IEC 31010:2019
Guidance on planning and carrying out a risk assessment and choosing assessment techniques: scope and criteria, information and models, identifying risk and causes, analysing controls, consequences, likelihood and dependencies, measuring and aggregating risk, verification, decisions, reporting and technique selection.
IEC 31010:2019 is a compliance framework from International (IEC/SC 62A with ISO/TC 262) with 8 domains and 32 controls. The largest domains are Clause 6.3: Apply risk assessment techniques – IEC 31010:2019 (10 controls), Clause 6.1: Plan the assessment – IEC 31010:2019 (9 controls), Clause 6.2: Manage information and develop models – IEC 31010:2019 (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Clause 5: Uses of risk assessment techniques – IEC 31010:2019
| Code | Title |
|---|---|
| iec-31010-2019::5 | 5 Uses of risk assessment techniques |
Clause 6.1: Plan the assessment – IEC 31010:2019
| Code | Title |
|---|---|
| iec-31010-2019::6.1.1 | 6.1.1 Define purpose and scope of the assessment |
| iec-31010-2019::6.1.2 | 6.1.2 Understand the context |
| iec-31010-2019::6.1.3 | 6.1.3 Engage with stakeholders |
| iec-31010-2019::6.1.4 | 6.1.4 Define objectives |
| iec-31010-2019::6.1.5 | 6.1.5 Consider human, organizational and social factors |
| iec-31010-2019::6.1.6.1 | 6.1.6.1 Review criteria for decisions: general |
| iec-31010-2019::6.1.6.2 | 6.1.6.2 Criteria for deciding whether risk can be accepted |
| iec-31010-2019::6.1.6.3 | 6.1.6.3 Criteria for evaluating the significance of risk |
| iec-31010-2019::6.1.6.4 | 6.1.6.4 Criteria for deciding between options |
Clause 6.2: Manage information and develop models – IEC 31010:2019
| Code | Title |
|---|---|
| iec-31010-2019::6.2.1 | 6.2.1 Manage information: general |
| iec-31010-2019::6.2.2 | 6.2.2 Collecting information |
| iec-31010-2019::6.2.3 | 6.2.3 Analysing data |
| iec-31010-2019::6.2.4.1 | 6.2.4.1 Developing and applying models: general |
| iec-31010-2019::6.2.4.2 | 6.2.4.2 Using software for analysis |
Clause 6.3: Apply risk assessment techniques – IEC 31010:2019
| Code | Title |
|---|---|
| iec-31010-2019::6.3.1 | 6.3.1 Applying techniques: overview |
| iec-31010-2019::6.3.2 | 6.3.2 Identifying risk |
| iec-31010-2019::6.3.3 | 6.3.3 Determining sources, causes and drivers of risk |
| iec-31010-2019::6.3.4 | 6.3.4 Investigating the effectiveness of existing controls |
| iec-31010-2019::6.3.5.1 | 6.3.5.1 Analysing the type, magnitude and timing of consequences |
| iec-31010-2019::6.3.5.2 | 6.3.5.2 Analysing likelihood |
| iec-31010-2019::6.3.6 | 6.3.6 Analysing interactions and dependencies |
| iec-31010-2019::6.3.7.1 | 6.3.7.1 Determining measures of risk |
| iec-31010-2019::6.3.7.2 | 6.3.7.2 Aggregating measures of risk |
| iec-31010-2019::6.3.7.3 | 6.3.7.3 Societal risk |
Clause 6.4: Review the analysis – IEC 31010:2019
| Code | Title |
|---|---|
| iec-31010-2019::6.4.1 | 6.4.1 Verifying and validating results |
| iec-31010-2019::6.4.2 | 6.4.2 Uncertainty and sensitivity analysis |
| iec-31010-2019::6.4.3 | 6.4.3 Monitoring and review |
Clause 6.5: Apply results to support decisions – IEC 31010:2019
| Code | Title |
|---|---|
| iec-31010-2019::6.5.2 | 6.5.2 Decisions about the significance of risk |
| iec-31010-2019::6.5.3 | 6.5.3 Decisions that involve selecting between options |
Clause 6.6: Record and report – IEC 31010:2019
| Code | Title |
|---|---|
| iec-31010-2019::6.6 | 6.6 Record and report risk assessment process and outcomes |
Clause 7: Selecting risk assessment techniques – IEC 31010:2019
| Code | Title |
|---|---|
| iec-31010-2019::7.2 | 7.2 Selecting techniques |
What is IEC 31010:2019 and who does it apply to?
IEC 31010:2019 is a compliance framework from International (IEC/SC 62A with ISO/TC 262) with 8 domains and 32 controls. Guidance on planning and carrying out a risk assessment and choosing assessment techniques: scope and criteria, information and models, identifying risk and causes, analysing controls, consequences, likelihood and dependencies, measuring and aggregating risk, verification, decisions, reporting and technique selection. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does IEC 31010:2019 actually require?
IEC 31010:2019 has 32 controls organised across 8 domains. The largest domains are Clause 6.3: Apply risk assessment techniques – IEC 31010:2019 (10 controls), Clause 6.1: Plan the assessment – IEC 31010:2019 (9 controls), Clause 6.2: Manage information and develop models – IEC 31010:2019 (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of IEC 31010:2019 do I already cover?
IEC 31010:2019 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement IEC 31010:2019?
Start your IEC 31010:2019 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IEC 31010:2019 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 894 frameworks.
Get Started Free →Free forever — no credit card required