ALARP
ALARP means a risk has been reduced as low as reasonably practicable: further reduction would require sacrifice grossly disproportionate to the benefit gained. Demonstrating ALARP means showing your controls, not just your risk matrix.
Plain-language definitions of the vocabulary used in bowtie analysis, barrier management, and critical control management — the way practitioners and auditors actually use it.
The product writes barriers as controls and the top event as the risk; each entry notes both names where they differ.
ALARP means a risk has been reduced as low as reasonably practicable: further reduction would require sacrifice grossly disproportionate to the benefit gained. Demonstrating ALARP means showing your controls, not just your risk matrix.
Barrier effectiveness is a judgement of how reliably a barrier performs its function in current operational reality — not as designed, but as found. Ratings like high, medium, or low must be defensible to an auditor.
A barrier — also called a control — is a measure that either prevents a top event or limits its consequences. Barriers sit on the threat and consequence lines of a bowtie diagram and are the things audits actually test.
Bowtie analysis is a structured risk assessment method that maps one top event's threats, consequences, and the barriers controlling both onto a single bowtie-shaped diagram, making the control picture visible and auditable.
A bowtie diagram is a risk visualisation that places a single top event at its centre, threats and preventive barriers on the left, and consequences and recovery barriers on the right — showing how a hazard is controlled on one page.
A consequence is a distinct harmful outcome that can follow the top event — the right-hand lines of a bowtie diagram. Each consequence carries the recovery barriers that limit how bad the outcome gets.
Critical control management is the ICMM-championed practice of identifying the controls that matter most for material unwanted events, defining their required performance, verifying them in the field, and acting when they fall short.
A critical control is a control that is crucial to preventing a material unwanted event or mitigating its consequences — one whose absence or failure would significantly increase the risk despite other controls being in place.
A degradation factor — also called an escalation factor — is a condition that defeats or weakens a barrier: the corroded relief line, the alarm nobody responds to, the procedure nobody follows. Each one needs its own degradation control.
Fault tree analysis works backward from one undesired top event through AND/OR logic gates to basic causes, supporting quantification. It shares its top event with the bowtie's left side but trades readability for logic rigour.
FMEA systematically lists each component's failure modes, their effects, and their causes, ranking them for action — bottom-up and component-centred, where a bowtie is top-down and event-centred.
A HAZOP is a systematic, guideword-driven review of a process design that finds deviations (no flow, more pressure, reverse flow) and their causes and consequences. Bowties pick up where HAZOPs leave off: managing the controls.
LOPA is a semi-quantitative method that checks whether enough independent protection layers stand between an initiating event and a consequence, crediting each layer with an order-of-magnitude risk reduction.
A performance standard defines what a control must achieve and how that is verified: its objective, measurable criteria, verification activities in the system and the field, and the trigger for acting when performance falls short.
SFAIRP is the Australian WHS duty: eliminate or minimise risks so far as is reasonably practicable, weighing likelihood, degree of harm, knowledge, availability of controls, and — last — cost. It is demonstrated through controls.
James Reason's Swiss cheese model pictures defences as slices with holes — accidents happen when holes line up. The bowtie is its practical descendant: slices become barriers, holes become degradation factors.
A threat is a credible cause with the potential to release a hazard and bring about the top event — the left-hand entry lines of a bowtie diagram. Each threat carries its own set of preventive barriers.
The top event is the moment control of a hazard is lost — the central point of a bowtie diagram, after prevention has failed but before the consequences have played out. Example: loss of containment of flammable hydrocarbon.
Six worked bowtie examples ship with the product — open one read-only, no sign-in, and read every control in full.