How to Run a Non-Routine Maintenance JHA in 10 Steps
A field-ready 10-step method helps supervisors and EHS managers analyze non-routine maintenance before work starts, assign control owners, and verify that the plan still matches the job.

Key takeaways
- 01Define the changed condition before the team copies assumptions from the last maintenance job.
- 02Break the work into 9 observable stages and write hazards as exposure statements that point toward real controls.
- 03Assign one accountable owner to each critical control, including the authority to stop or re-plan the task.
- 04Test at least 3 controls at the worksite before exposure, during execution, and after equipment reinstatement.
- 05Use Andreza Araujo’s Safety School and safety culture expertise to turn JHA findings into decisions leaders protect in the field.
A maintenance job can be called non-routine even when the crew has performed similar work before. The difference appears when the equipment state, access route, isolation boundary, contractor team, sequence, or production constraint changes enough to invalidate the old assumptions.
This guide shows supervisors and EHS managers how to run a Job Hazard Analysis, or JHA, for that kind of work in 10 steps. The purpose is not to create another form. It is to expose the decisions that can change the exposure, assign each critical control to an owner, and verify that the plan remains credible when the job reaches the field.
OSHA explains that a Job Hazard Analysis focuses on the relationship between the worker, the task, the tools, and the work environment. HSE guidance on risk assessment asks employers to identify hazards, decide who might be harmed, and review the assessment when conditions change. The practical test is whether the JHA changes the work package before people are exposed.
Use the JHA and pre-task tool comparison when the team is unsure which planning method fits. The workflow below is for non-routine maintenance where a short briefing alone cannot carry the decision.
Step 1: Define why the maintenance is non-routine
Write one sentence that explains what has changed from the last comparable job. Name the equipment, task, operating state, and changed assumption, because a vague label such as unusual maintenance does not tell the team where the risk assessment needs to go deeper.
Record the change in four parts. State whether the difference concerns the asset, the people, the environment, or the work sequence. A pump replacement with a new isolation point has a different JHA trigger from the same replacement performed during a night shutdown with a new contractor team.
Set the review boundary before collecting solutions. Include the preparation, isolation, access, execution, testing, reinstatement, and first restart. If the boundary ends when the repair is complete, the JHA may miss the moment when stored energy returns or a temporary control is removed.
Step 2: Assemble the people who control the exposure
Invite the supervisor, work owner, operator, isolator, maintenance lead, contractor representative, and technical specialist whose decision can change the hazard. Do not treat attendance as participation. Each person should be able to explain which condition they control and what evidence will prove that the control is in place.
Keep the group small enough to make decisions. Six to eight people is usually workable for a complex maintenance package, while a larger group can split into task-specific reviews. If the team lacks the person who controls an isolation, lift plan, confined-space entry, or process restart, pause the JHA rather than filling the gap with assumptions.
Andreza Araujo’s work across more than 250 cultural transformation projects emphasizes a useful leadership test. The person who owns the schedule must also be willing to accept a changed sequence when the JHA exposes a serious control gap. Otherwise, the meeting records concern without transferring decision authority.
Step 3: Break the job into observable task stages
Divide the work into stages that someone can see and time. A useful sequence may include mobilization, isolation, access, removal, repair, installation, testing, reinstatement, and handover. Avoid grouping the entire job under one heading, because hazards often appear at the transition between stages rather than inside the task that receives the most attention.
Use no more than 12 stages in the first pass. When a stage contains several different exposures, split it again. For example, removing a motor may involve lifting, stored electrical energy, residual process pressure, line-of-fire exposure, and temporary support, each of which deserves its own control discussion.
Link every stage to the responsible work instruction, permit, drawing, or equipment record. This creates an evidence trail that can be checked when the field team finds a difference between the plan and the asset.
Step 4: Identify hazards from the changed condition
For every stage, ask what can injure someone, what can damage the asset, and what can make the next control fail. Start with energy sources, movement, pressure, temperature, chemicals, height, access, visibility, traffic, workload, and simultaneous work. Then ask which assumption from the last job is no longer reliable.
Write hazards as exposure statements rather than labels. Stored pressure released during flange separation is more useful than pressure hazard, because the sentence already points toward the task, the energy path, and the people who could be affected.
Use the stored-energy verification walkdown when isolation and residual energy are central to the job. The JHA should include the field evidence that confirms zero energy, not only the procedural step that says the isolation was completed.
Step 5: Rate consequence and exposure without false precision
Estimate the credible consequence, the people exposed, the duration, and the opportunity for the hazard to reach them. A numerical score can support prioritization, but it should not turn a serious exposure into a low concern because the task is short or the crew is experienced.
Record the worst credible outcome separately from the expected outcome. A dropped component may be unlikely during a two-minute lift, yet the consequence remains serious if a person can enter the drop zone. That distinction keeps the JHA connected to serious injuries and fatalities rather than only to frequency.
ISO 31000 describes risk management as an iterative process that depends on context, communication, and review. Treat the score as a decision aid, not as evidence that a barrier works. The evidence must come from the control itself.
Step 6: Select controls in the right order
Choose controls by asking whether the exposure can be removed, reduced through design, separated from people, managed through a reliable procedure, or protected with personal equipment. Administrative controls and PPE may still be necessary, although they should not be allowed to hide a design or isolation opportunity.
For each control, write the action, the owner, the timing, and the verification evidence. A barricade is not a complete control statement until the JHA says who installs it, where it starts, when it is checked, and what condition requires the boundary to move.
The Prevention Through Design decisions that reduce exposure can help the team move beyond a training-only response when the hazard is built into access, layout, equipment, or tooling.
Step 7: Assign control owners and stop conditions
Name one accountable owner for every critical control, even when several people help execute it. The owner should have the authority to delay the job, call for technical support, or change the sequence when the evidence no longer matches the JHA.
Write stop conditions in language the crew can recognize. Examples include an isolation that cannot be proven, a support that shifts, a rescue route that becomes blocked, a change in weather, unexpected process pressure, or a work boundary that no longer protects nearby people.
Connect each stop condition to an escalation route. A worker who knows that a concern must reach the area supervisor within 10 minutes is more likely to act than a worker who is told only to report issues through a general channel.
Step 8: Test the plan at the worksite
Walk the planned sequence before the first tool is used. Compare the JHA with the actual access route, equipment condition, isolation points, lifting path, lighting, exclusion zone, emergency route, and location of simultaneous work.
Ask the crew to demonstrate the two controls that would prevent the most serious outcome. If the demonstration depends on a missing tag, an unavailable drawing, an obstructed route, or a person who is not present, the JHA has found a decision gap that must be closed before work begins.
Use the field risk escalation huddle when the walkdown reveals a changed condition that affects more than one work group. The handoff matters because a maintenance control can fail when operations, contractors, and logistics interpret the boundary differently.
Step 9: Brief the crew and check understanding
Brief the people who will perform, supervise, isolate, monitor, or receive the work. Do not read the JHA line by line. Explain the changed condition, the highest-consequence exposure, the critical controls, the owner of each control, and the decision that stops the task.
Ask each role to explain one action in their own words. A six-minute briefing can be adequate for a familiar work package, but a complex job may require a longer review, a drawing, a demonstration, or a second briefing at the point of work.
Record questions and unresolved differences. The quality of a JHA is visible when the plan changes in response to a credible question, not when every person signs the same page without discussion.
Step 10: Verify controls during execution and after restart
Schedule at least three verification points, before exposure, during the highest-risk stage, and after reinstatement. The supervisor should compare the field condition with the JHA, record any deviation, and decide whether the work can continue, must be re-planned, or should stop.
After the equipment returns to service, verify that temporary supports, barriers, tags, tools, and bypasses have been removed or formally managed. A repair that is technically complete can still leave a serious exposure if the restart boundary is unclear.
Close the JHA only after the control evidence is recorded and the next owner receives the relevant information. If a corrective action remains open, use the 30-day corrective-action verification method rather than treating a revised document as proof of effectiveness.
What should the supervisor do when the JHA changes?
The supervisor should stop the affected stage, explain what changed, and bring the right decision owner back into the review. A new contractor, tool, isolation point, weather condition, access route, or sequence can require a focused revision, even when the broader work package remains valid.
A JHA earns trust when it changes the job before the exposure changes people. In Andreza Araujo’s book Safety Culture: From Theory to Practice, the difference between a declared system and an operating system is measured by what leaders protect when production becomes uncomfortable. For a non-routine maintenance task, that protection begins with a JHA whose controls can be demonstrated, challenged, and verified.
For deeper support, explore Andreza Araujo’s Safety School and her practical work on safety culture transformation. The right next step is a field review that turns one difficult maintenance job into a clearer decision process for the next 30, 60, and 90 days.
Frequently asked questions
When should a maintenance team use a JHA?
What is the difference between a JHA and a JSA?
Who should lead a non-routine maintenance JHA?
How many steps should a maintenance JHA include?
What should happen if the field conditions differ from the JHA?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.