Knowledge / Risk and reliability
Bow-tie analysis: from barrier diagrams to performance criteria
Define bow-tie barriers through functions, response margins, dependencies, performance criteria and evidence of availability.
On this page
A bow-tie can put an accident pathway on one page, but its value depends on what lies behind each box. A barrier label should lead to a defined function, an accountable owner and evidence that the function is available when needed. Otherwise a reassuring diagram may conceal an unprotected pathway. This article develops a hypothetical shipboard liquid-transfer example and an original barrier-assurance exercise. It is an educational guide, not an approved transfer plan or a statement that a particular vessel meets its obligations.
Choose one loss-of-control event
The hazard is a source of potential harm; the top event is the point where control over it is lost. In the hypothetical example, the hazard is liquid inventory being transferred into a receiving tank. The top event is loss of containment by overfilling that tank. A fire, a slip injury and pollution are possible consequences, not alternative names for the top event. “Unsafe transfer” is too broad to place controls reliably.
The UK CAA’s bow-tie explanation distinguishes threats, the top event, consequences and controls on either side. Its guidance comes from aviation, but the graphical logic can be used to reason about a maritime example. It does not establish marine approval criteria. Define precisely whether a spill inside secondary containment already counts as the top event; moving that boundary midway through the study moves barriers from one side to the other.
Make threats specific enough to test
A threat is a cause that can lead to the top event. “Equipment failure” leaves too much unexplained. More useful entries might be a level indication that understates the actual inventory, continued inflow after the intended stopping point, or a transfer directed into the wrong receiving tank. These pathways call for different evidence. One concerns measurement integrity, another timely interruption, and another configuration control.
Avoid a single chain that assumes every threat occurs in sequence. The wrong tank might overfill even while its indicator works correctly, because the operator is watching a different display. A control that helps on one threat path may not help on another. Ask which physical or organizational mechanism connects each threat to the top event. If the connection depends on several intermediate events or timing conditions, record those outside the simplified picture so that the diagram does not become a substitute for reasoning.
Describe barriers as actions or functions
“Alarm,” “procedure” and “training” are resources, not complete descriptions of successful protection. “Detect approaching high level and achieve cessation of inflow before the available margin is consumed” describes a function. It can then be decomposed into measurement, annunciation, diagnosis, communication and final action. A failed link may defeat the whole function even when the alarm itself passes an electrical test.
In the hypothetical diagram, one preventive barrier could be a verified pre-transfer receiving-capacity check. Another candidate is an independent high-level stop function, subject to detailed engineering justification. On the consequence side, containment and emergency response might limit the extent or duration of a spill. Their placement depends on the chosen top-event definition. Do not count equipment three times merely because it appears under several labels; the same valve may be a shared final element for multiple functions.
Define performance before choosing an indicator
A barrier performance statement should answer what it must accomplish, under what conditions and how success is recognized. For a containment feature, relevant properties could include effective capacity, drainage status and resistance to the identified liquid. For a stop function, response time and actual interruption matter. “Inspected monthly” is an activity frequency; it does not state the required condition of the barrier after inspection.
Suppose the example requires the transfer to cease within an analytically justified response window. The assurance record needs the demand signal, final flow response and relevant system configuration. A completed maintenance task that tested only a display cannot establish end-to-end cessation. Performance requirements should also identify survivability under the initiating event. If a common power loss causes the threat and disables the protective action, a successful test with normal power does not address that pathway.
Test the available response margin
Assume a hypothetical tank has 4.0 m³ of usable headroom between the detection point and the defined overflow condition. At a constant inflow of 0.20 m³/s, the ideal time margin is 4.0/0.20 = 20 seconds. Assume detection and transmission take 3 seconds, decision and communication take 8 seconds, and final flow cessation takes 6 seconds. The nominal total is 17 seconds, leaving only 3 seconds of calculated margin.
These invented values are not design recommendations. The calculation assumes known headroom, constant flow and no additional draining of transfer piping into the tank. Measurement error, higher flow, delayed communication or final isolation taking longer than the assumed six seconds may remove the apparent margin. The analytical output is a list of conditions requiring evidence and a sensitivity test, not permission to operate with three seconds spare. If response cannot be shown adequate, reconsider the function and operating envelope through the authorized engineering process.
Separate barrier degradation from accident threats
An escalation factor explains how a barrier can become less effective. In this example, obscured indications, an overdue functional test, an unauthorized bypass or a containment drain incorrectly left open can degrade specific barriers. An escalation-factor control addresses that degradation. A bypass register, for example, is meaningful only if it supports authorization, visibility, time limits and verified restoration; the existence of a spreadsheet alone does not prevent a bypass from remaining active.
Be precise about where a factor acts. A failed level measurement might initiate one pathway and also defeat an alarm based on that measurement. In that case it is not merely a housekeeping issue attached to the alarm box. Show the dependency explicitly. The CAA development guidance points readers toward evaluation of effectiveness, ownership and control characteristics. These attributes are useful prompts, but their local definitions and evidence still have to be supplied.
Do not infer independence from separate boxes
Two controls may share a sensor, power source, communication link, final valve or person. A pre-transfer check and a later alarm response can share the same mistaken tank identity. Separate signatures do not necessarily create independent verification if both people use the same incorrect drawing. The diagram should identify these shared dependencies or link to a supporting register that does.
Bow-ties are often qualitative communication models. Multiplying imagined failure probabilities for every box can produce a numerical answer with no valid probability model underneath. The CAA’s CAP1329 strategy paper explicitly discusses limitations of bow-tie modelling, including the absence of a quantitative acceptability assessment from the diagram alone. A quantitative extension requires defined events, dependencies, data and treatment of uncertainty. Barrier count is not a risk metric, and a symmetrical picture is not proof of balanced protection.
Use leading measures that refer to a function
A leading measure should indicate whether a needed barrier is becoming unavailable or ineffective. For the example, useful questions include whether a required end-to-end demonstration is overdue, whether a bypass remains active beyond its authorization, or whether configuration discrepancies remain unresolved. Record both the count and the exposure context. One impaired barrier during a single transfer can matter more than several minor defects found while equipment is isolated.
A lagging measure records an outcome such as a demand, failed test, near miss or actual spill. These records should update the pathway, not just a dashboard. Zero spills over a short period does not prove strong barriers; the hazardous demand may not have occurred. Conversely, an increased count of reported small defects may reflect improved reporting rather than deteriorating equipment. Interpret indicators alongside exposure, detection coverage and changes in reporting practice.
Turn a barrier impairment into a decision
Suppose a scheduled test cannot demonstrate the stop function through the final element. The barrier status should be “not demonstrated” or another locally defined state, rather than automatically “available” because no defect was found. Determine which transfer scenarios rely on it, what restrictions follow from the approved procedures and who has authority to decide. This is a decision process, not a suggestion to improvise compensating actions from an educational article.
A temporary measure must address the same pathway and its own limitations. Adding another watchkeeper may not solve a response-time shortage or a shared incorrect indication. Record the proposed measure, the evidence for its effect, the duration, the review point and restoration requirements. If an impairment is accepted without updating the operating decision, the bow-tie has failed as a management tool even if its digital boxes remain green.
Keep the model alive through evidence and change
The useful deliverable combines the diagram with a barrier register. Each entry should identify its function, relevant pathways, owner, dependencies, performance requirements, assurance activity, current state and evidence location. Include the basis for accepting or rejecting candidate barriers. An independent reader should understand why “training” supports a human barrier without being counted as a separate physical interruption of the accident sequence.
Revisit the model when the transfer arrangement, tank designation, control logic, staffing or operating envelope changes. A near miss can reveal an omitted threat even when all existing barriers worked as designed. Review should therefore challenge the scenario structure as well as update test dates. For the hypothetical transfer, the decisive question is whether every material pathway has demonstrable protection with understood limitations. The diagram becomes useful when it makes that question easier to answer honestly.
Sources
- How does bowtie work · UK Civil Aviation Authority · Source check date: 2026-10-06
- Developing and evaluating a BowTie · UK Civil Aviation Authority · Source check date: 2026-10-06
- CAA Strategy for Bowtie Risk Models, CAP1329, May 2020 · UK Civil Aviation Authority · Source check date: 2026-10-06