Risk Management

How to Build a Barrier-Owner Map Before a Shutdown in 14 Days

A shutdown plan can list hazards and controls while nobody can say who will verify the barrier that matters most. This 10-step guide shows shutdown managers how to turn critical controls into named decisions before work starts.

By 6 min read
Shutdown team reviewing critical barriers, owners, and field verification points

Key takeaways

  1. 01A barrier-owner map is useful only when each critical control has a named decision owner, a verification point, and a response if the barrier is weak.
  2. 02Shutdown teams should map credible high-energy exposures before reviewing the task list, because the schedule can otherwise hide the barriers that deserve attention.
  3. 03The person who verifies a control is not always the person who can restore it, so ownership and verification must be recorded separately.
  4. 04A shutdown review should test changed conditions, handovers, temporary arrangements, and restart criteria rather than treating the approved plan as proof of field readiness.
  5. 05Across more than 250 cultural transformation projects, Andreza Araujo has seen that visible ownership turns safety language into management action.

A shutdown can have an approved schedule, signed permits, and a long list of controls while one basic question remains unanswered. Who has the authority to stop the job when a critical barrier is not ready?

That question separates a documented shutdown from a controlled shutdown. A barrier-owner map makes the answer visible before the first isolation, lift, line break, or confined-space entry. The map is not another register for EHS to maintain. It is a short operating agreement that links serious exposure to decision rights, verification, and escalation.

In more than 250 cultural transformation projects supported by Andreza Araujo, the recurring weakness has rarely been a complete absence of safety language. The weakness is that the language does not identify who must make the next decision when field conditions differ from the plan. The 14-day method below is designed for shutdown managers, operations leaders, maintenance planners, and EHS partners who need to close that gap before work starts.

What you need before starting

Gather the shutdown scope, current process drawings, isolation philosophy, permits, contractor work packages, emergency arrangements, temporary-deviation records, and restart requirements. Do not begin by copying every hazard into a new spreadsheet. Start with the exposures that could produce severe harm if a control fails.

Use James Reason's distinction between active errors and latent conditions to keep the review balanced. A missed step may be visible at the worksite, while the conditions that made the step easy to miss may sit in design, planning, supervision, or schedule pressure. The map should expose both layers without turning the exercise into a search for a convenient person to blame.

Step 1: Define the shutdown decision window

Write down the exact period the map covers, including preparation, execution, testing, handback, and restart. A shutdown does not become safe merely because the maintenance task is complete. Risk changes again when systems are re-energized, temporary equipment is removed, and production resumes with people who may not have been present during the work.

Name the decision gates that matter. These may include first isolation, first entry, simultaneous operations, pressure testing, energized testing, handback, and restart. The output is a one-page timeline that shows when a barrier must be verified and when authority can move to another role.

Step 2: Select credible high-energy exposures

List the exposures that deserve barrier-level attention, such as stored energy, toxic release, fire, dropped load, vehicle interaction, unexpected movement, or loss of containment. Keep the list specific to the shutdown. A generic hazard catalogue creates volume without helping the team decide.

For each exposure, describe the credible unwanted event in one sentence and identify the work or condition that could make it possible. If the sentence is so broad that every task fits it, narrow the boundary until the team can picture where the barrier must operate.

Step 3: Map preventive and mitigative barriers

For every unwanted event, record the barriers that should prevent it and the barriers that should limit harm if prevention fails. Separate physical safeguards, engineered systems, isolation arrangements, procedures, supervision, and emergency response. This prevents the plan from treating a briefing as equivalent to a physical control.

Test each barrier with a practical question. What would a worker, supervisor, or engineer actually observe if this barrier were available and effective? If the answer is only that a document was signed, the map is describing an intention rather than a control.

Step 4: Assign the decision owner

Give every critical barrier one primary decision owner. The owner must be able to approve resources, change sequencing, accept a defined residual condition, or stop the work. A distribution list is not ownership, and a department name is not a decision right.

Ownership may sit with engineering for a design safeguard, operations for an operating boundary, maintenance for equipment restoration, or a contractor manager for mobilized work. EHS can challenge and verify the evidence without becoming the default owner of every control it did not have authority to change.

Step 5: Name the independent verifier

Record who will verify that the barrier exists and works under the actual shutdown conditions. Independence does not always require a different department, but it does require enough distance from the task to question the evidence. The person who installs an isolation should not be the only person deciding that the isolation is complete.

Define the evidence in plain terms. A verifier may need to see a tested zero-energy state, a field condition, a functional test, a signed boundary, a rescue route, or a restored interlock. The map should state what will be checked, not merely who will attend the meeting.

Step 6: Set the escalation threshold

Write the condition that requires work to stop or the decision to move upward. Examples include a missing isolation, an untested alarm, an unapproved scope change, a failed gas test, a rescue path that is not usable, or a barrier whose owner cannot be reached.

The threshold should be observable by the team and connected to a response time. A vague instruction to escalate concerns leaves the decision to the person under production pressure. A clear threshold gives the supervisor permission to pause the job before uncertainty becomes exposure.

Step 7: Test contractor and shift handovers

Shutdown risk often moves during the handover between planners, contractors, operations, and the next shift. Review each barrier whose status can change while the work remains open. Record what must be transferred, who receives it, and how the receiving person confirms understanding.

Pay special attention to temporary arrangements. A blind, bypass, scaffold, temporary cable, isolation lock, or restricted access route can become normal during a long outage, even though its safety meaning changes from one crew to another. The owner must remain visible until the temporary condition is removed or formally accepted.

Step 8: Reconcile the map with the work sequence

Place the barriers on the shutdown schedule and compare them with task dependencies. If two work packages need the same isolation, lifting route, ventilation system, or emergency resource, the conflict belongs in the decision process before crews arrive.

This step is where the map becomes more than a control list. It shows whether the schedule asks a barrier to serve incompatible purposes at the same time. When the sequence cannot protect the barrier, change the sequence or change the work scope. Do not ask a briefing to compensate for a planning conflict.

Step 9: Run a field verification rehearsal

Before the final readiness meeting, walk one representative work package with the owner and verifier. Ask them to demonstrate how they would confirm the barrier, what evidence they would retain, and what they would do if the condition failed.

Use the rehearsal to find gaps in access, instruments, competence, communication, or authority. A control that cannot be verified in the field is not ready, even when the paperwork is complete. The rehearsal also reveals whether the named owner understands the decision they are expected to make.

Step 10: Freeze, publish, and re-open the map when conditions change

Publish the agreed map with the shutdown readiness pack, then define the events that automatically reopen it. Scope growth, a new contractor, a changed isolation, a failed test, a serious near miss, a delayed emergency resource, or a restart sequence change should trigger review.

At the final readiness meeting, ask three questions for every high-energy exposure. Is the barrier present, who verified it, and who decides what happens if it fails? If any answer is missing, the work is not ready for that gate. After restart, close the loop by recording which barriers were tested, which conditions changed, and what the next shutdown should do differently.

Shutdown barrier-owner checklist

Use this short checklist before the readiness decision:

  • Each credible high-energy exposure has a defined unwanted event.
  • Preventive and mitigative barriers are listed separately.
  • Every critical barrier has one named decision owner.
  • The verifier and the verification evidence are identified.
  • Stop-work and escalation thresholds are observable.
  • Contractor, shift, and temporary-condition handovers are covered.
  • The work sequence has been checked for shared or competing barriers.
  • A field rehearsal has tested the readiness evidence.
  • Scope or condition changes automatically reopen the map.

A shutdown becomes more controllable when the team can see the barrier, the evidence, and the decision right in the same place. For more practical guidance on risk management and safety leadership, visit Andreza Araujo's English safety blog or explore her books at the Andreza Araujo store.

Topics risk-management shutdown-safety critical-controls barrier-management maintenance-safety safety-leadership

Frequently asked questions

What is a barrier-owner map?
A barrier-owner map links each credible high-energy exposure to the controls intended to prevent or limit it, then names who can make decisions about those controls and who will verify them in the field.
Who should own a critical safety barrier during a shutdown?
The owner should be the person with authority, resources, and a clear decision right over the barrier. EHS may verify evidence, while engineering, operations, maintenance, or a contractor manager may own restoration or redesign.
How early should the map be completed?
Complete the first version before the shutdown work list is frozen, then update it as scope, contractors, isolation boundaries, sequencing, or restart conditions change. A map created only during the final readiness meeting is too late to shape decisions.
Does the map replace a permit or risk assessment?
No. It connects existing risk assessments, permits, isolation plans, and verification records to the people who must act when a control is missing or ineffective. It is a decision tool, not a substitute for those processes.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI