NewMeet the Virtual Facility: your terminal, live in real time.See it in action
Logo Stowlog
Port Safety & HSSE

Job Safety Analysis (JSA) at Port Terminals: How to Write One That Works

What a job safety analysis is, how JSA differs from JHA and risk assessment, and how to write a JSA for port and terminal tasks step by step.

Stowlog Team

Stowlog Team

Port HSSE Insights

10 min read
Container terminal operations requiring a job safety analysis

Ask any terminal HSSE lead what separates a controlled operation from a lucky one, and the honest answer is rarely the big-ticket engineering. It is whether the crew about to unlash the aft bays, enter the ballast tank or plug in a reefer bank has thought through, step by step, what can go wrong in the next hour and what stops it. That thinking, written down and worked before the task starts, is a job safety analysis. Done as a box-ticking exercise it is worse than nothing, because it manufactures confidence without buying safety.

What is a job safety analysis (JSA) in a terminal context

A job safety analysis is a structured method for breaking a specific task into its sequence of steps, identifying the hazards at each step, and defining the controls that make each step acceptably safe before anyone starts work. The unit of analysis is the task, not the site or the job title. "Unlashing a fully loaded 40-foot bay on a rolling vessel at night" is a JSA. "Terminal operations" is not.

That distinction keeps a JSA honest, because the same nominal activity carries different hazards depending on where and when it runs. Container lashing at height, confined-space entry into a hold or bunker tank, reefer plugging across an energised bank, RoRo ramp marshalling with live vehicle movements, and bulk cargo handling in a dust-laden hold each demand their own analysis, where generic site-wide risk registers stop being useful. The output is practical: a short document a supervisor can brief in five minutes at the point of work, and a worker recognises as the job in front of them.

JSA vs JHA vs risk assessment

The terminology causes more confusion than it should, so it is worth being precise.

Job safety analysis (JSA) and job hazard analysis (JHA) are the same thing. Both names describe one method: decompose a task, expose its hazards step by step, and control them. The terms are used interchangeably across industries and regulators, and US OSHA's own guidance, Publication 3071, titled Job Hazard Analysis, treats them as synonyms.

Risk assessment is the broader parent concept. Where a JSA is a task-level tool, "risk assessment" is the wider discipline the international standards frame: the systematic process of identifying hazards, evaluating the risk, and deciding on controls at every level, from the whole facility down to the individual job. ISO 45001 requires an organisation to establish processes for hazard identification and assessment of risk at the core of its safety management system. The EU Framework Directive 89/391/EEC places a legal duty on the employer to assess risks to workers' safety, and the UK Management of Health and Safety at Work Regulations 1999 carry the same suitable-and-sufficient assessment duty. A JSA is one instrument a facility uses to discharge that broader obligation at the sharp end, alongside area assessments, substance assessments and manual-handling assessments. Sitting under the port's ISPS security regime and the ILO's occupational safety conventions, the JSA is where all of that becomes something a lashing gang can read.

Practically: you run a risk assessment to understand the terminal. You write a JSA to run a task.

When a terminal runs a JSA

A JSA is not needed for every routine, low-hazard, well-drilled activity; pretending otherwise drowns crews in paper nobody reads. Three triggers justify one.

  • New or changed tasks. A cargo the terminal has never handled, a modified stowage plan, an unfamiliar vessel configuration, a new piece of quay-side equipment, or a change to the crew's method: anything that means the last analysis no longer describes the job.
  • High-risk and permit-controlled work. Confined-space entry into holds, tanks and voids; hot work near residues; working at height on crane structures or on the container stack; energy isolation on quay cranes and conveyors; lifting operations outside standard parameters. These almost always run under a permit-to-work, and the JSA is the reasoning that justifies issuing the permit.
  • After an incident or near miss. When something has gone wrong or nearly did, the JSA for that task is re-opened. A good near-miss reporting loop feeds directly into revising the relevant analyses, so the lesson is captured in the document the next crew works from, not buried in an investigation file.

The judgment call is proportionality: reserve the full written JSA for tasks where the analysis genuinely changes what the crew does. That is also the argument for building assessments in a system rather than by hand. Stowlog's risk-assessment module lets a terminal template the recurring high-risk tasks once and re-run them per operation.

How to write a JSA step by step

The method is simple. The discipline is in doing each stage honestly, with the crew in the room.

1. Break the task into steps

Walk the task as it will actually be performed and list the discrete steps in order: "climb to the trolley platform", "isolate and lock off the hoist drive". Too coarse and the hazards hide between steps; too fine and the document becomes unusable. Most terminal tasks land between eight and fifteen steps, and the crew who does the job will name the step missing from the official method.

2. Identify the hazards at each step

For every step, ask what can cause harm at that moment: stored energy, suspended loads, work at height, atmosphere, moving vehicles, pinch and crush points, dust, manual handling, slips on wet or oily steel. Name the mechanism, not the abstraction. "Falls from height" is weak; "fall from the unguarded trolley platform edge while both hands are on the tensioner" is a hazard you can control.

3. Rate likelihood and severity

Score each hazard on how likely harm is and how severe it would be, using whatever risk matrix the facility has standardised. The number is a triage tool, not the point. A high score tells the crew this step needs an engineered or eliminated control, not a line of PPE; a residual score after controls tells them whether the task is fit to proceed. Consistency across the terminal matters more than the precise scale, another reason to hold the matrix in one system.

4. Apply the hierarchy of controls

For each hazard, work the hierarchy in order and stop at the highest level that is reasonably practicable. This is the part crews most often skip, jumping straight to PPE because it is easy to write down.

  1. Elimination. Remove the hazard. De-energise the reefer bank before plugging; land the box to the deck rather than release it under a suspended spreader.
  2. Substitution. Swap it for something less hazardous: a less toxic tank-cleaning agent, a mechanical lashing tool that removes the manual overhead reach.
  3. Engineering controls. Isolate people from the hazard: fixed edge protection, lock-out/tag-out on the hoist drive, forced ventilation and continuous atmosphere monitoring in the tank, physical segregation of the RoRo pedestrian route from vehicle lanes.
  4. Administrative controls. Change how people work: permit-to-work, a trained standby attendant at the tank manway, a traffic management plan and banksman, exclusion zones under the load.
  5. PPE. The last line, never the first: fall-arrest harness with a rated anchor, gas-tight suit, hearing protection, respiratory protection against cargo dust.

5. Assign and verify

Every control needs an owner and a check: who confirms the isolation, who tests the atmosphere and logs the reading, who verifies the harness anchor. A control with no name against it is a hope, not a barrier. The JSA is not complete until each line has an accountable person and a means of confirming the control is in place before the step runs.

A worked terminal example: confined-space entry into a ballast tank

Consider a common high-risk task: sending a crew into a ballast tank for inspection during a lay-up.

Step: open and secure the tank manway. Hazard: residual pressure or trapped liquid behind the cover; manual handling of a heavy cover. Controls: confirm the tank is drained and vented per the plan (engineering); crack the cover in stages to relieve residual pressure (administrative); mechanical aid or two-person handling (administrative). Owner: entry supervisor verifies before the crew approaches.

Step: test the atmosphere. Hazard: oxygen deficiency, flammable vapour or toxic gas in an enclosed volume, the primary killer in tank entry. Controls: forced ventilation established and running (engineering); a calibrated gas detector tests oxygen, LEL and toxics at multiple depths before and continuously during entry (engineering and administrative); entry prohibited until readings are within limits and logged. Owner: authorised gas tester, reading recorded on the permit.

Step: enter and work inside the tank. Hazards: engulfment risk if any line could feed the tank; restricted egress; falls from the internal structure; poor lighting. Controls: positive isolation and lock-off of every line into the tank (engineering); intrinsically safe lighting (engineering); a standby attendant stationed at the manway in continuous communication and never entering (administrative); rescue arrangements confirmed and equipment staged before entry (administrative); full-body harness with retrieval line where vertical entry applies (PPE). Owner: standby attendant holds the entry log; supervisor confirms rescue readiness.

Step: exit and close out. Hazard: a worker unaccounted for; the space wrongly left as "safe". Controls: positive headcount out against the entry log; permit and JSA formally closed on sign-off. Owner: entry supervisor.

The value is not the list. It is that every atmospheric and isolation control is owned, verified and logged before a person is inside a steel box with one way out.

Common mistakes

  • Writing it in the office. A JSA composed without the crew, from a generic template, describes an idealised task nobody performs. The people who do the job find the missing step.
  • Copy-paste JSAs. Reusing the same document for lashing on a calm berth and on a rolling vessel at night. The hazards moved; the paper did not.
  • PPE as the first control. Reaching straight for the harness and the respirator because the higher levels take effort. The hierarchy is an order, not a menu.
  • Named hazards, unnamed controls. Identifying the fall, the atmosphere, the suspended load, then leaving the control column vague and ownerless.
  • Filing it, not briefing it. The most common failure: a competent analysis the crew never reads because it lives in a binder, not in the pre-task brief.

Making JSAs live

A JSA that reaches the worker at the task changes behaviour; one that sits in a folder does not, however well written. Two links close that gap. The JSA should be bound to the permit-to-work for any high-risk task, so the permit cannot issue unless the analysis has been done, the controls are named and their owners assigned. And the relevant hazards and controls should surface in the safety induction and the pre-task brief, so the crew hears the analysis in the words of the task they are about to start, not as a signature on a page. When those two connections hold, the assessment stops being a compliance artefact and becomes the operating instruction for the job.

JSAs must also stay audit-ready without a scramble. A terminal should be able to show, for any operation, which JSA applied, which controls were specified, who owned them, and that the permit and induction referenced it. Holding assessments on paper makes that a manual reconstruction; holding them in a system makes it a query. This is the reasoning behind Stowlog's risk-assessment module: task-level assessments built once, re-run per operation, linked to the permit and induction, and stored so the record is there when the auditor asks for it. For where the JSA sits in the wider picture, the port safety and HSSE guide and the note on permit-to-work at port terminals set the context.

A job safety analysis earns its place when the crew about to work the tank, the stack or the ramp recognises it as the job in front of them, and every control on it has a name and a check. That is the standard the risk-assessment module is built to hold a terminal to.

From the blog

Latest articles

View all articles