Exact delivered baseline
Products, models, revisions, firmware, software, options, licenses and supplier dependencies.
Home › O-PAS Commissioning, Site Acceptance and Cutover
FAT Release · Site Readiness · SAT · Cutover · Handover
A practical guide for owners, EPCs and system integrators transferring an O-PAS multi-vendor system from FAT through site installation, commissioning, site acceptance, cutover, stabilization and lifecycle handover.
The short answer
Commissioning an O-PAS multi-vendor system requires a controlled transfer of the accepted FAT baseline into the installed site architecture, followed by site-specific verification, operational cutover and a documented handover to the owner.
The project must preserve product identities, configurations, applications, interfaces and evidence while accounting for what changes at site: real field equipment, facility services, retained systems, cybersecurity infrastructure, process conditions, operating procedures and support responsibilities. SAT proves the installed system satisfies its site acceptance basis; it does not simply repeat FAT.
01 · Release from FAT
The site team needs a reproducible record of what passed FAT, what changed afterward and what remains to be proven at site.
Products, models, revisions, firmware, software, options, licenses and supplier dependencies.
Settings, identities, certificates, mappings, schemas, interfaces, infrastructure services and backups.
Source, libraries, build inputs, versions, dependencies, deployment artifacts and rollback package.
Requirements traceability, procedures, results, defects, accepted limitations and approval records.
Items deferred to SAT, owners, prerequisites, expected results, dates and commercial consequences.
Approval, impact assessment and regression rules for every change between FAT and site acceptance. Use the configuration management and regression testing guide →
Use the O-PAS FAT and Interoperability Testing Guide and the Integration Environment and Testbed Planning Guide to establish the evidence and baseline entering this stage.
02 · Baseline transfer
Shipping, staging, installation and site configuration can change the tested system. Record each transfer so the project knows whether a result still applies.
The evidence rule
A FAT result remains usable only when the site team can show that the relevant products, versions, configurations, applications, interfaces and assumptions remain valid. Changed conditions require an explicit impact decision and appropriate regression testing.
03 · Site readiness
Site acceptance depends on plant infrastructure, construction completion, field readiness, cybersecurity services, operating procedures and people. Define these dependencies as entry criteria.
04 · Site acceptance testing
SAT should verify the installed system where site conditions, real equipment, facility infrastructure or contractual requirements could not be demonstrated fully in FAT.
| SAT layer | Question answered | Typical evidence |
|---|---|---|
| Installation verification | Is the approved equipment installed correctly and in the intended architecture? | Identity checks, inspection records, topology, services, configuration comparison and deviations. |
| Field and retained-system interfaces | Do real instruments, actuators, packaged units and retained systems behave as required? | Loop checks, commands, feedback, quality, timing, alarms, loss and restoration results. |
| Site infrastructure | Do identity, security, time, monitoring, backup and support services operate in the facility environment? | Configuration records, access tests, logs, alarms, backup and restore demonstrations. |
| Functional operation | Does the installed system execute required control, sequence, interlock, alarm and operator functions? | Approved procedures, expected results, witnessed behavior, trends and defect records. |
| Failure and recovery | Does the site system respond and recover within required bounds? | Loss, restart, failover, degraded operation, resynchronization and recovery evidence. |
| Operational readiness | Can the owner operate, support and change the system safely? | Procedures, training, access, diagnostics, spares, support and handover readiness records. |
Site testing should execute an approved acceptance basis. New integration problems follow the defect, correction and regression process; they should not be resolved through undocumented site changes.
Use the Interface Definition and Boundary Management Guide →05 · Commissioning sequence
The exact sequence follows the facility and project risk, but each stage should have entry criteria, responsible parties, expected evidence and a hold point before higher-consequence activity begins.
Verify delivered identities, physical installation, site services, configuration, approved changes and recovery copies.
Apply controlled startup procedures, confirm health, identity, time, monitoring, diagnostics and expected local behavior.
Verify site endpoints, information exchange, commands, states, access, loss behavior and restoration.
Confirm instrument, I/O, actuator, packaged-equipment and retained-system paths from source through operator response.
Confirm approved applications, libraries, dependencies, versions, execution, alarms, backup, restore and rollback.
Demonstrate control, sequences, interlocks, operator functions, abnormal scenarios, performance and recovery.
Verify procedures, training, access, support, spares, cybersecurity operations, escalation and acceptance authority.
Approve the production baseline, open-item position, rollback basis, operating window and decision rights.
06 · Cutover control
The plan should connect technical steps to process safety, production, personnel, communications, decision authority and a time-bounded fallback position.
| Cutover control | Required definition |
|---|---|
| Entry criteria | System baseline, tests, staffing, process state, open defects, backups, spares and approvals required to begin. |
| Step ownership | Named performer, checker, communications lead and decision authority for every critical action. |
| Hold points | Conditions that require verification and approval before the next irreversible or higher-consequence step. |
| Success criteria | Observable system and process conditions required to continue and declare the transfer successful. |
| Rollback triggers | Technical, process, safety, schedule and resource conditions requiring fallback or shutdown. |
| Communications | Control-room, field, project, supplier and management channels, status cadence and escalation paths. |
For brownfield coexistence, migration boundaries and sequencing, use the Open Process Automation Migration Strategy Guide.
07 · Rollback readiness
Rollback is not a sentence in the method. It is a prepared technical and operating path with defined triggers, retained assets, verified recovery artifacts and people authorized to act.
08 · Stabilization
Define a monitored stabilization period in which the owner, integrator and suppliers confirm performance, close defects and prove the support model under real operating conditions.
Availability, resource use, communications, alarms, logs, synchronization, failures and recovery behavior.
Loops, sequences, interlocks, operator response, application behavior and process constraints.
Severity, ownership, workarounds, corrections, regression, evidence and acceptance disposition.
Accounts, certificates, monitoring, vulnerabilities, remote access, patching and incident escalation.
Procedures, training, diagnostics, backup, restore, supplier support and shift-to-shift knowledge transfer.
Required duration, performance, defect status, documentation, support readiness and owner approval.
09 · Owner handover
Handover should leave the owner with the accepted system baseline, the rights and access to use it, and the competence and support model required for day-two operation.
The handover baseline becomes the starting point for future patches, substitutions, application changes, recovery and component replacement. Assign its lifecycle custodian before project demobilization.
Use the O-PAS System Management and Lifecycle Operations Guide → Define the multi-vendor operations and support model →10 · Responsibility and contract
The commissioning plan should name accountability for the integrated system, process safety, acceptance, supplier correction, cutover and owner handover.
| Decision or activity | Required accountable position |
|---|---|
| FAT baseline release | Who approves shipment and the position on open or deferred items? |
| Site readiness | Who confirms construction, field, infrastructure, operations and supplier prerequisites? |
| Integrated commissioning | Who coordinates components, applications, interfaces, defects and multi-vendor correction? |
| Process safety | Who controls permits, isolations, safe operating state and authorization for process interaction? |
| SAT acceptance | Who witnesses, approves deviations and accepts the installed system evidence? |
| Cutover decision | Who authorizes start, hold, continuation, rollback and return to operation? |
| Defect correction | Who diagnoses, coordinates suppliers, approves changes, pays and requires regression? |
| Lifecycle handover | Who confirms deliverables, access, competency, support and custody of the accepted baseline? |
Use the O-PAS Responsibility Matrix and the O-PAS Procurement Specification Checklist to make these positions contractual before execution.
11 · Connected guidance
Stabilize the multi-vendor baseline and correction process before formal acceptance.
FATBuild the approved evidence package that releases the system toward site.
CutoverDefine coexistence, retained-system boundaries, sequencing and fallback.
SecurityCarry identity, access, monitoring, patching and incident ownership into operation.
ApplicationsTransfer source, dependencies, deployment, backup, restore and owner control assets.
DeliveryCoordinate architecture, suppliers, commissioning, correction and lifecycle handover.
Frequently asked questions
FAT verifies the integrated candidate in the approved factory or integration environment. SAT verifies the installed system where real site equipment, infrastructure, retained systems, process conditions and operating responsibilities matter. SAT should close defined site-specific requirements rather than repeat every FAT test.
The project needs the exact accepted product and configuration baseline, application source and deployment packages, interface records, backups, test evidence, defects, deviations, deferred tests, dependencies and change history.
One named party should be accountable for integrated automation commissioning and supplier coordination. In many projects that is the OPA system integrator within the EPC delivery model, while the owner retains process-safety and acceptance authority.
When the approved baseline is installed, required commissioning and SAT work is complete, blocking defects are closed, operations and support are ready, rollback remains executable, and the named authority confirms all entry criteria for the operating window.
It should define triggers, decision authority, time limits, the retained or recoverable prior state, configuration and application backups, technical restoration steps, operating actions, communications and the tests required before returning the facility to service.
Commissioning is complete when the contractual functional and site evidence is accepted, stabilization exit criteria are met, defects are dispositioned, owner deliverables and access are complete, operations can support the system, and custody of the lifecycle baseline is formally transferred.
CSI supports FAT release, site baseline verification, interface and application commissioning, SAT planning and execution, multi-vendor defect resolution, cutover and rollback planning, stabilization, acceptance evidence and owner lifecycle handover.
Before the operating window becomes the integration plan
CSI can review the FAT release, site prerequisites, acceptance plan, supplier responsibilities and cutover basis, then identify the gaps that need to close before startup.
O-PAS™ and Open Process Automation™ are trademarks of The Open Group. CSI is an independent commercial licensee of the O-PAS Standard. This guide is a project-planning aid; the applicable contract, owner standards, site procedures, current O-PAS Standard and current certification records govern the delivered system.