Element 05 · IOGP 510
Risk Assessment and Control
Purpose
To define how risk is identified, assessed, controlled, accepted and changed — the structured discipline by which the organisation knows what could go wrong, what it has done about it, who has authority to accept what remains, and how change to any of that is governed. MoC applies enterprise-wide: operational, organisational, financial, legal and technical change all flow through here.
The challenge it forces
"Most operators have plenty of risk assessments and very little risk control. This element demands evidence that an identified risk has a named control, an accountable owner, and a way to know if the control has degraded. If MoC is treated as paperwork to clear, the organisation has no real control over its own risk profile — which is also its own change profile."
What lives here
- ·Risk assessment methodologies (HAZID, HAZOP, HIRA, Bowtie analysis)
- ·Risk registers (People Risk Register, Reservoir Risk Register, Supply Chain Risk Register)
- ·Risk acceptance and authority frameworks
- ·ALARP demonstration and barrier health (Bowtie/Barrier Engineering Input, Barrier Management Process)
- ·Management of Change (MoC) — the process itself: design MoC, organisational MoC, technical deviation, temporary equipment
- ·Specific scenario assessments (SIMOPS, Stress Risk Assessment, Sanctions Exposure Review)
What does not live here
- →The standards against which risk is judgedE2 Policies
- →The procedures by which a risk control is executed in the fieldE7 Procedures
- →The verification that a risk control is workingE10 Assurance
- →Findings that feed into MoC from monitoring and auditE9 Monitoring
Upstream O&G expectations (4)
- 5.1Processes manage risks to an acceptable level: identify hazards and risks across all functions, assess risks, implement controls and barriers.
- 5.2Significant risks are documented and communicated; risk acceptance is approved at appropriate levels.
- 5.3Temporary and permanent changes — operational, organisational, financial, legal, technical — are subject to a formal, risk-based MoC process, with timeframes and actions tracked to completion.
- 5.4Maintain a culture of risk awareness across all functions — vulnerabilities, non-conformances and weak signals are recognised and surfaced.
Upstream O&G adaptation notes
Status:Same as IOGP, applied at full enterprise scope
The company applies this element across every function's risk — operational, integrity, people, supply chain, financial, legal, subsurface uncertainty. One MoC process, one acceptance authority framework.
- ·MoC location is aligned with IOGP base position — change is a risk-control act and lives here, not in Element 7. Some operators have historically misread the framework. The company is faithful to IOGP 510.
- ·Scope is enterprise-wide. Risk and MoC apply across all functions, not behind separate departmental walls.
Framework comparison — IOGP 510 base · Upstream O&G adaptation
IOGP 510 base expectations
- 1.Processes manage risks to an acceptable level: identify hazards, assess risks, implement controls/barriers.
- 2.Document and communicate risk management for significant risks; risk acceptance approval at appropriate levels.
- 3.Temporary/permanent changes are subject to a formal, risk-based MoC process with timeframes and actions tracked to completion.
- 4.Maintain a culture of risk awareness — vulnerabilities, non-conformances, weak signals are recognised.
Upstream O&G adapted expectations
- 1.Processes manage risks to an acceptable level: identify hazards and risks across all functions, assess risks, implement controls and barriers.
- 2.Significant risks are documented and communicated; risk acceptance is approved at appropriate levels.
- 3.Temporary and permanent changes — operational, organisational, financial, legal, technical — are subject to a formal, risk-based MoC process, with timeframes and actions tracked to completion.
- 4.Maintain a culture of risk awareness across all functions — vulnerabilities, non-conformances and weak signals are recognised and surfaced.
By department
Engineering
This is where Engineering does its most consequential work: identifying, assessing, controlling, accepting and changing technical risk. MoC sits in Element 5 (the IOGP 510 base position) — which keeps…
15 docs →
Operations & Maintenance
This element holds operational risk control — operational risk assessments, integrity risk management, MoC for operations, and deferral / production risk decisions.
10 docs →
HSSE
This element is where HSSE risk is identified and controlled — occupational, environmental and security risk, organisational change, and the registers that show what could go wrong.
11 docs →
Commercial
This element is where PSCM becomes a risk-control function — contractor HSE risk, supply chain risk, single-source risk and late-life contracting risk.
4 docs →
Finance & Legal
This element holds financial and legal risk — financial risk, fraud risk, legal risk, sanctions exposure and dispute risk.
5 docs →
HR / People
This element reframes HR as a risk-control function — managing people risk, fitness-for-work, safeguarding and the human consequences of change.
2 docs →
Business Services
This element holds information and cyber risk — the information security management system, cyber risk management and disaster recovery.
4 docs →
Subsurface
This element holds the management of uncertainty — scenario planning, sensitivity analysis, decision-gate risk assessment and the reservoir risk register.
5 docs →
Wells
This element holds the core of wells safety — risk assessment, barrier management, well control risk, SIMOPS and abnormal-situation management.
5 docs →