IEC 31010 - Risk management -- Risk assessment techniques

 

Why IEC 31010

All organizations manage risk but often in a rather ad hoc manner relying on historical precedent.  A good understanding of risk and its causes and consequences, enables strategies to treat risk to be well targeted and hence more effective and often more cost effective. 

IEC 31010 describes a range of techniques that can be used for gaining a better understanding of risk so that uncertainty is taken into account in decisions and actions are based on a sound understanding of risk.

The approach of 31010

IEC 31010 introduces a wide range of techniques that can be used to identify and understand risk.  It describes the process to be followed when assessing risk, from defining the scope and purpose of the assessment through to delivering a report.  

As well as their use as part of the ISO 31000 process of deciding whether and how to treat risk, the standard demonstrates how the techniques can be used to take risk into account when comparing options or undertaking a cost benefit analysis of opportunities

The standard discusses application of the techniques to identifying risk and its causes, sources and drivers, and to understanding consequences and their likelihood and measures of risk .It also introduces some techniques for making decisions involving risk.

The Annex of the standard includes a summary of 41 techniques covering a wide range of applications, and for each describes their uses, inputs and outputs and their strengths and limitations. References are provided to sources of more detailed information on each technique.

Guidance is given on the characteristics of each technique to help the reader select a technique for a particular application.

IEC 31010 as part of the 31000 Family

ISO 31000 provides generic principles and guidelines for establishing a risk management framework and embedding a process for managing risks within an organization.

IEC 31010 focusses on techniques that can be used within the risk assessment part of this process and also for gaining a more detailed understanding of particular risks.

Although the majority of techniques were originally developed for analyzing risk with negative consequences in technical applications IEC 31010 takes a broad approach demonstrating the wider application of the techniques.

IEC 31010 is currently being revised to support ISO 31000:2018 and provides guidance on selection and application of systematic techniques for risk assessment. This standard is not intended for certification, regulatory or contractual use.