Risk Management

Bowtie Analysis: A Practical Risk Assessment Guide

Standarity Editorial Team·ISO 31000 and ISO 31010 risk assessment specialists
··6 min read

Bowtie analysis is a visual risk assessment technique, named in ISO 31010, that maps a single hazard from its causes on the left, through a central loss-of-control moment called the top event, to its consequences on the right, with preventive and mitigative barriers drawn between them.

The diagram earns its name from its shape. Threats fan out on the left, consequences fan out on the right, and the knot in the middle is the top event. What makes the method powerful is that it puts the barriers, the controls that actually keep the risk in check, front and centre rather than burying them in a spreadsheet. For teams who have only ever scored risk on a matrix, a bowtie is often the first time everyone literally sees how a scenario unfolds and what stops it.

What Is Bowtie Analysis?

Bowtie analysis combines two older techniques into one two-dimensional picture. The left side behaves like a simplified fault tree, tracing the causes that could lead to a loss of control. The right side behaves like an event tree, tracing how that loss of control could escalate into harm. By merging cause analysis and consequence analysis, the bowtie implements the cause, event and consequence definition of risk that sits at the heart of ISO 31000.

Because it is qualitative and highly visual, a bowtie is well suited to workshops with mixed audiences: engineers, managers, auditors and frontline staff can all read the same diagram. It is used across safety, operational, environmental and increasingly cyber risk, wherever it helps to show not just how big a risk is but exactly what is keeping it under control.

The Anatomy of a Bowtie Diagram

Every bowtie is built from the same set of components. Understanding each one is the fastest way to read, or challenge, any diagram you are shown.

  • Hazard: the source of potential harm, the thing you accept in order to operate, such as data at rest or a pressurised vessel.
  • Top event: the exact moment control over the hazard is lost, for example unauthorised access granted or containment breached.
  • Threats: the causes on the left that could each independently trigger the top event.
  • Consequences: the outcomes on the right that could follow once the top event occurs.
  • Preventive barriers: controls between each threat and the top event that stop the loss of control from happening.
  • Mitigative barriers: controls between the top event and each consequence that reduce or contain the damage.
  • Escalation factors: conditions that weaken a barrier, together with the escalation-factor controls that keep those barriers effective.

A widely cited review of the method in Reliability Engineering and System Safety (ScienceDirect, 2016) confirms the bowtie was designed specifically to make barriers, and the factors that degrade them, visible to non-specialists, which is why it has spread from process safety into aviation, healthcare and cyber risk.

How to Build a Bowtie Step by Step

Building a bowtie follows a disciplined left-to-right sequence. Rushing the top event is the most common mistake, so define it precisely before you add anything else.

  • Identify the hazard, the activity or asset that carries the risk.
  • Define the top event, the single point where control over that hazard is lost.
  • List the threats on the left that could each cause the top event.
  • List the consequences on the right that could result once it occurs.
  • Place preventive barriers on each threat line between the threat and the top event.
  • Place mitigative barriers on each consequence line between the top event and the outcome.
  • Add escalation factors and their controls to show where barriers could fail.

Take a phishing example. The hazard is employees handling privileged credentials. The top event is a valid credential compromised. Threats include a convincing phishing email and a reused password. Preventive barriers are security awareness training, email filtering and multi-factor authentication. If the top event still occurs, consequences range from data exfiltration to ransomware, and mitigative barriers such as least-privilege access, network segmentation and rapid detection reduce the damage.

Where Bowtie Beats a Risk Matrix

A risk matrix gives you a single likelihood-times-impact score, and that is genuinely useful for prioritising. But it hides the mechanism. It cannot tell you which control is doing the heavy lifting, whether two barriers share a common failure mode, or where a single point of failure lurks. A bowtie answers all three because every barrier is drawn explicitly and can be tested for effectiveness. For a deeper look at scoring, see our guide to the risk assessment matrix.

The two techniques are complementary rather than competing. Many teams score a risk on a matrix to decide whether it warrants attention, then build a bowtie for the high-priority risks to design and stress-test the controls. This pairing is exactly how ISO 31010 intends its catalogue of techniques to be used: pick the tool that fits the decision. Our overview of ISO 31010 risk assessment techniques explains how bowtie sits alongside HAZOP, FMEA and fault tree analysis.

Using Bowtie Across Safety, Operational and Cyber Risk

The method is domain-agnostic. In process safety it models loss of containment. In operations it models service outages or supply-chain disruption. In cyber risk it models credential compromise, data breach or a control-system intrusion. In each case the value is the same: a shared, auditable picture that shows management which barriers must hold and where investment should go. Because barriers map cleanly onto real controls, the bowtie also feeds naturally into a risk treatment plan and into control assurance, giving auditors a direct line of sight from scenario to safeguard.

A frequent question is how detailed a bowtie should be. The honest answer is: detailed enough to support the decision at hand and no more. A workshop bowtie for a board briefing may show only the primary threats and the critical barriers, while an engineering bowtie for a safety case may enumerate every barrier, every escalation factor and the assurance activity that verifies each one. The same diagram type scales from a one-hour discussion to a formal, maintained artefact reviewed after every incident.

Common Mistakes to Avoid

Three errors recur in practice. The first is a vague top event that is really a consequence in disguise, which collapses the right side of the diagram. The second is listing controls that exist on paper but are never tested, so the bowtie looks robust while the real barriers are decorative. The third is treating the diagram as a one-off deliverable rather than a living record that is revisited when a barrier fails or a near-miss occurs. Avoiding these keeps a bowtie honest, and an honest bowtie is worth far more than a tidy one.

Frequently Asked Questions

What is the difference between bowtie analysis and fault tree analysis?

Fault tree analysis works only on the cause side, deducing the combinations of events that lead to an undesired outcome. Bowtie analysis embeds a simplified fault tree on its left and adds an event-tree consequence side on the right, then overlays the preventive and mitigative barriers. In short, a fault tree analyses failure logic, while a bowtie shows causes, consequences and controls together in one diagram.

Is bowtie analysis qualitative or quantitative?

Bowtie analysis is primarily a qualitative and visual technique. It is designed to communicate how barriers control a scenario rather than to produce a precise number. Some organisations add semi-quantitative barrier ratings, but its core strength is clarity and communication, which is why ISO 31010 lists it among the techniques for understanding controls.

What is a top event in a bowtie diagram?

The top event is the central knot of the bowtie: the precise moment at which control over the hazard is lost. Everything to its left explains how you could reach that moment, and everything to its right explains what could happen afterwards. Defining the top event clearly is the single most important step, because a vague top event produces a vague diagram.

When should you use a bowtie instead of a risk matrix?

Use a risk matrix to prioritise many risks quickly by likelihood and impact. Use a bowtie when a specific high-priority risk needs its controls designed, tested or communicated, because the bowtie makes each barrier and its potential failure visible. Most mature programmes use both, matrix first to triage, bowtie second to engineer the controls.

Can bowtie analysis be used for cyber security risk?

Yes. Bowtie analysis maps well to cyber scenarios such as credential compromise or data breach, where preventive barriers include multi-factor authentication and awareness training, and mitigative barriers include least-privilege access and rapid detection. It gives security and business stakeholders a common picture of which safeguards must hold.

Explore Courses on Udemy

Intermediate

ISO 31000: Risk Management Implementation Step by Step

Intermediate

ISO 31010:2019 - 30+ Risk Assessment Techniques Explained

Intermediate

CRISC Certification — IT Risk Management with AI Tools