A lockout/tagout procedure template is the fastest way to bring consistency to a program drowning in one-off documents — as long as the template is built around what OSHA actually requires. Generic forms that skip energy identification or verification steps are worse than nothing, because they teach the floor that thin procedures are acceptable.
Below is a complete, machine-specific LOTO procedure template aligned to OSHA 1910.147(c)(4), followed by field instructions for filling it out and the mistakes to avoid. Copy it into your program as-is, or use it as the structure when you digitize your procedures. Either way: one completed template per machine, not per machine family.
What OSHA requires the procedure to contain
Section 1910.147(c)(4) lists exactly what a machine-specific procedure must document. A compliant template needs fields for all of it:
- Intended use: the scope, purpose, and the machines or equipment covered
- The specific procedural steps for shutting down, isolating, and securing the equipment
- Steps for the placement, removal, and transfer of lockout/tagout devices and who has responsibility for them
- Requirements for testing the machine to verify the effectiveness of the lockout
- Machine-specific identification: equipment ID, location, and every energy source with its type and magnitude
The template: header block
Start every procedure with an identification block. It sounds bureaucratic until the day an inspector asks "which machine is this for?" and the procedure cannot answer.
- Procedure title and unique ID (e.g., LOTO-M11-001)
- Equipment name, model, and asset/location ID (e.g., Mixer M-11, Building 3, Line 2)
- Energy sources summary (e.g., 480V 3-phase electrical · 90 psi pneumatic · stored spring tension)
- Required PPE (e.g., arc-rated face shield for panel work)
- Written by / reviewed by / approval date
- Revision number and revision date
The template: energy source table
One row per energy source. The discipline of the table is what keeps a tech from missing the second, third, or fourth energy source — the classic cause of LOTO incidents.
- Energy type (electrical, hydraulic, pneumatic, mechanical, thermal, chemical, gravitational)
- Magnitude (e.g., 480V, 120 psi, 2,000 lb suspended load)
- Isolation point — named exactly: "Main disconnect BD-11, south wall panel", not "the breaker"
- Lockout device required (breaker lock, valve lockout, blank flange, chain + lock)
- Stored/residual energy and how to release or restrain it (bleed valve, discharge resistor, blocking pin)
| Energy source | Magnitude | Isolation point | Lockout device | Stored energy |
|---|---|---|---|---|
| Electrical | 480V 3-phase | Main disconnect BD-11, south wall | Breaker lock | DC bus capacitor — discharge 5 min |
| Pneumatic | 90 psi | Ball valve V-3, east header | Valve lockout | Trapped line — bleed at B-2 |
The template: the seven sequence sections
The heart of the procedure is the ordered sequence. OSHA’s framework — and every defensible program — uses the same seven phases:
- 1. Notify — inform affected employees that servicing is beginning and the equipment is coming down
- 2. Shut down — stop the machine using its normal operating controls
- 3. Isolate — operate each energy-isolating device listed in the energy table, in order
- 4. Apply locks and tags — every authorized worker applies a personal lock at each isolation point
- 5. Release stored energy — bleed, vent, discharge, block, or lower until residual energy is controlled
- 6. Verify — attempt a start (try-start), check indicators, test for zero energy before hands go in
- 7. Return to service — confirm tools and personnel clear, reinstall guards, remove locks by owner, notify affected employees, restart
How to fill the template out in the field
A template filled out at a desk is a guess. Walk the machine with the techs who service it: photograph every isolation point, trace every energy line, and ask the "what else feeds this machine?" question until the answer is nothing. Record breaker and valve identifiers exactly as labeled in the field — if the panel label says "BD-11", the procedure says "BD-11", never "main breaker".
Note the awkward realities: the disconnect behind the machine that needs a specific tool, the pneumatic line that holds pressure for minutes after shutoff, the conveyor section that gravity-drives when raised. Field truth is what makes a procedure followable — and what makes it defensible.
Template mistakes that become citations
These are the template-level failures OSHA cites most — check yours against the list before rollout:
- Generic procedures ("isolate all energy") with no named isolation points
- Missing magnitude values — "electrical" instead of "480V 3-phase"
- No verification step, or a verification step that only checks one energy source
- No stored-energy section for equipment with springs, accumulators, or suspended parts
- Vague restart responsibility — OSHA requires the procedure to state who removes locks and when
- One procedure covering "all mixers" when mixers differ by model, vintage, or feed configuration
Generic steps become citations. Follow Tegis on Google for procedure-writing guides that hold up in audits.
From paper template to living document
A template solves consistency, not currency. The moment after rollout, equipment changes, panel labels wear off, and the printed copies on machines drift from the master file. That is why mature programs move the template into a system where each machine has a current record, isolation photos, and a QR code at the asset that opens the live version.
However you host it, keep two rules: every machine has exactly one current procedure, and the version at the machine is the version in the system. The template above is the skeleton — the discipline around it is the program.
Key takeaways
- 1910.147(c)(4) defines the required content: scope, shutdown, isolation, lock application, verification, and restart steps.
- One completed procedure per machine — the energy table with exact isolation points is the core.
- Walk the machine with the techs who service it; field truth beats office guesses.
- The most-cited template failures: generic steps, missing magnitudes, no verification, no stored-energy section.
- A template is consistency; a current, accessible record is the program. Plan for both.
Frequently asked questions
Is a generic lockout/tagout template enough for compliance?
No. OSHA requires machine-specific procedures for machines with multiple energy sources or where a single isolation does not fully de-energize the equipment. A template is the format; each machine needs its own completed procedure with named isolation points and magnitudes.
Does OSHA approve or certify LOTO procedure templates?
No — OSHA does not approve templates or programs. Compliance is determined by whether your actual procedures meet 1910.147(c)(4) and whether they are followed in the field. Templates labeled "OSHA-approved" are marketing, nothing more.
Can one procedure cover several identical machines?
Yes, in limited cases: 1910.147 allows a single procedure for a group of machines with the same type and magnitude of energy, the same isolation methods, and the same type of lockout devices. The procedure must clearly identify which machines it covers — and if any machine deviates, it needs its own.
How often should templates be reviewed?
OSHA requires a periodic inspection of each energy control procedure at least annually — a review by an authorized employee who does not use the procedure. Treat that review as your template audit: if the field has drifted from the document, correct the procedure and retrain.
Can consultants reuse this template for client work?
Yes. The template is free to use and adapt for the procedures you deliver to clients. If you deliver many client procedures, a structured builder turns this format into reusable, QR-ready client deliverables.