Process / pipelineDisaster StudiesProcess safety / barrier managementPipeline

Bow-Tie Risk Analysis

Also known as: Bowtie Method, Bow-Tie Diagram, Barrier Analysis (Bow-Tie), Cause-Consequence Barrier Model

OriginatorSynthesized review by de Ruijter & Guldenmund; standardized in ISO/IEC 31010Year2016Sources2Related methods5

Bow-tie risk analysis is a barrier-centred technique that places a single top event — the moment control over a hazard is lost — at the knot of a diagram, branches its possible causes to the left and its possible consequences to the right, and arrays along each pathway the barriers meant to prevent or mitigate it. The shape gives the method its name: the fanning threats and consequences form the two halves of a bow tie around the central event. de Ruijter and Guldenmund's 2016 review in Safety Science documents how the approach grew popular precisely because it combines, in one readable picture, the cause logic of a fault tree and the consequence logic of an event tree while foregrounding the controls that managers actually own. ISO/IEC 31010 lists bow-tie analysis among standard risk-assessment techniques, used both qualitatively to communicate risk and barrier coverage and quantitatively to estimate consequence likelihoods.

Key highlights

  • Shows causes, consequences and the barriers between them in a single, highly readable diagram understood by engineers and managers alike.
  • Foregrounds barrier adequacy and defense-in-depth, making it a natural backbone for barrier and safety-critical-element management.
  • Combines the multiple-cause logic of fault trees with the multiple-outcome logic of event trees without requiring two separate analyses.
  • Captures why barriers fail in practice through escalation factors and their controls, beyond a static list of defenses.

Intuition

This section is available to Pro members. Upgrade to Pro

How it works

This section is available to Pro members. Upgrade to Pro

When to use it

Use bow-tie analysis when you need to understand and communicate, in one picture, both how a major hazard can be realized and how its consequences are controlled, with the emphasis on the adequacy of barriers. It is especially valuable in process-safety and high-hazard industries for major-accident hazards, for demonstrating defense-in-depth to regulators, and for engaging operational staff who own the barriers. The method works well as a bridge between detailed fault-tree and event-tree studies and front-line barrier management, and it can be quantified when barrier-failure data exist. It is less suited to hazards with no clear single loss-of-control event, to problems requiring fine probabilistic detail beyond what barrier data support, or to situations where the cause logic is too complex to summarize on one diagram, in which case a full fault tree should be used directly.

Strengths & limitations

Strengths
  • Shows causes, consequences and the barriers between them in a single, highly readable diagram understood by engineers and managers alike.
  • Foregrounds barrier adequacy and defense-in-depth, making it a natural backbone for barrier and safety-critical-element management.
  • Combines the multiple-cause logic of fault trees with the multiple-outcome logic of event trees without requiring two separate analyses.
  • Captures why barriers fail in practice through escalation factors and their controls, beyond a static list of defenses.
Limitations
  • Simplifies cause logic, so it cannot represent the detailed combinations of failures that a full fault tree can, as the review notes.
  • Quantification depends on barrier-failure and threat-frequency data that are often unavailable or uncertain.
  • Assumes barriers on a pathway act largely independently, which can overstate protection when common-cause failures link them.
  • Lacks a single standardized method, so qualitative and quantitative bow-ties vary widely in rigor and meaning across organizations.

Common pitfalls

This section is available to Pro members. Upgrade to Pro

Applications

This section is available to Pro members. Upgrade to Pro

Frequently asked

How does a bow-tie relate to fault trees and event trees?

A bow-tie can be seen as a fault tree and an event tree joined at a common central event. The left side, fanning threats into the top event, plays the role of the fault tree's cause logic, and the right side, fanning the top event into consequences, plays the role of the event tree's outcome logic. As de Ruijter and Guldenmund describe, quantitative bow-ties literally use a fault tree and event tree together with barriers to calculate risk. The bow-tie trades some of the detailed combinatorial logic of a full fault tree for a single readable picture centred on barriers.

What are escalation factors and why do they matter?

An escalation factor is a condition that defeats or degrades a barrier, such as poor maintenance disabling a relief valve or alarm fatigue undermining an operator response. The review highlights them as a key elaboration of the method because a barrier credited on the diagram may not function if an escalation factor is present. Modeling escalation factors, and the secondary controls that manage them, turns the bow-tie from a static inventory of defenses into a realistic picture of how those defenses can be lost, which is exactly what barrier management needs to know.

Can a bow-tie give quantitative risk numbers?

Yes, but with care. A quantitative bow-tie treats threat frequencies and barrier failure probabilities like a combined fault-tree and event-tree calculation to estimate the likelihood of each consequence. This requires credible data on how often threats occur and how often each barrier fails, which are frequently scarce or uncertain, and it assumes barriers act independently. The review notes that many bow-ties remain qualitative for exactly this reason. When data are weak, the bow-tie is best used to compare relative barrier coverage rather than to assert precise consequence probabilities.

Sources

  1. 1.
    de Ruijter, A., & Guldenmund, F. (2016). The bowtie method: A review. Safety Science, 88, 211-218.
  2. 2.
    International Organization for Standardization. (2019). IEC 31010:2019 Risk management — Risk assessment techniques. ISO/IEC, Geneva.

You have read it. What now?

Cite this page

ScholarGate. (2026, June 23). Bow-Tie Risk Analysis. ScholarGate. https://scholargate.app/disaster-studies/bow-tie-analysis