JSA vs Bow-Tie vs Critical-Control Verification: Which Evidence Should a Supervisor Trust Before High-Risk Work?
JSA, Bow-Tie analysis, and critical-control verification answer different safety questions. This comparison shows which method should lead before high-risk work, what evidence each method can prove, and where supervisors are most likely to mistake paperwork for control.

Key takeaways
- 01Match the method to the decision, because JSA, Bow-Tie analysis, and critical-control verification answer different questions.
- 02Use Bow-Tie analysis to define high-consequence pathways and barrier ownership before the work package is built.
- 03Use a JSA to adapt the control strategy to the actual task sequence, crew, tools, and temporary conditions.
- 04Use critical-control verification to prove that essential barriers are present and working before exposure begins.
- 05When evidence conflicts, pause the start decision and correct the field condition instead of relying on a completed form.
F3 deep comparative for supervisors, EHS managers, and operations leaders
A crew is ready to begin a high-risk task, and three documents are open on the supervisor's desk. The job safety analysis describes the steps, the Bow-Tie diagram shows threats and consequences, and the critical-control checklist says several barriers were verified. Which document should decide whether the work starts?
The answer is not always the document with the most detail. A JSA, a Bow-Tie analysis, and critical-control verification serve different decisions. The JSA explains how the task will be performed. Bow-Tie analysis explains how a hazardous event could develop. Critical-control verification tests whether the barriers that prevent a serious consequence are present and working now. Treating them as interchangeable creates a polished record without a reliable start decision.
What decision must the evidence support?
The right method is the one that answers the decision in front of the supervisor. Before choosing a tool, define whether the team needs to understand the task sequence, design the barrier system, or confirm that a serious consequence is controlled at the point of work.
That distinction matters because risk is not static. A document written during planning may describe an acceptable arrangement, while the field condition has changed after a late delivery, a missing guard, a weather shift, or a different crew composition. ISO 45001:2018 expects organizations to manage hazards and operational controls, but it does not turn one form into proof that every barrier remains effective.
James Reason's work on latent failures is useful here. A visible unsafe condition may appear during execution even though earlier decisions about design, maintenance, procurement, planning, or supervision created the opportunity. The method selected before work begins should therefore expose the failure pathway that the decision-maker actually needs to control.
For leaders who need to separate risk acceptance from field proof, Risk Criteria Explained provides a useful companion. The present comparison focuses on the evidence used immediately before high-risk work.
Which evaluation criteria separate the three methods?
A practical comparison uses six criteria. First, consider primary question, because each method is built around a different inquiry. Second, consider best timing, since planning evidence and execution evidence are not the same. Third, check unit of analysis, meaning whether the method examines task steps, an accident pathway, or a specific barrier.
The fourth criterion is field sensitivity. Can the method detect that the actual workplace differs from the plan? Fifth is decision ownership. Does the output make it clear who can stop, redesign, or release the work? Sixth is failure exposure. What dangerous assumption remains hidden when the method is used alone?
These criteria prevent a common procurement mistake. A site buys a template because it looks familiar, then asks that template to answer questions it was never designed to answer. The issue is not whether the document is technically correct. The issue is whether the document provides decision-grade evidence for the next action.
When should a JSA lead the decision?
A JSA should lead when the main decision concerns how the task will be performed safely from step to step. It is strongest when the work has a defined sequence, the hazards can change during that sequence, and the crew needs to agree on controls before starting.
A useful JSA connects each major task step to its hazards, controls, responsible person, and verification point. It should not merely list hazards beside a generic control such as “use PPE” or “follow procedure.” The supervisor needs to see what changes at the point where the task moves from preparation to execution, where energy is introduced, or where people and equipment interact.
The JSA is particularly valuable for non-routine maintenance, simultaneous operations, temporary work, and tasks whose risk depends on the order of actions. It helps the crew identify whether isolation, access, lifting, communication, tools, and emergency arrangements are ready before the first step begins.
Its limitation is equally important. A JSA can describe a sound method while leaving a critical barrier untested. A crew may write that a lifting device will be inspected, for example, without proving that the correct device is available, that its capacity is suitable, or that the exclusion zone is actually established. The JSA records the intended method. It does not automatically prove that the barrier exists in the field.
Supervisors should also resist turning the JSA into a signature ritual. If the document is completed after the crew has already positioned equipment, the tool has lost much of its preventive value. The strongest JSA is brief enough to use at the worksite and specific enough to change the work when a condition is different.
When does Bow-Tie analysis provide the better view?
Bow-Tie analysis should lead when leaders need to understand how threats can reach a top event and how consequences are contained afterward. Its value is architectural. It connects initiating threats, the top event, preventive barriers, consequences, and mitigating barriers in one causal view.
This method is useful when the hazard is high consequence, the control system contains several independent layers, or ownership is distributed across engineering, maintenance, operations, and emergency response. A Bow-Tie can show that a barrier is not simply a line in a procedure. It may depend on design integrity, inspection, alarm response, competence, supervision, or recovery capacity.
The method is also useful for deciding which controls deserve critical status. A barrier that prevents a major release or protects a person from a fatal energy may require a higher standard of performance, assurance, and escalation than a control that reduces a minor inconvenience. The analysis helps the organization see that difference before a checklist is built.
Its limitation is timing. A Bow-Tie is normally a system-level analysis, not a substitute for a pre-job conversation. It may show that an isolation barrier is essential, but it does not prove that the isolation was applied correctly on this shift. It may identify emergency response as a mitigating barrier, but it does not confirm that access, equipment, communications, and trained responders are ready today.
A Bow-Tie can also become decorative if the team treats every control as equally effective. The diagram should distinguish barriers that are engineered, administrative, dependent on human response, or vulnerable to common failure. Otherwise, the visual simplicity hides the operational weakness it was meant to expose.
When should critical-control verification decide whether work starts?
Critical-control verification should decide the start when a specific barrier must perform to prevent a serious or fatal consequence. It is the most field-sensitive of the three methods because its central question is immediate: is the required control present, functional, and owned before exposure begins?
Verification should be built around observable evidence. For energy isolation, that may include the correct isolation point, lock identification, test result, and release authority. For confined-space entry, it may include atmospheric testing, communication, rescue readiness, and control of unauthorized access. For work at height, it may include a suitable anchor, inspected equipment, edge protection, and a rescue arrangement that can be executed rather than merely described.
The method becomes stronger when each critical control has a performance standard, a verifier, a timing requirement, and an escalation path. “Check the control” is too vague. “Confirm the isolation is identified, locked, tested, and accepted by the authorized person before entry” gives the supervisor a decision rule.
Critical-control verification does not replace task planning. Without a JSA or equivalent work review, the team may verify a barrier while missing a new interaction created by the task sequence. It also does not replace Bow-Tie analysis, because the organization needs a reasoned basis for deciding which controls are critical and what consequence they prevent.
The main trap is false completion. A checklist can be marked complete while the barrier is weak, bypassed, unavailable, or owned by nobody with authority to correct it. Verification should therefore include a response to failure. If a critical control cannot be confirmed, the correct output is not a red box on a dashboard. It is a changed plan, a delayed start, or a different method of work.
How do the three methods compare in the field?
The comparison becomes clearer when each method is matched to the evidence it can legitimately provide. A JSA provides task-specific reasoning and crew alignment. Bow-Tie analysis provides a causal model and barrier architecture. Critical-control verification provides current evidence about the performance of selected barriers.
| Dimension | JSA | Bow-Tie | Critical-control verification |
|---|---|---|---|
| Primary question | How will this task be performed? | How could the hazardous event develop? | Is the essential barrier working now? |
| Best timing | Before and during task preparation | During hazard and barrier design | Immediately before and during exposure |
| Strength | Sequence, interaction, and crew understanding | System view, ownership, and barrier logic | Observable field proof and escalation |
| Main weakness alone | Can describe controls without proving them | Can remain too abstract for the shift | Can verify barriers without explaining the full task |
| Best owner | Supervisor with the work team | Risk owner with technical contributors | Authorized verifier and accountable operations leader |
The table shows why a single-tool program is usually a design failure. The tools overlap enough to create confusion, yet differ enough that one cannot reliably substitute for the others.
What sequence works best before high-risk work?
The most reliable sequence is to design the barrier logic, adapt the task method, and verify the critical controls. Bow-Tie analysis usually comes first for the high-consequence hazard because it establishes which threats, consequences, and barriers matter. The JSA then translates that understanding into the actual task sequence, crew arrangement, tools, and temporary conditions. Critical-control verification follows at the point where the supervisor must decide whether exposure can begin.
The sequence is not rigid. A routine task may need a short JSA and a focused critical-control check, while a major process change may require Bow-Tie analysis before the work package is written. A field discovery can also force the team backward. If the JSA reveals an unanticipated interaction, the risk owner may need to revisit the Bow-Tie or redesign the barrier.
That review loop is a strength, not a process failure. A method that changes the work after new evidence appears is doing its job. The failure occurs when the organization protects the original plan because the form has already been signed.
Which method should a supervisor trust when evidence conflicts?
When the evidence conflicts, the supervisor should trust the unresolved field condition over the completed document and pause the start decision. A signed JSA cannot compensate for a missing critical control. A Bow-Tie cannot compensate for an unverified isolation. A checklist cannot compensate for a task sequence that introduces a hazard outside the original analysis.
The supervisor should identify the conflict, state which assumption is no longer valid, assign the person who can correct it, and define the evidence required for release. If the correction changes the task, the JSA must be revised. If it changes a barrier or consequence pathway, the risk owner should reassess the system logic. If a critical control remains uncertain, the work should not proceed on the strength of administrative completion.
Andreza Araujo's work in safety culture emphasizes the distance between declared control and operated control. That distinction is especially important before high-risk work, because the decision is not whether the organization owns a procedure. The decision is whether the people facing the exposure have a reliable barrier at the moment it matters.
What should leaders build into the program?
Leaders should define the role of each method in the management system rather than asking every team to invent its own interpretation. The program should specify when a Bow-Tie is required, which barriers qualify as critical, when a JSA must be refreshed, who can verify each control, and what happens when verification fails.
Training should focus on decision quality rather than document completion. Supervisors need practice distinguishing an intended control from an observable control, and they need permission to delay work when the evidence is incomplete. The review should also examine whether corrections are made at the level that created the weakness, which may be design, planning, procurement, maintenance, staffing, or supervision rather than the final operator.
A useful management review asks three questions. Did the method change the work? Was the critical barrier independently verified? When evidence conflicted, did the organization correct the condition or simply record the exception? Those questions reveal more about control strength than the number of completed forms.
How should a plant choose between JSA, Bow-Tie, and verification?
Choose a JSA when the immediate challenge is task sequence and crew coordination. Choose Bow-Tie analysis when the organization needs to understand a high-consequence pathway and assign barrier ownership. Choose critical-control verification when the start decision depends on proof that a specific barrier is working at the worksite.
For serious work, use them as a connected system. Bow-Tie analysis explains why a barrier matters, the JSA explains how the task will protect it, and verification establishes whether exposure can begin. The central test is simple, although the evidence behind it must be specific: can the supervisor show which barrier prevents the consequence, how the task preserves it, and what proves it is ready now?
That is the difference between a safety document that describes intention and a safety decision that controls exposure.
Frequently asked questions
Is a JSA the same as a Bow-Tie analysis?
Can critical-control verification replace a JSA?
When should a supervisor use Bow-Tie analysis?
What should happen when a critical control cannot be verified?
Which method is best before high-risk work?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.