5 myths about lockout/tagout verification that supervisors still believe
Lockout/tagout fails when teams treat the lock as the proof. These five myths show why field verification, stored-energy release and restart discipline matter more.

Key takeaways
- 01A lock shows that isolation started, but it does not prove that every hazardous energy source is gone.
- 02OSHA 1910.147 and HSE guidance both make it clear that shutdown is not the same as safe isolation.
- 03Try-start or equivalent field proof matters because a checklist cannot confirm zero energy by itself.
- 04Operations and maintenance must share the verification burden, especially during handback and shift change.
- 05Andreza Araujo's safety culture work treats LOTO as a discipline of proof, not a signature ritual.
OSHA's Lockout/Tagout Fact Sheet says proper control of hazardous energy prevents an estimated 120 fatalities and 50,000 injuries each year. That number is not a decorative statistic. It is the cost of believing that a padlock is the same thing as proof.
The common story is simple. Put the lock on, sign the form, start the job. That story feels neat, yet it hides the real question, which is whether every hazardous energy source was identified, released, restrained, and checked in the field before anyone put hands near the machine.
Across 25+ years in executive EHS and more than 250 cultural transformation projects, Andreza Araujo has seen the same pattern repeat. The padlock is usually not the failure point. The failure sits in the assumption that a completed checklist already means the equipment is safe, even when no one has proved it under real conditions.
This article is for supervisors and maintenance leaders who need a cleaner standard than procedural optimism. The sharper thesis is simple: a lock can show that isolation started, but only field verification can show that hazardous energy is gone.
Key takeaways
- A lock shows that isolation started, but it does not prove that every hazardous energy source is gone.
- OSHA 1910.147 and HSE guidance both make it clear that shutdown is not the same as safe isolation.
- Try-start or equivalent field proof matters because a checklist cannot confirm zero energy by itself.
- Operations and maintenance must share the verification burden, especially during handback and shift change.
- Andreza Araujo's safety culture work treats LOTO as a discipline of proof, not a signature ritual.
Why the lock is not the proof that matters
OSHA 29 CFR 1910.147 requires hazardous energy control during servicing and maintenance, and it says stored or residual energy shall be relieved, disconnected, restrained, and otherwise rendered safe. HSE guidance on maintenance adds a blunt correction that many teams ignore: it is not enough to switch the machine off.
The equipment that looks dead can still hold spring force, trapped pressure, gravity, thermal load, hydraulic energy, or a second source that was never included in the original isolation plan. That is why the lock is only one visible step in a longer chain, not the chain itself.
As Andreza Araujo writes in A Ilusão da Conformidade, the form can look complete while the field condition remains unsafe. James Reason's work on latent failures makes the same point from another angle. The harmful event rarely appears because one person forgot a lock. It appears because the system accepted a weak version of proof.
Myth 1: If the lock is on, the job is safe
This myth survives because a visible lock feels reassuring. It is easy to count, easy to photograph, and easy to report. The problem is that the lock only tells you that one energy-isolating device was controlled. It does not tell you whether another source, which may be upstream, downstream, or stored inside the machine, was also made safe.
A supervisor who trusts the lock alone is trusting a symbol instead of a condition. That is exactly how teams miss residual pressure, trapped motion, elevated components, or a disconnected but still energized circuit. The operator sees a tidy board, the maintenance lead sees a signed form, and the worker who opens the guard becomes the one who pays for the gap.
In more than 250 cultural transformation projects, Andreza Araujo has seen that organizations often celebrate visible compliance while quietly underinvesting in verification. That is the logic of The Illusion of Compliance. The paperwork is clean, although the machine state is still unknown.
Myth 2: Switching the machine off is the same as isolating it
Switching the machine off is only a stop command. Safe isolation is a controlled condition that removes the chance of unexpected energization, startup, or release of stored energy. Those are not the same thing, and HSE maintenance guidance says so plainly.
The difference matters most on equipment that restarts easily but fails badly. A conveyor can coast. A press can store force. A pump can hold pressure. A mixer can trap material. If the main isolator, the disconnect point, or the bleed method was never confirmed, then the machine was only quiet, not safe.
This is the point where many crews become overconfident because the stop button worked. The button did its job. The safety job only begins after the stop button, when the supervisor confirms that the work boundary is correct and the isolation method matches the hazard.
Myth 3: Try-start is just a formality after the checklist
The try-start is not a ritual. It is the test. If the control cannot energize the machine after isolation, the crew has proof that the process worked. If the control can energize it, the job is not ready, no matter how many signatures sit on the form.
Teams that rush this step usually tell themselves that the checklist already covered it. That is a weak argument because the checklist is only an administrative description of the work. The try-start, meter check, pressure check, movement check, or equipment-specific proof is what converts the description into evidence.
The companion article on LOTO verification: how to prove zero energy gives the step-by-step sequence. This article is narrower. It exists to remove the mental shortcut that says the checklist is the control.
Myth 4: Only maintenance needs to understand LOTO
This myth sounds efficient, but it is operationally weak. Maintenance knows the task. Operations knows the machine behavior, the normal sequence, the abnormal sounds, the bypasses, and the pressure that builds when production wants a fast restart. If either side owns the story alone, the verification quality drops.
The best handover is a shared one. The supervisor, who carries responsibility for the work boundary, should hear what changed, what was isolated, what was drained, what was blocked, and what still needs attention before restart. That conversation matters because the person who can explain the control is usually the person who can notice when it slips.
This is where field discipline becomes culture. A crew that can explain the hazard aloud is less likely to accept a vague closeout. A crew that cannot explain it is relying on memory, and memory is the weakest safety device on the table.
Myth 5: Restart is separate from verification
Restart is part of verification because that is where the hazard returns. A lock can be removed, a panel can be closed, and the work order can be signed, yet the machine can still be wrong for the first cycle after maintenance. That is why handback, shift change, and re-energization deserve the same respect as the original isolation.
OSHA's standard makes the residual-energy requirement explicit, which is another way of saying that the system must stay safe until the job is truly over. If the equipment can reaccumulate pressure, move unexpectedly, or wake up in a different condition after the first start, then the verification window was too short.
A mature operation treats handback as a control point, not an administrative finish line. That is also where a lot of low-grade incidents begin. The machine did not fail at the lock. It failed at the moment the team assumed the lock had already done enough.
What supervisors should do this week
Pick one maintenance job that carries real exposure and has been done many times before. Do not start with the most dramatic job on the site. Start with the one that looks routine, because routine is where weak verification gets normalized.
Then force five questions into the job review. What energy sources exist? Which one is easiest to miss? How will the team prove zero energy? Who owns the handback? What changes if the equipment behaves differently after restart?
When the team cannot answer those questions cleanly, the job is not ready. The answer is not to hurry the checklist. The answer is to slow the work until the field proof matches the paperwork.
If you want the operational sequence behind this article, use the companion guide on LOTO verification and then compare it with your own site practice. If the gap is large, the site does not have a paperwork problem. It has a verification problem.
FAQ
What is the difference between lockout/tagout and verification?
Lockout/tagout is the control process that isolates hazardous energy. Verification is the field proof that the isolation actually worked, residual energy was released or restrained, and the equipment cannot hurt the worker when servicing starts.
Is a lock enough to prove zero energy?
No. A lock helps secure an isolating device, but it does not prove that stored energy, trapped pressure, gravity, thermal energy, or another source has been made safe.
Who should own LOTO verification?
Authorized employees perform the task, but supervisors and operations leaders must verify the job boundary, the field proof, and the handback before restart.
What is the most common LOTO mistake?
The most common mistake is treating paperwork as proof while skipping field verification, especially when a team is under production pressure or restarting after a shift change.
How does better verification change safety culture?
Better verification changes culture because it rewards evidence, pause discipline, and shared responsibility instead of speed, routine, and blind trust in forms.
Frequently asked questions
What is the difference between lockout/tagout and verification?
Is a lock enough to prove zero energy?
Who should own LOTO verification?
What is the most common LOTO mistake?
How does better verification change safety culture?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.