Bowtie glossary

Consequence

A consequence is a distinct harmful outcome that can follow the top event — the right-hand lines of a bowtie diagram. Each consequence carries the recovery barriers that limit how bad the outcome gets.

Consequences answer "how bad does it get if the top event happens?" A single loss of containment can end as a pool fire, a vapour cloud explosion, a toxic exposure, or an environmental release — four separate consequence lines, because each is fought with different recovery barriers: detection and isolation, ignition control, emergency response, spill containment.

That separation is the point. A generic consequence like "people get hurt" hides the fact that preventing escalation to an explosion needs different controls from limiting a toxic dose. Writing consequences as distinct outcomes forces the recovery side of the bowtie to be as deliberate as the prevention side — which matters, because recovery barriers are the ones you rely on precisely when the plan has already failed once.

Consequences also anchor severity conversations. When a board asks "what is the worst credible outcome of this risk?", the answer should be the most severe consequence line on the bowtie — with the recovery barriers that stand in its way, and their current effectiveness, on the same page.

See the pattern across disciplines in the worked templates — the consequence sets differ completely between a data breach and an airspace loss of separation, but the structure is identical.

Last reviewed 2026-08-09 · Back to the glossary

See the method in working software.

Six worked bowtie examples ship with the product — open one read-only, no sign-in, and read every control in full.