What this is
What is a bow tie analysis?
What is a bow tie analysis?
A bow tie analysis is a diagram-based risk method that puts a single top event — an ammonia release, a structural collapse — in the centre, with the threats that could cause it on the left and the consequences that could follow on the right. Preventive barriers sit between threats and the top event; mitigating barriers sit between the top event and consequences. It is deliberately reserved for the small number of hazards that could kill someone or close the site, because doing it properly for every hazard would be prohibitively slow.
What's the difference between a bow tie and a standard risk assessment?
A standard risk assessment scores likelihood and severity for a hazard as a whole. A bow tie forces you to name every individual barrier standing between the threat and the top event, and between the top event and each consequence, then rate each one separately. That granularity is the point — it shows which specific barrier is carrying the most weight, and which barriers share a common weakness.
Why does a barrier need an owner?
A barrier without a named owner degrades silently, because nobody is accountable for checking it still works. Assigning ownership is what turns a bow tie from a one-off diagram into something that can be verified on a schedule, which is the entire reason the Barrier Health Review exists downstream of this record.
Scope
When is a bow tie analysis record required?
This is a facilitated analysis for a single named top event, not a running log and not a general hazard register. Using it outside a genuine fatal-risk scenario dilutes both the effort and the credibility of the ones that matter.
Use this template when
- The hazard could plausibly kill someone or close the site — ammonia release, fire, major food safety failure, structural collapse, confined space, major environmental release
- A new process, plant, or major change introduces one of those hazard categories for the first time
- An incident or near-miss reveals that the existing bow tie's threats or barriers no longer match reality
- The Critical Control Register needs a documented source analysis behind a critical control it lists
- The organisation is standing up its fatal-risk programme and needs the first bow tie for each named hazard
Do not use it for
- Job Safety Analysis, which breaks a single task into steps and hazards for the people doing that task, not a site-level major hazard.
- Hazard Identification Study, which is the broader screening exercise used to decide whether a hazard is significant enough to warrant a bow tie in the first place.
- Critical Control Register, which lists the controls once they're named — the bow tie is where they're identified and reasoned through.
- Risk Assessment (FDN-012), which is the general-purpose task and area risk tool for hazards that don't meet the fatal-risk bar.
- What If Study, which is a faster brainstorming method for hazards that don't need full bow tie rigour.
Compliance mapping
Which ISO 31000 cl.6.4 requirements does this satisfy?
ISO 31000 cl.6.4 covers risk assessment as identification, analysis and evaluation — the bow tie record maps its sections onto that structure so each part of the process leaves a distinct, checkable trace.
| Clause | Requirement | Where it lands |
|---|---|---|
| cl.6.4.2 Risk identification | Threats on the left and consequences on the right are identified before barriers are discussed | Structure |
| cl.6.4.2 Risk identification | The top event is defined precisely enough that everyone in the room agrees what it means | Structure |
| cl.6.4.3 Risk analysis | Each barrier is assigned an owner and classified by type before it counts as identified | Barrier quality |
| cl.6.4.3 Risk analysis | Barrier effectiveness is rated, and critical barriers — the ones that alone stand between threat and top event — are flagged | Barrier quality |
| cl.6.4.3 Risk analysis | Barriers are verified to actually exist on site rather than assumed from the process design | Reality check |
| cl.6.4.3 Risk analysis | Single barrier reliance and common cause failure across barriers are explicitly tested for | Reality check |
| cl.6.4.4 Risk evaluation | Barrier coverage is judged adequate or not, and the count of barriers and critical barriers is recorded | Outcome |
| cl.6.6 Monitoring and review | A Barrier Health Review is scheduled with a due date before the record closes | Outcome |
What it does not cover
- Threats Identified On The Left marked Partly, which means the causal chain to the top event is incomplete and any barrier count built on it understates the real exposure.
- Each Barrier Has An Owner answered No for any barrier, which means that barrier will degrade unnoticed because nobody is accountable for checking it.
- Barriers Actually Exist On Site answered No or left unverified, which turns the diagram into an aspiration rather than a record of what actually stands between the site and the top event.
- Single Barrier Reliance Identified answered No when only one preventive barrier separates a threat from the top event, which hides the site's real dependence on that one control.
- Barrier Health Review Scheduled left as No, which means the analysis will sit unverified indefinitely and nobody will know when a barrier has quietly failed.
Global
Bow Tie Analysis Record requirements by country
Bow tie analysis is a method, not a legal requirement, but three regimes shape how rigorously it gets treated and who gets to see the result.
COMAH Regulations 2015
Top-tier COMAH sites must produce a safety report demonstrating major-accident hazards are identified and controlled, and bow tie diagrams are the method regulators most commonly expect behind that demonstration.
A bow tie built for a COMAH-scoped hazard should be defensible to an HSE inspector, not just the internal facilitation team.
Seveso III Directive (2012/18/EU)
Establishes the same major-accident hazard control obligations as COMAH across EU member states, expecting a documented barrier-based analysis for the substances and quantities it covers.
Sites operating across UK and EU jurisdictions should keep the bow tie structure consistent so one record satisfies both regimes.
OSHA Process Safety Management, 29 CFR 1910.119
Requires a process hazard analysis for highly hazardous chemicals; bow tie is one accepted methodology alongside HAZOP and What-If, where the hazard and quantity thresholds are met.
US sites should confirm the hazard clears PSM's chemical thresholds before treating a bow tie as the compliance artefact.
How to complete it
How to complete a bow tie analysis record, step by step
The fields are quick to tick through. The defensibility of the record rests on four judgement calls the facilitator has to make honestly, not on how many boxes got filled in.
The header's Info field is blunt: bow tie is expensive and slow, reserved for ammonia release, fire, major food safety failure and structural collapse. Running it on a lesser hazard doesn't control that hazard better — it burns the method's credibility for the hazards that genuinely need it.
A gas detector and the shutdown it triggers are not two barriers if the shutdown has no other trigger path. The facilitator must trace each barrier to what actually makes it work before Common Cause Failures Considered can honestly be marked Yes.
Barriers Verified Not Assumed gets rubber-stamped Yes because everyone remembers installing the barrier years ago. The call is whether anyone has actually looked at it since, not whether anyone remembers it existing.
Escalation Factors Identified asks what conditions cause a barrier to fail — a bypass during maintenance, a sensor blinded by buildup. A bow tie without escalation factors looks complete but hasn't interrogated how barriers actually break.
What auditors find
Most common bow tie analysis record findings
The same handful of gaps show up across facilitated bow ties, almost always because the workshop ran out of time before the harder questions.
| Finding | Clause | What fixes it |
|---|---|---|
| Barriers listed without an owner | cl.6.4.3 | Assign a named owner to every barrier before Complete — an unowned barrier is a line on a diagram, not a control. |
| Barriers never verified against the actual site | cl.6.4.3 | Walk the barriers against the physical plant, and mark Barriers Actually Exist On Site from that walk-down, not the design drawing. |
| Single barrier reliance not flagged despite only one preventive control | cl.6.4.3 | Count preventive barriers per threat; where the count is one, mark Single Barrier Reliance Identified Yes and route it to the Critical Control Register. |
| No Barrier Health Review scheduled at close-out | cl.6.6 | Set Next Review Due before sign-off — a bow tie with no scheduled review has no mechanism for catching degradation. |
| Human barriers rated equal in weight to engineered barriers | cl.6.4.3 | Rate human barriers lower in Barrier Effectiveness Rated unless independently verified, since they fail more often and more quietly. |
| Critical barriers not distinguished from the general list | cl.6.4.4 | Flag which barriers are critical so the Barrier Health Review knows where to concentrate verification effort. |
Case in point
Case in point: the shared alarm that looked like three barriers
A food manufacturing site ran a bow tie for major food safety failure and listed three preventive barriers between a refrigeration fault and product contamination: a temperature sensor, an automated alarm, and a supervisor response procedure. All three depended on the same sensor feed — if it failed to register the fault, the alarm never fired and the supervisor never knew to respond.
The Reality Check section's Common Cause Failures Considered question caught it at the next facilitation cycle. The fix was a second, independently powered temperature check with its own sensor, plus a manual spot-check that didn't depend on any sensor — three fragile layers became two that could fail independently.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-029
- Archetype
- Assessment
- Record ID
- BOW-2026-000
- Scoring
- Barrier health
- Direction
- High is good
- Singleton
- Yes
- Basis
- ISO 31000 cl.6.4
- Links
- Links Critical controls, Enterprise risk
- Tags
- Governance, Bow tie
- Sections
- 5
- Fields
- 45
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
13 fieldsAnalysis ID*
Auto sequence. Format BOW-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Top Event*
Hazard Category*
Facilitator*
Participants*
Operators Involved*
- Yes3 pts
- No0 pts
Specialist Input*
- Yes3 pts
- No1 pt
Only For The Few Things That Could Close The Site
Bow tie analysis is expensive and slow. Use it on ammonia release, fire, major food safety failure and structural collapse, not on everything.
Structure
6 fieldsTop Event Correctly Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Threats Identified On The Left*
- Yes3 pts
- Partly1 pt
- No0 pts
Consequences Identified On The Right*
- Yes3 pts
- Partly1 pt
- No0 pts
Preventive Barriers Named*
- Yes3 pts
- Partly1 pt
- No0 pts
Mitigating Barriers Named*
- Yes3 pts
- Partly1 pt
- No0 pts
Escalation Factors Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Barrier quality
6 fieldsEach Barrier Has An Owner*
- Yes3 pts
- Partly1 pt
- No0 pts
Barrier Type Classified*
- Yes3 pts
- Partly1 pt
- No0 pts
Barrier Effectiveness Rated*
- Yes3 pts
- Partly1 pt
- No0 pts
Critical Barriers Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Degradation Controls Named*
- Yes3 pts
- Partly1 pt
- No0 pts
Verification Activity Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Reality check
6 fieldsBarriers Actually Exist On Site*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Barriers Verified Not Assumed*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Single Barrier Reliance Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Common Cause Failures Considered*
- Yes3 pts
- Partly1 pt
- No0 pts
Human Barriers Not Over Relied On*
- Yes3 pts
- Partly1 pt
- No0 pts
Linked To Critical Control Verification*
- Yes3 pts
- Partly1 pt
- No0 pts
Outcome
14 fieldsBarriers Identified*
Critical Barriers*
Adequate Barrier Coverage*
- Yes3 pts
- Partly1 pt
- No0 pts
Barrier Health Review Scheduled*
- Yes3 pts
- No0 pts
Review ID
Links to CMP-030 Review ID
Next Review Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Facilitator*
Signature*
Site Manager*
Second Signature*
CMP-029 · record IDs look like BOW-2026-000 · Links Critical controls, Enterprise risk
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The workshop produces the diagram. Keeping the barriers verified, the review scheduled, and the critical controls linked back to this record is the work that quietly stops happening once the facilitator moves on to the next hazard.
Holds the bow tie library against the Critical Control Register and the Barrier Health Review schedule, and flags any named hazard whose review date has slipped.
Surfaces near-misses and incidents tagged to the same hazard category so a bow tie's threats and escalation factors get updated from real events, not just the original workshop.
Links barrier maintenance and calibration schedules to the barriers named here, so a missed maintenance task shows up against the specific barrier it degrades.

Coordinates facilitator, barrier owners and site management across the analysis and its downstream review, and holds every write for approval before it touches the record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Bow Tie Analysis Record definitions and key terms
- Top event
- The single point at the centre of the bow tie where loss of control becomes real — the release, the fire, the collapse — not the ultimate consequence.
- Preventive barrier
- A control sitting between a threat and the top event, stopping the threat from developing into loss of control.
- Mitigating barrier
- A control sitting between the top event and a consequence, limiting how bad the outcome gets once control is already lost.
- Escalation factor
- A condition that defeats a barrier — a bypass, a blocked sensor, a skipped step — recorded so the barrier's real-world weakness isn't hidden.
- Common cause failure
- When two or more barriers that look independent actually share a single underlying weakness, so one failure removes them all at once.
FAQ
Frequently asked questions about bow tie analysis record
How many bow ties should a site have?+
One per named fatal-risk hazard, not one per incident or area. Most sites end up with a handful — ammonia release, fire, structural collapse, and whatever else clears the fatal-risk bar.
Who should be in the room for the facilitation?+
The people who actually run the process, plus specialist input where the hazard needs it. A bow tie built by compliance staff alone without operator input will miss real-world escalation factors.
What happens after the bow tie is signed off?+
It feeds the Critical Control Register directly, and schedules a Barrier Health Review to verify the barriers named in it are still in place. Sign-off with no downstream review is only half the job.
Can a bow tie replace a Job Safety Analysis for a hazardous task?+
No. A bow tie analyses a site-level major hazard scenario; a Job Safety Analysis breaks a specific task into steps. They operate at different levels and don't substitute for each other.
What does it mean if Adequate Barrier Coverage is marked No?+
It means the facilitator judged the identified barriers don't sufficiently control the top event. That should trigger an action to add or strengthen barriers, not a note carried forward unaddressed.
Why does the record ask for a numeric count of barriers?+
The counts make barrier density visible at a glance — a top event with two barriers looks very different from one with eight, which matters when prioritising verification effort.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Critical Control and Fatal Risk
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working
Critical Control Register
Lists the controls that stand between your people and a fatal or catastrophic event, with an owner and a required check frequency for each
Risk Assessment
The single risk assessment used across the whole business
Serious Potential Incident Report
Used when an event could have killed or seriously injured someone, whatever the actual outcome
Job Safety Analysis
Breaks a job into steps, finds the hazards in each and sets the controls
Pre-Task Risk Assessment
A short check done by the crew right before work starts, covering what has changed today
More in Risk Governance
Enterprise Risk Register
Holds the risks that could stop the organisation meeting its objectives, above the level of individual task risk
Risk Appetite Statement
States how much risk the organisation is prepared to accept in each domain, so decisions are consistent
Risk Acceptance Record
Records a deliberate decision to accept a risk rather than treat it, with who accepted it and for how long
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 31000:2018 cl.6.4 — Risk assessment
- COMAH Regulations 2015 (SI 2015/483)
- Seveso III Directive 2012/18/EU
- OSHA Process Safety Management, 29 CFR 1910.119
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.