The Control Room
Home/Commissioning and change/Proving that alarms and interlocks actually work

Commissioning and change

Proving that alarms and interlocks actually work

An interlock that has never been tested is a design intention. Testing is what makes it a protective function.

10 min read993 wordsUpdated July 2026

Alarms and interlocks are configured, documented and assumed to work. Testing them end to end — from the initiating condition through to the final element — is what establishes that they do, and it is one of the commissioning activities most likely to be curtailed under schedule pressure.

The gap this leaves is specific: a protective function that has never operated will operate for the first time during the event it exists for, which is not the moment to discover a wiring error.

End to end, not by parts

The temptation is to test in sections: verify the input reads, verify the logic evaluates, verify the output drives. Each section passes and the function as a whole is never exercised.

Frequent task switching creates cognitive overhead and increases the chance that small details are missed. Further details are available in this guide.

For process facilities, the surrounding management framework is covered in OSHA process safety guidance.

Full functional testing initiates the real condition at the sensing element — or as close to it as safely possible — and confirms the final element responds. That is what catches the failures at the boundaries between sections, which is where most of them are.

Initiate at the sensor, observe at the final element

Testing the logic by forcing a signal in software verifies the logic and skips the two ends where the errors usually are.

Documenting the test properly

For each function: the initiating condition and the value at which it was applied, the observed setpoint at which action occurred, the observed response of the final element, the time taken, and the reset behaviour.

The observed trip point matters. A function specified to act at eighty percent and observed to act at eighty-three has a discrepancy that needs explaining rather than accepting.

Testing the failure directions

A protective function should be tested not only for correct operation but for correct behaviour when its own components fail.

Loss of signal on the initiating measurement. Loss of power to the logic solver. Loss of instrument air to the final element. In each case, the question is whether the system goes to the safe state and whether that state is what the design intended.

This is where the deferred checks from loop testing come back, and it is the part most often skipped.

Where safety instrumented systems are involved

Functions classified as safety instrumented functions sit under a separate lifecycle with its own requirements for validation, proof testing intervals, documentation and competence, defined in the applicable functional safety standards.

The testing described here is the general engineering practice for control system interlocks. Anything that has been classified as a safety instrumented function is subject to those additional requirements, which are specific, jurisdictionally relevant and not something to improvise around. The governing documents and the site's functional safety management arrangements are the authority, not general practice.

Proof testing after commissioning

Protective functions degrade in service: instruments drift, valves seize, logic is modified. A function tested at commissioning and never again is untested after the first year.

Periodic proof testing at a defined interval, with results recorded and trended, is the mechanism. Trending matters: a valve whose stroke time has doubled over three tests is telling you something before it fails.

Bypasses during testing

Testing protective functions requires bypassing them or accepting that the plant will trip, and bypasses are a recognised hazard in their own right.

The controls are a documented bypass with an owner, a time limit, a register of what is currently bypassed, notification to operations, and a verified restoration. The failure mode is a bypass applied for a test and not removed, which has caused real incidents.

Testing alarms as well

Alarms receive less testing attention than interlocks and are also a protective layer where an operator response is the barrier.

Each rationalised alarm should be verified at least once: that it annunciates at the specified threshold, at the specified priority, with the specified description, and that the response procedure is reachable. This is quick per alarm and worth building into commissioning rather than discovering during the first upset that a description says something meaningless.

Planning the test around the plant state

Functional testing of protective systems is easiest before the plant contains process fluid and hardest once it is running, which argues for completing as much as possible during commissioning.

Tests deferred to a running plant require a bypass, a permit, and a production decision, and they consequently tend to be deferred again. The register of untested functions should be visible during startup authorisation.

Partial stroke and other in-service tests

For final elements that cannot be fully exercised without shutting the plant, partial testing methods exist and provide partial coverage.

The important point is that partial coverage is partial: it demonstrates that some failure modes are absent and not others. Where these methods are used within a functional safety regime, the coverage assumptions form part of the safety calculation and are not a matter for local judgement.

Trending test results

Individual test results establish that a function worked on the day. The sequence of results over years establishes whether it is degrading.

Recording measurable quantities — trip point, stroke time, response time — rather than a pass or fail makes that trend available. A valve whose closure time has increased across three successive tests is giving warning that a pass or fail record would conceal.

Recording the test as evidence

Functional test records for protective systems are examined during audits, insurance reviews and incident investigations, sometimes years later.

That places requirements on the record beyond its immediate use: it should identify the function tested, the method, the measured results, the personnel, the date, and any deviations accepted.

Records kept only as a signed checklist, without measured values, satisfy the immediate need and provide nothing for the later examination.

Testing after modifications

A protective function that has been modified requires retesting, and the scope of the retest should reflect what was changed.

The failure mode is a logic change tested only by inspection, on the basis that the change was small. Small changes to interlock logic have caused real incidents, and functional retesting is the only verification that covers the whole path.

General information. Nothing here is accounting, tax or legal advice. Stock valuation methods, write-off evidence requirements, the tax treatment of losses and the rules on monitoring staff differ substantially between jurisdictions and change over time. Take qualified advice on your own situation.

Related

Continue reading