The Tools That Need Verification Before Every Use
Why this matters
Most tools tell you when they are broken. You feel the slip, you hear the bearing, the cut goes crooked, the light does not come on. A small number of items do the opposite: they keep producing a confident output after they have stopped being right, and the output is the thing a person's safety rests on. A voltage tester that reads zero on a live conductor is not a broken tool, it is a device actively giving permission to touch something that will kill. A gas detector that has drifted low is a device that says the space is fine. Those items are the ones that need proving before use, every time, and the reason a shop needs a written list of them is that under time pressure a tech will skip the check on exactly the item that has quietly failed.
The two gates that put an item on the list
An item belongs on the every-use verification list only when both of these are true. One alone is not enough, and running them as an OR is how a shop ends up with a forty-item card that nobody uses.
- It can fail silently. Its failure is not visible, audible, or obvious in normal use. A drill with a dying motor announces itself; a meter reading 0.0 volts looks identical whether the circuit is dead or the lead is broken.
- A wrong output causes injury or an undetectable defect. Either someone gets hurt acting on it, or the work it certifies passes inspection today and fails in service later with no way to tell which jobs were affected.
Run both gates over your actual kit and the list comes out short, which is the point. A card of eight or nine items gets done in a few minutes at the start of a shift and survives; a card of thirty gets photocopied, posted, and ignored inside a month.
The list, and the specific check for each
| Item | Why it fails silently | The check, before use |
|---|---|---|
| Contact voltage tester or multimeter used for dead checks | Blown fuse, broken lead conductor, dead battery, wrong function selected: all read zero | Prove on a known live source, test the target, prove on the known live source again |
| Non-contact voltage detector | Reads through shielding inconsistently, and reads nothing on a de-energized-looking but live conductor behind a barrier | Prove on a known live source. Never accept it alone as a dead check, use a contact tester on the conductor |
| Combustible gas detector or leak detector | Sensor drift and sensor poisoning both bias low, and the display looks normal | Bump test against a known gas source, confirm alarm, confirm return to zero in clean air |
| CO monitor or personal gas monitor | Same drift failure, and the reading you are trusting is a zero | Bump test, confirm alarm at the setpoint, check the sensor expiry on the label |
| Ladder | Cracked rail, loose rivet, worn foot: visible only if someone looks | Full visual before first use each shift, and again after anything falls on it or it falls |
| Harness, lanyard, and anchor connector | Webbing cut by an edge, stitching pulled, snap hook gate sprung | Full-length webbing and hardware inspection every time it is put on |
| Sling, chain, or lifting rigging | Broken wires, stretched links, illegible rated tag | Inspect each day before use, and remove from service on any damage finding |
| Cord set with GFCI protection | The device protects nothing when the internal element has failed, and the tool still runs | Press test, confirm trip, reset, confirm power returns |
| Tight-fitting respirator | A seal gap you cannot feel is a seal gap you are breathing through | User seal check at every donning, positive and negative |
| Pressure or vacuum gauge used to certify a result | Drifts off zero, and the number still looks like a number | Confirm zero at ambient before connecting |
The specific instructions matter more than the list. "Check the tester" means nothing. Proving the tester on a known live source, using it on the target, and proving it again on the known live source is a defined sequence with a defined failure detection: if the tester passes the first proof, reads dead on the target, and then fails the second proof, the target is not confirmed dead and the tester is out of service. A tech who only proves before, and whose tester dies during the test, walks away with a false dead reading and no way to know.
Two regulatory triggers sit inside that table and are worth stating as instructions rather than footnotes. Before test equipment is used on any shift, 29 CFR 1910.334(c)(2) requires that the instrument and all associated test leads, cables, probes, and connectors be visually inspected for external defects and damage, and any item that is damaged or defective is removed from service until it has been repaired. Each time a tight-fitting respirator is put on, 29 CFR 1910.134(g)(1)(ii) requires the wearer to perform a user seal check, and a facepiece that will not seal is not worn into the atmosphere it was selected for.
The items people expect on the list and why they are not
Leaving items off is as deliberate as putting them on, and being able to say why keeps the card short.
- Torque wrench. It absolutely can fail silently and the defect it produces is absolutely undetectable at the time, so it passes both gates on consequence. It comes off the every-use list because there is no field check that proves it: verifying a torque wrench needs a calibration fixture, not a shop-floor gesture. It moves to a scheduled verification interval instead, and the pre-use step reduces to confirming the setting was returned to the low end of its range at storage. Putting it on the every-use card gives techs a check they cannot actually perform, and a card with one impossible item on it teaches everyone that the card is theatre.
- Hand tools generally. They fail loudly. A slipping wrench is felt immediately.
- Cordless tool batteries. A dead pack is obvious at the trigger. The battery problem is a logistics problem, not a verification problem.
- A tool's own self-test. The instrument's internal check confirms the instrument thinks it is working. It shares components with the measurement path and it does not test the leads at all, which is where most silent failures actually live. The sibling article on verifying a test instrument works this through; do not substitute a self-test for a known source.
The failure that makes this a safety topic and not a quality one
A test instrument that reads wrong is a safety device that lies, and the lie is directional. Almost every silent failure mode in the table biases toward the reassuring answer: a broken lead reads zero volts, a poisoned sensor reads clean air, a failed GFCI element reads as a working outlet. There is no common failure mode where a dead meter reports a dangerous condition that is not there. That asymmetry is why "it read zero, so we were fine" is not evidence of anything on its own, and why the after-proof is not optional.
The second-order failure is the one that catches whole shops. When one instrument is found bad, the question is not just "replace it." It is: what did this instrument certify since the last time it was proven good? If a tester failed its after-proof on Thursday and it was last proven good Monday morning, every dead check that instrument performed in between is unconfirmed, and every one of those is a place someone worked on a circuit they believed was dead. That is a call-the-tech, re-verify-the-work conversation, not a purchasing one.
Worked example: a seven-tech shop builds its card
A mixed-service shop with seven techs and four trucks had no pre-use standard beyond "check your gear." They built the list in an afternoon.
The candidate pool. They wrote down every item on the trucks that produces a reading, protects a person, or bears a load. That came to 34 items across the four trucks, counting duplicates of the same type as one entry.
Gate 1, silent failure. 21 of the 34 were struck immediately because their failure is obvious in use: drills, saws, hand tools, lights, the compressor. That left 13.
Gate 2, injury or undetectable defect. Of the remaining 13, four were struck because a wrong output is caught at the next step anyway: a tape measure, a level, a stud finder, and a temperature probe used only for customer-facing comfort readings, since a bad reading there produces an argument, not an injury. That left 9 items on the card. Nine of 34 candidates is roughly 26% of the pool, and it fit on one side of a card taped inside each truck door.
The time cost. They timed the full nine-item sequence at the start of a shift on two techs. It ran about 6 minutes on the first day and settled to about 4 minutes once the sequence was familiar, because six of the nine are visual and take seconds. Against an eight hour shift, 4 minutes is around 0.8% of the day. They stopped arguing about whether it was affordable.
Running the rule on a real finding. Three weeks in, a tech's contact tester passed the before-proof, read dead on a disconnect, and then failed the after-proof on the same known live source. Under the rule as written, the target was not confirmed dead, so he stopped, treated the conductor as energized, tagged the tester out, and re-verified with a second tester from another truck. The second tester proved good before and after, and the conductor really was dead. The first tester had a broken lead conductor that opened when the lead was flexed, which is exactly the failure the after-proof exists to catch and exactly the failure a before-proof alone misses.
The back-trace. The tester's last recorded good verification was two days earlier. Two days of that tech's dead checks were unconfirmed. They pulled his tickets for those two days, found three jobs where a dead check had been the basis for working on a circuit, and had him confirm at the next visit that those circuits had genuinely been isolated, which they had. Uncomfortable, cheap, and the only version of that conversation that is not a guess.
What changes the list
Three conditions genuinely move an item on or off, and none of them are convenience.
- The consequence class of the work changes. A shop that starts taking commercial work with higher available fault energy has not changed its instruments, but the cost of a wrong reading went up, and items that were borderline on gate 2 move onto the card.
- The item gains or loses a self-proving feature. Some instruments cannot indicate a blown fuse or an open lead at all, which makes the external proof the only detection available. An item that genuinely detects and annunciates its own lead continuity changes what the before and after proof is buying, though it does not remove the need to prove on a known source.
- The item becomes shared or borrowed. An instrument that lives with one tech has a known history. The same instrument pulled from a shared crib, or borrowed from another trade on site, has an unknown one, and the verification is doing more work because it is the only thing standing between you and someone else's damage.
Reduce the list for none of these: a slow day, a small job, a residential rather than commercial site, or a tech's seniority. The senior tech's tester fails the same way.
References
- OSHA 29 CFR 1910.334(c)(2), visual inspection of test instruments, leads, cables, probes, and connectors before use on any shift
- OSHA 29 CFR 1910.134(g)(1)(ii), user seal check each time a tight-fitting respirator is donned
- OSHA 29 CFR 1910.23(b)(9), ladders inspected before initial use in each work shift for visible defects
- OSHA 29 CFR 1910.184(d), slings and their fastenings and attachments inspected each day before use, with damaged slings removed from service
- See related: How to Verify a Test Instrument Before You Trust It; The Calibration Schedule Worth Keeping; The Damaged Tool That Kept Getting Used