HAZOP vs Bow-Tie vs FMEA: Which Method Fits a Process-Safety Decision?
HAZOP, Bow-Tie, and FMEA answer different process-safety questions. This comparison helps engineering, operations, maintenance, and EHS leaders match each method to design deviations, barrier assurance, or equipment and task failure modes.

Key takeaways
- 01HAZOP is strongest for challenging process deviations against design intent in a multidisciplinary review.
- 02Bow-Tie is strongest for connecting a defined top event to preventive and recovery barriers with owners and evidence.
- 03FMEA is strongest for tracing failure modes in defined equipment, subsystems, maintenance activities, or tasks.
- 04The methods can form a sequence, but one worksheet should not be treated as proof that another decision has been addressed.
- 05The best method is the one that exposes the uncertainty a responsible leader must resolve before work proceeds.
A process-safety team can spend days filling out a risk worksheet and still leave the plant manager with the wrong decision. The problem is usually not a lack of technical effort. It is that HAZOP, Bow-Tie, and FMEA answer different questions, so selecting one by habit can make a serious exposure look neatly documented without making the decision safer.
HAZOP is strongest when a multidisciplinary team needs to challenge how a process can deviate from its intended design. Bow-Tie is strongest when leaders need to see how threats, preventive barriers, consequences, and recovery barriers connect around a defined top event. FMEA is strongest when a component, subsystem, or task has identifiable failure modes whose effects and controls can be ranked. None is a universal risk assessment method.
Andreza Araujo's safety leadership work has consistently connected technical analysis with the decision made at the point of work. Her book Safety Culture: From Theory to Practice treats the quality of a safety system as a management question, not only a paperwork question. The practical test is therefore simple, although it is not easy. Choose the method that exposes the uncertainty the decision-maker actually needs to resolve.
Evaluation criteria for choosing a process-safety method
The right comparison starts with the decision, not the preferred software or the team's training history. Before selecting a method, define what is changing, what could fail, who may be exposed, and which evidence must exist before work is authorized.
Seven criteria make the choice more disciplined. The first is the object of analysis, such as a process node, a critical barrier, a component, or a task. The second is the type of uncertainty, whether it concerns deviations, failure modes, escalation, human interaction, or barrier performance. The third is the level of design maturity. The fourth is whether the team needs discovery or communication. The fifth is whether safeguards must be linked to owners and verification evidence. The sixth is how often the analysis must be updated. The seventh is whether the result will support design, operations, maintenance, or executive review.
| Criterion | HAZOP | Bow-Tie | FMEA |
|---|---|---|---|
| Primary object | Process deviations at defined nodes | One top event and its barrier system | Failure modes in a component, subsystem, or task |
| Best question | How could the design depart from its intent? | What prevents the top event, and what limits its consequences? | How could this item fail, and what would the effect be? |
| Best timing | Design review, modification, or structured revalidation | Risk communication, critical-control definition, or barrier assurance | Equipment design, reliability review, and maintenance planning |
| Typical output | Deviation causes, consequences, safeguards, and recommendations | Threats, top event, consequences, barriers, owners, and degradation factors | Failure-mode list, effects, causes, controls, and prioritization |
| Main trap | Turning a creative challenge into a slow checklist exercise | Drawing barriers without proving their performance or independence | Ranking scores while missing interactions between failures |
This matrix is a selection aid, not a substitute for the applicable legal, engineering, or company requirements. ISO 12100:2010, which sets general principles for machinery risk assessment and risk reduction, emphasizes understanding intended use, foreseeable misuse, hazards, and risk-reduction measures. A process-safety method should add decision clarity to that work rather than create a parallel record that nobody owns.
HAZOP fits design deviations and multidisciplinary challenge
HAZOP is the strongest first choice when the central uncertainty is how a process can deviate from its intended operating conditions. The team examines a defined node, applies guide words to parameters such as flow, pressure, temperature, or composition, and asks whether a credible cause could produce a harmful consequence.
Its value comes from structured disagreement. Operations can identify a response that a design package does not show. Maintenance can describe a temporary configuration that exists during isolation or restart. Instrumentation specialists can challenge whether an alarm is available, timely, and understood. The method is useful because the discussion follows process intent while allowing different disciplines to test the assumptions behind it.
HAZOP becomes weaker when the team treats every deviation as equally important, copies safeguards from a previous node, or closes recommendations without checking the changed design. A recommendation that says “provide training” may sound responsible while leaving the initiating cause, engineered protection, and operating boundary untouched. The same weakness appears when a workshop is scheduled after construction, when the most important design choices have already become expensive to change.
For a plant manager, the output to demand is not a thicker worksheet. It is a short list of unresolved design assumptions, the decisions required before commissioning, and the evidence that each recommendation has changed the risk picture. Link the result to the plant's change-control and pre-startup gates, because a HAZOP recommendation that never reaches the authorization workflow is only an observation.
Bow-Tie fits barrier ownership and critical-control assurance
Bow-Tie is the strongest choice when the decision-maker needs a visible connection between a threat, a top event, a consequence, and the barriers that should prevent or limit harm. It is especially useful when the organization must decide which controls are critical, who owns them, how they can degrade, and what evidence proves that they remain effective.
A good Bow-Tie is not a decorative diagram. It identifies a defined top event, separates preventive barriers from recovery barriers, names degradation factors, and describes the verification activity that reveals loss of effectiveness. If a shutdown system is listed as a barrier, the team should be able to explain its required function, testing interval, bypass controls, failure response, and responsible owner.
The principal trap is confusing presence with performance. A barrier can appear in a procedure, an audit checklist, or a control register while remaining unavailable in the operating moment. Bow-Tie also becomes misleading when every administrative action is drawn as an independent barrier, even though the same supervisor, staffing level, or rushed decision supports all of them.
Andreza Araujo often frames safety leadership around the distance between declared control and operated control. That distinction makes Bow-Tie valuable for executive review, provided the review asks for barrier evidence rather than a favorable color. A useful companion is the decision-log comparison for plant leaders, because a barrier exception should produce an explicit decision, owner, expiry condition, and escalation route.
FMEA fits failure modes in equipment and tasks
FMEA is the strongest choice when the team can define the item being examined and list credible ways it may fail. It works well for equipment, subsystems, maintenance tasks, and interfaces where the effect of a failure can be traced from a local cause to a system or user consequence.
The method helps teams move from vague concern to specific failure logic. A pump may fail to start, lose containment, run in the wrong direction, or provide a misleading status signal. Each failure mode can then be connected to causes, effects, existing controls, detection opportunities, and an action that improves prevention or detection.
FMEA is less suitable when the dominant risk comes from interactions between process conditions, human decisions, and multiple barriers that fail together. A component-by-component review can miss a sequence in which a small deviation, a delayed alarm, a temporary bypass, and an unclear handover combine into a major exposure. Prioritization scores can also create false precision when the numbers are not supported by evidence.
For maintenance and reliability leaders, FMEA should connect directly to work planning. The question is not only which failure mode has the highest score. It is also whether the inspection can detect the relevant degradation, whether the task introduces a new exposure, and whether the equipment is safe to return to service. That logic complements control verification and recurring-exposure review, where the organization decides whether a signal belongs in maintenance, operations, or formal risk governance.
Where the methods overlap and where they should stay separate
All three methods can describe causes, consequences, controls, and recommendations, which is why teams sometimes treat them as interchangeable. The overlap is useful when it creates a deliberate sequence. HAZOP can discover credible process deviations. Bow-Tie can turn a selected major scenario into a barrier-assurance model. FMEA can examine whether a specific component or task can make one of those barriers unavailable.
The methods should stay separate when their outputs answer different decisions. A Bow-Tie cannot replace a design review that has not challenged process intent. FMEA cannot prove that a complete process scenario has been considered. HAZOP cannot, by itself, demonstrate that a critical barrier is tested at the required interval. Combining every worksheet into one large study usually increases volume while reducing accountability.
The sequence should also reflect the life cycle. A new process or major modification may need structured deviation analysis before commissioning. A mature operation may need Bow-Tie assurance for a small set of high-consequence scenarios. A maintenance organization may need FMEA to decide inspection tasks, spares, or failure detection. The correct combination depends on the uncertainty and the decision horizon.
Decision matrix for common plant decisions
The following matrix translates the comparison into decisions that engineering, operations, maintenance, and EHS leaders commonly face. It does not assign a universal score, because the consequence of a wrong choice depends on the process, jurisdiction, equipment, and exposure.
| Plant decision | Primary method | Useful companion | Evidence to request |
|---|---|---|---|
| Validate a new process node or major design change | HAZOP | Bow-Tie for selected major scenarios | Closed design assumptions, approved safeguards, and commissioning actions |
| Define controls for a high-consequence loss-of-containment scenario | Bow-Tie | FMEA for barrier components | Barrier function, owner, test, degradation factor, and exception process |
| Improve reliability of a critical pump or shutdown subsystem | FMEA | Bow-Tie for the consequence pathway | Failure evidence, detection method, maintenance task, and return-to-service proof |
| Review a temporary operating condition | HAZOP or focused deviation review | Bow-Tie for changed barriers | Defined expiry, responsible decision-maker, compensating control, and restoration trigger |
| Investigate repeated loss of a safeguard | Bow-Tie barrier review | FMEA for the failing item | Actual barrier performance, degradation pattern, and action effectiveness |
The table becomes useful only when the organization gives each output a home. Recommendations should enter the relevant design, maintenance, operating, or leadership workflow, with an owner who can be challenged when evidence is late or incomplete. A risk review that ends at approval has not yet shown that the control works.
Recommendation per context
Use HAZOP when the main question is whether the process design can deviate in a credible and harmful way. Use Bow-Tie when the main question is whether the organization can prevent a defined top event and limit its consequences with controls that have owners and proof. Use FMEA when the main question is how a defined item or task can fail and how that failure should be prevented or detected.
For a new process or major modification, begin with HAZOP and carry the most serious scenarios into focused Bow-Tie work. For an operating plant that already understands its major scenarios, prioritize Bow-Tie barrier assurance and use FMEA where equipment reliability threatens a critical control. For a maintenance problem, begin with FMEA, then check whether the failure belongs to a larger process scenario that requires a barrier review.
Andreza Araujo's practical contribution is to keep the method subordinate to the decision. A polished analysis is not evidence of control effectiveness, and a low score is not evidence that exposure is acceptable. Leaders can also compare this choice with the hierarchy of controls in real work decisions before approving a safeguard. The responsible leader should be able to state what was analyzed, what remains uncertain, which control must work, how it will be checked, and what happens when the evidence is missing.
That discipline is also consistent with the logic of James Reason's work on latent conditions and organizational accidents. Technical failures rarely exist in isolation when design assumptions, maintenance choices, supervision, and operating pressure shape the conditions in which people work. The method is useful when it reveals those connections early enough for someone with authority to act.
The most dangerous method is the one selected because it is familiar, completed because it is scheduled, and trusted because its form is full. Match the analysis to the uncertainty, assign the output to a decision owner, and verify the control where exposure actually occurs.
Frequently asked questions
Is HAZOP better than Bow-Tie?
When should a plant use FMEA?
Can HAZOP, Bow-Tie, and FMEA be used together?
What is the main weakness of Bow-Tie analysis?
Who should choose the process-safety method?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.