Authoring tools for serious risk work.
Bowtie Risk Engine is built around the workflow engineers actually use in workshops, audits, and safety cases — and around the register that has to stand up afterwards.
Precision editor
Built for the way real diagrams grow — dense, linked, and revised many times — and for keeping a large bowtie coherent as it does.
- Linked controls — model a control once and reuse it on every threat or consequence it guards; edit it in one place and every instance updates in step.
- Duplication — clone a control as a one-off or as a linked copy that stays in sync, so repeating a control across threats never means re-keying it.
- Control library — save the controls you trust and drop them into any diagram, keeping wording, ownership, and control sets consistent across studies and across the team.
- Direct manipulation — drag to reorder arms and move controls between threats and consequences with the layout re-flowing live, and set criticality, control effectiveness, and owner inline.
The model, in full
Threats & consequences
Each risk carries multiple threat arms on the left and consequence arms on the right. Reorder freely; every arm is independent, with its own name, description, and ownership.
Preventive & recovery controls
Controls are first-class objects, not labels on a line. Annotate control type, owner, criticality, and assessed control effectiveness, and distinguish preventive from recovery at a glance.
Degradation factors
Capture the conditions that defeat or degrade a control — sometimes called escalation factors — and the secondary control that defends against them: the honest part of a bowtie, and the part audits probe.
Linked controls
Reuse a control across multiple threats or consequences and see its linkage surfaced in the register, so shared single points of failure don't hide in plain sight.
The control register
Every diagram produces a structured control register: preventive and mitigative sections grouped by threat and consequence — each control with its criticality, assessed control effectiveness, owner, and degradation factors.
It exports to a clean, multi-page PDF suitable for design reviews, safety cases, and procurement packs — generated from the diagram, never re-keyed.
Preventive controls · Mitigative controls · Degradation factors · Performance standards — paginated and print-ready.
| Control | Criticality | Control Effectiveness |
|---|---|---|
| Cavitation / NPSH starvation · 3 controls | ||
| Low-suction-pressure tripHardwired trip at the calculated NPSH-required margin. | Critical | Adequate |
| Hydraulic system design marginNPSH-available > 1.3 × NPSH-required at duty. | Non-critical | Adequate |
| Anti-vortex baffles in suction vesselsVortex breakers and adequate liquid level. | Non-critical | Deficient |
| Unplanned production outage · mitigative | ||
| Installed standby pump (auto-start)Auto-starts on low discharge pressure. | Critical | Adequate |
Performance standards, on the control
For the controls that matter most, author a performance standard: the control's objective, the criteria it must meet, the activities and systems that support it, and how each criterion is verified — at the system level and in the field.
Standards live on the control, not in a separate document. Linked instances share one standard, and it exports as an annex of the register PDF, critical controls first — so the bowtie, the register, and the standard can never disagree.
Objective · Criteria & verification · Degradation factors · Target performance · Triggers — searchable, and filterable by criticality.
Detect developing bearing and rotor faults early enough to plan intervention before functional failure.
Sensor drift or channel failure — managed by scheduled calibration and channel-fault alarms.
Monitoring available whenever the pump runs; every alarm answered and dispositioned.
Sustained zone-C reading — control review. Zone D — controlled shutdown.
| Control | Criticality | Linked frequency | ||
|---|---|---|---|---|
| Cause | Cons. | Total | ||
| Continuous vibration monitoring (online) | Critical | 4 | – | 4 |
| Protective trips (over-current / over-temperature) | Critical | 1 | 2 | 3 |
| Installed standby pump (auto-start) | Critical | – | 2 | 2 |
| Low-suction-pressure trip | Critical | 1 | – | 1 |
| Lubrication management programme | Non-critical | 1 | – | 1 |
The controls that carry the system
The control summary ranks every control by how many threats and consequences it stands between, on the cause side and the consequence side. The handful that recur most are the load-bearing controls — the ones the whole system leans on.
Here a single control — continuous vibration monitoring — sits between four separate threats and the risk. That makes it both your strongest line of defence and your most concentrated single point of failure: precisely the prioritisation a flat list of controls can't show you.
Exports, and where it runs
Export anywhere
PNG for slides. SVG for high-resolution prints and embedding. JSON for version control and diffing revisions. PDF for the register.
Web & desktop
Run in the browser under your licensed account, or install the native desktop edition for macOS, Windows, and Linux — same model, same files, fully offline.
Licensed & accountable
The editor requires sign-in with a licensed account, so work is tied to a named user and your data stays in your workspace.
Walk through it with us.
Explore the read-only preview now, or book a short demonstration of the editor and the register on a scenario from your domain.