🔍 Introduction to the Tool
Barrier Analysis is a technique used to identify how and why a failure or risk was not prevented. It focuses on the effectiveness of existing safeguards—called “barriers”—designed to stop undesired outcomes. This tool is especially helpful in Internal Audit and Project Management when reviewing incidents, non-conformances, or risk exposure. It helps organizations understand which barriers failed, were missing, or were bypassed.
🛠 Template for Applying Barrier Analysis
The following steps provide a practical approach:
-
Step 1: Identify the Undesired Event
Clearly define the incident, error, or failure being analyzed. -
Step 2: List Existing Barriers
Include all preventive, detective, and corrective controls intended to stop the event. -
Step 3: Assess Barrier Status
For each barrier, ask: Was it effective, missing, or failed? -
Step 4: Determine Why Barriers Failed
Analyze the cause behind each barrier failure. -
Step 5: Recommend Improvements
Propose how to strengthen or implement better barriers.
🏢 Example – ACME Corp: Data Breach Incident
ACME Corp’s Internal Audit team, led by Auren, investigated a data breach that exposed client records. The incident was analyzed using Barrier Analysis.
-
Undesired Event: Unauthorized access to sensitive data.
-
Barriers Reviewed:
-
Password security (ineffective – default credentials used)
-
Multi-factor authentication (missing)
-
Access logs monitoring (failed – alerts not configured)
-
Project Manager Aven and the IT Team were involved in the review. CEO Liora mandated corrective action: implement MFA, audit user access monthly, and automate security alerts. A follow-up audit showed improved compliance and no further breaches.
Conclusion: Barrier Analysis helped ACME identify control weaknesses that directly led to the breach. By focusing on what failed and why, Auren and team built stronger defenses and reduced future risk exposure.