When a Thailand factory evaluates a cloud production management system, “subscription means cheaper” and “inside the factory means secure” are both inadequate decision rules. A defensible comparison must show where production orders, actuals, inventory, lots, quality, equipment and cost data are processed, who operates each layer, and what remains available when a network link fails or a contract ends. This guide compares cloud, on-premises and hybrid architectures using five-year TCO, availability, offline operation, data location and cross-border transfer, scalability and customization, exit and migration, and evidence from FAT, SAT and UAT. It does not rank vendors; it shows how to test fit against your own requirements.
Executive answer: start with transactions that cannot stop
Do not begin by choosing cloud or on-premises. Begin by deciding how long each factory process can tolerate a loss of connectivity or an upstream system. An order inquiry may wait, while label printing, material verification, production reporting, quality release or an equipment interlock may not. Once maximum tolerable downtime, acceptable data loss and recovery order are defined per transaction, the deployment choices become clearer.
| Option | Often suitable when | Principal design issue | Evidence to obtain before award |
|---|---|---|---|
| Cloud | Multi-site rollout, variable demand, remote operations, standard processes | WAN dependency, shared responsibility, data location, exit | SLA text, responsibility matrix, data flow, complete export test |
| On-premises | Low latency on site, isolated network, special equipment links, local autonomy | Redundancy, patching, backup, concentration of know-how | Architecture, recovery exercise, parts/support lifetime, runbooks |
| Hybrid | Factory continuity plus corporate integration | Synchronization conflicts, master ownership, replay, monitoring boundaries | Link-loss test, resynchronization, duplicate prevention, clock alignment |
NIST defines cloud computing through on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service. Merely locating a server outside the plant does not deliver these operating benefits. The question is whether elasticity, standardization, measurement and divided responsibility are usable in daily operations. Likewise, installing servers in the plant does not create availability by itself. Power, cooling, storage, backup, spare capacity, monitoring and recovery staff become the plant’s responsibility.
Divide the production management system into four layers before comparing
Treating an entire product as one block hides the important differences. A Thailand factory should separate at least four layers:
- Enterprise and planning: orders, MPS/MRP, purchasing, inventory valuation, standard cost and management reporting.
- Factory execution: production orders, issue, output, defects, lots, WIP, labor and equipment actuals.
- Edge control: PLCs, testers, scales, label printers, gates and local buffers.
- Evidence and control: approvals, signatures, audit logs, master versions, backups and recovery records.
Enterprise planning is readily shared across sites and can benefit from elastic capacity and remote support. Edge control may require millisecond-to-second response and autonomous operation during a link outage. Factory execution sits between the two. All functions therefore need not run in one place. A hybrid can keep planning and visualization in the cloud, retain essential verification and buffering on site, and reconcile records after recovery.

Compare cloud production management systems with five-year TCO
Do not compare only an implementation fee with a subscription
A common production management system comparison error is to put a cloud subscription beside an on-premises license. Use the same evaluation period and handle tax, exchange rate, growth, maintenance renewal and downtime on the same basis. Five years is a proposed comparison horizon, not a statutory or universal value; use three or seven years if your asset and contract policies require it.
Cloud TCO model
implementation and migration + 60 months of service fees + primary/backup connectivity + APIs and integrations + excess storage/transfer + monitoring + customization maintenance + training + audit support + exit extraction/migration + expected downtime impact
On-premises TCO model
servers, storage, OS and database + redundancy + UPS, rack and cooling + architecture/build + license maintenance + backup media/off-site storage + patching, monitoring and incident labor + replacement parts + technology refresh + training + expected downtime impact
Hybrid TCO model
Add the costs of both sides plus edge devices, synchronization software, message queues, certificates, dual monitoring, conflict resolution and local support. Hybrid is not automatically cheaper because it sits in the middle. It deliberately operates two surfaces to preserve continuity.
Normalize TCO inputs in the RFP
| Input | Answer required from bidder | Comparison caution |
|---|---|---|
| Users | Named, concurrent and device pricing | Include peak shifts, contractors and shared terminals |
| Transactions | Limits for orders, actuals, APIs, reports and attachments | Confirm overage and throttling |
| Storage | Database, logs, images and backups separately | Ask about retention after production deletion |
| Connectivity | Main/backup circuits, SIM, private link, transfer | Use measurements from the actual industrial estate |
| Environments | Production, test, training and DR | Confirm whether non-production can be stopped cheaply |
| Updates | Scheduled release, emergency patch, custom regression | Confirm forced updates and permitted deferral |
| Exit | Full export, medium, labor and deletion certificate | Confirm grace period and unit charges |
Obtain prices at one baseline date and currency, state whether VAT and remittance costs are included, and document the exchange-rate assumption. Do not claim certainty for future cloud pricing or server parts. Compare a baseline with proposed sensitivity scenarios such as 20% higher volume, a 10% exchange-rate movement and increased outage duration. These percentages are planning assumptions, not market forecasts.
Measure availability through business recovery, not one SLA number
A high monthly service level does not keep production running if the factory’s circuit, identity provider, terminal, printer or integration API fails. An on-premises deployment with one UPS, one database, backups in the same room and one knowledgeable engineer also concentrates risk.
NIST SP 800-34 Rev.1 is guidance for U.S. federal information systems, not a law or manufacturing standard directly applicable to a Thailand factory. This article uses it as a reference framework for structuring factory recovery design. The guide explains that a business impact analysis informs system criticality, impact, RTO, backup frequency, redundancy and alternative-site needs. Define the following per factory transaction:
- MTD: maximum downtime the business can tolerate.
- RTO: target time to restore the business service after disruption.
- RPO: acceptable period of data loss at recovery.
- Recovery sequence: identity, masters, orders, actuals, labels, stock and reporting.
- Degraded mode: paper, local cache, CSV or temporary manual entry.
Do not copy an RTO or RPO from a brochure. Restore a backup into an alternative environment, let users authenticate, reconcile pending records and time the process until the business owner approves restart. List scheduled maintenance, regional incidents, plant connectivity, customer misconfiguration and third-party integrations that the SLA may exclude.
Keep the factory operating during a WAN outage
Verify offline capability transaction by transaction
“Offline supported” is too vague. For each transaction, test whether users can read, create, correct, cancel, approve and print while disconnected.
| Transaction | Minimum during outage | Verification after recovery |
|---|---|---|
| Production order | View the latest approved version | Detect work against an obsolete version |
| Material issue | Verify item, lot and expiry | Detect duplicate issues or blocked lots |
| Production actual | Buffer with timestamp | Prevent duplicate posting with idempotency key |
| Quality | Retain rule and specification version | Isolate decisions made with the wrong version |
| Label | Control numbering and reprint | Find duplicate numbers and audit reprint reason |
| Inventory move | Record a provisional transaction | Resolve negative stock and concurrent movement |
Resynchronization determines hybrid quality
After the link returns, “messages were sent” is not enough. Verify ordering, duplicates, conflicts, clocks and master versions. Give each transaction a unique ID, device time, server-received time, operator, source order and master version. If delivery is at least once, the receiver must not process the same ID twice. If two sites can update a master, define the authoritative owner and whether conflicts are resolved automatically or placed into a review queue.
A proposed link-loss test set is 5 minutes, 30 minutes, 2 hours and a shift boundary. These are not regulatory or standard thresholds; replace them with values derived from plant impact. Also inject different faults: total disconnection, latency, packet loss, DNS failure and an identity-only outage.

Separate Thailand PDPA, data location and cross-border transfer
A Thailand region does not automatically mean no cross-border processing
Section 28 of Thailand’s Personal Data Protection Act B.E. 2562 addresses transfers of personal data abroad, generally requiring adequate protection in the destination country or international organization while setting out exceptions. Section 29 addresses qualifying intra-group policy arrangements. Application depends on the data, parties, contract and exception, so legal counsel or the DPO should confirm the case.
Production records can contain personal data such as operator IDs, attendance context, competency, approvers, photographs, location or device logs. Even when the primary database is in Thailand, overseas processing may occur through:
- administrative access by an overseas support team;
- monitoring, log analysis, email, backup or disaster recovery abroad;
- connection to headquarters ERP or a regional data lake;
- APIs for generative AI, OCR or translation;
- subcontractors, remote-support tools and ticketing systems.
The RFP should require a data-flow answer for storage and processing location, backup location, support access origin, subprocessors, encryption-key controller, deletion and return, and handling of government requests. “Certified” is not a substitute for PDPA analysis. Connect legal basis, notice, processing agreement, cross-border mechanism, retention, data-subject rights and incident handling to named organizational owners.
Certification is useful evidence, not the entire conclusion
ISO/IEC 27001 sets requirements for an information security management system. ISO/IEC 27017:2026 gives cloud-specific control guidance to both cloud customers and cloud service providers. Certification and statements of applicability are useful evidence, but check scope, location, service, exclusions and audit date. A SaaS application, the implementation company and the underlying data center may not all sit in the same certification scope.
Convert shared responsibility into RACI and operating evidence
In the cloud, the provider protects infrastructure while the customer retains responsibilities for data, identities, configuration, access and endpoints. AWS’s official explanation distinguishes security “of” the cloud from security “in” the cloud and notes that customer responsibility varies with the service, data sensitivity and applicable requirements. This is not a vendor recommendation; it is a useful procurement question.
| Control area | SaaS provider | Implementer | Factory/HQ | Evidence |
|---|---|---|---|---|
| Infrastructure patch | Leads | Verifies | Reviews notice | Release record, vulnerability SLA |
| Application configuration | Provides functions | Configures/transports | Approves | Configuration register, change approval |
| Identity and access | Provides controls | Supports integration | Leads | Access review, leaver disablement |
| Masters | Validates input | Supports migration | Leads | Version, approval, change log |
| Backup | Contracted scope | Supports restore | Defines/verifies | Restore-test result |
| Incident | Detects/notifies | First triage | Decides/reports | Contact tree, timeline, corrective action |
For each activity, assign one Accountable owner in principle, at least one Responsible person, and the necessary Consulted and Informed parties. Leave no gaps around restoration, encryption keys, log preservation, leaver access, subprocessor changes, emergency patches or audit-evidence delivery.
Evaluate production management system customization through changeability
Measure upgrade consequences, not the number of modifications
Cloud favors standardization but can still provide extension points. On-premises may permit deep changes while increasing upgrade cost and fault ownership. Process each requirement in this order:
- Can the business adopt the standard process?
- Can configuration, workflow or report settings meet it?
- Can a published API, event or supported extension externalize it?
- Is a core modification genuinely necessary?
For every gap, document business value, regulation or customer obligation, workaround, user population, frequency and disruption impact. Tie a core change to source ownership, test environment, deployment, rollback, vulnerability response, next-release compatibility and rights when switching suppliers.
Acceptance of production management system customization should include concurrent updates, duplicate submissions, latency, partial failure, insufficient privilege, master cutover and month-end load—not only happy paths. Multilingual testing should cover Thai combining marks, Japanese/English/Thai search, Buddhist and Gregorian years, time zones, grouping separators, units and label widths.
Test contract termination and migration before signing
“Exportable” does not always mean reusable
Exit risk is not unique to cloud. An on-premises system can also become hard to migrate because of a proprietary database, unavailable encryption keys, obsolete operating system, expired support or missing source. Require the RFP to cover:
- complete export of masters, open orders, actuals, inventory, lots, quality, approvals, audit logs and attachments;
- documented format, character encoding, timestamp, unit, code lists and referential relationships;
- stable identifiers connecting attachments to records;
- delta extraction and final freeze extraction;
- post-termination read-only period, assistance rates, deletion timing, backup deletion and certificate;
- API limits, transfer charges, encryption, transport media and cross-border treatment.
As a proposed pre-contract test, export representative data, load it into a separate database and reconcile record counts, values, quantities, references, hashes and readable attachments. If a full-volume test is impractical, contractually require it early after award with remediation for failure. “Discuss at termination” leaves the buyer with weak leverage.
Manage production management system implementation time through FAT, SAT and UAT
Cloud is not always fast and on-premises is not always slow. Implementation time depends on standard-process fit, data migration, equipment interfaces, approvals, training, sites and permissible shutdown. Define completion evidence and dependencies instead of promising a date from deployment type alone.
FAT: verify specifications and exceptions in the supplier environment
Use a requirements traceability matrix to test configuration, custom functions, interfaces, roles, reports and audit logs. Include anonymized representative data as well as synthetic data, inject failures and test rollback. Give every open defect a severity, workaround, owner and due date.
SAT: verify connections and continuity in the Thailand factory
Use actual terminals, scanners, printers, PLC or equipment gateways, primary and backup circuits, identity service, clock source and power. Test link loss, resynchronization, duplicate labels, equipment replay, shift boundaries and peak load. A healthy cloud service does not equal SAT acceptance if the plant cannot use it.
UAT: the process owner approves an end-to-end scenario
UAT is not a click-through. Real roles, including Thai-speaking users, should execute from order and planning through issue, production, quality, shipping and cost/inventory reconciliation. Compare quantities and values with the legacy process and verify exceptions, closing, correction, cancellation and audit evidence.

Proposed stage gates
| Gate | Entry | Exit evidence | Go/No-Go owner |
|---|---|---|---|
| Design freeze | Requirements/data flow agreed | Specification, responsibility, test plan | Business owner + IT |
| FAT complete | Configuration/development done | Execution log, defect list, regression | Project owner |
| SAT complete | Site connection ready | Outage, equipment, printing, recovery evidence | Plant manager + IT |
| UAT complete | Training/migration rehearsal done | Signed scenarios, reconciliation | Process owner |
| Production cutover | Critical defects resolved | Cutover/backout plan, contact tree | Steering committee |
A proposed severity model can define Severity 1 as major safety, legal, shipment or data-integrity impact; Severity 2 as a principal process with no practical workaround; and Severity 3 as a tolerable workaround. These definitions and acceptance limits are proposed values that each company must approve. Do not accept based only on a defect count; assess impact and workaround.
Narrow options with constraints before weighted scoring
Weighted scores are useful, but a legal or continuity requirement must not be averaged away. Exclude candidates that fail mandatory conditions, then score the remainder.
Example mandatory conditions
- The target process can continue for the agreed time during a WAN outage.
- Legal or DPO review can approve the data flow and cross-border basis.
- RTO and RPO can be demonstrated by restore testing.
- All required data can leave in a reusable form.
- Critical equipment interfaces and label controls can pass SAT.
- Audit logs can be retained with integrity and searchability for the required period.
For qualifying candidates, score TCO, rollout speed, standard fit, operating capacity, extensibility, support languages and roadmap. Every score should point to a source URL, document version, demonstration or test ID. Avoid converting impressions into numbers.
Three representative deployment scenarios
Scenario A: rapidly standardize planning and visibility across sites
Cloud becomes a strong candidate when plants have similar base processes, control remains in a separate MES or edge layer, and headquarters needs consistent KPIs. Emphasize a common template, site-level configuration, integrated identity, API monitoring, data location and phased rollout.
Scenario B: specialized equipment and low-latency execution dominate
On-premises or edge execution may be rational when legacy equipment, proprietary protocols, isolated networks, strict response and long product lifecycles dominate. Include off-site backup, patching, spare parts, cyber controls and staff succession in TCO.
Scenario C: combine outage continuity with enterprise data integration
A hybrid keeps order cache, material checks, production buffers and label control locally while cloud handles planning, analytics and multi-site integration. Synchronization is the success condition. Put more SAT effort into version control during disconnection and conflict resolution after recovery than into the normal connected path.
Ten questions ready for your RFP
- Separate the proposed architecture into enterprise, execution, edge and evidence layers, with owners.
- State RTO/RPO, offline actions, buffer capacity and resynchronization for each transaction.
- State SLA scope, exclusions, measurement point, remedies and historical availability information.
- List the countries/regions for production, backup, logs, monitoring and support, plus subprocessors.
- Put PDPA roles, purpose, retention, deletion and cross-border basis into the data-flow diagram.
- Distinguish standard configuration, low-code extension, external extension and core modification.
- Explain release notice, deferral, validation, regression and rollback.
- Provide export specifications, charge, lead time and deletion evidence for all data and audit logs.
- Define FAT/SAT/UAT environments, data, roles, evidence and defect governance.
- Define L1/L2/L3 support, Thai/English/Japanese coverage and on-site dispatch.
For functional requirements, see Production Management System Functions: RFP Requirements for Thailand Factories. For failure modes and prevention, see Production Management System Implementation Failure: Practical Design for Thailand. Together with this deployment comparison, they connect requirements, contract and acceptance.
FAQ about cloud production management systems
Is a cloud production management system cheaper than on-premises?
Not always. Compare users, transactions, storage, connectivity, integration, customization, operations, updates, downtime and exit over the same period. Cloud can reduce upfront assets, but long-term subscription, overage and extraction matter. On-premises needs redundancy, cooling, backups, staff and refresh in addition to licenses.
Does an on-premises production management system eliminate WAN risk?
It can preserve local processing, but dependencies may remain on headquarters ERP, license validation, external identity, email or remote backup. The factory also retains LAN, power, database and storage risks. Draw the dependencies and perform isolation testing.
How much production management system customization is acceptable?
Confirm value and reason, then prefer standard process, configuration, supported extension and core modification in that order. Evaluate regression per release, rollback, source rights, vulnerability fixes and maintainability after a supplier change—not only modification count.
Can cloud shorten production management system implementation time?
It can shorten infrastructure procurement, but process alignment, data cleansing, equipment interfaces, PDPA review, training and UAT remain. Duration is driven by sites, gaps, decision speed and preparation of acceptance evidence.
Is hybrid automatically the safest option?
No. It can improve local continuity but adds synchronization, monitoring, certificates, dual operations and conflict resolution. It is effective when outage/resynchronization can pass SAT and the organization can sustain the responsibilities.
Conclusion: prove the right cloud/on-premises choice before contracting
Choosing a cloud production management system is not a preference about server location. It is the design of transactions that cannot stop and the evidence that controls them. Divide the system into four layers, compare a common five-year TCO, define RTO/RPO and offline transactions, review PDPA data flows, and put shared responsibility and exit into the contract. Then demonstrate acceptance through FAT, SAT in the Thailand plant and UAT by process owners. Whichever architecture wins, management receives a traceable reason and a clear statement of residual risk.
TOMAS TECH can support the early mapping of processes and data flows, cloud/on-premises comparison, RFP, equipment integration, outage testing and FAT/SAT/UAT design before a product is selected. You are welcome to contact us even when the first question is simply what must be decided now.
Sources
- NIST, *The NIST Definition of Cloud Computing (SP 800-145)*: https://csrc.nist.gov/pubs/sp/800/145/final
- NIST, *Contingency Planning Guide for Federal Information Systems (SP 800-34 Rev.1)*: https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final
- Personal Data Protection Act B.E. 2562, Royal Thai Government Gazette: https://ratchakitcha.soc.go.th/documents/17082307.pdf
- Thailand PDPC, Government Platform for PDPA Compliance, Privacy Policy: https://gppc.pdpc.or.th/privacy-policy/
- ISO, *ISO/IEC 27001:2022 Information security management systems*: https://www.iso.org/standard/27001
- ISO, *ISO/IEC 27017:2026 Information security controls for cloud services*: https://www.iso.org/standard/27017
- AWS, *Managing security responsibilities for Amazon VPC*: https://docs.aws.amazon.com/vpc/latest/userguide/security.html
This article provides general system-selection and governance information, not legal advice. Confirm current laws and notifications and involve legal counsel, the DPO and audit teams when assessing PDPA, cross-border transfers and industry-specific requirements.