How to Run a Bow-Tie Workshop for a New High-Risk Task in 8 Steps
A bow-tie workshop turns a high-risk task into a decision-ready control map. Follow eight steps to define threats, verify barriers, assign owners, and authorize work.
Key takeaways
- 01Define one task boundary and one top event so the team can test each threat and barrier against the work that will actually occur.
- 02Map preventive and mitigative controls separately, because a recovery measure cannot make an absent preventive barrier credible.
- 03Write a performance standard for every critical control, then assign one owner who has authority to stop or escalate the work.
- 04Verify controls with evidence that matches the barrier, since a signature or photograph cannot prove every control remains effective.
- 05Challenge the bow-tie with frontline workers and update the decision whenever scope, conditions, interfaces, or control evidence changes.
F2 practical guide for EHS managers, maintenance leaders, and supervisors
A new high-risk task rarely arrives with a complete history. The equipment may have changed, the contractor interface may be unfamiliar, or the team may be relying on a control that nobody has tested at the point of work. A bow-tie workshop gives the team a disciplined way to connect the initiating event, the threats, the consequences, and the barriers that must hold.
This guide explains how to run that workshop before work is authorized. The goal is not to produce a decorative diagram. The goal is to leave with named control owners, verification evidence, and a decision rule for when the task must pause.
A bow-tie workshop is a structured risk review that maps threats on the left, a top event in the center, consequences on the right, and preventive or mitigative controls around the event. It becomes operational only when each critical control has an owner, a performance standard, and a verification method.
What you need before starting
Bring the task scope, the latest work method, relevant drawings or process information, the permit-to-work requirements, and people who understand how the job will actually be performed. Include operations, maintenance, engineering, contractors when relevant, and the supervisor who will authorize the work. A workshop that excludes the people closest to the task may produce a technically elegant map that does not describe the real exposure.
Use ISO 31000 as the management-system anchor and IEC 31010 as the reference for risk assessment techniques. Neither standard turns a workshop into a substitute for engineering judgment. They help the team establish context, identify uncertainty, evaluate risk, and record treatment decisions. Andreza Araujo's *80 Ways to expand risk perception* adds a useful practical test because the team must ask what the task looks like from the worker's position, not only from the procedure writer's desk.
Step 1: Define the task boundary
Write one sentence that states where the task begins, where it ends, what equipment is included, and which interfaces are inside the review. Avoid a title such as “maintenance activity,” because it hides the sequence that creates exposure. A better boundary names the asset, the work phase, the energy sources, and the conditions that could change the plan.
Verify the boundary against the work order and the field layout. If the team cannot agree on what is being reviewed, stop there. A vague boundary will make the bow-tie appear complete while leaving adjacent work, stored energy, or simultaneous operations outside the frame.
Step 2: Select one top event
Choose the moment when control of the hazard is lost, before the worst consequence occurs. For lifting, the top event might be an uncontrolled load movement. For chemical transfer, it could be loss of containment. For isolation work, it might be unexpected energization. Keep the event specific enough that the barriers can be tested.
Do not write the consequence as the top event. “Worker fatality” is too late in the chain, while “unsafe maintenance” is too broad. James Reason's work on organizational accidents supports this distinction because active failures and latent conditions become easier to examine when the event sequence is visible.
Step 3: List credible threats
Ask what could cause the top event under the actual work conditions. Consider incorrect isolation, degraded equipment, wrong assumptions about the process, poor communication, simultaneous operations, weather, fatigue, contractor interface, and changes introduced after the permit was approved. Record threats as observable conditions or actions rather than vague labels such as “human error.”
Test each threat against evidence. A threat belongs on the map when the team can explain how it could arise and what would reveal it before the top event. Link the review to the weekly risk register when the threat needs an owner beyond the immediate job.
Step 4: Map the preventive controls
Place the controls between each threat and the top event. Start with elimination, substitution, and engineering measures before administrative controls and PPE. A procedure can support a barrier, but a procedure alone does not prove that the hazard is controlled. The team should state what prevents the event, when the control must be present, and what condition makes it unreliable.
Separate controls that prevent the event from actions that merely remind people to be careful. A physical isolation, an interlock, or a verified design change may prevent exposure, while a briefing may only communicate the expected method. Both can matter, but they should not be treated as equivalent. Use the frontline escalation matrix when a failed preventive barrier requires a decision above the supervisor's authority.
Step 5: Map the consequences and recovery controls
On the right side, identify what can happen after the top event, including injury, exposure, equipment damage, fire, environmental release, production interruption, or loss of containment. Keep the consequence statements concrete enough to guide emergency planning. A consequence such as “serious outcome” does not tell anyone what protection is needed.
Then add mitigative controls that limit harm after the event. These may include detection, shutdown, separation, emergency response, rescue, medical arrangements, and communication. A recovery control does not make the initiating event acceptable. It reduces the severity if prevention fails, which is why the control needs its own owner and verification evidence.
Step 6: Identify the critical controls
Not every barrier deserves the same management attention. Select the controls whose failure would materially increase the chance of a serious injury or fatality, or whose absence would leave the task without a credible line of defense. The selection should reflect consequence and control dependence, not the number of boxes on the diagram.
For each critical control, write a short performance standard. “Isolation is effective” is weak. “All identified energy sources are isolated, locked, tagged, and independently verified before the first break of containment” is testable. If several people share the same control, clarify who owns the decision and who supplies the evidence. The article on control ownership and decision rights can help the team resolve that boundary.
Step 7: Assign verification before authorization
Decide how the control will be checked, who will check it, and when the check must occur. Verification may involve a field observation, a document review, a functional test, a measurement, or a direct conversation with the person performing the task. The method must match the control. A signed form cannot verify a physical guard, and a photograph cannot prove that an isolation remains effective after the work changes.
Record the evidence where the next decision maker can find it. If the control cannot be verified before the task starts, define the temporary protection and the authority that decides whether work can continue. This is where the workshop moves from analysis to governance. The map is useful only when it changes the release decision.
Step 8: Run the challenge and close the decision
Ask the people closest to the work to challenge the map. Which threat is missing? Which control looks stronger on paper than it is in the field? What has changed since the method was written? Which assumption would be most dangerous if it were wrong? A challenge is not a sign that the workshop failed. It is evidence that the team is testing the model against reality.
Close the review with a clear decision. Authorize the task when the boundary is understood, critical controls are present, verification evidence is credible, and escalation rules are known. Pause or redesign the task when a critical control is absent, degraded, or owned by nobody. Andreza Araujo's *Make The Difference: Be a Leader in Health & Safety* frames this kind of follow-through as a leadership responsibility because care becomes visible through the decisions that protect work before pressure narrows attention.
Use the workshop output after the meeting
Store the bow-tie with the job package, but do not let it become a static file. Revisit it after a scope change, a failed control, an abnormal condition, a contractor change, or a near miss. The strongest review is the one that stays connected to field evidence and changes the plan when the evidence changes.
- Confirm that the task boundary matches the work released to the field.
- Check that every critical control has one accountable owner.
- Test the performance standard before the first high-risk step.
- Record failed or degraded barriers and escalate them before continuation.
- Update the map when the work method, equipment, or interface changes.
For a practical risk-management system, combine the workshop with a live risk register, a defined escalation path, and control verification that can be seen where work occurs. That combination is more valuable than a polished diagram that nobody uses.
Andreza Araujo's work connects engineering, creativity, and care in safety decisions. Explore her broader safety leadership work and use the same standard for every high-consequence task: people should not have to discover a missing barrier through an incident.
FAQ
What is the purpose of a bow-tie workshop?
Its purpose is to connect threats, a defined top event, consequences, and the barriers that prevent or limit harm. The workshop is valuable when it produces control owners, performance standards, verification evidence, and escalation decisions.
Who should participate in the workshop?
Include operations, maintenance, engineering, EHS, the authorizing supervisor, and contractors when their work or interface affects the exposure. People who perform or supervise the task should be able to challenge the map before authorization.
How many controls should a bow-tie include?
There is no useful universal number. Include credible barriers that materially affect the event sequence, then identify which ones are critical. A short map with testable controls is stronger than a crowded map filled with reminders.
Can a bow-tie replace a job safety analysis?
No. A bow-tie shows the control logic around a high-consequence event, while a JSA or JHA examines task steps and hazards. Use them together when the task needs both barrier management and detailed execution planning.
When should the bow-tie be reviewed again?
Review it when the scope, equipment, work method, contractor interface, conditions, or control evidence changes. Revisit it after a failed barrier, near miss, abnormal condition, or event that exposes a weakness in the original assumptions.
Frequently asked questions
What is the purpose of a bow-tie workshop?
Who should participate in the workshop?
How many controls should a bow-tie include?
Can a bow-tie replace a job safety analysis?
When should the bow-tie be reviewed again?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.