7.1 IEC 31010 Framework and Selection Criteria
Key Takeaways
- IEC 31010:2019 serves as the supporting standard to ISO 31000:2018, detailing 41+ systematic techniques across risk identification, risk analysis, and risk evaluation.
- Technique selection must align with five core criteria: decision context/purpose, system life cycle stage, data availability, degree of uncertainty, and decision complexity.
- Early life cycle stages (concept/design) rely primarily on qualitative techniques due to data scarcity, whereas operational stages leverage semi-quantitative and quantitative modeling.
- No single risk assessment technique is universally applicable; optimal risk assessment frequently requires combining complementary qualitative and quantitative tools.
7.1 IEC 31010 Framework and Selection Criteria
Overview of IEC 31010:2019
While ISO 31000:2018 establishes the overarching principles, framework, and high-level process for managing risk, IEC 31010:2019 (Risk management — Risk assessment techniques) serves as its primary technical companion standard. Developed jointly by the International Electrotechnical Commission (IEC) and the International Organization for Standardization (ISO), IEC 31010 provides non-prescriptive guidance on the selection and application of systematic techniques for risk assessment.
Risk assessment under ISO 31000 comprises three distinct sub-processes: risk identification, risk analysis, and risk evaluation. IEC 31010 categorizes more than 41 distinct risk assessment techniques, ranging from broad qualitative workshop methodologies to complex quantitative statistical simulations. The standard does not specify which technique must be used for a given scenario; instead, it establishes a rigorous selection framework enabling risk managers to match appropriate tools to their specific decision context, resource availability, and operational environment.
+-----------------------------------------------------------------------+
| ISO 31000:2018 |
| Overarching Principles, Governance Framework & Process |
+-----------------------------------------------------------------------+
| (Supported by)
v
+-----------------------------------------------------------------------+
| IEC 31010:2019 |
| Technical Catalog & Selection Criteria for 41+ Techniques |
+-----------------------------------------------------------------------+
| | |
v v v
Risk Identification Risk Analysis Risk Evaluation
(e.g., SWIFT, (e.g., HAZOP, (e.g., Risk Matrix,
Brainstorming) Bow-Tie, FMEA) ALARP Criteria)
Categorization and Taxonomy of Risk Assessment Techniques
IEC 31010 classifies techniques across multiple analytical dimensions. Understanding these classifications is essential for selecting the correct tool for an exam scenario or organizational implementation.
1. Analytical Method Spectrum
- Qualitative Techniques: Express risk in descriptive terms (e.g., High, Medium, Low) based on expert judgment, structured checklists, or workshop consensus. These are ideal when data is limited or when rapid screening is required.
- Semi-Quantitative Techniques: Assign numerical scale values or scores to qualitative descriptors (e.g., Likelihood scores 1–5 multiplied by Severity scores 1–5 to yield a Risk Priority Number). They provide structured ranking without requiring full empirical statistical modeling.
- Quantitative Techniques: Calculate explicit numerical estimates of consequence, frequency, or overall risk metrics (such as Expected Monetary Value, Loss Event Frequency, or Value at Risk) using empirical historical data, physics models, or probabilistic distribution functions.
2. Application Stage Mapping
| Assessment Stage | Primary Focus | Representative IEC 31010 Techniques |
|---|---|---|
| Risk Identification | Uncovering what, why, where, when, and how events could occur | Brainstorming, Delphi, SWIFT, Structured Interviews, Checklists |
| Risk Analysis — Consequence | Analyzing potential impacts and severity of identified risk events | Consequence/Likelihood Matrix, Bow-Tie Analysis, Event Tree Analysis (ETA), FMEA |
| Risk Analysis — Likelihood | Estimating the frequency or probability of occurrence | Fault Tree Analysis (FTA), Markov Analysis, Historical Data Analysis, Bayesian Networks |
| Risk Analysis — Control Effectiveness | Evaluating existing safeguards and preventative measures | Layer of Protection Analysis (LOPA), Bow-Tie Analysis, Cause-Consequence Analysis |
| Risk Evaluation | Comparing analyzed risk levels against risk criteria to decide treatment priorities | Pareto Analysis, ALARP (As Low As Reasonably Practicable), Decision Tree Analysis |
Systematic Selection Criteria Framework
Choosing an inappropriate risk assessment technique can lead to misallocated resources, false confidence, or complete failure to identify critical vulnerabilities. IEC 31010:2019 defines five primary criteria that must govern technique selection:
1. Purpose and Decision Context
The decision context dictates the required analytical depth. Strategic decisions (e.g., entering a new foreign market or executing a corporate acquisition) require broad qualitative scenario techniques to capture political, legal, and macroeconomic uncertainties. Conversely, operational engineering decisions (e.g., designing an offshore gas platform safety shutdown valve) require precise quantitative failure mode analyses.
2. System Life Cycle Stage
An organization or asset evolves through distinct life cycle phases. Techniques must adapt accordingly:
- Concept and Definition Phase: Data is highly uncertain or non-existent. Broad, qualitative techniques such as Brainstorming, SWIFT, or Delphi are used to define boundary risks.
- Design and Development Phase: System architecture is defined. Semi-quantitative tools such as HAZOP, FMEA, and Bow-Tie Analysis identify structural and design vulnerabilities.
- Implementation and Operation Phase: Operational history exists. Quantitative techniques such as Fault Tree Analysis (FTA), Markov Analysis, and statistical reliability modeling monitor ongoing risk levels.
- Decommissioning Phase: Focus shifts to environmental, legal, and site remediation risks using targeted checklists and scenario analysis.
3. Data Availability and Resource Constraints
Quantitative techniques require large volumes of reliable empirical data, specialized software, and trained analytical personnel. If reliable statistical data is absent, attempting full quantitative modeling creates misleading precision (the "garbage in, garbage out" trap). Under severe time, budget, or data constraints, structured qualitative methods provide far greater practical value.
4. Decision Complexity and System Uncertainty
Systems characterized by non-linear dependencies, human behavioral interactions, or extreme complexity cannot be modeled using simple linear checklists. Complex, tightly coupled systems require dynamic techniques like Bayesian Networks, System Dynamics modeling, or multi-disciplinary workshop evaluations.
5. Quantitative Capability and Output Requirements
Risk managers must understand what output stakeholders require. If executive leadership requires monetary loss distributions (e.g., annual loss expectancy for insurance purchasing), quantitative techniques such as Monte Carlo Simulation must be selected.
+---------------------------------------------------------------------------------------------------+
| IEC 31010 SELECTION MATRIX SUMMARY |
+-----------------------------+-----------------------+-----------------------+---------------------+
| Technique | Life Cycle Stage | Data Requirement | Output Type |
+-----------------------------+-----------------------+-----------------------+---------------------+
| Delphi Technique | Concept / Design | Low (Expert Judgment) | Qualitative |
| SWIFT | Concept / Operations | Low-Medium | Qualitative |
| HAZOP | Design / Operations | Medium (Design Specs) | Qualitative / Semi |
| Failure Mode & Effects (FMEA)| Design / Build | Medium-High | Semi-Quantitative |
| Bow-Tie Analysis | Operations / Design | Medium | Qualitative / Semi |
| Fault Tree Analysis (FTA) | Operations / Maintain | High (Failure Rates) | Quantitative |
| Monte Carlo Simulation | Operations / Finance | High (Distributions) | Fully Quantitative |
+-----------------------------+-----------------------+-----------------------+---------------------+
Practical Application Example: Financial Technology Infrastructure Deployment
Consider a retail bank introducing an AI-driven digital lending platform. During the initial project kickoff (Concept Stage), the risk team utilizes SWIFT and Delphi workshops with cybersecurity, compliance, and credit risk experts to identify macro threats (e.g., algorithmic bias, regulatory changes, vendor reliance). As software architecture is finalized (Design Stage), the team applies FMEA to evaluate individual API failure modes and data pipeline latency. Finally, during live operation (Operations Stage), the risk department deploys continuous quantitative monitoring using historical transaction failure data and automated Bayesian Networks to assess real-time operational risk.
By leveraging the IEC 31010 selection framework, the bank avoids over-engineering early conceptual reviews while ensuring that critical operational phases receive rigorous quantitative oversight.
What is the primary role of IEC 31010:2019 within the ISO 31000 risk management framework?
Which factor is most critical when selecting a qualitative risk assessment technique during the early concept and design stage of a novel engineering project?
According to the selection criteria in IEC 31010:2019, under what conditions is a semi-quantitative or fully quantitative technique preferred over a purely qualitative technique?