Offshore wind operators are increasingly being pitched software that promises to cover maintenance, permits and risk assessment in one package. In practice, a CMMS, a control of work system and a permit to work are three different things doing three different jobs, and treating them as interchangeable is where gaps open up. The one that shows up most often in practice: a CMMS work order gets approved through its own sign-off routing, and someone treats that approval as sufficient authorisation to break into high-voltage switchgear in a nacelle or offshore substation. It isn't, and conflating the two is a genuine safety gap, not just a terminology quibble.

What separates control of work, permit to work and a CMMS

A CMMS records what maintenance is due, on which asset, and what parts or resources it needs. Control of work is the governance layer that decides whether that work can happen safely right now — checking competency, hazards, and conflicting activity elsewhere on the asset. A permit to work is the specific authorisation document that control of work produces, tracks, and closes out.

Those three sentences hold up as a working definition. The rest of this is about where each one actually does its job in an offshore wind operating model, because the boundary matters most at the points where people assume one system covers what another is responsible for.

The CMMS holds the asset and maintenance record

A computerised maintenance management system is built around the asset hierarchy — turbine, tower section, nacelle, transition piece, array cable, offshore substation — and the maintenance regime attached to each one. It tells you what's due, what the last inspection found, what spares are on the vessel or in the onshore store, and what the scheduled interval says should happen next. For planned preventative maintenance on safety-critical elements, that record matters for demonstrating the maintenance programme has actually been followed, and we've written elsewhere about what OEUK's KPI guide means for tracking that kind of backlog.

What a CMMS generally isn't built to do is check whether it's safe to start the work today. Its approval workflow answers "is this job scheduled and resourced," not "is the equipment isolated, is the technician competent for HV work, and is someone else working on the adjacent string at the same time." Vendors sometimes describe a permit module bolted onto a CMMS as solving this. It's worth asking, specifically, whether that module can conflict-check a proposed job against every other live activity on the asset, not just log that a permit exists.

Control of work governs whether the job can happen safely right now

This is the layer that checks who's authorised to do what, what else is happening on the asset, and what the hazards are before anyone touches equipment. In offshore wind, authorisation for HV work typically runs through a Senior Authorised Person and Authorised Person structure under the Electricity at Work Regulations 1989 — a scheme, not a job title anyone can self-assign, and control of work software should be able to enforce who currently holds that authorisation rather than relying on someone remembering to check a spreadsheet.

Simultaneous operations is where control of work earns its keep on a wind farm. Multiple contractors on the same array string, a vessel alongside a turbine while cable work is underway nearby, a crew inside a nacelle while another team is at the base of the same tower — none of that is visible from a maintenance calendar. It needs a system that actively checks proposed permits against each other before they're issued, which is the same problem we've set out in more detail in building a permit interaction matrix.

The permit is the document control of work produces, not a replacement for it

A permit to work is an output, not a system in itself. It's the record of a specific authorisation, tied to a specific scope, valid for a specific window, with named people responsible for issuing and accepting it. An isolation certificate is a related but distinct artefact — it records the points of isolation, the proving-dead and earthing steps, and who verified them, and it typically has to be in place and valid before the associated permit can be issued at all. Confusing an isolation certificate with the permit it supports, or assuming a signed CMMS work order stands in for either, is a common source of ambiguity, and we've covered the isolation side of this in more depth in isolation management: the SIMOPS blind spot.

Mapping common offshore wind questions to the right system

A few questions that come up repeatedly on wind assets, and which system actually answers them:

- **Who can authorise entry to a nacelle under HV isolation?** Control of work, through the Authorised Person hierarchy — not whoever approved the CMMS work order.
- **What stops two contractors working the same array string at the same time?** Control of work's simultaneous operations check, not the maintenance scheduling calendar.
- **How is a permit suspended if the weather window closes mid-task?** Control of work's suspension workflow, recorded against the same permit rather than closed and reopened as something new.
- **Who confirms an isolation is still valid after a shift or crew change offshore?** The isolation register and handover process within control of work, not a note left in the maintenance log.

If a vendor's answer to any of these routes back through the CMMS rather than a dedicated risk-governance workflow, that's worth pressing on before it becomes a live-asset problem.

Where the systems need to connect

None of this means an operator should run three unconnected systems and reconcile them by hand. The asset ID in the CMMS needs to match the asset referenced on the permit; the work order reference needs to appear on the permit so closure in one system updates the other; and isolation records need to be visible to whoever is planning the next job on that asset, not buried in a separate log. That's an integration problem, typically solved through APIs rather than by picking a single system to do everything — a point we go into further in digital control of work: connecting the system.

If you're mapping your current tool stack against these boundaries — CMMS, control of work, and the permits and isolation certificates they should be producing between them — we can work through where the gaps sit before committing to a procurement decision. Our buyer's guide to permit to work software is a reasonable starting point for that conversation, even outside offshore wind specifically.

Frequently Asked Questions

What's the actual difference between a CMMS, control of work and a permit to work?
A CMMS records what maintenance is due on an asset and what resources it needs. Control of work is the governance layer that checks whether that work can safely happen right now, looking at competency, hazards and conflicting activity. A permit to work is the specific authorisation document that control of work produces, tracks and closes out.
Is it okay to treat a signed-off CMMS work order as authorisation to start HV work?
No. A CMMS approval just confirms the job is scheduled and resourced, not that it's safe to start — it doesn't check isolation, technician competency for HV work, or conflicting activity nearby. Treating it as sufficient authorisation to break into high-voltage switchgear is a genuine safety gap, not just a wording issue.
Who is actually allowed to authorise entry to a nacelle under HV isolation?
That authorisation runs through control of work, specifically the Senior Authorised Person and Authorised Person structure under the Electricity at Work Regulations 1989. It's a formal scheme people are appointed into, not something granted just because someone approved a CMMS work order.
What stops two contractors from working on the same array string at the same time?
That's handled by control of work's simultaneous operations (SIMOPS) check, which actively checks proposed permits against each other before they're issued — not the maintenance scheduling calendar in a CMMS.
Is an isolation certificate the same thing as a permit to work?
No, they're related but distinct. The isolation certificate records the isolation points, proving-dead and earthing steps and who verified them, and it generally has to be valid before the associated permit can even be issued.
Does this mean operators need three completely separate, disconnected systems?
No — the CMMS, control of work and permits should still be connected, typically via APIs, so the asset ID and work order reference match across systems and isolation records are visible to whoever plans the next job. It's an integration problem, not a case of picking one system to do everything.
← Back to Blog