Most bowties are reviewed on a calendar, not on evidence. How to close the loop between what your investigations find and the barriers your risk model still claims are working.
Somewhere on a shared drive there is a bowtie for your highest-consequence hazard. A facilitator built it in a workshop, a room full of experienced people argued about it for a day, and it was good work. It has a review date on it, probably twelve months out. In the months since, your organisation has run investigations that found barriers on that diagram doing nothing at all, and the diagram has not been told.
That gap is the ordinary state of bowtie practice, and it is not a failure of the people involved. The bowtie lives in the risk function and the findings live in the investigation function, and nothing joins them except somebody remembering.
An annual review asks a room to remember what changed. The evidence that should drive that review has been sitting in investigation reports the whole time, in far more detail than anybody will recall twelve months later. When a haul truck access ladder fails because the anti-slip tread was worn to a third of its surface, that is not just an incident finding. It is a measurement of a barrier the bowtie claims is holding.
The better trigger is an event. Every investigation that touches a modelled hazard is an evidence-backed review of the barriers on that diagram, run by people who have just spent weeks looking closely at them.
An ICAM investigation examines absent or failed defences as a matter of course. That is the DF family, and it is doing bowtie work under a different name: DF asks which controls should have stopped this and why they did not. The information the risk model needs has already been gathered, argued over and evidenced. It is simply recorded somewhere the risk model cannot see.
A useful barrier finding is more precise than a note saying the control did not work. Four states carry different corrective work, and they are worth separating every time:
That last distinction matters more than any of the others. A barrier that people routinely go around is telling you something about the task, not about the people doing it. Recording it as bypassed keeps the conversation on the system.
Escalation factors are the conditions that undermine a control while leaving it apparently in place: the inspection with no defined threshold, the permit issued without the check it depends on, the alarm that has been in nuisance mode for months. They are the hardest part of a bowtie to populate in a workshop, because by definition nobody has noticed them yet.
Investigations find them constantly. A pre-start checklist with a single generic tick where a specific measurement was needed is an escalation factor discovered the expensive way. Feeding it back onto the diagram is how a workshop artefact becomes a live model.
None of that requires a new program. It requires the investigation and the risk model to be the same system rather than two documents. In SafetyPulse a failed-barrier finding is linked to the barrier it belongs to, so control health reflects what your own events have shown rather than what the last workshop assumed. If you want the method itself, with no software in the way, ICAM Australia publishes a full written guide to bow tie risk analysis.
SafetyPulse by ICAM Australia Pty Ltd. ICAM training and methodology.