Ask what decision last month's risk register changed. If the answer takes more than a moment, the register is an archive.
Most organisations of any maturity maintain a risk register. It is reviewed monthly, scored by likelihood and consequence, colour-coded, and reported upward. It is also, in a great many cases, functionally inert: a record of concerns that accompanies decisions without influencing them.
The inertness is not caused by poor administration. It is caused by structure. A register is a list of risks with owners and ratings. A list cannot show how a risk would actually occur, which controls stand between the organisation and the event, whether those controls are independent of one another, or which of them is currently degraded. Without that, there is nothing specific to act on — only a number that went from twelve to nine because someone felt better about it.
The Strategic Context
Risk management earns its cost in exactly one way: by changing what the organisation does. Not by documenting exposure, not by demonstrating diligence to an auditor, and not by producing a heat map. If the process runs for a year and no investment, sequence, design, contract or staffing decision was different as a result, the process consumed resources and produced paper.
The gap between documenting risk and managing it is largely a gap in representation. How a risk is written down determines what can be reasoned about it.
A register entry says: Crane failure during heavy lift — likelihood 3, consequence 5, rating 15, owner: Site Manager, treatment: ensure compliance with lifting procedures.
Nothing in that entry tells a decision-maker how a crane failure happens, what currently prevents it, what would limit the damage if prevention failed, or which of those defences is weakest today. "Ensure compliance with lifting procedures" is not a control; it is a hope expressed as an action.
What Leaders Commonly Misread
That a risk rating is information. A rating is a compression of two estimates, each uncertain, into one number that is then treated as comparable across dissimilar risks. It is useful for sorting a long list and almost useless for deciding anything. Two risks rated fifteen may require completely different responses and completely different amounts of money.
That risk review is a reporting obligation. When risk sits in the assurance function rather than the decision function, it optimises for completeness and defensibility. Completeness is not the objective — consequence is. A register with three hundred entries has usually lost the four that matter.
That controls exist because they are documented. A control that is written in a procedure, not verified in practice, degraded by workload, or dependent on the same person or system as three other controls, is providing far less protection than the register implies. Control existence and control effectiveness are different claims, and registers rarely distinguish them.
That risk is a delivery concern. Most of the largest risks an organisation carries are created at investment selection — through concentration, dependency and over-commitment — and are simply inherited by delivery. [Related article: Why Portfolio Balance Fails Before Delivery Does]
Reframing the Issue
The bow-tie is not a new risk method so much as a different representation, and the difference in representation is what changes behaviour.
At the centre sits a single event — the moment control is lost. Not a cause, not a consequence: the event itself. Crane fails during a heavy lift. Uncontrolled release of process fluid. Loss of the production scheduling system during a shift.
To the left are the causes, and between each cause and the event sit preventive controls — the barriers that stop the event occurring.
To the right are the consequences, and between the event and each consequence sit mitigating controls — the barriers that limit harm once the event has occurred.
The structure forces four things a register does not.
It separates prevention from mitigation. Organisations routinely discover, on drawing one, that they have invested almost entirely in prevention and have almost nothing on the right-hand side. This is comfortable until prevention fails, which is the only circumstance in which the right-hand side matters.
It makes each control specific and attributable. A barrier must be a thing that someone does, maintains or inspects. "Compliance with procedures" does not survive the drawing; "pre-lift inspection signed by a competent person, recorded, audited quarterly" does.
It exposes shared dependencies. When three barriers all depend on the same inspection regime, the same sensor, the same supervisor or the same software, the defence-in-depth is illusory. This is the practical content of James Reason's Swiss cheese model: layered defences protect only when the holes are in different places. Independence is the property that makes layers work, and it is invisible in a list.
It shows degradation. A barrier can be marked as effective, degraded or absent. A bow-tie with two degraded preventive barriers is a specific, actionable statement. A rating that moved from fifteen to twelve is not.
Where the Method Earns Its Cost
Bow-ties are not free. Drawing one properly takes a facilitated session with people who know the work, and maintaining one takes discipline. Applying the method to every entry in a three-hundred-item register would be a poor use of effort and would produce the same inertness in a more elaborate format.
The method pays where three conditions hold: the consequence is severe, the event is credible, and the organisation currently believes it is protected. That last condition is the important one. Bow-ties are most valuable precisely where confidence is high, because that is where undetected shared dependencies accumulate.
A practical rule: bow-tie the small number of events that could stop the business, injure people, or destroy the value of a major asset or program. Leave the rest in the register, where a list is adequate.
Decision Framework
Five questions convert a bow-tie from a diagram into a decision.
1. Which barriers are currently degraded, and what would it cost to restore them? This is the primary output and should be expressed as a funded or unfunded decision, not as an observation.
2. Do any two barriers share a dependency? Same person, same system, same supplier, same assumption, same inspection. Where they do, the count of barriers overstates the protection.
3. Is the right-hand side real? If the event occurred this week, what would actually limit the consequence — and has it been tested, or only written?
4. Who verifies each barrier, and when did they last do so? A barrier with no verification owner is a claim.
5. What would have to change for us to accept this risk knowingly? Not every risk requires treatment. Conscious acceptance, recorded with reasoning, is a legitimate and under-used answer. [Related article: Designing Controls That Fail Safely]
From Strategy to Execution
Immediately. Select the three events that would most damage the organisation. Draw a bow-tie for each with the people who do the work — not with the risk function alone. The first session usually finds at least one barrier everyone assumed existed and nobody owns.
Over one to two quarters. Establish barrier ownership and verification frequency for the events analysed, and report barrier status rather than risk ratings to the executive. This is a small change in reporting format with a disproportionate effect on the quality of the conversation, because barrier status is specific and ratings are not.
Over one to three years. Push the analysis upstream into design and investment selection, where barriers are cheapest to build and shared dependencies are easiest to avoid. A barrier designed in costs a fraction of one retrofitted, and independence is a design property that is nearly impossible to add later. [Related article: The Cost You Commit Before You Spend]
Signals to Monitor
- Risk ratings drifting downward without any control change. Familiarity is being recorded as improvement.
- Treatments phrased as "ensure", "monitor" or "raise awareness". None of these are barriers; all of them are intentions.
- The same individual owning many critical barriers. An independence failure wearing a name badge.
- Near misses not triggering barrier review. A near miss is a free test of the left-hand side, and most organisations file it rather than learning from it.
- Mitigating controls that have never been exercised. Untested mitigation is an assumption, particularly where it depends on people acting under stress.
- Risk reports that have never accompanied a funding decision. The clearest evidence that risk is documented rather than managed.
Questions for the Leadership Team
- Which decisions in the last twelve months were changed by our risk process? Name one.
- For our three most severe credible events, which barriers are currently degraded, and is restoring them funded?
- Where do multiple barriers share a single dependency, and do we know?
- What would actually happen in the first hour after our worst credible event, and when did we last test that?
- Which risks have we knowingly accepted, and is that acceptance recorded with the reasoning and the accepting authority?
- Does our executive risk report show barrier status, or only ratings?
Closing Perspective
The difference between risk documentation and risk management is not effort, maturity or sophistication. It is whether the representation supports a decision.
A list of concerns with scores can be maintained indefinitely without anyone ever having to choose between spending money and accepting exposure — which is precisely why it survives, and precisely why it changes so little. A control-centred view removes that comfort. It names what stands between the organisation and the event, says which of those things is currently weak, and puts a price on fixing it.
That is an uncomfortable conversation to hold and a straightforward one to act on, which is the right way round. Risk work should end in a decision about money, sequence or design. If it ends in a colour, it has not finished.