
IEC 31010:2019, published jointly with ISO as a supporting standard to ISO 31000:2018, provides internationally recognized guidance for selecting and applying risk assessment techniques across engineering, financial, and operational domains. It summarizes 41 techniques in its Annex, ranging from simple checklists to quantitative modeling methods, describing each technique’s uses, inputs, outputs, strengths, and limitations. For oil and gas engineers, the standard matters because HAZOP, LOPA, and QRA each answer a different question about risk, and IEC 31010 is the reference point for deciding which question a given hazard actually requires answering.
Most process safety programs default to whichever technique the last project used, HAZOP for everything, or a full quantitative risk assessment regardless of scope. IEC 31010 does not prescribe a fixed technique for a fixed project stage. It describes the characteristics that make a technique suitable for a given purpose, and leaves the selection decision to the assessor. This article covers what IEC 31010 actually says about technique selection, how the main oil and gas techniques differ in the question each one answers, how regional operators and regulators reference the standard, and the selection gaps that generate review comments during safety case submission.
What Is IEC 31010:2019 and How It Relates to ISO 31000
IEC 31010:2019 is the technique-level companion to ISO 31000:2018, not a replacement for technique-specific standards such as IEC 61882 for HAZOP. ISO 31000 establishes the overall risk management process: communication and consultation, scope and context and criteria, risk assessment, risk treatment, monitoring and review, and recording and reporting, applied across an organization. IEC 31010 expands one stage of that process, risk assessment, which ISO 31000 itself defines as three linked activities: risk identification, risk analysis, and risk evaluation.
IEC 31010 indicates how different techniques can contribute to activities such as identifying risks, understanding causes and consequences, estimating likelihood, assessing existing controls, and supporting risk-related decisions. A technique suited to identification, structured brainstorming, for instance, does not automatically produce the quantified output an evaluation decision needs. Selecting a technique that only partially covers the identification-analysis-evaluation sequence a decision requires is one of the gaps reviewers most often raise against process safety documentation.
The standard states explicitly that it is not intended for certification, regulatory, or contractual use on its own. IEC 31010 provides guidance, not a compliance requirement in the way IEC 61511 functions for safety instrumented systems. A facility cannot claim IEC 31010 certification. What auditors and safety case reviewers increasingly expect, however, is that the standard’s selection logic is visible in the documentation, a stated reason why HAZOP was chosen over a broader hazard identification technique, or why LOPA was applied ahead of a full quantitative risk assessment.
Matching the Technique to the Question Being Asked
The most common technique-selection error is not choosing the wrong method in isolation; it is treating HAZOP, LOPA, and QRA as interchangeable alternatives when each is built to answer a distinct question. HAZOP identifies what can go wrong: it examines process deviations node by node against design intent. LOPA asks whether the independent protection layers already in place are adequate for a defined initiating event and consequence, using order-of-magnitude frequency and probability data rather than a fully quantified model. Consequence modeling asks what physical effect, thermal radiation, overpressure, toxic concentration, would result if a scenario occurred. Quantitative risk assessment combines consequence models with frequency data to produce individual and societal risk figures against tolerability criteria. Bow-tie analysis connects threats, preventive barriers, the top event, mitigation barriers, and consequences in a single diagram, making it a communication and barrier-management tool as much as an assessment technique in its own right.
IEC 31010’s Annex catalogs the techniques oil and gas engineers draw on most, alongside their primary process safety use and typical data maturity requirement.
| Technique | Primary Process Safety Use | Typical Data Maturity | Common Oil & Gas Application |
|---|---|---|---|
| Checklist Analysis | Systematic hazard screening | Low | Early design review, compliance checks |
| Structured What-If / SWIFT | Hazard identification through guided questioning | Low to Medium | Concept and modification screening |
| Preliminary Hazard Analysis (PHA) | Early hazard identification and prioritization | Low to Medium | Concept and pre-FEED |
| HAZID (ISO 17776-aligned) | Broad hazard identification | Low to Medium | Concept, pre-FEED, FEED |
| HAZOP (IEC 61882) | Deviation-based hazard analysis | Medium | FEED, detailed design, operations |
| FMEA / FMECA | Failure-mode and equipment or system effects analysis | Medium to High | Rotating equipment, packages, control and electrical systems |
| Bow-Tie Analysis | Threat, barrier, and consequence pathway analysis | Medium | Major accident hazard management |
| Layer of Protection Analysis (LOPA) | Semi-quantitative independent protection layer adequacy | Medium to High | SIL decision support, IPL verification |
| Fault Tree Analysis (FTA) | Cause and failure-combination modeling | High | Complex initiating-event analysis |
| Event Tree Analysis (ETA) | Outcome-sequence modeling following an initiating event | High | Escalation and consequence-path modeling |
| Consequence Analysis | Physical effect modeling | High | Fire, explosion, and toxic release assessment |
| QRA framework | Quantified individual and societal risk estimation, combining several of the above techniques | High | Major accident risk, land-use planning, ALARP studies |
A useful cross-check when scoping a study is to work backward from the decision the study needs to support. What hazards exist points toward a HAZID study, PHA, or SWIFT. How the process can deviate from design intent points toward HAZOP. What equipment or component failures can occur points toward FMEA or FMECA. Whether existing safeguards are adequate points toward LOPA, which feeds the SIL decision under IEC 61508 and IEC 61511. Whether the residual risk is tolerable points toward the applicable risk evaluation criteria, informed by QRA where the scope justifies it.
Recognized for excellence.
PROJECTS DELIVERED ACROSS THE GLOBE
A Practical Lifecycle Application in Oil & Gas Projects
IEC 31010 does not assign specific techniques to specific project stages; that mapping is engineering practice built around the standard’s selection guidance, not a requirement stated in the standard itself. A practical lifecycle application of IEC 31010 principles in oil and gas projects typically favors lower-resolution techniques, checklists, PHA, structured brainstorming, earlier in the project when process configuration and P&ID detail are still evolving, and shifts toward higher-resolution techniques, detailed HAZOP, LOPA, fault tree analysis, as design data matures and the consequence of a wrong decision increases.
A detailed, node-by-node HAZOP may provide limited value if run before the process configuration, P&IDs, and control philosophy have reached sufficient maturity; earlier stages often benefit more from a broader HAZID or PHA, with detailed HAZOP following once the design is fixed. The same logic applies in reverse at the quantitative end: where the study scope is not already prescribed by a regulator, operator standard, or project terms of reference, a preliminary qualitative screening stage can help focus detailed quantitative modeling on the scenarios that materially influence individual, societal, or facility risk, rather than applying full QRA uniformly across a hazard inventory that includes many low-consequence nodes. Where a facility-wide QRA is a fixed regulatory or contractual requirement, that screening step is not optional; the requirement stands regardless of what a preliminary study would have flagged.
Using IEC 31010 Alongside Regional and Operator Requirements
IEC 31010 functions as a common technique-selection reference across jurisdictions, while the studies a specific project must actually deliver are set by local legislation, regulator expectations, operator standards, and project-specific terms of reference. It supplements, rather than replaces, those requirements.
In India, hazard identification and risk analysis obligations for petroleum industry installations are shaped by the applicable standard drawn from the OISD standards list, statutory requirements under environmental clearance and factory licensing processes, and project-specific HIRA and QRA specifications set by the client or the licensing authority. IEC 31010’s technique catalog and selection guidance can inform how a HIRA study is scoped, but the specific studies required for a given facility are determined by the applicable statutory and client requirements rather than by IEC 31010 itself.
In the GCC, ADNOC’s published HSE framework identifies ISO 31000 among the international standards with which its management system aligns, and project-specific ADNOC requirements may additionally prescribe particular hazard and risk studies depending on facility type and project stage. Other GCC operators commonly specify HAZID, HAZOP, LOPA, QRA, and safety case studies through company engineering practices and project-specific HSE requirements, independent of any direct citation to IEC 31010.
Across Southeast Asia, regulatory systems, competent authorities, and major hazard requirements vary by country, and a single regional generalization does not hold across Malaysia, Indonesia, and neighboring jurisdictions. IEC 31010 can still provide a common internal technique-selection framework for a multi-country project, while the mandatory studies for each facility are confirmed against that country’s specific legislation and the operator’s own requirements.
Common Technique-Selection Gaps
Because IEC 31010 is guidance rather than a certifiable requirement, deviating from its selection logic is not a non-conformance in the audit sense; it is a gap that commonly draws review comments at safety case or HAZOP close-out stage. The most frequent gap is technique selection driven by organizational habit, running HAZOP for every hazard class, including scenarios a checklist or PHA would screen more efficiently, without a documented reason tied to the assessment’s purpose, complexity, available information, and the significance of the decision it supports.
A second recurring gap is applying one technique across an entire hazard inventory instead of layering techniques to the scenario. Running full QRA uniformly, including on low-consequence utility systems, delays a submission without adding proportionate risk insight. Relying on qualitative screening alone for scenarios that clearly sit within major accident hazard territory produces the opposite problem: reviewers routinely return submissions that lack the quantified individual risk contours a major hazard facility needs to support its ALARP argument.
A third gap involves output mismatch: treating a technique’s identification-stage output as though it already supports an evaluation-stage decision. A screening-level PHA may not provide sufficient quantitative or barrier-specific evidence to support a final tolerability decision for a major accident scenario, even where it correctly ranks hazards by relative severity. Moving from PHA directly to a risk acceptance decision, without the analysis and evaluation stages IEC 31010 describes as part of the full risk assessment sequence, is a gap reviewers are likely to challenge.
Closing these gaps starts with a documented technique selection rationale at project kickoff: for each hazard category identified during initial screening, which technique was chosen, what data maturity and decision it needs to support, and why. That rationale, built into the project’s process safety basis of design, gives reviewers a traceable answer instead of an assumption, and is what separates a defensible technique choice from one that simply repeats the last project’s approach.
Conclusion
IEC 31010 risk assessment techniques give oil and gas engineering teams a shared reference for choosing between HAZOP, LOPA, QRA, and the other methods in its Annex, based on the purpose, data maturity, and decision each study needs to support, rather than defaulting to whichever technique the last project used. The standard does not fix a technique to a project stage; it describes what each technique is suited for and leaves the selection reasoning to the assessor, which is exactly why that reasoning needs to be documented rather than assumed.
For engineering teams preparing HIRA or safety case submissions across GCC, India, or Southeast Asia, a documented technique selection rationale, tied to hazard category, data maturity, and the decision it supports, closes one of the gaps that most often generates review comments at first submission. iFluids Engineering applies IEC 31010-informed technique selection across HAZID, HAZOP, LOPA, and QRA engagements for upstream, midstream, and downstream facilities in the GCC, India, and Southeast Asia. Speak to our process safety team to scope the right technique mix for your project stage.
Frequently Asked Questions
IEC 31010:2019 provides guidance on selecting and applying risk assessment techniques across the identification, analysis, and evaluation stages that ISO 31000 defines as risk assessment. It summarizes 41 techniques in its Annex, describing each one’s typical uses, inputs, outputs, strengths, and limitations. Oil and gas engineers use it to support the choice between techniques such as HAZOP, LOPA, and QRA for a given hazard and decision.
IEC 31010 states explicitly that it is not intended for certification, regulatory, or contractual use on its own, so it functions as guidance rather than a compliance requirement. Regional operators and regulators, including OISD-based requirements in India and ADNOC’s HSE framework in the GCC, reference broader ISO 31000-aligned risk management without mandating direct citation of IEC 31010. Safety case reviewers increasingly expect its selection logic to be visible in documentation even without a formal citation requirement.
IEC 31010:2019 summarizes 41 risk assessment techniques in its Annex, an expansion from the 2009 first edition. Not every technique applies to process safety; oil and gas engineers typically draw from a working set that includes checklists, PHA, HAZID, HAZOP, FMEA, bow-tie analysis, LOPA, fault tree and event tree analysis, consequence modeling, and the quantitative risk assessment framework that combines several of these methods.
ISO 31000:2018 establishes the overall risk management process, covering scope, context and criteria, risk assessment, risk treatment, monitoring and review, and recording and reporting. IEC 31010:2019 is the supporting standard that expands the risk assessment stage of that process by describing the characteristics, uses, and limitations of specific techniques. An organization implements ISO 31000 as its management framework and draws on IEC 31010 when deciding which technique to apply to a specific risk assessment task.
Technique selection should consider the purpose and scope of the assessment, the nature and complexity of the decision, the degree of uncertainty and information available, the resources and expertise required, and the form of output the decision needs. Lower-consequence scenarios with limited data typically call for qualitative techniques such as checklists or PHA. Higher-consequence scenarios with mature design data typically call for LOPA, fault tree analysis, or a quantitative risk assessment, often following a qualitative screening stage.
HAZOP identifies what can go wrong by examining process deviations against design intent at each node. LOPA verifies whether the independent protection layers already credited for a specific scenario are adequate, using order-of-magnitude frequency and probability data. QRA combines consequence modeling with frequency data across a hazard set to produce quantified individual and societal risk figures against tolerability criteria. Each answers a different question, and a complete risk basis for a major hazard facility typically draws on more than one.