Y4.05.1Lockout/tagout for hazardous energy controldesign

Locking out every energy source before servicing keeps equipment from starting on someone underneath it

Aliases: lockout/tagout for hazardous energy control · hazardous energy control

What it is

Lockout/tagout (LOTO) is a complete energy-control workflow before servicing: identify every energy source that could endanger workers, physically lock the corresponding isolating devices in the open position, dissipate or restrain any stored energy, and finally verify in the field that energy has actually reached zero — so the equipment cannot unexpectedly start or release energy for the entire duration of the work. Under common usage, an ordinary start/stop pushbutton on a control circuit is not an energy-isolating device — it is only a path into control logic, not a physical switch that removes energy itself.

Why it happens

A lock provides physical restraint — without the key, the isolating device cannot physically be turned back on; a tag communicates information — who applied the lock, why it is there, and when it can come off. The two do different jobs and neither can substitute for the other: pressing "stop" on a control panel leaves the equipment looking still, but a fault in the control logic, an erroneous remote command, or energy already stored inside the equipment (a spring, an accumulator, a suspended load) can still set it in motion or release energy without physical isolation. Field verification exists precisely to turn "isolation on paper" into "isolation confirmed by measurement" — documented isolation lists and the actual state of field equipment can always drift apart, and verification is the last check that removes that gap.

Where it stops holding

Exactly which regulation and industry procedure applies varies by jurisdiction and equipment type — electrical systems and maritime operations, for instance, often have their own more specialized energy-control rules that a generic lockout/tagout process cannot simply be substituted for. A tag itself typically carries none of a lock's physical restraint — tearing off a tag is far easier than opening a lock, and designers must recognize that difference in physical strength. Equally important: a software-level interface lock (disabling a button on an operating screen) is not the same as physically isolating actual energy — software state can silently change through a system restart, a permission change, or a remote override, with a failure mode entirely independent of a physical lock's.

Applying it

Following the applicable local regulation and equipment inventory, identify electrical, mechanical, hydraulic, pneumatic, chemical, and thermal energy sources one by one, then execute shutdown, isolation, lockout, energy dissipation, field verification, and controlled restoration in order, without skipping or reordering steps.

  • How to check: require an actual field measurement at every isolation point and every location where energy could be stored — an instrument confirming no voltage difference across an isolation point, visual confirmation that a stored-energy device has actually discharged — rather than treating a checked box on an isolation list as completion. Any isolation point verified only by inferring from paperwork, without an actual field measurement, counts as a failed verification.

Related

  • Same group: Y4.05.2 Identifiable lockout/tag ownership · Y4.05.3 Permit-to-work field verification · Y4.05.4 Expired permit and residual work state
  • Nearby: Y4.04 Inadvertent-operation prevention devices · Y8.01 On-site environmental constraints
  • Search terms: Lockout/tagout for hazardous energy control · hazardous energy control · safety-critical work

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Y4.05.1