Profile picture for user mkli

Coming out of the summer break we already had several very interesting sessions in our product team and with customers. We discussed approaches and capabilities for GRC platforms. So I suddenly felt the need to draw for myself a new overview how everything belongs together. There will be some new things that need to be fitted into the picture. 

How everything belongs together

Where we still see room for improvement is the way how risks are identified - still the main driver is  the one or other regulatory issue. This approach invariably leads to the question: "What control library should I use?" I try to encourage to break down business objectives first to identify the risks that are really endangering the success of a company - that may be but also not be regulatory risk.

One of the new things I had to fit into the picture is Bow Tie Modeling. With the next ARIS service release we expanded our modeling methodology to support this approach which allows to analyze a risk scenario in depth without loosing yourself in too much detail. Especially in risk intensive businesses like energy providers this risk analysis and description methodology has become more and more popular. The success of this diagram lies in its clear structure and simplicity which is easy for the non-specialist to understand, but still has sufficient depth for an expert discussion. The basic idea is to combine the cause (threats) with the consequence via the risk event. The diagrams main strength lies in scenarios where clear, independent paths lead to the occurrence of a risk event or consequence. They focus on controls to be established and thus form the basis for actively managing the risk situation.

I made a small example to show you how it could look like:

bow tie model - demo

I'm convinced that Bow Tie modeling will offer our customers risk officers a great new way to make their risk scenarios understood by management.

As usual I appreciate any ideas and comments on this - we will elaborate on some other "new things" in the next weeks.

by Geoff Hook
Posted on Thu, 10/13/2011 - 11:50

Maybe the GRC simulation could be added as part of 'responding to the Risk' ?

by Martin Kling Author
Posted on Thu, 10/13/2011 - 13:15

Geoff - you're totally right, I missed that great capability to decide on which measures (controls) are helping to reduce the damages or even prevent the risk event to take place. (I edited the overview)

by Florian Canicas
Posted on Tue, 07/17/2012 - 10:19

Hi Martin!

Thank you for your post on this topic. I am really interrested in this model, as it would perfectly fit some of my needs. I have a concern though, how would you best link this type of model with a process, like a monitoring process of installation for instance?

by Martin Kling Author
Posted on Tue, 07/17/2012 - 16:36

Florian, the idea of the bow-tie was to be assigned to a risk. So the natural answer would be to model a risk into the ePC/VACD and then assign the bowtie to the risk.

by maitrey ahuja
Posted on Wed, 02/26/2014 - 08:55


I am trying to analyse bow tie diagram vs business control diagrams.

Are they replaceable with each other . I understand that Bow tie diagram might be applicable to  certain indsustries.


Could you provide some insights into their comparative view.


Thank You.

by Martin Kling Author
Posted on Fri, 02/28/2014 - 11:37

Maitrey, of course those two diagrams are related and both assigned to a risk but hey are not replaceable.

The bow tie goes into detail explaining the cause and effect situation of a complex risk scenario, the BCD defines the relationship between a risk and its mitigating controls and furthermore defines how a given control should be tested/assessed. Thus the BCD gives direct input to the workflows of ARIS Risk & Compliance Manager while the bow tie is more on a descriptive level.

Hope that helps.

Cheers, Martin


Featured achievement

Say hello to the ARIS Community! Personalize your community experience by following forums or tags, liking a post or uploading a profile picture.
Recent Unlocks
  • SS
  • MZ
  • Profile picture for user kbiront
  • Profile picture for user Tony Iliev
  • Profile picture for user amandeep.7.singh
  • PacMan


icon-arrow-down icon-arrow-cerulean-left icon-arrow-cerulean-right icon-arrow-down icon-arrow-left icon-arrow-right icon-arrow icon-back icon-close icon-comments icon-correct-answer icon-tick icon-download icon-facebook icon-flag icon-google-plus icon-hamburger icon-in icon-info icon-instagram icon-login-true icon-login icon-mail-notification icon-mail icon-mortarboard icon-newsletter icon-notification icon-pinterest icon-plus icon-rss icon-search icon-share icon-shield icon-snapchat icon-star icon-tutorials icon-twitter icon-universities icon-videos icon-views icon-whatsapp icon-xing icon-youtube icon-jobs icon-heart icon-heart2 aris-express bpm-glossary help-intro help-design Process_Mining_Icon help-publishing help-administration help-dashboarding help-archive help-risk icon-knowledge icon-question icon-events icon-message icon-more icon-pencil forum-icon icon-lock