Projectmanagertemplate iconProjectmanagertemplateSep 12, 2026 ~6 min source read

Bow-Tie Analysis: A Practical Guide to Visualizing and Managing Project Risk

Bow-Tie Analysis maps how hazards and threats can cause a loss-of-control top event and how preventive and mitigating barriers reduce probability or consequence. This brief explains the model, its components, and a step-by-step approach for project teams.

Bow-Tie Analysis: A Complete Guide to Risk Management

Share this story

Send the public story page.

Useful takeaways from this story.

A bow-tie diagram centers on a clearly defined top event: the moment control is lost but before consequences occur.

Distinguish hazards, threats, top event, preventive barriers, mitigating barriers, and escalation factors to avoid conflating causes and outcomes.

Follow a structured process—define the hazard, set the top event, identify threats and consequences, then map barriers and escalation factors—to produce actionable controls.

# Analysis is and why teams use it

# Core concepts, stated simply Hazard: a source of potential harm (for example: stored energy, hazardous chemicals, heavy lifting operations, high-voltage equipment, cybersecurity access, or critical infrastructure failure).

Threats: credible, specific causes of the top event. They should be detailed enough that a meaningful preventive control can be identified (e.g., avoid generic "equipment failure" in favor of "failure of the temporary lifting mechanism due to inadequate inspection").

Mitigating barriers: controls that reduce the severity or likelihood of consequences after the top event. Examples include emergency shutdown systems, fire suppression, evacuation procedures, emergency response teams, containment systems, backup systems, and crisis communications.

Escalation factors: conditions that can reduce barrier effectiveness. A procedure may work normally but fail if personnel are unavailable, communications systems fail, or required equipment is inaccessible. Identifying escalation factors exposes where apparently strong controls can break down under certain conditions.

# How to perform a Bow-Tie Analysis (step-by-step)

  1. Define the hazard: identify the source of potential harm rather than an undesirable outcome.
  2. Identify the top event: choose the point that represents loss of control immediately before harm could occur.
  3. Identify threats: list credible, specific causes that could trigger the top event. Treat each threat independently to find the appropriate preventive controls.
  4. Identify consequences: list outcomes that could follow the top event (injury, environmental damage, financial loss, schedule disruption, regulatory or reputational impact, or project failure).
  5. Map preventive barriers: assign controls between threats and the top event. For each barrier, assess whether it can actually interrupt the threat pathway.
  6. Map mitigating barriers: assign controls between the top event and each consequence to reduce severity or likelihood.
  7. Identify escalation factors for each barrier and consider controls or redundancies to address those factors.

# Practical points teams should apply

  • Be specific. Vague threats or barriers produce weak analyses. Replace high-level labels like "equipment failure" with a failure mode and cause that shows how to control it.
  • Use the bow-tie as both a visualization and a checklist for control gaps and escalation scenarios.

# Outcome you should expect A structured bow-tie diagram that clarifies which threats lead to the defined top event, which barriers are intended to stop those threats, and which mitigating measures limit consequences. The work highlights weak or single-point-of-failure controls and surfaces escalation factors that require additional attention.

More context around this story.

ISO 27001 Risk Assessment: What It Is and How to Do It
Factorialhr iconFactorialhrAug 19, 2026

ISO 27001 Risk Assessment: What It Is and How to Do It

The risk assessment is where nearly every ISO 27001 project stalls out, and it’s also where you can tell whether the management system was actually built or just written up on paper. Plenty of companies spend weeks filling out a giant spreadsheet packed with dozens of theoretical threats and scores pulled out of thin a

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app