Permit-to-Work vs JSA vs Control Verification
Permit-to-Work authorizes the job, JSA translates the hazards, and control verification proves whether the barrier still works in the field.

Key takeaways
- 01Permit-to-Work authorizes high-risk work, but it cannot prove that the crew fully understood the hazard path.
- 02JSA translates the task into hazards and controls, although it fails when the team copies last week's analysis.
- 03Control verification is the only one of the three that proves the barrier is present and working in the field.
- 04Supervisors should use PTW, JSA, and control verification in sequence, not as substitutes for each other.
- 05Andreza Araujo's safety culture work shows that repeated decisions under pressure matter more than the number of forms completed.
Permit-to-Work authorizes the job, JSA translates the job into hazards and steps, and control verification proves that the barrier exists in the field. When leaders blur those three functions, the operation gets more paperwork, not more control.
The useful question is not which tool sounds more rigorous. The useful question is which decision the leader needs at that moment. Across 25+ years leading EHS at multinationals, Andreza Araujo has seen that many sites confuse approval with understanding, and understanding with proof. That confusion is expensive because the form can look complete while the work still depends on memory, speed, and luck.
As Andreza Araujo argues in Safety Culture: From Theory to Practice, culture becomes visible in repeated decisions under pressure. This comparison uses that lens to separate the authorization gate, the hazard translation step, and the field proof that the control still works. If you want the adjacent operational detail, Permit-to-Work Handover shows how the same job can drift between shifts, while Pre-Task Risk Assessment shows what a supervisor should confirm before exposure begins.
What each tool is for
Permit-to-Work is a decision gate. It exists to say who may authorize high-risk work, under what conditions, and with which limits. JSA, or Job Safety Analysis, is a planning tool. It breaks the task into steps, identifies the hazards in each step, and forces the team to think before the job starts. Control verification is a proof tool. It checks whether the selected barrier is present, effective, and understood where the work happens.
Those differences matter because each tool answers a different management question. PTW asks whether the job may proceed. JSA asks what can hurt people during the job. Control verification asks whether the control selected to prevent harm is real enough to trust. A site that uses one tool to answer all three questions is asking for ritual.
In more than 250 cultural-transformation projects supported by Andreza Araujo's team, a common pattern appears. The organization approves the work, the crew discusses the hazards, and nobody returns later to check whether the barrier still exists after production pressure, weather, contractor turnover, or schedule drift. That gap is where control becomes fiction.
Permit-to-Work is the authorization gate
PTW is strongest when the work is nonroutine, high energy, or sensitive to interface risk, such as hot work, line breaking, confined space entry, working at height, lifting, or electrical isolation. The system should make clear who can authorize the job, who must be consulted, and which conditions stop the job before it starts.
The weakness appears when PTW is treated as a signature exercise. A form can be signed because the task is urgent, the supervisor is busy, or the crew has worked the same job for years. That produces comfort, not control. The best warning sign is a permit that has become invisible to the people who depend on it.
During the PepsiCo South America tenure, where the accident ratio fell 50% in six months, Andreza Araujo learned that follow-up beats ceremony every time. The same lesson applies here. If the permit is approved but never revisited, the site may have a cleaner file and a weaker barrier.
LOTO Verification is a useful companion because it shows why authorization is not proof. A lockout can be approved and still fail if the isolation step, verification step, or restart discipline is weak.
JSA is the hazard translation step
JSA is the bridge between the task and the hazard. It is where the team names the steps, the energy sources, the likely deviations, and the controls that must exist for the job to stay safe. Good JSA work makes the invisible visible, especially when the hazard is hidden inside routine work.
The market often turns JSA into a prefilled form. That is a mistake because the value of JSA is not the document. The value is the thinking. If the team copies last week's analysis, the method has become a paperwork habit. A copied hazard list can miss a changed route, a different contractor, a new weather condition, or a temporary repair that changes the control path.
As Andreza Araujo notes in The Illusion of Compliance, a document can look orderly while the field remains exposed. JSA is only useful when it changes how the task is planned. It should force the team to ask what will happen if the step takes longer, if the space is tighter, if the isolation is delayed, or if the crew has to change sequence under pressure.
The article on Pre-Task Risk Assessment is the closest operational cousin here, because a strong supervisor uses the JSA to test the real job, not to certify the paper version of the job.
Control verification is the barrier proof
Control verification is where the leadership question gets harder. It asks whether the control named in the permit or JSA is actually present, effective, and maintained. It should not be satisfied by a screenshot, a signed box, or a general statement that the crew knows the rule. It needs field proof.
That proof can be physical, visual, or procedural, depending on the control. For an exclusion zone, it may be the actual barrier placement and worker position. For isolation, it may be the test that confirms zero energy. For a rescue plan, it may be the staffing, timing, and access conditions that show the response can happen in real time. If the verification cannot survive a night shift or a rushed restart, it is not verification.
James Reason's work on latent conditions is useful here because the visible act often hides the deeper weakness. A job can look controlled while the barrier is weak, bypassed, or only present when the supervisor stands nearby. That is why Critical Control Verification should sit closer to serious-risk governance than either PTW or JSA alone.
In more than 250 cultural-transformation projects, Andreza Araujo has repeatedly observed that leaders overestimate the control they can see on paper and underestimate the control they can verify in the field. The habit to break is trusting the form before the barrier.
Comparison matrix
The table below keeps the three routines in their proper lanes. The scores are not a ranking of importance. They are a ranking of fit for purpose.
| Dimension | Permit-to-Work | JSA | Control verification |
|---|---|---|---|
| Main question | May this job start now? | What can hurt people during the job? | Is the barrier actually in place and working? |
| Main output | Authorization with limits | Task hazard map and control plan | Field proof of control quality |
| Best owner | Supervisor or authorized manager | Supervisor, crew, and planner | Line leader, EHS, or control owner |
| Common failure | Signature theater | Copy paste hazard lists | Checking paperwork instead of the field |
| What it cannot prove | That the hazards were fully understood | That the barrier still works | That the job was properly authorized |
Which routine fits the supervisor
The supervisor needs all three, but not for the same reason. PTW helps the supervisor decide whether the job should proceed. JSA helps the supervisor understand where the job can go wrong. Control verification helps the supervisor test whether the selected control still exists when the crew is under pressure.
The practical test is simple. If the supervisor can approve the job but cannot explain the key hazard steps, the JSA is weak. If the supervisor can describe the hazards but never checks the barrier, the job plan is incomplete. If the supervisor checks the barrier but never questions the authorization, the work may still start under the wrong conditions.
That is why the best site routines connect PTW and JSA before the task starts, then return to the field to verify the control during execution. A form that never reaches the work area is not a safety routine. It is a storage location.
Which routine fits EHS and plant leaders
EHS should treat PTW as a governance signal, not as a paperwork archive. Repeated weak permits show where supervision, planning, or production pressure is eroding control. Plant leaders should treat JSA as a planning quality check, because a bad JSA usually means the work is being understood too late or too superficially.
Control verification belongs closest to critical control management. If the operation says a barrier is protecting people, leaders should be able to prove it in the field and not only in the file. That is the line between administrative order and real risk reduction.
Andreza Araujo's book Safety Culture: From Theory to Practice helps explain why. Culture appears in repeated decisions, and repeated decisions appear in whether leaders revisit the job, test the barrier, and close the gap between what is approved and what is actually done. Safety is about coming home, which means leaders have to value proof more than appearance.
How to combine all three without ritual
Start by assigning each routine a different question. PTW answers whether the job may start. JSA answers what must be controlled during the job. Control verification answers whether the control is alive where the work happens. Then make sure the answer to one question does not substitute for the answer to another.
Next, make the review sequence visible. Before the shift, use PTW and JSA together. During the task, verify the control at the point of work. After the task, check whether the permit conditions, hazard assumptions, and field proof still match what happened. If the same deviation appears twice, the issue is not the form. The issue is the management system.
In more than 250 cultural-transformation projects supported by Andreza Araujo's team, the strongest gains came when leaders stopped celebrating the existence of forms and started asking which form changed the next decision. That is the practical measure of usefulness.
Conclusion
Permit-to-Work authorizes, JSA translates, and control verification proves. When each one stays in its lane, leaders get a cleaner decision path and a stronger barrier against serious harm. When they are mixed together, the site gets ritual instead of control.
Andreza Araujo's work across multinationals shows that the strongest safety systems are not the ones with the most paperwork. They are the ones where authorization, hazard thinking, and field verification stay connected to the real work. If you want the next step after this comparison, use the internal guides on Permit-to-Work Handover, Pre-Task Risk Assessment, and Critical Control Verification as a practical sequence, then test the site in the field.
Frequently asked questions
What is the difference between Permit-to-Work and JSA?
What does control verification prove?
Can JSA replace Permit-to-Work?
Which routine should EHS audit first?
How does Andreza Araujo connect these tools to safety culture?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.