How to Verify Lockout/Tagout Before Maintenance Starts
A field-ready lockout/tagout verification method that tests isolation, stored energy, ownership, and restart control before maintenance begins.

Key takeaways
- 01Define the exact maintenance boundary before selecting isolation points.
- 02Identify every energy source, including stored and alternate energy.
- 03Match each source to a physical isolation point and named owner.
- 04Prove zero energy at the point of work with an approved test method.
- 05Control restart with the same discipline used for isolation.
Maintenance is ready to begin, the permit is signed, and every worker has received a lock. The job can still be unsafe if nobody has proved that the machine is incapable of moving, energizing, pressurizing, or releasing stored energy.
Lockout/tagout verification is therefore more than checking whether locks are visible. It is a controlled decision that confirms the isolation boundary, the people who own it, the energy that remains inside the system, and the conditions for a safe restart. OSHA 29 CFR 1910.147 provides the regulatory anchor in the United States, while ISO 45001:2018 places operational control and change management inside the wider safety management system.
What you need before starting
Before the verification begins, obtain the current equipment-specific procedure, the work order, the isolation diagram, the names of authorized and affected employees, and the planned test method. The procedure should identify every energy source, including electrical, hydraulic, pneumatic, thermal, chemical, gravitational, and process energy.
Use the site process that connects permit-to-work with isolation control. The control-of-work decision tests are useful here because a lock is not evidence that the job is ready by itself. If the task could create a serious incident, preserve the original condition and record the verification in a way that supports later review, consistent with the evidence discipline described in this incident-evidence guide.
Step 1: Define the maintenance boundary
Write down exactly what will be opened, entered, adjusted, cleaned, tested, or replaced. A vague description such as “repair pump” leaves too much room for an isolation that protects the motor but not the connected line, coupling, impeller, or automatic start command.
Mark the equipment boundary on the drawing or work pack, then ask which adjacent systems can affect the task. The boundary should be specific enough that a second person can walk to the correct valves, breakers, disconnects, and bleed points without relying on memory.
Step 2: Identify every energy source
Build the energy list from the equipment design and the work history rather than from the nameplate alone. Check normal supply, backup supply, remote control, gravity, pressure, stored electrical charge, hot surfaces, chemicals, rotating parts, and energy that can enter through another connected system.
ANSI/ASSP Z244.1 is a useful technical reference because it treats hazardous energy control as a system of methods, verification, and employee protection, not as a lock inventory exercise. When the team cannot explain how an energy source reaches the work point, the isolation plan is not complete.
Step 3: Match each source to an isolation point
For every source, record the physical isolation point, the device used, the lock number or identifier, and the person responsible for applying it. A control-room command, a closed valve, or a stop button may control a process without isolating the energy that can injure a worker.
Compare the field position with the current diagram because temporary piping, bypasses, recent modifications, and mislabeled disconnects can invalidate an otherwise correct procedure. If the field does not match the drawing, stop the job and escalate the discrepancy through management of change rather than improvising a new isolation.
Step 4: Apply locks and tags with clear ownership
Each lock and tag should communicate who controls the isolation and how that person can be contacted. The authorized employee who applies the device must understand the procedure, the hazards, and the release conditions, while affected employees need to know that the equipment is unavailable and why.
Group lockboxes can protect complex work, but they do not remove individual accountability. The group arrangement should show when the primary isolation was established, who verified it, which workers are protected, and how each worker removes personal protection before restart.
Step 5: Release or restrain stored energy
Isolation is incomplete until residual energy has been dissipated, blocked, restrained, or otherwise made safe. Open the approved bleed or drain path, discharge capacitors, lower or block suspended parts, secure rotating components, cool hot surfaces, and control pressure according to the equipment procedure.
Do not treat a zero reading at one point as proof that the entire system is safe. A trapped section can remain pressurized behind a closed valve, and a suspended component can still move after an electrical supply is removed. The test must match the energy type and the failure mode that the procedure identifies.
Step 6: Prove zero energy at the point of work
Use the approved test instrument or functional test at the location where the worker will be exposed. First confirm that the instrument works on a known live source when the procedure requires it, then test the isolated equipment, and confirm the instrument again afterward. Record the result, the tester, and the time.
For electrical work, the test method must reflect the voltage and equipment category. For mechanical or process work, the team may need a try command, pressure gauge observation, drain verification, rotation check, or physical restraint inspection. The point is not to perform a ritual; it is to create evidence that the expected energy is absent.
Step 7: Challenge the isolation under controlled conditions
Attempt the normal start command only when the procedure authorizes it and everyone is clear of danger. The test should confirm that the machine does not start, the control system reports the expected state, and no alternate source can energize the equipment.
After the try step, return controls to the neutral or off position. A failed challenge is not a minor paperwork issue. It means the isolation boundary, device selection, or control logic requires correction before anyone enters the exposure zone.
Step 8: Confirm work release and restart control
Before maintenance begins, the supervisor and the authorized employee should confirm that the verification is complete, the work group understands the boundary, and the permit reflects the actual field condition. If the job changes, the team should pause and reassess rather than extending the original isolation by assumption.
Restart deserves the same discipline. Remove tools and temporary restraints according to the procedure, confirm that people are outside the danger zone, account for every personal lock, notify affected employees, and restore energy in a controlled sequence. HSE guidance in HSG85 emphasizes that isolation arrangements must remain effective through preparation, execution, and reinstatement, which is why restart cannot be treated as an administrative afterthought.
Final verification checklist
- Confirm the maintenance boundary and adjacent systems.
- List every hazardous energy source and its isolation point.
- Check the field condition against the current diagram.
- Verify lock, tag, group-lockbox, and ownership records.
- Release, block, restrain, or drain stored energy.
- Test at the point of work with the approved method.
- Complete the controlled try step and return controls to neutral.
- Define worker release, notification, and restart conditions.
James Reason's work on latent failures explains why a visible lock can coexist with a weak protection system. The failure may sit in a missing diagram, an unchallenged assumption, a change that was never incorporated, or a handover that transferred responsibility without transferring knowledge. Andreza Araujo's experience across more than 250 cultural transformation projects supports the same practical conclusion: verification becomes credible when supervisors can see the decision, the evidence, and the person who owns the next action.
A lockout/tagout program is working when maintenance can explain what was isolated, how zero energy was proven, what would invalidate the control, and who governs restart. That standard is stricter than asking whether locks are present, and it is the standard that protects people when the plan meets the machine.
For a deeper operational review, connect this method with the field verification approach used for fall-arrest anchors, then audit whether your own procedures produce evidence or only signatures.
Frequently asked questions
What is the most important lockout/tagout verification step?
Does pressing the stop button count as lockout/tagout?
Who should verify a lockout/tagout isolation?
What should happen when the equipment does not match the isolation diagram?
Why is restart part of lockout/tagout verification?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.