Bow-tie analysis places a defined top event in the centre, threats and preventive controls on the left, and consequences and recovery controls on the right. It is useful when teams need a shared view of how an event can occur and how harm can be limited.
Define the top event
The top event is the moment control is lost—not the initial cause and not the final consequence. A clear top event keeps the analysis focused and prevents the diagram from becoming a general process map.
Build the left side
List credible threats that could lead to the top event. For each threat, identify preventive controls and the conditions that could weaken those controls.
Build the right side
List distinct consequences that could follow the top event. Identify controls that detect, respond, contain, recover, or reduce impact.
Evaluate control quality
For each important control, identify an owner, performance standard, evidence, test frequency, dependencies, and escalation if the control is unavailable or ineffective.
When it helps
- Several causes and consequences
- Workshops needing a visual model
- Clarifying prevention versus recovery
- Identifying critical controls
- Communicating a risk concisely
Limitations
A bow tie simplifies reality. It may not show timing, feedback loops, simultaneous events, or dynamic system interactions. Use other methods where those factors are material.
Build the diagram around a clear top event
The centre of a bow tie is the moment control is lost, not the final harm. Causes or threats appear on the left, with preventive controls between each threat and the top event. Consequences appear on the right, with mitigative or recovery controls that limit the outcome after the event occurs.
Examine control degradation
Controls can fail because of missing maintenance, poor competence, unavailable information, workload, environmental conditions, conflicting incentives, or dependency on another system. Recording these escalation factors and the controls that protect against them makes the analysis more useful than a simple list of barriers.
Quality checks
- Is the top event specific and observable?
- Are threats distinct from consequences?
- Are controls concrete, owned, and verifiable?
- Are critical dependencies and common-mode failures visible?
- Does the analysis lead to assurance or treatment priorities?