Linked bow-tie models: from one event’s consequence to the next loss of control

Connect a leak, equipment loss and service loss through explicit interface states, preserving one shared barrier identity and consistent probability denominators.

On this page

A release can damage equipment, and damaged equipment can remove a service. Separate bow-ties make those stages readable, but a connector arrow can hide the state information that makes the next stage credible. This original leak-to-service model carries exposure, equipment state and a shared drainage function across the links before attaching any numbers.

Give each linked model one clear top event

Define T1 as loss of primary containment of a specified liquid near two control cabinets, A and B. Define T2 as loss of the specified function of at least one cabinet. Define T3 as delivered service below its required capacity for more than 10 min within a 60 min event mission. Each cabinet can support the full required duty when functioning under the stated conditions.

CAA’s top-event guidance supports manageable linked bow-ties for complex pathways. Here the liquid exposure created after T1 supplies a threat to the cabinet model, while the equipment-loss state after T2 supplies a threat to the service model. Neither connection means that the next top event is inevitable, and the first top event’s frequency is not reapplied at every link.

Write an interface-state contract

A source model should state what it hands to the next model, and the receiving model should identify which of those attributes its response depends on. A common word such as “release” is rarely enough. The same released quantity can produce different cabinet effects if it arrives at a different place, has a different duration or follows a different path.

InterfaceState carried forwardWhy retain it?
I12: leak → cabinetsLiquid/location; arrival and wetting duration; target set; D1 stateA release label alone does not determine equipment effects.
I23: cabinets → serviceA/B loss vector; remaining capacity; transfer state; elapsed mission timeAn equipment-loss label alone does not determine service loss.

The numerical example below groups those details into a small set of wetting and loss states. It assumes that each group is sufficiently homogeneous for the supplied conditional probabilities. The interface register still records the underlying conditions. If residual timing, conductivity, support state or access changes the next response, refine the groups rather than treating a convenient label as a complete physical description.

Give the shared drainage function one identity

Call the physical drainage function D1. It can appear in the release-spread discussion and in the cabinet-exposure discussion because it influences both descriptions of the same pathway. Use the same identifier, function definition, state and evidence record in both places. Two drawn copies represent one physical function, not two independent drains or two opportunities to earn numerical protection credit.

HSE’s control-systems guidance calls for explicit treatment of shared utilities, environments and dependencies. Here D1 has a stipulated functional probability of 0.8 conditional on the leak; its unavailable probability is 0.2. The function’s state is selected once for the modeled event and passed through the links. A later recovery or state change would need an explicit time-dependent extension.

Condition the exposure states on that one drainage state

When D1 is functional, stipulate wetting probabilities of 0.75 for no cabinet exposure, 0.25 for A-only exposure and zero for common A+B exposure. When D1 is unavailable, the corresponding probabilities are 0.10, 0.30 and 0.60. Both rows sum to unity. Functional drainage is not assumed to prevent every local splash or every cabinet exposure.

Weighting by D1’s state gives P(no wetting | L) = 0.8 × 0.75 + 0.2 × 0.10 = 0.62. A-only wetting has probability 0.26, and common wetting has probability 0.12. These three probabilities remain conditional on the leak L. They already include the single drainage-state mixture; no extra D1 failure factor belongs after them.

Propagate exposure into the joint equipment state

Assume no wetting causes no cabinet loss. With A-only wetting, A loses its function with probability 0.70 while B remains functional. With common wetting, stipulate joint loss probabilities of 0.10 for neither, 0.20 for A only, 0.20 for B only and 0.50 for both. This joint law is supplied directly and does not assume independent cabinet vulnerabilities.

A lostB lostProbability
000.710
100.206
010.024
110.060

For example, A-only loss is 0.26 × 0.70 + 0.12 × 0.20 = 0.206. The no-loss probability is 0.62 + 0.26 × 0.30 + 0.12 × 0.10 = 0.710. Any equipment loss has probability 0.29, and exactly one cabinet loss has probability 0.23. Preserve the complete loss vector rather than merging all three damaged states into one undifferentiated label.

Original linked model with T1 liquid leak, I12 exposure states 0.62 none, 0.26 A only and 0.12 common, T2 cabinet-function loss and I23 joint loss states 0.710 none, 0.206 A only, 0.024 B only and 0.060 both. T3 service loss has probability 0.083 given the leak and frequency 0.00332 per operating year at leak frequency 0.04. D1 is one shared drainage identity whose state is included once.
Original interface-state chain supporting linked bow-ties. All shown state probabilities, including the D1 mixture weights, are conditional on the same leak. The numerical model supplies joint states and conditional responses; qualitative diagrams are not multiplied and the shared drainage function is credited only once.

Resolve service loss from the surviving capacity

If both cabinets lose their functions, the service endpoint occurs. If exactly one is lost, the surviving cabinet has sufficient capacity, but the defined duty-transfer function fails with probability 0.10 conditional on that single-loss state. If neither is lost, the service is maintained in this toy family. These assumptions include the mission and duration criterion; they are not inferred from the diagram.

Consequently P(T3 | L) = 0.060 + (0.206 + 0.024) × 0.10 = 0.083. The single-loss states contribute only when transfer fails, while the both-lost state contributes directly. Calling all equipment loss service loss would instead use 0.29 and ignore surviving capacity. Calling every single loss harmless would omit the transfer requirement.

Attach the initiating frequency once

Let the leak-family frequency be an invented 0.04 per operating year for the same configuration and exposure basis. Multiplying it once by 0.083 gives a service-loss frequency of 0.00332 per operating year. The computation follows a coherent conditional state model from one leak family to one defined final endpoint; it does not multiply three qualitative bow-tie risk ratings.

The event mission limits the consequence calculation; it does not convert the operating-year frequency into a calendar-year probability. Other leak locations, faults unrelated to leakage and later recovery are outside the numerical family. The three linked models can be extended to those cases only with compatible new initiating populations, state transitions and endpoint definitions, avoiding overlap with the existing family.

Do not count D1 again in the receiving diagram

CAA’s recovery-control guidance cautions that drawn controls need not be sequential or independent. If the analyst multiplies the final 0.083 by another D1 unavailability factor of 0.2, the result becomes 0.0166 and the annual frequency 0.000664. That is wrong for this model: the upstream state mixture already includes D1, including local exposure while it is functional.

A useful cross-check calculates service loss separately for each D1 state. The functional-state result is 0.0175; the unavailable-state result is 0.345. Their mixture is 0.8 × 0.0175 + 0.2 × 0.345 = 0.083. This checks the linked calculation without treating either drawing of D1 as an additional probabilistic event.

Keep denominators and known states visible

The equipment table is conditional on L, not on reaching T2. If a receiving model is defined only for events with equipment loss, renormalize its input state masses by 0.29. Its conditional service-loss probability is then 0.083/0.29, approximately 0.286207. Multiplying 0.04 × 0.29 by that conditional value returns 0.00332 per operating year.

Using the unnormalized 0.083 after already multiplying by 0.29 would count the equipment-loss restriction twice. Likewise, if D1 is known unavailable for a particular assessed configuration, the conditional value 0.345 is relevant within this example; the population mixture is not. A design change that alters the mix of exposure states can invalidate an old averaged downstream response even when the connecting label stays the same.

Audit the links as part of the model

Check that each conditional state partition sums to unity, that every outgoing state has a receiving interpretation and that shared barriers retain one physical identity. Trace the event and parameter identifiers through all calculations. Review any feedback loop explicitly: if service loss changes drainage, the one-way model used here may be inadequate and the joint timing must be reconsidered.

The completed argument contains three defined top events, two interface contracts, one D1 identity and a reproducible endpoint calculation. The bow-ties communicate the causal structure; the separate state model supplies the arithmetic. Their connection is defensible only while the physical conditions, conditioning populations and barrier identities remain consistent from the initial leak to the final service loss.

Sources

  1. UK CAA — Bowtie elements: Define the Top Event.
  2. UK CAA — Bowtie elements: Identify Recovery Controls.
  3. HSE — Control systems.