A chronological timeline with energy or hazard source, target person or target object, and the intervening actions is available.
Barrier Analysis
Prerequisite
What needs to be finished first
Preparation
What needs to be ready before start
Whiteboard or diagramming tool with a source -> barriers -> target sketch; table with columns for barrier, existent, functional, effective, failure reason, measure; access to procedures, training logs, audit reports, logs.
One analyst with RCA experience (lead); one to three domain specialists (plant, process, protection systems); one owner of the controls under review; one sponsor with authority to approve measures.
Incident description with damage and people involved; list of existing protective mechanisms (technical, procedural, organizational); risk assessment of the system; predecessor incidents.
2-4 h
Sketch the source on the left, the target on the right, and barriers as vertical lines in between. Prepare the table. Keep procedures and reports close at hand.
Core question
The one question this method answers
Which barriers were supposed to prevent the damage, which existed, functioned, and were effective enough, and which are missing or failed?
Flow
Marker: Phase
| Step | Duration | Action | Hint |
|---|---|---|---|
1Phase 1: Sketch the line of effect | 20-30 min | Name the energy or hazard source concretely, for example 'hot hydraulic fluid at 80 C, 30 bar'. Name the target person or target object. Draw the line of effect on the whiteboard. | If the source stays abstract ('risk'), the barrier analysis cannot be carried out. A concrete physical, procedural, or organizational line of effect is mandatory. |
2Phase 2: Inventory the barriers | 30-45 min | List all existing barriers: technical (guards, sensors, emergency shutdown), procedural (approvals, checklists), organizational (training, supervision). Add a short description per barrier. | Frequently only technical barriers are seen. Procedural and organizational barriers are often the first to fail and belong in the list. |
3Phase 3: Check existence, function, and effectiveness per barrier | 45-90 min | Answer three questions separately for each barrier: Did it exist at the time of the event? Did it function technically? Was it effective enough? Add evidence to each answer. If it failed, document the failure reason. | Mixed judgments ('it was there but not good enough') are a common mistake. Three separate questions create clarity. Failure reason distinguishes technical defect, operating error, and design weakness. |
4Phase 4: Identify missing barriers | 20-30 min | Check each phase of the line of effect: which barrier is missing that could have prevented the event? Reference industry standards, best practices, and audits. Record missing barriers as separate findings. | Missing barriers are easily overlooked because they did not fail, they were simply absent. Search actively with the question 'what should have been there?'. |
5Phase 5: Derive measures | 30-45 min | For every failure finding, define a measure: repair, replace, strengthen, or add the barrier. Prioritize measures by impact and effort. Assign owner and deadline per measure. | A measure like 'repeat training' is often a weak answer. If the failure reason was a design weakness, training is symptom treatment. Prefer engineered solutions first. |
Artifact
What comes out at the end
Line-of-effect sketch (PNG or PDF) plus barrier table with status per column and failure reasons, list of missing barriers, measures backlog with owner and deadline. Often attached to an MORT or causal factor report.
Date, incident ID, and investigator in the header. Add a new status column for each measure iteration (open, in progress, done). For follow-up incidents, reference the previous analysis.
- Whiteboard with photo export plus spreadsheet
- Miro or Mural with a barrier template
- drawio or Lucidchart for the line-of-effect diagram
- TapRoot or Causelink for integrated RCA tools
barrier-analysis-working-template.md
Compact working template for Barrier Analysis with context, input, output artifacts, and next step.
Barrier Analysis Working Template
Goal
Analyzes which barriers should have prevented an incident and why they failed.
Context
When and for what do we use this method?
Input
Which data, observations, decisions, or materials are available?
Execution
Short notes along the runsheet.
Output artifacts
- Barrier inventory:
- Failure analysis by barrier:
- Action backlog:
Assumptions and open questions
- ...
Decision / next step
Owner, date, and success signal.
Example output
Concrete filled scenario, fictional example
barrier-analysis-beispiel.md
Concrete filled scenario, fictional example
Barrier Analysis — burn injury in maintenance room, 03.05.2026 (18.05.2026)
Source: Hot hydraulic fluid at 78 C, pressure line from pump 3. Target: Maintenance technician (@ben) during filter replacement.
Barrier table:
| Barrier | Existent | Functional | Effective | Failure reason |
|---|---|---|---|---|
| LOTO lockout (technical) | Yes | Yes | No | LOTO only on main pump, not on bypass line |
| Pressure relief routine (procedural) | Yes | No | No | Routine assumed 20 min cooling time, only 8 min waited here |
| Hot-work training (organizational) | Yes | Yes | Partly | Training does not cover the bypass scenario |
| Heat-protective PPE (technical) | No | — | — | Not provided for regular filter maintenance |
Missing barriers:
- Extend LOTO to bypass lines (industry standard ISO 14118).
- Temperature sensor with interlock logic before maintenance.
Measures:
- Extend LOTO to bypass. Owner @sabine, by 15.06.
- Design a temperature interlock. Owner @marcus, spike by 30.05., implementation in Q3.
- Add the bypass scenario to training. Owner @lisa, by 30.06.
- Evaluate heat-protective PPE for regular maintenance. Owner @anna.
Status check in 8 weeks: 17.07.2026.
Pitfalls
Recognize symptoms and steer against them
Mixed judgment on existence, function, and effectiveness
A barrier is rated as 'it was there, but it was not enough', while the failure reason stays vague.
Answer the three questions strictly separately. Use one column per question in the table. If the answer cannot be separated cleanly, gather more evidence.
Only technical barriers considered
The table contains sensors and valves, but no training, procedures, or supervision.
Walk through technical, procedural, and organizational categories as mandatory. Aim for at least one barrier per category per line of effect.
Missing barriers overlooked
Only failing barriers are listed, while absent protective layers stay invisible.
Explicitly ask 'what else should have been there?'. Use industry standards, comparable systems, and audit recommendations.
Measure = training
Three out of four findings lead to 'repeat training', with no engineered solution.
Apply the hierarchy of controls: Elimination > Substitution > Engineering > Administrative > PPE. Use training as an administrative control only when higher levels are impossible.
Line of effect too abstract
The source is described as 'risk' or 'danger', and the barriers would fit any line of effect.
Make the source concrete in physical or procedural terms. If that is not possible, Barrier Analysis is not the right tool; use a risk matrix or FMEA instead.
Stop criteria
Done signals checkable in under a minute
Finished the runsheet?
Go to the profile for purpose, similar methods, and sources or continue to the next method in the catalog.