A risk register lists three control measures against a hazard and marks the residual risk as Low. On paper, three controls sound like defence in depth — multiple independent layers standing between a threat and harm. In practice, on more Malaysian risk registers than most HSE teams would like to admit, those three controls share a single point of failure that nobody checked for.
This is the question a HIRARC or risk register almost never forces you to ask, and a Bowtie diagram always does: are your controls actually independent of each other, or do they just look like three separate lines on a spreadsheet?
Counting Controls Is Not the Same as Testing Them
A typical risk register entry rewards volume. Three control measures against a hazard looks more robust than one, and in a genuine sense it usually is — more barriers generally means more chances to catch a failure before it becomes a consequence. But that logic only holds if the barriers are independent: if the thing that could defeat Barrier 1 is unrelated to the thing that could defeat Barrier 2.
Take a common example: “supervisor inspection,” “permit-to-work sign-off,” and “toolbox talk before task start” listed as three separate controls against the same hazard. All three sound distinct. All three are, in practice, executed by people relying on the same shift schedule, the same workload pressure, and often the same underlying assumption about how routine the task is. If the job gets labelled “light work” and everyone downstream inherits that assumption, all three controls can fail together, for the same reason, on the same day — not because any one of them was poorly executed, but because they were never actually independent in the first place.
A risk register with three items in the control column has no mechanism to catch this. It counts controls. It doesn’t test whether they’d survive the same failure mode simultaneously.
What “Independent” Actually Means for a Barrier
In barrier-based risk management, independence has a specific, testable meaning: a barrier is independent if its failure is not caused or influenced by the failure of another barrier in the same chain. This is a harder bar than it sounds. Two engineering controls that both depend on the same power supply are not independent. Two procedural controls that both depend on the same supervisor being present and not overloaded are not independent. A physical barrier and a training-based control that both assume the same risk classification of the task are not independent — if the classification is wrong, both controls inherit the same blind spot.
This is precisely what a longer companion piece on this site — HIRARC vs Bowtie Analysis Malaysia — covers in more depth: HIRARC is not designed to test for this at all. It’s a list format, and a list has no way of representing the relationship between the items on it. Independence is a structural property of a barrier system, and a structural property can’t be evaluated from a column of text.
Why This Gap Survives Most Audits
Independence failures are hard to catch precisely because each individual control, inspected on its own, looks fine. The supervisor did inspect. The permit was signed. The toolbox talk happened. An auditor checking each item against its own record will find every control in place. What the audit doesn’t check — because most audit formats aren’t built to check it — is whether the three items share a hidden common cause that would take all three down together under one specific set of conditions.
This is the same structural issue that shows up in incident investigations built around Tripod Beta or similar systemic methods: when several barriers fail on the same day, the investigation usually finds they weren’t actually independent to begin with — they were connected by an unexamined shared assumption, a shared resource constraint, or a shared classification decision made upstream of all of them.
Testing for Independence on Your Own Risk Register
The practical test is straightforward to state, even though applying it consistently takes discipline: for any hazard with more than one listed control, ask what single event or condition could disable all of them at once. If an honest answer exists — a shared supervisor, a shared assumption about task risk level, a shared piece of equipment, a shared point in the schedule where everyone is under the same pressure — the controls are not independent, regardless of how many are listed.
This test doesn’t require abandoning the risk register. It requires adding a question the register format doesn’t ask by default. A Bowtie diagram asks it automatically, because barriers are drawn as separate, position-specific elements on a threat line — a barrier that shares a failure mode with another barrier is visually and structurally obvious once it’s drawn out, in a way it never is as a bullet point in a control-measures column.
Bilangan langkah kawalan yang disenaraikan bukan penunjuk sebenar tahap perlindungan — yang penting ialah sama ada setiap satu benar-benar bebas antara satu sama lain. Three listed controls are not automatically three real layers of protection. Whether they are depends entirely on independence — and independence is exactly what a risk register, by design, doesn’t test for.
Want to know whether your critical hazards are actually protected by independent barriers — not just multiple listed controls? Cikgu Barrier’s Bowtie Analysis training teaches Malaysian HSE teams how to test every barrier for independence and map the escalation factors that could take multiple controls down at once. Read the fuller comparison in HIRARC vs Bowtie Analysis Malaysia, or get in touch to discuss in-house delivery.