Aging equipment IoT is not a plan to replace every old machine at once. It is a staged way to inventory assets, test failure hypotheses and data quality without disrupting production, and decide whether to retain, migrate or retire each asset. This guide turns that approach into practical RFP, PoC, FAT and SAT requirements for factories in Thailand and ASEAN.
Aging equipment IoT: buy a staged decision loop, not a box of retrofit sensors
Adding sensors to old machines and forwarding values to a cloud platform does not, by itself, manage aging risk. Management and plant teams need evidence that reduces uncertainty: what assets actually exist, which failures matter, which signals can be trusted, what maintenance action follows an alert, and where repair, spares and modernization budgets should go.
The unit of implementation should therefore be a decision loop rather than a sensor count:
- Inventory assets, controls, firmware, drawings, backups, spares and support capability.
- Rank equipment by production, quality and safety impact, recovery time and failure mode.
- Begin with read-only access or electrically isolated sensing that does not alter control.
- Accept signal status, timestamps, sequence and gaps before accepting analytics.
- Run a no-stop 90-day PoC that connects detection to inspection and maintenance action.
- Use evidence gates to retain, monitor, migrate or retire the asset.
This approach does not make life extension the default objective. An asset can be retained when its condition is stable, spares and skills remain available, recovery is proven and monitoring makes its risk manageable. If safety components are unavailable, failure consequences are unacceptable or recovery cannot be demonstrated, IoT must not become an excuse to postpone migration or retirement.
Why existing-equipment IoT matters in Thailand now
Thailand’s Board of Investment reported 132 applications, valued at THB17.2 billion, under the Smart and Sustainable Industry category in the first half of 2026. Those figures are applications, not approvals, completed installations or verified benefits. They nevertheless indicate active consideration of modernization projects. See the BOI first-half 2026 release.
The current Smart and Sustainable Industry measure page states a minimum investment of THB1 million, excluding land and working capital, and lists machinery import-duty exemption. It describes a three-year corporate income tax exemption for existing projects, capped at 50% of the qualifying efficiency-improvement or business-upgrade investment excluding land and working capital. The 100% cap applies only when machinery linked to or supporting Thailand’s domestic automation industry represents at least 30% of the total value of machinery, automation systems or robotics used or upgraded in the project. The page also requires full implementation within three years after the incentive certificate is issued. Activities, qualifying costs, timing, eligibility and approval must be confirmed with BOI for the specific project; this article does not conclude that a project qualifies. A notice that solar-energy applications stopped after 30 June 2025 must not be generalized as an expiry of every smart-industry category. Check the current BOI Smart and Sustainable Industry measure.
Regardless of incentives, mixed-age factories face a common layer of uncertainty: nameplates do not match the asset register, PLC and HMI firmware versions vary, backups cannot be located, communication cards and power supplies are obsolete, and stop causes remain in the memory of one technician. The first value of aging equipment IoT is not a spectacular prediction rate. It is converting these unknowns into a managed evidence set.
Keep monitoring retrofits separate from safety and control changes
In this guide, a monitoring retrofit observes equipment and supports maintenance decisions. It is not a modification to safety circuits, interlocks, emergency stops, protection relays, PLC logic, motion, or pressure and temperature control settings.
Work that can fit the monitoring scope
- Read an approved tag list through an existing interface using read-only permissions.
- Add non-intrusive current clamps or external vibration and surface-temperature sensors without changing machine function.
- Isolate the monitoring network and provide no write route from the gateway into control.
- Record measurement health, including missing data, clock problems, sensor detachment and low battery.
- Route early alerts to human verification and work management rather than automatic machine trips.
Work that requires a separately governed project
- Changes to a safety PLC, emergency stop, guard, light curtain or safety relay.
- Writes to PLC programs, interlocks, motion, PID loops or protective settings.
- Operation beyond design limits, disabling a protection, or bypassing an alarm.
- Modifications affecting machine risk assessment, certification or legal conformity.
When a safety or control change is needed, use formal management of change, risk assessment, testing and authorization with the responsible owner, machine builder and qualified engineers. Never bypass a safeguard for an IoT PoC or intervene in a live cabinet without an approved safe method.
NIST SP 800-82 Rev.3 explains that OT security must account for performance, reliability and safety requirements, and treats an accurate asset inventory as foundational to OT risk management. Factory constraints belong in the design; an IT pattern should not simply be imposed on the production environment. See NIST SP 800-82 Rev.3, September 2023.
The six-stage aging-equipment modernization loop

| Stage | Core question | Minimum evidence | Decision produced |
|---|---|---|---|
| 1. INVENTORY | What do we own, and what is unknown? | Register, drawings, versions, backups, spares | Investigate or qualify |
| 2. CRITICALITY | What happens when it fails? | Impact, failure mode, recovery time | Priority |
| 3. READ-ONLY SENSE | What can be observed safely? | Connection design, isolation, tag/sensor list | PoC readiness |
| 4. SIGNAL CHECK | Can the data be trusted? | Status, time, sequence, gaps, calibration | Analytics readiness |
| 5. 90-DAY POC | Can the evidence change action? | Detection, check, work and result history | Continue or correct |
| 6. DECISION GATE | Retain, migrate or retire? | Technical, operational, economic and safety evidence | Investment decision |
Do not skip stages. Training a model while equipment IDs are duplicated, inferring degradation while clocks are drifting, or buying sensors before a failure mode has been stated makes a failed PoC difficult to diagnose.
Stage 1: inventory the asset, firmware and spare-parts reality
An asset register containing only machine name and purchase year is not enough. Link equipment, controls, connectivity, maintenance and business-continuity information to one stable equipment ID.
| Class | Inventory fields | Example verification |
|---|---|---|
| Machine | ID, maker, model, serial number, install year, capacity | Reconcile nameplate and register |
| Control | PLC, HMI, drive, I/O and firmware | Follow approved access procedure |
| Backup | Programs, parameters, recipes and restore instructions | Confirm more than file existence |
| Connection | Ports, protocols, IP, serial and existing tags | Update physical and logical drawings |
| Spares | Quantity, location, compatibility, obsolescence, lead time | Reconcile stock, buying records and maker data |
| Maintenance | Failures, inspections, skills and external support | Combine CMMS, paper and interviews |
| Dependency | Upstream/downstream, tooling, utilities and quality checks | Test propagation of a stoppage |
Do not hide missing knowledge in blank cells. Mark it as unknown, assign an owner and set a confirmation date. Honest uncertainty is more useful than a register that appears complete.
A backup file is not proof of recoverability. The target machine, version, capture date, engineering tool, license, cable, restore procedure and skilled person all matter. A controlled restore rehearsal—performed in a safe environment and not on live production without authorization—is stronger evidence than a screenshot of a directory.
ISO 55001:2024 provides a framework for realizing value from assets by aligning lifecycle decisions with organizational objectives. It does not mandate an IoT product or replacement interval, but it is a useful reference for balancing performance, risk, opportunity and cost in asset decisions. See ISO 55001:2024.
Stage 2: rank criticality through consequence and failure mode
Priority based only on age or accumulated downtime is misleading. An old, low-load machine with a workable alternative may be less urgent than a newer single point of failure. Evaluate at least:
- Safety, environmental and quality consequence.
- Impact on the line, customer delivery, work in process and tooling.
- Detectability and the actionable time between a warning and a failure.
- Realistic recovery time, including the required spare, tool and skill.
- Feasibility of alternate routing, manual work, transfer or standby equipment.
- Known failure modes and whether their precursors are observable.
An existing FMEA method can be used, but retain the rationale, author, date and applicable version rather than only the score. For a hypothesis such as bearing wear, state which vibration bands, temperature, current, lubrication information and product conditions may be relevant. “Use AI prediction” is not a failure mode.
An initial PoC asset should be both important and testable within 90 days. If a failure occurs once every several years and no safe surrogate test exists, the PoC may never obtain a valid positive case. Spares, recovery rehearsal and migration design may deliver better evidence first.
Stage 3: design retrofit sensing as read-only or isolated
There are three typical routes into old-equipment data: read approved data from an existing controller, install an external sensor, or integrate an existing instrument or recorder. Multiple routes can be combined, but their boundary from control must remain explicit.
Reading existing controller data
A PLC, CNC or instrument with a communication port is not permission for unrestricted access. Specify the approved tags, scan interval, concurrent session limit, timeout, load ceiling and maintenance window. Disable gateway writes, but do not rely on a single setting: constrain writes through accounts, firewall rules, communication direction and configuration review.
When evaluating PLC replacement and retrofit in Thailand, separate monitoring connection work from control migration. First record current signals, then compare old and new control behavior, and only then execute an approved cutover and rollback plan.
Installing external sensors
Current clamps, vibration, surface temperature and acoustic sensors can reduce required downtime, but data quality depends on mounting, range, sampling, calibration, cable, power and environmental suitability. A surface-temperature measurement, for example, is not automatically the internal bearing temperature. Record what proxy it represents and under which operating conditions it is comparable.
If installation can affect a guard, insulation, cleanability, hygiene or hazardous-area requirement, do not call it a simple add-on. Submit it to the appropriate review. A no-stop objective never authorizes unsafe work.
Selecting a gateway
For industrial IoT gateway selection, assess more than protocol support. Require local buffering, time synchronization, credential or certificate management, update and rollback, audit logs, replacement procedure, configuration backup, and deterministic behavior after a network outage. Translating a legacy protocol into IP is not synonymous with safe operation.
Stage 4: accept signal quality, time and sequence before analytics
A line on a dashboard may not represent equipment reality. Attach measurement context before analytical acceptance.
| Quality element | Failure example | Acceptance evidence |
|---|---|---|
| Status/quality | A communication loss is stored as zero | Status remains separate from value |
| Source time | Device clock is seven minutes wrong | Time source, tolerance, detection, correction history |
| Receive time | Backfilled data appears as current | Source-to-receive delay remains visible |
| Sequence | Retries count an event twice | Gap, duplicate and restart rules |
| Sampling | A short transient disappears | Period/window/aggregation and rationale |
| Calibration | Replacement sensor changes the baseline | Sensor ID, calibration, replacement, mounting history |
| Context | Product or speed change appears as degradation | Product, recipe, load and mode association |
The most dangerous predictive-maintenance pattern is a sophisticated model placed on low-quality signals, followed by confidence in a headline accuracy number. During the initial 90 days, review gaps, time alignment, retries, detached sensors and operating context every week before optimizing model metrics.
CISA’s Cross-Sector Cybersecurity Performance Goals offer a prioritized baseline of IT and OT cybersecurity practices. They are not a legal obligation or a complete site design. Adapt account management, backups, vulnerability handling and logging to the site’s risk and equipment constraints. See CISA Cybersecurity Performance Goals.
A no-stop 90-day PoC

A 90-day PoC is not a promise to predict a failure within 90 days. Its purpose is to verify an operational closed loop: observation, signal quality, hypothesis, alert, human check, maintenance action and outcome. The timeline below is a working template and should be adjusted for maintenance windows and realistic failure cycles.
Days 0–15: freeze the baseline and safety boundary
- Approve the target equipment ID, owners, connection drawing and work permit.
- Review evidence that the monitoring path cannot write into safety or control.
- Record normal, setup, idle and known-abnormal operating conditions.
- Record sensor ID, mounting point, orientation, tightening, calibration and photographs.
- Convert historical failures and operator knowledge into testable hypotheses.
Days 16–45: validate data quality and failure hypotheses
- Safely test a communication outage, gateway restart, clock issue and sensor detachment.
- Verify that gaps, duplicates, delays and quality states remain distinguishable.
- Separate normal variation caused by product, speed, load and ambient conditions.
- Revise thresholds with documented false-alert and missed-event reasons.
Days 46–75: operate from alert to work order
- Define alert recipients, acknowledgement time and escalation.
- Record inspection results, including “no abnormality found.”
- Link work order, spare part, observation, photograph and remeasurement to the event.
- Give maintenance users an understandable explanation and access to raw evidence.
Days 76–90: replay and hold the decision gate
- Verify that the same stored inputs and version reproduce the same decision.
- Test recovery from sensor, gateway and network interruption.
- Close FAT/SAT exceptions, temporary measures, owners and deadlines.
- Compare retain, modify, migrate and retire outcomes instead of assuming rollout.
No major failure during a PoC is not a failed PoC. A trustworthy baseline, a rejected failure hypothesis, identification of a signal that cannot be obtained, and measurement of operating effort are useful evidence. Conversely, one successful alert is not enough to justify a plant-wide deployment.
Evidence gates for retain, monitor, migrate or retire

RETAIN
Retain when there is no unresolved safety issue, failure consequence is manageable, required spares, skills and backups are available, recovery is proven, and monitoring operating cost is justified. Retain does not mean “do nothing.” Register upkeep, periodic testing, restore rehearsal, sensor-health review and spares review are continuing conditions.
MONITOR
Expand monitoring when signal quality is accepted, a defined failure mode can be checked earlier, and an action follows the alert. Before scaling the device count, standardize templates, naming, access, calibration, replacement, training and support cost.
MIGRATE
Plan partial or full migration when control obsolescence, unavailable spares, disappearing skills, cyber exposure, recovery time or quality requirements cannot be controlled through monitoring. Capture current I/O, sequences, recipes, alarms, history, reports and upstream connections; design old/new comparison, rollback and the maintenance window.
RETIRE
Retire when demand, capacity, quality, energy, maintenance cost and alternatives show that the asset no longer creates sufficient value. Close data retention, component reuse, disposal, network and account removal, and drawing updates. Sunk IoT cost is not a reason to keep an unnecessary machine.
| Gate perspective | Evidence supporting RETAIN/MONITOR | Signal supporting MIGRATE/RETIRE |
|---|---|---|
| Safety | Risk is formally assessed and controlled | Unresolved protection or conformity issue |
| Technical | Signal quality, backup and recovery proven | Unknown version, no restore, obsolescence |
| Operating | Alert-to-action ownership is clear | Ignored noise, no responsible skill |
| Economic | Avoided loss and run cost are explainable | Life-extension cost exceeds migration value |
| Business | Asset matches production and customer plan | Demand gone or alternative route available |
Make OT security and role boundaries procurement requirements
The ISA/IEC 62443 series addresses IACS security across the lifecycle and contains standards relevant to asset owners, product suppliers and service providers. “62443 compliant” alone does not identify the applicable document, scope, edition, evidence or responsibility. Specify them in the RFP and retain operational accountability. See the ISA/IEC 62443 series overview.
Agree before contract award:
- Who maintains and exports the hardware and software inventory.
- Who owns local, service and administrator accounts and their authentication.
- How remote maintenance is requested, approved, time-limited, recorded and stopped.
- How gateway, OS and agent updates are notified, tested and rolled back.
- How configuration and data are backed up, encrypted, restored and retained.
- How timestamped logs are stored and exported.
- How vulnerabilities, end of support, obsolete parts and incidents are communicated.
- How accounts, certificates, routes and cloud data are removed at contract exit.
Blocking all cloud connections does not automatically create security, and using cloud services does not automatically create insecurity. Choose an architecture by making flows, privileges, updates, monitoring, recovery and accountability explicit.
Requirements to put in an aging-equipment IoT RFP
An RFP should let vendors propose against the same conditions and let the plant accept evidence—not merely compare product feature lists.
Scope and outcome
- Equipment IDs, quantity, location, operating hours, environment and maintenance window.
- Target failure modes and observable precursors.
- Business outcome to validate in 90 days and outcomes not guaranteed.
- Monitoring-only boundary, explicitly excluding safety and control changes.
Technology and data
- Tags/sensors, unit, range, period, quality, timestamp and retention.
- Read-only design, isolation, approved flows, bandwidth and load ceiling.
- Behavior for gaps, retries, duplicates, clock drift and offline operation.
- Export formats for raw data, events, settings and audit logs.
- Keys linking equipment, product, order and maintenance history.
Operations and support
- Alert ownership, response expectation, severity and escalation.
- Sensor replacement, calibration, battery and gateway spare.
- Multilingual training, procedure and support in Thailand or the region.
- Five-year cost including license, communication, cloud, maintenance and update.
Acceptance and exit
- FAT, SAT and 90-day test cases with required evidence.
- Correction, retest, hold and termination conditions.
- Data and configuration ownership, export and migration assistance.
- Removal, credential revocation and data-deletion evidence at exit.
If equipment-failure prediction is proposed, do not contract only for “95% accuracy.” Require the definition of a failure, prediction horizon, sample denominator, class imbalance, false-alert and miss cost, unknown states, exclusion rules, independence of validation assets, and revalidation after model updates.
Illustrative FAT, SAT and 90-day acceptance criteria
Every value below is an illustrative assumption for making an RFP testable, not a market benchmark or performance promise. Replace it with agreed values appropriate to the equipment, process, network and risk.
| ID | Test | Illustrative acceptance | Evidence |
|---|---|---|---|
| FAT-01 | Read-only boundary | Zero unauthorized write commands | Access matrix, config, packet record |
| FAT-02 | Network outage | Identify gaps and replay after a 30-minute outage | Event log and replay result |
| FAT-03 | Clock offset | Flag a 60-second offset as a quality issue | Time log and alert |
| FAT-04 | Duplicate | Zero double-counted business events | Input/output reconciliation |
| SAT-01 | Equipment load | Remain within agreed PLC/cycle impact | Before/after measurement |
| SAT-02 | Sensor comparison | Difference stays within agreed tolerance | Calibration and comparison record |
| SAT-03 | Recovery | Restore within agreed time after gateway swap | Recovery work record |
| POC-01 | Data quality | Valid-data ratio meets agreed target | Weekly quality report |
| POC-02 | Closed loop | Alert, check, work and result are traceable | Linked work order |
| POC-03 | Reproducibility | Same input/version reproduces the decision | Replay result |
“The dashboard opens” and “an email arrives” are insufficient acceptance. Test exceptional conditions, recovery, log export, staff handover, machine restart and contract exit. Distinguish what FAT can simulate from what SAT must prove on the actual machine and production network.
Turning the evidence into an investment decision
Benefits may include avoided or shortened downtime, more efficient inspection, lower emergency-spare exposure, reduced quality loss and lower key-person or cyber risk. Avoid double counting.
The following is an illustrative assumption, not a market fact. Suppose one machine has four major stops per year, each stop costs THB200,000, monitoring can avoid or shorten 25% of that impact, and annual system and operating cost is THB120,000. The rough annual avoided value would be 4 × 200,000 × 25% = THB200,000, leaving THB80,000 before tax and other effects. Replace frequency, loss and contribution with plant evidence and run a sensitivity analysis.
Do not hide lifecycle costs:
- Survey, design, installation review and maintenance-window coordination.
- Sensors, gateway, network, server and cloud.
- Integration, tag normalization, master-data and retention.
- Calibration, battery, replacement, cyber update, certificate and spare gateway.
- Alert review, false alerts, training and standard-work changes.
- Contract exit, data migration, removal and reintegration after machine migration.
When expanding toward a condition-based maintenance system, connect sensor evidence to maintenance action and feed the result back into the threshold or decision. Measure changed decisions and outcomes, not dashboard views.
Operations after rollout: sensors age too
Retrofit sensors and gateways are new assets. If left unmanaged, the system monitoring legacy equipment becomes the next legacy system. Register sensor identity, software version, calibration, battery, certificate, mounting, replacement and end-of-support date.
Monthly governance should review:
- Valid-data ratio, gaps, delay, clock drift and resend behavior.
- Noise, drift and detachment by sensor identity.
- True, false, missed and unclassified alerts with reasons.
- Time from alert to acknowledgement, work and restoration.
- Changes to failure mode, criticality, threshold and model version.
- New evidence that changes the retain, migrate or retire gate.
Link changes in sensor position, collection rate, tag, machine program, network, model and threshold. Without before/after traceability, teams cannot tell whether the asset improved or the measurement condition changed.
Common failure patterns and how to avoid them
Giving every machine the same sensor kit
Failure modes and observability differ. Prioritize by consequence and hypothesis, then choose only the required signals.
Writing casually into an old PLC
Mixing monitoring and control raises safety, quality and stoppage risk. Make read-only access, isolation, privilege and direction testable acceptance conditions.
Treating data volume as the outcome
Point count and storage size do not show better maintenance. Trace detection through inspection, work and result.
Contracting only a prediction score
Rare-failure data can produce misleading headline accuracy. Separate denominator, false alerts, missed events, horizon and unknown states.
Ending the PoC without an operating owner
Assign ownership for tags, calibration, alerts, models, updates and recurring cost in the RFP phase.
Assuming life extension is the only success
When monitoring does not reduce uncertainty, or safety, recovery and spare risks remain unacceptable, migration or retirement is a successful evidence-based conclusion.
Aging equipment IoT FAQ
Which machine should start an aging-equipment IoT project?
Do not simply choose the oldest. Prioritize a machine with material stop consequence, a defined failure-mode and signal hypothesis, and an operational loop that can be tested within 90 days. If it has an unresolved safety issue, begin with formal risk reduction and modernization decisions rather than a monitoring PoC.
Does existing-equipment IoT require PLC replacement?
Not always. Approved read-only access or external sensing may support monitoring. If obsolescence, no restore capability, performance, cyber, safety or quality requirements cannot be controlled through monitoring, plan PLC or machine migration.
Can sensors be retrofitted while equipment runs?
Even non-intrusive devices require assessment of mounting, cabinet work, insulation, hazardous area, guarding, hygiene and permits. “No stop” never means unauthorized work. Use a maintenance window when safe installation cannot otherwise be assured.
What quality information matters first for old-machine data collection?
Check status/quality, source time, receive time, sequence, gaps, duplicates, and calibration and mounting history before trends. Product, load and speed context are also necessary.
Can predictive maintenance be proved in 90 days?
Depending on the failure cycle and available data, actual prediction performance may not be provable in 90 days. Accept data quality, failure hypotheses, alert operations, work integration and reproducibility, then decide whether a longer evaluation is justified.
What is the split between FAT and SAT?
Use FAT for repeatable tests with simulated inputs, outages, duplicates, clock offsets, privileges and log exports. Use SAT to confirm actual-machine load, real network behavior, mounting, signal comparison, recovery and staff procedure.
Does a BOI incentive automatically make the investment viable?
No. Eligibility and approval require project-specific confirmation. Evaluate technical, operational and economic evidence without assuming the incentive, and verify current conditions with BOI or an appropriate adviser. Do not treat application counts as approvals or realized benefits.
Summary: turn aging from intuition into evidence
Aging equipment IoT succeeds through neither sensor quantity nor the number of AI screens. Combine asset, firmware and spares inventory; criticality and failure modes; read-only or isolated sensing; signal status, time and sequence; a no-stop 90-day PoC; and retain, migrate or retire gates. Together, they reduce uncertainty in maintenance and capital allocation.
Keep safety and control changes separate from monitoring. In RFP, FAT and SAT, accept outage, retry, clock, recovery and data-exit evidence—not just a normal dashboard. If monitoring reveals that a risk cannot be managed, “migrate” or “retire” is a sound PoC outcome.
TOMAS TECH supports factories in Thailand and ASEAN with asset discovery, read-only connection design, 90-day PoCs, and practical RFP, FAT and SAT acceptance criteria. Even if the retain-versus-replace decision is still open, you can contact us to structure the equipment scope and evidence needed for that decision.