HAZOP
A HAZOP is a systematic, guideword-driven review of a process design that finds deviations (no flow, more pressure, reverse flow) and their causes and consequences. Bowties pick up where HAZOPs leave off: managing the controls.
A HAZOP (hazard and operability study) walks a design node by node, applying guidewords — no, more, less, reverse, other than — to process parameters to surface every credible deviation: no flow, more pressure, reverse flow, contamination. For each deviation the team records causes, consequences, existing safeguards, and actions. The method (standardised in IEC 61882) remains the workhorse of process hazard analysis because it is exhaustive by construction.
Exhaustive is also its limitation. A completed HAZOP is hundreds of worksheet rows — superb for finding gaps in a design, nearly unreadable as a live picture of how a major hazard is controlled. The safeguards column names barriers but says nothing about their ongoing effectiveness, ownership, or verification.
That is the handover point to the bowtie. The HAZOP's high-consequence deviations become candidate top events; its causes become threats; its safeguards become barriers that can now be rated, assigned, degraded, and verified. HAZOP finds the risk; the bowtie manages the controls — most mature process-safety systems run both, in that order.
The loss of containment example shows what a HAZOP's worth of safeguards looks like after that translation.
Last reviewed 2026-08-09 · Back to the glossary
See the method in working software.
Six worked bowtie examples ship with the product — open one read-only, no sign-in, and read every control in full.