Maintenance shutdown process flowchart (planned turnaround)
Maintenance shutdown process flowchart template: worklist and scope freeze, contractor and permit planning, readiness go/no-go, isolation, emergent-work approval, testing, start-up and close-out record.
What the maintenance shutdown process flowchart (planned turnaround) process is
A maintenance shutdown, or turnaround, is planned work carried out while a plant, unit or line is deliberately taken out of service for a fixed window, rather than maintenance squeezed around production. The trigger is the shutdown date on the maintenance calendar, and the chart below follows one shutdown from the worklist compiled ahead of it through to the record closed once production is running again: requests prioritised and the scope frozen at a cut-off date, contractors, permits and long-lead spares planned against a schedule with its own critical path, a readiness review before a single lock goes on, isolation and execution against the worklist, emergent work approved within a contingency budget or deferred, inspection and testing, de-isolation and a written start-up sequence, a performance check, and a close-out report that feeds the next shutdown's planning.
This chart covers the plant or asset owner's own management of the shutdown, not a specialist contractor's internal procedure for the work it is engaged to do inside it: a calibration, electrical or inspection provider mobilised for the outage runs its own service SOP under this shutdown's isolation and permit-to-work regime, and the two meet at the handover into 'Execute work against the worklist' rather than being drawn as one chart. It is also distinct from routine preventive maintenance, which schedules one asset against a calendar or meter interval and never freezes a shared scope, books a plant-wide outage window or coordinates a contractor crew; where a shutdown turns up work that is really routine PM due anyway, that item is better tracked on the asset's own PM schedule than folded permanently into this one. Because isolation, lockout and permit-to-work sit at the centre of this process, treat the chart as a starting point to adapt under your own process safety management, isolation standards, statutory duties and competent-person review, not as a substitute for them.
Four decisions carry the process, and each sits in the lane that should own it. 'Late addition after freeze?' belongs to the planner because scope discipline is a planning function: an approved exception re-enters the plan under change control, a deferred one is logged for next time, and either way the worklist stays the single record of what the shutdown covers. 'Readiness review passes go/no-go?' gates isolation on the schedule, permits, spares and crews being confirmed together, not on the calendar date alone, which is what stops a shutdown starting only to stall on day one waiting for a permit or a part. 'Emergent work found?' and 'Approve within contingency?' are deliberately two decisions rather than one: Engineering / inspection reports what it finds, and the shutdown manager decides what the contingency budget can absorb, which keeps discovery and spending authority with different people. 'All work passes inspection?' and 'Performance meets spec?' are the two checks either side of start-up, run by inspection and by Operations, so the crew that did the work is never the only signature on whether it is done.
What this flowchart covers
In this template
- Six swimlanes (Shutdown manager / planner, Operations, Maintenance / contractors, EHS, Engineering / inspection and Procurement) across six phases: scope and freeze, plan and mobilise, readiness review, shutdown and execution, testing and start-up, and close-out
- A "Late addition after freeze?" decision that splits every request arriving after the cut-off into a genuine exception added under change control or a job logged for the next shutdown, so scope discipline survives a busy planning week
- A "Readiness review passes go/no-go?" gate that sits before a single lock goes on, checking the schedule, permits, spares and crews together rather than letting isolation start on the strength of the worklist alone
- An "Emergent work found?" decision in the Engineering / inspection lane that feeds a separate "Approve within contingency?" decision owned by the planner, so what gets added to a live shutdown is a budgeted choice, not whatever the crew happens to find
- An "All work passes inspection?" decision that routes a failed check back to "Inspect and test completed work" for rework and retest, so a defect found under isolation cannot reach de-isolation on the strength of the first pass
- A "Performance meets spec?" check after start-up owned by Operations, the lane accepting the equipment back, before "Record close-out report and costs" and a lessons-learned step close the turnaround for the next planning cycle
When to use this template
- You are planning an upcoming plant shutdown and want the worklist, freeze, mobilisation and go/no-go gate fixed on one chart before the outage date arrives
- You need to show contractors, EHS and operations exactly where isolation, permits and daily progress meetings sit relative to each other during the window
- Shutdowns keep overrunning and you want to see whether they stall at the freeze, the readiness gate, or emergent work eating the contingency budget
- You are configuring a CMMS or project tool for turnaround management and want the process agreed before work order types and approvals are set up
- An auditor, insurer or client has asked how a planned shutdown is scoped, executed under isolation and closed out, including how emergent work is approved
How it works
Rename the lanes to your roles
Replace Shutdown manager / planner, Operations, Maintenance / contractors, EHS, Engineering / inspection and Procurement with the roles that genuinely run a shutdown on your site. On a smaller site the shutdown manager and the planner are often one person: merge those lanes rather than drawing a handoff that never happens.
Set your scope freeze rule
State how many weeks or months ahead of the outage the worklist is frozen, and who has the authority to approve a late addition under change control versus defer it to the next shutdown. The later the freeze, the less time contractors, permits and spares have to catch up.
Write your isolation and permit-to-work rules onto the chart
Record what isolation each job needs, who applies and removes the lock, which jobs require a written permit, such as hot work, confined space entry or work on stored energy, and where the signed permit and isolation certificate are kept during the outage.
Define what the readiness review checks
List what has to be confirmed before 'Readiness review passes go/no-go?' can return a Go: schedule and critical path signed off, contractors and crews confirmed, permits drafted, and long-lead spares physically on site, not just on order.
Set the contingency rule for emergent work
Agree what 'Emergent work found?' actually means on your site, and give the shutdown manager a real contingency figure, hours and cost, to weigh against before approving a job into a live outage rather than deferring it to the next one.
Define the close-out record
List what 'Record close-out report and costs' must capture: actual cost and duration against plan, the punch list of anything still outstanding, and every emergent job, whether it was executed or deferred, so the next shutdown starts from evidence.
Walk it against a completed shutdown
Take a recent shutdown, ideally one that overran, and trace it through the chart from the frozen worklist to close-out. Any step people describe from memory that is not drawn, or drawn but routinely skipped, is the finding worth fixing before you publish it.
Frequently asked questions
What are the steps in a maintenance shutdown process?
The worklist is compiled from requests across operations, maintenance and inspection, prioritised by risk and criticality, and the scope is frozen at a cut-off date; any later addition is either approved as an exception under change control or deferred to the next shutdown. Contractors are mobilised, long-lead spares are ordered, a permit-to-work and isolation plan is prepared, and the schedule and its critical path are built. A readiness review has to return a Go before equipment is isolated and locked out and work begins against the worklist, tracked in daily progress meetings. Emergent work found during execution is approved within the contingency budget or deferred. Once work is inspected and tested and passes, equipment is de-isolated, started up against a written sequence and checked against performance spec before handover, and the shutdown is closed out with a cost and lessons-learned record.
How is a shutdown different from routine preventive maintenance?
Preventive maintenance schedules one asset against a calendar or meter interval, on its own downtime slot, independent of every other asset on site. A maintenance shutdown, or turnaround, deliberately takes a plant, unit or line out of service for a fixed window and executes many jobs from a shared, frozen worklist at once, coordinated through a single schedule, a critical path and a contractor crew mobilised specifically for the outage. A shutdown also carries planning and safety steps a routine PM does not need at that scale: a scope freeze with a change-control exception path, a readiness go/no-go gate before isolation, and a contingency budget for work discovered once the plant is already down. Where a shutdown turns up work that is really routine PM due anyway, the cleaner move is to track it on that asset's own PM schedule rather than fold it permanently into turnaround planning.
What is a permit-to-work system and why does it sit before isolation on the chart?
A permit-to-work system is a formal, documented authorisation issued before higher-risk maintenance work, such as hot work, confined space entry or work on isolated plant, is allowed to start; it is a control recommended by process-safety regulators, including the UK's Health and Safety Executive, for exactly the kind of concentrated hazardous activity a shutdown creates. Drawing 'Prepare permit-to-work and isolation plan' as its own step in the EHS lane, ahead of 'Isolate and lock out equipment', makes clear the authorisation is agreed before the outage starts, not written up after a crew is already on the tools. Frameworks such as the US OSHA lockout/tagout rule also require equipment to be physically isolated and locked out, not just paperwork-authorised, wherever unexpected start-up or a release of stored energy could injure someone: adapt both the permit categories and the isolation method to your own jurisdiction's requirements and your site's own procedures.
Who approves emergent work, and how is that different from the late-addition decision at freeze?
'Late addition after freeze?' is a planning-stage decision: a job requested after the worklist is frozen but before the outage starts, weighed against a schedule and crew that are still being built. 'Emergent work found?' and 'Approve within contingency?' happen once the plant is already down, when Engineering / inspection uncovers something during execution itself. Splitting discovery from approval, so the person who finds the work is not the same person who decides whether it gets done, keeps a contingency budget from being spent by whoever raises their hand first in a daily progress meeting. Work that is approved is executed within the live outage; work that is deferred is logged against the worklist for the next shutdown rather than dropped, which is what keeps the next planning cycle honest about the backlog it is actually starting from.
What should the close-out record capture?
Enough to make the shutdown usable as evidence for the next one, not just a completion notice: actual cost and duration measured against the plan, a punch list of anything still outstanding after start-up, and a record of every emergent job, whether it was approved and executed or deferred, with the reason either way. Where equipment is subject to statutory inspection or examination, keep those certificates and results as their own record rather than folding them into the general close-out narrative. A shutdown's real value is in the pattern across several outages, not one report: recurring emergent work in the same area, or a contingency budget that is consistently overrun, is worth escalating into the scope of the next shutdown rather than treated as a one-off surprise each time.