Home › O-PAS Commissioning, Site Acceptance and Cutover

FAT Release · Site Readiness · SAT · Cutover · Handover

O-PAS commissioning and site acceptance Move the accepted design into safe operation

A practical guide for owners, EPCs and system integrators transferring an O-PAS multi-vendor system from FAT through site installation, commissioning, site acceptance, cutover, stabilization and lifecycle handover.

The short answer

Commissioning an O-PAS multi-vendor system requires a controlled transfer of the accepted FAT baseline into the installed site architecture, followed by site-specific verification, operational cutover and a documented handover to the owner.

The project must preserve product identities, configurations, applications, interfaces and evidence while accounting for what changes at site: real field equipment, facility services, retained systems, cybersecurity infrastructure, process conditions, operating procedures and support responsibilities. SAT proves the installed system satisfies its site acceptance basis; it does not simply repeat FAT.

01 · Release from FAT

Move an approved baseline, not a collection of equipment

The site team needs a reproducible record of what passed FAT, what changed afterward and what remains to be proven at site.

System identity

Exact delivered baseline

Products, models, revisions, firmware, software, options, licenses and supplier dependencies.

Configuration

Accepted system state

Settings, identities, certificates, mappings, schemas, interfaces, infrastructure services and backups.

Applications

Controlled deployment package

Source, libraries, build inputs, versions, dependencies, deployment artifacts and rollback package.

Evidence

FAT results and deviations

Requirements traceability, procedures, results, defects, accepted limitations and approval records.

Open work

Named site verification

Items deferred to SAT, owners, prerequisites, expected results, dates and commercial consequences.

Release stop condition: equipment can ship, but the project cannot recreate the FAT baseline or identify which site tests close the requirements that FAT did not prove.

Use the O-PAS FAT and Interoperability Testing Guide and the Integration Environment and Testbed Planning Guide to establish the evidence and baseline entering this stage.

02 · Baseline transfer

Verify custody from integration environment to installed system

Shipping, staging, installation and site configuration can change the tested system. Record each transfer so the project knows whether a result still applies.

FreezeApprove the FAT release baseline and open-item position.
PackageProtect equipment, software, configuration, applications and records.
TransferTrack custody, shipping, storage, access and intervening changes.
InstallVerify identity, condition, topology, services and configuration.
ReconcileCompare site baseline with FAT and assign required regression.

The evidence rule

A FAT result remains usable only when the site team can show that the relevant products, versions, configurations, applications, interfaces and assumptions remain valid. Changed conditions require an explicit impact decision and appropriate regression testing.

03 · Site readiness

The automation system cannot commission into an unready facility

Site acceptance depends on plant infrastructure, construction completion, field readiness, cybersecurity services, operating procedures and people. Define these dependencies as entry criteria.

Installation

Physical completion

  • Equipment installed and inspected
  • Power, grounding, cooling and environmental conditions
  • Network pathways and physical segregation
  • Panels, cabinets, labeling and access
  • Construction punch items classified
Field

Signals and equipment

  • Instrument and actuator installation
  • I/O checks and loop readiness
  • Packaged-unit interfaces
  • Retained control-system connections
  • Safe methods for stimulus and movement
Infrastructure

Site services

  • Identity, naming and time services
  • Certificate and credential readiness
  • Monitoring, logging and backup
  • Remote support and supplier access
  • Approved software and update process
Operations

People and procedures

  • Commissioning roles and shift coverage
  • Operating, alarm and response procedures
  • Permit, isolation and safety controls
  • Training and competency status
  • Escalation and decision authority
Process

Operating conditions

  • Utilities and process availability
  • Safe test windows and constraints
  • Representative loads and materials
  • Environmental and production limits
  • Fallback operating arrangements
Commercial

Supplier support

  • Required suppliers mobilized
  • Correction and retest obligations active
  • Spare and replacement access
  • Open defects dispositioned
  • Witness and acceptance availability

04 · Site acceptance testing

SAT closes the site-specific acceptance basis

SAT should verify the installed system where site conditions, real equipment, facility infrastructure or contractual requirements could not be demonstrated fully in FAT.

SAT layerQuestion answeredTypical evidence
Installation verificationIs the approved equipment installed correctly and in the intended architecture?Identity checks, inspection records, topology, services, configuration comparison and deviations.
Field and retained-system interfacesDo real instruments, actuators, packaged units and retained systems behave as required?Loop checks, commands, feedback, quality, timing, alarms, loss and restoration results.
Site infrastructureDo identity, security, time, monitoring, backup and support services operate in the facility environment?Configuration records, access tests, logs, alarms, backup and restore demonstrations.
Functional operationDoes the installed system execute required control, sequence, interlock, alarm and operator functions?Approved procedures, expected results, witnessed behavior, trends and defect records.
Failure and recoveryDoes the site system respond and recover within required bounds?Loss, restart, failover, degraded operation, resynchronization and recovery evidence.
Operational readinessCan the owner operate, support and change the system safely?Procedures, training, access, diagnostics, spares, support and handover readiness records.

Do not turn SAT into uncontrolled discovery

Site testing should execute an approved acceptance basis. New integration problems follow the defect, correction and regression process; they should not be resolved through undocumented site changes.

Use the Interface Definition and Boundary Management Guide →

05 · Commissioning sequence

Move from installed components to an operable system in controlled stages

The exact sequence follows the facility and project risk, but each stage should have entry criteria, responsible parties, expected evidence and a hold point before higher-consequence activity begins.

Confirm installation and baseline

Verify delivered identities, physical installation, site services, configuration, approved changes and recovery copies.

Energize infrastructure and components

Apply controlled startup procedures, confirm health, identity, time, monitoring, diagnostics and expected local behavior.

Establish supplier and system boundaries

Verify site endpoints, information exchange, commands, states, access, loss behavior and restoration.

Complete field and loop verification

Confirm instrument, I/O, actuator, packaged-equipment and retained-system paths from source through operator response.

Deploy and verify applications

Confirm approved applications, libraries, dependencies, versions, execution, alarms, backup, restore and rollback.

Execute integrated functional tests

Demonstrate control, sequences, interlocks, operator functions, abnormal scenarios, performance and recovery.

Confirm operational readiness

Verify procedures, training, access, support, spares, cybersecurity operations, escalation and acceptance authority.

Authorize cutover

Approve the production baseline, open-item position, rollback basis, operating window and decision rights.

06 · Cutover control

Cutover is a governed operating event

The plan should connect technical steps to process safety, production, personnel, communications, decision authority and a time-bounded fallback position.

AuthorizeConfirm entry criteria, approvals and operating window.
SecureEstablish safe plant state, permits and isolations.
TransferExecute approved equipment, interface and application steps.
VerifyCheck functions, protection, alarms, visibility and control.
DecideProceed, hold or roll back at defined decision points.
StabilizeMonitor performance and close immediate defects.
Cutover controlRequired definition
Entry criteriaSystem baseline, tests, staffing, process state, open defects, backups, spares and approvals required to begin.
Step ownershipNamed performer, checker, communications lead and decision authority for every critical action.
Hold pointsConditions that require verification and approval before the next irreversible or higher-consequence step.
Success criteriaObservable system and process conditions required to continue and declare the transfer successful.
Rollback triggersTechnical, process, safety, schedule and resource conditions requiring fallback or shutdown.
CommunicationsControl-room, field, project, supplier and management channels, status cadence and escalation paths.

For brownfield coexistence, migration boundaries and sequencing, use the Open Process Automation Migration Strategy Guide.

07 · Rollback readiness

A rollback plan must be executable under time pressure

Rollback is not a sentence in the method. It is a prepared technical and operating path with defined triggers, retained assets, verified recovery artifacts and people authorized to act.

Trigger

Know when to stop

  • Safety or protection criteria
  • Loss of required control or visibility
  • Unrecoverable interface or application failure
  • Exceeded outage or stabilization window
  • Unavailable correction resources
Technical path

Preserve a restorable state

  • Approved pre-cutover baseline
  • Configuration and application backups
  • Retained equipment and connections
  • Credentials, licenses and dependencies
  • Verified restore and restart procedure
Operating path

Return the facility safely

  • Required plant state and isolations
  • Manual or alternate control arrangements
  • Operator and field actions
  • Alarm and communications provisions
  • Production and quality disposition
Authority

Make the decision explicit

  • Named decision owner
  • Required technical advice
  • Time limits and hold points
  • Notification and escalation
  • Post-rollback evidence and review

08 · Stabilization

Startup success is not the end of acceptance

Define a monitored stabilization period in which the owner, integrator and suppliers confirm performance, close defects and prove the support model under real operating conditions.

System health

Watch the assembled system

Availability, resource use, communications, alarms, logs, synchronization, failures and recovery behavior.

Control performance

Confirm operating outcomes

Loops, sequences, interlocks, operator response, application behavior and process constraints.

Defects

Close the real operating issues

Severity, ownership, workarounds, corrections, regression, evidence and acceptance disposition.

Cybersecurity

Move into operating governance

Accounts, certificates, monitoring, vulnerabilities, remote access, patching and incident escalation.

Operations

Verify owner capability

Procedures, training, diagnostics, backup, restore, supplier support and shift-to-shift knowledge transfer.

Exit criteria

Define stable operation

Required duration, performance, defect status, documentation, support readiness and owner approval.

09 · Owner handover

Transfer the capability to operate and change the system

Handover should leave the owner with the accepted system baseline, the rights and access to use it, and the competence and support model required for day-two operation.

Architecture

As-built system records

  • Architecture and component-role mapping
  • Interface register and supplier boundaries
  • Product and version inventory
  • Network and infrastructure records
  • Approved deviations and dependencies
Applications

Owner control assets

  • Source, libraries and documentation
  • Build and deployment packages
  • Version, backup and restore procedures
  • Dependencies and license rights
  • Accepted application test records
Evidence

Acceptance and recovery records

  • FAT, SAT and commissioning results
  • Defects, deviations and closeout
  • Cybersecurity and recovery evidence
  • Requirements traceability
  • Formal acceptance approvals
Operations

Lifecycle capability

  • Access, accounts and credential custody
  • Monitoring and diagnostic procedures
  • Patching and vulnerability workflow
  • Supplier support and escalation
  • Training and competency records

Preserve the accepted architecture after startup

The handover baseline becomes the starting point for future patches, substitutions, application changes, recovery and component replacement. Assign its lifecycle custodian before project demobilization.

Use the O-PAS System Management and Lifecycle Operations Guide → Define the multi-vendor operations and support model →

10 · Responsibility and contract

Assign site decisions before the commissioning window opens

The commissioning plan should name accountability for the integrated system, process safety, acceptance, supplier correction, cutover and owner handover.

Decision or activityRequired accountable position
FAT baseline releaseWho approves shipment and the position on open or deferred items?
Site readinessWho confirms construction, field, infrastructure, operations and supplier prerequisites?
Integrated commissioningWho coordinates components, applications, interfaces, defects and multi-vendor correction?
Process safetyWho controls permits, isolations, safe operating state and authorization for process interaction?
SAT acceptanceWho witnesses, approves deviations and accepts the installed system evidence?
Cutover decisionWho authorizes start, hold, continuation, rollback and return to operation?
Defect correctionWho diagnoses, coordinates suppliers, approves changes, pays and requires regression?
Lifecycle handoverWho confirms deliverables, access, competency, support and custody of the accepted baseline?

Use the O-PAS Responsibility Matrix and the O-PAS Procurement Specification Checklist to make these positions contractual before execution.

Frequently asked questions

O-PAS commissioning and cutover questions

How is SAT different from FAT on an O-PAS project?

FAT verifies the integrated candidate in the approved factory or integration environment. SAT verifies the installed system where real site equipment, infrastructure, retained systems, process conditions and operating responsibilities matter. SAT should close defined site-specific requirements rather than repeat every FAT test.

What must transfer from FAT to site?

The project needs the exact accepted product and configuration baseline, application source and deployment packages, interface records, backups, test evidence, defects, deviations, deferred tests, dependencies and change history.

Who should lead multi-vendor commissioning?

One named party should be accountable for integrated automation commissioning and supplier coordination. In many projects that is the OPA system integrator within the EPC delivery model, while the owner retains process-safety and acceptance authority.

When is an O-PAS system ready for cutover?

When the approved baseline is installed, required commissioning and SAT work is complete, blocking defects are closed, operations and support are ready, rollback remains executable, and the named authority confirms all entry criteria for the operating window.

What should an O-PAS rollback plan include?

It should define triggers, decision authority, time limits, the retained or recoverable prior state, configuration and application backups, technical restoration steps, operating actions, communications and the tests required before returning the facility to service.

When is commissioning complete?

Commissioning is complete when the contractual functional and site evidence is accepted, stabilization exit criteria are met, defects are dispositioned, owner deliverables and access are complete, operations can support the system, and custody of the lifecycle baseline is formally transferred.

How does CSI support O-PAS commissioning?

CSI supports FAT release, site baseline verification, interface and application commissioning, SAT planning and execution, multi-vendor defect resolution, cutover and rollback planning, stabilization, acceptance evidence and owner lifecycle handover.

Before the operating window becomes the integration plan

Make commissioning, SAT and cutover executable

CSI can review the FAT release, site prerequisites, acceptance plan, supplier responsibilities and cutover basis, then identify the gaps that need to close before startup.

O-PAS™ and Open Process Automation™ are trademarks of The Open Group. CSI is an independent commercial licensee of the O-PAS Standard. This guide is a project-planning aid; the applicable contract, owner standards, site procedures, current O-PAS Standard and current certification records govern the delivered system.