Quick answer: Matching ISO 31000 and IEC 31010 techniques to each stage of the risk cycle replaces guesswork with genuinely defensible analysis. How applied risk assessment technique selection delivers precision under pressure, not just paperwork.
Originally published on LinkedIn: 29 June 2026.
In the modern enterprise, risk is too often relegated to intuition — a collection of vague apprehensions discussed in boardrooms without a unifying syntax. That reliance on gut feeling creates a dangerous illusion of certainty, leaving leadership ill-equipped to manage the variables that influence objectives amid uncertainty. When volatility strikes, unstructured approaches offer no shelter. High-maturity organisations instead leverage the ISO 31000 and IEC 31010 frameworks, which convert qualitative anxiety into disciplined, defensible, and where possible quantitative judgement.
Boards, executives, managers, and specialists across safety, security, risk, and resilience — particularly those responsible for essential, critical, and vital infrastructure — should treat this alignment as a professional obligation. Systemic failures follow when the chosen technique does not match the stage of the risk management cycle it is meant to serve.
Risk assessment is a three-act process, not a single event
A common failure in strategic management is treating risk assessment as one monolithic event. In the ISO 31000 architecture, the process is tripartite, and conflating its stages produces catastrophic errors in judgement. Risk identification is the discovery phase, using techniques such as Failure Modes and Effects Analysis (FMEA) or Hazard and Operability Studies (HAZOP) to map the threat landscape and support operational resilience. Risk analysis is the investigative phase, where the nature and magnitude of a risk are examined in depth. Risk evaluation is the decision phase, where findings are weighed against established criteria under principles such as ALARP (as low as reasonably practicable) or SFAIRP (so far as is reasonably practicable).
Evaluating a risk's acceptability before completing a rigorous analysis produces false confidence in risk appetite. IEC 31010 is explicit that techniques vary in their applicability to identification, analysis, and evaluation — treating the three as interchangeable is a structural error, not a shortcut.
Analysis is where the heavy lifting happens
Identification sets the stage, but analysis is where the real intellectual and technical work occurs. IEC 31010 dedicates five distinct technique groups almost exclusively to this phase — more concentrated specialisation than any other stage receives. Understanding consequence and likelihood calls for sophisticated methods: root cause analysis to identify the primary drivers of volatility, Monte Carlo simulation to project a range of potential outcomes, Bayesian networks to calculate conditional probabilities in complex systems, and causal mapping or cross-impact analysis to trace dependencies and interactions between risks. Identification is a prerequisite. The true value, and the highest technical barrier, sits in the analysis required to quantify uncertainty.
Different risks demand different techniques
A one-size-fits-all toolset leaves an organisation exposed. The ISO taxonomy is deliberately layered: techniques for eliciting views, such as brainstorming or the Delphi technique, are strongly applicable to identification but only moderately useful for evaluation. Techniques for determining sources, causes, and drivers work the other way — applicable to identification but strongly applicable to analysis. High-precision tools sit at the other end of the spectrum: measures of risk such as toxicological risk assessment, Value at Risk, and data protection impact analysis are essential for quantitative analysis, while techniques for selecting between options — game theory and cost-benefit analysis — help leadership make trade-offs at the evaluation stage. Applying a qualitative discovery tool to a problem that demands quantitative measurement is not a minor methodological slip; it is a strategic failure that leaves an organisation blind to tail-risk events.
The process only works if it is underpinned by reporting
ISO 31000 is not a linear path that terminates at evaluation. Recording and reporting underpin every step, and the framework rewards dual-use tools. Bow-tie analysis, for instance, is strongly applicable to analysing controls and also serves as a primary tool for recording and reporting. That reporting layer is the connective tissue of the whole system: the risk register functions as a centralised audit trail rather than a simple list, S-curves provide a cumulative probability distribution so stakeholders can visualise the likelihood of meeting objectives, and consequence-likelihood matrices standardise how risk posture is communicated across the enterprise. Even the most rigorous analysis is worthless if it is not captured in a form that supports continuous monitoring and review.
From guesswork to framework
Moving to a structured taxonomy such as IEC 31010 shifts an organisation's culture from reactive firefighting to disciplined foresight. Breaking the process into its three-act structure — identification, analysis, evaluation — and applying the correct group of techniques at each stage replaces best guesses with a defensible, evidence-based approach. Business impact analysis and toxicological risk assessment help pinpoint the key risk indicators worth monitoring before threats escalate; causal mapping and cross-impact analysis expose the hidden dependencies that drive cascading failures across complex systems; and decision tree analysis, game theory, and cost-benefit analysis support leaders navigating genuine decision points. The greatest danger is rarely the hazard nobody anticipated. It is the complacent assumption that a documented risk is a neutralised one.
Tony Ridley, MSc, CSyP, FSyI, SRMCP works with boards and executive teams to map their risk assessment toolkit against the ISO 31000 and IEC 31010 stages, closing the gap between the techniques an organisation uses and the ones its critical infrastructure and operating environment actually demand. Contact EMA Global to review whether your current risk assessment techniques are matched to the stage of the cycle they are meant to serve.