Barrier (control)
A barrier — also called a control — is a measure that either prevents a top event or limits its consequences. Barriers sit on the threat and consequence lines of a bowtie diagram and are the things audits actually test.
Barriers are the working parts of a bowtie. Preventive barriers sit on the left side, between a threat and the top event; recovery (or mitigative) barriers sit on the right, between the top event and a consequence. A pressure relief valve, a permit-to-work system, a risk-based inspection programme, an emergency shutdown system — all barriers.
The terminology splits by tradition: the CCPS and European bowtie literature says barrier; ICMM-style critical control management and most Australian WHS practice says control. They are the same object. Bowtie Risk Engine uses control throughout the product — this glossary uses both so search and procedure vocabularies both land.
A useful discipline: a real barrier must be able to fail. "Operator competence" written as a barrier is an aspiration; "verified competency assessment for isolation authorities, refreshed every two years" can fail in identifiable ways, which means it can also be checked. That is what separates a barrier from a wish, and it is why every barrier deserves an effectiveness rating, a set of degradation factors, and — for the ones that matter most — a performance standard.
The same barrier often defends several threats. Modelling it once and linking it everywhere it appears (rather than re-typing it) is what keeps a control register honest — see how linked controls work in the product feature tour.
Last reviewed 2026-08-09 · Back to the glossary
See the method in working software.
Six worked bowtie examples ship with the product — open one read-only, no sign-in, and read every control in full.