The Consequence Side: Six Points Where Escalation Can Still Be Interrupted
The consequence side of the Operations BowTie follows a different logic: these are the outcomes once the top event has occurred and mitigation falls short. The article maps the escalation pathway from loss of demonstrated Ex condition through uncontrolled ignition source to fire or explosion, and marks six points where Operations can still interrupt the chain. The last of these is restart, where automatic resumption is the trap. The closing definition of the role: know when control is being lost, which barriers are degraded, when to intervene, when to STOP, and what evidence is required before the plant starts again.

Head of Operations asked me for another session to address potential consequences as per outcome of BOWTIE assessment on operational Ex.
On the consequence side, the logic changes again. These are are the possible outcomes once the Top Event has occurred and mitigation is insufficient.
For the Head of Operations, the POI becomes: At what point can Operations still interrupt escalation, protect people/assets, or prevent one consequence from cascading into the next?
See potential consequences below
The first two items form an escalation pathway:
TOP EVENT
Plant outside demonstrated Ex-safe condition
↓
Uncontrolled ignition source
↓
Explosive atmosphere + effective ignition source coincide
↓
FIRE / EXPLOSION
↓
People | Assets | Production | Legal | Compliance | Business
POI 1 - Loss of demonstrated Ex condition
→ assess / restore / compensate / restrict / STOP
POI 2 - Ignition control uncertain/lost
→ isolate ignition source / de-energize / restrict
POI 3 - Explosive atmosphere may coexist with ignition source
→ immediate make-safe / ESD / evacuation as applicable
POI 4 - Fire/explosion occurs
→ emergency response
POI 5 - After event stabilization
→ preserve evidence / investigate / assess damage
POI 6 - Restart requested
→ do not automatically restart → Correct → Verify → Authorize → Return to Service
The controlled cycle should be:
Incident → stabilize → investigate → identify failed/degraded barriers → correct → verify Ex integrity → update EPD/HAC/Ex Register/MoC where affected → authorize → return to service
So the final Head of Operations outcome should actually be:
The plant is returned to a demonstrated Ex-safe condition before production resumes.
That closes the entire BowTie loop:
Threat → Preventive Barrier → Degradation → TOP EVENT → Mitigation → Consequence → Recovery → Verification → Safe Return to Service
An overall definition of the Head of Operations role:
Know when control is being lost.
Know which barriers are degraded.
Know when to intervene.
Know when to STOP.
And know what evidence is required before allowing the plant to START again.