IEC 31010
IEC 31010 is an international standard that offers guidance on how to choose and use techniques for assessing risk across many different situations and industries. Rather than telling organizations what risks to accept, it acts as a reference toolkit describing methods that can support the risk assessment part of managing risk. It is designed to reflect good practice and supports, rather than replaces, broader risk management frameworks.
IEC 31010 is a standard on risk management jointly associated with the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) that provides guidance on the selection and application of techniques for assessing risk in a wide range of situations. It is supporting guidance oriented toward the risk assessment component of the risk management process, covering the identification, analysis, and evaluation of risk through a range of systematic techniques. The 2009 edition states it reflects current good practices in the selection and utilization of risk assessment techniques and does not address new or evolving methods; the 2019 edition (published as EN IEC 31010:2019 in the European context) continues to provide guidance on selecting and applying techniques across industries. It is intended as a complement to broader risk management guidance and does not itself prescribe specific risk criteria, acceptable risk levels, or implementation tooling.
Why it matters
Risk assessment is only as reliable as the techniques used to conduct it, and practitioners face a wide array of methods that vary in rigor, data requirements, and suitability for different problems. IEC 31010 matters because it provides a structured reference for selecting and applying techniques appropriate to a given situation, helping organizations avoid the common pitfall of defaulting to a single familiar method regardless of its fitness for the task. By describing a range of techniques and the contexts in which they may be useful, it supports more defensible and consistent risk assessment practice.
The standard also matters because of what it deliberately does not do. It does not set risk criteria, define acceptable levels of risk, or prescribe implementation tooling; those decisions remain the responsibility of the organization and are shaped by its objectives, obligations, and broader risk management framework. This scoping is significant for practitioners, who should treat IEC 31010 as supporting guidance for the assessment component of the risk management process rather than as a complete risk management system or a source of compliance requirements.
Because the standard is positioned to reflect good practice and to complement broader guidance, its value depends on being used alongside an organization's governance structures and risk management approach. Users should note that the 2009 edition states it reflects current good practice and does not address new or evolving techniques, so reliance on it does not guarantee that every relevant or emerging method has been considered.
Who it's relevant to
Inside IEC 31010
Common questions
Answers to the questions practitioners most commonly ask about IEC 31010.
