Automation Glossary • Bowtie Analysis

What Is Bowtie Analysis?

Merobix Engineering • • 7 min read

Bowtie analysis is a visual method of understanding a major hazard by placing a single loss-of-control event at the center of a diagram and showing, on either side, what could cause it and what it could lead to. The threats that could trigger the event sit on the left with the prevention barriers that stop them, and the consequences that could follow sit on the right with the mitigation barriers that limit them. The resulting shape, narrowing to the central event and fanning out on both sides, gives the method its name and makes a complex hazard legible on a single page.

Back to Blog

Bowtie Analysis in one line: Bowtie analysis is a barrier-based hazard model with a hazard and top event at the center, threats on the left each blocked by prevention barriers, and consequences on the right each limited by mitigation barriers. It gives a clear picture of how a major hazard is controlled and is widely used for barrier management in high-hazard industries.

The Anatomy of a Bowtie

At the knot of the bowtie sit two things: the hazard and the top event. The hazard is the source of potential harm, something inherently dangerous that the facility handles, such as a large inventory of hydrocarbon under pressure. The top event is the moment control over that hazard is lost, most often expressed as loss of containment, the point at which the hazard is released and begins to cause harm. Everything else on the diagram is arranged around this central loss of control, which is what makes the top event the anchor of the whole analysis.

The left wing of the bowtie holds the threats: the credible causes that could bring about the top event. For a pressurized vessel these might include overpressure, corrosion, external impact, or overfilling. Between each threat and the top event stand the prevention barriers, the controls whose job is to stop that threat from ever reaching the loss of control, such as a relief valve against overpressure or an inspection regime against corrosion. Each threat has its own line of barriers, and the diagram makes explicit which controls are relied upon to keep the top event from happening.

The right wing holds the consequences: the outcomes that could follow if the top event does occur, such as fire, explosion, environmental damage, or harm to people. Between the top event and each consequence stand the mitigation barriers, the controls whose job is to reduce the severity once containment is already lost, such as gas detection and shutdown, firefighting systems, drainage, or emergency response. The full bowtie thus reads as a story: threats pushing toward a loss of control that prevention barriers resist, and if it happens, consequences spreading outward that mitigation barriers hold back.

Bowtie Compared With Fault-Tree Analysis

Bowtie and fault-tree analysis both examine how things go wrong, but they answer different questions and look very different. A fault tree is a detailed, logical, and often quantitative model of a single unwanted event: starting from that top event it works downward through AND and OR gates to the combinations of basic failures that could cause it, and it is well suited to calculating a probability. Its strength is depth on the causation side, dissecting exactly how one outcome can arise from many contributing failures.

A bowtie is broader and more communicative but less mathematically detailed. It spans both the cause side and the consequence side of a single top event in one picture, and it foregrounds the barriers rather than the fault logic. Where a fault tree drills down into the precise Boolean combinations behind an event, a bowtie stays at the level of threats, barriers, and consequences and is usually qualitative. The two are complementary: a fault tree can sit behind a single threat line of a bowtie to quantify how that threat reaches the top event, while the bowtie provides the overall map of prevention and mitigation that the fault tree does not attempt.

The practical consequence is that they serve different audiences and purposes. A fault tree is a specialist's quantitative tool for demonstrating that a specific event is sufficiently improbable. A bowtie is a barrier-management tool that a broad audience, from engineers to operators to management, can read to understand at a glance what stands between a hazard and harm and which barriers must therefore be kept healthy. Many organizations use both, reserving fault trees for the events that need numbers and using bowties to communicate and manage the barrier picture across the facility.

Mapping Barriers to SCADA Monitoring

The barriers on a bowtie are not abstractions; they are real equipment and systems, and a great many of them are visible to a SCADA system. Take a loss-of-containment top event on a pressurized separator. On the prevention side, the pressure transmitter and its high-high trip that closes an inlet valve is a barrier whose state, pressure reading, alarm status, valve position, is continuously reported to the control system. On the mitigation side, the gas detectors that would sense a release, the emergency shutdown that isolates the inventory, and the flare or blowdown that safely disposes of it are all instrumented and monitored. The bowtie names the barrier; the SCADA system shows whether it is present and working.

This is what makes a cloud SCADA platform like Merobix relevant to barrier management rather than only to production. A barrier is only protective if it is actually healthy, and a bypassed trip, an inhibited alarm, a stuck valve, or a detector out of service is a hole in the bowtie that the paper diagram cannot reveal. Continuous monitoring surfaces those states: an override left in place, an alarm that never clears, a valve that does not stroke to its commanded position. Being able to see the live condition of the very barriers a bowtie relies on turns the analysis from a one-time exercise into something that can be checked against reality every day.

The historian adds a time dimension that barrier management needs. It records when a barrier was impaired and for how long, so the accumulated exposure while a prevention barrier sat bypassed can be understood rather than guessed, and trends can show a barrier degrading, a relief path slowly fouling, a detector drifting, before it fails outright. Mapping the bowtie's barriers to the tags that monitor them, and watching those tags on a SCADA platform, is a concrete way to keep the barriers that stand between a top event and disaster demonstrably in service rather than merely assumed to be.

Frequently Asked Questions

What is the top event in a bowtie?

The top event is the central point of the bowtie, the moment control over the hazard is lost, most often expressed as loss of containment. It sits at the knot of the diagram between the threats and prevention barriers on the left and the consequences and mitigation barriers on the right. Everything on a bowtie is arranged around this loss of control, which anchors the whole analysis.

What is the difference between prevention and mitigation barriers?

Prevention barriers sit on the left of the bowtie between the threats and the top event, and their job is to stop a threat from ever causing the loss of control, such as a relief valve against overpressure. Mitigation barriers sit on the right between the top event and the consequences, and their job is to reduce the severity once containment is already lost, such as gas detection, shutdown, and firefighting.

How is a bowtie different from a fault tree?

A fault tree is a detailed, often quantitative model that works downward from a single event through logic gates to the failure combinations that cause it, giving depth on causation and a probability. A bowtie is a broader, usually qualitative picture spanning both causes and consequences of a top event and foregrounding the barriers. They are complementary: fault trees quantify specific threats, while bowties map and manage the overall barrier picture.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Safety Barrier  •  Escalation Factor  •  Process Hazard Analysis (PHA)  •  What-If Analysis  •  Risk Matrix  •  ALARP  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →