Executive Summary
Marine Safety Forum alert 26-11 records another lost-time injury caused by a failure to isolate, filed under hand injuries. We dissect the recurring mechanism behind isolation and permit-to-work breakdowns, show why the paperwork rarely catches them, and set out concrete verification, LOTO and handover controls for survey, inspection and diving operations.
A brief alert, a familiar failure
The Marine Safety Forum issued safety alert 26-11, “Lost Time Incident – Failure to Isolate,” on 21 August 2026, filed under the category of hand injuries. The published alert is short. It names the mechanism – a failure to isolate – and the consequence – a lost-time injury serious enough to keep someone off work.
That single line sits alongside a run of recent MSF alerts that will be familiar to anyone managing offshore deck and subsea operations: complacency during tubular cargo handling (26-09, a crew member injured loading 13-inch casing in port), a mooring line drawn into a thruster (26-08), and a high-potential near miss during fast rescue craft maintenance (26-01, crew members falling to sea while changing out lifting slings). Different tasks, different vessels, one shared theme – energy that was present when someone assumed it was absent.
We are not going to invent the details of 26-11; the alert does not give them, and speculating on the specific injury would add nothing. What the alert does give us is a mechanism worth taking apart, because “failure to isolate” is not a one-off. It is one of the most durable causes of lost-time injury across survey, inspection, IMR and diving work, and the reasons it survives every generation of procedure are worth stating plainly.
Where isolation actually breaks down
Isolation is a control with a defined engineering sequence, and each step in that sequence is a place it can fail. Industry guidance and the IOGP Life-Saving Rules on energy isolation set the same expectation: identify every energy source, isolate it, lock and tag the isolation, and verify zero energy before anyone puts a hand into the danger zone. The failures cluster at specific stages.
Incomplete energy identification. The most common root cause is not a skipped lock – it is an energy source nobody wrote down. A survey or inspection worksite carries more stored and live energy than the obvious rotating machinery. Hydraulic accumulators hold pressure long after a pump is stopped. Pneumatic lines, sprung mechanisms, suspended loads on A-frames and cranes, capacitive charge in subsea electronics, and hydrostatic head across a valve or caisson are all energy that can move a component or a body. For divers, the differential-pressure hazard across an unisolated intake, sea chest or flooded caisson is the extreme case: a source that is invisible, silent, and lethal, and one that a “stop the pump” instruction does not remove if a valve downstream is open.
Isolation planned but not positively secured. A valve turned to the closed position is not an isolation. Without a lock and a tag it can be reopened by another party who has no idea a person is exposed. This is the failure mode that combined and simultaneous operations create almost by design – two work parties, one system, and an isolation held by trust rather than hardware.
Verification skipped. The step that most often disappears under schedule pressure is the try-out: physically confirming zero energy by attempting to operate the equipment, bleeding down pressure, proving dead electrically, or checking that a valve genuinely holds. “It looked isolated” is the phrase that recurs in incident reports, and it is not verification.
Why the permit-to-work did not catch it
A permit-to-work is supposed to be the net that catches all of the above. It frequently does not, and the reasons are systemic rather than individual.
The first problem is that the permit becomes an administrative artefact rather than a live verification. When a permit is signed at a desk, distant from the isolation point, the signature confirms that a form was completed – not that anyone walked the system and proved it dead. A permit signed on the strength of a verbal assurance carries the same paper weight as one signed after a physical walkdown, and that is the flaw. The control depends entirely on the integrity of the verification behind the signature, and nothing on the form distinguishes a rigorous check from a rushed one.
The second problem is single-person verification. Where the same individual identifies the energy sources, applies the isolation and confirms it, there is no independent check on the mental model. If that person missed a source at the planning stage, they will miss it again at the verification stage, because they are verifying against their own incomplete list. A separate isolation authority breaks that loop.
The third problem is the handover. Isolations that survive a shift change often lose their provenance. The oncoming supervisor inherits a permit and a set of tags but not the reasoning – which specific valve, why that isolation point and not another, what was tried and proven. Without a face-to-face isolation walkdown at handover, the second crew works to the first crew’s assumptions without ever testing them.
Underneath all three sits production pressure, and it deserves to be named as an engineering factor rather than a moral one. When the vessel is on a weather window, the ROV is ready to launch, or the diving bell is about to be deployed, the verification steps are the ones that feel optional because they produce no visible progress. The same dynamic drives crews to work around controls elsewhere on the vessel; we have examined how it plays out on the bridge in the context of DP crews bypassing station-keeping guidelines under operational pressure. The mechanism on deck is identical – a control that costs time is quietly demoted when the schedule tightens.
What this carries into diving and inspection work
The failure to isolate is dangerous everywhere, but diving raises the consequence because the person exposed is in the water, remote from the isolation point, and unable to remove themselves quickly.
Thruster isolation is the clearest case. Diving from a vessel in dynamically positioned mode – governed by IMCA D 010 – creates a direct conflict between two safety goals. The diver needs thrusters near the working area isolated so a rotating unit cannot injure them or draw them in. The vessel needs those same thrusters to hold position. Resolving that tension is a planning task, not a deck decision: which thrusters are isolated, which are available, what the position-keeping margin is with the reduced thrust envelope, and what the abort criteria are if position degrades. When the isolation is treated as a checkbox rather than a designed configuration, the diver ends up either exposed to a live thruster or exposed to a position excursion. Neither is acceptable, and the choice between them should never be made live.
Subsea system isolation adds hydraulic, hydrocarbon and electrical hazards that the diver cannot see. A manipulator or subsea tool with residual accumulator pressure, a hydrocarbon line that was depressurised but not drained, cathodic protection or hot-work currents, and the delta-P across an intake all require positive isolation and verification before the diver is committed. The general code of practice for offshore diving, IMCA D 014, and the associated diving guidance set the framework, but the framework only works if the energy identification behind it is complete.
Inspection and survey vessels running IMR scopes carry the same exposure in a less obvious form. Winches, A-frames, launch and recovery systems, tugger lines and deployment sheaves store and release energy, and the person changing a sheave, reterminating a wire or clearing a fouled line is exactly the person the mooring-line-in-thruster and FRC sling-change-out alerts describe. These are hand-injury and fall hazards created by unisolated mechanical energy, and they belong to the same family as 26-11.
Multi-party worksites concentrate the risk. When a survey contractor, a diving contractor and the vessel crew all work the same deck and the same subsea system, the isolation register has to be single and shared, with locks held by every party exposed. We have set out how that interface should be governed in our analysis of running combined subsea operations across separately contracted teams, and isolation control is the sharpest edge of it – the point where a gap between two companies’ procedures becomes a person’s injury.
Closing the gap: what to change before the next dive
The corrective actions that follow an isolation LTI are usually a repeat of the toolbox talk and a reminder to “follow the permit.” That does not address the mechanism. The following do, and each is testable inside your own operation.
-
Build an energy-source register for every task, before the permit is raised. List each source by type – electrical, hydraulic, pneumatic, hydrostatic/delta-P, gravitational/suspended load, stored/sprung, chemical. Require it to be signed off against the P&ID or the equipment schematic, not from memory. The register, not the permit signature, is the primary control.
-
Separate the isolation authority from the person doing the work. No permit is issued until an independent competent person has physically verified zero energy at the isolation point – proved dead, bled down, or tried out. Track the proportion of permits that record a documented zero-energy verification, and treat any permit without one as a live finding.
-
Use lock-out/tag-out hardware with personal locks, one per exposed person. For diving, the diver’s isolation is held under the control of the dive supervisor and cannot be removed while a diver is in the water or committed to the worksite. A shared valve position is not an isolation; a locked one is.
-
Design thruster isolation as a configuration, not a deck call. For DP diving under IMCA D 010, define in the dive plan which thrusters are isolated, the position-keeping capability with the remaining envelope, and the abort criteria. Confirm it in the pre-dive with the DPO and the dive supervisor together.
-
Make handover a physical walkdown, not a paper transfer. No isolation crosses a shift change without the oncoming and outgoing supervisors walking the isolation points together and confirming the reasoning behind each one. Record it.
-
Give the exposed person an unambiguous stop trigger. Anyone who cannot personally confirm the isolation, or who sees a tag or lock they do not understand, stops the task until it is resolved – with no schedule consequence for doing so. Measure how often that authority is used; a rate of zero over a long period usually means it is not real.
The value in alert 26-11 is not the incident it records but the mechanism it names. Isolation failures are not caused by people who do not know isolation matters. They are caused by verification steps that produce no visible progress being quietly dropped under pressure, and by permits that certify paperwork rather than proven-dead systems. Close the gap between the signature and the walkdown, and this class of lost-time injury stops repeating.
Based on: Lost Time Incident – Failure to Isolate
Published by
Diving & Subsea Operations Panel
Commercial Diving, Life Support & IMCA Standards
An expert panel reviewing commercial and saturation diving operations, life support systems, IMCA diving standards, and subsea intervention safety practices.
Offshore Geomatics Foundation Certificate · October 2026
Turn reading into certified competence
Most of the failures we analyse trace back to fundamentals nobody verified. The Foundation Certificate is a structured way to close exactly those gaps.
Early-access list gets 40% off at launch. No spam – the waitlist is only ever used for the certificate. What the certificate covers →