Beyond prevention: seeing both sides of critical risk
When organisations talk about risk controls, the conversation often focuses on one question:
What are we doing to stop this from happening?
It is an essential question, but it is only half of the picture.
For significant and critical risks, organisations also need to ask:
If the event still happens, what will reduce the harm?
Bow-tie risk management helps answer both questions by separating controls according to when they operate: before an event or after it.
Understanding both sides of an event
At the centre of a bow-tie analysis is the event an organisation is trying to manage.
On one side are Preventative Controls. These are intended to stop the event from occurring or reduce its likelihood.
They might include:
- physical guards and barriers;
- isolation procedures;
- equipment inspections;
- competency requirements; and
- safe operating procedures.
On the other side are Recovery Controls. These come into play if the event occurs and are intended to reduce its consequences or limit the resulting harm.
Examples include:
- emergency shutdown systems;
- rescue plans;
- first-aid and emergency response procedures;
- spill containment equipment; and
- evacuation processes.
Looking at both sides gives organisations a more complete view of how a risk is being managed. It moves the conversation beyond “we have controls” to the rather more useful question: what do those controls actually do?
Why the distinction matters
A long list of controls can create an impression of strong risk management. But quantity alone does not show whether an organisation is prepared for both prevention and response.
A critical risk might have several well-documented Preventative Controls but no clear Recovery Control. If the preventative measures fail, the organisation may have little in place to limit the consequences.
The reverse can also occur: an organisation may have strong emergency arrangements but insufficient controls for reducing the likelihood of the event in the first place.
Classifying controls as Preventative or Recovery makes this imbalance easier to recognise.
Making control gaps visible
The value of bow-tie thinking is not the shape of the diagram. It is the visibility it provides.
When controls are organised around when they operate, teams can more easily identify:
- risks with controls on both sides of the event;
- critical risks without a documented Recovery Control;
- an over-reliance on one type of control;
- critical controls that require closer monitoring;
- controls connected with incidents; and
- areas where further review may be needed.
This does not automatically determine whether a risk is adequately controlled. That still requires professional judgement, knowledge of the work and an understanding of how effective each control is in practice.
What it does provide is a clearer structure for asking better questions.
Better incident learning
The distinction also adds valuable context during an incident investigation.
When a control is found to have been absent, ineffective, failed or not followed, knowing its intended role helps explain the failure more clearly.
Was it a Preventative Control that should have stopped the event? Or was it a Recovery Control that should have reduced the consequences?
That distinction can help investigators understand whether the event occurred because prevention failed, whether the outcome became more serious because recovery measures failed, or whether weaknesses existed on both sides.
It also supports more targeted corrective action. Strengthening an emergency response process will not correct a missing preventative barrier, just as adding another procedure may do little to improve an ineffective recovery system. Risk management does enjoy punishing vague solutions.
From a static register to active control management
Traditional risk registers can become static collections of hazards, ratings and control descriptions. Bow-tie functionality makes the relationship between risks and controls more meaningful.
By classifying controls according to their purpose, organisations can:
- review the balance of control coverage;
- focus assurance activities on critical controls;
- connect incident findings with control performance;
- report on preventative and recovery coverage; and
- prioritise critical risks with obvious control gaps.
This helps turn the risk register into a more active tool for reviewing how important risks are managed—not simply a record that proves someone completed a form.
Practical bow-tie capability in Engage
Engage brings this approach into the existing Risk Register by allowing individual controls to be classified as Preventative or Recovery.
The classification can be carried through risk views, incident-control links and reporting, helping organisations see how their controls operate across both sides of an event.
Rather than requiring teams to maintain a separate graphical model, the functionality connects bow-tie thinking with the risk, incident and reporting processes they already use.
For organisations getting started, critical risks are the natural place to begin:
- Identify the event being managed.
- Review the controls intended to prevent it.
- Identify the controls intended to reduce harm if it occurs.
- Check whether important controls exist on both sides.
- Review how those controls are verified and monitored.
The aim is not to create a perfectly symmetrical bow tie. Risk, inconsiderately, rarely arranges itself that neatly.
The aim is to create a clearer and more useful picture of what stands between a critical risk and a serious outcome.
Interested in having a closer look at Engage? Click here to contact us today.
