Bowtie analysis is a visual risk assessment technique, named in ISO 31010, that maps a single hazard from its causes on the left, through a central loss-of-control moment called the top event, to its consequences on the right, with preventive and mitigative barriers drawn between them.
The diagram earns its name from its shape. Threats fan out on the left, consequences fan out on the right, and the knot in the middle is the top event. What makes the method powerful is that it puts the barriers, the controls that actually keep the risk in check, front and centre rather than burying them in a spreadsheet. For teams who have only ever scored risk on a matrix, a bowtie is often the first time everyone literally sees how a scenario unfolds and what stops it.
What Is Bowtie Analysis?
Bowtie analysis combines two older techniques into one two-dimensional picture. The left side behaves like a simplified fault tree, tracing the causes that could lead to a loss of control. The right side behaves like an event tree, tracing how that loss of control could escalate into harm. By merging cause analysis and consequence analysis, the bowtie implements the cause, event and consequence definition of risk that sits at the heart of ISO 31000.
Because it is qualitative and highly visual, a bowtie is well suited to workshops with mixed audiences: engineers, managers, auditors and frontline staff can all read the same diagram. It is used across safety, operational, environmental and increasingly cyber risk, wherever it helps to show not just how big a risk is but exactly what is keeping it under control.
The Anatomy of a Bowtie Diagram
Every bowtie is built from the same set of components. Understanding each one is the fastest way to read, or challenge, any diagram you are shown.
- Hazard: the source of potential harm, the thing you accept in order to operate, such as data at rest or a pressurised vessel.
- Top event: the exact moment control over the hazard is lost, for example unauthorised access granted or containment breached.
- Threats: the causes on the left that could each independently trigger the top event.
- Consequences: the outcomes on the right that could follow once the top event occurs.
- Preventive barriers: controls between each threat and the top event that stop the loss of control from happening.
- Mitigative barriers: controls between the top event and each consequence that reduce or contain the damage.
- Escalation factors: conditions that weaken a barrier, together with the escalation-factor controls that keep those barriers effective.
A widely cited review of the method in Reliability Engineering and System Safety (ScienceDirect, 2016) confirms the bowtie was designed specifically to make barriers, and the factors that degrade them, visible to non-specialists, which is why it has spread from process safety into aviation, healthcare and cyber risk.
How to Build a Bowtie Step by Step
Building a bowtie follows a disciplined left-to-right sequence. Rushing the top event is the most common mistake, so define it precisely before you add anything else.
- Identify the hazard, the activity or asset that carries the risk.
- Define the top event, the single point where control over that hazard is lost.
- List the threats on the left that could each cause the top event.
- List the consequences on the right that could result once it occurs.
- Place preventive barriers on each threat line between the threat and the top event.
- Place mitigative barriers on each consequence line between the top event and the outcome.
- Add escalation factors and their controls to show where barriers could fail.
Take a phishing example. The hazard is employees handling privileged credentials. The top event is a valid credential compromised. Threats include a convincing phishing email and a reused password. Preventive barriers are security awareness training, email filtering and multi-factor authentication. If the top event still occurs, consequences range from data exfiltration to ransomware, and mitigative barriers such as least-privilege access, network segmentation and rapid detection reduce the damage.
Where Bowtie Beats a Risk Matrix
A risk matrix gives you a single likelihood-times-impact score, and that is genuinely useful for prioritising. But it hides the mechanism. It cannot tell you which control is doing the heavy lifting, whether two barriers share a common failure mode, or where a single point of failure lurks. A bowtie answers all three because every barrier is drawn explicitly and can be tested for effectiveness. For a deeper look at scoring, see our guide to the risk assessment matrix.
The two techniques are complementary rather than competing. Many teams score a risk on a matrix to decide whether it warrants attention, then build a bowtie for the high-priority risks to design and stress-test the controls. This pairing is exactly how ISO 31010 intends its catalogue of techniques to be used: pick the tool that fits the decision. Our overview of ISO 31010 risk assessment techniques explains how bowtie sits alongside HAZOP, FMEA and fault tree analysis.
Using Bowtie Across Safety, Operational and Cyber Risk
The method is domain-agnostic. In process safety it models loss of containment. In operations it models service outages or supply-chain disruption. In cyber risk it models credential compromise, data breach or a control-system intrusion. In each case the value is the same: a shared, auditable picture that shows management which barriers must hold and where investment should go. Because barriers map cleanly onto real controls, the bowtie also feeds naturally into a risk treatment plan and into control assurance, giving auditors a direct line of sight from scenario to safeguard.
A frequent question is how detailed a bowtie should be. The honest answer is: detailed enough to support the decision at hand and no more. A workshop bowtie for a board briefing may show only the primary threats and the critical barriers, while an engineering bowtie for a safety case may enumerate every barrier, every escalation factor and the assurance activity that verifies each one. The same diagram type scales from a one-hour discussion to a formal, maintained artefact reviewed after every incident.
Common Mistakes to Avoid
Three errors recur in practice. The first is a vague top event that is really a consequence in disguise, which collapses the right side of the diagram. The second is listing controls that exist on paper but are never tested, so the bowtie looks robust while the real barriers are decorative. The third is treating the diagram as a one-off deliverable rather than a living record that is revisited when a barrier fails or a near-miss occurs. Avoiding these keeps a bowtie honest, and an honest bowtie is worth far more than a tidy one.