Lock Out Tag Out Procedures
One machine, every energy source, and a written way to prove there is nothing left in it before anybody puts a hand inside.
- One procedure per machine, with every isolation point named
- Ten energy types listed, and a blank row is a deliberate answer
- Zero energy proved at the point of work before anyone starts
- A written route for removing somebody else's lock
Lock Out Tag Out Procedures
One machine, every energy source
| # | Energy source | Off | Lock | Test |
|---|---|---|---|---|
| 1 | Electrical, 415V 3-phase at isolator IS-14 | |||
| 2 | Hydraulic pressure bled to zero, gauge checked | |||
| 3 | Gravity, raised parts lowered or blocked |
The document you will get. Download for the full, editable file.
Who this lockout procedure is for
Four people rely on this document, and one of them is whoever opens the machine at three in the morning.
Whoever writes the procedure
You are working machine by machine. The energy source inventory is the part that takes the time, because it needs the isolation device and its location, not just the energy type.
The authorised person applying locks
You are following it under time pressure. The shutdown and isolation order, and the verification steps, are the lines that keep you out of a machine that still has something in it.
Maintenance or engineering lead
You own the set. What matters to you is that every machine has a procedure and that each one names real isolation points, which is what a generic procedure cannot do.
Safety lead or auditor
You are checking whether it is real. Named authorised persons, an energy inventory with no deleted rows, and a written lock-removal exception are the three things you look for first.
Which section matters the most in your sector
The procedure is the same shape everywhere. What changes is the section that carries the risk, and it is usually decided by who works on the machine. If you run one of these, the sector page goes further than the template does.
- FM service providers
Contractor use and group lockout. When a subcontractor works on your machine, whose permit the isolation sits under is the line that gets left blank.
FM service provider software - Healthcare
Shift handover. Isolations that run across a shift change are routine in a hospital, and the locks have to overlap rather than swap.
Healthcare maintenance software - Data centres
Electrical energy sources. Redundant supplies mean one isolator is rarely the whole answer, and a second feed is what the inventory is for.
Data centre maintenance software - Education
Authorised persons. High turnover and seasonal staff make the named-persons list the part most likely to be out of date.
Campus maintenance software - Commercial real estate
One procedure per machine. Across a portfolio the gap is not procedure quality, it is machines that have no procedure at all.
Portfolio maintenance software - Corporate facilities
Stored energy. Plant rooms full of pumps, dampers and actuators are where springs and raised parts get missed after the power is off.
Corporate facilities software
What a lock out tag out procedure should contain
A lock out tag out procedure is a written energy control document for one machine. It lists every energy source, names the isolation point for each, sets the order of shutdown and isolation, requires zero energy to be proved at the point of work, and states how the machine is brought back.
A. Fields specific to a lockout procedure
| Field | What goes in it | Why it earns its place |
|---|---|---|
| Procedure number and machine | One procedure for one machine, with asset ID and location | A generic procedure covering a plant room cannot name isolation points, which is exactly what makes it useless at the machine. |
| Authorised and affected persons | Named individuals, plus who else to notify | Authorised means trained and permitted to apply and remove locks. A job title cannot be held to that, so the form asks for names. |
| Energy source inventory | Ten energy types, each with source, magnitude, isolation device and location | The heart of the document. Electrical, hydraulic, pneumatic, mechanical, gravity, thermal, chemical, water, gas and stored energy each get a row. |
| Isolation device and where it is | The specific isolator, valve or breaker, and its location | Somebody who has never worked on this machine has to find the device. Isolator IS-14 on the plant room B wall is findable; the isolator is not. |
| Shutdown sequence | Ordered steps, with the emergency stop explicitly ruled out | The order matters, and the last line exists because people do use the emergency stop as an isolation. It removes the command, not the energy. |
| Stored energy release | Pressure, raised parts, rotation, capacitors, spring tension, heat | This is what injures people after the power is off. Every line needs a reading or an observation written beside it rather than a tick. |
| Zero energy verification | Test method and result, at the point of work | Try to start it, test for absence of voltage, prove the instrument before and after, and confirm gauges read zero where the work will happen. |
| Lock and tag register | One row per lock: applied by, time on, removed by, time off | Every person working on the machine applies their own lock and removes their own. One lock applied by a supervisor for a team is not lockout. |
| Group lockout and lockbox | The box or hasp ID, and how each worker secures it | The keys go in the box and each worker puts a personal lock on the box. It may only be opened when every personal lock has been removed by its owner. |
| Shift handover | Outgoing and incoming person, and the continuity method | The incoming person applies their lock before the outgoing person removes theirs. Locks overlap; they never swap, so the isolation is never unlocked. |
| Removing another person's lock | Attempts to contact, named authoriser, witness, incident reference | The most dangerous action in the procedure and the one most often improvised. Every line has to be completed before a lock is cut off. |
If you cut the procedure down, keep the energy inventory and the verification section. Everything else describes how to work carefully. Those two are what establish that the machine has nothing left in it, and they are the two that a generic plant-room procedure can never supply, because they are specific to one machine and one point of work.
B. What it looks like filled in
The energy source inventory for one air handling unit. The Excel register records three energy sources against LOTO-AHU-03, and the rows for energy types that are not present are kept rather than deleted.
| Energy type | Source and magnitude | Isolation device and location | Method | Verification |
|---|---|---|---|---|
| Electrical | 415V 3-phase, 32A | Isolator IS-14, plant room B wall | Rotary isolator off, padlock and tag | Test dead at terminals |
| Mechanical | Supply fan impeller, coasts to rest | Drive guard, fan chamber | Allow to stop, do not slow by hand | Visual, impeller stationary |
| Gravity | Access hatch counterweight | Hatch stay, north face | Prop fitted and pinned | Physical attempt to move |
| Pneumatic | Not present on this unit | Row kept, not deleted | ||
| Hydraulic | Not present on this unit | Row kept, not deleted |
Three live energy sources, and two rows deliberately left blank. Electrical is the one everybody isolates. Mechanical and gravity are the two that hurt people, and both are here: a fan impeller that coasts after the isolator is off, and a counterweighted hatch that moves under gravity. Note that neither is verified by a meter. One is verified by looking at a stationary impeller, the other by trying to move the hatch. The blank pneumatic and hydraulic rows are doing real work too: they record that somebody checked this unit for stored pressure and found none, which is a different statement from a procedure that never mentions pneumatics at all.
Word to write one procedure per machine and name your own isolation points, Excel for the procedure register with its days-to-review countdown, PDF for the copy displayed at the machine. Free, and yours to rebrand.
How do you write a lock out tag out procedure?
Write it at the machine, not at a desk, and write one per machine. The energy inventory is where the work is; everything else follows from it. Six steps.
Name the machine, not the area
Procedure number, machine or equipment name, asset ID, make, model and serial, and the location down to the room and line position. One procedure covers one machine, because the isolation points are what the procedure exists to name.
Name the people, not the roles
Authorised persons who may apply and remove locks, affected persons who work on or near the machine, and anybody else to notify. Then whether group lockout is required and whether contractors may work under it.
Inventory every energy source, and keep the blank rows
For each of the ten energy types: the source and its magnitude, the isolation device and where it is, the method, the lock and tag, and how it will be verified. If a type is not present, leave the row blank rather than deleting it.
Write the shutdown and isolation order, and rule out the emergency stop
Notify, bring to a normal stop, finish or park any cycle, shut down auxiliaries, confirm at rest. Then operate every isolation device in the order listed and apply a personal lock and tag to each. The emergency stop is not an isolation device.
Write the stored energy and verification steps as observations
Bleed pressure to zero and read the gauge, lower or block raised parts, let rotation stop on its own, discharge capacitors, drain and vent, allow cooling, relieve spring tension. Then prove zero energy at the point of work, with whoever is doing the job watching the test.
Write the restoration order and the lock-removal exception
Restoration is the isolation in reverse, with guards refitted and a function test before handback. Then complete section 12: what has to be true before anybody removes a lock that is not theirs, who authorises it, and the incident report it raises.
Lockout versus tagout, and why the difference matters
The two words are used together so often that the difference gets lost, and the difference is the whole point.
| Aspect | Lockout | Tagout |
|---|---|---|
| What it does | Physically prevents the device being operated | Warns that the device must not be operated |
| What it relies on | A lock, and the key in one person's pocket | Everybody reading the tag and obeying it |
| When it applies | Whenever the isolation device can accept a lock | Only where the device cannot be locked at all |
| What else is needed | Nothing beyond the lock and the tag | An additional safeguard, because a tag stops nobody |
| Who may remove it | Only the person who applied it | The same rule, with nothing physical to enforce it |
| If you only do one | Lockout, every time it is possible | Tagout is the fallback, never the preference |
Tagout alone is an exception, not a choice. Where an isolation device genuinely cannot take a lock, the procedure in this template asks for a lockable cover or the fuse removed and secured instead, and only falls back to a tag when neither is possible. That is why the energy inventory has a separate column for the lock and tag: it records which of the two you actually achieved at each device, so a machine that is only ever tagged out shows up as a machine that needs a different isolator rather than a machine with a compliant procedure.
When the template starts to feel limiting
A document handles one machine well. It handles a set of machines across a site badly, and always in the same four ways. Building the wider programme is a separate job, and our guide to LOTO procedure steps and building a LOTO program covers that ground.
The review date cannot chase itself
The register counts the days to the next review, but only while somebody has the file open. A procedure that went out of date when the machine was modified stays in use until the next audit finds it.
You cannot see which machines have no procedure
The question that matters is not whether these procedures are good, it is which assets have none. A folder can only tell you about the documents in it, never about the gaps.
Lock registers stay on paper
Who has a lock on what, right now, is a live question during a shift handover or an emergency. A register on a clipboard by the machine cannot answer it from anywhere else.
Modifications do not reach the procedure
A new drive, a second supply or a relocated isolator changes the isolation points. Nothing connects that work back to the procedure, so the document quietly stops describing the machine.
What running this in Facilio looks like
The template is the paper version of this procedure. The fields are the same ones; the difference is that a review date and an isolation stop being things somebody has to remember to look at.
Work Completion Validator
An isolation cannot be closed by being ticked
On paper the verification section is complete when it is signed. Work Completion Validator holds each step against evidence, so zero energy recorded without a test result is caught before the work order closes.
Ops Performance Intelligence
Review dates and expiring procedures raise their own work
Each procedure carries its own review date, so an overdue review surfaces as work rather than waiting for an audit. Modifications to the asset flag the procedure that describes it.
Audit Report Intelligence
Coverage becomes a number instead of a search
Which assets have a current procedure, which are overdue, and which have none at all: held as data, so a regulator or an insurer gets an answer rather than a folder.
Contractor Work Tracker
Contractor isolations sit under a named permit
When a subcontractor works on your machine, the isolation, the permit it belongs to and the locks applied are one record, so whose authority the work sat under is never reconstructed afterwards.
Hallucination-free by design. Atom AI answers from the records in your tenant rather than generating plausible text, so an empty field reads as empty rather than filled in for you.
Frequently asked questions
What is a lock out tag out procedure?
A lock out tag out procedure, often shortened to LOTO, is a written energy control document for a single machine. It lists every energy source the machine holds, names the isolation device for each one and where it is, sets the order in which the machine is shut down and isolated, requires zero energy to be proved at the point of work, and states how the machine is restored afterwards.
It also covers the parts people improvise: group lockout with a lockbox, isolations that continue across a shift change, and the exception route for removing a lock that belongs to somebody else.
What should a LOTO procedure include?
The machine it covers, with asset ID, make, model, serial and location. The named authorised and affected persons. An inventory of every energy source with its magnitude, isolation device and location, method, lock and tag, and verification. An ordered shutdown sequence, the isolation and lock application steps, the stored energy releases, and the zero energy verification at the point of work.
Then a lock and tag register, group lockout and lockbox arrangements, shift handover, the restoration sequence in reverse order, the exception for removing another person's lock, training records and a sign-off. This template runs to fifteen sections in four parts.
What is the difference between lockout and tagout?
Lockout physically prevents a device being operated: a lock goes on the isolator and the key stays with the person doing the work. Tagout only warns, and it depends entirely on everybody reading the tag and obeying it.
Lockout is used whenever the isolation device can accept a lock. Tagout alone is for the case where it genuinely cannot, and it then needs an additional safeguard, because a tag on its own stops nobody. Before falling back to a tag, this procedure asks for a lockable cover or the fuse removed and secured. For the device-level differences and the steps in OSHA order, see our LOTO procedure guide.
Do you need a separate procedure for each machine?
Yes, and this is the single most common failing. A generic procedure written for a plant room or a production line cannot name the isolation points, and naming the isolation points is the reason the document exists.
The practical test is whether somebody who has never worked on that machine could find every isolation device from the procedure alone. Isolator IS-14 on the plant room B wall passes that test. The main isolator does not.
Who is allowed to remove a lock?
Only the person who applied it. Every person working on the machine applies their own lock and removes their own when they have finished, which is why the register has a row per lock rather than a row per job. One lock applied by a supervisor on behalf of a team is not lockout.
Removing somebody else's lock is an exception with its own section, and it needs every reasonable attempt to contact the owner recorded, a named senior authoriser, confirmation that the owner is off site, an inspection of the machine and work area, a witness, and an incident report. Cutting a lock off without those has killed people who came back from a break.
What is group lockout and when do you need a lockbox?
Group lockout is for work where several people, or several trades, are on the same machine. The authorised person isolates and locks the machine, then the keys go into a lockbox and every worker applies a personal lock to the box.
The box can only be opened once every personal lock has been removed by its owner, which means the machine cannot be re-energised while anybody is still working on it. It is the mechanism that lets one isolation protect a group without anybody relying on a headcount.
Can I edit and rebrand this template?
Yes. It is free to use, edit, rename and put your own logo on, internally or for clients. No attribution required.
The Word version is the one to edit if you want to write a procedure per machine, change the energy types or match your own authorisation levels. The Excel version is the one to use if you want the procedure register, where the days-to-review column counts down against today's date for every machine on the list.
In one paragraph
A lock out tag out procedure is written for one machine, and that constraint is what makes it work: the whole value of the document is that it names the isolation device for every energy source, which a generic plant-room procedure cannot do. Inventory all ten energy types and keep the blank rows, because a blank row records that somebody checked for stored pressure and found none. Release stored energy with an observation written beside each line, since that is what injures people after the power is off. Prove zero energy at the point of work, with whoever is doing the job watching the test rather than taking somebody's word. Then restore in reverse order, with each person removing their own lock, and treat cutting off somebody else's lock as the exception it is.
The template is the floor, not the ceiling
Take the procedure; it will control the energy on one machine and stand up to an audit. When a folder per plant room stops being enough, a connected CMMS runs the programme: procedures tied to assets, review dates that raise their own work, isolations recorded against the permit they sat under, and coverage across every machine as a single number.