Blog

2026.09.19

Water Treatment Automation 2026: PLC and SCADA Guide

Water Treatment Automation 2026: PLC and SCADA Guide

Successful water treatment automation is not a project to add more sensors or make a more attractive dashboard. It is the engineering of a system that moves pumps, blowers, dosing equipment and valves to a safe state when influent changes, an instrument fails or communications are lost—while still allowing operators to intervene and later reconstruct why each action occurred. This guide is written for industrial wastewater facilities in Thailand. It covers PLC–SCADA boundaries, pump, aeration and chemical dosing control, alarms, fail-safe design, OT security, RFP requirements, FAT/SAT and a practical 90-day implementation. It deliberately avoids duplicating our existing discussion of statutory limits and monitoring points; the question here is how a measured value becomes a safe physical action.

The first water treatment automation decision is the control boundary

The first deliverable should be neither a product list nor a SCADA screen. It should be a control-boundary schedule: which signals are read, which outputs may be written, what causes automatic control to revert to manual, and what must stop or continue after each failure.

LayerPrimary roleTypical assetsWhat the RFP must define
Field instrumentationMeasure process conditionDO, pH, flow, level, pressure, currentRange, accuracy, calibration and failure output
PLC and motor controlMove equipment on a sub-second-to-second basisPumps, blowers, dosing skids, valves, VFDsInterlocks, priorities and safe state
SCADAPresent status, history, alarms and authorised commandsHMI, historian, reports and audit trailWrite authority, alarm response and retention
Business and reportingSupport daily decisions and external reportingMaintenance, laboratory, ERP and reportsSystem of record, approval and accountability

Critical local control normally remains close to the process in the PLC. A SCADA server or corporate-network outage must not make basic treatment impossible. The plant should continue within a tested operating envelope or transition to a defined safe condition. A design in which a cloud connection is required to start a pump adds an operational dependency that must be justified, not hidden.

Why September 2026 matters—and why AI is not the safety authority

In a 15 September 2026 announcement for WEFTEC 2026, Rockwell Automation said it would showcase AI, visualisation, control and cybersecurity technologies for water and wastewater operations. The announcement names several products as exhibits. These are vendor claims and exhibition examples, not independent performance evidence, mandatory requirements for Thai factories, or a guarantee of local availability and support.

The useful procurement signal is therefore not “specify that product.” It is that future RFPs should evaluate analytics, deterministic control, cybersecurity and lifecycle support as distinct capabilities. An AI layer may propose an aeration or chemical-dose setpoint, but deterministic limits, rate-of-change constraints, equipment interlocks and manual recovery remain authoritative. Adoption should require a tested fallback to conventional control when the model is unavailable and change control for every model update.

Do not confuse reporting with wastewater treatment automation

Thailand’s Department of Industrial Works (DIW) has described the use of WPMS measurements and POMS for continuous wastewater monitoring and alerts. That reporting and oversight path has a different purpose from the loop that changes blower speed or stops a dosing pump. A regulatory or reporting value is not automatically suitable for closed-loop control: calibration, response time, missing-data treatment, network path and maintenance responsibility may differ.

Point of comparisonMonitoring and reportingControlRisk if they are confused
PurposeEvidence, visibility and submissionSafe physical actionReporting latency becomes control latency
Time scaleMinutes or longer may be acceptableSeconds to minutes may matterA slow signal causes oscillation
Missing dataRecord and investigate the gapUse a fallback or safe stateLast value drives indefinite output
AuthorityReporting owner or administratorAuthorised operations and maintenanceA data user can move equipment
VerificationData, timestamps and auditabilityInterlocks, stop and recoveryA healthy screen masks unsafe motion

DIW’s factory-environment law index lists notifications covering wastewater, equipment, reporting and environmental personnel and includes 2026 updates. Applicability is not uniform. It depends on factory type, size, process, licence conditions, location and discharge route. This article is not legal advice. Before design approval, check the current Thai text, the factory’s licence conditions and instructions from DIW or the competent authority, and involve qualified environmental and legal specialists where appropriate.

Water Treatment Automation 2026: PLC and SCADA Guide - figure 1

Dividing responsibility among PLC, SCADA and VFD

The PLC owns safe sequence and constraints

PLC logic should implement start and stop sequences, minimum run and rest times, duty/standby rotation, standby changeover and level-, pressure- or motor-based interlocks. Before starting a transfer pump, for example, it should check suction level, discharge-valve state, downstream capacity, motor fault and emergency-stop status. A low DO value must not translate directly into an unrestricted blower command; surge limits, VFD range, valve position and minimum air flow still apply.

SCADA supports operator decisions

SCADA should present the overall process, trends, alarms, command history and controlled changes to recipes or setpoints. Every writable parameter needs a range, role permission and, where risk requires it, a reason and second confirmation. A green “AUTO” label is not enough. Operators need to see which loop is automatic, which unit is in local manual, and which constraint is limiting control.

Our guide to SCADA platform selection and lifecycle cost explains tag models and acceptance evidence. For segmentation and remote-maintenance controls, also see the OT Security for Manufacturing in Thailand guide. A separate factory wastewater monitoring guide covers the monitoring side; this article concentrates on control.

A VFD does not create efficiency by itself

Energy performance depends on the control around the VFD: flow, pressure or DO target; minimum speed; cooling; resonance bands; valve coordination; and restart conditions. The failure action must also be specified. On loss of communications, does the drive hold its last frequency, move to a validated fixed value, or stop? The answer depends on the process hazard.

Pump control must consider the whole transfer path

A level-on/level-off scheme may be an acceptable starting point, but a production system commonly requires:

  • two- or three-pump rotation and runtime balancing;
  • automatic substitution after a duty-pump failure;
  • dry-run, blockage, pressure and overcurrent detection;
  • start inhibition when a downstream tank is high;
  • staggered restart after power restoration; and
  • retention of safety interlocks in manual mode.

Fail-safe does not always mean “stop everything.” If influent continues, stopping all transfer pumps can create an overflow hazard. Conversely, retaining the last chemical-dose output after flow falls can cause overdosing. For every asset, define the safe response to communications loss, sensor failure, PLC fault, power loss and loss of instrument air through a process-risk review.

Aeration control: never wire a DO number straight to a blower

The US EPA’s design material discusses aeration energy conservation and control using dissolved oxygen measurements. It is valuable engineering context, but its numerical examples are not a design basis for every Thai industrial effluent. Oxygen demand depends on influent load, temperature, basin volume, biomass condition, diffuser performance and treatment objective. Setpoints require local data and process responsibility.

Control levelInputsOutputsBenefitPrecondition
Fixed operationSchedule and run commandBlower on/offSimple and transparentConfirm load margin and over-aeration risk
DO feedbackDOVFD frequency or unit countResponds to changing loadSensor fouling, delay and minimum airflow handled
CascadeDO plus header pressure/flowPressure target, blower and valvesCoordinates multiple basinsSurge, valve priority and loop interaction tested
Predictive assistanceAbove plus influent/historyCandidate targetMay act earlierFallback, model monitoring and approval defined

The design must carry the DO instrument’s quality flag, implausible rate-of-change and calibration status. If the sensor is bad, the loop must not trust the last value indefinitely. It should move to a validated fixed or conservative regime. FAT and SAT should establish how much load remaining equipment can carry after one blower fails and what happens when minimum air flow cannot be maintained.

Chemical dosing: separate feedforward flow from quality correction

A practical candidate architecture uses flow-proportional feedforward with a bounded pH or quality correction. Aggressive feedback around a slow pH probe and mixing delay can make acid and alkali doses chase each other. Measure residence time between dosing and sensing, verify mixing, then specify deadband, maximum rate of change and absolute dose limits.

Interlocks should cover zero process flow, low chemical-tank level, leak detection, pump fault, valve position and local-manual status. A concentration or reagent change is a controlled process change—not merely a new screen setting—and should update the calculation, labels, approval and test record.

Alarm design: more alarms do not mean more safety

An alarm is a timed request for operator action, not a list of every abnormal measurement. Adding High and Low to every tag creates floods that hide the critical event. Priority should be based on consequence and available response time. The message should state the condition, first check and prohibited action, not just an instrument code.

Example priorityConsequenceResponse windowNotificationEvidence retained
P1Safety, overflow or major treatment lossImmediateAudible, distinct and continuously staffed pathOccurrence, acknowledgement, action and recovery
P2Reduced capacity or loss of standbyShortSCADA and duty personCause, owner and temporary measure
P3Maintenance need or degradationWithin shiftList and work-management linkWork order, due date and completion
EventCommand or mode changeNo operator response requiredHistory onlyUser, before/after value and reason

Shelving, suppression and disablement require an owner, reason and expiry. FAT should verify not only that an alarm appears, but also duplicate suppression, acknowledgement, recovery, time ordering and behaviour after power restoration.

Water Treatment Automation 2026: PLC and SCADA Guide - figure 2

Make water-treatment OT security a functional requirement

NIST IR 8183 Rev. 2, the Cybersecurity Framework 2.0 Manufacturing Profile, was published on 29 September 2025 as an Initial Public Draft. Its public-comment period is closed, but it is not a final publication at the time of writing. Use it only as voluntary, risk-based input to a manufacturing cybersecurity assessment—not as a legal duty, certification criterion or final normative requirement. ISA/IEC 62443 addresses industrial automation and control systems across asset-owner, service-provider, system and component lifecycles. Neither is a one-product compliance list. They help an owner translate assets, risk and accountability into design, procurement and operations.

CISA, EPA and FBI’s practical actions for water systems include reducing public-internet exposure, maintaining asset inventories, changing default passwords, assessing risk, backing up and restoring systems, planning incident response and training personnel. They are not automatically Thai legal requirements, but they are useful RFP checks.

A minimum zone-and-communications model

  1. Identify field devices, PLCs and VFDs as a control zone.
  2. Separate SCADA and historian services into a server zone.
  3. Put a controlled boundary between OT and business/cloud services.
  4. Permit only required source, destination, port and direction.
  5. Require named accounts, MFA, approval, time limits and recording for vendor remote access.

Security controls themselves must be tested for operational failure. What happens to local control when a firewall fails, time synchronisation is lost, the authentication service is unavailable or the log destination is full? Do not run unplanned active scans or office-IT patch routines against live equipment; use a test environment and approved outage window.

RFP deliverables that make bids comparable

“PLC package” and “SCADA package” are not comparable line items. Specify deliverables and acceptance evidence.

DeliverableMinimum contentFAT evidenceSAT evidence
Control narrative and cause/effectModes, start/stop, fault and recoverySimulation recordPhysical action and operator confirmation
I/O and tag listUnit, range, quality, owner and write permissionPoint-by-point checkLoop-check record
Alarm registerPriority, response and suppressionTrigger, acknowledge and clearValidation in shift operation
Network diagram and flow tableZones, paths, ports and remote accessAllow/deny testsSite configuration match
Backup and restore procedurePLC, HMI, SCADA, VFD and setpointsRestore into clean environmentRestore on designated equipment
Maintenance handoverSource, licences, spares and trainingReceipt registerOwner performs an approved change

If a brand is named because it must integrate with an installed standard, explain the reason and equivalent criteria. Do not turn a WEFTEC exhibit into a mandatory requirement. Write performance requirements for I/O, cycle time, redundancy, environment, maintainability and cybersecurity. Evaluate spare-part lead time in Thailand, support languages, licence renewal and source-code handover.

Ten questions for bidders

  1. How do you distinguish a process upset from equipment failure?
  2. What is the fallback when an instrument quality flag is bad?
  3. Which controls continue after a SCADA outage?
  4. Which interlocks remain in manual mode?
  5. Who can restore the system, from what backup, within what demonstrated time?
  6. Who approves remote support and who closes the session?
  7. Who owns PLC, HMI and SCADA source and credentials?
  8. Which failures can the FAT simulator reproduce?
  9. How will SAT cover conditions that cannot safely be produced with real effluent?
  10. Where are post-handover changes recorded?

Twelve checks before a brownfield modification

In a live water-treatment plant, the as-built drawing and the installed system may not match. A spare terminal shown on paper may already serve another function. Instruments with the same name may use different signal, power, isolation or fault conventions. The survey must therefore establish evidence for design, FAT, SAT, cutover and recovery—not merely confirm that an asset exists.

CheckSite fact to establishRFP/design consequenceFAT/SAT evidence
1. Spare I/OActual use of racks, cards, channels, terminals and cable routesState required cards, panel work and actual pointsI/O reconciliation, terminal photo and loop check
2. Signal type4–20 mA, contact, pulse, communications and NO/NC conventionSpecify input, isolation, scaling and line-fault detectionInject low/mid/high and broken-line states
3. Calibration and qualityHistory, drift, noise, grounding and response delayDefine quality flag, calibration due and filter ownershipReference comparison, trend and bad-quality test
4. Control power and UPSCircuits, hold-up, load and battery conditionDefine which PLC, network and instruments remain poweredPower-loss/recovery timeline and restart result
5. MCC and VFDCircuit, protection, local panel, communications and parametersDefine start/stop, speed reference and fault-reset boundaryRotation, frequency range and fault/reset tests
6. Local/Remote and manualSelectors, buttons, keys and current procedureDefine mode priority and interlocks retained in each modeCause/effect and command record for every mode
7. Safe state on control lossContinued inflow, tank margin and equipment responseDefine safe state separately for PLC, SCADA and network lossFault injection and approved recovery
8. Time synchronisationTime source and drift for PLC, SCADA, analyser and networkDefine NTP, timezone and loss-of-time-source actionCross-system event comparison and resync record
9. Historian and retentionTags, period, compression, capacity, retention and exportSet periods from required evidenceGap, resend, capacity, search and export tests
10. Backup and restoreSource, version, password, licence and replacement hardwareSpecify scope, owner, frequency, storage and restore environmentRestore from a clean copy and compare settings
11. Maintenance accessVendor VPN, modem, shared ID, service PC and persistent pathsRequire named ID, MFA, approval, expiry, record and kill switchAllow/deny, expired access and session log
12. Cutover and rollbackAvailable outage, temporary operation, decision and contactsDefine hold points, go/no-go and preservation of old systemRehearsal, rollback demonstration and sign-off

Verify spare I/O at the terminal, not on the drawing

An allowance such as “20% spare” is not enough to make a decision. Allocate every added DO, pH, flow, level, motor-status and command signal, and verify the card type, channel, terminal, cable route, panel space, heat load and power capacity against the installed system. If the existing PLC cannot be expanded, decide whether to add remote I/O, install a separate PLC, or link another controller to the existing control system. That choice changes the failure boundary and maintenance accountability, so it cannot be made on purchase price alone.

For a 4–20 mA signal, confirm the lower and upper scaling limits, whether an open circuit drives the value low, whether a bad value is held, and whether a signal isolator or splitter exists. For a digital point, confirm Normally Open/Closed convention, wet or dry contact, voltage and pulse width. For a communicating device, the tag list must include not only the protocol name but the register to read or write, update period, quality state, communications timeout and behaviour after reconnection.

Make the control-power and MCC/VFD boundary explicit

A UPS does not establish continuity if it keeps only the PLC alive while the network switch or instrument power fails. Conversely, if the PLC and SCADA remain available while the MCC main circuit is de-energised, a command may remain visible without any physical response. Reconcile the single-line diagram with installed wiring, then define which components survive each power loss, which restart automatically after restoration, and which require an operator confirmation.

Before overwriting an existing VFD, upload and preserve its parameters, motor nameplate data, minimum and maximum frequency, acceleration and deceleration, prohibited frequencies and fault history. Even when the new PLC supplies the speed reference, do not inadvertently defeat local emergency operation, hardwired interlocks or machine protection. FAT should verify the logic with simulated signals; SAT should verify it against actual motor rotation, current, vibration and valve state.

Define Local/Remote priority in operator language

In an installed plant, Local at the panel, Hand at the field station, PLC Auto and SCADA Remote may coexist under inconsistent names. Harmonising the labels is not enough: it remains unsafe if nobody knows which mode has priority, who may change it, or whether the output bumps during transfer. For every mode, document the permitted commands, interlocks that remain active, alarm destination and return condition, and connect them to procedures for normal operation, cleaning, calibration, maintenance and emergency response.

If manual operation is the fallback, demonstrate what the field operator will observe, in what order actions are taken, and how far equipment may be operated after SCADA loss. Hand over local indications, a concise procedure, contact path and decision criteria. Do not make the memory of one experienced operator the recovery system.

Time, history and backup underpin acceptance evidence

If the PLC, SCADA, analyser and network devices disagree on time, the sequence among low DO, blower command, motor fault and operator action cannot be reconstructed. Define the NTP source, timezone, daylight-saving treatment and behaviour when the source is lost, then compare timestamps for the same event across systems during SAT.

“Save everything” is not a historian requirement. Select tags, collection period, compression and retention from the evidence needed for causal analysis and reporting. A fast control variable and a daily reporting value do not need the same period. Also verify what happens when storage reaches capacity: whether old data is overwritten, acquisition stops, or an alarm is raised.

A backup is a recovery capability, not the existence of a file. Align the versions of PLC, HMI, SCADA, VFD, network and analyser configurations, then restore them from a clean copy with the necessary licence, password, firmware and engineering-tool version. After restoration, compare I/O, tags, alarms, permissions, communications and time settings and retain the comparison as acceptance evidence.

Every cutover plan needs rollback criteria

Cutover is not the calendar time at which the new system is switched on. It is one continuous sequence covering backup of the old system, temporary operating arrangements, equipment isolation, I/O transfer order, loop checks, initial filling or real-load validation, go/no-go decision and operating approval. At every hold point, define who reviews which evidence and who has authority to permit continuation.

“Roll back if there is a problem” is not a usable criterion. Define project-specific, observable triggers such as inability to maintain safe treatment, failure to establish critical-signal quality, alarm load beyond operator capacity, or a restore procedure that does not work. Approve removal of the old panel, program and wiring only after stable operation and completion of restore testing. This is how RFP accountability, FAT simulation and SAT verification move a brownfield modification from merely “connected” to genuinely ready for operational handover.

FAT and SAT serve different purposes

FAT is the safe place to expose logic, screen, alarm and fault-sequence defects before shipment. Simulate instrument failure, loss of communications, pump fault, downstream high level and power restoration. SAT verifies field wiring, rotation, valve position, actual communications, operating procedure and interfaces with safety equipment. Passing FAT neither eliminates SAT nor makes SAT a mechanical repeat.

TestNormal caseFault caseAcceptance evidence
Instrument loopSensor to display and historyOpen circuit, out of range, bad qualityCalibration value reconciled to screen
PumpStart, stop and rotationOvercurrent, dry run and standby changeoverTime-series log and witnessed action
AerationDO tracking and stagingBad DO, blower fault and network lossTarget/output/response trend
DosingFlow ratio and maximum limitZero flow, low level and sensor delayDose stop and alarm history
SecurityApproved flow and loginBlocked flow and expired userFirewall, identity and audit logs
RecoveryBackup creationSimulated PLC/server replacementPost-restore comparison

An acceptance case must include input, expected action, tolerance, evidence and approver. Where variable real wastewater cannot be represented during FAT, record the simulation boundary and close the gap through a defined performance-verification period after SAT.

A 90-day plan: 15 + 15 + 30 + 30 = 90 days

Ninety days is suitable for one representative train or basin, not an uncontrolled plant-wide conversion. The arithmetic is explicit: Days 1–15 are 15 days; 16–30 are 15; 31–60 are 30; and 61–90 are 30, totalling 90.

PeriodPrincipal workGate deliverableStop or redesign condition
Days 1–15Survey, P&ID, I/O, operator interviews and applicability checkBoundary, baseline and risk registerAsset responsibility or permit basis unknown
Days 16–30Basic design, cause/effect, alarms, zones and test planApproved design and RFP deltaSafe state or manual operation undefined
Days 31–60Panel/software build, simulation, FAT and training preparationFAT pass, restore test and SAT planMajor fault sequence untested
Days 61–90Installation, loop check, SAT, staged operation and handoverSAT, operating approval and source/proceduresQuality deterioration, alarm flood or failed recovery

Take a baseline from Day 1. Candidate metrics include blower and pump energy, chemical use, alarm count, manual interventions, equipment downtime and process variation in DO and pH. These are examples, not universal guarantees. Normalise for production, flow, temperature and load where possible, and disclose when pre/post conditions differ.

Do not jump directly to full automatic operation on Day 61. Progress from monitoring, to recommendations, to operator-approved moves, to bounded automatic control. Define the rollback trigger and accountable person at every step.

Water Treatment Automation 2026: PLC and SCADA Guide - figure 3

Build the business case from the loss structure, not a promised percentage

Aeration may be a major electricity load, but no supplier should promise one universal saving percentage before measuring the existing plant. EPA material provides useful efficiency concepts, while the outcome still depends on present control, load, blower curves, diffuser condition and operations.

An example calculation structure is:

Annual benefit = energy reduction + chemical reduction + avoided outage loss + avoided emergency maintenance − annual support and licence cost.

Use metered baselines and plant-specific outage cost rather than a supplier’s generic assumption. Environmental harm and non-compliance should not be reduced to an average expected-value calculation; treat them as constraints that the design must prevent.

Common failure patterns

Buying screens before behaviour

Approve the I/O list, cause/effect, modes and fault responses before screen design.

Giving AI final authority

Start with recommendations. Retain independent limits, rate constraints and interlocks, and record training-data period, gaps, seasonality and model version.

Allowing manual mode to bypass everything

Maintenance may need controlled overrides, but safety-critical interlocks should remain. Every override needs authority, expiry, reason, visibility and an audit log.

Keeping backups without proving restore

Test licences, keys and compatible replacement hardware. Include PLC, HMI, SCADA, VFD parameters, alarm registers and network devices.

Treating DIW reporting as the plant control loop

Separate reporting and control paths. Define conversion, timing, gaps, retransmission and ownership. DIW applicability still requires a factory-specific check.

FAQ

Where should wastewater treatment automation start?

Choose one train where loss is material, inputs and results are measurable, and rollback is possible. Pump rotation, DO-based aeration or flow-proportional dosing may be candidates. The correct scope is one that can complete FAT, SAT and operational handover within the pilot.

Can a wastewater PLC run when SCADA is down?

Important local control and interlocks should normally remain in the PLC so the process can continue within a tested envelope or stop safely. Test actual dependencies—including network, licence and time services—during FAT and SAT.

What energy saving should aeration control guarantee?

There is no universal percentage. Establish a baseline normalised for flow or load and measure the pilot. A fixed-speed, over-aerated basin has a different opportunity from a well-tuned existing DO loop.

Does a water treatment control system require AI?

No. Measurement quality, deterministic control, alarms, recovery and asset inventory come first. AI can be evaluated as an advisory layer with a tested fallback.

What is the first water-treatment OT security action?

Inventory assets and paths, reduce internet exposure, remove default passwords, test restoration and control remote support. Use ISA/IEC 62443 and the NIST profile to structure ownership and lifecycle controls.

Does DIW POMS/WPMS apply equally to every factory?

No. Confirm factory category, size, licence and discharge conditions against current DIW material and the Thai source text before each decision.

Summary

Water treatment automation converts measurements into safe, explainable physical action. Keep local control and interlocks in the PLC, use SCADA for operator awareness, history and governed commands, and engineer pumps, aeration and dosing around process delays and equipment constraints. Define RFP evidence, expose faults in FAT, verify the installed system in SAT, and complete a bounded pilot and handover in 90 days. AI and named products may be options; they are not substitutes for fail-safe behaviour, recovery or OT security.

If you are defining a Thai factory pilot, PLC/SCADA boundary, RFP or FAT/SAT evidence, you can contact TOMAS TECH during the planning stage. We can start from the installed equipment and control risk before selecting a product.

References