Lockout/tagout that survives a rushed shift change
The written procedure isn't the control. The handoff between shifts is where energy isolation actually fails, and it's the part audits rarely test.
Most lockout/tagout audits check two things: does a written procedure exist, and are locks applied. Both can be perfect on paper while the real failure mode goes unmeasured, the moment a partially completed isolation is handed from one crew to the next.
Where the standard meets the shift
OSHA’s energy-control standard, 29 CFR 1910.147, requires documented procedures and, specifically, provisions for shift changes so that protection is continuous when personnel change. The letter of it is easy to satisfy: a line in the procedure, a lockbox, a signature. What the standard can’t legislate is whether the incoming lead actually holds the outgoing lead’s mental model of what is isolated, what isn’t, and why.
Read the shift-change provision at 1910.147(f)(4) closely and it asks for two distinct things. One is the orderly transfer of the devices, the locks and tags moving from off-going to oncoming employees. The other is continuity of protection. Most sites build a process for the first and assume it delivers the second. It does not. Transferring a lock is a physical act that takes seconds and can be witnessed. Transferring protection means the incoming crew now understands the isolation well enough to work inside it, and nothing about handing over a padlock demonstrates that.
That gap is where the risk lives. A lock on a breaker is a fact. “This system is de-energised except for the accumulator that still holds pressure” is knowledge, and knowledge is exactly what a rushed, end-of-shift handoff drops. When the transfer of understanding depends on a tag rather than a conversation, the control has quietly moved from the isolation to the paperwork, and paperwork doesn’t answer questions.
Stored energy is the part a lock cannot show you
The reason the knowledge matters more than the hardware is that the most dangerous state of a machine mid-job is a partial isolation, and partial isolation is invisible from the outside.
1910.147(d) walks through the sequence: shut down, isolate, apply the devices, then relieve, disconnect, restrain, or otherwise render safe all stored or residual energy, then verify. That fourth step is the one that carries the risk across a shift boundary. Hydraulic accumulators, capacitors, springs under compression, elevated tooling, steam and process lines that were drained but not yet blanked, all of them can sit behind a properly applied lock and still hurt somebody. The lock tells you the source is isolated. It says nothing about what is still stored downstream of it.
An outgoing electrician carries that map in their head, along with the reason a particular valve was left where it was. If the handoff is a signature at the gate, the map does not travel. The incoming crew inherits a machine that looks fully isolated and is not, and the verification step at 1910.147(d)(6) has already been signed off by someone who has gone home.
Your annual inspection probably never watches a handoff
Here is the structural reason this stays broken on otherwise well-run sites.
The audit mechanism inside the standard is the periodic inspection at 1910.147(c)(6): at least annually, conducted by an authorized employee other than those using the procedure being inspected, and for lockout it must include a review with each authorized employee of that employee’s responsibilities. It is a genuinely good requirement, and it is almost universally scheduled for a weekday day shift, because that is when the inspector, the maintenance lead, and the EHS coordinator are all on site.
Which means the one moment the standard cares most about, the transfer at 06:00 or 22:00 between two crews who are tired and want to leave, is the moment your inspection almost never observes. The procedure gets inspected. The handoff does not. Then the corrective actions land on documentation, because documentation is what the daytime inspection can see.
Field check
Walk a live shift change on a line that's mid-isolation. Ask the incoming lead, unprompted: which energy sources are locked, by whom, and what's left to verify? If the answer comes from reading the tag rather than from the person, your continuity of protection depends on a document surviving a handoff, the weakest link in the whole procedure.
Making the handoff a step, not a gap
The fix isn’t more forms. It’s treating the handoff as a controlled step in its own right, a verified, face-to-face transfer with a walk-down of the isolation state, not a signature collected on the way out the door. Cheap to require. Almost never audited.
In practice that means three things a supervisor can enforce without a budget request. The transfer happens at the equipment, not in the office, because the questions people ask standing in front of a machine are different from the ones they ask over a desk. The outgoing lead states what is still stored, not just what is locked, and the incoming lead repeats it back. And the incoming lead performs their own verification before any work resumes, rather than inheriting someone else’s.
Then move one periodic inspection a year onto the night handoff. It is the cheapest change on this list and the only one that tells you whether the other two are actually happening.