A bow-tie analysis can show several barriers between a hazardous event and its consequences. On paper, this may create the impression that the organization has multiple layers of protection.
But there is a critical question every process safety team should ask:
Are those barriers genuinely independent—or could one failure disable several of them at the same time?
Consider a process where an alarm alerts an operator to abnormal pressure, the operator takes corrective action, and an emergency shutdown system provides another layer of protection. These may appear as separate barriers.
However, what happens if the alarm and shutdown function depend on the same transmitter? What if the alarm is ineffective during a power failure? What if both safeguards depend on the same utility, communication network, procedure, or person?
The diagram may show several barriers, while the actual system has far less protection than expected.
This is why effective Bow-Tie Analysis must go beyond identifying barriers. Organizations also need to understand barrier effectiveness, dependencies, degradation factors, escalation factors, and potential common-cause failures.
What Is a Safety Barrier in Bow-Tie Analysis?
A safety barrier is a control intended either to prevent a threat from progressing to the Top Event or to reduce the consequences after the Top Event occurs.
A typical Bow-Tie model places the Top Event at the center and divides barriers into two broad categories.
Preventive Barriers
Preventive barriers appear on the left side of the bow tie. Their purpose is to prevent an identified threat from causing the Top Event.
Depending on the scenario, examples could include:
- Process control functions
- Engineering safeguards
- Inspection and preventive maintenance
- Alarm and operator intervention
- Mechanical protection
- Operating procedures
- Interlocks and shutdown functions
Mitigative Barriers
Mitigative or recovery barriers appear on the right side. These controls are intended to limit escalation or reduce the consequences once the Top Event has occurred.
Examples may include:
- Emergency shutdown and isolation
- Fire and gas detection
- Fire protection systems
- Emergency response arrangements
- Containment systems
- Evacuation measures
The important point is that the number of barriers shown on a Bow-Tie diagram does not, by itself, demonstrate the strength of risk control.
The quality and independence of those barriers matter.
What Does Barrier Independence Actually Mean?
In practical terms, barrier independence means that the successful operation of one barrier should not rely on the successful operation of another barrier where those barriers are being treated as separate protection.
Suppose a facility identifies three safeguards for an overpressure scenario:
Barrier 1: High-pressure alarm
Barrier 2: Operator response to the alarm
Barrier 3: Automatic shutdown function
At first glance, there appear to be three layers of protection.
Now consider that:
- the alarm and shutdown both receive information from the same pressure transmitter;
- the operator response depends entirely on receiving that alarm; and
- both electronic functions depend on the same electrical supply.
The safeguards may therefore contain significant dependencies.
A failure of the transmitter, power supply, or another shared component could affect multiple barriers simultaneously.
Three boxes on a Bow-Tie diagram do not necessarily mean three independent barriers.
That distinction is central to meaningful barrier management.
Why Barrier Dependence Can Create Hidden Risk
Organizations can develop false confidence when barriers are counted without examining how they actually function.
A Bow-Tie diagram may appear robust because every threat path contains several controls. But if those controls share equipment, utilities, people, information, or failure mechanisms, the real level of protection may be weaker than the diagram suggests.
This can create several problems.
Overestimating Risk Reduction
If dependent safeguards are treated as completely separate controls, the organization may overestimate how much protection exists against a hazardous scenario.
Missing Single Points of Failure
A shared transmitter, power supply, control system, utility, communication network, or other dependency may become a point where one failure affects several controls.
Underestimating Escalation Factors
A barrier may exist and function under normal conditions but become unavailable under the exact circumstances in which it is most needed.
Weakening Decision-Making
Management may prioritize resources based on a risk picture that assumes barriers provide more resilience than they actually do.
The objective should therefore not be to create a Bow-Tie diagram with as many barriers as possible. It should be to establish a credible representation of how risk is controlled in the real facility.
Common Ways Safety Barriers Become Dependent
Barrier dependency is not limited to shared equipment. It can arise from technical, human, organizational, and environmental factors.
1. Shared Instrumentation
Two protection functions may depend on the same sensor or measurement.
For example, an alarm and shutdown action could both rely on one process transmitter. A transmitter failure could therefore affect both functions.
2. Shared Power or Utilities
Multiple safeguards may depend on a common:
- Electrical supply
- Instrument air system
- Hydraulic system
- Cooling system
- Communication network
- Control infrastructure
Loss of the common utility may compromise several barriers at once.
3. Shared Logic or Control Systems
Controls that appear separately on the Bow-Tie diagram may operate through the same control platform or shared architecture.
Their functional relationship should therefore be examined before they are assumed to represent independent protection.
4. Dependence on the Same Operator
Human intervention is particularly important to examine.
Imagine that one operator must:
- notice an alarm;
- diagnose the abnormal condition;
- identify the correct procedure; and
- initiate the required action.
Listing the alarm, procedure, and operator response as completely separate barriers could give a misleading impression if they form parts of one dependent response sequence.
5. Shared Maintenance or Testing Weaknesses
Several barriers can be degraded by the same maintenance-management problem.
Examples include overdue inspections, bypassed systems, incomplete testing, calibration problems, or unresolved defects.
The equipment may be physically separate while still being vulnerable to a common organizational weakness.
6. Environmental Conditions
A fire, flood, extreme temperature, structural damage, or other hazardous condition could disable several barriers simultaneously.
A barrier should therefore be considered in the environment in which it may actually be required—not only under normal operating conditions. For emergency systems, an emergency systems survivability analysis can support this examination.
Common-Cause Failure: A Critical Bow-Tie Question
One of the most important concepts when examining barrier independence is common-cause failure.
A common-cause failure occurs when a shared cause or condition contributes to the failure of multiple systems or safeguards.
Consider two pumps intended to provide redundancy. If both depend on the same electrical supply, loss of that supply could make both unavailable.
Similarly, multiple instruments may appear independent while sharing a common impulse line, cabinet, communication system, environmental exposure, or maintenance vulnerability.
When reviewing a Bow-Tie Analysis, teams should therefore ask:
What single event, condition, or failure could defeat more than one of these barriers?
That question often reveals dependencies that are not obvious from the initial diagram.
Barrier Independence vs Barrier Effectiveness
Independence and effectiveness are related, but they are not the same concept.
A barrier can be independent but ineffective.
It can also be technically effective but highly dependent on another safeguard.
A robust barrier review therefore needs to consider several characteristics.
| Barrier Question | What the Team Should Examine |
| Does the barrier actually prevent or mitigate the scenario? | Function and effectiveness |
| Is it available when required? | Availability |
| Can its condition be verified? | Assurance and testing |
| Does it depend on another barrier? | Independence |
| Could one failure defeat several barriers? | Common-cause vulnerability |
| What could cause the barrier to fail? | Escalation factors |
| Who is responsible for maintaining it? | Ownership |
| How is performance monitored? | Performance assurance |
This shifts Bow-Tie Analysis from a simple hazard visualization exercise toward a more practical barrier-management framework.
Escalation Factors: What Could Make the Barrier Fail?
A strong Bow-Tie Analysis should not stop after identifying the barrier itself.
It should also consider escalation factors—conditions that can reduce, defeat, or impair the effectiveness of a barrier.
For example:
Barrier: Emergency isolation valve
Possible escalation factor: Valve fails to close when demanded
Relevant control: Inspection, testing, maintenance, or another defined assurance measure
Another example:
Barrier: Operator response to high-level alarm
Possible escalation factor: Alarm is missed during a high workload period
Relevant controls: Alarm-management measures, competency arrangements, or other controls established for the specific facility
By explicitly mapping these weaknesses, teams can better understand not just what protects the facility, but also what protects the protection.
A Practical Test for Barrier Independence
During a Bow-Tie workshop or barrier review, each claimed barrier can be challenged systematically.
For every barrier, ask:
- What initiates this barrier?
- What equipment, utility, system, information, or person does it depend on?
- Does another claimed barrier depend on any of the same resources?
- Could one failure disable multiple barriers?
- Would the barrier still function during the hazardous event itself?
- How do we know the barrier is available today?
- How is its performance tested or monitored?
- What conditions could degrade it?
- Who owns the barrier and its assurance activities?
- Is the barrier truly separate, or are we counting different parts of the same protective function more than once?
These questions can expose assumptions that may otherwise remain hidden behind a visually convincing diagram.
Example: When Four Barriers May Not Mean Four Layers of Protection
Consider a hypothetical storage vessel where overfilling could lead to loss of containment.
The Bow-Tie diagram identifies four preventive controls:
- Level indication
- High-level alarm
- Operator intervention
- Automatic shutdown
This initially looks like a strong arrangement.
But a deeper review discovers that the level indication and alarm use the same measurement source, operator intervention depends on the alarm being received and correctly interpreted, and the shutdown function shares part of the same instrumentation architecture.
The Bow-Tie Analysis should not automatically treat those four controls as four fully independent protection layers.
Instead, the team should examine the dependencies and determine what each control actually contributes to the overall risk-management strategy.
That distinction becomes especially important when Bow-Tie findings are used alongside more quantitative or semi-quantitative risk assessment methods.
Bow-Tie Analysis and LOPA: Why Independence Matters
Bow-Tie Analysis and Layer of Protection Analysis (LOPA) can complement one another, but they answer different questions.
Bow-Tie Analysis provides a visual representation of:
Threat → Preventive Barriers → Top Event → Mitigative Barriers → Consequence
LOPA takes a more structured approach to evaluating scenario risk and the contribution of qualifying protection layers.
A safeguard shown on a Bow-Tie diagram should therefore not automatically be assumed to qualify as an Independent Protection Layer (IPL) in LOPA.
Where LOPA is required, the safeguard needs to be evaluated against the applicable criteria used by the organization or methodology.
This is an important distinction because a Bow-Tie diagram can contain many valuable controls that are relevant to risk management without every one of them being treated as an IPL.
Bow-Tie Analysis and HAZOP: Connecting Hazards to Barriers
A HAZOP study focuses on identifying process deviations, their causes, consequences, existing safeguards, and recommendations.
Bow-Tie Analysis can then help teams visualize selected hazard scenarios and understand the relationship between threats, Top Events, barriers, and consequences.
The methods can therefore support different stages of risk understanding:
HAZOP identifies and examines deviations and hazardous scenarios.
Bow-Tie Analysis visualizes how barriers manage selected scenarios.
LOPA may be used where further evaluation of scenario risk and protection layers is appropriate.
Aura Safety’s documented process safety portfolio includes Bow-Tie Analysis alongside HAZOP, HAZID, SIL, QRA, FERA, PSSR, FMEA and other risk studies.
Warning Signs That Your Barrier Model Needs Review
A Bow-Tie Analysis may warrant closer examination when:
- Almost every threat has the same barriers.
- Multiple barriers depend on the same operator action.
- Alarm, control, and shutdown functions share instrumentation without the dependency being recognized.
- Barriers are listed without clear owners.
- Barrier degradation or escalation factors have not been identified.
- Temporary bypasses and overrides are not reflected.
- Barrier availability cannot be demonstrated.
- Preventive maintenance or testing does not clearly connect to critical barriers.
- Different parts of one protective function are counted as separate barriers.
- The Bow-Tie diagram has not been reviewed after significant plant or process changes.
A visually complete Bow-Tie diagram is not necessarily an operationally reliable barrier-management system.
From Bow-Tie Workshop to Barrier Management
The greatest value from Bow-Tie Analysis comes when the diagram connects with day-to-day operations.
Critical barriers identified during the study can inform activities such as:
- Inspection and maintenance
- Testing and assurance
- Operating procedures
- Training and competency
- Management of Change (MOC) reviews
- Audit and verification
- Performance monitoring
- Incident investigation
- Process safety reviews
This helps move the organization from “we have a barrier” toward the more useful question:
“How do we know this barrier is available and capable of performing its intended function when required?”
That is where Bow-Tie Analysis becomes more than a workshop deliverable.
It becomes part of ongoing process safety management. Explore the key elements of an effective process safety management system for the broader management context.
How Aura Safety Supports Bow-Tie Analysis
Aura Safety & Risk Consultants provides Bow-Tie Analysis as part of its broader process safety services portfolio. The company also provides complementary studies and services including HAZOP, HAZID, QRA, SIL, FERA, FMEA, PSSR and PSM audit and implementation.
Depending on the defined project scope, a Bow-Tie study can help organizations structure hazard scenarios, map threats and consequences, identify preventive and mitigative barriers, examine escalation factors, and improve visibility of how critical risks are controlled.
Aura Safety serves industrial sectors including oil and gas, petroleum, automotive, petrochemicals, fertilizers, cement, pharmaceuticals, healthcare, warehousing, high-rise buildings, railways, steel and power.
Need to review whether the barriers in your Bow-Tie Analysis provide the protection your risk model assumes?
Get a Quote from Aura Safety & Risk Consultants to discuss the scope of a Bow-Tie Analysis or barrier review for your facility.
Barrier independence refers to the extent to which one barrier can perform its intended function without relying on another claimed barrier. Dependencies such as shared instrumentation, utilities, control systems, operators, or other resources should be identified when evaluating the overall barrier arrangement.
No. A barrier shown in a Bow-Tie diagram should not automatically be considered an Independent Protection Layer for LOPA purposes. If a safeguard is being credited as an IPL, it should be assessed against the applicable LOPA criteria.
A preventive barrier is intended to stop a threat from progressing to the Top Event. A mitigative barrier acts after the Top Event to limit escalation or reduce consequences.
An escalation factor is a condition that can weaken or defeat a barrier. Examples can include equipment failure, utility loss, environmental conditions, human factors, maintenance deficiencies, or other circumstances relevant to the particular barrier.
A common-cause failure occurs when a shared cause or condition contributes to the failure of multiple systems or safeguards. Identifying these dependencies is important when determining whether apparently separate barriers provide genuinely separate protection.
HAZOP systematically examines process deviations, causes, consequences, safeguards, and recommendations. Bow-Tie Analysis visually maps the pathways between threats, a Top Event, consequences, and the barriers intended to control those pathways.
A review may be appropriate when significant changes affect the process, equipment, operating conditions, safeguards, procedures, or other assumptions on which the existing analysis depends. Organizations can also integrate barrier reviews into their established risk-management and assurance processes.