Why Bow-Tie Analysis Is the Most Powerful Visual Risk Tool
Most risk analysis methods either focus on what causes a risk (like fault trees and fishbone diagrams) or what happens when a risk materialises (like event trees and consequence analysis). Bow-tie analysis does both — simultaneously — in a single, intuitive visual structure.
For heavy engineering, manufacturing, and defence projects, bow-tie analysis is particularly powerful because these environments involve complex causal chains, multiple control layers (defence-in-depth), and consequences that can cascade across safety, schedule, cost, and regulatory dimensions simultaneously. The visual format makes it immediately accessible to stakeholders who may not engage with spreadsheet-based risk registers.
The bow-tie method is widely used in the oil and gas, aviation, and nuclear industries — sectors where the consequences of risk failure are catastrophic and the control architecture must be demonstrably robust.
What Is a Bow-Tie Analysis?
The bow-tie diagram takes its name from its shape: two triangles meeting at a central point, resembling a bow-tie. The structure has five components:
| Component | Definition | Position |
|---|---|---|
| Causes | Events or conditions that could trigger the risk | Left side |
| Proactive Controls & Treatments | Barriers that prevent the risk event from occurring | Between causes and risk |
| Risk Event | The specific undesired event being analysed | Centre |
| Reactive Controls & Treatments | Barriers that limit damage after the event occurs | Between risk and consequences |
| Consequences | Outcomes that result if the risk event occurs | Right side |
The Bow-Tie Analysis Template
Template Structure
| CAUSES | PROACTIVE CONTROLS & TREATMENTS | RISK RANK | REACTIVE CONTROLS & TREATMENTS | CONSEQUENCE |
|---|---|---|---|---|
| [Cause 1] | [Prevention measure for Cause 1] | [Recovery measure for Consequence 1] | [Consequence 1] | |
| [Cause 2] | [Prevention measure for Cause 2] | [H / M / L] | [Recovery measure for Consequence 2] | [Consequence 2] |
| [Cause 3] | [Prevention measure for Cause 3] | [Recovery measure for Consequence 3] | [Consequence 3] | |
| [Cause 4] | [Prevention measure for Cause 4] | [Recovery measure for Consequence 4] | [Consequence 4] |
Header Fields
| Field | Entry |
|---|---|
| RISK | [Concise risk event title] |
| DESCRIPTION | [Detailed description of the risk event, its context, and scope] |
Worked Example — Crane Failure During Heavy Lift Operation
Header
| Field | Entry |
|---|---|
| RISK | Overhead crane failure during critical heavy lift |
| DESCRIPTION | Failure or malfunction of the 50-tonne overhead bridge crane during lifting operations in the main assembly bay, resulting in dropped load, structural damage, and/or personnel injury. |
Bow-Tie Analysis
| CAUSES | PROACTIVE CONTROLS & TREATMENTS | RISK RANK | REACTIVE CONTROLS & TREATMENTS | CONSEQUENCE |
|---|---|---|---|---|
| Crane exceeds safe working load (SWL) | Load charts posted at operator station; electronic overload protection system installed | Emergency lowering procedure activated; crane isolation protocol | Dropped load — damage to partially assembled hull section (AUD 500K–AUD 2M) | |
| Wire rope degradation not detected | Monthly wire rope inspection per AS 1418; replacement schedule based on manufacturer specs | HIGH | Exclusion zone protocol — no personnel beneath suspended loads | Personnel injury or fatality |
| Operator error — incorrect rigging configuration | All riggers hold TLILIC0005 certification; lift plan required and approved for every critical lift | Emergency response plan (ERP) activated; first aid officers on standby | Production schedule delay (6–12 weeks for replacement component) | |
| Mechanical failure of hoist mechanism | Annual major inspection per AS 1418; predictive maintenance program using vibration monitoring | Structural engineer assessment of crane runway and supporting structure post-incident | Structural damage to assembly bay — business continuity impact | |
| Electrical fault causing uncontrolled descent | Fail-safe brake system; monthly electrical safety inspection; RCD protection | Insurance claim process initiated; incident investigation per WHS Act | Regulatory investigation — SafeWork improvement/prohibition notice | |
| Environmental factor — extreme heat affecting brake performance | Operating temperature limits defined in crane manual; operations suspended above 42°C | Crisis communications plan — stakeholder notification within 4 hours | Reputational damage with prime contractor and customer |
How to Construct a Bow-Tie Analysis
Step-by-Step Process
Step 1: Define the risk event clearly. The centre of the bow-tie must be a specific, unambiguous event — not a vague category. "Crane failure during heavy lift" is specific. "Safety risk" is not. Step 2: Brainstorm causes (left side). Ask: "What could cause this event to occur?" Use techniques from the risk identification toolkit — brainstorming, expert interviews, historical incident data, and checklist review. Aim for completeness over brevity. Step 3: Brainstorm consequences (right side). Ask: "If this event occurs, what are all the possible outcomes?" Consider impacts across safety, cost, schedule, quality, regulatory, and reputational dimensions. Step 4: Identify proactive controls (left-centre). For each cause, ask: "What barriers exist or could be put in place to prevent this cause from triggering the risk event?" Map each control to the specific cause it addresses. Step 5: Identify reactive controls (right-centre). For each consequence, ask: "What barriers exist or could be put in place to limit the severity of this consequence?" Map each control to the specific consequence it mitigates. Step 6: Assess completeness. Look for causes without proactive controls and consequences without reactive controls — these are your control gaps and represent the highest-priority areas for risk treatment investment. Step 7: Assign the overall risk rank based on the assessed likelihood (considering proactive controls) and consequence (considering reactive controls).
Defence-in-Depth and the Swiss Cheese Model
Bow-tie analysis aligns directly with a widely used barrier-failure model's Swiss Cheese Model of accident causation. Each control barrier is like a slice of Swiss cheese — it has holes (failure modes). An accident occurs only when the holes in multiple barriers line up, allowing a hazard pathway to pass through all layers.
The bow-tie makes this layered defence architecture visible and auditable. During project reviews, gate reviews, and safety audits, the bow-tie provides immediate visual evidence of whether the control architecture is robust or whether single points of failure exist.
Common Pitfalls
Making the risk event too broad. "Equipment failure" is not a useful centre point — it could encompass hundreds of different failure modes. Narrow the scope to a specific event that can be meaningfully analysed. Listing controls without mapping them to specific causes or consequences. A generic list of "things we do" is not a bow-tie analysis. Each proactive control must address a specific cause, and each reactive control must address a specific consequence. If a control cannot be mapped, it may not be relevant to this risk. Confusing proactive and reactive controls. A proactive control prevents the event from happening. A reactive control limits the damage after the event has occurred. Training operators to avoid overloading the crane is proactive. Having an emergency lowering procedure is reactive. Placing a control on the wrong side misrepresents the control architecture. Ignoring control effectiveness. The bow-tie shows what controls exist, but not whether they are effective. Supplement the bow-tie with a control effectiveness assessment — are controls documented? Are they implemented? Are they tested? Are they reviewed?
Key Takeaways
- Bow-tie analysis provides a single visual that maps the complete risk landscape: causes → proactive controls → risk event → reactive controls → consequences
- Proactive controls reduce likelihood; reactive controls reduce consequence — each must be mapped to specific causes or consequences
- Control gaps (causes or consequences without mapped controls) represent the highest-priority treatment areas
- The method aligns with the Swiss Cheese Model and defence-in-depth principles used in safety-critical industries
- The visual format makes bow-tie analysis highly effective for stakeholder communication — particularly with senior leadership and non-technical stakeholders
- Complete one bow-tie per significant risk event — the analysis is most valuable for high-consequence, complex risks
