Skip to main content
Category: GRC Frameworks

IEC 31010

Also known as: ISO/IEC 31010, IEC 31010:2019, Risk assessment techniques
Simply put

IEC 31010 is an international standard that offers guidance on how to choose and use techniques for assessing risk across many different situations and industries. Rather than telling organizations what risks to accept, it acts as a reference toolkit describing methods that can support the risk assessment part of managing risk. It is designed to reflect good practice and supports, rather than replaces, broader risk management frameworks.

Formal definition

IEC 31010 is a standard on risk management jointly associated with the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) that provides guidance on the selection and application of techniques for assessing risk in a wide range of situations. It is supporting guidance oriented toward the risk assessment component of the risk management process, covering the identification, analysis, and evaluation of risk through a range of systematic techniques. The 2009 edition states it reflects current good practices in the selection and utilization of risk assessment techniques and does not address new or evolving methods; the 2019 edition (published as EN IEC 31010:2019 in the European context) continues to provide guidance on selecting and applying techniques across industries. It is intended as a complement to broader risk management guidance and does not itself prescribe specific risk criteria, acceptable risk levels, or implementation tooling.

Why it matters

Risk assessment is only as reliable as the techniques used to conduct it, and practitioners face a wide array of methods that vary in rigor, data requirements, and suitability for different problems. IEC 31010 matters because it provides a structured reference for selecting and applying techniques appropriate to a given situation, helping organizations avoid the common pitfall of defaulting to a single familiar method regardless of its fitness for the task. By describing a range of techniques and the contexts in which they may be useful, it supports more defensible and consistent risk assessment practice.

The standard also matters because of what it deliberately does not do. It does not set risk criteria, define acceptable levels of risk, or prescribe implementation tooling; those decisions remain the responsibility of the organization and are shaped by its objectives, obligations, and broader risk management framework. This scoping is significant for practitioners, who should treat IEC 31010 as supporting guidance for the assessment component of the risk management process rather than as a complete risk management system or a source of compliance requirements.

Because the standard is positioned to reflect good practice and to complement broader guidance, its value depends on being used alongside an organization's governance structures and risk management approach. Users should note that the 2009 edition states it reflects current good practice and does not address new or evolving techniques, so reliance on it does not guarantee that every relevant or emerging method has been considered.

Who it's relevant to

Risk managers and enterprise risk teams
Practitioners who need to assess and manage risk across industries can use IEC 31010 as a reference when choosing among assessment techniques for a given situation. It helps them apply methods appropriate to the problem rather than defaulting to a single approach, while leaving decisions on risk criteria and acceptable levels to be set within the organization's own framework.
Governance professionals
Those responsible for the structures and decision rights that direct risk management may reference IEC 31010 to understand how risk assessment techniques are selected and applied, and to ensure that assessment practice is grounded in recognized good-practice guidance. The standard supports, but does not substitute for, the broader governance and risk management frameworks under which risk decisions are made.
Internal auditors and assurance providers
Assurance functions evaluating the adequacy of an organization's risk assessment activities may use IEC 31010 as a benchmark for whether appropriate techniques have been selected and applied. In doing so, they should maintain independence from the management activities being assessed and recognize that the standard is supporting guidance, not a source of compliance obligations or acceptance criteria.

Inside IEC 31010

Risk assessment techniques catalogue
IEC 31010, published by the International Electrotechnical Commission, provides a catalogue of risk assessment techniques intended to support the risk assessment process. It describes methods rather than prescribing which organizations must use them.
Guidance on technique selection
The standard offers guidance to help practitioners select techniques appropriate to the context, the nature of the uncertainty, and the resources available, recognizing that no single technique suits all situations.
Support for the risk assessment steps
It addresses techniques applicable across risk identification, risk analysis, and risk evaluation, which together commonly constitute risk assessment within a broader risk management process.
Relationship to ISO 31000
IEC 31010 is commonly used as a supporting document alongside ISO 31000, the risk management guidance standard, providing technique-level detail that ISO 31000 does not itself elaborate. ISO 31000 sets out principles and a framework; IEC 31010 focuses on assessment methods.
Descriptive treatment of methods
For the techniques it covers, the standard typically discusses their applicability, and their relative strengths and limitations, so that users can judge suitability rather than treating any method as universally correct.

Common questions

Answers to the questions practitioners most commonly ask about IEC 31010.

Is IEC 31010 a standard that dictates which risk assessment technique an organization must use?
No. IEC 31010 is a supporting standard that describes and compares a range of risk assessment techniques; it does not mandate the use of any particular technique. It is intended to inform the selection of methods appropriate to the context, and the choice remains a judgment for the organization based on its objectives, the nature of the risk, and the resources available. Treating it as a prescriptive checklist misrepresents its advisory character.
Does IEC 31010 replace or serve as an alternative to ISO 31000?
No. The two are complementary rather than substitutes. ISO 31000 provides principles and a framework for managing risk, while IEC 31010 supports the risk assessment element of that process by cataloguing techniques and discussing their applicability, strengths, and limitations. IEC 31010 does not establish an overarching risk management framework of its own and is generally used alongside ISO 31000 rather than in place of it.
How does an organization decide which technique from IEC 31010 to apply in a given assessment?
IEC 31010 discusses factors relevant to selecting a technique, which commonly include the purpose and scope of the assessment, the complexity of the situation, the availability and quality of data, the level of expertise required, and whether qualitative, semi-quantitative, or quantitative output is needed. The standard presents these considerations to inform judgment rather than to produce a single answer; selection typically depends on the specific context and objectives.
Can more than one technique from IEC 31010 be used together in a single assessment?
Yes. In practice, techniques are often combined so that the output of one informs another, or so that different aspects of a risk are examined using methods suited to each. IEC 31010 discusses techniques individually and by attribute, which can help practitioners consider how methods may complement one another. The standard does not prescribe specific combinations, and the appropriate mix depends on context.
At what point in the risk management process is IEC 31010 most relevant?
IEC 31010 supports the risk assessment stage, which in many frameworks comprises risk identification, risk analysis, and risk evaluation. The techniques it describes may be applied across these sub-stages depending on their purpose. It is generally less concerned with risk treatment, monitoring, and communication, which fall to other parts of the risk management process; users should consult the broader framework, such as that in ISO 31000, for those activities.
What are the limits of relying on IEC 31010 techniques, and what does the standard not provide?
The techniques described have inherent limitations relating to data quality, assumptions, subjectivity, and the expertise of those applying them, and the standard commonly discusses such limitations alongside each method. IEC 31010 does not provide implementation detail, tooling, sector-specific requirements, or legal guidance, and applying a technique does not guarantee that risks are correctly identified or that outcomes will follow. Users should treat its output as an input to informed judgment rather than a definitive result.

Common misconceptions

IEC 31010 is a certifiable management system standard like ISO 37301 or ISO 27001.
IEC 31010 is guidance on risk assessment techniques, not a requirements standard against which an organization is certified. It supports the risk assessment activity and is commonly paired with ISO 31000, which is itself guidance rather than a certifiable specification.
The standard mandates specific techniques that organizations must apply.
The standard presents a range of techniques and helps users select among them based on context. It does not require any particular method; selection depends on the assessment objective, available data, and resources.
IEC 31010 covers the entire risk management process.
Its focus is the risk assessment portion, spanning risk identification, analysis, and evaluation. Broader elements such as establishing the framework, risk treatment, and monitoring are addressed at the level of principles and framework primarily in ISO 31000 rather than in IEC 31010.

Best practices

Use IEC 31010 in conjunction with ISO 31000 so that technique selection is grounded in a defined risk management framework and principles rather than applied in isolation.
Select assessment techniques based on the specific context, the nature of the uncertainty, the quality of available data, and the resources at hand, rather than defaulting to a familiar method.
Evaluate the strengths and limitations of a chosen technique before relying on its outputs, and document why it was considered appropriate for the assessment.
Consider combining more than one technique where a single method does not adequately cover identification, analysis, and evaluation needs.
Treat the standard as guidance to inform professional judgment, not as a prescriptive checklist or a substitute for context-specific expertise.
Align terminology and outputs from the selected techniques with the organization's broader risk management vocabulary so results feed consistently into evaluation and treatment decisions.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps