Bowtie analysis
Bowtie analysis is a structured risk assessment method that maps one top event's threats, consequences, and the barriers controlling both onto a single bowtie-shaped diagram, making the control picture visible and auditable.
Bowtie analysis is the method; the bowtie diagram is its output. The analysis proceeds in a fixed order: name the hazard, define the top event, list credible threats on the left and distinct consequences on the right, then place the barriers — preventive against each threat, recovery against each consequence — and finally interrogate each barrier for degradation factors and the controls that defend against them.
Its sweet spot is major, low-frequency, high-consequence risk: the events an organisation cannot learn about by experiencing them. For those, purely statistical approaches starve for data, and risk matrices compress everything that matters into one cell. Bowtie analysis instead makes the argument structural: here is every path to the event, and here is what stands in each path.
It is recognised in IEC 31010 among established risk assessment techniques, and it underpins critical control management — the bowtie is where critical controls are selected from.
For the full method with worked examples, read the guide: What is bowtie analysis? A practical guide.
Last reviewed 2026-08-09 · Back to the glossary
See the method in working software.
Six worked bowtie examples ship with the product — open one read-only, no sign-in, and read every control in full.