STPA[VisualPro Tech Brief] Some Maintenance Cannot Be De-Energized — Who Is Watching While the Interlock Is Off?
The foundation of equipment maintenance safety is energy isolation. Power down, lock, tag. Maintenance that can be done that way is safe maintenance.
The problem is the maintenance that cannot. To calibrate the dose on an X-ray tool you have to generate X-rays. To tune RF matching you have to apply RF. To re-teach a wafer-handling robot you have to move it. There is a class of work where the cover comes off and hands go in while the equipment is live, and for it the interlock that normally protects the technician is deliberately defeated with a maintenance key. OSHA's own lockout standard recognizes this case and carves out testing and positioning as an exception (29 CFR 1910.147(f)(1)).
During that window the technician is no longer protected by the interlock. Four other things stand in its place.
| Layer | What it protects against | Where it already exists |
|---|---|---|
| ① Equipment control state | Commands from the host (MES) and vendor remote service reaching the tool | SEMI E30 (GEM) Offline / Online-Local control states |
| ② Maintenance mode design | Bypass only by deliberate action, reduced output, interlocks automatically restored on exit | SEMI S2 maintenance mode requirements |
| ③ Work permit | Someone knows this job defeats an interlock, approves it, and supervises it | Permit to work (PTW), triggered risk reassessment |
| ④ Visibility | The fact that the interlock is off, or that wiring has changed, is visible to management | Status indication, work reports, post-maintenance interlock function test |
Every mechanism exists. The question is a single one: do these four layers actually operate in our maintenance procedures, and who verifies that they do?
On May 27, 2024, two technicians servicing a wafer-analysis X-ray tool at a semiconductor fab in Korea were exposed to radiation. One received 94 Sv to the hand — 188 times the annual equivalent-dose limit for skin and extremities (0.5 Sv).
What the Nuclear Safety and Security Commission (NSSC) found was not a failure. The interlock wiring had been altered so that opening the shielding no longer cut the X-rays, and the work had proceeded on an in-house procedure and the technicians' own judgment, without involvement of the radiation safety officer. Two radiation safety officers were responsible for 694 radiation devices. Who altered the wiring, when, and why was not established; the question of liability is under investigation.
This article does not take a position on liability. It reads the incident against the table above and notes only what is visible there. Layer ③, the work permit, was empty. Layer ④, visibility, was empty. The interlock was off, and that fact never reached any part of the management system. A tool with altered wiring looked normal, and there was no field in the work report where the alteration could have been recorded.
Semiconductor fabs are not short on safety processes. SEMI S10 assesses equipment risk, HAZOP works through process deviations, and PTW, LOTO, and management of change (MOC) govern maintenance. Yet if you line up the questions these tools ask, the window in which the tool is live and the interlock is defeated appears in none of them.
| Tool | What it asks | What it does not ask |
|---|---|---|
| Risk assessment (frequency × severity) | What hazards exist, and is there a safeguard | What remains while the safeguard is defeated and the tool is live |
| SEMI S10 · HAZOP | How equipment and process deviate from design | Who commands the tool during maintenance, and on what information |
| PTW · LOTO | Has energy been isolated | Do the four layers operate when energy cannot be isolated |
| MOC | Was the change approved | Who notices wiring that changed without approval |
The regulatory specifics below are Korean, but the gap they expose is not. Article 15 of Korea's Guidelines on Workplace Risk Assessment (Ministry of Employment and Labor Notice) requires a triggered reassessment for maintenance and repair — but exempts periodic, repetitive work that has already been assessed. Once preventive maintenance is coded as "routine PM," the reassessment can be skipped regardless of whether this particular job touches interlock wiring. Article 4 of the Enforcement Decree of the Serious Accidents Punishment Act then treats that same risk-assessment process as evidence that executive safety duties have been discharged. When the assessment is skipped, the evidence is missing too.
Whether the four layers operate is hard to answer with a checklist. You have to draw, on a single page, every path by which a command reaches the tool and every path by which information leaves it. That drawing is the first step of STPA (System-Theoretic Process Analysis) — the control structure. Developed at MIT by Professor Nancy Leveson, STPA treats accidents not as chains of component failures but as the result of inadequate control, and starts by mapping who controls what and what information each controller receives.
Below is the control structure for X-ray analysis tool maintenance, built as a virtual model in VWAY's safety analysis tool VisualPro.
Once drawn, the state of the four layers is visible at a glance.
From this one page the analysis traced nine unsafe control actions and 27 loss scenarios. The countermeasures that emerged are not new: Offline transition, automatic restoration on leaving maintenance mode, permits by job type, interlock function testing, a hardwired HV cutoff chain. The industry knows all of them. What STPA did was not invent countermeasures; it traced the command paths to show which known countermeasure was missing at which moment of which job.
They split into two groups. The first three are things EHS can verify tomorrow by opening a procedure. The last two belong in equipment purchase specifications and SEMI S2 evaluations, to be required of the equipment supplier.
Pick one maintenance procedure in which the tool stays live and an interlock is defeated. For that job, write down every path by which a command enters the tool and every path by which information leaves it, and connect them with arrows on one page. Then ask the five questions. Wherever an answer stalls is where one of the four layers is empty.
VWAY will draw that page with you. Send us one maintenance procedure that defeats an interlock, and we will return the control structure and the answers to the five questions.
· Nuclear Safety and Security Commission (Korea), press release on the investigation results of the radiation exposure at a semiconductor fab, September 26, 2024 — Korea Policy Briefing (Korean)
· Press coverage of the NSSC findings — Hankook Ilbo, Sept. 24, 2024 (Korean); Newsis, June 5, 2024 (Korean)
· Ministry of Employment and Labor (Korea), Guidelines on Workplace Risk Assessment, Notice No. 2023-19 and amendment No. 2024-76 (effective Jan. 2, 2025) — MOEL (Korean)
· Occupational Safety and Health Act (Korea), Article 36; Enforcement Decree of the Serious Accidents Punishment Act, Article 4 — Korea Law Information Center
· 29 CFR 1910.147 — The control of hazardous energy (lockout/tagout), paragraph (f)(1) Testing or positioning
· SEMI S2 — Environmental, Health, and Safety Guideline for Semiconductor Manufacturing Equipment
· SEMI S10 — Safety Guideline for Risk Assessment and Risk Evaluation Process
· SEMI E30 — Generic Model for Communications and Control of Manufacturing Equipment (GEM)
· ISO 14119:2024 — Safety of machinery: Interlocking devices associated with guards
· Nancy G. Leveson, Engineering a Safer World, MIT Press, 2011; Leveson & Thomas, STPA Handbook, 2018
· John Thomas, "Building Formal Scenarios: A New Scenario Approach," 2024

