What Is a Bow Tie Diagram?
A practical guide to bow tie analysis — what the diagram actually shows, how barriers earn credit, where it beats a fault tree, and the mistakes that make a bow tie look rigorous while proving nothing.
The short answer
A bow tie diagram is a single picture of one hazard: everything that could set it off on the left, the hazard itself in the middle, everything that could result on the right, and the barriers standing between them. It is named for its shape — causes fan in, consequences fan out, and the knot in the middle is the moment control is lost.
Its value is not that it is pretty. It is that it forces one specific question for every pathway through the diagram: what actually stops this, and how do you know it works? A risk register can hide a missing barrier behind a colour. A bow tie cannot — either something sits in the path or there is a gap you can see.
The method is commonly traced to lecture notes from the University of Queensland around 1979, and was taken up seriously by the process industries after Piper Alpha, where the Cullen Inquiry’s findings pushed operators towards demonstrating barrier integrity rather than asserting it. It is now standard practice across oil and gas, nuclear, rail, aviation and defence.
The anatomy, left to right
Every bow tie has the same five parts. The vocabulary shifts between industries — what rail calls a hazard, process safety calls a top event — but the structure does not.
| Part | What it is | Also called |
|---|---|---|
| Initiating events | The things that can start the sequence. Each carries a frequency — how often you expect it, per year or per operation. | Threats, causes, hazardous events |
| Preventative barriers | Anything that stops an initiating event from reaching the hazard. Interlocks, trips, procedures, design rules. | Prevention controls, safeguards, safety functions |
| The hazard | The moment control is lost. Not the accident — the point after which you are relying on mitigation. | Top event, hazardous state, loss of control |
| Mitigative barriers | Anything that limits the damage once the hazard has occurred. Containment, detection, alarms, evacuation. | Recovery controls, mitigations, consequence barriers |
| Consequences | The outcomes, usually split by who or what is exposed — workers, public, environment, asset — because the same hazard harms each differently. | Accidents, outcomes, exposure groups |
The left half answers “how likely is this?”. The right half answers “how bad, and for whom?”. Keeping them in one picture is the whole point: it is the only view where you can see that a hazard has four causes and only one barrier between them and the top event.
What makes a barrier count
This is where most bow ties quietly fail. Drawing a box labelled “operator training” between a cause and a hazard does not reduce risk. A barrier only earns credit if you can answer three questions about it:
- Is it independent? A barrier sharing a power supply, a sensor or a person with the thing it protects against is not a second line of defence. Common-cause failure is what turns three barriers into one.
- Is it effective, and how do you know? A claimed probability of failure on demand needs evidence — a proof-test record, a reliability calculation, a certificate. A number with nothing behind it is an opinion.
- Is it still there? Barriers degrade. A bow tie drawn once and filed is a description of a plant that no longer exists.
Most standards impose a ceiling on what you may claim. Human and procedural barriers are conventionally not credited better than one failure in ten demands, however well written the procedure. A single engineered function might earn one in a hundred; only genuinely independent, redundant systems justify more.
The uncomfortable consequence is that a barrier you have claimed but never substantiated should earn nothing at all. Tools that quietly credit it anyway produce a diagram that looks safer than the plant.
Bow tie, fault tree, or event tree?
They answer different questions, and the bow tie is not a replacement for either.
- A fault tree decomposes one failure into its logical combinations of sub-failures. It is the right tool when you need to know precisely how a system fails and to compute a probability from component data.
- An event tree traces what follows an initiating event through a sequence of successes and failures. It is the right tool for modelling escalation.
- A bow tie is effectively a fault tree and an event tree joined at the top event, with the detail deliberately collapsed so that barriers become the subject. It is the right tool when the question is barrier adequacy, and when the diagram has to be understood by people who will never read a fault tree.
In practice they nest. A bow tie shows the barrier; a fault tree may sit underneath one barrier to justify the number claimed for it.
Bow ties in the standards
Few standards mandate the bow tie by name. What they mandate is the thing a bow tie is good at — demonstrating that hazards are identified, that barriers exist, and that the residual risk is tolerable and as low as reasonably practicable. The scale you score against changes by sector:
- Nuclear — ONR SAPs. Safety-classified structures, systems and components with reliability expectations, assessed against numerical targets per exposure group.
- Rail — EN 50126. Safety integrity levels expressed as a tolerable hazard rate, with ALARP tolerability judged across affected groups.
- Aviation — ARP 4761 and AC 25.1309. Failure conditions classified by severity, each with a probability threshold that tightens as severity rises.
- Defence — Def Stan 00-056 and MIL-STD-882E. Goal-based direct judgement in the first case, a severity-by-probability risk assessment code in the second.
- Oil and gas — ISO 17776. Major accident hazards scored across personnel, environment and asset, with safety integrity requirements on instrumented functions.
The structure of the bow tie is identical in all five. Only the barrier vocabulary and the consequence scale change — which is why a tool that hard-codes one standard’s scale makes every other sector fight it.
Five ways a bow tie goes wrong
- The top event is actually the accident. If the middle of your bow tie is “fatality”, you have no room for mitigation. The top event is loss of control, not its outcome.
- Barriers that are not barriers. “Safety culture” and “management oversight” are conditions for barriers working, not barriers. If it cannot fail on a specific demand, it does not belong in the path.
- Double-counting a shared barrier. One system protecting three hazards is often credited three times. It fails once.
- Credit for the unsubstantiated. Claiming a barrier without evidence and taking the risk reduction anyway is the single most common way a safety case overstates its position.
- The diagram stops matching the plant. The day it is issued it is accurate. Eighteen months later a barrier has been taken out of service and nobody re-ran the numbers.
See one that works
Reading about bow ties only gets you so far. The link below opens a real, complete bow tie in your browser — initiating events with frequencies, barriers carrying safety classes and evidence, a hazard, and four exposure groups with their own residual figures. One barrier in it is deliberately shown as claimed-but-unsubstantiated, so you can see what that does to the numbers.
No sign-up, no sales call.
Bow ties that stay true
A bow tie is only worth drawing if it still describes the plant next year. That is the problem SAFOPS exists to solve.