Skip to content
Eurosystem

Safety & LOTO

Parent/child lockout: how to manage hierarchical isolations on complex plants

24 June 20267 min read

In breve

Parent/child lockout is the formal management of the dependencies between isolations when a "parent" point controls or enables several "child" points. UNI EN 17975:2025 requires it explicitly for complex plants: a defined application and release sequence, traceability of who unlocks what and when, and rules to avoid out-of-order releases.

When classic LOTO is not enough

An operation on an isolated valve is simple: one isolation device, one padlock, one tag. On a real plant of a pharmaceutical, chemical or manufacturing site, the typical scenario is different: a packaging line requires the simultaneous isolation of the main electrical supply, the service electrical supplies, compressed air, steam, cooling water and product flow. Six, ten, sometimes twenty isolation points for a single operation.

In these scenarios LOTO stops being an action and becomes a system of relationships. Some isolations must be applied before others. Some cannot be removed while others are active. Some protect several operators at the same time. This is where the parent/child logic comes into play.

What parent/child means

The analogy is hierarchical: a parent isolation controls, enables or protects one or more child isolations. Three typical cases:

Protective parent. A main disconnector (parent) must be locked before it is safe to work on the secondary disconnectors (children). Removing the parent before the children exposes operators to involuntary reactivations.

Shared parent. A main shut-off valve (parent) isolates a line on which several teams work in parallel. Each team applies its own child padlock; the parent cannot be released as long as even a single child padlock is active.

Enabling parent. The isolation of the compressed air (parent) is a precondition for working on the pneumatic cylinders (children). The sequence is constrained: parent first, then children; on release, children first, then parent.

What the 17975 requires

The standard does not prescribe a specific technology, but it makes three requirements substantial:

Formal mapping of dependencies. For each complex plant it must be defined which isolations are in a hierarchical relationship and of what type. It is not a side note: it is part of the LOTO procedure.

Application and release sequence. It must be written down, not left to experience. Who applies first, who last, who removes in which order.

Traceability of operations. Every application and release of a padlock must be recorded so that, at any moment, the state of the system can be reconstructed: which points are isolated, by whom, since when, for which operation. It is the audit trail that the standard requires explicitly.

Why paper struggles

On a plant with two or three isolation points, the paper register holds up just fine. On plants with dozens of points, practice repeatedly shows the same problems:

Sequence errors. An operator removes the parent before the children because "the colleague will take off the children anyway". The colleague assumes the parent is still isolated.

Lost tags. On a cabinet with sixty padlocks, the physical tag-to-point correspondence degrades over time.

Register filled in afterwards. At the end of the shift, the maintenance technician "reconstructs" the day's operations. The traceability is formal, not real.

Opaque shift changes. Handover between different teams without a single view of the system state opens windows of risk.

None of these is an exotic problem: they emerge whenever the plant's complexity exceeds the capacity of a sign-off sheet to keep up.

How to design an effective parent/child system

Regardless of the tool (paper, digital, hybrid), a parent/child system works if it meets five criteria:

  1. Procedural constraint, not just informational. Knowing that "the parent must be locked first" is informational; physically preventing a child from being applied without a parent is procedural. The 17975 pushes in the second direction.
  2. System state always queryable. At any moment, it must be possible to answer: which isolations are active, who applied them, for which operation, since when.
  3. Constrained release sequence. The children are removed before the parent, not the other way around. The system must prevent (or at least flag) out-of-order release.
  4. Automatic audit trail. Every operation is recorded at the moment it happens, not afterwards. Who, what, when, why.
  5. Shift-change management. When a team takes over, it inherits a clear and traced state, not a sheet to decipher.

These criteria are independent of the technology. They can also be achieved with very disciplined paper procedures and well-organized LOTO cabinets — but the cognitive cost grows with the number of points, and beyond a certain threshold it becomes unsustainable.

The digital translation

The natural evolution, on plants that have crossed that threshold, is a system in which the parent/child rules are coded into the software that manages the LOTO cabinet. Releasing a child padlock requires the parent to still be active. Releasing the parent is prevented while children exist. Every operation is recorded automatically, associated with the operator who performed it and with the operation for which it was done.

This is exactly the approach of SmartLOTO: the selective release of the padlocks is not an extra feature, it is the hardware-software translation of the parent/child logic required by the 17975. It is not the only possible route, but it is the one we chose because — in the sites where we operate — it is the only one that eliminates sequence errors and the audit trail filled in from memory at the root.

The Eurosystem experience

In the pharmaceutical sites where we manage maintenance procedures, the shift from paper-based management to system-constrained management has been the most visible leap in maturity. Not because paper does not work — it does, if disciplined — but because the operational stress of the discipline grows with complexity, and in an audit-ready site every recording anomaly is a point of observation. SmartLOTO was born from this experience: not to "digitize LOTO" but to relieve the operator of the burden of keeping the right sequence in mind.

Domande frequenti

Is parent/child lockout mandatory by law?

There is no specific legal obligation, but UNI EN 17975:2025 requires it explicitly for managing hierarchical or interdependent isolations on complex plants, whether through procedures or through software support. It is part of the requirements for demonstrating compliance with the state of the art.

When is a plant considered 'complex' for LOTO purposes?

There is no numerical threshold defined by the standard. In practice, a plant is considered complex when a single maintenance operation requires several simultaneous isolation points, when multiple teams work in parallel, or when there are sequential dependencies between isolations. Five or six points are already a significant operational threshold.

Can parent/child be managed with written procedures and a traditional LOTO cabinet only?

Yes, it is possible, and it is the starting point for many sites. The condition is rigorous discipline: detailed procedures for each typical operation, in-depth training, periodic checks. Beyond a certain threshold of complexity (and number of points), the cognitive cost of the discipline makes a digital support that constrains the sequence preferable.

What happens in case of a shift change during a prolonged operation?

The incoming team inherits the isolations applied by the previous team. The 17975 requires clear traceability of the state: which points are isolated, by whom they were applied, for which operation, since when. Without this view, the shift change is a window of risk. Digital parent/child systems solve the problem structurally.

What does the audit trail of a parent/child system record?

At least: operator identifier, isolation point, type of operation (application/release), timestamp, reference operation, and any parent-child relationship. On digital systems, compliance with the expected sequence and any flagging of out-of-order release attempts are also recorded.

Related resources