Job safety analysis is one of the oldest and most useful ideas in occupational safety, and also one of the most reliably hollowed out. The method is simple enough to explain in a paragraph: take a specific job, break it into the steps in which it is actually performed, ask what can hurt someone at each step, and decide what will be done to prevent that. What makes it valuable is not the form it is written on. It is the act of walking a job in sequence with the people who do it, and discovering the hazards that only exist because of the order in which things happen. What kills it is volume, copying, and signatures collected in place of conversations.
The message up front: a JSA is a thinking tool that happens to leave a document behind, not a document that happens to require thinking. The two most common failures are producing them for every routine task until nobody reads any of them, and writing "be careful" or "wear appropriate PPE" in the controls column, which is the absence of a control rather than a control.
What this article is
This is a general explanation of a method, written for planners, supervisors and managers who need to understand how it works and how to judge whether theirs are any good. A job safety analysis for real work must be produced by competent people, for that specific task, site and crew, under the law that applies where the work happens. Nothing here substitutes for that, and nothing here is a form to adopt.
1. What a job safety analysis actually is
A job safety analysis is a structured examination of a single job. You name the job precisely, break it into the sequence of steps that make it up, identify the hazards present at each step, and determine the controls that will be in place for each of those hazards before the step begins. Those four elements, the job, the steps, the hazards per step, the controls per step, are the whole method. Everything else that appears on a JSA form is administration around the method rather than the method itself.
The name varies. Job safety analysis, job hazard analysis, task hazard analysis, safe work method statement in some jurisdictions, and a dozen house variants in between. The terminology argument is genuinely less interesting than practitioners make it, and it has its own home: see JSA vs JHA: what is the difference if you need the distinction settled. For this article, JSA means the task-step method regardless of what the header on your form says.
It is worth being clear about legal status, because a lot of copy on this subject is confidently wrong. In the United States, no OSHA regulation mandates a written job safety or job hazard analysis. OSHA publishes free guidance material on job hazard analysis, and guidance is not a regulation. Duties to assess hazards do exist in law in many jurisdictions: in Great Britain the risk assessment duty sits in the Management of Health and Safety at Work Regulations 1999 (SI 1999/3242), Regulation 3. Those duties oblige you to assess risk. They do not prescribe a JSA as the document that discharges them. JSA is one widely used and well proven method of doing the thinking that such duties require, chosen on merit rather than mandated by format.
On the management-system side, ISO 45001:2018 (as amended by Amd 1:2024) is certifiable and requires the hierarchy of controls at clause 8.1.2, and ANSI/ASSP Z10.0-2019 section 8.4 does the same in the United States. Neither names a JSA form. ISO 31000:2018 offers general risk management guidance and is not certifiable, and IEC 31010:2019 , never "ISO 31010", catalogues risk assessment techniques including job and task analysis approaches. That is the honest standing of the method: internationally recognised as a technique, nowhere prescribed as a form.
2. Why task-level and sequence-aware is the whole point
The distinction that makes a JSA worth doing, rather than duplicating work you have already done elsewhere, is granularity plus order. A general risk assessment is usually written at activity level or area level. It covers "electrical maintenance in the plant room" or "working in the tank farm". It produces a list of hazards that are present somewhere in that activity or that area, with controls attached to each. That is the right instrument for its job, and the process behind it is covered in the risk assessment guide.
A JSA is narrower and deeper. It covers one job, and it follows that job through time. That second property is the one that cannot be recovered from a flat hazard list, because a flat list has no concept of "before" and "after". Several classes of hazard exist only in sequence:
- Hazards created by an earlier step. A guard removed at step three is a hazard at steps four through seven and is not a hazard at step two. A line drained at step two is a different hazard from the same line at step one. An area-level list records "unguarded machinery" as a hazard with no sense of when it exists.
- Transition hazards. The moment between steps is where a great deal of harm occurs: repositioning, handing over, moving tools, climbing down, changing from one posture or location to another. Nothing productive is happening, so nothing is being watched, and these moments tend to be invisible to both the crew and the paperwork.
- Set-up and reinstatement. Getting ready and putting back are steps. They are frequently omitted, because people describe the job as the productive part and treat the bracketing work as preamble. Reinstatement in particular gets rushed, at the end of a shift, by tired people, with the pressure of finishing.
- Hazards the work itself introduces. Much of what a JSA finds is not present in the area before the crew arrives. Heat, dust, noise, temporary openings, trailing leads, disturbed insulation, restricted egress. An area-based assessment struggles to capture hazards that the job brings with it.
The test of whether a JSA was worth writing
Read it and ask: does this document contain anything that could only have been discovered by following the job in order? If every hazard on it could have been lifted from an area-level assessment, the JSA has added a page and no knowledge. Sequence is the value, and sequence is the thing copy-paste destroys first.
3. The method, and where each step goes wrong
Before working through the stages individually, it helps to see the whole method with its failure modes attached. Most poor JSAs are not poor because the author did not know the method. They are poor because one stage was skipped or faked, and the table below is a reasonable diagnostic for finding which one.
| Step of the method | What it must produce | How it goes wrong |
|---|---|---|
| Select the job | A defensible reason this job, among all jobs, justifies the effort | Everything gets one, so nothing gets attention |
| Define the job precisely | A scope narrow enough that the steps are the same every time | Scope so broad the steps have to be written generically |
| Break into steps | Steps described as actions, each with a distinct hazard profile | Too coarse and hazards hide inside a step; too fine and nobody reads it |
| Observe the real job | Steps that match what the crew actually does, not the procedure | Written at a desk, describing an imagined version of the work |
| Identify hazards per step | Hazards tied to specific steps, including transitions | A generic hazard list pasted against every step equally |
| Determine controls per step | A control for every hazard, chosen through the hierarchy | Defaults to PPE and exhortation; hazards left with no control |
| Assign ownership | A named role responsible for each control being in place | Controls written in the passive voice, owned by nobody |
| Brief and confirm understanding | A crew who can describe the hazards in their own words | Signatures collected; no conversation took place |
| Define the reassessment trigger | A stated condition on which work stops and the analysis is revisited | No trigger, so conditions change and the JSA silently expires |
| Review after the work | Corrections fed back into the next version | Filed unread; the same errors reappear next time |
4. Selecting which jobs justify a JSA
Selection is the first discipline and the one most organisations abandon. The jobs that repay the effort share recognisable characteristics:
- Non-routine work. Jobs done rarely, or never before at this location, where the crew has no accumulated feel for what goes wrong. Familiarity is itself a control, and unfamiliar work has lost it.
- Work with serious potential consequence. Not the most probable harm, the most severe credible harm. A job with a small chance of a fatality deserves more analysis than a job with a high chance of a minor cut.
- Work with a history. Incidents, near misses, or the quieter signal of repeated informal workarounds on the same task. A near miss on a job is an invitation to analyse it properly.
- New or changed tasks. New equipment, a modified procedure, a different location, a new contractor, a changed sequence. Change invalidates experience, and analysis is how you rebuild it deliberately.
- Complex multi-trade work. Where two or more crews work in the same space or in dependency on each other. The hazards of simultaneous operations are almost entirely sequence and interface hazards, which is exactly what this method is good at.
Now the counterpoint, and it is not a minor caveat. JSAs written for every routine task destroy the method. Once the expected output is a JSA per job per day, volume takes over. People copy the last one. They copy one for a job that resembles this one. The document stops being a record of thinking and becomes a record of production, and crews learn, correctly, that reading it is not worth the time because it was not written for them. An organisation with four hundred JSAs a month has no working JSA system. It has a photocopier with a safety department attached.
Where the method does not belong
Truly routine, low-consequence, well understood work is better served by a good procedure, competent people and a short pre-start conversation. Forcing a JSA onto it produces a worse document and, more damagingly, teaches everyone that JSAs are paperwork. Selectivity is not laziness. It is what keeps the instrument sharp enough to matter when it is used on the job that could kill someone.
5. Breaking the job into steps: the craft is the granularity
Decomposition is where skill shows. There is no correct number of steps, but there are two failure directions and they are easy to recognise.
Too coarse and hazards hide inside a step. "Replace the pump" is not a step, it is the job. Everything dangerous about the work is folded inside that phrase: isolating, draining, breaking the coupling, lifting, aligning, reinstating, testing. A step written at that altitude cannot carry a meaningful hazard list, so what gets written against it is generic, which is how a JSA ends up saying nothing.
Too fine and the document becomes unusable. Fifty-step analyses of a two-hour job exist, and nobody reads them. A JSA that cannot be briefed in a few minutes will not be briefed at all, and an unread analysis controls nothing regardless of how thorough it is. Thoroughness that destroys usability is not thoroughness.
The practical rule I would give: a step is a unit of work with a distinct action and a distinct hazard profile. If two consecutive activities carry the same hazards and the same controls, they are probably one step. If a single named activity carries two genuinely different hazard sets, it is probably two steps. Let the hazard profile decide the boundaries, not the elegance of the list.
Two habits improve decomposition immediately. First, describe steps as actions, not outcomes. "Isolate and lock the supply" is an action. "Equipment safe" is an outcome, and outcomes cannot be examined for hazards because they describe a state rather than something a person does. Start each step with a verb and the problem mostly solves itself. Second, include the bracketing steps. Access, set-up, and reinstatement are part of the job, and reinstatement in particular is where the rushed end-of-shift harm happens.
6. Observe the job as it is actually done
A JSA written from a desk describes the work as the author imagines it. That is not a criticism of the author, it is a description of how knowledge is distributed. The people who perform a task know things about it that appear in no procedure: which fitting always seizes, where you have to brace yourself because there is nowhere good to stand, the step everyone does in a different order because the documented order does not work with the actual layout.
So the method requires observation, with the crew, at the place. Watch the job, or walk it if watching is not possible. Ask what they do differently from the written procedure and why, and take the answer as information rather than as a finding. Workarounds are usually intelligent local adaptations to a real obstacle, and a JSA that documents the imagined sequence while the crew performs the real one is analysing a job nobody does.
This is also where the hazards get found, because the gap between written and actual work is precisely where uncontrolled hazards live: the controls were designed for the written version. General methods for finding hazards in the first place are covered in hazard identification methods and process, and the broader hazard and risk framework in HIRA.
The honest note: a JSA written by one person alone is usually a description of how that person imagines the work happens. It may be a good description, but it remains a hypothesis untested against the crew who will be asked to follow it. Moving the analysis to the workface is the highest-yield improvement available to most organisations, and it costs nothing.
7. Identifying hazards, step by step
With the steps established, each one is interrogated separately. The question is not "what hazards exist here" in the abstract, but "what could harm someone during this step, given what the previous steps have already done to the equipment and the workplace". Four categories repay deliberate attention because they are the ones that generic lists miss:
- Hazards inherent to the step. The energy, substance, height, load or mechanism that the step deals with directly. These are usually found, because they are the obvious ones.
- Hazards created by the work. What this crew brings or produces that was not here before: heat, sparks, dust, fume, noise, openings, temporary cabling, obstructed routes. These get missed when the analysis is based on an area assessment.
- Transition and set-up hazards. The gaps between steps. Moving between positions, passing tools, dismantling access, getting the last item out of a confined space. Ask explicitly what happens between step three and step four, because nobody volunteers it.
- Hazards from residual state. What an earlier step left in place: a removed guard, a partially drained system, stored energy, a lifted floor plate, an item left temporarily supported. These are the purest sequence hazards and the strongest argument for this method over a flat list.
Consider also who else is exposed. Other trades, operators, occupants, cleaners, passers by. A hazard that only harms the crew is a narrower hazard than one that reaches into an occupied space, and for a facilities audience that distinction matters constantly. Context on the broader discipline sits in what HSE means in practice.
8. Determining controls: the hierarchy, and what is not a control
Every identified hazard needs a decided control, and the controls are chosen through the hierarchy of controls rather than selected by habit. The hierarchy is a principle rather than a standalone standard. It is required by ISO 45001:2018 at clause 8.1.2 and by ANSI/ASSP Z10.0-2019 at section 8.4, and it is described on free public pages by NIOSH , which has no regulatory power. The full treatment is in the hierarchy of controls guide, and you should read it before writing controls into anything.
The discipline the hierarchy imposes on a JSA is that you must have considered elimination before you arrive at protective equipment. Can this step be removed from the job? Can the job be done at ground level, or from outside the space, or with the energy source permanently removed? Can something less hazardous be substituted? Only when those questions have been asked and answered does an engineering, then an administrative, then a personal-protection answer become the right one. The most common defect in real JSAs is not that PPE is listed. It is that PPE is listed because nothing above it was considered. Equipment selection and its limits are covered in the PPE guide.
Then the specific failure that deserves naming plainly. "Be careful", "use appropriate PPE" and "follow procedure" are not controls. They are the absence of a control, written in the space where a control should be. Each restates the objective while leaving the decision unmade, and each is unverifiable: a supervisor cannot check that someone was careful, and a crew cannot act on "appropriate" without being told what is appropriate. A control specifies what will be in place, who puts it there, and how anyone can tell whether it is.
| Written as a control, but is not one | Why it fails | Shape of a real control |
|---|---|---|
| Be careful / take care / stay alert | Restates the aim; nothing is decided, nothing can be checked | Names the physical or procedural barrier that removes the exposure |
| Use appropriate PPE | Leaves the selection to the person least placed to make it | States which protection, for which hazard, at which step, selected against an assessment |
| Follow the procedure | Points at a document instead of deciding what happens here | States the specific step of the procedure that controls this hazard, and who confirms it |
| Trained personnel only | True of all work; not specific to this hazard | Names the competence required for this task and how it is verified before start |
| Good housekeeping | A condition, not an action anyone owns | Says what is cleared, by whom, at which point in the sequence |
| Awareness of surroundings | Shifts the hazard onto the worker's attention | Segregates, barriers, or removes the interaction that required the awareness |
| Supervision | Named without saying what the supervisor does or when | States the specific check or authorisation, at a defined point, by a defined role |
One more test worth applying to a finished JSA: count the hazards, count the controls, and check that no hazard has been left without one. A hazard listed with an empty or rhetorical control column is worse than an unwritten JSA, because it is documented evidence that the risk was recognised and nothing was decided about it.
9. Assigning who does what
Controls written in the passive voice are the quietest failure in this method. "The area will be barriered." "Isolation will be verified." "Access will be restricted." Every one of those may happen and none of them is anybody's job. An unowned control is a hope.
The fix is mechanical: each control names a role responsible for putting it in place, and where the timing matters, the point in the sequence at which it must exist. Roles rather than individuals, usually, because crews change and a JSA naming a person who is on leave has a gap in it. Where a control must exist before a step can begin, say so, because that converts the control into a gate rather than an aspiration.
This is also what makes a JSA verifiable in the field: a supervisor can walk the job and ask, at each step, whether the named role has done what the analysis says. That conversation is impossible when the document is a list of conditions with no agents.
10. The reality of dynamic conditions
A JSA is written before the work and the work happens afterwards, in weather, with the equipment as found, alongside whatever else is going on that day. Conditions change. The fitting that was supposed to come off does not. Another crew arrives in the same space. The lift cannot be positioned where the analysis assumed. The scope grows by one small extra task that nobody analysed.
A method that does not account for this is a method that will be quietly abandoned mid-job. So the analysis needs a defined trigger: a stated condition on which work stops and the JSA is revisited rather than mentally adjusted. Typical triggers are a change in scope, a change in the crew, the appearance of a hazard not on the analysis, a change in the condition of the equipment or the environment, or the arrival of another party into the work area. The value of stating them in advance is that stopping becomes a planned response rather than an individual judgement call under pressure.
The cultural tell
The reliable indicator that a JSA system is real is not the quality of the documents. It is whether crews actually stop. If a stop for reassessment is treated as a delay to be explained, nobody will stop, the written trigger is decoration, and the analysis governs only the first thirty minutes of the job. If stopping is unremarkable and supported, the method is alive.
11. How a JSA relates to everything around it
A JSA is not a standalone artefact, and knowing where it sits prevents both duplication and gaps.
- The general risk assessment is upstream. It establishes the activity-level and area-level hazards and controls that the JSA inherits rather than rediscovers. See the risk assessment guide.
- The method statement sits alongside it. A method statement says how the work will be performed; the analysis says what could go wrong at each stage and what prevents it. The relationship, and the RAMS pairing, is covered in RAMS explained.
- The permit to work may require one. For higher-hazard work, a completed and accepted analysis is frequently a condition of permit issue, which gives the JSA a formal gate it otherwise lacks. See the permit to work guide, and for how permits behave inside a maintenance system, permit to work integration with a CMMS.
- The toolbox talk is how the analysis reaches the crew. The pre-start briefing is where the steps, hazards and controls are discussed and understood, and it is also where the crew corrects the analysis. See the toolbox talk guide.
- The work order is the administrative carrier. In most maintenance operations the analysis is attached to, or referenced from, the work order that authorised the job, which is what makes it retrievable later.
Software is incidental here. A maintenance or safety system can attach an analysis to a job, remind people it is required, and make old ones findable, and that is genuinely useful administration. None of it improves the analysis. A system that makes it easy to duplicate the last JSA makes the underlying problem worse, faster.
12. A worked illustration (invented teaching example)
The table below is an invented teaching example. Every line in it was written to illustrate the method, not to describe any real task, site or crew. It is not a form, it is not a template, and it must not be used as one. A real analysis for this kind of work would be considerably longer, written for the specific equipment and location, produced with the people doing the job, and would be reviewed by someone competent for that work under the law that applies there. Read it for the shape of the reasoning, particularly how hazards attach to particular steps and how the transition steps carry their own entries.
Invented task: replacing a failed drive belt on a small ventilation fan located on an accessible plant-room floor.
| Step (illustrative) | Hazards at this step (illustrative) | Controls decided, with owner (illustrative) |
|---|---|---|
| 1. Access the plant room and establish the work area | Unfamiliar layout; other plant running; occupants or other trades entering | Technician confirms the correct unit against the asset record before touching anything; technician barriers the work area and posts it at the door before starting; supervisor confirms no other work is booked in the room that shift |
| 2. Isolate and lock the electrical supply, and prove dead | Live supply; wrong circuit isolated; remote or automatic restart | Isolation performed and locked by the authorised person named on the work order, who retains the key; proving performed at the machine after isolation; supervisor verifies the lock and the proving result before step 3 is permitted to begin |
| 3. Confirm the fan has come to rest | Stored rotational energy; assumption that isolation equals stationary | Technician observes the fan to a complete stop before opening the guard; opening the guard is gated on that visual confirmation, not on the isolation alone |
| 4. Remove the belt guard (transition step) | Fastener and tool handling; guard becomes a loose item; the machine is now unguarded for all later steps | Technician places the removed guard and its fasteners in a designated position clear of walking routes; the barrier from step 1 remains in place specifically because the machine is now open; supervisor treats reinstatement of the guard as a closing gate |
| 5. Release tension and remove the failed belt | Stored spring tension in the tensioner; pinch points between belt and pulley; sharp edges on the failed belt | Technician releases tension using the designed adjuster rather than levering; hands kept clear of the pulley line while tension is released; technician removes debris from the failed belt before proceeding rather than after |
| 6. Fit the replacement belt and set tension | Pinch points; awkward posture in restricted space; incorrect fitment left undetected | Technician sets the drive to a position that allows hand clearance before fitting; tension set with the designed adjuster; technician records that the correct part reference was fitted, on the work order, before closing up |
| 7. Refit the guard and clear the area (reinstatement) | Guard omitted or partially secured; tools or the old belt left inside the housing; end-of-job time pressure | Technician accounts for all tools and the removed belt before the guard goes back; guard refitted with all original fasteners; supervisor physically confirms the guard is secure and the housing is clear before isolation is removed |
| 8. Remove isolation and run up the fan | First rotation with people nearby; unexpected noise or movement; a fault revealed on start | Only the authorised person who applied the isolation removes it; technician and anyone else stand clear of the drive line for the first run; technician stops the unit and reapplies isolation before investigating anything abnormal, rather than adjusting a running machine |
| 9. Remove barriers, hand back and close out | Area handed back with a residual hazard; the next shift unaware of what changed | Technician walks the area against step 1 before removing barriers; technician records what was done and anything found, on the work order, and raises a separate job for anything not completed rather than leaving it verbal |
Note what the illustration is doing, because the shape matters more than the content. Hazards attach to particular steps rather than sitting in one list at the top. Two of the nine steps exist only because something has to be taken apart and put back. The controls name who acts, and several are written as gates on the next step. And the unguarded condition created at step four is carried forward into later steps, which is the sequence awareness a flat list cannot express.
13. How JSAs fail
The failure patterns are consistent enough to be diagnostic, and none of them require a bad intention to produce.
- Templates reused across dissimilar jobs. The header changes and the body does not. The analysis now describes a job that was not examined, and worse, it reads plausibly enough that nobody notices.
- Signatures as evidence of a conversation that did not happen. A sheet passed round at the gate. The signature block was intended as a record of understanding and has become a record of attendance.
- Hazards listed with no corresponding control. The hazard column is full, the control column is thin or rhetorical. Documented recognition of a risk with no decision attached to it.
- Controls listed with no owner. Passive constructions that nobody is accountable for, which means nobody checks them.
- Written after the work, as a record. Produced to close out a job or satisfy an audit. A retrospective analysis prevented nothing, and it teaches everyone that the document is for the file.
- A crew who have never read the one with their name on it. Common, and easy to test: ask any two members of a crew to describe the main hazards of the job in their own words. The answer tells you whether the analysis exists in anyone's head or only on paper.
- The organisational failure: volume measured, quality not. Where the reported metric is JSAs produced, JSAs will be produced, and their quality will fall to whatever passes review. What gets counted is what gets optimised, and nobody has ever counted thinking.
A fair observation to close on. The paperwork burden is a real problem, not a moral failing. Crews who copy JSAs are usually responding rationally to a requirement that exceeds the available time, and supervisors who sign them without reading are usually managing an impossible document load. Blaming the people at the point of production misdiagnoses the fault, which sits with whoever decided that every job needs one. That is why selectivity is not a side point in this method. It is the condition under which everything else in it can work.
The idea to walk away with
A job safety analysis is the practice of following one specific job through its sequence, with the people who do it, asking what can harm someone at each step and deciding what will prevent it. It earns its place because sequence matters: hazards are created by earlier steps, they live in the transitions, and a flat activity-level list cannot express either. It loses its place when it is applied to everything, written from a desk, filled with exhortations instead of controls, and measured by the tonne.
If you want to improve the quality of JSAs in an organisation, there are two interventions worth more than any form redesign. Reduce how many are required so the ones that are required can be done properly. And read a sample of the existing ones looking only for the words "be careful", "appropriate PPE" and "follow procedure", because the density of those three phrases is a fair proxy for how much thinking the system is currently producing.
Final thoughts
The method has survived for decades because it is sound and because it is cheap. It needs no software, no licence and no standard to be bought. It needs a job worth analysing, an hour at the workface with the crew who perform it, the discipline to work through the hierarchy of controls instead of defaulting to the bottom of it, and a named owner against every control. That is genuinely all.
What it cannot survive is being turned into an output. The moment the question becomes "do we have a JSA for this" rather than "have we thought this job through", the document detaches from the work and the method is finished while the folder keeps filling. Keep the number small, keep the analysis at the workface, keep the controls specific and owned, and make stopping to reassess an ordinary thing rather than a confession. Do that and the paperwork looks after itself, because it will be describing something that actually happened.
Disclosure
Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.
Reviewing how safe-work documentation runs in your operation?
Independent advisory on how permits, risk assessments and task-level analysis sit inside maintenance and facilities workflows, and how to reduce document volume without losing control. 22+ years across utilities, oil and gas, manufacturing, government and facility operations.
Book a conversationRelated reading: JSA vs JHA: what is the difference, Hierarchy of controls, Risk assessment with examples, Hazard identification methods, RAMS explained, Permit to work, Toolbox talks.
Muhammad Abbas
CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.
Work with me