Combined Control Effectiveness in BowTie Pro

Overview 

In a BowTie, no single control carries the whole burden of managing a risk. Threats and consequences are held in check by the combination of controls working together. Each control is a barrier that should either eliminate the hazard, reduce how often it occurs, or lessen its potential consequences — and it is the collective strength of these barriers, not any one of them alone, that determines how well the risk is managed.

How It Works

Each control acts as a barrier standing in the path of a threat or a consequence. Crucially, the hazard or consequence only materialises when every control on that pathway fails — and which side of the BowTie you are on decides whether that failure lets a top event occur or a consequence unfold.

This is the idea captured by James Reason’s “Swiss cheese” model: each barrier is a slice of cheese, and each slice has holes — its weaknesses. A single hole rarely matters, because the next slice covers it. Only when the holes in every slice happen to line up can a hazard pass all the way through.

Controls can take many forms, including physical systems, operational systems, and procedures already in place.

Caption: Risk only materialises when the gaps in every barrier line up — the essence of combined control effectiveness.

How Many Controls Do We Need?

Sometimes the number of controls needed for a threat or consequence is set by predefined rules, judged as suitable and sufficient for the level of risk. Where that approach is used, the rules should be agreed up front so the method is applied systematically rather than case by case.

One example of such a rule set graduates the requirement by risk level:

Intolerable Risk Risk Reduction Tolerable Risk
Threat Controls Minimum 3 independent effective control Minimum 2 independent effective control Minimum 1 effective control
Consequence Controls Minimum 3 independent effective control Minimum 2 independent effective control Minimum 1 effective control
Controls for the Threat to the Controls Minimum 2 independent effective controls Minimum 1 effective control Minimum 1 effective control
Trap: The danger with a numbers-driven approach is that, to hit the required count, controls often turn out not to be truly independent — if the first fails, the others fail with it — or the same control is simply reworded to make up the numbers.
Tip: In many cases a more pragmatic approach, supported by rigorous peer review, works better than chasing a target number.

The Key Principle: Independence and Effectiveness

For combined protection to hold, each control needs to be both independent and effective.

  • Independent means one control’s failure does not drag the others down with it. If a single power cut, a single person, or a single system failure can disable several “separate” controls at once, they were never really independent — and the Swiss cheese slices all have their holes in the same place.
  • Effective means the control genuinely does the job it’s credited with, reliably, under the conditions that matter.

Weak or dependent controls give a false sense of security: the diagram looks well protected, but the real-world resilience isn’t there.

Practical Considerations

  • Avoid duplicating similar controls. Three variations on the same measure aren’t three barriers — they’re one barrier with one shared weakness.
  • Prioritise reliability. A smaller number of dependable, independent controls beats a long list of fragile ones.
  • Favour quality over quantity. The goal is genuine protection, not an impressive count.

How Much Is Enough? The ALARP Principle

A common rule is that risk should be reduced to a level that is ALARP — “as low as reasonably practicable.” This means weighing a risk against the trouble, time, and money required to control it further.

“Reasonably practicable” is a narrower idea than “physically possible.” In essence, the risk owner must weigh the size of the risk on one side against the sacrifice — in money, time, or effort — needed to avert it on the other. If there is a gross disproportion between the two, with the risk being insignificant compared to the sacrifice required to reduce it further, then it is not reasonably practicable to do more.

Note: The precise legal wording of the ALARP test comes from case law and is quoted in full on the original BowTie Pro™ knowledge base page. The description above is a plain-English paraphrase — refer to the source for the exact legal definition.

Summary

Effective risk management in a BowTie doesn’t come from any single barrier, but from how well multiple controls work together. Independent, effective controls, layered so their weaknesses don’t overlap, are what stop the holes in the Swiss cheese from ever lining up. Adding more controls only helps if they are genuinely independent and reliable — and the ALARP principle provides a sensible test for knowing when enough has been done.

Get Started Today







    By submitting this form, you agree that BowTie Pro may use your details to respond to your enquiry. We will never share your information with third parties without your consent. See our Privacy Policy for more information.