Skip to content

Bow-tie Diagram

Map a bounded risk scenario from threats through a loss-of-control top event to possible consequences, separating preventive from mitigative barriers.

Version
v1 · 2026-10-03 · History
Domain-specific #
13023
Domain group
Applied Sciences & Engineering
Origin domain
Engineering & Design (beyond software)
Subdomain
Safety Risk Analysis → Engineering & Design (beyond software)
Aliases
Bow Tie Risk Diagram

Core Idea

A bow-tie diagram places one bounded risk scenario around a central top event: a loss-of-control event or condition that has occurred before any particular adverse consequence is assumed. To its left, possible threats or initiators lead toward that event, with prevention or control barriers located on those paths. To its right, paths lead from the event to possible consequences, with mitigative barriers located on those later paths. The diagram makes the difference between preventing loss of control and limiting what follows it visible at a glance.[1][2]

The underlying hazard, the top event and the consequence are distinct. A hazard is a potential source of harm; a threat is a way it may be released or realized; the top event marks loss of control; a consequence is one possible later outcome. Hudson's hospital analysis makes the temporal distinction explicit: the top event is reached before adverse consequences necessarily occur. HSE's offshore example likewise centers a release and places prevention/control barriers before, and mitigation barriers after, that central event.[2][1]

This is a qualitative representation, not a certificate of safety. A line labeled “barrier” reports that an analyst has placed a control claim on a path; the drawing alone does not establish that the barrier works, is independent of other barriers, or covers every credible path. HSE says bow-ties can document barriers, support qualitative gap assessment and inform a later semi-quantitative analysis. Hudson treats frequencies and barrier-effectiveness quantification as additional information, not as part of simply drawing the model.[1][2]

Structural Signature

Sig role-phrases: bounded scenario and hazard — incoming threat paths — loss-of-control top event — preventive/control barriers — outgoing consequence paths — mitigative barriers — optional assurance annotations.

  • Bounded scenario and hazard. The diagram is about a particular risk scenario. Its hazard is a potential source of harm, not itself the event at the center; defining the scenario controls which threats and outcomes belong in one drawing.[1][2]
  • Incoming threat paths. Each left-side path represents a possible initiator or route to loss of control. This preserves the distinction between several ways an event might arise without claiming every conceivable route has been found.[1][2]
  • Loss-of-control top event. The pivot is a specified event or condition where control is lost. If the center is already the eventual harm, there is no clean place to represent mitigation after it.[2]
  • Preventive or control barriers. Labels on incoming paths show claimed measures meant to interrupt threats or control the event before or at the pivot. Their placement is a functional classification, not performance evidence.[1][2]
  • Outgoing consequence paths. Several consequences can follow the same top event, or none may occur in a given realization. The right side distinguishes these possibilities from the event itself.[2]
  • Mitigative barriers. Labels after the pivot denote claimed measures meant to limit subsequent consequences. They are not interchangeable with prevention merely because both can be called safeguards.[1][2]
  • Optional assurance annotations. Barrier degradation factors, ownership, numerical frequencies and reliability estimates may enrich an analysis; they are not required by HSE's minimal Appendix C representation. If added, their evidential status must be separately established.[1][2]

The two-sided path grammar is the identity. It can be drawn graphically or rendered as a table while preserving the same functional distinction, as in HSE's high-rise residential report.[3]

What It Is Not

Not a proof of adequate, independent protection. HSE says the diagram facilitates qualitative examination of gaps. Depicting several barriers—even with separate labels—does not demonstrate their performance, independence or completeness. Shared references may instead reveal that one barrier appears on multiple paths.[1]

Not a quantified risk estimate by default. Frequencies of threats and measured effectiveness of barriers are additional inputs if an analyst proceeds to risk assessment. A qualitative map can be useful without those numbers, but it cannot silently supply them.[1][2]

Not a hazard, top event and consequence collapsed into one label. This collapse prevents the left/right distinction from doing analytical work. Nor are escalation-factor annotations constitutive: they may clarify possible barrier degradation, but a diagram without them can still satisfy the original HSE form.[1][2]

Scope of Application

HSE's offshore risk-assessment guidance gives an explicit bow-tie example with an event in the center, possible initiators and consequences, and prevention/control versus mitigation barriers. The purpose is to document lines of defence and identify possible gaps within a broader assessment, not to replace that broader assessment.[1]

HSE's high-rise residential research used bow-tie exercises for fire and structural serious-incident scenarios. The workshop results were even presented as tables, showing that spatial graphics are a convenient medium rather than the only encoding of the relation. The report says potential controls need to be considered against the specifics of the building, so its tables are not generic prescriptions.[3]

Hudson's hospital medication-risk article applies the same top-event-centered split to patient-safety scenarios. It distinguishes possible wrong-patient, wrong-diagnosis, wrong-drug, wrong-dose and wrong-route top events, then separates threats and preventive controls before the event from consequences and mitigations after it. The example here describes the representation only; it is not guidance on medication practice.[2]

Clarity

The diagram clarifies where a safety claim sits. Is the proposed barrier intended to stop a threat from becoming a loss of control, or to limit an outcome after control is lost? If two analysts place the same claimed control on different sides, they are making different causal assertions, not merely choosing different drawing styles.[1][2]

It also clarifies what has not been established. An empty path may suggest a gap to investigate, while a filled path records a claimed line of defence. Neither depiction is a measured estimate of likelihood or assurance. The top event is a useful pivot because it prevents an analyst from treating a possible consequence as inevitable once a threat exists.[1][2]

Manages Complexity

Many initiators and outcomes can be organized around one central event. That reduces a large collection of scenario statements to two directional questions: what can bring about loss of control, and what can follow it? HSE's high-rise workshop tables show the compression in practice by collecting causes, event, consequences and potential controls into a legible common format.[3]

Compression necessarily omits detail. A diagram for one scenario can hide coupled events, incomplete hazard identification or performance dependencies among barriers. HSE therefore treats the bow-tie as one aid within risk assessment, including qualitative gap identification and, where needed, a separately justified deeper analysis. The notation is useful when its selective scope remains visible.[1]

Abstract Reasoning

Start by testing the representation's internal grammar, not by assuming its content is true. Is there one declared top event, with threats genuinely before it and consequences genuinely after it? Are barriers located by their intended prevention/control or mitigation function? This test can reveal that a purported “bow-tie” is only a cause list, a consequence list, or a generic flowchart.[1][2]

Then reason conditionally from the map. If a threat path has no depicted preventive measure, that is a candidate gap for inquiry, not proof that no real control exists. If two paths share a barrier label, that prompts a dependency question, not an automatic failure claim. If an outcome has a mitigating measure, the drawing indicates an intended intervention point but supplies no reliability estimate. These are disciplined uses of the representation rather than conclusions the diagram by itself proves.[1]

Knowledge Transfer

The literal method transfers from offshore scenarios to high-rise buildings and hospital medication safety because each setting can specify a hazard context, one loss-of-control pivot, incoming threats, outgoing possible consequences and barrier roles on the two sides. What transfers is the scenario grammar; the particular threats, controls and evidence of their effectiveness do not.[1][3][2]

Outside risk analysis, a two-sided diagram around a middle node may visually resemble a bow tie without being this named method. Live Bow Tie Biology concerns many inputs converging on a narrow conserved core and then diverging into many outputs—a different relation despite the shared image. The broad representational act does transfer through live prime Representation, the proposed parent, but the safety-barrier interpretation remains domain-specific.[4][5]

Examples

Canonical: high-rise residential serious-incident tables

HSE Research Report RR1170 describes workshops that used bow-tie exercises for high-rise residential fire and structural-event scenarios. The researchers compared the workshop diagrams and presented common causes, event categories, consequences and potential prevention or mitigation barriers in tables. The report explicitly says building-specific circumstances matter before using such high-level lists. This is an instance of the representation grammar, not evidence that any particular building's listed controls had been verified.[3]

Mapped back: The scenario and hazard are the bounded high-rise fire or structural serious-incident context; incoming threat paths are workshop-identified causes; the top event is the declared fire or structural event; preventive/control barriers are possible pre-event controls. Outgoing consequence paths record possible injuries, damage or other outcomes; mitigative barriers are the separate post-event measures. Optional assurance annotations are not inferred from the table.

Applied: hospital medication-risk analysis

Hudson's patient-safety article treats a wrong-dose medication event as one possible central top event, distinct from other event types and from any later patient harm. The analysis places possible routes to that event on the incoming side and possible consequences on the outgoing side, assigning different preventive and mitigative roles to claimed controls. It says quantitative threat frequencies and barrier-effectiveness estimates would be additional inputs. No clinical or operational recommendation follows from reproducing this published diagram logic.[2]

Mapped back: The scenario and hazard are hospital medication risk; threat paths are routes to the wrong-dose event; that event is the loss-of-control pivot. Claimed preventive controls sit before it, possible consequences after it, and claimed mitigative controls on the later paths. Optional assurance annotations such as frequencies or effectiveness are not assumed merely from the drawing.

Structural Tensions

T1: Qualitative legibility versus quantified assurance. A sparse map lets a multidisciplinary group see distinct pathways and candidate gaps without inventing precision, but cannot establish event likelihood or barrier performance. Adding measured frequencies and effectiveness can inform a stronger decision, yet creates data, dependence and validation burdens that the map itself does not satisfy. Leaning toward legibility sacrifices numerical assurance; leaning toward quantification may exceed the evidence available. Diagnostic: Is the present decision to identify and discuss pathways, or does it require separately validated performance and frequency estimates?

T2: Scenario breadth versus event-specific traceability. A broad view can reveal shared barrier labels across several scenarios, but risks conflating distinct top events or hiding which path each control addresses. Separate narrow bow-ties preserve a clear pivot and path meaning, but users then need cross-references to discover common exposures. Neither maximal breadth nor maximal splitting gives both benefits for free. Diagnostic: Can all paths be read against one well-defined loss-of-control event, or should the analysis use several linked scenario views?

Structural–Framed Character

Bow-tie diagrams are mixed but framed toward risk-analysis practice. Their causal-path layout is structurally recognizable; their evaluative weight enters when “gap” or “adequate protection” is claimed, which requires separate judgment rather than following from the lines. They depend on human practice for scenario selection, diagram construction and interpretation, even though the represented events and possible harms are not created by drawing them. Their institutional origin in safety management shapes how they are used, but no one regulator's diagram convention exhausts the form. Their vocabulary travels among offshore, residential and healthcare safety settings because “threat,” “top event” and “barrier” retain risk-analysis meanings; a lookalike biological hourglass does not inherit them. Import versus recognition matters: the diagram can be deliberately imported into another safety domain, whereas merely finding a many-to-one-to-many shape outside safety is not recognition of the same method. Its character: a broadly reusable representation structure held within a constitutive, judgment-laden risk-barrier frame.[1][3][2]

Structural Core vs. Domain Accent

The portable skeleton is a selected target system mapped into an interpretable medium. Live Representation already owns that skeleton and is the proposed strict parent: bow-tie paths stand for selected scenario relations while other details are omitted. A more specific causes-to-pivot-to-outcomes skeleton could be a future-prime question, but is not admitted here.[5]

The domain accent is indispensable: the pivot is loss of control, the left and right sides distinguish prevention/control from mitigation, and path labels concern threats, hazards and possible consequences. Those roles have evidential limits in safety analysis. Exporting only the bow-tie silhouette or the bare notion of a middle node loses the identity, so this entry remains domain-specific rather than a prime despite its reusable visual grammar.[1][2]

This entry is a kind of Representation. A bow-tie diagram is a specialized representation of a bounded risk scenario and its two-sided barrier pathways.

Relationships to Other Abstractions

Local relationship map for Bow-tie DiagramParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.Bow-tie DiagramDOMAINPrime abstraction: Representation — is a kind ofRepresentationPRIME

Current abstraction Bow-tie Diagram Domain-specific

Parents (1) — more general patterns this builds on

  • Bow-tie Diagram is a kind of Representation Prime

    A bow-tie diagram is a specialized representation of a bounded risk scenario and its two-sided barrier pathways.

Hierarchy path (1) — routes to 1 parentless root

Neighborhood in Abstraction Space

Bow-tie Diagram sits in a sparse region of the domain-specific corpus (72nd percentile for distinctiveness): few abstractions share its structure, so a faithful description tends to retrieve it precisely.

Family — Disaster Risk & Hazard Management (12 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-10-08

Not to Be Confused With

Fault Tree Analysis asks how lower-level events combine through Boolean logic to produce a specified unwanted event. Event-tree-style reasoning proceeds from an initiating point toward outcomes. A bow-tie may place similar questions on opposite sides of a pivot, but it is not automatically a validated union of two completed quantitative analyses, and its minimal form has no cut-set or probability requirement.[6][1]

Bow Tie Biology names a many-input-to-conserved-core-to-many-output architecture, not the risk diagram. Hazard, top event and consequence are not interchangeable labels; confusing them erases the prevention/mitigation separation. Escalation factors, ownership fields, numerical scores and assurance claims may be useful later layers, but their absence does not invalidate the qualitative core.[4][2][1]

References

[1] UK Health and Safety Executive, Guidance on Risk Assessment for Offshore Installations, Offshore Information Sheet No. 3/2006, Appendix C “Bow-Tie Diagrams,” PDF pp.18–19 and Figure 7, inspected 2026-10-01. This original source defines a qualitative representation and gap-assessment use. registry ↩a ↩b ↩c ↩d ↩e ↩f ↩g ↩h ↩i ↩j ↩k ↩l ↩m ↩n ↩o ↩p ↩q ↩r ↩s ↩t ↩u ↩v

[2] Patrick T. W. Hudson, “Risk analysis and assessment: a tool for pharmacy practice”, European Journal of Hospital Pharmacy, Patient Safety special supplement (2006), mirrored PDF pp.6–8, inspected 2026-10-01. Cited here for descriptive diagram logic only, not clinical guidance. registry ↩a ↩b ↩c ↩d ↩e ↩f ↩g ↩h ↩i ↩j ↩k ↩l ↩m ↩n ↩o ↩p ↩q ↩r ↩s ↩t ↩u

[3] UK Health and Safety Executive, High Rise Residential Buildings: Preliminary Serious Incident Scenarios and Potential Control Measures, Research Report RR1170, §3.6.2 PDF pp.46–48, inspected 2026-10-01. Its bow-tie tables describe potential controls subject to building-specific assessment. registry ↩a ↩b ↩c ↩d ↩e ↩f

[4] Encyclopedia of Abstractions, live prime Bow Tie (Biology), Core Idea and Structural Signature, inspected 2026-10-01. registry ↩a ↩b

[5] Encyclopedia of Abstractions, live prime Representation, Core Idea and Structural Signature, inspected 2026-10-01. registry ↩a ↩b

[6] Encyclopedia of Abstractions, live domain-specific Fault Tree Analysis, Core Idea and Structural Signature, inspected 2026-10-01. registry ↩