
A completed HAZOP worksheet is dense with information: causes, deviations, consequences, and safeguards, all recorded row by row across dozens of nodes. Anyone who sat through the study can read it. Anyone who didn’t, an incoming operations manager, a new HSE lead, an auditor reviewing the file five years later, usually can’t. Bowtie analysis in process safety exists partly to solve exactly that problem, and the HAZOP to bowtie conversion is how a facility gets there: turning cause-local tabular data into a single diagram that shows the whole risk picture for a specific hazard, threats, barriers, and consequences, in one view.
This guide walks through the practical mechanics of the HAZOP to bowtie conversion: what maps to what, where teams typically get it wrong, and how the process changes when the facility sits under GCC, India, or Southeast Asian regulatory oversight. It assumes you already have a completed or near-complete HAZOP worksheet in hand. If you need a primer on HAZOP itself before converting it, our guide to HAZOP, FMEA, and bow-tie fundamentals covers the underlying methodologies first.
Why a HAZOP Worksheet Alone Doesn’t Show the Full Risk Picture
IEC 61882 structures HAZOP around a cause-local, consequence-global principle: each row documents one cause, its consequence, and the safeguards addressing that pairing. This works well for systematic deviation coverage but poorly for judging whether a hazard is fully controlled, which is the gap bowtie analysis in process safety is built to close.
The limitation isn’t a flaw in HAZOP itself. It’s a structural side effect of recording one cause and one consequence per row. A single hazard, such as loss of containment from a storage vessel, may be triggered by six or seven separate causes across multiple guide-word discussions, each with its own safeguard entry buried in a different part of the worksheet. Reading the table in sequence gives no sense of how those safeguards distribute across the hazard as a whole. A reviewer scanning fifty rows cannot easily tell whether prevention and mitigation are balanced, or whether one cause is carrying three overlapping safeguards while another has none.
This is precisely the gap the HAZOP to bowtie conversion closes. It reassembles the scattered rows around a single top event and makes the barrier picture visible in one diagram instead of fifty.
Mapping HAZOP Fields to Bowtie Elements
The HAZOP to bowtie conversion requires mapping four HAZOP fields, cause, consequence, safeguard, and node deviation, onto three bowtie elements: threat, consequence, and barrier. The top event is typically not a literal HAZOP field; it is inferred from the shared hazard that multiple causes and consequences have in common.
The mapping is mechanical once the source data is organized correctly, but it depends on discipline that most HAZOP worksheets don’t enforce by default. A cause recorded in isolation on row 14 and a related cause on row 31 need to be recognized as threats to the same top event before the bowtie can be assembled. Safeguards must also be split by function: those stopping the cause from developing into the top event belong on the prevention side, and those limiting harm after the top event occurs belong on the mitigation side. IEC 61882 does not require this split in the worksheet itself, which is why it has to be applied deliberately during the HAZOP to bowtie conversion.
| HAZOP Field | Bowtie Element | Notes |
| Cause | Threat (left side) | Multiple causes across different worksheet rows may map to the same threat if they describe the same failure mechanism |
| Node deviation / hazard | Top event (centre) | Inferred from the shared hazard, not a literal HAZOP column |
| Safeguard (cause-side) | Preventive barrier | Stops the threat from developing into the top event |
| Safeguard (consequence-side) | Mitigative barrier | Limits harm once the top event has occurred |
| Consequence | Consequence (right side) | Retains its severity classification from the HAZOP entry |

A structured HAZOP-to-bowtie mapping table like this one, built before the diagram itself, prevents the single most common error teams make when they convert HAZOP to a bowtie diagram: safeguards assigned to the wrong side of the top event.
Recognized for excellence.
PROJECTS DELIVERED ACROSS THE GLOBE
Applying the Conversion in GCC, India, and Southeast Asia Facilities
Regulators across GCC, India, and Southeast Asia increasingly expect bowtie diagrams as supporting evidence for ALARP demonstrations, not as a replacement for the underlying HAZOP. OISD-governed Indian facilities and GCC operators such as ADNOC and KOC typically require the bowtie to stay traceable to the specific HAZOP causes and safeguards it was built from.
This traceability requirement changes how the HAZOP to bowtie conversion should be documented. A bowtie built for internal team communication only needs to show barriers clearly. A bowtie built to support a safety case, an OISD-mandated process safety management review, or a PESO explosive-license renewal needs each barrier annotated with a reference back to its originating HAZOP row and node number. Without that reference, an auditor reviewing the bowtie independently of the HAZOP cannot verify that a barrier shown on the diagram was actually credited during the original study, which weakens the ALARP argument the bowtie is meant to support.
GCC and India-based process safety teams generally handle this by adding a short reference code to each barrier label, tying it back to the HAZOP node and cause number. This single addition preserves the audit trail through review cycles, MOC, and periodic HAZOP revalidation, and it is the detail most often missing from a rushed HAZOP to bowtie conversion.
Common Mistakes When Converting a HAZOP Into a Bowtie
Three mistakes account for most of the rework teams face after a HAZOP to bowtie conversion: treating bowtie as a hazard-identification method, letting safeguards default entirely to the prevention side, and losing the cause-consequence link during manual transfer between formats. Each mistake is avoidable once a team recognizes it as a pattern.
Bowtie analysis does not identify new hazards. It develops and visualizes hazards that a HAZOP, HAZID, or equivalent PHA technique has already identified. A team that skips the HAZOP and starts directly with a bowtie session risks missing hazard scenarios that a systematic guide-word review would have caught. The second mistake, safeguard imbalance, shows up constantly once a HAZOP is actually converted: worksheets frequently list strong preventive safeguards but leave the consequence side almost bare, because facilitators focus discussion time on stopping the cause rather than limiting the aftermath. The third mistake, losing traceability during manual transfer, happens when a team copies causes and safeguards into diagramming software without preserving the original HAZOP row references, making the bowtie impossible to audit against its source data later.
Catching the safeguard imbalance during the HAZOP to bowtie conversion, rather than after, is the single highest-value outcome of doing this exercise properly. It surfaces exactly which consequences have no meaningful mitigation in place.
A Step-by-Step Method for Building the Bowtie from Your HAZOP Output
The HAZOP to bowtie build sequence follows a defined order: select the top event, extract and consolidate threats, extract and consolidate consequences, classify safeguards by function, and verify traceability back to the source worksheet before the diagram is finalized. Each stage builds directly on the mapping established earlier in this guide.

A structured HAZOP to bowtie build sequence includes:
- Select the top event: identify the specific hazard, such as loss of containment or loss of control of energy, that will sit at the centre of the diagram
- Extract all causes linked to that hazard across every relevant HAZOP node, not just one row
- Consolidate duplicate or overlapping causes into single threats, keeping a reference to every originating row
- Extract all consequences linked to the same hazard, retaining their HAZOP severity classification
- Classify every safeguard as preventive or mitigative based on whether it acts before or after the top event
- Verify that each threat and each consequence has at least one credited barrier, flagging any gap for follow-up
- Cross-check the finished diagram against the original HAZOP worksheet to confirm no cause, consequence, or safeguard was dropped during transfer
Step 6 is where most of the practical value shows up. A bowtie that reveals a consequence with zero mitigative barriers is not a diagram problem; it is a finding that belongs in the HAZOP action register, whether or not the original study flagged it. Teams working under IEC 61511-governed safety instrumented systems often find this step of the HAZOP to bowtie process surfaces gaps that later feed directly into a SIL determination and LOPA study, since a bowtie barrier gap frequently points to a safeguard that needs to be re-evaluated for independence and effectiveness.
Frequently Asked Questions
A HAZOP to bowtie conversion maps each HAZOP cause to a bowtie threat, each consequence to a bowtie consequence, and each safeguard to a preventive or mitigative barrier around a shared top event. IEC 61882 governs the underlying HAZOP structure. The result reveals barrier gaps that the row-by-row worksheet format tends to hide.
A HAZOP to bowtie conversion runs through five stages: select the top event, extract and consolidate threats, extract and consolidate consequences, classify safeguards by function, and verify traceability against the original worksheet. Skipping the traceability check is the most common source of later audit findings. Each stage should reference the originating HAZOP node and row number.
Best practice for a HAZOP to bowtie conversion separates safeguards into preventive and mitigative categories before building the diagram, since HAZOP worksheets rarely make this split explicit. Tackle one top event per session rather than attempting multiple hazards at once. Annotate each barrier with its source HAZOP row to preserve traceability through future revalidation cycles.
No. Bowtie analysis develops and visualizes hazards that a HAZOP or HAZID study has already identified; it is not a hazard-identification method itself. Skipping the HAZOP risks missing scenarios that systematic guide-word review would catch. Facilities still need a documented PHA before building bowties from it, and IEC 61882 remains the reference standard for that underlying study.
A HAZOP cause is recorded per row against a single consequence, while a bowtie threat consolidates every cause across the worksheet that leads to the same top event. Multiple HAZOP rows often collapse into one threat during conversion. This consolidation is what reveals the true barrier count protecting a given hazard.
Safeguards that stop a cause from developing into the top event become preventive barriers on the left side of the bowtie. Safeguards that limit harm after the top event has occurred become mitigative barriers on the right side. HAZOP worksheets list safeguards without this distinction, so the classification has to be applied manually during conversion.
Yes. iFluids Engineering manages the full HAZOP to bowtie conversion for clients, developing bowtie diagrams directly from HAZOP output while preserving traceability to the source worksheet for ALARP and safety case submissions. This service supports facilities across GCC, India, and Southeast Asia. Details are available on our<a href=”https://ifluids.com/bow-tie-analysis/”> </a><mark style=”background-color:rgba(0, 0, 0, 0)” class=”has-inline-color has-vivid-red-color”><a href=”https://ifluids.com/bow-tie-analysis/”>bowtie analysis service page</a>.</mark>
Conclusion
The HAZOP to bowtie conversion is not a formatting exercise. It reorganizes cause-local worksheet data around a shared top event, and in doing so, exposes exactly where prevention and mitigation barriers are unbalanced, information a row-by-row HAZOP table rarely makes visible on its own. This is why bowtie analysis in process safety has become a standard follow-on step after major-hazard HAZOP studies across GCC, India, and Southeast Asia.
The practical takeaway for process safety teams: build the HAZOP-to-bowtie mapping table before touching diagramming software, classify every safeguard as preventive or mitigative as you go, and keep a reference back to the source HAZOP row on every barrier. That discipline is what keeps the bowtie auditable years later, particularly for facilities operating under OISD, PESO, or GCC operator safety case requirements where traceability back to the original study is expected, not optional.
Teams converting a HAZOP into a bowtie for the first time often find the safeguard imbalance step alone justifies the exercise. For a structured walkthrough of related process safety management requirements that intersect with bowtie development, see our process safety management programs page, or speak to our process safety team about building a bowtie from your existing HAZOP output.





