Two methods, two outputs
| Bowtie | Layer of protection analysis | |
|---|---|---|
| Output | Barrier map | Numeric event frequency |
| Input | Hazard, top event, threats, consequences, barriers | Initiating event frequency, layer probabilities, conditional modifiers |
| Tests | Effective, independent, auditable | Effectiveness, specificity, independence, dependability, auditability |
| Decision | Are the barriers adequate | Is the frequency below the tolerable criterion |
The backbone of the numeric side
The mitigated event frequency is the initiating event frequency multiplied by the probabilities of failure on demand of every independent protection layer. If the result exceeds the tolerable criterion, either another layer is added or a safety function is defined and the required integrity level is derived from it.
Five tests are harder than three
Not every barrier in a bowtie counts as an independent protection layer. One measured rule is sharp: only one layer may be credited within the same basic control system. Counting two functions of one system as two layers makes the arithmetic optimistic and the real protection look larger than it is.
Which one, when
- Structure unclear, team not sharing one picture → bowtie.
- Structure clear, question is "is it enough" → numeric analysis.
- An integrity level has to be derived for a safety function → numeric analysis is mandatory.
Using both
The most productive arrangement in practice is to treat each threat line on the left of the bowtie as a separate numeric scenario. The bowtie says which lines are worth quantifying; the numeric analysis says whether those lines are adequate.