Verify and validate the results of the assessment
  • Record and report results in a form usable by the decision maker
  • Review and update assessments as circumstances, data or the decision context change

Who Needs This Standard?

Risk managers, safety and reliability engineers, environmental and security specialists, project and programme managers, internal auditors, and anyone responsible for producing or reviewing risk assessments. It is used across manufacturing, energy, transport, healthcare, finance, construction and public administration, and by organizations implementing ISO 31000 or the risk clauses of certifiable management system standards.

Where to get ISO 31010

The full text of ISO 31010 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 31010 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 31010, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Related Standards