Guides

SIF and critical controls on a bowtie

Most organisations have plenty of controls documented. Fewer can answer, in plain English:

A bowtie is built for those questions. It puts SIF-level activities on one picture and forces you to say which controls are critical.

SIF in one paragraph

SIF means serious injury and fatality — the harm end of the scale you never want to manage by averages. High-frequency minor injuries and low-frequency life-altering events do not behave the same. A site can have a tidy all-injury rate and still be one failed critical control away from a funeral.

Bowties help because they start from the activity that can kill, not from the incident count that looks comfortable.

Critical controls in one paragraph

A critical control is a control you are relying on to prevent or limit SIF harm — one you would not allow to be skipped, bypassed or “made up for” with a toolbox talk. If that control fails, you should treat the job as unsafe for that path, not “slightly more risky”.

Critical is a label about consequence of failure, not about how impressive the control looks in a brochure.

Why a bowtie is the right map

A bowtie already separates:

  • Threats that drive a loss of control
  • Preventive controls on each threat path
  • The top event
  • Mitigative controls that only matter afterwards
  • Outcomes for people

That layout is the same layout critical control conversations need. You can point at a line and ask: if this control fails, does this threat reach the top event? If yes, and the outcome is SIF-level, that control is a candidate for critical.

A spreadsheet list of “key controls” without paths often becomes everything-is-critical — which means nothing is.

Method — map SIF exposure first

1. Choose SIF activities, not busywork

Start with activities that could kill or permanently disable someone. Typical set:

  • Working at height
  • Confined space entry
  • Excavations
  • Hot work
  • Lifting operations
  • Energy isolation / lockout
  • Vehicle and pedestrian interaction

Most organisations find somewhere between eight and fifteen. If your list has sixty “critical” activities, you have not prioritised.

2. One activity, one top event per board

Example: excavation → top event “excavation collapse”. Keep the knot clear. Mixed top events make critical-control ownership fuzzy.

3. Build threats and controls with the people who do the work

Critical controls fail in real conditions: time pressure, night shift, contractors, deferred inspections. The board must reflect that world. See bowtie vs risk assessment for how to feed findings back into paperwork.

4. Mark critical controls sparingly

On each threat path, ask:

  • Is the outcome on the far right SIF-level if this path runs away?
  • Is this control the one that materially stops that path (or materially limits harm on the right)?
  • If it failed at 2 a.m., would we stop the job?

If yes, mark it critical. Aim for a handful per board, not a red sticker on every box.

Examples of critical-leaning controls (illustrative — verify on your job):

  • Physical fall prevention that must be in place before work at height
  • Isolation proved before breaking containment
  • Trench support verified before entry
  • Atmosphere testing and controls before confined space entry
  • Exclusion of people from under a lift

Training alone rarely deserves the critical label unless it is truly the only control on a SIF path — and that situation should make you uncomfortable enough to add something stronger.

5. Record what defeats them

Critical controls need defeaters written down: overrun of inspection, temporary removal “for access”, unverified contractor competence, override of interlocks, weather changing ground conditions. Then write the response: stop criteria, escalation, who can authorise a restart.

6. Assure them on purpose

A critical control that is never checked is a story. Decide:

  • What good looks like (installed, proven, within date, competent person)
  • How often you verify
  • Who verifies
  • What happens when verification fails

Your bowtie can sit next to that assurance list. Some paid tools and enterprise suites go deep on barrier health; even a simple dashboard with review dates is better than a laminated diagram.

Preventive vs mitigative critical controls

Both can be critical.

  • Preventive critical: stops the top event (support before entry, isolation proved).
  • Mitigative critical: limits SIF outcome after loss of control (rescue capability for confined space, fall arrest where prevention has residual exposure, emergency response that actually works).

Do not let a strong left side excuse an empty right side for activities where people still enter the danger zone.

Governance without bureaucracy

Keep the operating rhythm light:

  1. Owner for each critical control (role, not a vague “site team”)
  2. Review date on the board
  3. Change triggers: method, equipment, contractor, incident, near miss, failed check
  4. Link to permit / temporary works / isolation certificates so the critical control is hard to bypass in the field

If your management system already has critical control standards, use the bowtie to show where each standard sits on the activity — not to invent a second library of words.

How Bowtie One supports this

On Bowtie One you can map activities free, with no account: threats, controls, defeaters, outcomes, control strength and type, severity and risk colouring. That is enough to run the SIF conversation and see thin spots.

Pro adds cloud save, sharing, PDF export, review dates and templates — useful when critical-control boards must live beyond one laptop browser.

Bowtie One does not claim to be a full enterprise barrier-management system. Use it to make the activity-level picture honest; connect assurance processes you already own.

Common mistakes

  • Labelling every control critical
  • Critical controls that only exist as a paragraph in a RAMS
  • No stop-work rule when a critical control is missing
  • Copying another company’s life-saving rules without mapping them to your threats
  • Reviewing the board annually while the job changes weekly

A short worked pattern (excavation)

  • Activity: working in an excavation
  • Top event: collapse
  • Critical preventive candidates: temporary works / support decision; physical support in place before entry; competent inspection
  • Defeater example: “quick job” without box → stop entry
  • Mitigative candidates: exposure limited; rescue plan and equipment ready

Full walkthrough: Excavation bowtie example.

FAQ

Is SIF the same as “high risk” on a 5×5 matrix?

Not reliably. A matrix score can bury a SIF path under “unlikely”. Treat SIF by potential severity and credibility of the path, not by whether last year was quiet.

How many critical controls should one bowtie have?

As few as you can defend. If everything is critical, prioritisation has failed. Many boards work with a small set of truly stop-the-job controls plus clear supporting controls.

Are life-saving rules the same as critical controls?

They overlap. Life-saving rules are often organisation-wide behaviours. Critical controls are activity-specific hardware, proof steps and mitigations on a bowtie path. Map rules onto boards so people see where they apply.

Do critical controls replace risk assessments?

No. They sharpen them. Keep the assessment; use the bowtie to show the SIF control story. See Bowtie vs risk assessment.

Who owns a critical control?

A named role who can stop the work and who is close enough to verify the control. Ownership that sits only in a corporate function tends to fail at the point of work.

Where should we start tomorrow?

Pick one SIF activity. Build one board. Mark no more than a few critical controls. Agree stop criteria. Brief the next shift from the picture. Then schedule the review.