← Maritime QHSE
Meriden Compliance Insights · Maritime QHSE

Why Work Should Not Start Just Because the Permit Is Approved

Offshore workers carrying out a Start Work Check beside isolated equipment before beginning a task
Illustrative concept image by AxiomOrdo. No endorsement by IOGP or any operator is implied.

A permit confirms that work has been planned and authorised. A Start Work Check asks a different question: are the lifesaving safeguards actually present, functioning and understood at the point where the work is about to begin?

A permit confirms that work has been planned and authorised. A Start Work Check asks a different question: are the lifesaving safeguards actually present, functioning and understood at the point where the work is about to begin?

A permit can be approved. The risk assessment can be complete. The toolbox talk can be signed. Every document can appear correct, and the worksite can still be unready.

An isolation may not be where the drawing says it is. Equipment may differ from what was assessed. Another team may have introduced a new interface. Wind direction may have changed. A temporary barrier may have been moved. A rescue arrangement may exist in the plan but not at the worksite. The people carrying out the job may each understand something slightly different.

This is the gap between planned readiness and actual readiness.

Permit-to-work systems, task risk assessments and toolbox talks are essential parts of control of work. They establish what is intended to happen and under what conditions. They do not, by themselves, prove that the required safeguards exist at the exact place and time where exposure is about to begin.

That is the purpose of a Start Work Check: to make the final decision to start dependent on what can be physically confirmed, not simply on what has already been approved.

What IOGP intended

The International Association of Oil & Gas Producers introduced a revised and simplified set of nine Life-Saving Rules in 2018 following analysis of fatality data. In December 2021, IOGP published Report 459-1, Life-Saving Rules – Start Work Checks, describing Start Work Checks as a human-performance tool intended to help organisations implement those rules more effectively.

The report contains thirteen checks covering activities including confined space entry, energy isolation, hot work, mechanical lifting, working at height, excavation, work near water and work around mobile equipment.

IOGP is clear about the purpose. Start Work Checks are intended to help frontline workers confirm that the controls or safeguards designed to prevent fatalities and serious injuries are present and functioning at the exact task location immediately before work begins. They use a Go/No-Go approach: if an applicable safeguard cannot be confirmed or verified, the work does not start and the team stops and seeks help.

The checks are not replacements for permits, risk assessments, procedures or competent supervision. IOGP assumes that organisations already have functioning management systems, permit-to-work arrangements, management of change, hazard identification, competence controls and emergency response arrangements.

The distinction is therefore simple:

A permit establishes planned readiness. A Start Work Check tests actual readiness.

IOGP also embeds three useful human-performance features in the process:

  • place keeping, by requiring each step to be addressed;
  • peer review, through the verifier role; and
  • stop and seek help, where a safeguard cannot be confirmed.

The check should be completed where the plant, equipment, tools and people are located, just before the task begins. It is not intended to be completed in an office, copied from a previous job or signed retrospectively.

Planned readiness versus actual readiness

One weakness in many control-of-work systems is that permit approval gradually becomes treated as the final permission to begin. Once the document has passed through the required signatures, the remaining steps can feel administrative.

That is where false readiness develops.

A permit approver may believe a physical visit is unnecessary because the job is familiar. A supervisor may assume that an experienced team has completed the checks correctly. A work party may treat a signed toolbox talk as proof that everyone understands the task.

Each assumption may appear reasonable. Together, they can leave nobody responsible for comparing the approved plan with the actual conditions immediately before exposure begins.

A Start Work Check should interrupt that drift. It should require the work party and verifier to establish that:

  • the task and location are correct;
  • isolations and critical safeguards are physically in place;
  • tools and equipment are suitable and in the expected condition;
  • access, barriers and exclusion zones remain effective;
  • simultaneous operations have not created a new interface;
  • emergency and rescue arrangements are available and usable;
  • the work party understands roles, controls and stop conditions; and
  • nothing material has changed since the work was authorised.

The check should cover any other safeguards identified in the permit, risk assessment or applicable Start Work Check. The aim is not to repeat every planning document. It is to confirm that reality still matches them.

Physical verification must include understanding

A meaningful verification starts with the task being explained at the worksite. The team leader should walk through what will happen, who will do it, which hazards have been identified and what prevents those hazards from causing harm.

The verifier should compare that explanation with the conditions actually found at the worksite.

This should not be limited to the team leader. A short discussion with members of the work party can reveal whether the briefing created shared understanding or only attendance signatures.

Workers should be able to explain their roles, the critical safeguards, what would cause the task to stop, how they would raise a concern and what they would do if conditions changed. A realistic scenario can be more useful than asking whether everyone understands. What happens if the general alarm sounds halfway through the task? What happens if ventilation fails, the wind shifts or the agreed communication method is lost?

The purpose is not to catch people out. It is to expose differences in understanding before those differences become part of an emergency.

The verifier must provide a real second perspective

IOGP states that the verifier should be someone other than the person confirming the steps and should understand the task, hazards, controls, equipment and tools. Where a permit is required, IOGP says the verifier should not be the permit holder.

That is a sound baseline, but organisations still need to decide how the role should work in their own environment.

There is a trade-off between technical familiarity and independence.

An experienced specialist is more likely to recognise task-specific defects and weak controls. The same familiarity can also create assumptions. Someone who has performed a task many times may accept conditions that have become normal without asking whether they remain defensible.

A less familiar verifier may need the work explained in full. That can be useful. Basic questions sometimes reveal assumptions the work team has stopped noticing. A fresh pair of eyes may ask why a particular route is being used, whether another line could become energised, what happens if weather changes, or why actual practice differs from the written procedure.

Neither model is universally superior. A verifier without enough competence can miss a critical technical issue. A verifier who is too close to the task can become another member of the same assumption set.

The practical standard should be:

The verifier must be competent enough to understand the risk and independent enough to challenge assumptions.

The role becomes unsuitable where the verifier lacks time, confidence, operational understanding or freedom to stop the task. It also fails where production pressure turns verification into a ceremonial signature.

When the plan and reality do not match

A Start Work Check is not a mechanism for repairing an incomplete plan at the worksite. It is a control for detecting when the plan is no longer sufficient.

If the verifier finds a substantive mismatch, the default should be to stop and return the issue to the appropriate planning level. Something that appears minor to the work team may affect equipment, people or activities outside their immediate expertise. Wider review allows someone else to ask what the change affects, what new hazard it creates and whether a quick fix introduces another problem.

Depending on the issue, the review may require the permit authority, task supervisor, technical authority, operations, maintenance, HSE or another affected discipline.

The group should determine whether the risk assessment remains valid, the permit or isolation plan requires amendment, different equipment or competence is needed, simultaneous operations must be resequenced, emergency arrangements remain suitable, or formal management of change is required.

The important point is that the verifier should not be pressured to improvise a new control set simply because the job is ready to start and delay is inconvenient.

Re-verification should follow change

IOGP identifies several occasions when Start Work Checks may be repeated: when the worksite is left unattended, after breaks, after a shift change, when work extends beyond one shift, when the crew or personnel change, when requested by supervisors, or when concerns arise about the status of safeguards.

The trigger is therefore change, uncertainty or loss of control—not simply the passage of time.

A fixed time rule may be useful in some environments, but one universal threshold will not fit every task. A two-hour absence from a busy deck with changing weather, shared equipment and simultaneous operations may be significant. The same period in a remote, controlled location may not create the same likelihood of change.

The planning or toolbox discussion should establish what would invalidate the original check. Relevant factors include environmental change, personnel change, altered isolations, moved barriers, borrowed equipment, new nearby work, loss of communication, extended absence or any doubt that the original safeguards remain in place.

Everyone with stop-work authority should also have explicit authority to request re-verification. That includes workers, supervisors, contractors, junior personnel and people nearby who identify a credible concern.

Stop-work authority and re-verification authority are related but not identical. A person may not be saying that the task is definitely unsafe. They may be saying that the basis on which it was started is no longer certain. That uncertainty should be enough to pause and check again.

Re-verification should consider the whole remaining task, not only the immediate change. If the wind shifts during grinding and begins carrying sparks towards a painting activity, the issue is not merely the direction of the sparks. The change may affect fire risk, ventilation, gas testing, exclusion zones, fire-watch arrangements and the sequence of both jobs.

The team should review the remaining work through the lens of what changed and what that change may affect downstream.

How Start Work Checks fail in practice

No checklist is self-executing. The same framework can produce meaningful assurance in one workplace and compliance theatre in another.

Superficial compliance: forms can be pre-filled, completed late or marked without physical verification.

Verifier bottlenecks: scarce verifiers create delay and pressure for hurried, remote or unsuitable approval.

Authority gradients: rank, contractor-client relationships and production pressure can suppress challenge.

False confidence: completion can create psychological closure, even though conditions may drift during execution.

Interface friction: if the organisation cannot explain how the SWC differs from the permit, risk assessment and toolbox talk, workers may see it as duplicate paperwork.

Handover decay: barriers, ventilation, rescue arrangements, isolations and nearby activities can change during breaks or shift changes.

Weak learning: protecting individuals from blame should not prevent organisations from identifying recurring system failures in equipment, isolation, planning or supervision.

These are not arguments against Start Work Checks. They are reasons to design and assure the process carefully.

The form should record the decision, not replace it. A signature proves that a name was written. It does not prove that the worksite was visited, the safeguard inspected, the crew questioned or the change understood.

Technology can support verification, but it cannot prove judgement

Digital systems can improve traceability, access and organisational learning, but they can also create new forms of false assurance.

Digital evidence: timestamps, location data and photographs may discourage pre-completion. They prove where a device was and what was captured, not what a person understood or challenged.

Connected monitoring: gas detectors, equipment telemetry and proximity systems can detect changing conditions after work begins. They also introduce calibration, maintenance, connectivity and alarm-management risks.

System-level learning: aggregated pause, stop and failed-check data can reveal recurring weaknesses without scoring individuals. The data must remain useful for local action and must not be repurposed punitively.

Electronic links to permit and competence systems may also prevent completion where required authorisations have expired. A current certificate, however, does not prove present competence, fitness or understanding.

Technology is valuable where it supports physical inspection, conversation and decision-making. It is dangerous where digital completion becomes a substitute for them.

Implementation must fit the operation

The operational additions discussed here are not universal rules. They are proposals for discussion, trial and adaptation.

The core principle is transferable: work should not begin or resume until critical safeguards have been confirmed at the point of risk. The detailed design should reflect the task, workforce, operating environment, verifier capacity, contractor arrangements, potential consequence and strength of the organisation’s safety culture.

A stable team of experienced professionals may need a different model from a workplace with frequent trainees, high turnover or weak challenge culture. Stronger structure may be justified in the second environment, but more paperwork alone will not create trust.

The process should be developed with the people who will use it, trialled in real conditions and adjusted using workforce feedback, assurance findings and recurring pause points.

Leadership behaviour is decisive. When a worker stops a task or requests re-verification, the response should be curiosity and support, not irritation or blame. If people believe that raising a concern will damage their reputation or delay targets, formal stop-work authority will exist only on paper.

Start Work Checks will work where people believe the process has value, trust that challenge will be supported and engage with it from design through daily use.

Conclusion

A permit is an essential control, but it is not evidence that the worksite is ready.

Planning and authorisation establish the intended task, hazards and controls. A Start Work Check confirms that the critical safeguards exist, function and remain suitable under the conditions actually present. It turns the decision to start from an administrative assumption into a physical Go/No-Go test.

That test should involve the people doing the work, a verifier who adds a genuine second perspective and a clear route to stop and seek help. Where the plan and reality do not match, the work should pause and the issue should return to the appropriate level of planning. Where conditions change, the remaining task should be reconsidered rather than only the immediate difference.

The process can still fail. It can become superficial compliance, weakened by authority gradients or reduced to another digital completion screen. Its effectiveness depends less on the format of the checklist than on whether the organisation protects the quality of the decision.

Work should never start because the paperwork is complete. It should start only when the safeguards that keep people alive have been physically confirmed where the work will take place.

A final operational dilemma

Offshore diving and operations team facing a conflict between an unverified isolation and an approaching facility shutdown
Illustrative concept image by AxiomOrdo. No endorsement by IOGP or any operator is implied.

Consider a hypothetical offshore scenario.

A specialist diving team is preparing to clear a severe blockage in a cooling-water intake. The blockage threatens an imminent shutdown affecting critical systems on connected installations during worsening weather.

At the manifold, every applicable safeguard is confirmed except one. A primary mechanical isolation valve on a secondary cross-feed cannot be fully locked because its actuator has seized. A secondary hydraulic seal is closed and the pressure indication reads zero, but the intended physical lock cannot be applied.

The verifier appears to face two unacceptable options.

Option A: authorise entry without the intended lockout

This relies on the remaining hydraulic seal. If it fails while the diver is inside the intake, the pressure differential could cause fatal entrapment. The verifier would knowingly accept a direct path to a fatal outcome for a specific person.

Option B: stop the work

Repair will take longer than the operating window. Stopping allows the cooling-water failure to progress towards an emergency shutdown, creating severe risks for personnel across connected installations.

The scenario appears to force a choice between one direct lethal hazard and a wider emergency. That framing should be challenged.

Once the safeguard cannot be verified, the SWC has performed its function: the task cannot proceed under the approved plan. The verifier should not be expected to defeat a lifesaving safeguard because the wider operation lacks resilience, nor should one person carry responsibility for a system-level life-versus-life trade-off.

The failed check should trigger immediate escalation to the authority capable of managing the wider consequences. Installation management, diving authority, operations, technical specialists and emergency leadership would need to test whether the assumed binary is real. Depending on the design, alternatives might include controlled load reduction, sequenced shutdown, temporary cooling, engineered isolation, remote blockage removal, personnel relocation or emergency power support. None can be assumed viable without engineering and operational review.

The point is not to solve the hypothetical from a distance. It is to expose the boundary of the Start Work Check.

What does it say about an organisation’s resilience when compliance with one critical safeguard appears to create an immediate threat somewhere else in the system?

Frequently asked question

What is the difference between a Permit to Work and a Start Work Check?

A Permit to Work authorises defined work under specified conditions. A Start Work Check confirms, immediately before work begins, that the critical safeguards are physically present, functioning and understood at the actual worksite. The permit establishes the plan. The Start Work Check tests whether reality still matches it.

Sources

  • [S1] International Association of Oil & Gas Producers, Life-Saving Rules – Start Work Checks, Report 459-1, December 2021, https://www.iogp.org/bookstore/product/life-saving-rules-start-work-checks/.

Author

Phillip Inzaghi — Founder, AxiomOrdo.