Skip to main content
Category: Enterprise Risk Management

Bow-Tie Analysis

Also known as: Bowtie Analysis, Bow-Tie Diagram, Bowtie Method
Simply put

Bow-tie analysis is a risk assessment technique that uses a single diagram to show, in an easy-to-understand picture, how a risk event can arise from various causes and lead to various consequences. The diagram is shaped like a bow-tie, with the potential event in the center and the causes and outcomes fanning out on either side. It is generally used to help people visualize and communicate risks so they can identify controls and make better decisions.

Formal definition

Bow-tie analysis is a visual risk assessment methodology used to display and communicate information about risks in situations where a central event (often depicted as the knot of the bow-tie) has a range of possible causes on one side and a range of possible consequences on the other. Practitioners typically use the diagram to map causes, the central hazardous or risk event, resulting impacts, and the barriers or controls positioned to prevent the event or mitigate its consequences, supporting analysis of both preventive and recovery controls in a single view. As a technique it is a barrier- or control-focused method that aids in identifying and communicating risk exposures; the specific structure, terminology, and rigor of application vary by organization, sector, and the framework or standard under which it is deployed. This entry is educational and describes the general method rather than any single mandated standard.

Why it matters

Bow-tie analysis matters because it condenses a complex risk picture into a single, accessible diagram that non-specialists can understand. By placing a central risk event at the knot and fanning out its causes on one side and its consequences on the other, the technique helps boards, management, and assurance functions see not just what could go wrong, but how it could arise and what could follow. This visual clarity supports communication across audiences who may not share a technical risk vocabulary, which is often where risk information breaks down in practice.

The method's particular value lies in its barrier- or control-focused structure. Because preventive controls (those aimed at stopping a cause from triggering the event) and recovery or mitigating controls (those aimed at reducing consequences after the event occurs) are displayed in the same view, bow-tie analysis helps organizations examine whether controls are positioned appropriately across the full risk pathway. This can surface gaps where an organization relies heavily on prevention but has little recovery capability, or vice versa, and can inform decisions about where to invest in additional controls.

It is important to keep the technique's limits in view. Bow-tie analysis is a communication and mapping tool, not a quantitative model; it does not by itself measure likelihood or impact, and its usefulness depends on the quality of the underlying analysis and the judgment of those who build it. The specific structure, terminology, and rigor vary by organization, sector, and any framework or standard under which it is applied. This entry is educational and describes the general method rather than any mandated standard; it is not legal, audit, or compliance advice.

Who it's relevant to

Risk Managers and Chief Risk Officers
Risk professionals use bow-tie analysis as a technique within the broader risk management process to visualize how a risk event can arise and unfold, and to examine the placement and adequacy of preventive and recovery controls. It can complement other assessment methods but does not replace quantitative analysis of likelihood and impact.
Boards and Risk Committees
Because the bow-tie condenses a risk into a single accessible picture, it can support the board's oversight role by making significant risk exposures and the controls relied upon easier to discuss and challenge. The board typically uses such outputs for oversight rather than for building or operating the analysis, which generally sits with management and risk functions.
Internal Auditors and Assurance Functions
Assurance functions may reference bow-tie diagrams to understand which controls management has identified along a risk pathway and to focus testing on whether those barriers are designed and operating as intended. The diagram itself illustrates intended control coverage; it does not, on its own, confirm that controls are effective in practice.
Operational and Safety-Focused Teams
The barrier-based structure makes bow-tie analysis common in settings where a hazardous event needs to be understood in terms of both prevention and consequence mitigation. Operational teams use it to communicate how identified hazards are being managed, though the terminology and rigor applied vary by sector and organization.

Inside Bow-Tie Analysis

Top Event (Central Knot)
The single undesired event placed at the center of the diagram, typically representing a loss of control over a hazard rather than the ultimate consequence. It is the point from which causes flow inward and consequences flow outward, and its precise framing determines the usefulness of the entire analysis.
Threats (Causes)
The factors or scenarios on the left-hand side that could plausibly give rise to the top event. Each threat is generally mapped as a distinct pathway so that preventive controls can be associated with it individually.
Consequences
The potential outcomes on the right-hand side that could result if the top event occurs. Multiple consequences may branch from a single top event, each with its own set of mitigating controls.
Preventive (Proactive) Barriers
Controls positioned on the threat side that are intended to reduce the likelihood of the top event occurring. In risk terms these act primarily on likelihood rather than impact.
Mitigating (Recovery) Barriers
Controls positioned on the consequence side that are intended to reduce the severity of outcomes once the top event has occurred. These act primarily on impact rather than likelihood.
Escalation Factors and Escalation Controls
Conditions that can defeat or degrade a barrier, together with the additional controls intended to manage those conditions. This layer helps distinguish a barrier's presence from its continued reliability.
Barrier Attributes
Descriptive information often attached to each barrier, which may include its owner, type, and an assessment of its condition. This supports the separation between whether a control is designed to exist and whether it is operating effectively.

Common questions

Answers to the questions practitioners most commonly ask about Bow-Tie Analysis.

Is bow-tie analysis a quantitative method that produces a numerical risk score?
Generally, no. Bow-tie analysis is typically a qualitative, visual technique that maps a central hazardous event to its causes (threats) on one side and consequences on the other, with preventive and mitigating controls arrayed as barriers between them. It is designed to communicate risk pathways and control logic clearly, not to generate a calculated probability or loss figure. Some organizations overlay semi-quantitative elements, such as ratings of barrier strength or likelihood bands, but the core method does not itself produce a precise numerical score. Where a quantified estimate is needed, bow-tie is often used alongside other techniques rather than as a substitute for them.
Does completing a bow-tie diagram prove that the mapped controls are actually working?
No. A bow-tie diagram represents control design, that is, the intended barriers and how they are supposed to function, but it does not by itself demonstrate operating effectiveness. Confirming that a control operates as intended over time requires separate testing or assurance activity, which typically sits with management for first-line monitoring and with internal audit or other assurance functions for independent evaluation. Treating a well-drawn bow-tie as evidence that barriers are effective conflates design with performance. The diagram is best viewed as a hypothesis about the control environment that still needs to be verified through monitoring, testing, or incident review.
How do you select the central event when building a bow-tie?
The central event, sometimes called the top event, is typically defined as the point at which control over a hazard is lost, framed neutrally rather than as a cause or a consequence. Practitioners generally aim for an event specific enough to be meaningful but not so narrow that it captures only one pathway. Setting the central event too early tends to merge it with threats; setting it too late tends to merge it with consequences. Because the choice shapes the entire analysis, it is often worth testing candidate events with the people who own the underlying process before proceeding. The appropriate framing depends on the risk, the sector, and the purpose of the exercise.
Who should be involved in developing a bow-tie, and which function owns it?
Bow-tie development typically benefits from a workshop bringing together those with direct operational knowledge of the threats and controls, often facilitated by a risk professional. Ownership of the analysis and of the underlying risk generally rests with management in the first line, since they operate the barriers, while a risk or governance function may facilitate, maintain the method, and provide challenge. Assurance functions such as internal audit usually remain independent of ownership so they can later evaluate the controls objectively. The board or a relevant committee may review significant bow-ties as part of oversight, but oversight should be distinguished from the operational ownership of the controls themselves.
How should barriers be documented so the analysis remains useful over time?
Barriers are typically documented in a way that identifies what each control is intended to do, whether it acts to prevent the central event or to mitigate consequences, and who is accountable for it. Many practitioners distinguish barriers by type, such as those relying on hardware, human action, or a combination, because barriers dependent on human performance often warrant closer monitoring. It is generally advisable to avoid listing aspirational or overlapping barriers that do not independently interrupt a pathway, since inflating the barrier count can create false confidence. Keeping documentation concise and tied to accountable owners helps the diagram support review and updating rather than becoming a static artifact.
How does bow-tie analysis fit within a broader risk management framework?
Bow-tie analysis is one technique among several and is generally used to complement, not replace, an organization's wider risk management approach. It can support activities described in frameworks such as ISO 31000 or COSO enterprise risk management, for example by informing risk assessment, control identification, and communication, but neither framework mandates the bow-tie method specifically. In practice it is often applied to a smaller number of significant or catastrophic risks where visualizing pathways adds value, rather than to every risk in a register. Whether and how to use it depends on the organization's risk profile, resources, and the judgment of its risk professionals. These entries are educational and not legal, audit, or compliance advice.

Common misconceptions

A bow-tie diagram quantifies risk and produces a numerical likelihood or impact score.
Bow-tie analysis is generally a qualitative, visual technique for mapping the pathways between threats, a top event, and consequences. It structures thinking about barriers but does not, in itself, calculate probabilities or financial impact; any quantification would require separate methods layered on top of it.
Showing a barrier on the diagram demonstrates that the risk is adequately controlled.
Depicting a barrier only reflects its intended presence in the control design. Whether that barrier operates effectively, and whether escalation factors have degraded it, is a separate question that typically requires assurance activity beyond the diagram. Control design and operating effectiveness should not be treated as the same thing.
Bow-tie analysis is a mandated methodology under governance or risk frameworks.
Bow-tie analysis is generally a voluntary analytical technique rather than a legal requirement. While it can support risk management processes that some frameworks describe, no single framework universally mandates its use, and its adoption varies by sector, jurisdiction, and organizational preference.

Best practices

Define the top event with care as a loss of control, keeping it distinct from both its underlying causes and its ultimate consequences, so that preventive and mitigating barriers can be allocated to the correct side.
Map each threat as a separate pathway and associate preventive barriers with individual threats, rather than presenting a single undifferentiated set of controls, to preserve clarity about what reduces likelihood versus impact.
Distinguish barrier presence from barrier effectiveness by recording escalation factors and escalation controls, and by treating control design and operating effectiveness as separate matters requiring separate evidence.
Assign a clear owner to each barrier and clarify whether responsibility sits with management as a control operator or with an assurance function that independently tests the control, avoiding conflation of operational and oversight roles.
Use the analysis as an input to broader risk assessment rather than a substitute for it, complementing it with quantitative or other methods where likelihood and impact estimates are needed.
Review and refresh diagrams periodically and after significant changes, since barriers can degrade over time and threats or consequences may evolve, and document that the output is educational analysis rather than an assurance opinion.