← ArticlesBow-Tie Risk AnalysisProject Delivery · RiskLesson 9/10← PrevNext →
GuidePublished 13 Aug 20267 min readBy Kevin Joginbow-tie analysispreventive controlsmitigating controlstop event

Project Delivery · Project Risk Management

Bow-Tie Risk Analysis

A visual and analytical method for connecting causes, a central risk event, preventive controls, mitigating controls and consequences.

8 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

A visual and analytical method for connecting causes, a central risk event, preventive controls, mitigating controls and consequences. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Define the top event
  • Map credible causes
  • Map consequences
  • Place preventive and mitigating controls
  • Test degradation factors and ownership
  1. Define the top event
  2. Map credible causes
  3. Map consequences
  4. Place preventive and mitigating controls
  5. Test degradation factors and ownership

Why Bow-Tie Analysis Is the Most Powerful Visual Risk Tool

Most risk analysis methods either focus on what causes a risk (like fault trees and fishbone diagrams) or what happens when a risk materialises (like event trees and consequence analysis). Bow-tie analysis does both — simultaneously — in a single, intuitive visual structure.

For heavy engineering, manufacturing, and defence projects, bow-tie analysis is particularly powerful because these environments involve complex causal chains, multiple control layers (defence-in-depth), and consequences that can cascade across safety, schedule, cost, and regulatory dimensions simultaneously. The visual format makes it immediately accessible to stakeholders who may not engage with spreadsheet-based risk registers.

The bow-tie method is widely used in the oil and gas, aviation, and nuclear industries — sectors where the consequences of risk failure are catastrophic and the control architecture must be demonstrably robust.

What Is a Bow-Tie Analysis?

The bow-tie diagram takes its name from its shape: two triangles meeting at a central point, resembling a bow-tie. The structure has five components:

Component Definition Position
Causes Events or conditions that could trigger the risk Left side
Proactive Controls & Treatments Barriers that prevent the risk event from occurring Between causes and risk
Risk Event The specific undesired event being analysed Centre
Reactive Controls & Treatments Barriers that limit damage after the event occurs Between risk and consequences
Consequences Outcomes that result if the risk event occurs Right side

The Bow-Tie Analysis Template

Template Structure

CAUSES PROACTIVE CONTROLS & TREATMENTS RISK RANK REACTIVE CONTROLS & TREATMENTS CONSEQUENCE
[Cause 1] [Prevention measure for Cause 1] [Recovery measure for Consequence 1] [Consequence 1]
[Cause 2] [Prevention measure for Cause 2] [H / M / L] [Recovery measure for Consequence 2] [Consequence 2]
[Cause 3] [Prevention measure for Cause 3] [Recovery measure for Consequence 3] [Consequence 3]
[Cause 4] [Prevention measure for Cause 4] [Recovery measure for Consequence 4] [Consequence 4]

Header Fields

Field Entry
RISK [Concise risk event title]
DESCRIPTION [Detailed description of the risk event, its context, and scope]

Worked Example — Crane Failure During Heavy Lift Operation

Field Entry
RISK Overhead crane failure during critical heavy lift
DESCRIPTION Failure or malfunction of the 50-tonne overhead bridge crane during lifting operations in the main assembly bay, resulting in dropped load, structural damage, and/or personnel injury.

Bow-Tie Analysis

CAUSES PROACTIVE CONTROLS & TREATMENTS RISK RANK REACTIVE CONTROLS & TREATMENTS CONSEQUENCE
Crane exceeds safe working load (SWL) Load charts posted at operator station; electronic overload protection system installed Emergency lowering procedure activated; crane isolation protocol Dropped load — damage to partially assembled hull section (AUD 500K–AUD 2M)
Wire rope degradation not detected Monthly wire rope inspection per AS 1418; replacement schedule based on manufacturer specs HIGH Exclusion zone protocol — no personnel beneath suspended loads Personnel injury or fatality
Operator error — incorrect rigging configuration All riggers hold TLILIC0005 certification; lift plan required and approved for every critical lift Emergency response plan (ERP) activated; first aid officers on standby Production schedule delay (6–12 weeks for replacement component)
Mechanical failure of hoist mechanism Annual major inspection per AS 1418; predictive maintenance program using vibration monitoring Structural engineer assessment of crane runway and supporting structure post-incident Structural damage to assembly bay — business continuity impact
Electrical fault causing uncontrolled descent Fail-safe brake system; monthly electrical safety inspection; RCD protection Insurance claim process initiated; incident investigation per WHS Act Regulatory investigation — SafeWork improvement/prohibition notice
Environmental factor — extreme heat affecting brake performance Operating temperature limits defined in crane manual; operations suspended above 42°C Crisis communications plan — stakeholder notification within 4 hours Reputational damage with prime contractor and customer

How to Construct a Bow-Tie Analysis

Step-by-Step Process

Step 1: Define the risk event clearly. The centre of the bow-tie must be a specific, unambiguous event — not a vague category. "Crane failure during heavy lift" is specific. "Safety risk" is not. Step 2: Brainstorm causes (left side). Ask: "What could cause this event to occur?" Use techniques from the risk identification toolkit — brainstorming, expert interviews, historical incident data, and checklist review. Aim for completeness over brevity. Step 3: Brainstorm consequences (right side). Ask: "If this event occurs, what are all the possible outcomes?" Consider impacts across safety, cost, schedule, quality, regulatory, and reputational dimensions. Step 4: Identify proactive controls (left-centre). For each cause, ask: "What barriers exist or could be put in place to prevent this cause from triggering the risk event?" Map each control to the specific cause it addresses. Step 5: Identify reactive controls (right-centre). For each consequence, ask: "What barriers exist or could be put in place to limit the severity of this consequence?" Map each control to the specific consequence it mitigates. Step 6: Assess completeness. Look for causes without proactive controls and consequences without reactive controls — these are your control gaps and represent the highest-priority areas for risk treatment investment. Step 7: Assign the overall risk rank based on the assessed likelihood (considering proactive controls) and consequence (considering reactive controls).

Defence-in-Depth and the Swiss Cheese Model

Bow-tie analysis aligns directly with a widely used barrier-failure model's Swiss Cheese Model of accident causation. Each control barrier is like a slice of Swiss cheese — it has holes (failure modes). An accident occurs only when the holes in multiple barriers line up, allowing a hazard pathway to pass through all layers.

The bow-tie makes this layered defence architecture visible and auditable. During project reviews, gate reviews, and safety audits, the bow-tie provides immediate visual evidence of whether the control architecture is robust or whether single points of failure exist.

Common Pitfalls

Making the risk event too broad. "Equipment failure" is not a useful centre point — it could encompass hundreds of different failure modes. Narrow the scope to a specific event that can be meaningfully analysed. Listing controls without mapping them to specific causes or consequences. A generic list of "things we do" is not a bow-tie analysis. Each proactive control must address a specific cause, and each reactive control must address a specific consequence. If a control cannot be mapped, it may not be relevant to this risk. Confusing proactive and reactive controls. A proactive control prevents the event from happening. A reactive control limits the damage after the event has occurred. Training operators to avoid overloading the crane is proactive. Having an emergency lowering procedure is reactive. Placing a control on the wrong side misrepresents the control architecture. Ignoring control effectiveness. The bow-tie shows what controls exist, but not whether they are effective. Supplement the bow-tie with a control effectiveness assessment — are controls documented? Are they implemented? Are they tested? Are they reviewed?

Key Takeaways

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Define the top event is defined, owned, evidenced and linked to the relevant project decision.
Check 02Map credible causes is defined, owned, evidenced and linked to the relevant project decision.
Check 03Map consequences is defined, owned, evidenced and linked to the relevant project decision.
Check 04Place preventive and mitigating controls is defined, owned, evidenced and linked to the relevant project decision.
Check 05Test degradation factors and ownership is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

Risk Analysis WorksheetsGuide · RiskNEXT LESSON →Risk Evaluation and Treatment Selection WorksheetGuide · RiskThe Project Risk Register HandbookGuide · RiskThe Practical Project Risk Identification ChecklistGuide · Risk