Lockout tagout (LOTO) exists for one reason: to make sure machinery and electrical equipment cannot be energised while someone is working on it. When it fails, the results are severe, and the failures are rarely exotic. They are the same handful of avoidable mistakes made under time pressure. This guide walks through the LOTO errors that most often lead to serious injury or death, and how a disciplined safe system of work prevents each one.
Mistake 1: failing to identify every energy source
The most dangerous LOTO mistake is isolating the obvious energy source and missing the rest. A machine that runs on electricity may also hold pneumatic pressure, hydraulic fluid under load, a raised weight held by gravity, or a second electrical feed. Locking off one supply while another remains live gives a false sense of safety that is worse than none at all.
Before any isolation, every energy source feeding the equipment must be identified and accounted for. That means reading the machine documentation, tracing the supplies, and treating multi-feed equipment with particular care. If you do not know how many ways energy can reach the point of work, you are not ready to lock off.
Mistake 2: using tags without locks
A tag is a warning. A lock is a control. Relying on a tag alone, hoping that nobody will operate an isolator that carries a "do not switch" label, is one of the most common and most serious shortcuts. Tags can be ignored, blown off, or overridden by someone who never saw the person at risk.
A proper lockout physically prevents the isolator from being moved, using a padlock and, where needed, a lockout device sized to the switch, valve or breaker. Powerpoint Engineering supplies Master Lock safety padlocks and lockout devices for exactly this. The tag says why; the lock makes sure. One without the other is a gap waiting to be exploited.
Mistake 3: skipping the prove-dead step
Isolating a circuit and assuming it is dead has killed people who did everything else right. Isolators can fail, the wrong one can be locked, or a circuit can be back-fed from another source. The only way to know a circuit is dead is to test it.
Prove the tester on a known live source, test the isolated conductors to confirm they are dead, then prove the tester on the known source again to confirm the tester itself did not fail during the check. This prove, test, prove routine is the discipline that turns an assumption into a fact. Skipping it, or using an unproven voltage indicator, removes the last safeguard before someone puts their hands on the work.
Mistake 4: ignoring stored and residual energy
Switching off is not the same as making safe. Capacitors hold charge, springs stay compressed, flywheels keep turning, and hydraulic and pneumatic systems hold pressure long after the supply is cut. Beginning work before that stored energy is released is a frequent and dangerous error.
After isolation, stored energy must be discharged or restrained: capacitors bled down, systems vented, moving parts brought to rest and blocked, and raised loads lowered or supported. Only when the equipment is at a genuine zero-energy state is it safe to start.
Mistake 5: weak group lockout and poor communication
When several people work on the same equipment, one lock is not enough. A single lock removed by one worker leaving early can re-expose everyone still inside the machine. This is where group lockout fails when it is treated casually.
In a group lockout, each person applies their own lock, often through a group lockout box or hasp, so the equipment cannot be re-energised until the last person removes the last lock. Clear communication before isolation and before re-energising is part of the same control. Everyone who could be at risk must know the equipment is locked off, and must confirm they are clear before power is restored.
Mistake 6: removing another person's lock
A padlock on an isolator represents a specific person's safety. Cutting off or removing someone else's lock so a job can continue is a grave breach, because you cannot be certain that person is clear of the machine. People have been injured when a lock was removed while they were still working out of sight.
Locks should only ever be removed by the person who applied them. Where that is genuinely impossible, a controlled removal procedure with senior authorisation and positive confirmation that the worker is clear is the only acceptable route, and it should be rare.
Mistake 7: no written procedures or training
Many LOTO failures trace back to the absence of a documented, equipment-specific procedure, or to workers who were never properly trained. Relying on memory and habit means the steps that matter most, identifying every source, proving dead, releasing stored energy, get skipped under pressure.
Effective LOTO needs machine-specific procedures, the right hardware to hand, and people trained to use both. Powerpoint Engineering helps on all three fronts, from customised lockout stations and shadow board systems to Lockout Tagout Safety Awareness training.
The common mistakes at a glance
|
Mistake |
The control that prevents it |
|
Missing an energy source |
Identify and isolate every source before work |
|
Tag with no lock |
Physical padlock and lockout device on every isolation point |
|
Not proving dead |
Prove, test, prove with a known live source |
|
Stored energy left in the system |
Discharge, vent, block and restrain before starting |
|
Casual group lockout |
One lock per person via a group box or hasp |
|
Removing another's lock |
Only the applier removes their lock |
FAQs
Why is a tag on its own not enough?
A tag only warns; it does not physically stop someone operating the isolator. A padlock and lockout device prevent the switch, valve or breaker from being moved, so the equipment cannot be re-energised by mistake. Best practice uses both together.
How do you verify zero energy?
Test for it. Prove your voltage tester on a known live source, test the isolated equipment to confirm it is dead, then prove the tester again. For non-electrical energy, confirm pressure is vented, moving parts are stopped and stored mechanical energy is released.
Who is allowed to remove a lockout padlock?
Only the person who applied it. This guarantees that the individual whose safety the lock protects has finished and is clear of the equipment before it can be energised. Removal by anyone else requires a strict, authorised exception procedure.
Most LOTO incidents come down to a missed source, a tag instead of a lock, or a skipped prove-dead check. If you want to close those gaps, talk to us about lockout hardware, customised stations and Lockout Tagout Safety Awareness training for your team.