Knowledge / Risk analysis methods
Protective-action side effects in bow-ties: reducing one hazard while worsening another
Follow a successful isolation action into a second hazard, preserve residual-energy and utility states, and quantify a bounded example without changing operating instructions.
On this page
A protective action can perform its specified function and still leave another system in a hazardous state. A bow-tie that ends every successful barrier path at “safe” may conceal that interaction. This original electrical-isolation example separates failure of the first protective action from a thermal hazard created when that same action succeeds.
Define success relative to the first function
Consider a fictional electrical feeder serving a powered equipment package and its normal after-run cooling. A genuine electrical fault creates a demand to isolate the feeder. Success means that the specified feeder is de-energized and the modeled electrical fault progression is stopped. It does not mean that every stored-energy source has disappeared or that every dependent consumer remains supported.
Evaluate named equipment-damage endpoints during an illustrative 20 min mission. The numerical example describes no real plant, protective setting or intervention sequence. Its purpose is to test the completeness of a function definition. A protective action’s verified success criterion and the overall acceptable state of the wider process are related but different engineering questions.
Follow the successful action into the next hazard
When feeder isolation succeeds, normal cooling powered by that feeder is lost as a direct consequence of the intended action. If the package has significant residual heat, cooling loss can challenge its thermal state. The relevant hazard is stored thermal energy; the secondary top event is loss of adequate residual-heat management. The resulting equipment damage is a later consequence, not the definition of isolation failure.
HSE’s control-systems guidance notes that maintaining a safe state can require continued active services, including cooling. In this example a separately defined thermal-support function addresses that post-isolation state. Its source, capacity and mission must be evaluated in the configuration that actually exists after isolation, rather than assumed from normal-operation availability.
Distinguish side effects from degradation and false demands
A degraded isolation barrier might fail to open, act too slowly or leave an unintended energized path. Here the side-effect branch begins only after successful performance of the first function. Relabelling the cooling loss as degradation of that first barrier would blur the causal distinction and could encourage a misleading “repair” of an action that worked exactly as specified.
A spurious trip is another different case: the action occurs without the initiating condition that justified the demand. This example contains genuine faults only and calculates no nuisance-trip downtime. The analysis asks what a justified successful action does to connected services and residual energy. False demands could require a separate operating-state model; their likelihood is not silently added to this one.
State the conditional numerical assumptions
For this original model, let isolation succeed with probability 0.96 conditional on the genuine fault. If it fails, let the primary electrical-damage probability be 0.50. Conditional on successful isolation, the package is in the heat-relevant state with probability 0.30. Given both success and that hot state, thermal support fails with probability 0.25 and the named secondary damage occurs.
These factors are conditional inputs, not generic barrier credits or measured equipment performance. In particular, the hot-state proportion belongs to demands with successful isolation, and the support-failure probability belongs to the post-isolation hot state. The branch products use the probability chain rule; they do not require unconditional independence between fault severity, operating state and protective performance.
Enumerate mutually exclusive terminal outcomes
The primary-damage branch has mass 0.04 × 0.50 = 0.020. Successful isolation followed by a hot state and failed thermal support has mass 0.96 × 0.30 × 0.25 = 0.072. Keep the other branches as well so that the model cannot silently lose successful or non-damaging outcomes.
| Original terminal path | Conditional product | Probability |
|---|---|---|
| Isolation fails; primary damage | 0.04 × 0.50 | 0.020 |
| Isolation fails; no named damage | 0.04 × 0.50 | 0.020 |
| Isolation succeeds; not hot | 0.96 × 0.70 | 0.672 |
| Succeeds; hot; thermal support succeeds | 0.96 × 0.30 × 0.75 | 0.216 |
| Succeeds; hot; thermal support fails | 0.96 × 0.30 × 0.25 | 0.072 |
The five terminal masses sum to 1. Primary and secondary damage are disjoint by this toy construction, so any named damage has probability 0.020 + 0.072 = 0.092. No named damage has probability 0.908. In a fuller model, electrical and thermal damage might overlap or develop after failed isolation too; those pathways would need explicit states before any union is calculated.
Keep functional success distinct from a harmless outcome
The isolation function succeeds on 0.96 of the modeled demands, yet 0.072 of all demands end in secondary thermal damage on that success branch. A summary that assigns every successful isolation to a harmless endpoint would retain only the primary-damage probability 0.020. That is a model omission, not an arithmetic disagreement about the first function’s success probability.
CAA’s bow-tie guidance explains that control relationships and dependencies matter beyond the number of boxes. Two boxes labelled isolation and cooling support do not establish compatible operation. The model must show whether the second service survives the first action, whether it is demanded in that state, and which conditions determine its performance after the action.
Attach frequencies only after defining the pathways
Stipulate a genuine-fault frequency of 0.02 per operating year for the same equipment and exposure basis. Primary-damage frequency is 0.0004 per operating year. Secondary-damage frequency is 0.00144 per operating year. Their disjoint union is 0.00184 per operating year. These figures apply only to the specified initiating family and mission endpoints.
They are event frequencies, not annual probabilities of at least one occurrence, and they do not value the consequences. An electrical-damage event and a thermal-damage event can have different severities even though both count once in this narrow union. Retain the separate endpoint frequencies when judging a proposed change; a single count cannot establish that one hazard compensates acceptably for another.
Evaluate a compatible-state alternative without weakening protection
For a bounded comparison, hold the isolation, hot-state and initiator assumptions fixed but stipulate thermal-support failure of 0.05 in the same post-isolation hot state. Secondary damage becomes 0.96 × 0.30 × 0.05 = 0.0144. Any named damage becomes 0.0344, with frequency 0.000688 per operating year. These are conditional results for a proposed model, not proof that an available device achieves them.
The evidence question is whether the complete residual-heat function can deliver that performance after the intended isolation action, including its own supports and exposure. This comparison provides no reason to delay, bypass or weaken the original protection. Any real change requires an integrated engineering assessment of both hazard pathways and the applicable authorization and verification process.
Review new risks and all relevant operating states
HSE’s good-control-practice discussion warns that introducing controls can create other risks. For this case, identify the pre-action energy state, the utilities removed, the remaining heat-removal paths and the endpoint horizon. Check whether normal operation, recent shutdown and maintenance produce different residual-energy populations before combining them into one averaged hot-state proportion.
A thermal-support arrangement can itself introduce dependencies through a shared supply, common control, unavailable access or required human action. Its successful performance may create yet another consequence pathway, such as a different release destination, which would need its own review. The aim is to trace credible physical effects at each interface, not to assume that adding one more barrier closes every possible route.
Record the two-function argument so it can be checked
A useful record names the initiating fault, the first action’s success criterion, the exact post-action utility state, the residual-energy condition, the second function and the terminal outcomes. Assign responsibility for verifying each interface. A test that proves the feeder opened is valuable evidence for isolation, but does not by itself establish continued management of stored thermal energy.
This example’s central result is the explicit successful-action branch that a one-hazard summary could omit. The numbers remain hypothetical and the pathway scope remains bounded. The practical analytical conclusion is to define success locally, then check the wider state it creates. A protective action earns its place in the overall safety argument through compatible functions and verified interfaces, not a universal “safe” label.