Ask a maintenance team what lockout/tagout is and most will describe the artefacts: the padlock, the hasp, the red tag, the board in the workshop with everyone's lock on it. That is not wrong, but it describes the visible surface rather than the thing itself. Lockout/tagout is the control of hazardous energy: the deliberate isolation and securing of every energy source that could start a machine, move part of it, or release something stored inside it, so that a person can put their hands into that machine and know it cannot act on them. The locks are how you hold that state. They are not the state.
The message up front: LOTO is an engineering control applied to energy, not an administrative ritual applied to equipment. Two ideas carry most of its protective value. First, a control-circuit stop, an interlock or a software inhibit is not an isolation. Second, an isolation you have not tested is a belief rather than a verified state. Most serious LOTO failures reported in the literature and in incident accounts break one of those two ideas.
Scope of this article
This is a general explanation of the principles, for managers who need to understand what a hazardous-energy programme is for. It is not a procedure you can adopt. An energy-control procedure must be written for the specific equipment and site by a competent person under the legal framework that applies where you work, and the programme should be reviewed by a competent safety professional against both that law and your actual plant. Nothing here substitutes for either.
1. What lockout/tagout is, and why it exists
Machinery is designed to be energised. A pump has a motor that turns, a press has a ram that descends, a chiller has refrigerant under pressure, a conveyor has a drive that pulls. Every one of those useful behaviours becomes a mechanism of injury the moment a person is inside the machine's envelope while the energy is still available to it. Lockout/tagout exists because the most dangerous moment in an asset's life is not when it is running normally, but when it has stopped and somebody has assumed that stopping and being safe are the same thing. Maintenance, cleaning, unjamming, setting up and clearing a blockage all put a person into the machine deliberately.
Mechanically, LOTO does three things in sequence. It removes the energy from the equipment. It secures the means of removal so the energy cannot be restored by anyone, deliberately or accidentally, while work is in progress. It then proves by test that the equipment really is in a zero-energy state. Everything else in a programme exists to make those three things reliable across many people, many shifts and many machines.
The other reason it exists is organisational. LOTO is a control that works between people who cannot see each other, which is exactly the situation in which informal care fails. For where hazardous-energy control sits in the wider safety picture, see the HSE pillar.
2. The framing that matters: it is a control on energy, not a procedure about padlocks
The most useful reframing I can offer a team is this: stop thinking of LOTO as a paperwork step before a job and start thinking of it as an engineering control applied to the energy itself. The padlock holds an isolation open. It has no protective power of its own. If the isolation behind it is the wrong device, an incomplete set of devices, or a device that does not actually break the energy path, the lock is securing nothing and the tag is describing a safety that does not exist.
The consequence is that the quality of a LOTO programme is decided long before anyone touches a lock: in whether the energy sources on each asset have been identified, whether the isolating device for each of those sources has been found and labelled, and whether the equipment was designed so that isolation is physically possible at all. Teams that treat LOTO as a compliance step audit the locks. Teams that treat it as an engineering control audit the isolation points.
It also positions LOTO correctly in the hierarchy of controls. Removing the hazard by design, for example by designing out the need to enter the machine, sits above procedural control. LOTO is the engineering-plus-procedure combination you apply where entry cannot be designed out. The hierarchy itself is a principle rather than a standard: it is required by ISO 45001:2018 at clause 8.1.2, a voluntary but certifiable international management-system standard, cited as amended by Amd 1:2024, and by ANSI/ASSP Z10.0-2019 at section 8.4 in the United States, and it is described on free public pages by NIOSH, a US research agency with no regulatory power. See the hierarchy of controls guide for how the tiers are applied.
The test I would apply
Point at any machine on your site and ask: can someone name every energy source it holds, and point to the device that isolates each one? If the answer takes longer than the walk to the machine, your LOTO exposure is in the identification, not in the locks.
3. The types of hazardous energy
Hazardous energy is any energy that can cause harm if released or applied while a person is exposed to it. A programme enumerates types rather than trusting judgement because people isolate the energy they are thinking about and forget the one they are not. An electrician isolates the supply and forgets the accumulator. A fitter drains the hydraulic line and forgets the suspended load overhead.
| Energy type | Typical sources | How it is isolated in principle | The stored-energy trap |
|---|---|---|---|
| Electrical | Mains supply, generators, UPS and battery backup, photovoltaic arrays, control transformers, capacitor banks, variable speed drives | Open a disconnecting device that physically breaks the supply conductors, then lock it in the open position | Capacitors and drive DC links hold charge after the supply is opened; backfeed can arrive from a second supply, a UPS, a generator or an interconnected panel |
| Mechanical (motion) | Rotating shafts, flywheels, conveyor drives, fan impellers, presses, drive belts | Remove the motive power, then physically block, pin or restrain the moving part so it cannot travel | Flywheel and rotor inertia keeps turning after power is removed; windmilling of fans from airflow or draught; belt tension released suddenly |
| Mechanical (gravity) | Raised platforms, counterweights, suspended loads, tilted or hinged panels, elevated tooling, vertical gates and dampers | Lower the component to its rest position, or support it on a positive mechanical restraint that does not rely on the raising system | A load held only by hydraulics, a brake or a chain block is held by a system that can fail or be released; gravity never switches off |
| Hydraulic | Power packs, cylinders, hydraulic presses, lifting and tipping systems, actuator circuits | Stop and isolate the pump supply, close the isolating valve, then bleed the circuit down to atmospheric pressure through a drain point | Accumulators are designed to store pressure and will hold it after the pump is off; trapped fluid between closed valves stays pressurised; a cylinder can drift |
| Pneumatic | Compressed air mains, receivers, air cylinders, clamps, air motors, spring-return actuators | Close the isolating valve on the supply, lock it closed, then vent the downstream side to atmosphere | Air is compressible, so line volume holds significant energy after isolation; a vented circuit can be re-pressurised by a cross-connection or a ring main |
| Thermal | Steam, hot water, hot oil, furnaces, dryers, refrigerant systems, exhaust and flue surfaces, cryogenic lines | Isolate the heat or cooling source, isolate and drain the medium, then allow the system to reach a safe temperature before entry | Thermal mass holds heat long after the source is off; surfaces cool unevenly; insulated pipework hides temperature; condensate and flashing steam |
| Chemical | Process lines, dosing systems, fuel gas, refrigerants, inert gas, drainage and effluent, residues inside vessels | Isolate the line by positive means, drain, purge or flush, then prove the isolation and the internal atmosphere before entry | Residues and sludge in low points, absorbed product in linings, reactions restarting as temperature changes, inert gas displacing oxygen |
| Stored and residual | Springs, capacitors, accumulators, flywheels, pressurised vessels and trapped sections, raised components, tensioned belts and cables | Relieve, discharge, vent, block or mechanically restrain the stored energy, then verify that the relief was effective | This category is the trap. See the next section, because this is where the people who believed they had isolated correctly get hurt |
The list is a prompt to think, not a checklist to tick. Most real machines carry three or four of these types at once.
4. Stored and residual energy, which deserves its own treatment
Of all the categories, stored energy is the one that kills people who thought they had done the job properly. The pattern is consistent. The worker identifies the primary energy source, isolates it correctly, locks it correctly, then begins work, and the machine moves, discharges or releases, because the energy that hurt them was already inside the equipment and had nothing to do with the supply just isolated.
The reason this failure mode persists is that isolation feels complete. The motor is locked off, the light is out, the noise has stopped. Every sensory cue says the machine is dead. But a compressed spring is not connected to the supply, nor is a charged capacitor inside a drive enclosure. A hydraulic accumulator is designed to keep working when the pump is off, because that is what it was installed to do. A flywheel keeps turning long after the electricity has gone.
The principle that covers all of it: after isolating supply, every remaining store of energy must be either released to a safe state or physically restrained so it cannot act. Released means bled, vented, drained, discharged, lowered or allowed to run down. Restrained means blocked, pinned, chocked, chained or otherwise held by something that does not depend on the system you have just isolated. That last qualification does a lot of work. Supporting a raised load on the hydraulics that raised it is not restraint.
The stored-energy question
For each piece of equipment: what inside this machine can still move, push, spring, fall, turn, discharge or escape now that the supply is locked off? Write the answer into the equipment-specific procedure, because it is not something a technician should have to derive under time pressure at the machine.
Stored energy is also why LOTO and other high-hazard controls overlap. A vessel that has been isolated, drained and purged may still be an oxygen-deficient or contaminated space, which brings a separate set of duties into play. Where work involves entry into a tank, pit, duct or vessel, hazardous-energy control is necessary but not sufficient, and the confined space guide covers the additional regime. In US general industry the confined space standard is 29 CFR 1910.146, whose scope excludes construction; US construction is covered separately under 29 CFR 1926 Subpart AA.
5. The energy-isolating device, and why a stop button is not an isolation
This is the highest-value technical distinction in the whole subject. If a team learns one thing from a LOTO briefing, this should be it.
An energy-isolating device is a mechanical device that physically prevents the transmission or release of energy. A disconnect switch that opens the supply conductors. A circuit breaker used as a disconnecting means where it is designed and rated for that duty. A line valve that closes the flow path. A blank or blind flange inserted into a line. A block inserted to prevent movement. What these have in common is that they interrupt the energy path physically, they can be held in the safe position, and their position can be positively established.
The following are not energy isolations, and treating them as such is one of the most common root causes in hazardous-energy incidents:
- A start/stop pushbutton. It signals a control circuit, which commands a contactor. The contactor can weld closed, the control circuit can fail to a dangerous state, and in any case the supply is still sitting on the incoming terminals.
- An emergency stop. An e-stop is a reaction device for an unplanned event, engineered to stop quickly rather than to be held safe against restoration for the duration of a maintenance job.
- A selector switch set to off, manual, local or maintenance. A switch position is a setting, and settings can be changed by anyone who reaches the panel or overridden by a higher-level control.
- An interlock. Interlocks are protective and valuable, but they are part of the control system and can be defeated, bypassed, bridged or fail. They prevent an unsafe sequence; they do not hold an isolation.
- A software inhibit, a PLC tag forced off, a scheme taken out of service in the SCADA, a permissive removed. Each is a state inside a programmable system that can be changed remotely, restored by a reload, overwritten by a colleague, or lost on a restart.
- A closed but unlocked valve, or a valve type that does not provide positive isolation. Closed is a position, not a secured state, and some valve types will pass under pressure.
The reason to be firm about this is that control-system stops are the convenient thing. They are on the front of the machine, they take a second, and they appear to work. An energy-isolating device is usually somewhere less convenient, and using it costs time. That gap in convenience is where the shortcut lives. Nobody makes this mistake out of ignorance of the risk; they make it because the button was closer.
A related design point: some equipment cannot be isolated properly because nobody specified an isolating device at the right place when it was bought. That is a capital problem being pushed onto the technician as a procedural one, and the answer is to fix the asset rather than write a cleverer procedure around it.
6. Roles: authorised, affected and other persons
A programme distributes duties across defined roles, and the distinction is not bureaucracy: it determines who gets what training, who may apply and remove locks, and who merely needs to know that work is happening. The terminology below follows US federal general-industry practice under 29 CFR 1910.147. The words differ between jurisdictions, but the structure is broadly recognisable.
| Role | Who it is | What they may do | Why the distinction matters |
|---|---|---|---|
| Authorised person | The person who performs the isolation and the servicing or maintenance work behind it | Identifies the energy sources, operates the isolating devices, applies and removes their own locks and tags, and verifies the zero-energy state | This is the trained and formally authorised role. Authorisation is equipment-specific, not a generic badge, and the training and the record behind it are part of the programme |
| Affected person | Someone whose job involves operating or using the equipment, or working in the area where the work is being done | Must be notified before isolation and before restoration. Does not apply or remove locks | Operators are the people most likely to try to restart equipment. They need to recognise the devices and understand the prohibition, but they do not need authorised-person training |
| Other person | Anyone else who may be in or pass through an area where energy control is in use, including visitors, drivers and unrelated trades | Must be able to recognise a lock or tag and must not touch, remove or bypass it | This is awareness level. It exists because the worst single-cause incident in LOTO is a lock removed by someone who did not know what it meant |
| Contractor personnel | Any external party performing work on site equipment | Whatever the host and contractor programmes jointly establish, informed to both parties in advance | Two programmes meeting at one machine is the classic multi-employer failure. Someone has to own the interface explicitly, in writing, before the work starts |
The principle underneath the whole role structure: each person's protection is under their own control. An authorised person applies their own lock and is the only person who removes it. That is not a preference, it is the mechanism by which the isolation protects an individual rather than a general intention.
7. The sequence, in overview
The order of operations in an energy-control procedure is neither arbitrary nor adjustable. Below is the sequence as a named overview so the logic is visible. It is deliberately not a procedure. For the step-by-step treatment, including what each step involves and where each is commonly cut short, see the dedicated LOTO procedure and steps guide.
- Prepare and identify. Establish the scope and identify every energy source the equipment holds, from the equipment-specific procedure rather than memory.
- Notify. Tell affected persons, operations and the control room before anything is operated.
- Shut down. Bring the equipment to an orderly stop using the normal operating controls, because an uncontrolled stop can itself create a hazard.
- Isolate. Operate each energy-isolating device to interrupt each energy path. This is where the distinction in section 5 either holds or is quietly broken.
- Lock and tag. Secure each isolating device in the safe position and attach the tag identifying who applied it and why.
- Relieve or restrain stored energy. Bleed, vent, drain, discharge, lower or block every remaining store identified in step one.
- Verify the zero-energy state. Attempt to start using the normal controls, test for absence of energy by means appropriate to each type, then return the controls to off.
- Work. Carry out the maintenance behind a verified isolation.
- Clear. Confirm the equipment is reassembled, guards refitted, tools recovered and all personnel clear.
- Remove the locks. Each authorised person removes their own lock and tag, in a controlled order.
- Restore and notify. Re-energise, confirm expected behaviour, and tell the affected persons it is back in service.
Two observations about that list. The two halves are mirror images, and the second half is the one that gets rushed, because the job is finished and the pressure has lifted. And the devices used in steps five and ten are a subject of their own: what a lock has to be able to do and what a tag has to say are covered in the LOTO tags and devices guide.
8. Verification, which is the step that carries the whole thing
Given one section of a LOTO programme to strengthen, I would choose verification. It converts an assumption into a fact, and it is the step most often reduced to a glance.
An isolation you have not tested is a belief, not a state. Everything before verification is a set of actions taken in the expectation of a result, and verification is the only point at which that expectation is checked against reality. Reality diverges more often than people assume, for entirely mundane reasons: the isolator that was locked feeds a different circuit from the one labelled, a second supply exists that nobody documented, the valve is closed but passing, the contactor has welded closed, the panel was modified during a project three years ago and the label was never changed.
Verification has two complementary parts and neither replaces the other. Attempting to operate the equipment with the normal controls proves the command path is broken. Testing for the absence of energy, by means appropriate to the energy type, proves the energy path is broken. A machine can fail to start and still be live.
Where verification is genuinely difficult
Verification is not always straightforward. Buried pipework, systems with no test point, and older plant with undocumented interconnections all make honest verification hard. The right response is to treat that difficulty as an asset defect to be fixed and, in the meantime, to escalate the job rather than substitute confidence for a test. What is not acceptable is letting difficulty quietly become omission.
9. Group lockout, and continuity across shifts
A single lock applied by a supervisor on behalf of a crew of six looks efficient and is unsafe, for a reason easy to state. That lock represents the supervisor's knowledge of where the crew is. The moment one technician is still inside the machine when the supervisor believes everyone is out, the lock comes off and the protection was never really the worker's own.
Group lockout preserves the principle that each person's protection is under their own control while keeping a multi-person job practical. Mechanisms differ between sites; the principle does not. Every person exposed has a personal means of preventing re-energisation, and the equipment cannot be restored until the last of those has been removed by the person who applied it. A group job therefore also needs someone accountable for the overall isolation, for who has joined and left it, and for the clearing order.
Continuity across shifts is the same principle stretched over time, and it is a classic failure point. A job running past the end of a shift creates a moment where the person holding the isolation is going home and the person taking over has not yet established their own protection. Handled badly, there is a window in which nobody's personal lock is on the equipment, or worse, one in which the outgoing person removes their lock assuming the incoming person has already applied theirs. The rule that prevents it: the isolation is never left unprotected during the transfer. The incoming person establishes their own control before the outgoing person releases theirs, and the handover is documented in enough detail that the incoming crew knows what is isolated, what stored energy has been relieved, what has been dismantled and what remains.
10. Tagout-only situations, and the limits of a tag
A lock is a physical restraint. A tag is a piece of information. That difference is the whole of it.
A lock prevents the isolating device from being operated, so someone who wants to re-energise has to overcome a physical obstacle, and overcoming it is an unmistakably deliberate act. A tag prevents nothing. It communicates a prohibition to a person who reads it, understands it and chooses to comply. Its protective value depends entirely on the behaviour of everyone who might touch that device, which is precisely the variable LOTO exists to remove.
Tagout-only arises where an isolating device cannot be locked, which on older plant is not unusual. The honest position is that the protection is materially weaker, and the programme has to compensate: more rigorous verification, additional measures at the isolation point, closer supervision, clearer communication to everyone who could reach the device. Compensating measures reduce the gap. They do not close it.
The uncomfortable conclusion
If a site has a lot of tagout-only equipment, the real finding is not procedural. It is that the asset base cannot be isolated properly and should be modified so that it can be. Treating a long-term inability to lock out as a permanent accommodation is a decision to accept a lower standard of protection indefinitely, and it should be recorded and escalated as such.
11. The legal picture, which is genuinely different by country
There is no single global scheme for hazardous-energy control. What LOTO is called, whether it is prescribed in its own regulation, and what the employer must document all vary by jurisdiction, so the first question for any programme is which body of law applies to the site. Each of the following carries its jurisdiction with it, and none applies outside it.
- United States, federal general industry. The energy-control standard is 29 CFR 1910.147, "The control of hazardous energy (lockout/tagout)", in Subpart J. It is where the authorised, affected and other-person structure and the requirement at 1910.147(c)(4) for equipment-specific written energy-control procedures come from. It is federal general industry only: US construction and certain other sectors are covered differently, and many US states run their own OSHA-approved plans, so a state requirement can differ from the federal one. California, for example, regulates lockout under 8 CCR 3314.
- Great Britain. There is no single dedicated lockout/tagout regulation. Isolation duties arise from general duties and from work-equipment and electrical-safety legislation rather than from a LOTO-titled instrument. The general duty framework is the Health and Safety at Work etc. Act 1974 (c. 37). Work-equipment duties, including means of isolation and maintenance carried out safely, sit in the Provision and Use of Work Equipment Regulations 1998 (SI 1998/2306), known as PUWER. The duty to assess risk sits at Regulation 3 of the Management of Health and Safety at Work Regulations 1999 (SI 1999/3242). Britain also has dedicated electrical safety at work legislation covering dead working and isolation, which should be looked up in its current published form rather than cited from memory. Northern Ireland has separate instruments, frequently with different years.
- United Arab Emirates. US OSHA regulations and UK HSE law have no legal force in the UAE; they are voluntary benchmarks many international contractors bring with them. The binding federal instrument is Federal Decree-Law No. 33 of 2021 on the Regulation of Employment Relationships, administered by MOHRE, with occupational safety and health duties at Article 13. In Abu Dhabi the framework is ADOSH-SF, the Abu Dhabi Occupational Safety and Health System Framework, Version 4.0, administered by the Abu Dhabi Public Health Centre. EHSMS and OSHAD-SF are legacy names.
- Voluntary international and consensus standards. ISO 45001:2018, as amended by Amd 1:2024, is a certifiable occupational health and safety management-system standard requiring the hierarchy of controls at clause 8.1.2, and it is the usual international reference where local law is less prescriptive. It is not law anywhere by itself. In the United States, ANSI/ASSP Z10.0-2019 requires the hierarchy at section 8.4, and NFPA 70E, "Standard for Electrical Safety in the Workplace", current 2027 edition, is a private consensus standard covering electrical work practices. NFPA 70E was developed at OSHA's request but is not an OSHA regulation, and because adoption is edition-specific, work to the edition adopted by the authority having jurisdiction over your site rather than to the number alone.
I have deliberately not summarised what any of these documents require; clause and regulation text should be read in the current published version. What matters at management level is knowing which framework binds you, and that a procedure lifted from another country's regime is not compliance. For the assessment work that sits under all of it, see the risk assessment guide.
12. Programme elements beyond the procedure
A written procedure is the most visible part of a LOTO programme and the smallest part of the work. What makes the difference between a folder and a functioning control is the surrounding apparatus.
- Equipment-specific written procedures. The most common programme defect I come across is a single generic procedure for the whole plant. It cannot tell a technician which isolating device serves this machine, where it is, what stored energy it holds or how to verify it, so the technician derives the procedure at the machine, which is what the procedure was supposed to prevent.
- Training and authorisation records. Authorisation is per person and per equipment type, recorded so a supervisor can check it before allocating work. It also has to cover affected and other persons at their own level, which is the part usually skipped.
- Periodic inspection of the programme itself. Distinct from inspecting equipment: an audit of whether procedures are correct, whether people apply them as written, and whether the plant has changed in ways the documents have not caught up with. This is what finds the mislabelled isolator before an incident does.
- Management of change. Every project and panel change can invalidate an existing procedure. If modifications do not trigger a review, the documents drift away from the plant silently, until someone relies on a document describing a machine that no longer exists.
- Contractor and multi-employer management. Where sites go wrong most often. Two organisations, each with a respectable programme, arrive at one machine with different lock colours, tag formats, authorisation rules and assumptions about who owns the isolation. The interface must be agreed explicitly before work starts, and the host normally owns that agreement because the host knows the plant.
On the maintenance-management side, three things make LOTO easier to run, none specific to any product. Isolation points recorded against the asset record, so energy sources and their isolating devices are a property of the equipment rather than tribal knowledge. Procedures attached to the work order, so the right asset-specific document arrives with the job. And a documented link between the work order and whatever permit regime applies, so the sequencing is visible rather than assumed. Most maintenance systems can hold all three; whether they do is an implementation decision. The permit side is covered in permit to work integration with CMMS, and how the work is classified and raised in work order types.
13. How LOTO fails in practice
The failure modes are not exotic and they repeat across industries. Each breaks a specific principle, which is the useful way to look at them, because it tells you what to reinforce rather than only what to warn about.
| Failure point | What it looks like | The principle it breaks |
|---|---|---|
| "It will only take a minute" | Clearing a jam, adjusting a guide or freeing a blockage without isolating, because the full procedure feels disproportionate to a short task | Exposure is not proportional to task length. The machine does not know how long you intended to be inside it |
| Stopping instead of isolating | Using a stop button, an e-stop, a selector switch or a software inhibit as the means of making the machine safe | A control-circuit stop is not an energy isolation. The energy is still available to the equipment |
| Unidentified energy sources | A second supply, a backfeed, a cross-connection or an interconnected system nobody knew about is left live | Isolation must be complete. Partial isolation offers partial protection, which in practice means none |
| Unlabelled or mislabelled isolation points | The isolator that was locked serves a different circuit from the label, or the label is missing and the wrong device is chosen | Isolation depends on identification. An unlabelled plant is a plant where isolation is guesswork |
| Generic procedures | One energy-control procedure for the whole site, written at a level that cannot direct anyone to a specific device | Procedures must be equipment-specific, or the technician improvises the critical decisions at the machine |
| Incomplete stored-energy release | Supply isolated and locked, but an accumulator, spring, capacitor, raised load or trapped pressure is left with its energy intact | Every store of energy must be relieved or restrained, not only the supply |
| Verification skipped | Isolation assumed from the position of a switch, the absence of noise or an indicator lamp, with no attempt to start and no test | An untested isolation is a belief. Verification is the only step that turns it into a state |
| Someone else's lock removed | A lock cut or removed to return equipment to service, by a person who did not apply it and does not know where its owner is | Each person's protection is under their own control. Removal by anyone else destroys the mechanism |
| Single lock on a group job | One supervisor's lock standing in for a crew, with no personal means of protection for the individuals exposed | Personal control of personal protection. A representative lock protects the intention, not the person |
| Lost continuity at handover | A shift change leaving the isolation unprotected, or an incoming crew inheriting an isolation they do not fully understand | The isolation must never be without an owner, and the handover must transfer knowledge as well as the lock |
| Rushed restoration | Re-energising before the equipment is reassembled, guards are refitted, tools are recovered and all personnel are confirmed clear | Restoration is a controlled sequence, not the absence of a procedure once the work is finished |
| Contractor interface undefined | Host and contractor programmes meeting at one machine with no agreement on whose rules govern the isolation | One machine needs one energy-control regime, explicitly agreed before work starts |
There is one more failure mode, and it is the organisational one that rarely makes it onto a training slide. LOTO compliance is high when it is being audited and low when the plant is behind schedule. That is not cynicism, it is the predictable behaviour of a control that costs time in an environment that rewards uptime. When a line is down and every hour is visible to someone senior, the pressure on the technician at the isolator is real and it is entirely upward.
The implication for management is uncomfortable but simple. If your LOTO performance depends on individual technicians absorbing schedule pressure on your behalf, you do not have a safety programme, you have people being asked to make a decision that should have been made above them. Building isolation time into the plan, and making it organisationally safe to stop a job for an isolation, does more for hazardous-energy control than any additional signage. The unplanned, urgent end of the work mix is where this bites hardest, which is why it is worth reading alongside the breakdown maintenance guide.
The idea to walk away with
Lockout/tagout is the control of hazardous energy, and the locks are only how the control is held. Get the energy identification right, use real energy-isolating devices rather than control-system stops, release or restrain every store of energy inside the machine, and prove the result by test rather than inference, and the padlock does the small job it was designed for. Get any of those four wrong and no amount of lock discipline recovers it.
The two sentences worth carrying away: a control-circuit stop, an interlock or a software inhibit is not an isolation, and an isolation you have not tested is a belief rather than a state.
Final thoughts
LOTO rewards precision in unglamorous places. Labelled isolation points. Asset-specific procedures. Authorisation recorded per person and per equipment type. A handover that transfers knowledge as well as a lock. A contractor interface agreed before anyone arrives. An audit of the programme, not just of the locks. None of it is hard to understand and all of it takes sustained attention, which is why it degrades quietly when nobody is looking.
If you are reviewing your own arrangements, the most useful place to start is not the procedure document. Walk to three or four machines with the person who maintains them and ask them to show you the isolating device for each energy source and tell you what stored energy the machine holds. That hour will tell you more about your real exposure than any folder, and it will point at which programme element needs the work. Then take the findings to a competent safety professional and to whoever owns the relevant legal framework on your site.
Two related pieces complete the picture. For step detail, the LOTO procedure guide takes the sequence apart properly. For how isolation relates to a permit regime, LOTO versus permit to work and the permit to work guide treat the two controls as complementary rather than alternatives.
Primary sources worth going to directly: US OSHA , UK HSE , ISO , NIOSH .
Disclosure
Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.
Reviewing how isolation is handled in your maintenance system?
Independent advisory on recording isolation points against the asset register, attaching equipment-specific procedures to work orders, and sequencing permits and isolations without duplicating records. 22+ years across utilities, oil and gas, manufacturing, government and facility operations. Safety programme content itself should go to a competent safety professional.
Book a conversationRelated reading: What is HSE, LOTO procedure and steps, LOTO tags and devices, LOTO vs permit to work, Hierarchy of controls, Confined space hazards and procedures, Risk assessment guide.
Muhammad Abbas
CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.
Work with me