A LOTO procedure is usually presented as a list, and a list invites the reader to treat every item as equally weighted and independently optional. That is the wrong mental model. The steps in an energy-control sequence are not chores that add up to safety. They are a chain, in which each link exists because of a specific way people have been injured, and in which the order of the links is itself part of the protection. Reorder them and you have not saved time. You have removed a defence.
The message up front: the order of the steps is the safety content. Notification comes before shutdown so that nobody is mid-task when the plant stops. Stored-energy release comes before verification so that verification has something meaningful to confirm. Verification comes before the spanner touches the machine because an isolation you have not verified is a belief, not a state. Learn the purpose of each step and you can look at your own site's procedure and tell whether it still works or has quietly become a form-filling exercise.
What this article is, and is not
This is a general explanation of why the lockout/tagout sequence is shaped the way it is. It is not a procedure to adopt. A real energy-control procedure is specific to one piece of equipment on one site, and must be written and reviewed by a competent person against the equipment as installed and the law of the jurisdiction it operates in.
1. Why the order is the safety content
Ask a maintenance team why they notify operations before shutting a machine down and you will often get a procedural answer: because the form says so, because the supervisor signs there. Ask why stored energy is released before the zero-energy check rather than after, and the answers get thinner. That is a symptom of how the sequence is normally taught, as a numbered list to be memorised for an audit rather than as a causal chain to be understood.
The chain moves from knowledge to communication to physical action to proof, holds that proof in place for the duration of the work, then unwinds in reverse. Every transition is there because the previous state was not yet safe. You cannot isolate what you have not identified. You cannot meaningfully verify a system that still holds pressure. When a step is merged with its neighbour, moved, or recorded in advance, one specific protection disappears entirely, and usually nobody notices until the day it was needed.
For the wider concept, the energy types, the roles and responsibilities, the programme elements and the legal picture, the place to start is the complete lockout/tagout safety guide. This article deliberately stays narrow: the sequence, and what each step is for.
A short word on where the sequence comes from, with jurisdictions attached, because this is where a great deal of published material goes wrong. In the United States, federal general industry has a dedicated standard for the control of hazardous energy, 29 CFR 1910.147, administered by OSHA. Its scope is general industry: construction and certain other sectors are covered differently, and many US states run their own OSHA-approved plans whose rules may differ, California being the familiar example with its own energy-control provisions at 8 CCR 3314. In Great Britain there is no single dedicated lockout/tagout regulation at all. Isolation duties arise instead from general work-equipment legislation, from the separate body of electrical safety law, and from the overarching statutory duties in the Health and Safety at Work etc. Act 1974 (c. 37), supported by the Provision and Use of Work Equipment Regulations 1998 (SI 1998/2306). Northern Ireland has its own instruments with different years. In the UAE, the binding framework is Federal Decree-Law No. 33 of 2021, with occupational safety duties in Article 13, administered by MOHRE, alongside emirate frameworks such as the Abu Dhabi Occupational Safety and Health System Framework (ADOSH-SF), Version 4.0. US and British rules carry no legal force there; they are voluntary benchmarks.
Layered on top, and law nowhere by itself, is the management-system expectation that hazardous work is controlled according to a hierarchy of controls: required by ISO 45001:2018 at clause 8.1.2 (as amended by Amd 1:2024), required by ANSI/ASSP Z10.0-2019 at section 8.4 in the US, and described by NIOSH on a free public page. Energy isolation sits in the engineering-control tier, which is worth holding onto: a lock is not administrative paperwork, it is a physical control. For that framework see the hierarchy of controls guide.
2. The sequence at a glance
Read the third and fourth columns rather than the first: the step names are the part everyone already knows.
| Step | What it is for | What it protects against | How it is got wrong |
|---|---|---|---|
| Prepare and identify | Establishing every energy source that feeds the equipment, and where each can be broken | Working on something that is still live from a supply nobody knew about | Relying on a drawing that no longer matches the plant; missing control supplies fed from another panel |
| Notify affected persons | Making sure nobody is mid-task on, or depending on, the equipment | Someone caught by the shutdown, or restarting the plant because they were never told | Notifying only the immediate team; treating a signature as notification |
| Orderly shutdown | Bringing the equipment to rest without creating a new hazard in the process | A process left in an unsafe intermediate state by an abrupt stop | Using an emergency stop as a shutdown method; stopping mid-cycle |
| Isolate at the energy-isolating device | Creating a physical break in the energy path itself | Energy re-entering the equipment while work is in progress | Treating a stop button, interlock or software inhibit as an isolation |
| Apply locks and tags | Making the isolation impossible for others to reverse, and its reason and owner visible | A well-meaning third party restoring supply | Shared locks; unsigned tags; a lock nobody can trace to a person |
| Release or restrain stored energy | Making the system genuinely de-energised, not merely disconnected | Trapped pressure, accumulators, capacitors, springs, suspended loads, residual heat, coasting inertia | Assuming disconnection equals de-energisation; releasing the obvious source and not the rest |
| Verify the zero-energy state | Converting a belief about the isolation into a tested fact | Every preceding step having been done correctly but on the wrong equipment or point | Verifying the wrong point; using an instrument of unknown condition; recording verification that did not happen |
| Carry out the work | Keeping the isolation under the protection of the people who depend on it | Protection lapsing partway through, typically at a shift change | Handover by conversation only; locks left on by people who have gone home |
| Restore in a controlled order | Confirming the equipment is fit to run and that nobody is in the danger zone | Start-up with a person, a tool or a missing guard still in place | Removing locks in a rush; one person clearing everyone's locks; restarting without telling anyone |
3. Prepare and identify: the step that carries the whole chain
The purpose of the first step is knowledge. Before anything is switched, somebody has to establish what energies are present, where they come from, and at which devices each can be physically broken. Electrical supply is only the beginning: there may be compressed air, hydraulics, steam, process fluid at pressure, gravity on a raised component, spring tension, a thermal reservoir, a stored charge, or rotating mass that keeps turning long after power is removed.
The failure mode recurs constantly in real incidents, and it is almost always a source that was genuinely not known about. A second electrical supply installed during a later modification. A shared header back-feeding from an adjacent line still running. A control supply from a different panel in a different room, so the main isolator is open and the control circuit is live. A recirculation path admitting fluid from downstream. None of these are exotic. They are the ordinary consequence of plant modified more often than its documentation.
This leads to an honest point most published material skips. Identification depends on asset information that a great many sites do not have in usable condition. If nobody can say with confidence which breaker feeds which motor, or which valve isolates which section, then the first step is being performed from memory by whoever happens to be on shift. That is an information-management failing more than a procedural one, and it is why isolation-point registers matter: a maintained record, per item of equipment, of the energy sources present and the specific devices that isolate each of them. Where that register exists and is current, the first step becomes a verification task. Where it does not, it becomes an act of recall.
The practical tell
An energy-control procedure that names the actual isolation points for that specific item of equipment is a real procedure. One that says "isolate all energy sources" is a policy statement wearing a procedure's clothing. The difference is not pedantry. The first one survives a shift where the usual technician is absent; the second one does not.
Isolation points, like asset data generally, decay unless something owns them. Attaching them to the asset record alongside the work order types that will reference them is sensible, but the register works on paper too provided somebody maintains it.
4. Notify affected persons: the step people think is administrative
Notification looks like the most bureaucratic step and is one of the most consequential. Its purpose is narrow: to establish that nobody is currently working on, inside, or relying on the equipment, and that everybody affected by it stopping knows it is about to stop and will stay stopped.
The failure mode runs two ways. Looking forward, the person who is not told is the one who restarts the equipment, opens a valve to relieve a process problem, or resets a tripped device because the line has stopped and nobody explained why. Looking backward, the person who is not asked is already part-way into a task the shutdown will interrupt in an unsafe place.
The step degrades characteristically. It shrinks to cover only the maintenance team while missing operations, contractors, cleaners, the control room and adjacent work sharing the same system. And it slides from a conversation to a signature: the box signed at the desk before anyone walks the floor, recording the notification without performing it. Notification that has not reached the people who could reverse your isolation has not happened, whatever the paperwork says.
This is where energy control and permit systems overlap without being the same thing. A permit coordinates and authorises work between parties; an isolation protects a person from energy. They are frequently confused, which is why that comparison has a page of its own: LOTO versus permit to work, with the permit mechanics themselves in the permit to work guide.
5. Orderly shutdown: not creating the hazard yourself
The purpose of an orderly shutdown is that the act of stopping the equipment does not itself create a hazard. Plant stopped at the wrong point in its cycle leaves a hazard behind: material part-way through a process, a partially filled vessel, a batch at a temperature that will now not be controlled, a conveyor stopped under load, a component left unsupported.
The failure mode is the process left in an unsafe intermediate state, which is why this step belongs to whoever understands the process, usually operations rather than maintenance, and why it comes before isolation rather than merged with it. A common corruption is using an emergency stop as the routine shutdown method because it is quickest to hand. An emergency stop arrests motion fast in a crisis and may deliberately leave the plant safe for the moment but not settled. It is not a shutdown procedure, and it is not, as the next section insists, an isolation.
6. Isolate at the energy-isolating device: the conceptual heart
This is the step the entire sequence exists to deliver. Its purpose is a physical break in the energy path: something that interrupts the flow of energy by its own construction, is capable of being held in the safe position, and cannot be undone by a signal, a setting or a command.
The failure mode here is a category error, and it is the single most dangerous misunderstanding in the subject. A great many things stop equipment. Very few isolate it. A control-circuit stop, a start/stop button, a guard interlock, a software inhibit or permissive, a variable-speed drive commanded to zero, a mode selector and an emergency stop share one property: they interrupt a command, not the energy. The energy is still present up to the device holding it back, and that device can be defeated by a fault, a bridged contact, a stuck contactor, a firmware state, or a person who does not know you are there and changes a setting.
State it plainly
A control-circuit stop is not an isolation. A start/stop button is not an isolation. An interlock is not an isolation. A software inhibit or control-system permissive is not an isolation. An emergency stop is not an isolation. Each of them stops the equipment doing something. None of them removes the energy, and none of them is a device you can put a lock on and then trust with your hands inside a machine.
| Commonly mistaken for an isolation | What it actually does | Why that is not enough |
|---|---|---|
| Stop button or control-circuit stop | Sends a stop command through the control circuit | The energy remains present; a control fault or a welded contactor can restore motion |
| Emergency stop | Arrests motion quickly in a crisis | It is a safety function, not an energy break, and it can be reset by anyone |
| Guard interlock | Prevents operation while a guard is open | Depends on a switch and a circuit continuing to work, and is a known target for defeating |
| Software inhibit, permissive or control-system block | Withholds permission to run inside the control logic | A configuration state, changeable remotely, invisible to anyone standing at the machine |
| Drive commanded to zero speed | Holds output at zero while remaining energised | The drive is live and a parameter change or fault can produce movement |
| Closing a valve by hand | Blocks flow while the valve holds | Valves pass and can be reopened; blocking is not the same as a secured break |
| An energy-isolating device | Physically interrupts the energy path by its own construction | This is the thing the procedure secures, and the only thing worth locking |
The order matters here too. Isolation follows shutdown rather than replacing it, because opening an isolator on running plant is both dangerous and damaging. And isolation precedes locking, because the lock secures a position already achieved: a lock on a device that was never moved to its safe position is a convincing-looking nothing.
7. Apply locks and tags: making it irreversible and legible
Two distinct purposes sit in this step, and conflating them is how it gets weakened. The lock makes the isolation impossible for anyone else to reverse. The tag makes the reason for it, and the person behind it, visible to anyone who comes across the device. One is a physical control, the other is information. A tag alone does not deliver the first.
The failure modes are about traceability and exclusivity. A shared lock, where several people work behind one padlock held by a supervisor, means the protection belongs to the supervisor's judgement rather than to each worker. A lock nobody can trace, hanging on a device with no indication of who applied it or why, will eventually be cut off by someone who needs the plant back. A tag with no name on it is decoration: it says something is happening without saying who to ask. Each turns an engineering control back into an administrative one.
The devices themselves, what makes a lock suitable, what a tag has to carry, and how the hardware differs between applications, are a separate subject, covered in LOTO tags: requirements, types and information. What matters for the sequence is simply this: the lock exists so that the isolation you created cannot be undone without your knowledge, and the tag exists so that nobody has to guess why.
8. Release or restrain stored and residual energy
Here is where the sequence stops being intuitive, and where a disproportionate share of serious energy-control incidents occur. The purpose of this step is to move the equipment from disconnected to de-energised. Those are not the same state, and the gap between them is where people are hurt by machines they had every reason to believe were safe.
Disconnection breaks the supply. It does nothing about the energy already inside the system. Pressure remains trapped between closed valves. Hydraulic accumulators exist specifically to store energy and will deliver it after the pump has stopped. Capacitors hold charge. Springs, in a machine's mechanism or in a valve actuator, stay compressed. A raised platform, a suspended load, a counterweight or a tool held up by hydraulics is gravity waiting on a seal. A flywheel, a fan or a large rotor coasts long after the motor is dead. Hot surfaces and hot process fluid remain hot. Thermal and chemical energy do not read the isolation tag.
The two available treatments differ in kind. Some stored energy can be released, brought to zero and kept there, so the hazard is gone. Some cannot be released and must instead be restrained: a raised component blocked or supported mechanically so it cannot fall, a rotating mass prevented from turning. The distinction matters because restraint is a continuing condition rather than a completed action. Released energy stays released. Restrained energy is being held, and something is doing the holding.
The failure mode is partial treatment. The obvious source is dealt with and the less obvious ones are not, usually because the first step never listed them. This is the clearest illustration of why the chain is a chain: incomplete identification produces incomplete stored-energy release, and together they produce a machine that passes a casual look and is not safe. It is also why this step precedes verification. Verifying before releasing stored energy tests a state you are about to change, which is worse than not verifying at all, because it produces a record saying the equipment was safe.
Where generic procedures fail hardest
Stored energy is the most equipment-specific part of the whole sequence, and therefore the part a generic site-wide procedure cannot possibly cover. A document that applies to every machine in a plant can say "release stored energy". It cannot tell you that this particular unit has an accumulator behind a panel, or that the guard on this press is held by a spring. That knowledge only exists in a procedure written for the equipment itself, by somebody competent who went and looked.
9. Verify the zero-energy state
Verification is the step that turns everything before it into something you can act on. Its purpose is narrow and absolute: to convert a belief about the state of the equipment into a tested fact. Up to this point, every step has been performed correctly as far as anybody knows. Verification is the only part of the sequence that tests whether that is actually true.
It has two halves, and they are not substitutes for each other. The first is attempting to operate the equipment's own normal controls, confirming that the machine does not respond: the thing that would have started it no longer does. The second is testing the energy itself at the point of work by a method suitable for the energy in question, confirming that the energy is genuinely absent rather than merely uncommanded. The first check can pass while energy remains present, because a stopped machine and a de-energised machine are different things. That is precisely why both halves exist.
The sentence to remember
An isolation you have not verified is a belief, not a state. Everything upstream of verification is an assumption about the plant, the drawings and your own recollection. Verification is where the assumption is either confirmed or destroyed, which is why it is the step that most rewards being done properly and most punishes being done for show.
The failure modes are worth naming individually. Verifying with an instrument of unknown condition proves nothing, because an instrument that reads zero when broken reads zero when the system is live. Verifying at the wrong point, upstream of a section still fed, or on the wrong one of two similar machines, produces a confident correct reading about the wrong thing. Verifying and then leaving the equipment unattended breaks the connection between the test and the work, because what you proved was the state at that moment. And the cultural failure is worst: verification treated as a box on a form, signed because the sequence requires a signature, in an organisation where nobody audits whether the check happened.
Method and instrumentation are deliberately outside the scope here. What constitutes a suitable test depends on the energy, the equipment, and the competence and authorisation of the person doing it, governed by the law and standards of the jurisdiction concerned. That belongs to the equipment-specific procedure and the competent person who writes it.
10. Carrying out the work: protection has to persist
The work itself is less a step than the interval the sequence exists to protect, and the requirement during it is continuity: the isolation must remain under the direct protection of the people relying on it, for the whole time they are relying on it. That single requirement is what turns two ordinary situations into special cases. When several people or trades work behind one isolation, each needs their own protection on it rather than trusting somebody else's, or the isolation can be released while one of them is still exposed. And when work crosses a shift boundary, the people whose protection is on the equipment are leaving the site, so protection has to be transferred deliberately rather than inherited by assumption. Both appear below as variations on the sequence rather than departures from it.
The failure mode during this phase is drift. The job takes longer than expected, people come and go, the scope grows to include a part of the equipment the original isolation did not cover, and at no point does anybody decide to change the isolation: it simply becomes less adequate than it was. Scope growth is a reason to revisit the first step, not a reason to carry on with the isolation you already have.
11. Restore in a controlled order
Restoration is the sequence run backwards, and it has two purposes. The first is confirming the equipment is fit to run: guards back, components reassembled, tools and materials removed, temporary supports taken out, the work actually finished rather than merely stopped. The second is confirming that no person is in a position to be hurt when it starts, which means the danger zone is checked and cleared, not assumed to be empty.
The failure modes cluster at the end of the job, exactly when attention is lowest and the pressure to hand the plant back is highest. A guard not replaced. A tool left inside a machine. A person in the danger zone whom nobody looked for. Locks removed by somebody other than the person who applied them, severing the link between the protection and the protected. And restarting without telling anyone, which is the notification failure from step two in mirror image: the people told the equipment was stopping also need to be told it is starting, because some of them have arranged their own work around it being off.
The reverse order is not decoration: removing locks before the equipment is reassembled invites a restart into an incomplete machine, and restoring energy before clearing the area removes the protection while the exposure still exists. Restoration comes under most strain during breakdown work, because the economic logic of the moment argues for speed. That relationship between urgency and discipline is worth understanding on its own terms, and is covered in the breakdown maintenance guide.
12. Why each person removes their own lock
The rule that a person's lock is removed only by that person is often taught as etiquette. It is not. It is the mechanism by which protection stays attached to the human being it protects. A lock applied by the person at risk, removable only by that person, means the equipment cannot be restored while they are exposed, regardless of who wants it back or how convincing their reasoning is. Move the authority to remove it anywhere else, to a supervisor, a shift lead, whoever has the spare key, and the protection stops being a physical control. It becomes a decision somebody else makes about your safety, based on their belief that you have finished.
That is why the orphan lock, still present with nobody available to remove it, is genuinely awkward rather than merely inconvenient: removing another person's lock is an exception to the mechanism itself. Where it is permitted at all, it is an exceptional event, specifically authorised, carried out with verified effort to contact the lock's owner, with the equipment confirmed clear and the owner informed before they next approach it, and documented afterwards. The documentation is not bureaucracy; it is the only thing stopping an exception becoming a habit.
The tell that an organisation has lost this distinction is that orphan-lock removal is smooth: a routine for it, a standing authorisation, a known person who does it at the end of every shift. At that point the lock no longer means what it should, and everybody has quietly learned that their padlock is a suggestion.
13. Group lockout and shift handover as sequence variations
Group work and shift handover are the two situations where the sequence has to flex, and both flex the same way: they add mechanism in order to preserve the principle that each exposed person holds their own protection.
In group lockout, the principle would be satisfied if every person could put a personal lock on every isolation point, and on a job with four isolation points and twelve people from three trades that is not physically possible. The usual answer is to interpose a device or a box: the isolations are secured, the keys to them are placed somewhere itself secured, and each individual applies a personal lock to that one place. That reproduces the original guarantee, because the isolations cannot be released until the last personal lock is gone. Conceptually, nobody's protection has been delegated; each person has simply been given a single point at which to hold it. An arrangement where the keys sit in a supervisor's pocket looks similar and is not the same thing.
In shift handover, the people holding the protection are going home while the exposure continues. The two principled outcomes are that the isolation is fully removed and re-established next shift with the sequence repeated, or that protection is transferred by a deliberate, overlapping act: the incoming people apply their own locks and satisfy themselves about the state of the equipment before the outgoing people remove theirs, with work status and isolation boundaries explained face to face. What must not happen is the gap, an interval during which the equipment is isolated but nobody present has a personal stake in that isolation and nobody arriving knows exactly what was done. Handover by conversation alone, with locks left in place by absent people, reliably produces an isolation that nobody owns.
Confined-space work compounds both variations, because the exposure is occupancy rather than proximity and entry control has to be reconciled with energy control. That interaction is set out in the confined space permit guide.
14. How a procedure decays
Energy-control procedures rarely fail by being abolished. They fail by erosion, in a recognisable pattern.
Generic procedures written once for a whole plant. A single document covering every machine can only describe the sequence in the abstract. It cannot name the isolation points or list the stored-energy sources, so it cannot be worked to. Its existence satisfies an audit and leaves the real knowledge in the heads of individuals, which is the state the procedure was meant to replace.
Steps merged for speed. Shutdown and isolation collapse into one action. Notification and shutdown happen simultaneously. Stored-energy release and verification become a single glance. Each merge removes a boundary that existed to force a check, and each feels harmless because the outcome is usually the same.
Verification recorded before it happens. The form is completed at the desk because that is where the pen is. This is the most corrosive decay, because the documentation is not merely absent but actively misleading, and it teaches everyone that the record and the reality are separate systems.
Isolation points that changed when the plant changed. A modification adds a supply, moves a breaker, reroutes a line, and the procedure is not revisited because nobody owns it. The document becomes a historical account of how the equipment used to be isolated. That is a management-of-change failure appearing as a safety failure, and it is why energy-control documentation belongs inside whatever process governs plant modification rather than beside it.
The best diagnostic remains the one stated earlier: read the procedure and see whether it names the actual isolation points for that specific equipment. Everything else can be written by somebody who has never seen the machine. That part cannot. For where energy control sits in the wider organisational safety picture, see what HSE actually covers, and for how isolation requirements attach to the work-management system in practice, permit to work integration with CMMS.
The idea to walk away with
Every element of the order is load-bearing. Identification comes first because nothing downstream can be complete if it is not. Notification precedes shutdown so nobody is caught by the stop. Shutdown precedes isolation so the plant is not left hazardous and the isolating device is not operated under load. Isolation is a physical break, not a command. Locks and tags make that break irreversible and legible. Stored energy is released or restrained because disconnected is not de-energised. Verification converts belief into fact. Protection persists for the duration. Restoration unwinds in reverse, with the danger zone cleared before the energy returns.
Read that way the sequence is not a checklist. It is an argument, and understanding the argument is what lets you recognise a hollowed-out procedure when you are handed one. A document that lists the steps in the right order and names nothing specific has kept the form and discarded the content.
Final thoughts
The two steps that deserve the most attention and get the least are stored-energy release and verification: where the sequence stops being intuitive, where the equipment-specific knowledge lives, and where serious incidents concentrate. If a site were to improve one thing, I would advise two questions. Are the stored-energy sources for each item of equipment written down anywhere? Is verification a check that happens or a box that gets signed? Both are answerable in an afternoon, and the answers tend to be uncomfortable.
Primary sources, with jurisdictions attached: the US Occupational Safety and Health Administration for 29 CFR 1910.147 and the federal general-industry position; the Health and Safety Executive for Great Britain, where isolation duties sit inside general work-equipment and electrical-safety law rather than a dedicated instrument; ISO for ISO 45001:2018 and its clause 8.1.2 requirement; and NIOSH for the free description of that hierarchy.
Disclosure
Alongside advisory work I also build a CMMS and CAFM platform, so I have a commercial interest in this category. Nothing above is a recommendation for it, and no vendor named here has paid for inclusion or had any editorial input. Weigh the analysis accordingly.
Reviewing how isolation is handled in your work management?
Independent advisory on isolation-point registers, asset data quality, and how permit and energy-control requirements attach to planned and unplanned work. 22+ years across utilities, oil and gas, manufacturing, government and facility operations.
Book a conversationRelated reading: Lockout/tagout: the complete safety guide, LOTO tags: requirements, types and information, LOTO versus permit to work, Permit to work guide, Hierarchy of controls, Confined space permits, What HSE covers, Breakdown maintenance, PTW integration with CMMS, Work order types in CMMS.
Muhammad Abbas
CMMS / CAFM Manager & Independent Advisor · 22+ years across enterprise CMMS, EAM, CAFM and ERP implementations in utilities, oil and gas, manufacturing, government and facility operations.
Work with me