Table of Contents
If you work in process safety or HSE in the oil and gas industry, you have almost certainly been asked to prepare or review a bowtie risk analysis. Most fresh graduates struggle here initially, not because the concept is difficult, but because nobody walks them through the actual document preparation process end to end.
This guide does exactly that. Using a real-world water injection facility scenario as the reference, you will learn how to build a complete bowtie risk analysis report from scratch – threats, barriers, consequences, critical controls, risk ratings, and action plans – the way it is done on live projects governed by API RP 14C, IEC 61511, and ISO 31000.
What Is Bowtie Risk Analysis in Oil and Gas?

Bowtie risk analysis is a structured process safety methodology that visually maps the relationship between causes, controls, and consequences around a single central hazardous event. In oil and gas, that central event is almost always a Loss of Containment (LOC), an uncontrolled release of hydrocarbons or process fluids under pressure.
The name comes from the shape of the diagram. On the left side, you list all the threats, the causes that could trigger the top event. On the right side, you list the consequences of what happens if the event occurs. In the middle sits the top event itself. Prevention barriers sit on the left side of the bow; recovery barriers sit on the right.
Unlike a simple risk matrix, bowtie risk analysis forces you to think about both prevention and recovery simultaneously. That is why major operators and regulators in the oil and gas sector require it for high-hazard facilities.
Why Bowtie Risk Analysis Matters More Than a Risk Matrix
A risk matrix tells you the risk level. A bowtie risk analysis tells you why that risk level exists and what is stopping it from getting worse.
Site conditions often change faster than design assumptions. A maintenance window might temporarily disable a pressure safety valve. A competency gap might exist in the night-shift crew. A corrosion inhibitor might be under-dosed due to a chemical supply issue. None of these show up on a static risk matrix, but every one of them shows up as a degraded barrier on a bowtie diagram.
For oil and gas engineers, the practical value is clear: BowTie risk analysis gives you a living document that connects daily operational decisions to major accident hazard risk. That is precisely why API RP 14C and IEC 61511 reference barrier management as a core safety function and why ISO 31000 positions it within a broader risk management framework.
Step 1: Define the Hazard and the Top Event

Every bowtie risk analysis begins with two locked definitions: the hazard and the top event. Get these wrong and the entire analysis drifts.
The hazard is the source of potential harm in oil and gas; this is almost always a process fluid under pressure. For a water injection facility, the hazard is produced water mixed with hydrocarbons at elevated pressure and temperature (design pressure 48.8 barg and design temperature 150°C in a typical configuration).
The top event is the precise moment of loss of control, not a consequence, not a cause. For hydrocarbon containment studies, the top event is always stated as ‘Uncontrolled Loss of Containment (LOC) Hydrocarbon Release’.
A common mistake junior engineers make is to define the top event too broadly (“fire and explosion”) or too narrowly (“flange leak on pump suction”). The top event must be the pivotal moment: the instant containment is lost. Everything before that moment is a threat; everything after is a consequence.
Document this clearly at the top of your report with the facility name, system boundary (injection piping, pump P-100, suction filters, valves and flanges) and the applicable operating conditions. This becomes the scope anchor for the entire analysis
Step 2: Identify and Classify Threats (Left Side of the Bowtie)
Threats are the causes that could lead directly to the top event. For a hydrocarbon release scenario at a water injection facility, five primary threats typically emerge:
T1 Corrosion and erosion of piping or equipment (high likelihood): High water cut service with H₂S presence accelerates internal corrosion rates significantly. Under NACE MR0175 requirements, material selection must account for sour service conditions.
T2 Mechanical failure of pump seals and flanges (high likelihood): Centrifugal pumps like P-100 in injection service operate under continuous load. Seal failures are the single most common LOC source in pump skid areas. API 682 governs seal flush plan selection for this reason.
T3 Overpressure from process upset or control failure (medium likelihood): Loss of DCS communication, a fouled pressure relief valve, or an incorrect setpoint on the pressure safety valve – any one of these can lead to overpressure transients that exceed design limits.
T4 Third-party or excavation damage to buried pipework (low likelihood): Low frequency but high consequence. Inadequate as-built drawing control is the primary escalation factor here.
T5 Operational error: Wrong valve operation or isolation failure (medium likelihood): Fatigue, shift handover failures, and time pressure during operations are the real escalation factors. This is where Lockout/Tagout (LOTO) and Permit to Work (PTW) systems earn their value.
For each threat, assign a likelihood rating (high / medium / low) based on facility-specific data, incident history, and engineering judgement. Document the escalation factors, the conditions that make each threat more likely to overcome its barriers. Reviewers and auditors pay close attention to escalation factors because they reveal where barrier performance is most at risk.
Step 3: Define Prevention Barriers for Each Threat
Prevention barriers are the controls that sit between each threat and the top event. They stop the threat from reaching the LOC.
For each barrier, you must be specific. “Good maintenance” is not a barrier. “Preventive maintenance programme per API 610 with documented inspection intervals for pump P-100” is a barrier.
Here is how the prevention barrier structure looks for the five threats above:
| Threat | Prevention Barriers |
| Corrosion / Erosion | Corrosion inhibitor injection system; piping inspection programme (UT/RT); corrosion monitoring probes; material selection per NACE MR0175 |
| Pump seal / flange failure | Preventive maintenance programme; mechanical seal flush plan per API 682; vibration monitoring; torque specifications for flanged joints |
| Overpressure | Pressure safety valves are set at the correct relief pressure. High-pressure trips (PAHH), pressure relief to soakaway, and PCS alarm management system |
| Excavation damage | Buried pipe marking and signage; Permit to Excavate / Dig Safe procedure; as-built drawing review before any dig |
| Operator error | LOTO procedure, Permit to Work system, operating procedures (SOPs) displayed at workstation, and operator competency training |
Four barriers per major threat is a reasonable minimum for high-consequence scenarios. Fewer than three barriers on a high-likelihood threat should immediately trigger an action to add controls; this is a recognised gap.
Step 4: Define Consequences and Recovery Barriers (Right Side of the Bowtie)

Once the top event occurs once containment is lost, the question becomes, ‘How bad can it get, and what stops it from getting worse?’
Consequences in a hydrocarbon release scenario typically cascade across five categories:
C1 Ignition leading to explosion and fire (catastrophic): Multiple fatalities are possible if ignition sources are present and ESD systems fail to isolate the release in time.
C2 flash fire causing personnel injuries and burns (major): wind direction and exclusion zone management become critical variables. PPE adequacy determines injury severity.
C3 Environmental contamination of soil and groundwater (major): Bund and berm integrity, regulatory notification timelines, and the effectiveness of the environment management plan (EMP) all govern the extent of impact.
C4 Loss of production due to unplanned shutdown (Moderate): The speed of isolation via emergency isolation valves (EIV) and the availability of depressurisation procedures directly affect the duration of production loss.
C5 Reputational damage and regulatory penalty (Moderate): Media exposure and a history of non-compliance amplify this consequence. Community liaison becomes a mitigation control.
Recovery barriers must be mapped to each consequence pathway. For C1 and C2, the critical recovery barriers are the Emergency Shutdown System (ESD), fixed gas and flame detection, fire and gas alarm to the control room, and the Emergency Response Plan (ERP). For C3, spill containment bunding, environmental spill response kits, and regulatory authority notification procedures take priority.
Step 5: Identify and Document Critical Controls
Not all barriers are equal. Critical controls are the barriers whose failure would most significantly increase the probability of the top event or the severity of its consequences. These must be called out separately with clear performance standards and accountable owners.
For a water injection hydrocarbon release scenario, the seven critical controls are:
- Pressure Safety Valves (PSVs) annual testing with a 100% pass rate is required. Owner: Mechanical Engineering.
- Emergency Shutdown System (ESD) monthly proof test; trip must occur within 2 seconds. Owner: Instrument Engineering.
- Fixed gas and flame detection quarterly calibration; zero false alarms target. Owner: Instrument Engineering.
- Permit to Work (PTW) 100% compliance with no violations; monthly audit. Owner: HSE Lead.
- Corrosion Inspection Programme inspections per schedule with no overdue items. Owner: Inspection Engineering.
- Operator competency training: 100% certification with annual refresh. Owner: Training Manager.
- Emergency Response Drill: biannual drills with all deficiencies closed within 30 days. Owner: HSE Manager.
The performance standard for each critical control is not optional; it is the measurable definition of what “the barrier is working” looks like. Without it, you cannot assure barrier effectiveness during audits or management reviews. operator competency training if you want to understand how this fits into a structured training framework, see our Comprehensive Training in Process & Technical Safety Study.”
Step 6: Complete the Risk Rating Table
The risk rating table is where the bowtie analysis converts qualitative barrier assessment into a structured risk picture. For each threat-consequence pair, record:
- Inherent risk: the risk level with no barriers in place
- Number of barriers in place: count of active, functional controls
- Residual risk: the risk level after barriers are applied
- Target risk: the acceptable risk level for this facility
- Action required whether additional controls are needed
A well-prepared risk rating table looks like this:
| Threat → Consequence | Inherent Risk | Barriers | Residual Risk | Target | Action? |
| Corrosion → Explosion | Critical | 4 | High | Medium | Yes, increase inspection frequency |
| Pump seal failure → Explosion | Critical | 4 | High | Medium | Yes, review PM schedule |
| Overpressure → Flash fire | High | 4 | Medium | Low | Monitor only |
| Excavation damage → Spill | Medium | 3 | Low | Low | No action required |
| Operator error → Shutdown | High | 4 | Medium | Low | Yes, competency reassessment |
Wherever residual risk exceeds target risk, an action must be raised. This is non-negotiable. A bowtie risk analysis that identifies a gap but raises no action is not a risk management tool; it is a liability document.
Step 7: Build the Action Plan

Every gap identified in the risk rating table must translate into a time-bound, owner-assigned action item. For the water injection facility scenario, six critical actions emerge:
- Increase ultrasonic thickness (UT) inspection frequency on injection piping to every three months, assigned to inspection engineering; target 30 days.
- Review and update pump P-100 preventive maintenance schedule per API 610 assigned to mechanical engineering; target 15 days.
- Conduct a full ESD functional test and update trip records assigned to Instrument Engineering, targeting 20 days.
- Re-assess operator competency for all field operators through practical assessment assigned to HSE Lead; target 30 days.
- Update the Emergency Response Plan to include water injection station scenarios assigned to the HSE Manager; target 45 days.
- Install an additional fixed gas detector at the pump P-100 skid area assigned to Instrument Engineering, subject to budget approval.
Track action status (open, in progress, closed, or pending budget) at every project review meeting. The action plan is what turns a bowtie analysis from a paper exercise into an operational risk management tool.
How Often Should a Bowtie Risk Analysis Be Reviewed?
The standard industry requirement is annual review, plus a mandatory review after any significant incident, near miss, or process change. If the facility design pressure changes, a new threat pathway is identified, or a critical control is found to be non-functional during an audit, the bowtie must be updated immediately, not at the next scheduled review.
In practice, the most effective organisations integrate bowtie critical control status into their monthly HSE dashboards. Overdue PSV tests, lapsed operator certifications, and expired gas detector calibrations are all tracked as leading indicators against the bowtie’s critical control performance standards.
Bowtie Risk Analysis vs HAZOP: When to Use Each

HAZOP (Hazard and Operability Study) and bowtie risk analysis are complementary, not competing methods. HAZOP identifies what can go wrong using a guide word methodology applied to process deviations; it is the discovery tool. Bowtie risk analysis takes the major accident hazards identified through HAZOP and structures the barrier management strategy around them.
In practice: conduct a HAZOP first, extract the major accident hazard scenarios, and then build bowtie diagrams for each top event. The barriers identified in the bowtie then feed directly into your Safety Instrumented System (SIS) design under IEC 61511 and your inspection and maintenance planning under API RP 14C.
Key Takeaways for Oil and Gas Engineers
Bowtie risk analysis oil and gas applications demand precision, specificity, and engineering rigour at every step. Here is what separates a professional bowtie risk analysis report from a template exercise:
- The top event must be defined exactly as loss of containment, not a consequence or a cause.
- Every barrier must be specific and verifiable, not generic.
- Escalation factors must be documented for each threat they reveal where barriers are most vulnerable.
- Critical controls must have performance standards and named owners, not just a list.
- Residual risk above target risk must generate a tracked, time-bound action.
- The document is reviewed annually, and after every significant change it is never filed and forgotten.
Master these seven steps, and you will produce a bowtie risk analysis report that stands up to regulatory scrutiny, supports major accident hazard management, and .If you want to go deeper into consequence modelling, our Advanced Quantitative Risk Assessment (QRA) Masterclass with PHAST & Safeti covers the next layer of analysis.
Frequently Asked Questions
What is bowtie risk analysis in oil and gas?
Bowtie risk analysis in oil and gas is a process safety methodology that maps all causes (threats) and consequences of a central hazardous event, typically a loss of containment, and documents the prevention and recovery barriers that control each pathway. It is used to manage major accident hazard risk under standards including API RP 14C, IEC 61511, and ISO 31000.
What is the difference between bowtie risk analysis and HAZOP?
HAZOP identifies process deviations and hazards through a systematic guide word study. Bowtie risk analysis takes the major accident hazards from HAZOP and structures barrier management around them. HAZOP is the hazard identification tool; bowtie risk analysis is the barrier management tool.
What are the 5 steps of a bowtie risk analysis?
Define the hazard and top event; identify threats and prevention barriers on the left side; identify consequences and recovery barriers on the right side; classify critical controls with performance standards; complete the risk rating table and action plan.
What is a top event in the bowtie methodology?
The top event is the central undesired event, the precise moment of loss of control. In oil and gas, this is almost always defined as ‘uncontrolled loss of containment’ (LOC). It is not a cause and not a consequence; it is the pivotal point between them.
How do you identify critical controls in a bowtie?
Critical controls are barriers whose failure would most significantly increase the probability of the top event or the severity of its consequences. They are identified by asking, ‘If this barrier were absent or failed, would the risk level increase substantially?’ Each critical control must have a measurable performance standard and an accountable owner.
Is bowtie risk analysis required by API RP 14C?
API RP 14C addresses surface safety systems for offshore production and references barrier management as a core safety function. While it does not mandate bowtie diagrams by name, bowtie risk analysis is the industry-accepted methodology for implementing and demonstrating barrier management compliance under API RP 14C requirements.
Do HSE engineers in oil and gas need to know bowtie risk analysis for jobs?
Yes, bowtie risk analysis is a core competency for process safety and HSE roles in oil and gas. Major operators, EPC contractors, and HSE consultancies expect engineers to be able to prepare, review, and update bowtie risk analysis documents independently. It is frequently tested in technical interviews for process safety and HSE positions.