Bow-tie analysis

Bow-tie analysis is a risk analysis and graphical representation technique that places a critical or main event (the loss of control of a hazard, such as a gas leak, a falling load, or contact with a running machine) at the center. To the left, it displays the threats or causes that can trigger the event and the preventive barriers that control them, while to the right, it shows the potential consequences and the mitigation or recovery barriers that limit their severity. The resulting diagram, shaped like a bow tie, combines the logic of fault tree analysis (cause side) with that of event tree analysis (consequence side). This allows for a quick overview of which barriers protect against each accident pathway, who is responsible for them, and what degradation factors can cause them to fail. The IEC 31010:2019 standard includes bow-tie analysis among risk assessment techniques as a simple tool for describing and analyzing risk pathways from causes to consequences, with a focus on barriers. Born in the process industry and in the analysis of serious accidents, the technique is applied today in the prevention of occupational risks for risks with serious consequences, in the investigation of accidents and in the communication of risks to managers and workers.

In short

A risk analysis and graphical representation technique that places the critical event (loss of hazard control) at the center, threats and preventive barriers on the left, and consequences and mitigation barriers on the right, along with the degradation factors for each barrier and their responsible parties. It combines fault tree and event tree analysis, is defined in IEC 31010:2019, and is primarily applied to risks with serious consequences, barrier management, incident investigation, and risk communication. It does not quantify risk on its own nor does it replace a comprehensive risk assessment.

Content
  1. Elements of the bow-tie diagram
  2. When to apply the bow tie and what it offers
  3. Relationship with risk assessment and the management system
  4. Organizational application: how to make a bow tie
  5. Limits and common mistakes
  6. Practical example
  7. Regulatory and reference framework
  8. Related concepts
  9. References

A–Z dictionary →

Elements of the bow-tie diagram

  • Hazard. A source with the potential for harm that needs to be controlled (a stored flammable substance, a suspended load, electrical energy).
  • Main or critical event. The moment when control of the hazard is lost (leak, load drop, electrical contact). It is the nexus of the diagram and must be precisely defined.
  • Threats or causes. Circumstances that can cause the main event (corrosion, error in operation, failure of a component, overload).
  • Preventive barriers. Measures that prevent a threat from leading to the main event (inspection, interlocking, procedure, training, maintenance).
  • Consequences. Undesired results of the main event (fire, injury, poisoning, environmental damage).
  • Mitigation or recovery barriers. Measures that reduce the probability or severity of the consequences once the event has occurred (detection and alarm, extinguishing, emergency plan , protective equipment, first aid).
  • Degradation factors and climbing controls. Conditions that weaken a barrier (lack of maintenance, fatigue, time pressure) and measures that counteract them.
  • Responsible parties and status. Each barrier has an owner, a type (technical, human, organizational) and a status of effectiveness that can be evaluated and monitored.

When to apply the bow tie and what it offers

Bow-tie is particularly useful for low-frequency risks with serious consequences, where probability and severity matrix assessments do not explain how the risk is controlled: serious accidents involving hazardous substances , work at height, confined spaces , hazardous energy, machine entrapment, vehicle collisions, or risks in facilities with multiple safety systems. In establishments subject to regulations on major accidents (Royal Decree 840/2015, which transposes Directive 2012/18/EU), the technique is commonly used to document the barriers in accident scenarios and support the safety management system.

Compared to other techniques, it provides a clear view of barriers and their adequacy (number, type, independence), the ability to identify critical barriers and unprotected accident pathways, a language understandable to managers and workers, support for incident investigations (which barriers failed or were missing), and a basis for defining barrier indicators and inspection and maintenance programs. Its limitations are that it does not quantify risk on its own, depends on the quality of the prior cause-and-effect analysis, and can oversimplify complex interactions between events.

Relationship with risk assessment and the management system

  • Risk assessment. The bow-tie develops and documents the critical risks identified in the assessment required by Law 31/1995 and Royal Decree 39/1997, without replacing the general assessment of all positions.
  • Fault tree and event tree. INSST Technical Prevention Notes 333 and 328 describe the two techniques that the bow-tie combines into a single diagram.
  • Hierarchy of controls. Barriers are classified according to the hierarchy of Law 31/1995 and ISO 45001 (elimination, substitution, engineering controls, administrative controls and personal protective equipment), which allows their robustness to be assessed.
  • Barrier management. Each barrier is linked to a responsible party, inspection and maintenance tasks, and status indicators, which connects the diagram to preventive planning and the OSH management system.
  • Incident investigation. The diagram is used to analyze which barriers failed, were degraded, or did not exist, and to define corrective measures.
  • Communication and training. Graphic representation makes it easier to explain to staff why each measure exists and what happens if it is omitted.

Organizational application: how to make a bow tie

  1. Select critical risks based on risk assessment, incident history and applicable regulations, and form a team with managers, prevention technicians, maintenance and workers skilled in the task.
  2. Precisely define the hazard and the main event, avoiding confusing it with a cause or a consequence.
  3. Identify the threats or credible causes of the main event and, for each one, the existing preventive barriers, classified by type and level of the hierarchy of controls.
  4. Identify the relevant consequences and the mitigation and recovery barriers that limit them.
  5. Analyze the degradation factors of each barrier and the controls that counteract them, and assign a responsible party to each barrier.
  6. Evaluate the adequacy of the barriers (number, independence, reliability, coverage of each accident route) and define measures for routes without protection or with weak barriers.
  7. Integrate the diagram into the management system: planning of measures, inspection and maintenance tasks, barrier indicators, training and periodic review or after an incident.

Preventive management software allows you to link bow-tie barriers with risk assessment, planned measures, inspections and maintenance, record their status and those responsible, and use the diagram in incident investigation, maintaining traceability of changes.

Limits and common mistakes

  1. Defining the main event incorrectly disrupts the entire diagram and confuses causes with consequences.
  2. Including as barriers elements that are not barriers (intentions, objectives, generic training) or barriers that depend on each other and are not independent.
  3. Prepare the diagram without the participation of those who know the task and the actual state of the measurements.
  4. Leaving the bow-tie as a static document, without responsible parties, indicators, or review after changes or incidents.
  5. Use it as a substitute for the general risk assessment or quantitative analysis required by major accident regulations.
  6. Overloading the diagram with detail until it becomes unreadable for its communication function.

The technique must be adapted to the complexity of the risk and the organization; this sheet is for informational purposes only.

Practical example

Situation: A water treatment plant with chlorine gas storage wants to review how it controls the risk of leakage after an incident without consequences.

  • Definition. The team defines the hazard (stored chlorine gas) and the main event (release of chlorine into the atmosphere) and identifies the following threats: corrosion of connections, error in changing containers, and impact of vehicles.
  • Barriers. For each threat, preventive barriers are documented (periodic inspection, change procedure and training, impact protections) and for the consequences (poisoning of workers and third parties) mitigation barriers are documented (detection and alarm, neutralization system, emergency plan, breathing equipment).
  • Findings. The analysis shows that the detection barrier has an uncontrolled degradation factor (expired calibration) and that the threat of vehicle impact only has an administrative barrier.
  • Result. Calibration with a status indicator, physical protection against vehicles, and bow-tie inspection after each incident are planned, and the diagram is used in the training of operating personnel.

Regulatory and reference framework

Directive 2012/18/EU (Seveso III), transposed by Royal Decree 840/2015, requires the establishments concerned to have a safety management system in which barrier analysis plays a central role.

Related concepts

References

  1. International Organization for Standardization. IEC 31010:2019. Risk management. Risk assessment techniques. 2019. Official source
  2. Official State Gazette. Law 31/1995, of November 8, on Occupational Risk Prevention. 1995, current consolidated text. Official source
  3. Official State Gazette. Royal Decree 39/1997, of January 17, approving the Regulation of Prevention Services. 1997, current consolidated text. Official source
  4. Official State Gazette. Royal Decree 840/2015, of September 21, approving measures for the control of risks inherent in major accidents involving hazardous substances. 2015, current consolidated text. Official source
  5. National Institute for Occupational Safety and Health. NTP 333: Probabilistic risk analysis: fault tree methodology. 1995. Official source
  6. National Institute for Occupational Safety and Health. NTP 328: Risk analysis using the event tree method. 1994. Official source
  7. European Union. Directive 2012/18/EU of the European Parliament and of the Council of 4 July 2012 on the control of major-accident hazards involving dangerous substances. 2012. Official source

Editorial information

Publication date: August 30, 2026 .

Editorial Manager: Sabentis Editorial Team .

Editorial review by Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra