Occupational Safety, Health, and Environmental (OSHE) Blog

What’s Lockout/Tagout (LOTO)? Procedure and Best Practices

A process safety assurance consultant walks the 29 CFR 1910.147 isolation sequence clause by clause, and the four steps that fail on real plant.

329
What’s Lockout/Tagout (LOTO)? Procedure and Best Practices

Lockout/tagout (LOTO) is the control of hazardous energy during servicing and maintenance: shutting equipment down, physically isolating every energy source that feeds it, securing each isolation point with a lock or a tag, releasing whatever energy is still stored inside, and proving the machine is dead before anyone puts a hand in it. In the United States it is governed by 29 CFR 1910.147, which OSHA titles The control of hazardous energy.

Two distinctions decide whether a programme works. The first is that LOTO is a programme, not a padlock — the standard defines it as procedures, training and periodic inspection together, and the lock is only the visible end of it. The second is that LOTO covers servicing and maintenance, not normal production. Most of the serious injuries I have investigated in this area sat exactly on that second line, in the grey zone where someone reached into a running machine to clear a jam and nobody had decided in advance whether that counted.

This article walks the isolation sequence the way I walk it on an assurance visit: the clause that governs each step, then what actually fails at that step on plant.

Key takeaways

The points below summarise what the standard requires, and where the most common misreadings of it sit:

  • US employers must run a documented energy control programme under 29 CFR 1910.147 covering procedures, training and an annual periodic inspection. UK employers meet the equivalent duty through PUWER 1998 Regulation 19 and, for electrical systems, Electricity at Work Regulations 1989 Regulation 12.
  • LOTO ranked fourth on OSHA's Top 10 most frequently cited standards for FY2025 — the highest-placed general industry standard on the list after hazard communication.
  • The standard does not apply to construction, agriculture, shipyard and longshoring work, electric utility generation and transmission installations, or oil and gas well drilling and servicing. Those sectors sit under different rules.
  • Push buttons, selector switches and other control-circuit devices are not energy isolating devices under 1910.147(b). Locking a stop button is not lockout.
  • Lockout is the default. Tagout alone is permitted only where the isolating device cannot accept a lock, or where the employer can demonstrate the tagout programme delivers protection equivalent to a lock.
  • OSHA sets no fixed retraining interval for LOTO. Retraining is triggered by change and by inspection findings — the widely repeated "annual LOTO training" rule is not in the standard.

What lockout/tagout actually is — and what it is not

Lockout is the placement of a lock on an energy isolating device so that the device, and the equipment it controls, cannot be operated until the lock comes off. Tagout is the placement of a prominent warning tag doing the same job by instruction rather than by physical restraint. The difference matters because one of them stops a hand and the other only asks it to stop.

Underneath both sits the definition that causes the most confusion on plant. An energy isolating device is a mechanical device that physically prevents the transmission or release of energy — a manually operated circuit breaker, a disconnect switch, a line valve, a block. Section 1910.147(b) then closes the door explicitly: push buttons, selector switches and other control circuit type devices are not energy isolating devices. A stop button interrupts a signal. A disconnect interrupts the energy. Locking the first and calling it isolation is one of the more common findings I write up, and it is usually made in good faith by someone who has never had the distinction explained.

The energy sources you have to account for

The standard's definition of an energy source is deliberately broad: electrical, mechanical, hydraulic, pneumatic, chemical, thermal, or other energy. In practice, the sources that get missed on a walkdown are almost never the main incomer. They are the second feed nobody documented, and the energy the machine is still holding after the power is off.

The sources I check for on every isolation walkdown, in the order they get forgotten, are:

  • Stored pneumatic and hydraulic pressure — accumulators hold pressure long after the pump stops
  • Gravitational energy — a raised platen, ram, counterweight or elevated conveyor section that needs blocking or cribbing, not just isolating
  • Rotational inertia — a flywheel or fan coasting down is still energised until it stops
  • Thermal energy — steam tracing, jacketed vessels, and surfaces that stay above burn threshold for hours
  • Chemical energy — process line contents, which is why blank flanges and bolted slip blinds are named as lockout devices in the standard
  • Capacitive and battery-backed circuits — drives, UPS supplies and control power that survive the main disconnect

Lockout versus tagout: why lockout is the default

Section 1910.147(c)(2) sets a clear hierarchy. Where an isolating device is capable of being locked out, the programme must use lockout, unless the employer can demonstrate that a tagout system will provide full employee protection. Where the device cannot accept a lock, tagout is permitted — but 1910.147(c)(2)(iii) requires that any equipment newly installed, or subject to major repair, renovation or modification after 2 January 1990, has isolating devices designed to accept a lock. Tagout, in other words, is a shrinking exemption for legacy hardware, not a design choice.

LockoutTagout
MechanismPhysical restraint on the isolating deviceWarning instruction only
When permittedAlways the defaultDevice cannot be locked, or equivalent protection demonstrated under (c)(3)
Extra measures requiredNone beyond the standardRemoval of a circuit element, blocking a controlling switch, opening an extra disconnect, or removing a valve handle — 1910.147(c)(3)(ii)
Hardware requirementNot removable without excessive force or bolt cuttersAttachment non-reusable, self-locking, minimum unlocking strength of 50 lb (approx. 22 kg)
Training burdenStandard authorised-employee trainingAdditional training on the six specific limitations of tags in (c)(7)(ii)
Periodic inspectionReview with each authorised employeeReview with each authorised and affected employee
Diagram showing industrial press machine components labeled as isolation devices or control devices, including main disconnect, line valve, hydraulic accumulator, stop button, selector switch, and raised ram, per 29 CFR 1910.147(b).

When LOTO applies — scope, exclusions and the production boundary

Two questions decide whether 1910.147 governs a job: is this servicing or production, and is this sector even covered? Both get answered wrongly often enough that they are worth settling before any procedure is written.

Sectors the standard does not cover

Section 1910.147(a)(1)(ii) removes five categories from scope. This is not a technicality — it decides which rulebook a supervisor should be holding. Construction and agriculture are out, as is work covered by the shipyard, marine terminal and longshoring parts. Installations under the exclusive control of electric utilities for power generation, transmission and distribution are out. Exposure to electrical hazards from work on, near or with conductors in electric-utilization installations sits under Subpart S instead. And oil and gas well drilling and servicing is excluded outright.

The sectors excluded from 1910.147, and where the duty sits instead, are:

  • Construction29 CFR 1926.417, a three-paragraph tagging provision that does not mirror 1910.147
  • Agriculture — Part 1928
  • Shipyards, marine terminals, longshoring — Parts 1915, 1917 and 1918
  • Electric utility generation, transmission and distribution29 CFR 1910.269: paragraph (d) for generation installations, paragraph (m) for de-energising lines and equipment
  • Electric-utilization installations — Subpart S, principally 1910.333
  • Oil and gas well drilling and servicing — no LOTO-specific standard; the General Duty Clause and operator standards apply

The line between production and servicing

Normal production operations are not covered by 1910.147. Servicing that takes place during normal production is covered only in two situations, set out at 1910.147(a)(2)(ii): where an employee has to remove or bypass a guard or other safety device, or where an employee has to place part of the body into the point of operation or an associated danger zone.

Against that sits the exception every plant leans on. Minor tool changes and adjustments, and other minor servicing activities during normal production, fall outside the standard on two conditions. They must be routine, repetitive and integral to the use of the equipment for production. And the work must be performed using alternative measures that provide effective protection. The last clause is the one that gets dropped. "Routine and repetitive" is not a defence on its own; without effective alternative protection, the exception does not exist.

Auditing a coating line at Glenbrook for BlueScope, I found a light curtain muted during a changeover with no documented temporary mode authorisation. The changeover was genuinely routine and genuinely repetitive — the crew ran it several times a shift, and everyone treated it as minor servicing. What was missing was the third condition. Muting the curtain removed the safeguard without putting anything in its place, so the activity had walked out of the minor servicing exception and into full lockout territory without anyone noticing the boundary.

I stopped the line, had the safeguard restored, and required documented mode control before changeovers restarted. Unauthorised mute events dropped once standard work was rolled out. The transferable check is short: if your alternative measure is "the operator is careful," you do not have an alternative measure, and the minor servicing exception does not apply to you.

Two narrower exclusions

Cord and plug connected equipment is outside the standard where unplugging controls the hazard and the plug stays under the exclusive control of the person doing the work. Exclusive control is literal — the plug in a pocket or under a lockout cap, not simply unplugged and lying on the floor where a passing operator can reconnect it.

Hot tap operations on pressurised transmission and distribution lines are excluded where the employer demonstrates that continuity of service is essential, that shutdown is impractical, and that documented procedures and special equipment provide proven effective protection. All three limbs, demonstrated, not asserted.

Flowchart decision tree for determining if regulation 1910.147 lockout tagout applies to a job, starting with sector exclusions and progressing through servicing, maintenance, guard removal, and routine task questions.

What the law requires — United States, United Kingdom, international

The duty is recognisable across jurisdictions; the drafting style is not. OSHA prescribes a sequence and a documentation regime. The UK sets a goal and leaves the method to risk assessment. Anyone writing one procedure for a multinational estate has to satisfy the prescriptive one to satisfy both.

United States

29 CFR 1910.147(c)(1) requires an energy control programme made of three parts: energy control procedures, employee training, and periodic inspections. Procedures must be developed, documented and used — with a narrow exception at (c)(4)(i) that only applies when all eight listed conditions hold simultaneously, including that the machine has a single energy source, no stored or residual energy, and no history of unexpected activation during servicing. In seventeen years I have seen that exception claimed far more often than it has actually applied.

Where a procedure is required, 1910.147(c)(4)(ii) sets its minimum contents: a statement of intended use; the specific steps for shutting down, isolating, blocking and securing; the steps for placing, removing and transferring devices and who is responsible for them; and the specific requirements for testing the equipment to verify that the energy control measures worked.

One interface is worth knowing if your plant contains both machinery and fixed electrical equipment. A procedure complying with paragraphs (c) to (f) of 1910.147 is deemed to comply with the lockout and tagging requirements of 1910.333(b)(2), provided it addresses the electrical hazards in Subpart S and incorporates the extra provisions at 1910.333(b)(2)(iii)(D) and (b)(2)(iv)(B). That is what allows one energy control programme to cover both, rather than two parallel systems.

United Kingdom

PUWER 1998 Regulation 19 states that every employer must ensure that, where appropriate, work equipment is provided with suitable means to isolate it from all its sources of energy — and that those means are not suitable unless they are clearly identifiable and readily accessible. Regulation 19(3) adds the reconnection duty: appropriate measures must ensure that restoring energy does not expose anyone to risk.

For electrical systems, Electricity at Work Regulations 1989 Regulation 12 supplies the sharper definition. Isolation there means the disconnection and separation of the equipment from every source of electrical energy, in such a way that the disconnection and separation is secure. That word does the same work as OSHA's lock.

International consensus standards

Two documents matter outside the regulatory instruments, and one of them has recently moved. ISO 14118:2017, Safety of machinery — Prevention of unexpected start-up, is the machinery-side counterpart used across EU design and installation practice. ANSI/ASSP Z244.1-2024 superseded the 2016 (R2020) edition and made a substantive change: alternative methods are now treated as a co-equal choice with lockout and tagout where a documented risk assessment supports them, rather than as a fallback.

That divergence is worth flagging to any US reader who has heard "Z244.1 allows alternative methods" and drawn the wrong conclusion. Z244.1 is a consensus standard. It does not amend 1910.147, and OSHA enforces the regulation. Alternative methods can be excellent engineering and still be a citation.

RequirementUnited StatesUnited KingdomInternational
Primary instrument29 CFR 1910.147PUWER 1998 Reg. 19; EAWR 1989 Reg. 12ISO 14118:2017
Written procedureMandatory, with an eight-condition exceptionNot prescribed; follows from risk assessment dutyDesign-side requirements
Documented inspection cycleAnnual, certified, by an independent authorised employeeNot prescribed; adequacy demonstrated by risk assessment
Alternative methodsNot recognised in the regulationPermitted where risk assessment supportsISO 14118 clause on other measures; ANSI/ASSP Z244.1-2024 treats as co-equal
Reconnection duty1910.147(e) release sequenceReg. 19(3)

For anyone writing one procedure to cover sites in several countries, the practical drafting rules are:

  • Write to the most prescriptive instrument, which in this set is 1910.147 — satisfying it will satisfy PUWER Reg. 19, but not the reverse
  • Keep the documented annual inspection globally, even where only the US mandates it, because it is the cheapest evidence of adequacy a UK inspector will ask for
  • Do not import alternative methods into a US site on the strength of Z244.1-2024 or ISO 14118 alone
  • State the jurisdiction on the procedure itself, so a travelling contractor knows which rules the site is operating under
Comparison table showing energy control procedure requirements across US, UK, and International standards, with rows covering written procedures, inspection cycles, alternative methods, and reconnection duties.

The lockout/tagout procedure, step by step

Section 1910.147(d) is unusual in that it states the elements "shall be done in the following sequence." The order is a requirement, not a suggestion, and every step below has a characteristic failure attached to it.

Step 1 — Preparation for shutdown

Before anything is switched off, the authorised employee must have knowledge of the type and magnitude of the energy, the hazards it presents, and the means of controlling it. In practice this means reading the equipment-specific procedure at the equipment, not at the desk, and reconciling it against what is physically in front of you.

Step 2 — Machine or equipment shutdown

Shutdown follows the established procedure for that machine, and 1910.147(d)(2) requires it to be orderly — a shutdown that creates a new hazard by dumping material, stalling a heater or stranding a load has failed the clause even though the machine stopped.

Step 3 — Machine or equipment isolation

All isolating devices needed to control energy to the machine are located and operated so the equipment is separated from its sources. This is the step where the paperwork and the plant most often disagree.

During a mill outage at Port Kembla, I traced a LOTO sheet on a legacy hydraulic unit against the actual valves. The sheet pointed to the wrong isolation valve. The crew had followed the document exactly, which is what you want them to do, and the document was wrong — so following it would have left the unit live while everyone believed it was dead.

I stopped the job, had the labelling and the map corrected, and required field verification of every point before restart. The finding then propagated: a sweep of that unit family cleaned up wrong-label findings across the mill. A LOTO map that lies is worse than no map, because no map makes people cautious and a wrong map makes them confident.

Step 4 — Applying the lockout or tagout devices

Devices are affixed to each isolating device by authorised employees. Locks hold the device in the safe or off position; tags must clearly indicate that moving the device is prohibited, and where a lock could have been fitted, the tag goes at the same point the lock would have gone.

The hardware requirements in 1910.147(c)(5) are more specific than most programmes realise:

  • Durable — capable of withstanding the environment for the full expected exposure, with tags legible after weather, damp and corrosive exposure
  • Standardised — within the facility by colour, shape or size; tags additionally standardised by print and format
  • Substantial — locks not removable without excessive force or bolt cutters; tag attachments non-reusable, attachable by hand, self-locking, with a minimum unlocking strength of 50 lb (approx. 22 kg)
  • Identifiable — the device must show who applied it
  • Singularly used — LOTO devices are the only devices used for energy control, and are not used for anything else

Step 5 — Releasing stored energy

After the devices are on, all potentially hazardous stored or residual energy must be relieved, disconnected, restrained or otherwise rendered safe. Where energy can reaccumulate to a hazardous level, 1910.147(d)(5)(ii) requires verification of isolation to continue until the work is finished — a one-time gauge reading does not discharge that duty on a system that repressurises.

Step 6 — Verification of isolation

Before work starts, the authorised employee verifies that isolation and de-energisation have been achieved. Try the start controls, confirm nothing moves and nothing reads live, then return every control to neutral or off.

Arriving at a wellsite tie-in in the Cooper Basin for Santos, I found a crew preparing to break a flange with incomplete drain and purge evidence. Everything upstream had been done. The isolation was in place, the permit was live, and the one thing nobody could produce was proof that the line between the isolations was actually empty.

I stopped the break, required verified drain and purge, and the job restarted under a field-walked permit. First-break verification became a hard gate on that package afterwards. The principle transfers to any energy source: if you cannot prove the line is dead, you do not break it. Verification is evidence, not confidence.

Infographic showing six steps of industrial equipment isolation procedure with illustrations of each stage, corresponding regulations, and potential failure points for each step in the lockout-tagout safety process.

Returning equipment to service — the half most articles skip

Almost every LOTO guide ends at verification. The standard does not. Paragraphs (e) and (f)(1) govern putting energy back, and in my experience the restart is where the injuries cluster, because the machine is intact, the crew is tired, and everyone assumes the dangerous part is behind them.

The release sequence

Before devices come off, 1910.147(e) requires three things in order. The work area is inspected to confirm non-essential items have been removed and that components are operationally intact — guards back on, panels closed, tools out. The area is then checked to confirm all employees are safely positioned or removed. Only then do devices come off, and affected employees must be notified after removal and before the machine is started.

Each device is removed by the employee who applied it. The exception at 1910.147(e)(3) permits removal under the employer's direction when that person is unavailable, but only where a specific documented procedure exists and three conditions are satisfied.

The three elements a compliant lock-removal procedure must contain are:

  1. Verification by the employer that the authorised employee who applied the device is not at the facility
  2. All reasonable efforts made to contact that employee to tell them their device has been removed
  3. Confirmation that the employee knows their device was removed before they resume work at that facility

The third condition is the one programmes drop, and it is the one that protects the returning worker on the next shift.

Testing or repositioning mid-job

Where the machine has to be energised temporarily to test or reposition it, 1910.147(f)(1) sets a five-action sequence: clear the equipment of tools and materials, remove employees from the area, remove the devices, energise and test, then de-energise and reapply all energy control measures before servicing continues.

Reapplication is the step that gets skipped under schedule pressure. A crew that tests, gets the result they wanted, and goes straight back in without re-isolating has spent the rest of the job unprotected — and the paperwork will still show a completed lockout.

Flowchart showing restart sequence 1910.147(e) and (f)(1) with two bands: Band A covers release to service steps from inspection through startup, and Band B details test or reposition mid-job procedures ending with de-energize and reapply controls.

Group lockout, shift handover and contractors

Isolation is straightforward when one person locks one device and stays there until the job is done. Real maintenance is a crew across three trades over two shifts with a contractor in the middle, and 1910.147(f) exists for that.

Group lockout

Where servicing is done by a crew, craft or department, the group procedure must give each person protection equivalent to a personal lock. Section 1910.147(f)(3)(ii) then specifies how. Primary responsibility is vested in an authorised employee for a set number of workers. That person must have a means of establishing the exposure status of each group member. Where several crews are involved, a designated coordinator holds overall control. And — the operative provision — each authorised employee affixes a personal device to the group lockbox or hasp when they start work, and removes it when they stop.

The mechanic is what makes it safe. The last personal lock off the box is what releases the equipment, so no individual can be locked in or locked out by someone else's schedule.

Shift and personnel changes

Section 1910.147(f)(4) requires specific procedures for the orderly transfer of protection between off-going and oncoming employees. Continuity is the whole point: there must be no interval in which the isolation is unowned. A handover that removes the off-going crew's locks before the oncoming crew arrives has created exactly the gap the clause exists to close.

Outside personnel and contractors

Where outside servicing personnel are involved, 1910.147(f)(2) requires the on-site employer and the outside employer to inform each other of their respective procedures, and the on-site employer to ensure its own employees understand and comply with the contractor's restrictions. The exchange runs both ways, which surprises people. A host site cannot simply hand over its own procedure and consider the duty met.

The interface questions I ask on any multi-employer isolation are:

  • Whose lock is the controlling lock, and who physically holds the lockbox key
  • Whose procedure governs where the host and contractor documents differ on verification or on device standards
  • How the contractor's authorised employees were verified as trained, and by whom
  • What happens at handover when the contractor demobilises mid-outage with the isolation still in place
  • Whether the contractor's locks are distinguishable from the host's on sight
Infographic comparing proper and improper group lockbox procedures for industrial safety, showing correct lockout practices versus common failures in equipment isolation protocols.

Training, competence and the annual periodic inspection

These are the two programme elements that carry citations more often than the hardware does, and they are the two that a supervisor can fix without a capital budget.

Three categories of worker

Section 1910.147(c)(7)(i) sets different training for three groups, and confusing them is a fast route to a finding. Authorised employees — those who apply and remove devices — must be trained in recognising applicable energy sources, the type and magnitude of energy present, and the methods of isolation and control. Affected employees must be instructed in the purpose and use of the procedure. All other employees working in areas where LOTO may be used must be instructed about the procedure and about the prohibition on attempting to restart locked or tagged equipment.

Where tagout is used, authorised and affected employees also need training on the six limitations of tags listed at 1910.147(c)(7)(ii) — including that a tag provides no physical restraint, that it must never be bypassed or defeated, and that tags can evoke a false sense of security.

Retraining is triggered, not scheduled

There is no annual training interval in 1910.147, despite how often you will read otherwise. Retraining is required whenever there is a change in job assignment, a change in machines, equipment or processes that presents a new hazard, or a change in the energy control procedures. It is also required whenever a periodic inspection reveals — or the employer has reason to believe there are — deviations or inadequacies in an employee's knowledge or use of the procedures. Training must be certified with each employee's name and the dates.

A fixed annual refresher is a reasonable programme design. It is not the legal requirement, and a site that runs the annual course while ignoring the change triggers has met neither.

The periodic inspection most sites do wrong

An inspection of the energy control procedure is required at least annually. Three details in 1910.147(c)(6) get missed:

RequirementClauseCommon failure
Inspector independence(c)(6)(i)(A)Performed by an authorised employee other than those using the procedure being inspected — sites routinely have crews inspect their own procedure
Employee review(c)(6)(i)(C)–(D)The inspection includes a face-to-face review of responsibilities with each authorised employee; for tagout, with affected employees too
Certification contents(c)(6)(ii)Must identify the machine, the date, the employees included, and the person who performed it — not a single site-wide sign-off sheet
Scope(c)(6)(i)It is an inspection of the procedure in use, observed at the equipment, not a desk review of the document

The retraining triggers that a compliant programme has to be able to detect are:

  • A change in job assignment that brings an employee into an authorised or affected role
  • A change in machines, equipment or processes that presents a new hazard
  • A change to the energy control procedure itself, however minor the wording
  • A periodic inspection finding of deviation from, or inadequacy in, an employee's use of the procedure
  • Any other reason to believe an employee's knowledge has lapsed
Infographic showing six key requirements for a periodic inspection certification card under 29 CFR 1910.147(c)(6)(ii), including machine identification, inspection date, employees involved, inspector details, and responsibilities review.

Best practices that survive an audit

Everything above is the requirement. What follows is what I have found separates programmes that hold up under pressure from programmes that hold up under inspection — drawn from mill outages at BlueScope, fixed plant at Newmont and BHP, pharmaceutical and biotech suites at Merck and CSL, and night sortation at DHL, where the same failures recur across sectors that share almost nothing else.

The strongest practice is unglamorous: field-verify every isolation point on the procedure at least once, and re-verify after any modification. The Port Kembla finding was not an unusual case. Legacy plant accumulates undocumented changes, and equipment-specific procedures written from P&IDs drift from the steel. Verification at the valve is the only thing that catches it.

The practices I check for on an assurance visit, in the order they predict programme health, are:

  1. Isolation points are labelled on the plant to match the procedure exactly — same identifier, same wording, physically present and legible
  2. Personal locks are personally held — issued to a named individual, keyed differently, never stored in a shared drawer or a supervisor's desk
  3. Verification is evidenced, not asserted — the procedure names the test method and the expected reading for each energy type
  4. Stored energy has a named control per source, not a generic "bleed down" line covering six accumulators
  5. The minor servicing exception is decided in writing, per task — with the alternative protective measure identified, so the boundary is not left to the operator at 3 a.m.
  6. Group lockbox discipline is observed, not described — walk to the box during an outage and count the personal locks against the crew on the job
  7. Restart is treated as a controlled step with the same rigour as isolation, including guard refit sign-off
  8. The periodic inspection is done by someone who does not use that procedure, and the certification names them

One further point, offered as my view rather than as a requirement. Where a site has a genuine, documented, high-frequency task that lockout makes more dangerous — the classic case being a jam clearance that requires the machine to cycle — the honest answer is an engineering change or a risk-assessed alternative method under ANSI/ASSP Z244.1-2024, formally approved. It is not a quiet local practice that nobody wrote down. If the deviation cannot survive being written on paper and signed, it will not survive an investigation either.

Pyramid diagram showing four levels of quality assurance checks: Hardware foundation with locks and devices, Accuracy layer with isolation points, Behaviour layer with verification, and Assurance top level with independent inspections and certifications.

Frequently asked questions

These are the questions that come up most often in LOTO training rooms and on audit closeouts, answered against the clause rather than against custom.

What are the six steps of lockout/tagout?

Preparation for shutdown, machine shutdown, isolation of all energy sources, application of lockout or tagout devices, release of stored energy, and verification of isolation. Section 1910.147(d) requires them in that order. Two further sequences follow: release to service under (e), and mid-job testing under (f)(1).

Who is allowed to remove a lockout device?

The employee who applied it. Where that person is unavailable, 1910.147(e)(3) permits removal under the employer's direction, but only under a documented procedure that verifies the employee is off site, makes all reasonable efforts to contact them, and confirms they know before they resume work at that facility.

How often is lockout/tagout training required?

The standard sets no fixed interval. Retraining is triggered by a change in job assignment, machinery, process or procedure, or by a periodic inspection revealing deviations. Training must be certified with each employee's name and dates. The energy control procedure itself is inspected at least annually.

Can I use tagout instead of lockout?

Only where the isolating device cannot accept a lock, or where the employer demonstrates the tagout programme provides protection equivalent to a lock — which requires additional measures such as removing a circuit element or a valve handle. Equipment installed or majorly modified after 2 January 1990 must be designed to accept a lock.

Does lockout/tagout apply to construction work?

No. 29 CFR 1910.147(a)(1)(ii)(A) excludes construction and agriculture. Construction lockout of circuits sits under 29 CFR 1926.417. Electric utility generation and transmission work falls under 1910.269, and well drilling and servicing is excluded from 1910.147 entirely.

Is a stop button an energy isolating device?

No. Section 1910.147(b) states that push buttons, selector switches and other control circuit type devices are not energy isolating devices. Isolation requires a mechanical device that physically prevents transmission or release of energy — a disconnect, a breaker, a line valve, or a block.

What is the difference between LOTO and a permit to work?

LOTO controls the energy; a permit to work controls the authorisation to do the job. They are complementary. A permit that authorises work on plant that has not been isolated and verified under the energy control procedure is a permit for an unprotected job.

About the author — Ethan Hughes

Ethan Hughes is an Australian Major Hazard and Process Safety Assurance Consultant with 17 years of continuous field experience across 14 countries, covering mining, steelmaking, upstream oil and gas, biotech and pharmaceutical manufacturing, EPC brownfield projects and logistics. His focus is field verification — checking that isolation, first-break and barrier controls still work at the equipment, not only where documents say they exist. He has inspected 190+ workplaces and conducted 75+ audits. He currently leads Hughes Major Hazard Assurance (since January 2026), based in Melbourne, after senior roles including Steel Mill HSE Manager at BlueScope Steel, Upstream Process Safety Advisor at Santos, and Mining Process Safety & Critical Control Lead at BHP.

Credentials: ISO 45001 Lead Auditor · ISO 14001 Internal Auditor · ICAM Incident Investigation · NEBOSH International General Certificate (or equivalent) · Major Hazard Facility / Process Safety Management Awareness · HAZOP Facilitator Awareness

Sources

Ethan HughesE
WRITTEN BY

Ethan Hughes is an environmental scientist passionate about sustainable workplace practices. With a background in environmental impact assessment and waste management, Ethan helps businesses reduce their ecological footprint without compromising safety standards. His OSHE Blog articles blend eco-conscious strategies with real-world safety solutions.

Related posts