Blog

2026.08.29

Unmanned Night Factory: Thailand Acceptance Guide

Unmanned Night Factory: Thailand Acceptance Guide

Unmanned night operation in a factory is not a headcount promise. It is an operating claim: the line can detect an abnormality, contain its effects, choose a safe recovery path, and preserve evidence without sending a person into exposure. This guide turns that claim into practical RFP, FAT, SAT, and production-handover gates for factories in Thailand.

Define unmanned night operation by abnormal-event capability

“Unmanned” means different things to different functions. Management may hear labor savings, engineering may hear automatic cycle time, and EHS may hear an uncontrolled facility. Resolve that ambiguity before requesting quotations.

In this guide, unmanned operation means normal production without a continuously present person, within an approved envelope of products, equipment states, materials, utilities, and time. It does not include cleaning, tooling changes, jam clearing, adjustment, inspection inside a safeguarded space, repair, or maintenance. Those servicing activities require a separate mode, energy isolation, verification of a safe condition, and trained personnel.

Use four verbs as the acceptance test:

CapabilityDesign questionTypical acceptance evidence
DetectCan hazards, quality drift, starvation, utility loss, and communication failure be found early enough?Diagnostic tests, sensor coverage, alarm history
ContainCan the event be kept from spreading to people, equipment, WIP, or adjacent processes?Stop sequence, isolation action, quarantine logic
RecoverIs there a bounded path for automatic retry, remote assessment, or on-site repair?State model, authority matrix, restart checklist
EvidenceCan the plant reconstruct what happened and decide product disposition?Event timeline, audit trail, lot links, validated backups

A line that runs only until something goes wrong is not 24-hour manufacturing automation. Approval must be based on abnormal-event capability, not a statement that a shift can be removed.

Set the operating boundary and prohibited activities first

Separate unattended production from servicing and maintenance

No person being present during an automatic cycle does not mean nobody will ever touch the machine. Cleaning, lubrication, replenishment, setup, troubleshooting, and preventive maintenance remain. The RFP should separate automatic production, attended production, safe hold, isolation, maintenance, validation, and restart modes. It should state who can select each mode and which safeguards must be proven before a transition.

U.S. OSHA 29 CFR 1910.147 is a useful reference for hazardous-energy control during servicing, but it is a United States regulation, not Thai law. A Thailand facility must establish applicable Thai legal duties, permits, insurer requirements, and corporate rules with qualified local advisers. Referencing an overseas standard does not by itself establish local compliance.

Limit products, recipes, material states, and duration

Avoid the vague sentence “the line is suitable for unmanned operation.” State the approved part numbers, signed recipes, raw-material conditions, packaging, maximum unattended duration, starting inventory, maintenance status, and required building services. New products and temporary parameters should remain attended until their differences are validated.

BoundaryAllowed exampleReturn to attended mode when…
Product and recipeReleased part number and signed recipeTrial lot, temporary correction, unsigned change
MaterialIdentified lot, enough stock plus marginSubstitute, unknown balance, label mismatch
EquipmentMaintenance current, no unresolved warningBypass active, degraded sensor, overdue work
UtilitiesPower, air, cooling, ventilation, fire systems healthyThreshold approached or partial service loss
AccessSafeguarded area confirmed emptyCleaning, setup, or service is in progress
TimeWithin a validated unattended windowMaximum duration exceeded or handover incomplete

Rework risk assessment for a shift with no local observer

ISO 12100:2010 provides a methodology for machinery risk assessment and risk reduction. ISO’s page says the edition was confirmed current in 2022 and also shows that it is under revision. The value is not the standard number on a purchase order; it is applying hazard identification, risk estimation, inherently safe design, protective measures, and information for use to the actual unattended use case.

During an attended shift, an operator may notice noise, smell, vibration, leakage, heat, or WIP disorder. That informal detection layer disappears at night. “The operator will notice it” cannot remain a credited control. The project must either implement equivalent detection and a safe response or exclude that condition from the unattended envelope.

Do not confuse production logic with safety functions

ISO 13849-1:2023 provides a methodology for designing and integrating safety-related parts of control systems. The required performance is derived from the risk reduction needed; this article cannot prescribe one Performance Level for every application. Emergency stop, gate interlocking, safe speed, safe torque off, or pressure release must be specified and validated as safety functions where the risk assessment requires them, not merely as bits in the standard PLC.

For robot cells, ISO 10218-2:2025 addresses integration, commissioning, operation, and maintenance of industrial robot applications and cells. A compliant robot does not make an integrated cell safe by itself. Tooling, fixtures, conveyors, fences, access points, and upstream/downstream equipment create system-level hazards.

ScenarioLoss or hazardDetectionAutomatic containmentBefore a person enters
Jammed workpieceUnexpected motion, damageTorque, position, cycle timeoutStop, secure energy, prohibit repeated retryIsolate, verify stored energy, use jam procedure
Robot grip failureDrop, collision, mixed qualityGrip switch, vision, weightStop cell, route to reject if safeConfirm cell state and object location
Leak or overheatingFire, release, damageLeak, temperature, smoke, flow balanceIsolate supply, stop zone, coordinate protectionEHS release and medium-specific response
Sensor failureMissed hazard or false goodOpen-wire, plausibility, comparisonFail safe and quarantine productReplace and function-test
Network or server lossLost control or recordsHeartbeat and time-sync monitoringLocal bounded control or defined stopVerify data integrity and known state
Unmanned Night Factory: Thailand Acceptance Guide - figure 1

Build the RFP as layered readiness gates

Treating unmanned operation as a single equipment feature makes proposals impossible to compare. Structure the RFP as gates. A higher layer never compensates for failure of a foundational one.

Gate 1 — safety and local compliance

Require the machine/cell risk assessment, safety requirements specification, validation plan, safeguarding, isolation points, fire/environment interfaces, and a responsibility matrix for Thailand compliance. Put formal reviews by plant EHS, engineering, maintenance, and qualified advisers into the commercial schedule.

Gate 2 — process and quality stability

Preventing escape is more important than avoiding a stop. Define critical quality characteristics, measurement availability, recipe governance, golden samples, rework rules, traceability, and the affected window around an abnormality. The quarantine must extend back to the last demonstrated good point, not merely start at the alarm timestamp.

Gate 3 — reliability and supply continuity

Test wear items, lubrication, tool life, replenishment, reject-bin capacity, air, cooling, extraction, ventilation, and power quality beyond the intended unattended window. Look for clustered micro-stops, intermittent sensors, and empty/full boundary behavior, not only average uptime.

Gate 4 — control, alarms, and recovery

Do not make every signal a red alarm. Classify what can auto-recover, what permits remote assessment, what requires on-site isolation, and what must trigger immediate escalation. Align alarm class with the state model and authority matrix.

Gate 5 — OT security, backups, and evidence

NIST SP 800-82 Rev.3 recognizes OT’s performance, reliability, and safety constraints. Adapt security to those constraints. Define assets, communication paths, identities, remote access, logging, change control, backups, and recovery in terms of their effect on safe and reliable production.

Gate 6 — people and accountability

Name who receives an alarm, acknowledges it, decides whether to dispatch, expands quarantine, authorizes restart, and reviews the night shift. “Call engineering” is not a control if the number, language, authority, and travel time are undefined.

RFP deliverableSupplier responsibilityFactory responsibilityAcceptance evidence
Risk and safety requirementsIdentify equipment hazards and proposed controlsConfirm actual use, local duties, constraintsReview record and disposition of open risks
Cause/effect and state modelDocument logic and event responseOperations, quality, maintenance approve outcomesSimulation and FAT records
Alarm registerTags, cause, consequence, priority, responseDefine roster and response objectivesInjected tests and load test
Backup and recoveryProcedures for PLC/HMI/robot/PCStorage, access, recovery approvalRestore to clean or spare hardware
Quality containmentIdentify and hold affected outputSet disposition authority and criteriaSimulated upset with lot trace
Training and handoverDiagnostic and maintenance materialVerify competence on every shiftPractical assessment records

Rationalize alarms to produce action, not notifications

IEC 62682:2022 covers management of alarm systems presented through control systems and HMIs, and applies to continuous, batch, and discrete processes. The ISA-18.2 series describes an alarm-management lifecycle; ISA-TR18.2.3-2024 addresses basic alarm design.

Forwarding every alert to a phone is not an unmanned-operation design. It buries important events and creates unnecessary dispatches. Every alarm needs a defined cause, consequence, available response time, assigned action, priority, suppression condition, and closure rule.

Alarm-fieldQuestionWeak statementUseful direction
ConsequenceWhat occurs if no action is taken?“Abnormal”Product temperature limit may be reached in ten minutes
PriorityWhat is affected and how soon?Everything is HighClassify by consequence and available response time
ActionWhat should the receiver do?“Please check”Review trend, command allowed stop, notify Quality
ResponseWhen is a decision due?ASAPAcknowledge in 5 min; dispatch decision in 15 min
SuppressionIn which states is it not meaningful?Always enabledEngineered suppression during planned cleaning
ClosureWhat proves resolution?Press ResetCause cleared, safe state confirmed, quality window set

FAT should include alarm-flood scenarios. If low plant air produces 50 actuator alarms, the system should identify the root event and organize consequential alarms without hiding relevant evidence. Suppression must be designed, approved, state-dependent, and logged.

Unmanned Night Factory: Thailand Acceptance Guide - figure 2

Agree stop, containment, and restart as a state machine

“Stop” can mean a production stop, controlled process stop, safety stop, emergency stop, utility isolation, cyber isolation, or quality hold. Define explicit states, transition guards, authority, timeouts, and evidence.

A practical model includes RUN, DETECT, CONTAIN, SAFE HOLD, REMOTE ASSESS, ON-SITE ISOLATION, VALIDATE, RESTART, and QUARANTINE REVIEW. DETECT checks signal plausibility. CONTAIN prevents propagation. SAFE HOLD blocks automatic restart. REMOTE ASSESS exposes only approved information and operations. ON-SITE ISOLATION begins the servicing workflow. VALIDATE proves safety, process, quality, and data before RESTART. QUARANTINE REVIEW is owned by Quality, not by the restart button.

Bound automatic retries

Automatic retry can improve availability, but repeated attempts can enlarge damage or mix suspect product. Permit it only when risk cannot increase, a transient cause can be distinguished, attempts and elapsed time are limited, and every attempt is logged. Repeated gripping, recurrent overcurrent reset, or replay of stale commands after reconnection should default to a hold unless explicitly justified.

Event classFirst actionRemote authorityAutomatic restartProduct disposition
Minor, demonstrated transientOne bounded retryObserve and acknowledgeAllowed within validated limitsAuto-inspect affected cycle
Unknown quality impactStop and establish affected windowView trends; enlarge holdProhibitedHold from last good point
Safety, fire, environmentSafe stop and required escalationNo remote restartProhibitedReview surrounding output
Suspected cyber compromiseSegment communication, reach known stateIncident-response path onlyProhibitedHold until data integrity is proven
Material or utility shortageControlled stop and protect WIPAssess stability and ETAOnly after stable restorationDecide using dwell/time/temperature rules

Put boundaries around remote access

NIST SP 1800-45, finalized in June 2026, demonstrates secure remote-access practices for water and wastewater systems. It is not a factory-specific mandate, but its cross-sector lessons are relevant: combine identity assurance, trusted endpoints, least privilege, session control, monitoring, logs, and rapid revocation.

A VPN alone is insufficient. Avoid shared vendor IDs, permanent tunnels, direct PLC routing, and unrecorded configuration changes. Consider a broker or jump host, MFA, time-bound approval, session recording, and read-only initial privilege.

Remote actionNight responderMaintenance leadSupplierConditions
View dashboardYesYesOnly when approvedNamed ID, MFA, log
Acknowledge/commentYesYesNormally noResponse procedure and synchronized time
Normal stopConditionalYesNormally noConsequences pre-assessed
Reset or restartOnly named low-risk eventsWith approvalSupervised session onlyState checklist and, where required, dual approval
PLC/HMI changeNoUnder change controlTime-bound and supervisedBackup, diff, rollback, FAT/SAT
Safety bypass/changeNoFormal safety change onlyNever aloneReassessment, validation, local isolation

Seeing a camera feed is not proof that the site is safe. Cameras have blind spots and may not reveal odor, slight vibration, floor leakage, or stored material. Define conditions requiring physical inspection so production pressure cannot erode the boundary.

Accept OT backups through restore tests

NIST’s OT security publications list includes the OT Backup Quick Start Guide, SP 1339, released in June 2026. Backups support recovery from ransomware, but also from PLC replacement, HMI storage failure, recipe error, robot replacement, and configuration loss.

A project file in a folder is not a recovery capability. Link firmware, licenses, communications, certificates, recipes, historian databases, accounts, calibration, robot frames, and network-device configurations to an asset register and dependency map.

AssetCapture pointProtectionRestore acceptance
PLC and safety PLCAfter approved change and periodicallySeparated offline/immutable generationsLoad to spare/test CPU and explain I/O differences
HMI/SCADA/industrial PCAfter change, before OS work, periodicallyImage, settings, licensesBoot spare/VM and verify communications/screens
Robot and motionAfter teaching or parameter changeVersioned and tied to machine serialRestore in test or controlled outage
Recipe, quality, history DBAutomated to required RPOEncrypted, integrity checked, separate failure domainSample restore with lot/timeline consistency
Switch, firewall, remote gatewayAfter approved changeSecrets separated; configuration diffsRestore spare and test paths/deny rules

RPO and RTO affect product decisions. If 30 minutes of history can be lost, that output needs a defensible quarantine rule. If recovery needs eight hours, SAFE HOLD and a morning handover may be safer than improvised remote restart.

Include materials, utilities, fire, and environment

An automated cell still stops when material runs out, air pressure falls, cooling is lost, or reject capacity fills. Extend scope beyond the cell to every service needed through the unattended window.

For materials, assess quantity sensing, usage variance, misfeed, wrong loading, splice points, empty-container flow, scrap collection, and label verification. Define where WIP stops, how dwell and temperature limits continue to be monitored, and what is discarded after restoration.

For utilities, set separate warning and trip thresholds for power, UPS, compressed air, cooling water, steam/gas where used, dust extraction, ventilation, HVAC, network, and time synchronization. SAT should test partial loss, gradual degradation, and upstream/downstream mismatch.

Fire detection, suppression, smoke management, emergency notification, drainage, bunding, and spill response must align with plant EHS, building systems, permits, and local emergency arrangements. Production shutdown must not disable protective functions; protective activation must place production in an appropriate safe state.

Accumulate evidence through FAT, SAT, and handover

FAT: inject failures, not only good cycles

Inject open-wire and stuck sensors, communication delay, clock offset, empty/full states, air and cooling loss, vision uncertainty, robot grip failure, database loss, and remote-session interruption. Where physical injection would be unsafe, use simulation or signal injection and record the limitation.

FAT testPass conditionEvidence
Sensor failureDiagnosed in required time, safe response, no false-good outputI/O log, video, event timeline
Alarm floodRoot event visible; critical notification not buriedAlarm summary and receiver record
Communication lossLocal logic reaches defined state; no duplicate commandPLC/network logs and state trace
Power recoveryNo unauthorized automatic start; recipe/time/WIP consistentStartup checklist and audit log
Backup restorationClean/spare environment runs; all differences explainedRestore record, hash, approval
Quality containmentAffected output traced from last good point and blockedLot query, hold status, MES record

SAT: test the actual Thailand factory environment

Verify power quality, latency, temperature/humidity, dust, lighting, material variation, local-language alarms, shift structure, building protection, and upper-level interfaces. Do not accept only while supplier engineers are standing beside the line. The plant team must receive, decide, contain, and hand over an event themselves.

A continuous run should cover product mix, declining inventory, planned fault injection, shift handover, remote duty, quarantine, and morning review—not only a headline number of hours without stopping. Duration is a risk-based project decision, not a universal legal threshold.

Production handover: distinguish technical completion from operating readiness

A working machine is not ready for unmanned production if rosters, spares, restores, escalation, disposition, or change control are incomplete. Maintain separate technical and operating punch lists. Keep attended operation until every item that can invalidate an unmanned claim is closed.

Unmanned Night Factory: Thailand Acceptance Guide - figure 3

Use a 30/60/90-day staged validation

The following is illustrative, not a market norm or mandatory timeline. Adapt it to process risk, product, competence, legal review, and available evidence.

PeriodOperating scopeAccountable ownerExample go condition
Days 0–30Fault validation under attended operationEngineering, EHS, QualitySafety validation complete; state tests pass; no critical open item
Days 31–60Short unattended windows with nearby responseProduction, Maintenance, IT/OTAlarm response, quarantine, restore, and handover meet targets
Days 61–90Limited products through night operationPlant manager and function headsRepeatable across shifts; dispatch logic works; no critical escape
After day 90Expand envelope through change controlChange boardDifference assessment before every product/time extension

Make shift handover part of the control loop

Before release, review unresolved alarms, bypasses, maintenance due dates, inventory, holds, recipe, utility/weather concerns, responder coverage, communication, and backups. In the morning, review micro-stops, retries, disconnects, manual operations, remote sessions, quarantines, and sensor diagnostics—not only production quantity.

Handover areaBefore unattended releaseMorning review
Safety/equipmentNo bypass; guards healthy; maintenance currentStops, safety demand, diagnostics
QualityReleased recipe; inspection available; hold capacityDeviations, retest, hold range, disposition
Material/logisticsQuantity, labels, empty/reject capacityStarvation warning, jam, scrap, inventory variance
OT/dataTime, storage, network, backup healthyDisconnects, remote operations, changes, missing data
OrganizationRoster confirmed; call tested; access route knownResponse time, decision quality, assigned improvement

Decide go/no-go with gates and metrics

A scorecard can expose disagreement, but it must never average away a critical hazard. The following is illustrative. Unvalidated safety functions, unresolved local compliance, unapproved fire/environment interfaces, failed quarantine, untested restoration, or no accountable responder are automatic no-go conditions.

DomainIllustrative weightMeasureMandatory gate
Safety/compliance25Open risks, function tests, isolation procedureNo unresolved critical item
Quality/traceability20Last-good point, containment, inspection availabilityNo path for suspect escape
Reliability/supply15Stops, material margin, utility responseContainment through unattended window
Alarms/recovery15Response, nuisance, retry, safe-hold successNo missed critical alarm
OT/backup15Access, logs, restore, approved changesSuccessful restore test
People/handover10Competence, calls, response, reviewEvery shift demonstrated competence

Define denominator and observation window for every metric. Useful candidates include response to high-priority alarms, nuisance ratio, bounded retries, successful SAFE HOLD transitions, completeness of quarantine, approved remote sessions, successful restore exercises, and completed morning reviews.

An illustrative, plant-specific economic frame is:

Annual value = avoidable night-shift cost + recoverable production capacity − added maintenance − duty coverage − connectivity/security − expected downtime and scrap loss.

This is not a market statistic. Document assumptions, sensitivities, downside cases, and owners. Labor savings alone ignore dispatch, spares, restore capability, cybersecurity, and quality-hold costs.

Thailand BOI reported 1,300 approved applications worth THB 1.31 trillion in the first half of 2026, including THB 17.2 billion for projects improving productivity through machinery, digital systems, and automation. This is context for Thailand’s investment environment, not proof of ROI for any unmanned line. Eligibility and benefits require project-specific confirmation.

Questions to put into an automation RFP

  1. Which abnormalities do operators currently detect through sound, smell, sight, or touch, and what replaces that detection?
  2. From which risk assessment are safety functions derived, and who validates them?
  3. How is the last good point established, and can affected output be automatically held?
  4. What occurs to equipment and WIP during material, reject-capacity, air, cooling, or extraction loss?
  5. Which events permit automatic retry, how often, for how long, and when is it prohibited?
  6. Who can view, stop, reset, restart, and change remotely, and is every session recorded?
  7. How quickly can PLCs, HMIs, robots, industrial PCs, recipes, and network settings be restored—and where is the restore evidence?
  8. Who owns escalation for fire, spill, ventilation loss, or suspected cyber compromise?
  9. Which failures are physically injected at FAT/SAT and which are simulated?
  10. Who decides continuation at days 30, 60, and 90, using which metrics?

Before issuing an RFP, review the common failure risks in Thailand automation projects. If controller age and backups are uncertain, use the Thailand PLC replacement and retrofit guide to establish a baseline. Applications that mix people and robots also benefit from the collaborative robot implementation guide.

Frequently asked questions

Can an unmanned night-operation factory truly have zero workers?

The defined production area may operate without a continuously present operator, but maintenance, cleaning, preparation, quality disposition, and emergency response remain. Bound the claim by product, time, and equipment state. Define conditions for dispatch and a safe hold when no one should restart remotely.

Which failures should a 24-hour automation project test first?

Let risk assessment set priority. Common candidates include power, network, air and cooling loss; starvation; jams; sensor failure; unavailable quality inspection; fire or leak; and interrupted remote access. Test detection, containment, evidence, and recovery—not only endurance during normal cycles.

What is the minimum preparation for factory automation under a labor shortage?

Standardize the process, inventory OT assets, characterize hazards and quality risks, collect stop-reason data, define materials/utilities, and appoint accountable owners. Automating unstable work can reproduce variation faster. Identify every abnormal cue currently supplied by a person.

Can the business case for labor-saving equipment use labor cost alone?

No. Include capacity, yield, downtime, added maintenance, spares, responder coverage, connectivity, cybersecurity, quality quarantine, and training. The formula in this article is illustrative, not an industry average. Test several availability and scrap scenarios without reducing safety or quality gates.

Does remote PLC reset eliminate night dispatch?

No. A remote screen may not show leakage, odor, dropped material, or the state inside a guard. Pre-authorize only defined low-risk events, limit retries, require evidence and logs, and dispatch for safety, fire, environmental, unknown quality, and cyber conditions.

Is U.S. OSHA lockout/tagout law directly applicable in Thailand?

OSHA 29 CFR 1910.147 is U.S. law, not Thai law. It can inform hazardous-energy thinking, but the facility must confirm Thai legal duties, permits, insurer conditions, and corporate standards locally, then document machine-specific isolation and restoration.

Conclusion: acceptance is proven when abnormal events occur

The value of unmanned night operation is not the absence of a person; it is expanding productive time without sacrificing safety, quality, or control. Write the operating boundary and accountability into the RFP, inject faults at FAT, test actual factory conditions at SAT, and validate in staged production gates. Approve only when detection, containment, recovery, and evidence remain effective—and keep servicing work in a separate isolated mode.

TOMAS TECH can help factories in Thailand assess readiness, translate operating risks into RFP/FAT/SAT criteria, and define responsibilities across PLC, robot, MES, maintenance, quality, and OT security. Early concepts and single-line pilots are welcome through our contact page.

Research / Sources