← Research library
SCHEMATEX / RESEARCH NOTEWorked analysis · Risk & reliability

Bowtie escalation factors: an air-receiver worked example

An escalation factor is not another threat. Map it to the one barrier it can degrade, then map a separate control to that degradation mechanism.

KEY RESULT2 pairs

escalation factors mapped one-to-one to the barriers they can degrade

FIGURE 01 / REPRODUCIBLE OUTPUTSVG · SCHEMATEX
Bowtie for compressed-air receiver loss of containment with overpressure and wall-thinning threats, two consequences, eight main barriers, and two escalation-factor control pairs
Rendered deterministically by Schematex 1.0.13 from the source reproduced here; the fictional barrier classification was independently checked against CAA, HSE, CCPS/EI, OSHA, and IEC guidance.

A bowtie escalation factor is a credible condition that can defeat or weaken one named barrier; it is not another threat, a generic problem, or the mere opposite of the barrier. Attach the factor to that barrier, then attach a separate escalation-factor control to the degradation mechanism. In the worked air-receiver example, “valve fouled or stuck” degrades the spring-loaded safety valve, while a scheduled functional test is the candidate control on that degradation path.

Air-receiver loss-of-containment bowtie with two degradation paths drawn below the barriers they affect
The two dashed boxes are escalation factors, not extra threats. Each drops from one barrier and has one candidate control beneath it. All equipment, pathways, and management measures are fictional and require site-specific engineering review.

Scope and terms before the worked example

IEC 31010:2019 lists bowtie analysis among the techniques used to support risk assessment. The CCPS/Energy Institute concept book treats bowties as a qualitative barrier-management method: threats approach a central loss-of-control event through preventive barriers, and consequences extend from that event through mitigative or recovery barriers. A basic bowtie shows structure; it does not calculate event frequency or certify that a control is adequate.

The terms form a causal chain:

ElementTest for classifying itAir-receiver example
hazardWhat has the intrinsic potential to cause harm?compressed air stored under pressure
threatWhat credible cause can lead directly toward loss of control?pressure exceeds the receiver limit
preventive barrierWhat can interrupt the threat before loss of control?spring-loaded safety valve
top eventAt what precise point is control of the hazard lost?loss of receiver containment
consequenceWhat direct harmful outcome can follow the top event?personnel exposed to the stored-energy release
mitigative barrierWhat can reduce likelihood or severity after the top event?restricted receiver area
escalation factorWhy might one particular barrier be defeated or weakened?safety valve fouled or stuck
escalation-factor controlWhat manages that degradation mechanism?scheduled functional test

The UK Civil Aviation Authority's current bowtie guidance supplies a useful discriminator: an escalation factor cannot directly cause the top event or consequence. If it can, classify it as a threat or consequence pathway instead. The factor should explain how or why a control becomes less effective, not merely rename the control in negative form.

Worked scenario, inputs, and assumptions

This is a fictional stationary air receiver in a workshop. It stores compressed air, has a defined safe operating limit, and is assumed to fall within a jurisdiction that requires a competent pressure-systems review. The diagram is a classification exercise, not a design basis.

The two left-wing threats are excess pressure and internal wall thinning. Candidate preventive barriers are a compressor pressure cut-out, a spring-loaded safety valve, condensate draining, and competent-person examination. The two direct consequence statements are personnel exposure to a stored-energy release and damage to adjacent equipment. Candidate mitigative barriers include access restriction, emergency response, separation or shielding, and post-event isolation.

Those choices have a factual anchor but are not a universal control set. HSE states that qualifying UK workplace pressure systems need a written scheme of examination and examination by a competent person. In the United States, OSHA 29 CFR 1910.169 separately addresses drains, visible pressure gauges, spring-loaded safety valves, relieving capacity, isolation between the receiver and safety valve, and regular safety-valve testing. The two legal regimes are cited as examples, not combined into a new international rule. The actual location, receiver specification, maximum allowable working pressure, relief capacity, inspection scheme, and applicable code must control a real assessment.

Reproducible Schematex source

bowtie "Air-receiver loss of containment"
layout: compact
legend: bottom

hazard "Compressed air stored under pressure"
topevent "Loss of receiver containment"

threat "Pressure exceeds the receiver limit"
  prevent "Compressor pressure cut-out"
  prevent "Spring-loaded safety valve"
    escalation "Valve fouled or stuck"
      barrier "Scheduled functional test"

threat "Internal wall thinning"
  prevent "Condensate draining"
  prevent "Competent-person examination"

consequence "Personnel exposed to stored-energy release"
  mitigate "Restricted receiver area"
    escalation "Temporary storage defeats the exclusion zone"
      barrier "Marked boundary and area inspection"
  mitigate "Emergency shutdown and response"

consequence "Adjacent equipment damaged"
  mitigate "Separation and physical shielding"
  mitigate "Post-event isolation and inspection"

Schematex 1.0.13 strictly parsed this source with no diagnostics on August 29, 2026. The renderer found exactly one top event, two threats, two consequences, eight main barriers, and two escalation factors. Its current bowtie syntax reference defines the indentation: prevent or mitigate belongs to a wing, escalation nests under the barrier it degrades, and the deeper barrier line controls that escalation factor.

Trace the two escalation-factor pairs

Pair 1: a preventive barrier can be unavailable

The spring-loaded safety valve is on the excess-pressure threat line. “Valve fouled or stuck” is not modeled as another independent source of excess pressure. It matters here because it can stop the named relief barrier from doing its job when challenged. That makes it an escalation factor.

“Scheduled functional test” then acts on the degradation question: can the organization detect and correct the stuck or fouled condition before demand? It is a candidate escalation-factor control, not proof that the valve is suitable. A real performance standard would still have to define the responsible owner, applicable test method and interval, pass/fail criteria, impaired-barrier response, records, and relationship to the governing code.

Pair 2: a mitigative barrier can be defeated

“Restricted receiver area” is on the consequence side because it does not prevent containment loss; it is intended to limit exposure if loss occurs. Temporary storage that occupies the marked zone can defeat that access and separation function. The storage condition therefore hangs from that specific mitigative barrier.

“Marked boundary and area inspection” is the candidate control on the storage-encroachment mechanism. It does not stop excess pressure, repair a thinned wall, or restore containment. This narrow scope is the point. UK CAA guidance says an escalation-factor control manages the condition reducing another control's effectiveness; it should not be drawn as though it acts directly on the threat.

Checks and invariants

Use these checks before accepting a bowtie for review:

  1. One hazard, one loss-of-control point. “Compressed air stored under pressure” is the hazard; “loss of receiver containment” is the top event. Do not merge the thing with harmful potential and the moment control is lost.
  2. Threat test. Each left-edge item can progress toward the top event. A degradation factor that cannot do that without first defeating a named barrier stays attached to the barrier.
  3. Consequence test. Each right-edge item follows from the top event, not directly from one preferred threat.
  4. Barrier-path test. Every threat and consequence has at least one main barrier. Schematex enforces this structural minimum, but it cannot decide whether the barrier is physically effective.
  5. Specific attachment. Replace “poor maintenance” or “human error” with the observable mechanism and the exact barrier affected. Generic factors create an unreadable diagram and weak assurance actions.
  6. Control-on-factor test. The escalation-factor control manages the degradation condition. It is not a duplicate of the original barrier.
  7. Barrier-quality test. CCPS conference guidance summarizes the desired main-barrier attributes as effective, independent, and auditable. A box on a diagram is not evidence that those tests pass.
  8. Status and ownership test. Record owner, performance expectation, current impairment, evidence, and action due date outside or alongside the diagram. HSE expects control measures to be monitored and their vulnerability to deterioration and failure to be reviewable.

Failure modes, limitations, and review boundary

Common failures are putting “barrier fails” beneath every barrier, treating training as a universal repair, calling a scheduled task an effective barrier without acceptance criteria, mixing preventive and mitigative functions, and assigning the same vague factor to the entire bowtie. Another error is adding probability-reduction numbers to a qualitative bowtie without a defined quantitative model. If frequency, conditional dependence, or uncertainty matters, link the scenario to a reviewed fault tree, event tree, LOPA, or other appropriate analysis rather than inventing arithmetic inside the graphic.

The diagram also omits many real pressure-system questions: receiver design and fabrication code, relief sizing and discharge routing, control-system architecture, corrosion mechanism, inspection scope, maintenance isolation, environmental exposure, occupancy, projectile and blast effects, emergency planning, and local legal duties. “Scheduled” deliberately has no invented interval. The competent person and applicable rules must set it.

Paste the source into the Schematex playground, then run one classification challenge with the review team: move “valve fouled or stuck” to the threat column and ask whether it can cause containment loss when pressure remains within limits. If the answer is no, return it to the safety-valve barrier and define the evidence that would reveal the degradation. Repeat that test for every escalation factor before adding more boxes.

References

  1. International Electrotechnical Commission. Risk management - Risk assessment techniques. IEC 31010:2019, Edition 2.0, 2019. https://webstore.iec.ch/en/publication/59809 Accessed August 29, 2026. [Paywalled]
  2. Center for Chemical Process Safety and Energy Institute. Bow Ties in Risk Management: A Concept Book for Process Safety. First edition, 2018. https://ccps.aiche.org/publications/books/bow-ties-risk-management-concept-book-process-safety Accessed August 29, 2026. [Paywalled]
  3. Charles Ian Cowley, Center for Chemical Process Safety. More Effective Bow Ties and Better Siting and Layout of Facilities. 4th Global Summit on Process Safety, 2017. https://proceedings.aiche.org/ccps/conferences/ccps-global-summit-on-process-safety/2017/proceeding/paper/more-effective-bow-ties-and-better-siting-and-layout-facilities Accessed August 29, 2026. [Paywalled]
  4. UK Civil Aviation Authority. Step 7: Identify Escalation Factors. 2026. https://www.caa.co.uk/safety-initiatives/working-with-industry/bowtie/bowtie-elements/escalation-factors/ Accessed August 29, 2026.
  5. UK Civil Aviation Authority. Step 8: Identify Escalation Factor Controls. 2026. https://www.caa.co.uk/safety-initiatives/working-with-industry/bowtie/bowtie-elements/escalation-factor-controls/ Accessed August 29, 2026.
  6. UK Health and Safety Executive. Major Hazard Regulatory Model. First published February 2013; amended December 2018, 2018. https://www.hse.gov.uk/regulating-major-hazards/assets/docs/major-hazards-regulatory-model.pdf Accessed August 29, 2026.
  7. UK Health and Safety Executive. Pressure Systems Safety Regulations 2000 (PSSR). Web guidance updated December 9, 2025, 2025. https://www.hse.gov.uk/pressure-systems/pssr.htm Accessed August 29, 2026.
  8. Occupational Safety and Health Administration. Air receivers. 29 CFR 1910.169, Current e-CFR text accessed August 29, 2026, 2026. https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.169 Accessed August 29, 2026.
  9. Schematex Project. Bowtie Risk Diagram syntax reference. Schematex 1.0.13 documentation, 2026. https://schematex.js.org/docs/bowtie Accessed August 29, 2026.

Cite this article

Ray Whitfield. “Bowtie escalation factors: an air-receiver worked example.” Schematex Research. Version 2026-08-29. Updated August 29, 2026. https://schematex.js.org/research/bowtie-escalation-factor-worked-example