Visualise hazards, threats, preventive barriers, consequences and mitigating controls in one structured risk assessment.
Barrier and hazard risk management goes beyond listing hazards and controls. It shows exactly which threat or consequence each barrier interrupts, and how much confidence you should place in that protection.
The approach separates the pathway into causes, the central risk event and consequences. Controls are then positioned where they act. That makes it easier to see a pathway with no protection, a pathway that relies on only one control, or several controls that can fail for the same reason.
If you are new to the diagram itself, start with our plain-English guide to bowtie diagrams. This page focuses on the barriers and control-management decisions behind the visual.
A useful barrier has a defined role in interrupting a specific risk pathway. Listing documents, intentions or overlapping controls can make protection look stronger than it really is.
A barrier should prevent the risk event or limit a consequence through an identifiable function. For example, a policy may support a control system, but the actual barrier may be an interlock, a physical separation, an authorised operator action or an emergency shutdown that interrupts the pathway.
Sit between a cause and the risk event. Their purpose is to stop the event from occurring. Each cause pathway may require different controls.
Sit between the event and a consequence. They assume the event has occurred and reduce the severity, spread or duration of what follows.
Conditions that can weaken a barrier, such as fatigue, a bypassed interlock, loss of power, poor maintenance or production pressure. They are not the same as the cause of the event.
Multiple controls may not provide multiple layers of protection if they depend on the same sensor, power supply, procedure or person. Visual mapping makes common-mode weakness easier to challenge.
Not every control deserves the same level of attention. Barrier management becomes more useful when the controls that are essential to major risk pathways are identified and actively assured.
Identify barriers whose failure would materially increase exposure to a significant event or consequence.
Record whether a barrier is working as intended using your organisation's own effectiveness or condition classification.
Capture escalation factors and supporting controls so degraded protection is visible rather than hidden in notes or separate spreadsheets.
Use supporting information, ownership and review processes to demonstrate that important controls are not merely documented but remain available and effective.
Barrier management is often associated with major-hazard safety, but the core question is broader: what prevents the event, and what limits the outcome if prevention fails?
Guarding, isolation, containment, detection, shutdown, emergency response and other controls can be mapped to the pathways they protect.
Access controls, MFA, segmentation, detection, backups and recovery controls can be separated into preventive and mitigative functions around a cyber event.
Maintenance, redundancy, quality checks, supplier controls and continuity arrangements can be linked to specific operational failure pathways.
Containment, monitoring, isolation, spill response and recovery controls can be mapped around releases and other environmental events.
BowTie Risk keeps the visual pathway readable while allowing supporting information to sit one level below each control.
State the event precisely enough that its causes and consequences can be distinguished.
Connect each cause to the event and each consequence to the event, then place the barriers that genuinely act on that pathway.
Record supporting notes, effectiveness, escalation factors and other metadata so the existence of a control is not mistaken for assurance that it works.
Use the visual model to identify weakly defended pathways and communicate the critical controls to operational, audit and governance audiences.
It is a control-focused way of analysing risk pathways. Preventive barriers act before the event, mitigating barriers act after it, and the quality of those controls is considered alongside the causes and consequences they protect.
A preventive barrier aims to stop the event from occurring. A mitigation barrier assumes the event has occurred and aims to reduce the resulting consequence.
Criticality depends on the risk and the organisation's criteria. In general, a control is more likely to be treated as critical where its failure would materially increase exposure to a serious event or consequence.
No. Barrier management is broader. Bowtie analysis is a particularly useful visual technique for showing causes, barriers, the event, consequences and mitigations on one page.
Yes. Supporting data can be recorded against controls so you can retain your own effectiveness, degradation, criticality or performance terminology.
Build clear barrier-based risk assessments on Mac, iPad and iPhone.