Blog

2026.09.02

Production Line Modification: Brownfield Change Control

Production Line Modification: Brownfield Change Control

A production line modification is difficult for reasons that go far beyond choosing a new PLC or robot. The project must reconcile the machine that is actually running with outdated drawings, legacy interfaces, blurred ownership boundaries, safety functions, a short shutdown window and a credible route back to production. A strong purchase specification does not merely order “modification work.” It defines evidence-based decision gates from the as-is survey and URS through risk assessment, offline verification, cutover, FAT/SAT, restart and rollback. This guide shows factory owners in Thailand and Southeast Asia how to procure and govern a brownfield change while protecting production, quality and safety.

This article is general procurement and project-governance guidance. It is not a machine design, live-work procedure, completed risk assessment, legal opinion or certificate of conformity. Confirm the applicable laws, standards, editions, customer rules and Type-C machinery standards with competent professionals for the machine, installation country, destination market and contract.

A production line modification is a brownfield change, not a component swap

On a greenfield line, requirements, electrical drawings, I/O, networks and installation conditions can be designed from a relatively clean baseline. A brownfield line has the opposite starting point. Years of shop-floor changes, terminal alterations absent from drawings, operator workarounds, obsolete communication devices, scarce spares and undocumented interlocks may coexist. A quotation that says “PLC modification — one lot” or “machine wiring — one lot” does not make scope, evidence or liability comparable.

Manage three classes of risk separately:

  1. Operational risk: the outage overruns, the process does not return to its good-product window, or upstream and downstream machines fail to coordinate.
  2. Technical risk: source files are missing, communication behavior is unknown, or replacement hardware is incompatible with existing signals.
  3. Safety risk: the effect on guards, emergency stops, restart prevention and safety-related control is overlooked.

If all three are left for engineers to “make it work on site,” the shutdown becomes the first integration test. A shutdown is not development time. It is the controlled installation and acceptance of changes that have already been designed and tested as far as practicable.

Decision gateWhat is approvedDo not proceed whenTypical evidence
G0 PurposeCapacity, quality, maintenance and safety objectivesKPI or equipment boundary is ambiguousBusiness case, constraints, asset list
G1 As-is freezeVerified current-state baselineCritical drawing-to-machine gaps remain unknownSurvey log, photos, backups, I/O checks
G2 Design approvalURS, interfaces and safety strategyOpen design choices are deferred to shutdownTraceability matrix, drawings, risk assessment
G3 Offline readinessLogic, HMI, communications and fault casesCritical scenarios remain untestedTest records, issues, residual-risk list
G4 Cutover authorizationPeople, parts, sequence, recovery and timeNo measurable rollback trigger existsRunbook, rollback kit, escalation map
G5 HandoverSAT, capability, quality, safety and documentationMajor defects or records remain openSAT report, training, as-built set, backups

Step 1: Turn the as-is line into evidence

The first deliverable in a factory equipment retrofit is not the new design. It is the current-state baseline. A site walkdown must capture more than nameplates and cabinet photographs. The team needs to establish which signals are exchanged in each state, what makes the line stop, who can recover it and which informal operating practices keep it productive. The survey pack should therefore combine an equipment register with operating scenarios.

Survey six boundaries

  • Physical: machines, conveyors, tooling, guards, operator stations and transfer points to adjacent equipment.
  • Electrical: supply point, available power, protection, bonding, terminals, spare I/O and cable routes.
  • Control: PLC, HMI, drives, robots, remote I/O, recipes, time synchronization and alarms.
  • Communication: protocol, addresses, scan or update behavior, data types, heartbeat, failure state and reconnection.
  • Safety: hazards, guards, interlocks, emergency stop, stopping behavior, stored energy and restart conditions.
  • Operations: product variants, changeover, rework, cleaning, maintenance, power recovery, modes and permissions.

A successful PLC upload does not complete the survey. A program without comments, setpoints stored only in the HMI, parameters inside drives, robot-side handshakes or inspection-system decision rules may still be missing. Every baseline backup should record the extraction time, engineering-tool version, asset identifier, checksum and whether restoration was tested. For the narrower decision about controller replacement, see our guide to PLC replacement and retrofit in Thailand. The present article concentrates on integration across several assets.

Record unknowns instead of hiding them

In an older factory, the absence of a correct drawing or source file is itself a material finding. Do not fill the gap with an assumption. Classify it as unverified, requiring a field test, awaiting an OEM answer, or only inspectable during shutdown. Assign an owner and due date. Any item that can only be checked while stopped must appear at the beginning of the cutover runbook with a decision branch. Unknowns then become managed exposure rather than a surprise.

Production Line Modification: Brownfield Change Control - figure 1

Step 2: Freeze the URS and interface agreements first

A User Requirements Specification is not a list of preferred part numbers. It states what the line must do, under which conditions, at what quality and how acceptance will be demonstrated. “Automate the production line” is too broad. State the product families, baseline capability, allowed downtime, behavior under abnormal conditions, required operator intervention, quality data and post-change performance verification.

Write requirements that can be tested

Words such as “easy,” “fast” and “safe” can be agreed during sales discussions but cannot be accepted objectively. Use a measurable condition and pass/fail method. At the same time, never invent a target when site data is missing. Make baseline measurement a G1 prerequisite and let the approved result populate the final acceptance value.

RequirementWeak wordingVerifiable wording
CapabilityMake the cycle fasterMeet the approved baseline or target for named products under a defined measurement method
QualityReduce defectsDefine defect modes, inspection method, data retention and action on deviation
RecoveryRecover quicklyTest state transitions and restart authority after power, network and emergency stops
MaintainabilityMake maintenance easierAccept diagnostics, replacement procedure, backups, training and spares
SafetyAdd a safety circuitDerive safety functions from risk assessment and require design and validation evidence

Build an interface control matrix

When the upstream station cannot release a workpiece, the downstream station is full, or an inspection device loses communication, the matrix must state which asset does what. As a minimum, capture signal name, meaning, sender, receiver, normal logic, timeout, initial value, fault state, recovery rule, test method and owner. A tag-only I/O list omits time and state behavior.

Legacy sequences may rely accidentally on an old PLC scan or network delay. Offline verification must cover not only Boolean values but sequence, pulse width, duplicates, missing messages, retries and power-up defaults. If the project includes a new cabinet, manage its electrical deliverables under a separate work package such as those described in control panel design for Thailand factories. Keep the panel boundary distinct from line-level integration acceptance.

Step 3: Reassess risk from the change delta

“The machine was already assessed” is not a sufficient conclusion. A change in speed, reach, conveying direction, robot tooling, guard opening, operator position, manual mode, recovery sequence or control architecture can change exposure and avoidance. ISO 12100:2010 provides general terminology, principles and a methodology for hazard identification, risk estimation and evaluation, risk reduction, documentation and verification across the machine life cycle. ISO says the 2010 edition remains current after its 2022 confirmation, while a successor is under development. State the adopted edition in the contract.

Risk reduction should follow the hierarchy of inherently safe design measures, safeguarding and complementary protective measures, and information for use. A conventional PLC software change alone must not be treated as eliminating a mechanical hazard. When safety-related control is required, evidence must link the risk assessment to safety functions, required performance, architecture, diagnostics, common-cause considerations, software, verification and validation.

Do not confuse the roles of the standards

  • ISO 12100:2010 provides general design principles and the risk-assessment and risk-reduction methodology.
  • ISO 13849-1:2023 provides methodology and requirements for designing and integrating safety-related parts of control systems in high-demand and continuous modes. It does not prescribe the safety functions or required PLr for every machine.
  • IEC 62061:2021+A1:2024, consolidated Edition 2.1 covers design, integration and validation of machine safety-related control systems. It does not replace all electrical-shock or physical guarding requirements.
  • IEC 60204-1:2016+A1:2021, consolidated Edition 6.1 applies to electrical, electronic and programmable electronic equipment of machines not portable by hand while working, including coordinated groups of machines. Its scope begins at the connection of the supply to the machine electrical equipment.
  • ISO 14119:2024 addresses design and selection of guard-associated interlocking devices and measures to minimize reasonably foreseeable defeat. Processing the stop signal is addressed through standards such as ISO 13849-1 and IEC 62061.
  • ISO 13850:2015 specifies functional requirements and design principles for emergency-stop functions. Its stated exceptions include machines where emergency stop would not reduce risk; an emergency stop is not a substitute for other protective measures.
  • ISO 14118:2017 addresses designed-in means to prevent unexpected start-up from electrical, hydraulic, pneumatic, stored and external energy sources.

A list of standard numbers in a quotation is not conformity evidence. The purchase specification should connect applicability, edition, safety functions, analysis, circuit drawings, component data, software releases, tests and unresolved items. Where a machine-specific Type-C standard, local law or customer rule applies, reconcile those requirements explicitly.

Change control means who changed what, why and what must be retested

After design approval, every change should have an ID, reason, affected assets and documents, software or drawing delta, safety impact, required regression tests, approver and implemented release. A logic change requested through an unrecorded chat breaks the relationship between FAT evidence and the version installed on site. Maintain a read-only pre-change baseline, reviewed release candidate, installed release and final as-built release. Emergency fixes still require subsequent delta review and validation recovery.

Step 4: Fail offline before the shutdown

The purpose of offline verification is not to stage a polished demonstration. It is to move failures out of the outage window. Depending on risk, combine actual PLC and HMI hardware, emulators, simulators, I/O rigs and stubs for peer systems. Perfect reproduction is rarely possible; explicitly identifying what cannot be reproduced is still valuable because it shapes SAT time and rollback criteria.

Test fault and recovery paths, not only normal production

Scenarios should cover start, stop, changeover and dry cycles, plus stuck sensors, blocked workpieces, network loss, timeout, drive fault, emergency stop, open guard, power loss, mid-sequence restart, upstream stop, downstream full and data-storage failure. The question is not only whether an alarm appears. The system must reach a safe state, identify the cause, permit authorized recovery through the intended sequence and avoid unintended restart.

Safety-function validation cannot normally be completed by simulating standard control logic alone. The actual circuit, components, diagnostics, software, machine motion, stopping time and guard position must be addressed using appropriate analysis and tests. ISO 13849-2:2012 is currently published but under revision; it covers validation by analysis and testing of specified safety functions, achieved category and achieved performance level for SRP/CS designed to ISO 13849-1. Specify the adopted edition and any transition rule.

Make FAT an acceptance activity, not a factory tour

Each FAT case needs prerequisites, inputs, actions, expected result, actual result, evidence, pass/fail and deviation ID. If real equipment is unavailable, mark the item as not tested rather than passed, and define its SAT carryover condition. Classify deviations so that everyone understands what must close before shutdown, what may proceed under an approved temporary control and what minor item may close after SAT.

Step 5: Put time, authority and rollback into the cutover plan

Production Line Modification: Brownfield Change Control - figure 2

A cutover plan is more detailed than a contractor schedule. From production-stop authorization through release back to operations, it names who verifies each step, where evidence is recorded and who may authorize the next stage. Even when commissioning support is outsourced, the business decision to resume production should remain with the plant. Appoint a cutover manager and named owners for operations, safety, quality and maintenance.

Have these ready before the line stops

  • The approved release and an identifier that proves it has not been altered.
  • Current backups for PLCs, HMIs, drives, robots, recipes and network devices.
  • Old hardware, adapters, spares, special tools, licenses, engineering laptop and correct cables.
  • Electrical and mechanical drawings, terminals, I/O, network schedule, change delta and risk assessment.
  • Work permits, energy isolation, safe access, shift handover and escalation contacts.
  • A time-stamped sequence, hold points, go/no-go criteria and latest rollback start time.

“Return to the old system” is not a rollback plan. Establish whether removed hardware can physically be reinstalled, old software can be loaded with a working tool and license, terminals and network parameters can be restored, and safety and quality can be verified afterward. Estimate or rehearse the duration. If machining or cable changes are irreversible, define an alternative recovery architecture and bring the management decision forward.

Divide the outage budget into three parts

If the entire window is called “modification time,” installation tends to consume validation and recovery margin. Allocate time separately to: (1) removal, installation, wiring and download; (2) technical tests, SAT and product-quality checks; and (3) corrective work or rollback contingency. At each hold point, use the remaining time to decide formally whether to continue, reduce scope or roll back.

Step 6: Increase load progressively during SAT and restart

Automatic motion after power-up is not project completion. SAT should verify installed condition, I/O, communications, interlocks, safety functions, fault recovery, product variants, capability, quality, data and maintainability against the URS and risk assessment. Before testing, establish a safe condition, permits, authorization and required witnesses.

Stage restart through no-load checks, individual motion, manual or low-risk conditions, inter-machine coordination, test workpieces, restricted production and normal production. Give every stage entry and exit criteria, with a defined route back one level when something fails. Safety validation and product-quality approval are separate lines of authority: passing one never substitutes for the other.

Contract a hypercare period

Some failures appear only across shift change, long runtime, product changeover, restart after planned stop, data accumulation or maintenance intervention. Define a hypercare period with response time, on-site and remote coverage, log collection, daily review, severity classification and final closure criteria. The handover must leave maintainers able to diagnose and recover the integrated line, not merely give them PLC source files. Our article on machine control software development in Thailand provides a useful companion checklist for software deliverables.

Compare quotation structure, not just the grand total

Production line modification cost varies with line size, outage constraints, baseline-document quality, legacy devices, software reuse, safety functions, fieldwork, test scope, language and night or holiday access. A universal market price without a survey would be misleading. Standardize the cost breakdown instead of inventing a benchmark.

Cost packageWhat should be includedCommon exclusion risk
Survey and designAs-is, URS, drawings, interfaces, risk assessmentSurvey visits, undocumented assets, third-party machines
HardwarePLC, I/O, panels, sensors, networks, mechanical partsObsolescence, freight, duties, spares
SoftwarePLC/HMI/robot/drive, communication and dataMissing source, licenses, third-party changes
VerificationReviews, bench, simulation and FATPeer systems, test workpieces, load tests
Site cutoverInstallation, supervision, setup, SAT and restartNight/holiday work, waiting, plant-caused delay
Handover and supportAs-built, backups, training and hypercareTranslation, extra shifts, long-term maintenance
Contingency/rate cardAllowance and approved rates for unknown workTrigger, cap and prior-approval rules

Normalize assumptions, exclusions, owner-supplied items, third-party dependencies, logistics and change approval as well as commercial model. Where uncertainty is high, contract the as-is survey and basic design as Phase 1, then approve implementation price and outage plan after the baseline. A low total price that excludes FAT, rollback, as-built records and restart support transfers a large operational risk back to the buyer.

Integrate multiple suppliers through RACI and an evidence pack

When the OEM, panel builder, control integrator, robot supplier, mechanical contractor, IT/OT team, production, quality, EHS and maintenance are involved, completion of each vendor’s task does not equal completion of the line. Use a RACI to assign requirements approval, design, software integration, safety assessment, FAT, cutover command, SAT, quality release and as-built updates. Several parties may be Responsible, but each decision needs one Accountable owner.

The evidence pack is not a folder where documents accumulate. It is a traceability structure from each URS identifier through design element, risk-reduction measure, software release, FAT/SAT case, result, deviation and as-built record. Agree file naming, language, revision control, approval method, submission format and delivery of editable native data before contract award. PDF-only handover can force the next modification team to rebuild the as-is baseline again.

Build owner readiness before requesting quotations

If decisions that belong to the factory are still open when quotations are requested, suppliers will price different assumptions. A proposal that looks inexpensive can then accumulate necessary work as post-award changes and increase both cost and outage risk. Before RFQ, identify at least the project owner, operational objective, scope, available outage window, production/quality/safety approvers, drawings and source files that can be supplied, and the contact owner for every third-party machine.

Readiness is more than the existence of documents. Confirm when drawings were last reconciled with the machine, whether backups have actually been restored in a test, the approval lead time for network changes, availability of test workpieces, agreement between production planning and the outage date, and arrangements for interpreters and local contractors. List unknowns separately for incoming power, mechanical work, controls, safety and IT/OT, then assign who will close each item, by when and with what evidence.

For example, one line may contain a factory-owned PLC, an OEM-owned robot program and a server managed by headquarters IT. Awarding the retrofit as one package does not automatically provide access rights or change approvals. Link work permits, backups, difference reviews, test witnessing and handover conditions to each ownership boundary. This makes the RFQ useful for judging not only price but also how each bidder will manage unknowns and dependencies.

After quotations arrive, copy every assumption, exclusion and unknown into one comparison sheet before negotiating price. Let the factory answer factual questions and ask bidders to revise their offers. Only after separating a price difference caused by scope, technical approach or risk allocation can the owner compare suppliers on equivalent conditions.

Factory readiness also includes decision speed. If an unexpected condition appears during cutover, work can stop for approval rather than for a technical reason when nobody is authorized to accept a design change, reduce the restart scope or order rollback. Define delegates, communication routes, response deadlines and decision records in advance, and verify that the same chain works at night and on holidays.

Do not close bidder questions in private email threads. Keep a clarification register and distribute the same factual answer to all bidders. When an answer changes a requirement or scope, revise the URS and drawings and identify the impact on price, schedule, testing and safety. This prevents one supplier from pricing an obsolete assumption and disputing the change after award.

Production Line Modification: Brownfield Change Control - figure 3

Purchase-specification checklist

Technical and operational

  • Scope, exclusions, adjacent machines, owner-supplied items and third-party assets are shown graphically.
  • Baseline measurement is linked to acceptance criteria for capability, quality and availability.
  • Normal, abnormal, recovery, manual, power-recovery and changeover scenarios are included.
  • Communication timeout, default value, failure state and reconnection are defined.
  • Backup, development environment, licenses and credential-handover method are defined.

Safety and change control

  • The owner of change-based risk assessment, applicable standards/editions and evidence are named.
  • Guards, interlocks, emergency stop, unexpected start-up and residual energy are assessed individually.
  • No assumption says that standard PLC software alone replaces a required safety-related architecture.
  • Change request, impact assessment, approval, release and regression scope are recorded.
  • Temporary bypasses have authorization, indication, expiry and reinstatement verification.

Cutover and acceptance

  • Pre-shutdown FAT scope, untested items and SAT carryover rules are explicit.
  • Command structure, hold points, go/no-go and remaining-time decisions are defined.
  • Rollback configuration, steps, parts, tools, duration and confirmation tests are present.
  • SAT distinguishes safety, function, capability, quality, data and maintainability acceptance.
  • As-built records, full source, parameters, training, spares and issue closure drive final payment.

FAQ about brownfield production line modification

How is production line modification different from PLC modification?

A PLC change may be one work package. A line modification integrates mechanical, electrical, control, safety, adjacent assets, quality, operations, shutdown and restart. Even a controller-only replacement needs an interface and safety-impact check.

When should a factory equipment modification be surveyed on site?

Use a short survey before budgeting and a detailed survey before basic design. Separate observations possible during production from terminals or mechanisms visible only when stopped, and carry every unknown into the estimate assumptions and cutover decisions.

How much FAT is needed for an equipment control modification?

Base it on risk and reproducibility. Verify logic, HMI, communication, fault recovery, release identity and traceability before shutdown wherever practicable. Carry only genuinely site-dependent load, motion and stopping-time checks into SAT, with explicit status.

How can we reduce production-line automation downtime?

Improve the as-is baseline, freeze interfaces, prefabricate panels and harnesses, test abnormal cases offline and rehearse the sequence and hold points. Removing rollback margin to create a shorter-looking schedule increases business exposure.

What can be outsourced in commissioning support?

Installation supervision, configuration, testing, training and hypercare can be outsourced. Keep named plant owners for production release, product quality, safety acceptance and residual-risk acceptance. Vendor work completion is not the same as operational acceptance.

Can an existing safety circuit remain unchanged after a PLC modification?

That cannot be assumed. Assess how the change affects hazards, speed, motion, access, stopping, restart and diagnostics, then confirm that existing safety functions and implementation still meet the project requirements.

How should production line modification quotations be compared?

Break them into survey, design, hardware, software, verification, fieldwork, documentation, training, support and contingency under the same URS and exclusions. Normalize FAT, SAT, rollback, as-built, night work and third-party waiting.

Conclusion: do not begin integration on shutdown day

Keeping a brownfield project under control is not about compressing every minute of the outage. It is about exposing as-is unknowns, fixing responsibility through the URS and interface matrix, reassessing safety from the change delta, finding failures offline, embedding go/no-go and rollback into cutover, and staging SAT and restart. Suppliers can then be compared by the operational risk they remove and the evidence they hand over, not merely by the lowest price.

TOMAS TECH can support the early survey and URS stage as well as the interfaces among controls, electrical, mechanical, safety and IT/OT work. If a Thailand production line modification is stalled by a short outage window or missing legacy documentation, share the current constraints through our contact page. A feasibility-stage discussion is welcome.

Primary references