Bowtie glossary

FMEA

FMEA systematically lists each component's failure modes, their effects, and their causes, ranking them for action — bottom-up and component-centred, where a bowtie is top-down and event-centred.

FMEA asks, for every component or process step: how can it fail (the failure modes), what happens when it does (the effects), why (the causes), and how bad, how likely, how detectable? Traditional FMEAs multiply severity, occurrence, and detection into a risk priority number; newer practice ranks with action-priority tables instead. Either way, the output is a worked list of what deserves engineering attention first.

The method is bottom-up: it starts from the hardware (or process step) and works outward to consequences. That makes it superb at completeness — no pump seal or software input goes unexamined — and weak at synthesis: a thousand-row FMEA cannot tell an operations manager which few defences keep the plant out of the newspaper.

The bowtie is the complementary view: top-down from one top event, showing the barriers that matter and their condition. In reliability practice the two chain naturally — FMEA identifies the failure modes that become threats, and the maintenance tasks it justifies become preventive controls with measurable criteria. The critical pump failure template shows that translation.

Rule of thumb: FMEA to decide what to maintain and design out; bowtie to show how the big event is controlled. Trying to make either do the other's job produces the worst of both.

Last reviewed 2026-08-09 · Back to the glossary

See the method in working software.

Six worked bowtie examples ship with the product — open one read-only, no sign-in, and read every control in full.