When a Thai factory evaluates robot maintenance support, the key question is not how many visits are included. What the factory should buy is a measurable recovery system: detect the event, place the cell in a safe state, diagnose it, restore the approved configuration, verify safety and process quality, release production, and close corrective action. A contract built around vague “fast support” can leave the hardest questions unanswered: who may authorize a remote connection, where the compatible spare is, which backup is approved, and who may release the line.
This guide shows production, maintenance, engineering, and procurement managers how to combine an asset register, criticality, preventive maintenance, monitoring, local and remote response, spares, backups, cyber controls, safety revalidation, failure drills, and KPI evidence into one industrial robot maintenance contract. It is a vendor-neutral model for comparing offers and managing the transition from FAT/SAT to stable operations.
Why buy recovery capability rather than maintenance visits?
The International Federation of Robotics reported 542,000 industrial robots installed worldwide in 2024. Annual installations exceeded 500,000 for the fourth consecutive year; Asia represented 74% of new deployments, Europe 16%, and the Americas 9%. These figures are market context, not a count of robots installed in Thailand.
Thailand BOI/OSOS reported that investment applications in machinery, automation, and robotics reached about THB 13.1 billion across 82 projects in the first half of 2026. Smart and Sustainable Industry recorded 132 applications worth about THB 17.2 billion, covering machinery upgrades, digital adoption, and automation or robotics integration. These are applications and proposed investment values, not installed robots or realized production results. They nevertheless reinforce the need to make lifecycle support repeatable as automation expands.
A robot cell is more than the arm. Its controller, drives, end effector, fixtures, sensors, PLC, industrial network, safety devices, vision, upstream systems, recipes, licenses, programs, and backups work together. A hotline for the robot alone cannot define responsibility for recovering the cell. The buyer must design the chain from incident intake to production release and assign every link.

Figure 1 exact labels: ASSET REGISTER -> CRITICALITY -> PM / INSPECTION -> MONITOR -> RESPOND -> RECOVER -> REVIEW
Start robot maintenance support with an asset register
“Ten robots” is not an adequate scope. Each cell needs a unique asset ID linked to the information required to identify, restore, and verify it.
| Register field | Why the contract needs it | Example evidence |
|---|---|---|
| Robot, controller, and drive model and serial numbers | Defines coverage and compatible spares | Nameplate photographs, manufacturer parts list |
| Software, firmware, options, and licenses | Defines the recoverable configuration and support horizon | Version list, license register |
| Safety configuration, I/O, and interlocks | Defines post-repair revalidation | Safety-function list, schematics |
| Programs, recipes, and calibration | Provides the approved normal baseline | Approved files, checksums |
| Backup location, date, and restore-test date | Proves recoverability rather than storage alone | Restore-test record |
| Critical spares, storage, condition, and quoted lead time | Shows whether a part will be usable when needed | Inventory and inspection records |
| Obsolescence and vendor support dates | Triggers migration and replacement planning | Lifecycle notices |
| Local skills and authorized personnel | Defines the safe limit of first-line response | Training records, authority matrix |
Classify every asset by production and safety consequence, not purchase price. A cell with no alternative route, a change that requires hazard re-evaluation, or an obsolete long-lead component deserves a higher tier than a redundant cell that uses standard parts and is supported by trained local staff.
Service tiers by criticality
| Tier | Typical condition | Contract emphasis |
|---|---|---|
| Tier A | No alternative; major safety, quality, or shipment consequence | Explicit escalation, critical spares, restore tests, failure drills, time-zone coverage |
| Tier B | Temporary alternative exists, but extended loss is difficult | Preventive maintenance, remote diagnosis, agreed dispatch, shared spares |
| Tier C | Redundant capacity and limited interruption consequence | Planned maintenance, business-hours support, standard lead times |
This avoids buying the same premium SLA for every arm while leaving no gap around truly critical assets. Record why each tier was assigned, when it is reviewed, and which changes trigger reclassification.
Break the industrial robot maintenance scope into outcomes
“Full support” is not a usable scope. Divide it into planned work, monitoring, incident response, recovery, and continual improvement. For each element, specify inputs, tasks, outputs, exclusions, and evidence.
ABB’s official service-agreement page illustrates possible dimensions such as technical and onsite support, preventive maintenance and inspection, fixed-fee labor and spares, condition monitoring, backup management, and asset optimization. ABB also advertises customizable onsite response windows of 4–48 hours. This is an ABB example, not a universal benchmark or a TOMAS TECH commitment. Coverage, hours, people, parts, geography, and exclusions for the actual Thai site require written confirmation.
KUKA similarly illustrates preventive maintenance, repair, spare-parts delivery, hotlines, contracts, remote and onsite service, performance checks, programming, and upgrades. Its published examples include 24/7/365 support, contract-specific response and spares commitments, and secure-VPN remote service. They depend on vendor and contract. A published feature is not automatically a guaranteed service level at the buyer’s site.
Planned maintenance and inspection
Build the preventive-maintenance plan from manufacturer guidance, running hours, duty, environment, failure history, and applicable internal or regulatory requirements. Define the asset, interval, tolerance, measurement, planned stop, replacement criterion, and record—not merely the task name. Evidence should show readings, adverse trends, due dates, and closure.
Apply change control whenever inspection or repair may alter a setting or program. Link the pre-change backup, approver, reason, exact modification, test, rollback, and updated baseline. The objective is to make “who changed what and when” traceable without depending on individual memory.
Monitoring and alarm evidence
Condition monitoring is not valuable merely because a dashboard exists. Define alarms, events, temperature, load, or cycle data; time synchronization; retention; treatment of data gaps; permissions; and the action after an anomaly. An alarm that never creates a ticket, notification, or escalation does not improve recovery.
The contract should state who watches which data, who performs initial triage, how missing data is flagged, what recommendation is delivered, and how history is returned. Where machine data leaves the site, also define the network boundary, storage location, access logs, and data return or deletion at contract end.
Define “response” as seven separate timestamps
Response language causes many robot maintenance contract disputes. “Four-hour response” might mean an acknowledgment, a qualified remote connection, dispatch, arrival, or restoration. Define at least these milestones.
| Milestone | Meaning | Required evidence |
|---|---|---|
| Acknowledgment | Request accepted and ticket opened | Ticket ID and timestamp |
| Qualified remote connection | A person qualified for the asset connects through the approved process | Identity, approval, and session log |
| Technician dispatch | Skills, tools, and parts checked and dispatch authorized | Dispatch record and ETA |
| Onsite arrival | Technician reaches the designated factory point | Entry or arrival record |
| Workaround | Restricted temporary operation is enabled under agreed controls | Constraints and risk approval |
| Restore | Technical fault is corrected and approved configuration restored | Repair, configuration, and test record |
| Verified production release | Safety and process or first-piece checks are approved by authorized personnel | Acceptance sheet and signatures |
Define the clock trigger: phone, portal, or email; required incident data; pauses for missing information; business hours and holidays; remote location; site entry; and customer-caused waiting. A miss should trigger analysis and improvement, such as corrective action or a repeated drill, not only a commercial credit.
Evaluate spares by usability, not “in stock” status
Effective robot downtime countermeasures require more than a spare-parts list. Confirm the part number, firmware and hardware compatibility, storage condition, shelf life, replenishment after issue, tools, and work instructions.
By criticality, distinguish onsite stock, vendor consignment, regional stock, and make-to-order items. Define ownership, price, issue authority, reorder point, counting frequency, warranty start, and obsolescence. Do not invent a lead time; require a written, part-specific quotation that is periodically refreshed.
Practice the replacement. A drive on a shelf is not recoverable without compatible firmware, parameters, an approved backup, a service computer, cables, permissions, and a revalidation plan. Acceptance drills should prove the sequence from issue to safe production release.
Make backup and change control genuinely restorable
A “backup completion” KPI can hide corrupted files, old versions, missing encryption keys, and absent licenses. The managed set should include robot programs, controller settings, PLC, HMI, vision, recipes, calibration, safety configuration, network settings, licenses, and restoration tools.
Link every backup to the asset ID, configuration version, date, operator, change ticket, storage location, integrity check, and restore-test result. Define online and offline storage, separated access, encryption, generations, and disaster access according to site policy. Make one approved normal baseline unambiguous.
A restore test is more than opening a file. In an agreed safe environment, restore and verify communications, I/O, coordinates, tools, recipes, interlocks, safety functions, and process results. Plan sampling by criticality and change frequency. Correct failures and retest them.
Design cyber-safe remote support
Remote access can accelerate triage but permanently open shared accounts create risk. Specify the business purpose, assets, approver, allowed time, identity verification, least privilege, operation logs, command or screen evidence, session termination, and emergency cutoff.
A practical pattern is case-by-case site approval, an approved gateway or VPN, named accounts with multi-factor authentication, and time-limited access only to required assets. Implementation must follow the factory’s IT/OT policy and risk assessment. A vendor statement such as “secure VPN” does not by itself satisfy site authorization, segmentation, monitoring, or retention requirements.
Also drill the no-remote-access case: circuit failure, identity-service outage, absent approver, or expired certificate. The fallback may combine safe phone triage, dispatch, and controlled log export.
Separate technical repair from safety and production release
ISO 10218-1:2025 is Edition 3, published in February 2025, and covers safety requirements for the industrial robot itself as partly completed machinery. ISO points integration and applications to ISO 10218-2:2025. Applicability depends on the system, jurisdiction, contract, and risk assessment. A maintenance contract alone does not establish compliance; cell and application hazards and revalidation responsibilities remain to be assigned between integrator and site. This article is not legal advice.
Clearing an alarm after replacing a component does not prove that coordinates, speed, path, tool, interlocks, protective devices, safety stops, and work quality are back at the approved state. Name who declares technical restoration, who verifies safety, who approves the first piece or process, and who releases production.
The release check should cover the restored backup and version, modifications, applicable safety-function tests, interlocks, low-speed or step checks, dry run, process acceptance, residual restrictions, and enhanced monitoring. A temporary workaround needs an expiry, operating boundary, additional control, and permanent-action due date.

Figure 2 exact labels: DETECT -> TRIAGE -> SAFE STATE -> RESTORE -> VERIFY SAFETY -> RELEASE -> RCA / ACTION, with FAIL -> FIX & RETEST returning to verification.
Run failure drills before accepting the contract
A proposal and contact list do not prove recovery. Before the FAT/SAT-to-operations transition, or at the beginning of a new support contract, safely simulate representative failures and retain evidence:
- Controller or drive fault triage.
- Industrial-network loss and capture of alarms and logs.
- Restoration from the approved backup.
- Issue, replacement, and replenishment request for a critical spare.
- Fallback when remote access fails.
- After-hours intake and escalation.
For every drill, define preconditions, start signal, safe state, expected result, roles, evidence, and pass/fail criteria. Record wrong contacts, insufficient privileges, incompatibility, and missing logs—not only the completion time. A failed test stays open with an owner and due date and must be repeated.
There is no need to damage production equipment. Use simulation, a spare controller, a planned stop, or a tabletop exercise under the factory’s authorization and risk assessment. The point is to prove that people, parts, data, permissions, and procedure form one working chain.
Put a decision matrix in the RFP and support contract
Require every bidder to complete the same matrix by asset and tier. Replace words such as “available,” “standard,” and “extra” with explicit coverage, hours, location, qualifications, deliverables, exclusions, pricing boundaries, and customer prerequisites.
| Scorecard area | Mandatory question | Acceptance evidence |
|---|---|---|
| COVERAGE | Which assets, peripherals, versions, and tasks are included? | Asset and work matrix |
| RESPONSE | What starts and ends each milestone, in which hours, with which exceptions? | Ticket timestamps and escalation log |
| SPARES | Where are parts, are they compatible, what is the quoted lead time, and who replenishes? | Inventory, compatibility list, replacement drill |
| BACKUP | What is saved, by whom, when, and how is restoration proven? | Version register and restore test |
| CYBER | How are remote approval, authentication, privilege, logging, and cutoff controlled? | Session logs and access review |
| SAFETY | What is revalidated after repair and who releases the cell? | Safety and process acceptance sheet |
| DRILL | Which failures are tested, when, and against which pass criteria? | Drill record and retest result |
| KPI | Which data proves trends and recurrence prevention? | Monthly scorecard and RCA due dates |

Figure 3 exact labels: COVERAGE, RESPONSE, SPARES, BACKUP, CYBER, SAFETY, DRILL, KPI
Define price boundaries too: intake, remote work, visits, labor, travel, parts, and out-of-hours work included in a fixed fee versus separately charged consumables, modification, upgrades, unsupported legacy equipment, and third-party assets. “Fixed fee” does not mean unlimited unless limits, exclusions, and approvals say so.
Do not rank vendors by the shortest advertised response alone. Compare evidence that qualified people can reach the actual Thai site with access rights, tools, and parts during the contracted hours. Map boundaries among manufacturer, system integrator, local service partner, and in-house maintenance. For procurement and integration decisions, see our robot system integrator selection guide for Thailand and our collaborative robot implementation guide.
Use KPIs to improve recovery capability
Do not rely on one average. Separate critical from ordinary assets, in-hours from after-hours, remote from onsite, and planned from unplanned work. Useful fields include asset coverage; planned-maintenance completion; alarm and event capture; backup restore tests; spare availability and quoted lead times; remote-access controls; safety revalidation; escalation; drill results; and closure of recurring-failure RCA.
Agree targets from criticality, local conditions, supplier capability, and tolerable interruption. Do not infer downtime, MTTR, availability, payback, or response promises from the figures in this article. Where no reliable baseline exists, agree measurement definitions first, collect evidence, and then revise targets.
RCA is not complete when a report is issued. Track cause, containment, permanent action, replication to similar assets, owner, due date, and effectiveness. Make repeated alarms, repeated replacement, and aging workarounds visible.
Operate monthly and quarterly reviews
Before the monthly meeting, factory and supplier should reconcile asset ID, criticality, incident date, seven response timestamps, parts, configuration changes, safety and quality checks, and open actions from one dataset. Prioritize overdue PM, failed restore tests, stock below minimum, remote-access exceptions, and overdue RCA.
Quarterly, review criticality, legacy support dates, staff changes, contacts, drills, and out-of-scope assets. A new product, fixture, software version, or network design should trigger immediate updates rather than waiting for the next meeting. Name factory owners for contract, equipment, safety, quality, IT/OT, and purchasing, plus supplier owners for service, technical escalation, and parts. Give every role a deputy.
At renewal, evaluate evidence quality and improvement closure as well as price. Customer-caused entry delay, missing information, or denied access may require customer corrective action; supplier staffing, wrong spares, old backups, or repeated diagnosis errors require supplier action. The SLA becomes a common improvement language rather than a blame mechanism.
For mixed-brand or multi-site fleets, map vendor-specific documents to common fields: asset ID, tier, seven timestamps, backup, spares, safety revalidation, and RCA. Targets may differ because geography, shifts, local skills, and product risk differ, but terminology, evidence, change control, and pass criteria can remain standard.
FAT/SAT-to-operations handover checklist
- Current asset, configuration, license, and obsolescence register.
- Approved programs, settings, drawings, operating and maintenance instructions.
- Backup integrity and selected restore tests completed.
- Critical-spare compatibility, storage, stock, replenishment, and quoted lead times recorded.
- Onsite and remote contacts, intake, hours, and escalation tested.
- Cyber controls and no-remote fallback approved.
- Safety-function, interlock, process, and first-piece release criteria and authorities defined.
- Maintenance, failure, change, and drill records and repositories agreed.
- KPI definitions, data sources, review cycle, and corrective action agreed.
Assign owners and dates to every gap. “It ran” and “it can be reproducibly recovered after a failure” are different acceptance conditions.
Frequently asked questions
Should robot maintenance support come from the manufacturer or the SI?
There is no universal answer. A manufacturer may hold deeper product diagnostics, original parts, and software rights; an SI may understand the complete cell, PLC, peripherals, and process. In-house maintenance often owns first response. Assign a lead, backup, and escalation path by asset and failure class so no boundary is empty.
Which spares are the minimum for industrial robot maintenance?
There is no fixed universal list. Evaluate configuration, criticality, environment, obsolescence, supply terms, compatibility, quoted lead time, storage life, and replacement skill. Treat tools, cables, software, licenses, parameters, and revalidation instructions as part of the recovery kit.
Does preventive robot maintenance eliminate unplanned stops?
It reduces risk but cannot guarantee their elimination. Combine it with alarms, backups, spares, contacts, safe restoration, and drills to reduce impact and variation in recovery.
How many hours should a response commitment be?
No one number fits every cell. Decide from criticality, alternative production, geography, coverage hours, skills, part location, and tolerable interruption. Separate acknowledgment, remote connection, dispatch, arrival, workaround, restore, and release. Confirm actual-site terms in writing.
Does remote maintenance remove the need for onsite support?
No. Remote access may help log review and diagnosis, while mechanical failure, wiring, replacement, safety checks, or connectivity loss require onsite work. Define the switching rule and dispatch decision.
Who returns the robot to production after repair?
Technical restoration and production release are different. The factory’s authorized roles must verify applicable safety functions, interlocks, operation, process or first piece, and restrictions. Set responsibilities according to the system, jurisdiction, contract, and risk assessment.
Conclusion: contract for an evidence-backed recovery system
Effective robot maintenance support for a Thai factory connects asset data and criticality to PM, monitoring, response, spares, backup, cyber control, safety revalidation, drills, and KPIs. Separate the seven response timestamps, distinguish repair from production release, and demonstrate the chain before acceptance. That converts vague promises into comparable, improvable capability.
TOMAS TECH can help translate your factory conditions into an asset and tier model, support RFP, responsibility matrix, acceptance drills, and operational handover. Whether you are reviewing an existing agreement or preparing a new cell from FAT/SAT, contact TOMAS TECH to discuss the next step.