Risk Management
Bow-Tie Analysis of Critical Risks
Preventive versus mitigating barrier counts and integrity for the entity's most critical risks.
Why Bow-Tie Analysis for Critical Risks
For the handful of risks that could derail service delivery or trigger a disclaimer, a simple likelihood-impact score is too blunt to guide control investment. Bow-tie analysis maps the preventive barriers that stop a risk materialising and the mitigating barriers that limit its consequences, giving the audit committee a clear view of where defences are thin. AuditPro Core counts and scores these barriers for each critical risk so the entity can prove, in COSO and King IV terms, that critical exposures are actually controlled.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Critical risks mapped
12
Degraded barriers
23
of 148
Preventive barriers
84
Mitigating barriers
64
weaker flank
Barrier integrity by critical risk
Weakest barriers by critical risk
| Risk | Weakest barrier | Side | Integrity % |
|---|---|---|---|
| Data breach | Incident response plan | Mitigating | 42 |
| Water supply failure | Maintenance schedule | Preventive | 51 |
| Service unrest | Community engagement | Preventive | 48 |
| Financial collapse | Liquidity reserve | Mitigating | 55 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Anatomy of a Bow-Tie
A bow-tie places the top event in the centre, the threats and preventive barriers on the left, and the consequences and mitigating barriers on the right. It makes visible, on one diagram, the entire defence line around a single critical risk.
Preventive versus Mitigating Barriers
Preventive barriers reduce the likelihood the event occurs at all; mitigating barriers reduce the damage once it has. A risk defended only on one side is dangerously exposed regardless of how many controls it appears to have.
Barrier Integrity
Counting barriers is not enough — each must be tested for whether it actually works and is operating as designed. A degraded or untested barrier offers false comfort and should be treated as absent.
Single Points of Failure
Where one barrier is doing all the work, its failure leaves the entity defenceless. Bow-tie analysis is especially good at exposing these single points of failure for targeted reinforcement.
How AuditPro Core Bridges the Gap
- Barrier mapping: preventive and mitigating barriers are catalogued against each critical risk and counted on both sides of the bow-tie.
- Integrity scoring: barriers carry a tested-effectiveness rating so degraded defences are not mistaken for working ones.
- Exception workflow: risks with thin or single-sided barrier coverage are escalated to the risk owner for reinforcement.
- Traceability to source: each barrier links to the control record and its latest test evidence for assurance review.
Key Takeaways
- Bow-ties show the full preventive and mitigating defence line around a critical risk on one view.
- A risk defended on only one side is exposed no matter how many controls it lists.
- Untested or degraded barriers should be treated as if they are not there.
- The technique excels at exposing single points of failure for targeted reinforcement.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
