Technical Summary
Key takeaways:

The article shows that permanently reducing bypassing requires observing actual work in practice and eliminating its technical and organizational causes. In practice, tolerating known bypasses amounts to a management decision to accept the associated risks and costs.

  • Bypassing safeguards usually results from a conflict between safety, ergonomics, and production pace, not merely from a lack of discipline.
  • Blaming individuals without analyzing actual work obscures the source of the problem: design decisions, procedures, and workstation organization.
  • It is worth measuring the number of entries into the zone, jams, restarts, and the difference between the planned cycle and the actual cycle.
  • Regular walkthroughs indicate the need to review technical solutions, supervision, and the workstation risk assessment.
  • Safe working methods should also be the easiest and fastest; otherwise, shortcuts become predictable.

Bypassing safeguards is a design signal, not just a discipline issue

Bypassing safeguards at a production workstation usually does not result from disregard for risk. More often, the operator is trying to maintain work pace, product quality, or access to the working area within a poorly arranged process. If performing the task as instructed means slower changeovers, more difficult jam clearing, or a series of unnecessary stops, the bypass is not an exceptional event but a predictable response to a conflict between safety, ergonomics, and production requirements. That is why the first management mistake is to personalise the problem and look for “those at fault” before the plant understands when, why, and under what conditions safeguards are being bypassed. That reaction may be organisationally convenient, but it usually obscures the real source of the issue: design decisions that made the shortcut a rational choice.

From the perspective of production management, occupational health and safety, and maintenance, this means changing the starting point. A safety culture is not about multiplying prohibitions, signatures under instructions, and additional warnings. It is about shaping the workstation and work rules so that safe action is also the easiest and fastest option. If a guard slows down changeovers, an interlocking switch makes short interventions harder, a light curtain restricts visibility, or the control system generates false stops, the problem does not end with human behaviour. It also involves workstation ergonomics, machine operating logic, the way responses to disturbances are organised, and often workstation and safeguard design that does not conflict with production, including design that takes maintenance needs into account. In practice, it is not the operator who is “fighting safety”; the work system is forcing a choice between performance and compliance with the original design assumptions.

This is easiest to see in simple operating situations. The line runs correctly in the nominal cycle, but several times per shift it requires entry into the danger zone because a part jams, a sensor loses position, or reject ejection causes a micro-stop. If every such intervention involves a full stop, a long restart, and loss of process continuity, bypassing the safeguard becomes, from the operator’s point of view, a way to meet the plan. In that case, it is worth measuring not only the rule violations themselves, but also the number of interventions requiring entry into the zone, the frequency of jams and restarts after safeguard activation, and the gap between the planned and actual cycle time. This usually gives a more useful picture than a behaviour audit alone, because it shows where cost and risk are really building up.

A reliable diagnosis must therefore cover real work, not just the instruction, the risk assessment prepared at acceptance, or the process assumptions. The gap between those two realities usually explains the source of the bypasses. You need to observe the workstation during a normal shift, during product changeover, cleaning, unblocking, and restart after downtime; only then does it become clear which safeguards are bypassed most often and why. In Polish and EU compliance practice, this is crucial, because the obligation to ensure safe use of a machine is not fulfilled simply by formally equipping it with protective measures. If the way work is organised or an established operating practice leads to systematic circumvention of safeguards, this is a signal for the employer and those responsible for the process that they need to review not only discipline, but also the adequacy of the technical solutions, procedures, supervision, and minimum occupational health and safety requirements and the safe use of machines, and, where necessary, also revisit the workstation risk assessment.

The cost of bypassing rises where the organisation does not see real work

The most expensive consequences of bypassing safeguards rarely appear first in the accident register. Before an injury event occurs, the plant usually pays in other ways for a long time: the process becomes unstable, jam clearing turns into routine, the number of ad hoc repairs increases, and quality starts to depend on who happens to be standing at the machine. That is exactly why the problem must not be assessed solely through the lens of a single incident. If a safeguard is bypassed regularly, it means the organisation has accepted the hidden cost of everyday work performed in deviation from the rules. In practice, it is worth looking not only at downtime, but also at the number of interventions in the danger zone per shift, the time lost to manual unblocking and system reset, the repeatability of faults after operation in bypass mode, and the share of such events in downtime and quality deviation analyses. That provides a picture accurate enough for decision-making, without creating an illusion of precision.

In the background, there is almost always a poorly balanced trade-off between machine availability, production pace, and the safety of interventions. Management often sees only the outcome: downtime, missed targets, a complaint, or a reported incident. What it does not see is that the source lies in design and organisational decisions: overly frequent changeovers with no time to prepare the workstation safely, manual jam clearing built into normal operations, an unclear restart sequence, poorly positioned protective devices, or the failure to eliminate the technical root cause permanently. In such conditions, bypassing a safeguard is not “human error” in any simple sense, but a predictable response to the way incentives are set up. This is also the point at which the issue stops being treated as purely operational. If known bypasses are tolerated, the decision not to eliminate them becomes a management decision, comparable to any other decision to accept the cost of downtime instead of the cost of modification.

The clearest example appears on machines where short changeover time and a quick return to operation after a jam are critical. If the operator knows that formal shutdown, energy isolation, entry in line with procedure, and restart will take longer than a “quick” intervention through a bypassed safeguard, the organisation itself is pointing them toward the shortcut. From the outside, it looks like a single violation, but from a process perspective, it creates a parallel, informal working standard. Training does not cover it, instructions do not describe it, risk analysis does not account for it, and formal accountability usually pretends it does not exist. At the same time, this informal standard is exactly what starts to determine line performance, product quality, and actual machine availability. The longer this continues, the more the plant becomes dependent on “experienced” operators who know how to work around the problem without stopping production. That is a very bad sign for the maturity of line supervision, because it means process stability does not come from well-designed work, but from local practices and employee memory.

Failure to act on known bypasses carries another cost, one that is harder to capture in a spreadsheet but highly significant: it undermines the credibility of supervisors. Operators quickly recognise whether the company genuinely wants safe work or only formal confirmation that the rules are being followed. If a supervisor reacts only after an incident, while previously tolerating bypassing guards, interlock switches, or working in the danger zone during jam clearing, the message is unambiguous: results matter, as long as nothing serious happens. In that environment, reporting bypasses becomes politically risky, and deviation management turns into a box-ticking exercise. That is why the first decision is not always to spend a long time measuring the scale of the issue; sometimes simple technical and organisational corrections need to be launched in parallel wherever the source is obvious, while data on interventions, restarts, and quality deviations is gathered at the same time. Only against that background does it become clear whether the problem requires escalation to plant management, changes to intervention procedures and safe machine stopping, or broader modification of safeguards and redesign of the safety function logic.

In the Polish and EU context, this matters not only organisationally but also from a compliance perspective. The mere fact that a machine is formally equipped with protective measures does not end the responsibility of the employer or those directing the work if the known operating practice is to bypass them. If the bypass has become part of day-to-day work organisation, the issue no longer concerns isolated behaviour, but the adequacy of the technical measures adopted, the instructions, supervision, and the way rules are enforced. For that reason, the cost of a bypass should be presented not as an abstract “occupational health and safety risk”, but as the combined cost of an unstable process, quality deviations, ad hoc maintenance, and weakened management accountability. Describing it this way usually prepares the ground for an investment decision better than an appeal for stricter discipline alone.

The operator’s decision conditions need to change

If an operator regularly bypasses a safeguard, it is usually not because they consciously choose greater risk, but because in that working setup it appears to be the fastest way to complete the task. The conflict arises when production rhythm, quality, and delivery performance all have to be maintained at the same time, while the safeguard in place makes it harder to access the point of disturbance, observe the process, or carry out a simple intervention after a minor stoppage. In practice, these are exactly the situations that should be described first: for what type of disturbance the operator enters the danger zone, how many steps safe stopping requires, how many restarts and alarm acknowledgements are needed after resumption, and how long the compliant method takes compared with the bypass practice. Only that kind of intervention map shows whether the source of the problem lies in workstation design, machine operating logic, inconsistent changeover rules, or the way performance is measured. Without it, a plant can very easily mistake a rule violation for poorly designed work.

An effective response almost never comes down to a single action. You need to change the conditions shaping the operator’s decision so that the safe method is also workable in organisational terms. Some causes can be removed without a full upgrade: improve sensor settings, reduce false stops, simplify service access to points where disturbances occur frequently, eliminate unnecessary restarts, streamline the alarm acknowledgement logic, or standardise the sequence of steps during changeover. If, however, the workaround stems from the workstation’s basic architecture, changes may be needed to the guard design, the material feed method, the motion sequence, or the intervention concept during disturbances. At the same time, performance indicators that unintentionally reward risky shortcuts must be corrected: the team leader and shift manager must have real authority to stop the process without being penalised for a short-term drop in results if that is necessary to work safely and consistently. Otherwise, the organisation sends two conflicting signals: formally it requires compliance with the rules, while in practice it rewards bypassing them.

The most common mistake is involving operators only when a finished solution is ready for approval. Their input is needed earlier, at the stage of identifying where the procedure diverges from the real job. Short workplace observations and interviews with operators, team leaders, and maintenance staff usually reveal very quickly where the instruction assumes ideal conditions while day-to-day operation depends on frequent minor disturbances. In a plant with many similar workarounds across different lines, it makes little sense to start with an equally detailed review of the entire machine fleet. A better approach is to combine two criteria: frequency of intervention and potential severity of consequences. Workstations where disturbances occur every day create the strongest pressure for shortcuts; workstations with lower frequency but high potential harm may require immediate restrictions on operation or a shutdown until the cause is removed. This is already a matter of managing technical and organisational change, where ownership of actions on the production, occupational health and safety, and maintenance sides must be assigned clearly, without blurred responsibility.

  • First, remove the obvious and recurring causes that make the workaround predictable.
  • Next, compare the time required and the number of steps for the safe method and for the workaround used in practice.
  • If the difference results from the workstation design or the control logic, a technical change is needed, not another instruction.

Only in that context does a disciplinary conversation make sense. The employer and those supervising the work can require compliance with the rules when they can show that the safe method is understandable, technically feasible, and supported by the organisation. If that condition is not met, a sanction usually does not remove the cause; it merely pushes the problem into silence: the workarounds do not disappear, they simply stop being reported. From a compliance perspective, this is fundamental, because a known and tolerated practice of bypassing protective measures undermines the claim that the adopted solution actually ensures the machine’s safe use. Where a planned improvement affects safety functions, the control system, access to hazardous areas, or the organisation of interventions, a formal risk assessment may be needed after the technical and organisational changes. Quick operational corrections, by contrast, make sense only if they do not become a substitute for a decision to rebuild the workstation or to re-check whether the current safeguards and the way the machine is used are actually adequate for the real work.

Only at the end: responsibility, conformity assessment, and lasting rules

Responsibility and compliance requirements should help structure decisions, but they cannot replace an understanding of the real work. A regulation, standard, or manufacturer’s instruction will not by itself explain why, on a specific line, an operator chooses to bypass a guard, interlock, or hazardous-area entry procedure. That has to be established at workstation level: what task is being performed, at what pace, under what disturbances, and under what performance pressure. Only then can you sensibly decide whether the problem lies in the technical design, the organisation of interventions, the control logic, the availability of tools, or the way supervision is carried out. This order matters in practice: if the analysis ends with nothing more than an appeal for discipline, the plant usually reinforces a situation in which the official rule says one thing while daily work forces another.

That is why a lasting safety culture starts with consistency in decision-making. The technical design, workstation instructions, training, line supervision, and the performance management system must not send conflicting signals. If the team leader is judged solely on cycle time, maintenance accepts temporary fixes, and the documentation formally assumes an operating mode that no one actually uses, then the workaround will remain the rational choice. In practice, the most important factor here is management consistency. No tolerance for known workarounds must go hand in hand with a willingness to fund technical corrections, organisational changes, and the downtime needed to implement a safe method. Otherwise, the plant is demanding compliance with rules that it has not made workable itself.

This is especially clear with “minor” changes that, from a production perspective, seem purely operational. Moving a sensor, changing the stop sequence, repositioning a guard, adding exceptions to service access, or permanently leaving a hatch open because “it makes clearing jams easier” are not neutral adjustments. If they affect how the machine operates, the control system, protective measures, or access logic, the plant must assess the impact of those changes on safety, continued use, and the related compliance obligations. This is exactly where the practical question arises: when does a change at a workstation require a broader analysis of its impact on machine safety, and is a more comprehensive machine conformity assessment needed after technical and organisational changes? It is equally important to determine who approves such deviations and whether instructions, training, and supervision criteria are updated after implementation.

Documenting these actions only makes sense if it supports work management rather than just filling a file. A useful record should show what was changed, why it was changed, how it affected the way the machine is used, what measures were adopted, and how it was verified that the safe method is actually being followed and is workable. In practice, it is worth tracking not so much the “number of violations” as the list of technical and organisational changes introduced together with an assessment of their impact, the number of returns to previous practices after corrective actions were implemented, and the results of workstation reviews after changes. This provides a basis for linking corrective actions with periodic risk review and makes it possible to identify early when a formally improved solution does not work in day-to-day operation.

Only in this context do legal and normative requirements serve their proper purpose: they clarify the scope of the employer’s duties for work organisation, the rules for safe use of the machine, and the need to verify conformity after changes. This is not about a legal interpretation, but about a simple decision-making consequence: if the plant knows about a workaround and tolerates it, it accepts responsibility for a situation in which the formal rules do not match actual operation. The right end result, then, is not “zero violations on paper”, but a predictable system of work in which the workaround is no longer needed, worthwhile, or tolerated. This is also the right point to distinguish routine operational adjustments from cases requiring a broader conformity assessment of machines, and, where solutions involve pressure equipment or its accessories, to also take into account the separate requirements applicable to that scope of change, including the Pressure Equipment Directive 2014/68/EU (PED).

Safety culture in a manufacturing plant: how to reduce the bypassing of safeguards without conflicting with production

Most often, it is not because they disregard the risk, but because they are trying to maintain work pace, quality, or access to the work area in a poorly designed process. When a safe procedure clearly slows the job down, bypassing it becomes a predictable system response.

Not only that. The article stresses that looking for someone to blame, without understanding when and why safeguards are bypassed, usually obscures the real source of the problem: design, organizational, and operational decisions.

You need to observe actual operation, not just the instructions or the assumptions made at machine acceptance. Situations involving changeovers, cleaning, clearing jams, and restarting after downtime are particularly important.

Useful indicators include the number of interventions requiring entry into the danger zone, the frequency of jams, the number of restarts after safeguards have been triggered, and the gap between the planned and actual cycle time. This kind of picture can be more useful than a behavioural audit alone.

The starting point should be to design the workstation and work rules so that safe operation is also the easiest and fastest option. In practice, this means reviewing ergonomics, the machine’s operating logic, procedures, supervision and, where necessary, the workstation risk assessment.

Share: LinkedIn Facebook