Bow-tie risk assessment turns a single top event into a visual map of every credible threat that could cause it, every consequence that could follow, and the specific barriers standing between them — with a named owner and a performance standard for each. A bow tie risk assessment is most valuable not as a diagram but as the discipline it forces: naming barriers precisely enough that someone can actually verify whether each one is working. This guide sets out the seven-step method, a barrier-quality test, a fully worked example for an Indian process plant scenario, and a template for running your own workshop.
Bow-tie analysis is a risk-assessment method that places a top event at the center, threats and their preventive barriers on the left, and consequences and their mitigative barriers on the right, producing a single diagram that shows how a hazard is controlled from cause through to consequence. Unlike a hazard identification list, a bow-tie forces every barrier to be specific enough to have an owner, a performance standard and an assurance activity — a barrier you cannot verify is not a real barrier.
What bow-tie analysis is
A bow-tie diagram gets its name from its shape: threats converge from the left into a top event at the center, and consequences diverge to the right, resembling a bow tie when barriers are drawn as vertical bars across each connecting line. The method's real value is not the visual — it is that drawing the diagram forces a team to be explicit about which barrier stops which threat, rather than relying on a general sense that "controls are in place." A generic entry like "training" or "procedures" on a bow-tie is a warning sign that the barrier has not been thought through to the level of specificity the method requires.
When to use bow-tie assessment
Bow-tie is best applied to major-accident or high-consequence hazards where multiple independent barriers are expected to exist — process safety scenarios like loss of containment, major fires, structural collapse or transport incidents involving hazardous materials — rather than to routine, lower-consequence tasks better served by a JSA. It is commonly used after a HAZOP or PHA has already identified the hazard and the deviation that could cause a loss of control, to convert that finding into a barrier-and-ownership model that operations can manage day to day. It is also a natural framework for consolidating lessons from an incident investigation into the barrier structure, showing precisely which barrier was missing, failed or degraded rather than just what happened.
Sites frequently prioritize which top events get a full bow-tie treatment by starting with the scenarios already flagged as major-accident hazards in a site risk assessment, quantitative risk assessment or environmental clearance condition, since these are the scenarios where regulators, insurers or corporate risk owners are most likely to expect documented barrier assurance. Where a client or major operator standard specifically requires bow-tie or critical-control documentation for certain hazard categories, treat that requirement as a floor, not a ceiling — the method adds equal value on any scenario where barrier ownership is currently unclear, whether or not a standard mandates it.
Hazard vs top event
A hazard is the source of potential harm that exists whenever the material or activity is present — for example, flammable solvent stored under normal operating conditions. The top event is the specific point at which control over that hazard is lost — for example, loss of containment of the solvent from its tank. Keeping this distinction clear matters because barriers are drawn against the top event, not against the hazard in the abstract: you cannot put a barrier "on" a flammable solvent, but you can put a barrier on each threat that could cause it to escape containment.
Define hazard and top event
Write the top event as a loss of control, not as a consequence and not as a cause — "loss of containment of flammable liquid from the storage tank," not "tank fire" (a consequence) and not "tank overfilled" (a threat). A top event stated too broadly produces a diagram with too many unrelated threats and consequences to manage coherently; stated too narrowly, it misses credible related scenarios. Confirm the hazard and top event with the people who operate the asset day to day before the workshop, since a diagram built only from a procedure review often misses how the equipment actually behaves in practice.
Identify threats and consequences
Threats are the credible causes that could independently lead to the top event — each threat should be capable of causing the top event on its own, without needing another threat to also occur (a combination of two independent failures is a separate, lower-likelihood scenario, not a single threat line). Consequences are the credible outcomes if the top event is not controlled, ranging in severity, and each should be developed on its own branch since the barriers that mitigate a pool fire are different from the barriers that mitigate environmental contamination even though both stem from the same top event.
Select preventive barriers and mitigative barriers
Preventive barriers sit between a threat and the top event, stopping the threat from causing loss of control. Mitigative barriers sit between the top event and a consequence, reducing the severity or likelihood of that consequence once control has already been lost. A common error is treating emergency response as a preventive barrier — it is almost always mitigative, since it acts after the top event has occurred.
Barrier validity tests
A barrier only belongs on the diagram if it passes four tests: it must be capable of stopping or mitigating the specific threat or consequence line it sits on (specificity); it must not depend on another barrier on the same line to function (independence); it must have a defined performance standard that can be checked; and it must be something the organization can demonstrate is actually in place today, not a planned future control. A barrier that fails any of these tests should either be redefined more specifically or removed from the diagram — an aspirational barrier on paper gives false assurance.
Human, engineered and procedural barriers
Barriers fall into three broad types, and a resilient bow-tie usually mixes them rather than relying on one type across every line: engineered barriers (a relief valve, a bund wall, an interlock) that function without requiring a human decision at the moment of need; procedural barriers (a permit step, an isolation sequence) that depend on a person following a defined process correctly; and human-action barriers (an operator response to an alarm) that depend on a person recognizing a situation and acting correctly under time pressure. Engineered barriers are generally the most reliable because they do not depend on real-time human performance, but a bow-tie built entirely from procedural barriers is more fragile than one team members often assume, since procedural failure under pressure is a well-documented pattern in major incidents.
Add degradation factors and controls
Escalation-factor controls
An escalation factor is a condition that defeats or weakens a specific barrier — for example, a high-level alarm barrier can be defeated by an escalation factor such as alarm nuisance rates causing operators to habitually acknowledge without investigating. Every escalation factor identified should have its own escalation-factor control: a specific measure that manages that degradation mechanism, distinct from the barrier it protects. Escalation factors are where a bow-tie earns its keep over a simple barrier list, because they force the team to ask not just "does the barrier exist" but "what could quietly stop it from working."
Common escalation-factor categories worth checking systematically against every barrier on the diagram include maintenance backlog or deferred inspection, competency gaps in the people who operate or verify the barrier, organizational change (restructuring, contractor turnover) that disrupts ownership continuity, and production or schedule pressure that incentivizes bypassing a step. A barrier with no identified escalation factor has usually not been examined closely enough rather than genuinely having none — most real barriers have at least one plausible degradation mechanism once the team looks for it deliberately.
Assign critical-control owners and performance standards
Every barrier judged critical — meaning its failure alone could allow the top event or a major consequence — needs a named individual owner (a role, not a department), a written performance standard describing what "working" means for that specific barrier, and an assurance activity with a stated frequency that verifies the standard is being met. Without this level of specificity, a bow-tie remains a workshop artifact rather than a live management tool that operations, maintenance and audit can actually use.
Assign ownership to a role that has genuine operational authority over the barrier, not to whoever happened to be in the workshop. An instrumentation engineer can reasonably own a level-trip proof-test schedule; they cannot meaningfully own a bund's structural integrity, which sits with civil or mechanical maintenance. Where a barrier's ownership is unclear or contested during the workshop, that ambiguity is itself a finding worth recording — an unowned critical barrier is a gap the workshop has surfaced, not a detail to resolve informally afterward.
Validate and facilitate the workshop
Run the bow-tie workshop with a mixed team — process/technical authority, operations, maintenance and HSE — since threats, barriers and escalation factors are rarely visible to any single discipline alone. A trained facilitator keeps the group disciplined about barrier specificity and independence rather than accepting the first plausible-sounding answer, and should explicitly record workshop assumptions (design basis, operating envelope, current barrier inventory) since a bow-tie is only valid for the conditions it was built against. Validate the finished diagram against the underlying HAZOP or PHA and any relevant incident learnings before it is accepted as the site's control document, and set a review trigger — a process change, a new incident, or a fixed periodic review — rather than treating the diagram as permanent.
Linking HAZOP findings and incident learnings
Where a hazard and operability study (HAZOP) has already identified the deviation that leads to this top event, use its findings directly as a starting threat list rather than re-deriving them from scratch, and where a past incident or near miss involved this hazard, add its causal findings as a validated threat or a documented escalation factor rather than treating it as a hypothetical.
Worked industrial example
The example below is an anonymized, illustrative bow-tie for a bulk flammable-solvent storage tank at an Indian process plant tank farm. Barrier names and assurance frequencies are illustrative of the method, not a template to copy without your own site-specific verification.
| Element | Detail |
|---|---|
| Hazard | Bulk storage of flammable solvent (e.g., toluene) in an atmospheric tank within the plant tank farm |
| Top event | Loss of primary containment (LOPC) of flammable liquid from the storage tank |
| Threat | Preventive barriers |
|---|---|
| Overfilling during tanker offloading | Independent high-high level trip shutting the offload pump; operator dip-check verification before start; offload procedure requiring continuous attendance |
| External corrosion causing shell or floor failure | Protective coating and cathodic protection system; scheduled ultrasonic thickness testing under a risk-based inspection plan; corrosion allowance built into original design |
| Vehicle or mobile-equipment impact on tank or connected pipework | Physical crash barriers around the tank and pipe rack; defined vehicle exclusion zone with signage; site traffic management procedure for the tank farm area |
| Consequence | Mitigative barriers |
|---|---|
| Pool fire within the bunded area | Bund wall sized to contain full tank inventory; fixed fire detection and deluge/foam system; trained emergency response team with a rehearsed tank-farm fire response plan |
| Vapor cloud formation with potential explosion or flash fire | Fixed gas detection with control-room alarm; automatic/manual emergency shutdown isolating ignition sources in the area; defined exclusion zone and muster procedure |
| Contamination of surface water via site drainage | Bund drain valve normally closed by design/procedure; spill-response kit and interceptor at the drainage point; environmental monitoring of the discharge point |
| Barrier | Escalation factor | Escalation-factor control |
|---|---|---|
| High-high level trip | Nuisance alarm rate causes operators to habitually silence or delay response | Periodic alarm-rationalization review; trip tested independently of the alarm's perceived reliability |
| Ultrasonic thickness testing program | Inspection interval extended under production or turnaround-schedule pressure | Risk-based inspection schedule governed and signed off by a technical authority independent of production scheduling |
| Bund drain valve normally closed | Valve left open after routine bund-water drainage and not returned to closed position | Valve position checklist item on routine area inspection; locked-closed administrative control where practicable |
Note how each preventive barrier is specific and testable — "independent high-high level trip" rather than "level monitoring" — and how each escalation factor names the actual mechanism that could quietly defeat the barrier rather than a generic "human error" label. This is the level of detail a workshop should aim for on every line.
Critical-control verification
Once the diagram is complete, the barriers judged critical need a documented assurance plan, checked on a defined cycle and escalated if a check fails rather than simply logged.
| Critical control | Owner | Performance standard | Assurance activity | Assurance frequency |
|---|---|---|---|---|
| High-high level trip | Instrumentation/E&I lead | Trip activates and isolates pump within design response time | Functional proof test | Set per site inspection/testing plan |
| Bund integrity | Civil/mechanical maintenance lead | Bund holds full tank inventory with no visible cracking or degradation | Visual inspection and integrity check | Set per site inspection/testing plan |
| Gas detection and ESD | Process safety/instrumentation lead | Detector responds and ESD isolates ignition sources within design threshold | Functional test and calibration check | Set per site inspection/testing plan |
Confirm your own assurance frequencies against equipment manufacturer specifications, your site's risk-based inspection plan and any applicable regulatory or insurer requirement — the frequencies above are illustrative of the method, not a stated interval for you to adopt directly.
Bow-tie template and checklist
| Step | Checklist item | Status |
|---|---|---|
| Scope | Hazard and top event defined and confirmed with operations | |
| Threats | Each threat independently capable of causing the top event | |
| Consequences | Each consequence developed on its own branch with distinct barriers | |
| Barriers | Every barrier passes the specificity, independence, standard and existence tests | |
| Escalation factors | Degradation mechanisms identified with a distinct escalation-factor control | |
| Ownership | Critical controls have a named owner and performance standard | |
| Validation | Diagram cross-checked against HAZOP/PHA and relevant incident learnings | |
| Review trigger | Periodic and change-triggered review dates set |
Use the worksheet below to generate a starting barrier register from your own workshop notes. It is a screening aid to organize a workshop's output — it does not replace facilitation by a competent process-safety practitioner or the validation step described above.
Screening aid only. Add an owner, performance standard, escalation factor and assurance frequency to each line before treating it as a live critical-control register.
Frequently asked questions
What is the difference between bow-tie and HAZOP?
HAZOP systematically identifies deviations from design intent and their causes across a process, typically at a node-by-node level of detail, while bow-tie takes a single already-identified top event and maps its full range of threats, consequences and barriers on one diagram. Many teams use HAZOP findings as an input to the threat list on a subsequent bow-tie for the highest-consequence scenarios identified.
What is a top event?
A top event is the specific point at which control over a hazard is lost — for example, loss of containment — sitting at the center of the bow-tie between the threats that could cause it and the consequences that could follow if it is not controlled.
Can a procedure be a barrier?
Yes, provided it meets the same barrier-validity tests as any other control: it must be specific to the threat or consequence line, independent of other barriers on that line, have a defined performance standard, and be demonstrably in place today. A procedural barrier is generally considered less inherently reliable than an engineered barrier because it depends on correct human performance, so it deserves closer assurance attention.
How are critical controls verified?
Through a documented assurance plan for each critical control that states a performance standard, a specific verification activity (functional test, inspection, calibration check) and a defined frequency, with failed checks escalated and tracked to closure rather than simply logged as a completed inspection.
Which software is needed?
Bow-tie diagrams can be built in general diagramming tools for a single workshop, but organizations managing many critical controls across multiple assets generally need a risk-register platform that links each barrier to its owner, performance standard and assurance schedule so verification status is visible without manually cross-referencing spreadsheets.
Himaya Prevention facilitates bow-tie workshops and critical-control assurance programs for process and major-hazard sites in India and the GCC. Request a facilitated bow-tie study if your team needs an independent facilitator to build or validate a bow-tie for a specific top event.
Download the bow-tie worksheet above to capture your workshop's threats, barriers and consequences in a structured format, and see our related comparison of fault tree analysis (FTA) vs event tree analysis (ETA) and our guide on preliminary process hazard analysis (PHA) for how bow-tie fits alongside these related methods, or connect the resulting barrier register to a live risk register through HSEFQ.com.
0 Comments