Back to Explore
🧭

Risk Management

Bow-Tie Analysis of Critical Risks

Preventive versus mitigating barrier counts and integrity for the entity's most critical risks.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why Bow-Tie Analysis for Critical Risks

For the handful of risks that could derail service delivery or trigger a disclaimer, a simple likelihood-impact score is too blunt to guide control investment. Bow-tie analysis maps the preventive barriers that stop a risk materialising and the mitigating barriers that limit its consequences, giving the audit committee a clear view of where defences are thin. AuditPro Core counts and scores these barriers for each critical risk so the entity can prove, in COSO and King IV terms, that critical exposures are actually controlled.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Critical risks mapped

12

Degraded barriers

23

of 148

Preventive barriers

84

Mitigating barriers

64

weaker flank

Barrier integrity by critical risk

Weakest barriers by critical risk

RiskWeakest barrierSideIntegrity %
Data breachIncident response planMitigating42
Water supply failureMaintenance schedulePreventive51
Service unrestCommunity engagementPreventive48
Financial collapseLiquidity reserveMitigating55

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Anatomy of a Bow-Tie

A bow-tie places the top event in the centre, the threats and preventive barriers on the left, and the consequences and mitigating barriers on the right. It makes visible, on one diagram, the entire defence line around a single critical risk.

Preventive versus Mitigating Barriers

Preventive barriers reduce the likelihood the event occurs at all; mitigating barriers reduce the damage once it has. A risk defended only on one side is dangerously exposed regardless of how many controls it appears to have.

Barrier Integrity

Counting barriers is not enough — each must be tested for whether it actually works and is operating as designed. A degraded or untested barrier offers false comfort and should be treated as absent.

Single Points of Failure

Where one barrier is doing all the work, its failure leaves the entity defenceless. Bow-tie analysis is especially good at exposing these single points of failure for targeted reinforcement.

How AuditPro Core Bridges the Gap

  • Barrier mapping: preventive and mitigating barriers are catalogued against each critical risk and counted on both sides of the bow-tie.
  • Integrity scoring: barriers carry a tested-effectiveness rating so degraded defences are not mistaken for working ones.
  • Exception workflow: risks with thin or single-sided barrier coverage are escalated to the risk owner for reinforcement.
  • Traceability to source: each barrier links to the control record and its latest test evidence for assurance review.

Key Takeaways

  • Bow-ties show the full preventive and mitigating defence line around a critical risk on one view.
  • A risk defended on only one side is exposed no matter how many controls it lists.
  • Untested or degraded barriers should be treated as if they are not there.
  • The technique excels at exposing single points of failure for targeted reinforcement.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.