The Control Room
Home/Commissioning and change/Documentation that still matches the plant

Commissioning and change

Documentation that still matches the plant

Every site knows its drawings are out of date. Very few know by how much, or which ones.

9 min read950 wordsUpdated July 2026

Control system documentation begins accurate at handover, assuming the as-built exercise was done properly, and degrades from that point at a rate determined by how many changes are made and how reliably they are recorded.

After a decade the typical state is that some documents are current, some are years behind, and there is no way to tell which is which by looking at them.

The cost of not knowing

The practical consequence is that engineers verify everything in the field before acting, because they cannot trust the drawing. That is sensible behaviour and it means the documentation provides no time saving at all, which is its entire purpose.

Clear ownership matters in administrative workflows just as it does in control-room operations. Further details are available through this reference.

For process facilities, the surrounding management framework is covered in OSHA process safety guidance.

The more serious consequence appears during troubleshooting under time pressure, when there is no opportunity to verify and a wrong drawing leads to a wrong action.

What has to be maintained

  • Loop drawings and wiring: field device to terminal to card to channel.
  • The I/O schedule: what is connected where, with spare capacity marked.
  • Network architecture: what is connected to what, with addresses.
  • Control logic and its source.
  • The graphics set and its source.
  • The alarm database with rationalisation records.
  • Control narratives and interlock schedules.
  • The tag register, with descriptions and ranges.
  • System software inventory: versions, patch levels, licences.

The last is the one most often absent and the first thing needed when a vendor asks what version you are running, or when a vulnerability advisory arrives and the question is whether it applies.

Marking currency explicitly

The cheapest improvement available is to put a revision date and an owner on every document, and to record when it was last verified against the plant.

A drawing marked as verified last month is usable. The same drawing with no date is a guess, even if it happens to be accurate. The marking costs nothing and changes how the document is used.

Update at the change, not in a campaign

Documentation catch-up projects are periodically funded, complete, and then decay again over the following years because the mechanism that caused the drift is unchanged.

The only durable approach is that a change is not closed until the affected documents are updated. That requires the documents to be easy to edit, which in turn argues against formats that require specialist software or an external contractor.

Field verification on a cycle

Even with a good change process, drift occurs through undocumented changes and errors. A periodic verification of a sample — a proportion of loops each year, checked against the drawings — measures the drift rate.

The number found is diagnostic. A sample where nearly everything matches suggests the process works. One where a significant fraction is wrong suggests undocumented changes are routine, which is a different problem from a documentation problem.

One authoritative location

The recurring practical failure is several copies: a drawing on the network, a marked-up print in the control room, a version in the contractor's system, and a scan in a document management system.

They diverge, and each user consults whichever is nearest. Declaring one location authoritative, and physically removing or clearly marking the others, resolves more confusion than any amount of updating.

Accessible where the work happens

Documentation stored in a system that requires a desktop, a login and a search is documentation that will not be consulted by a technician in the field at midnight.

Making the current drawing set available on a mobile device, or at minimum on a terminal in the control room, is a small change that substantially increases the chance it is used — which is also the mechanism by which errors in it get reported.

The formats that survive

Documentation held in proprietary formats requiring specific software versions becomes unreadable over the life of a plant. Drawings produced in a CAD package two versions obsolete, held only as native files, are a risk.

Keeping a rendered copy in a durable format alongside the editable source addresses it. The source allows updates; the rendering guarantees the document remains readable.

Documentation during an outage

Turnarounds generate a high volume of change in a short period, under pressure, which is exactly the condition in which documentation updates are deferred.

The practical mitigation is a mark-up discipline during the outage — every change recorded on a marked print at the time — with formal update afterwards. This is far more achievable than formal update during the outage and far better than reconstruction from memory.

Making gaps visible

A documentation set with unknown accuracy is used defensively. One where currency is marked per document allows the user to know which parts to trust.

A simple status indication — verified date, last change date, owner — on each document, and a summary showing which documents are overdue for verification, turns a vague concern into a work list.

Documentation ownership after the project

During a project, documentation has an owner because someone is contractually responsible for producing it. Afterwards, ownership frequently lapses.

Assigning a named owner per document type — loop drawings, network diagrams, narratives, the tag register — at handover is what keeps the maintenance obligation attached to somebody.

Where no owner exists, the documents are maintained by whoever happens to need them, which produces exactly the mixed accuracy that makes the whole set untrustworthy.

Prioritising which documents to trust

Bringing an entire documentation set up to date is rarely fundable. Prioritising is possible and is rarely done deliberately.

The documents worth verifying first are those used during abnormal situations and those covering protective functions: interlock schedules, loop drawings for safety-related loops, network diagrams, and the emergency response information.

A partial set that is known accurate for the critical systems is more valuable than a complete set of uncertain currency.

General information. Nothing here is accounting, tax or legal advice. Stock valuation methods, write-off evidence requirements, the tax treatment of losses and the rules on monitoring staff differ substantially between jurisdictions and change over time. Take qualified advice on your own situation.

Related

Continue reading