Reference

Lightning protection risk assessment

A lightning protection risk assessment decides whether a structure needs protection, and how much. It is a calculation, not an opinion. This page sets out what the work involves, who it applies to, where its numbers come from, and what makes a result you can defend in a review.

A lightning bolt striking behind an industrial building, the exposure an IEC 62305 assessment quantifies

A lightning protection risk assessment answers one question with a number: is the risk to this structure higher than the level that can be tolerated?

Everything else follows from that comparison. IEC 62305-2:2024 (Ed.3) clause 7.3 puts it in one line: you need protection when R sits above the tolerable level RT, and where it does, you add measures until R is no higher than RT. There is no separate judgement about whether a building "looks exposed", and no height above which protection becomes automatic.

That makes the assessment a piece of engineering work with a defined input set and a reproducible output, and it is why two competent engineers assessing the same building should arrive at the same verdict. This page covers the work itself: what falls inside the assessment, who it applies to, where the numbers come from, what the report has to show, and the places practitioners most often get it wrong. The arithmetic of the risk components is set out separately in the IEC 62305-2 risk assessment method.

Scope

What the assessment actually covers

The scope is defined, not assumed. IEC 62305-2:2024 (Ed.3) clause 7.2 lists what counts as the structure under assessment: the building itself, the installations it carries, its contents, anyone inside it or on its roof or standing within 3 m of its walls, and whatever the surroundings suffer when the building is damaged.

Two parts of that list are regularly missed. The first is the 3 m band outside the building, which is what brings a person standing near a down conductor into the calculation rather than leaving them outside it. The second is the contents and the people, which is why an assessment depends on what a building is used for and not only on its shape. A warehouse and a school of identical dimensions in identical locations do not produce the same result.

Connected lines sit at the boundary. The same clause counts a line outside the building only so far as it can bring a damaging current indoors. A power or telecom service is therefore in scope as a route into the building, and the cable run itself is not the thing being protected.

A large or mixed-use structure is usually divided into risk zones, and where it is, the standard asks for R against RT zone by zone, and for the building as a whole only where it holds a single zone. That distinction matters in practice: a building can pass on an averaged view and still contain a zone that fails.

Applicability

Who needs a lightning protection risk assessment

The standard defines three types of loss, and which of them applies to your structure decides what has to be calculated.

L1

Injury to human beings

Loss from injury to people, death included. Clause 5.3 notes it can also follow from failure of internal systems where that endangers life, and it names buildings at risk of explosion, and hospitals, as the examples.

L2

Physical damage

Loss from physical damage to the structure and its contents. Clause 5.3 NOTE 2 records that loss of national heritage is covered here rather than by a loss type of its own.

L3

Failure of internal systems

Loss from failure of internal systems. NOTE 1 is specific that this is about surges affecting the function those systems provide, not physical damage to them.

The same clause gives the applicability rule: run the risk calculation for any structure that carries loss type L1 or loss type L2. Since almost every occupied or valuable building carries one of those, the practical answer to "does this need an assessment" is usually yes. Where L3 is the concern, the standard adds a frequency of damage calculation performed in addition to the risk calculation, and it is explicit that where such a failure would harm the environment, or reaches equipment that safety depends on, it belongs in the risk calculation rather than the frequency of damage.

Obligation

Required, or advisable?

These are different questions and it is worth separating them early on a project. IEC 62305-2 defines the method and states where it is applicable. What makes an assessment mandatory for a specific building is normally something outside the standard: the national building regulation, the project specification, the insurer, or the authority having jurisdiction.

The standard acknowledges the gap. Clause 7.3 NOTE 2 leaves the choice of whether to reduce R with the building owner or manager wherever no rule obliges a risk evaluation in the first place. So there is a real category of building where nobody compels an assessment and the decision rests with the owner, and there is a much larger category where a regulation or a contract compels it. Establish which one you are in before you start, and record the answer, because it determines who is entitled to set the tolerable value you will be measured against.

The standard is also clear that a computed pass does not end the discussion. Clause 7.3 NOTE 3 points out that where R is already within RT, protection is not necessary to reduce risk, but can still help bring down the frequency of damage to internal systems, or appropriate where you want to reduce loss or service unavailability in any way.

Which standard

The standard that governs your project

Most of the world assesses lightning risk to IEC 62305, reached through a national or regional adoption rather than the international document itself. The technical content of an adoption is the IEC content; what an adoption can carry is a recorded national departure, and those change the arithmetic rather than the method. Germany, Greece and Italy each have one, and each is documented in the standard's own list of differing practices.

The United States is the significant exception, working to NFPA 780 instead. If your project sits under a US specification, or under a specification that names both, settle which one governs before you calculate, because the two are separate documents with separate methods and a result computed under one is not a result under the other. The comparison is set out in NFPA 780 vs IEC 62305.

The edition matters as much as the standard. IEC 62305 was revised in 2024, and the third edition changed things that move numbers, including the move to a ground strike-point density. An assessment carried out on the 2010 method is not wrong arithmetic, it is a result under a superseded model, and a reviewer citing the current edition will treat it as such. See what changed in IEC 62305:2024 and IEC 62305 around the world.

The strike rate

Where the lightning data comes from

Annex A gives three sources for the ground strike-point density NSG, in a clear order of preference. A report should say which one it used.

Preferred

Measured LLS data

Clause A.1 records that across much of the world NSG comes from lightning location system data meeting IEC 62858, and clause 8.1 names that data as the main source for the dangerous-event rate. This is the strongest input available.

Equation (A.1)

Scaled from flash density

Where NSG is not directly available, NSG = k NG scales a ground flash density by a factor k that should come from the national LLS data provider. NOTE 1 allows a factor of 2 to be assumed where the provider cannot supply it, for example where only an NG map exists.

Equation (A.2)

Satellite estimate

Where no ground-based location network covers the site, the standard recommends NSG = 0,5 NT, where NT is the total density of optically recorded flashes, cloud-to-ground and intracloud together, from satellite climatology data.

The reason to record which rung you used is that they carry different confidence, and the difference is not small. A k factor assumed as 2 because no provider value exists is a defensible choice made under a NOTE in the standard, and it is a weaker input than a measured density for the site. Annex A is informative rather than normative, which makes stating your source a matter of professional honesty rather than a box to tick. A single density figure printed with no provenance is the most common untraceable number in this field.

The threshold

The tolerable risk is not a fixed constant

RT is widely quoted as though the standard fixes it at 10-5 per year. It does not, and the wording is unambiguous. Clause 7.3 NOTE 1 gives RT = 10-5 per year as a representative value of tolerable risk, and adds that another value may be set once the case has been investigated in detail, weighing how exposed people are inside and around the building under assessment and how much the public depends on that building and its surroundings.

The standard goes further and allows national or local regulations to fix RT, the tolerable frequency of damage FT, and the calculation rules and parameter values of its annexes. So the tolerable value is properly resolved from the jurisdiction and the project, with the representative figure as the default where nothing else is specified. Carrying it as a hardcoded constant is a modelling error, not a simplification.

The tolerable frequency of damage is treated the same way. Clause 9.3 NOTE 1 offers FT = 0,1 per year for internal systems critical to the service being maintained and FT = 1 per year for non-critical systems, and calls these typical values. NOTE 2 then puts the choice with the owner or manager of the structure, who is the one who knows what service unavailability can be tolerated. That is a conversation to have and record, not a number to pick quietly.

The practical consequence is that "the risk passed" is an incomplete statement. What passed is a comparison against a threshold that somebody chose, and a report that does not say who chose it, or on what basis, has left out the part a reviewer will ask about first.

The deliverable

What a defensible assessment contains

The test is simple. Can a competent stranger take your report and reproduce your verdict without asking you a question?

01

Edition and jurisdiction

Which edition of the standard the result is computed under, which national adoption governs, and any recorded departure applied. This frames every number that follows.

02

Inputs with sources

Every input, and where it came from. The density figure with its rung of Annex A, each table selection with its table, each dimension with its drawing. An input with no source cannot be checked.

03

Components, not just a total

The risk broken into its components, per zone where the structure is zoned. A single total hides which mechanism drives the result, and therefore hides what a mitigation would need to act on.

04

Threshold and verdict

The tolerable value used, who set it, the comparison for each zone, and the measures specified where the risk exceeded it. Where it could not be brought within the level, the residual risk stated plainly.

Where the best measures on offer still leave R above the tolerable level, the standard does not let that hang. Clause 7.3 NOTE 5 says the site owner is informed, and that where temporary preventive measures can significantly reduce the risk, a thunderstorm warning system per IEC 62793 can be installed. The deliverable in that case is a communicated residual risk plus an operational response. Read more on what makes a report audit-ready and on why the result has to be traceable.

Common errors

Where assessments go wrong

Treating the tolerable risk as a law of nature. Covered above, and the most frequent. The representative value is a default, and in a jurisdiction that has fixed its own it is the wrong number.

A density figure with no provenance. If the report does not say whether the strike-point density came from a lightning location system, from a scaled flash density, or from a satellite estimate, the reader cannot weigh the result. The three are not interchangeable.

Averaging a zoned structure. Where a structure is partitioned into risk zones, the comparison against the tolerable value belongs to each zone. A structure-level average can report a pass over a zone that fails.

Running the previous edition. Spreadsheets and templates outlive standards. A calculation still encoding the 2010 model produces a result under a model that has been replaced, and the change to ground strike-point density alone can move a verdict.

Confusing the risk assessment with the design. The assessment decides whether protection is needed and to what level. Designing the physical protection system, the air terminations, down conductors and earthing, is the work of IEC 62305-3 and a separate exercise. Read lightning protection levels for how the two connect.

Letting a language model write the numbers. A risk assessment is a computation with a defined method. Text that resembles an assessment is not an assessment, and a figure that cannot be recomputed cannot be signed.

Keeping it current

When to reassess

An assessment is a function of its inputs, and clause 7.2 lists what those inputs describe: the structure, its installations, its contents, the people in and around it, and the environment affected by damage to it. Change any of them and the result can move.

In practice that means a change of use, an extension or a new storey, a new incoming power or telecom service, a change in what is stored or manufactured inside, the removal or addition of fire provisions, new construction nearby that changes how sheltered the location is, or a revision of the standard itself. Each is a reason to recompute rather than to reissue.

Any fixed review interval you are working to comes from your jurisdiction, your insurer or your project specification rather than from the risk method, so check where yours comes from. Note that the physical protection system carries its own separate obligation: the periodic inspection of an installed system belongs to IEC 62305-3, and is covered in IEC 62305-3 and its inspection.

Where to go next

Related reading

For the method behind the verdict, the risk components and how they are built, read the IEC 62305-2 risk assessment method. For the arithmetic worked through on a real building, see how IEC 62305 risk is calculated. For the standard as a whole and its four parts, start at what is IEC 62305.

Sector guides cover the cases where one mechanism dominates: data centres, hospitals, renewable energy sites, oil, gas and hazardous facilities, telecom sites and heritage buildings.

Where Lumex fits

The assessment, computed and traced

Lumex runs the IEC 62305-2 procedure on the current third edition and keeps the trace behind every figure, so the report shows the inputs, their sources, the components per zone, the tolerable value it was measured against and the clause each of those comes from. The jurisdiction is an input, so a recorded national departure is applied before the calculation runs rather than noted afterwards.

What it does not do is replace the engineer. The physical design belongs to IEC 62305-3 and to a competent person, and responsibility for every result rests with whoever signs it. See the Lumex platform, or read how the assessment is computed clause by clause.

FAQ

Questions answered

What is a lightning protection risk assessment?

It is a calculation that decides whether a structure needs lightning protection, and if so how much. Under IEC 62305-2 it turns the building, its surroundings, its contents, the people in and around it and the services entering it into a risk R, then compares that risk against a tolerable level R_T. Clause 7.3 sets the rule: you need protection when R sits above the tolerable level R_T, and where it does, you add measures until R is no higher than R_T. It is not a checklist and not a rule of thumb about building height.

Who needs a lightning protection risk assessment?

IEC 62305-2:2024 (Ed.3) clause 5.3 puts every structure carrying loss type L1 or L2 in scope for the risk calculation. L1 is injury to people and L2 is physical damage to the building and what it holds, so in practice that covers almost any occupied or valuable building. Where L3 is the concern, meaning failure of the electrical and electronic systems inside, the standard adds a frequency of damage calculation alongside the risk calculation. What makes an assessment mandatory for a particular project is usually the contract, the building regulation or the authority having jurisdiction rather than the standard itself, so confirm that at the start.

Is the tolerable risk always 10 to the power minus 5 per year?

No, and treating it as a universal constant is one of the most common errors in this field. IEC 62305-2:2024 clause 7.3 NOTE 1 gives R_T = 10 to the power minus 5 per year as a representative value, and says another value may be set once the case has been investigated in detail, weighing how exposed people are inside and around the building and how much the public depends on it. The standard also allows national or local regulations to fix R_T, the tolerable frequency of damage F_T, and the calculation rules and parameter values of its annexes. So the tolerable value is resolved from the jurisdiction and the project, and the representative figure is the default you use when nothing else is specified.

Where does the lightning strike rate in an assessment come from?

From the ground strike-point density N_SG for the location, and IEC 62305-2 Annex A gives three sources in order of preference. First, measured data from a lightning location system complying with IEC 62858, which is the source clause 8.1 names as the main one. Second, where an N_SG value is not directly available, equation (A.1) scales a ground flash density N_G by a factor k obtained from the national data provider, with NOTE 1 allowing a factor of 2 to be assumed when the provider cannot supply it. Third, where no ground-based location network covers the site, equation (A.2) estimates N_SG as 0,5 multiplied by N_T, the total density of optically recorded flashes from satellite data. A report should say which of the three it used, because they are not equally strong.

What does a lightning protection risk assessment report need to contain?

Enough for someone else to reach the same number. That means the edition of the standard used, the jurisdiction and any national departures applied, every input with its source, the tolerable value and why it was chosen, the risk components broken out rather than a single total, the comparison against the tolerable value, and the protection measures specified where the risk exceeded it. If the structure was divided into risk zones, the report shows the comparison for each zone. A verdict with no trace behind it cannot be checked, and an assessment that cannot be checked cannot be defended.

Does the assessment cover the area outside the building?

Partly, and the boundary is defined. IEC 62305-2:2024 (Ed.3) clause 7.2 draws it. In scope are the building, the installations and contents inside it, anyone inside it or on its roof or standing within 3 m of its walls, and whatever the surroundings suffer when the building is damaged. A line running outside counts only so far as it can bring a damaging current indoors. So a person standing next to a down conductor is inside the scope of the calculation, and a neighbouring building is not, except through the environmental effect of damage.

When does a lightning protection risk assessment need to be redone?

When an input to it changes. The assessment is a function of the structure, its contents, its occupancy, its connected services, its surroundings and the protection in place, so a change of use, an extension, a new incoming service, a change in what is stored inside, new construction nearby that alters the shielding of the location, or a revision of the standard can all move the result. Treat the assessment as a live document tied to those inputs rather than a one-off certificate, and check whether your jurisdiction or insurer sets its own review interval.

What happens if the risk cannot be brought below the tolerable level?

The standard addresses this directly. IEC 62305-2:2024 (Ed.3) clause 7.3 NOTE 5 covers it. The site owner is told whenever the best measures on offer still leave R above the tolerable level. Where temporary precautions would cut the risk a long way, a thunderstorm warning system to IEC 62793 may be added. The outcome in that case is a documented, communicated residual risk and an operational response, not a silently failed calculation.

What Lumex does, and what stays with you

Lumex computes the IEC 62305-2 method and shows the working. It does not certify a structure. You may not issue or submit a Lumex output until a competent person, qualified where the structure is located, has reviewed the inputs and the result and signed it.

The tolerable risk in IEC 62305-2 is not a fixed constant. Clause 7.3 NOTE 1 gives RT = 1×10-5 per year as a representative value of tolerable risk and adds that another value may be set once the case has been investigated in detail. Printed p.12 then lets national or local regulations fix RT, the tolerable frequency of damage FT, and the Annex A, B, C and E calculation rules and parameter values. Every Lumex assessment states the jurisdiction it was computed under and the values that applied.

Get started today

Run a traceable assessment on your own building

Contact our team