The Control Room
Home/Running the system/Spares for a system that is no longer manufactured

Running the system

Spares for a system that is no longer manufactured

The spare you need is the one that has been sitting untested in a cupboard since 2011.

9 min read986 wordsUpdated July 2026

Control system spares are held against the failure of items that rarely fail, which makes the holding easy to underfund and easy to forget. The consequence appears when a module fails and the spare is missing, wrong, or does not work.

Deciding what to hold

The basis is consequence rather than failure rate. For each item type: what happens if it fails and no spare is available, how long a replacement takes to obtain, and what that outage costs.

Items where the plant continues to run in a degraded state can tolerate a procurement lead time. Items where a failure stops production, or removes a protective function, cannot.

Workforce optimisation can help planners balance routine operations, maintenance and project work. Further details are available at this link.

Security decisions should also be checked against NIST guidance on operational technology security.

Redundancy changes the calculation but does not remove it: a redundant pair with one half failed is running without redundancy, and the clock on obtaining a replacement is now a risk exposure rather than an inconvenience.

Hold against consequence, not against probability

A module that fails once a decade and stops the plant for six weeks justifies a spare more than one that fails annually and is worked around.

Testing spares on receipt and periodically

A spare that has never been powered is an assumption. Electronic modules fail in storage, batteries deplete, and a module purchased from the secondary market may be faulty or may be a different revision.

Testing on receipt, and periodically thereafter for critical items, converts an assumption into a known state. Where a test rig exists this is straightforward; where it does not, building one is usually justified by the critical spares holding alone.

Firmware and revision compatibility

A replacement module of the same part number may carry different firmware and may not be a drop-in replacement. This is a common and unpleasant discovery during an outage.

The record for each spare should include the firmware revision, and the compatibility position should be established before the spare is needed rather than at the moment of failure.

Configuration is part of the spare

A replacement module without its configuration is not a working replacement. For anything holding configuration — controllers, intelligent devices, network equipment — the current configuration backup is as much a part of the spare as the hardware.

The test is whether someone could take the spare from the shelf, load the configuration and return the plant to service without help. Where the answer depends on one engineer, that is a continuity risk rather than a spares issue.

The secondary market

For obsolete systems, refurbished modules from specialist suppliers are often the only source. This is normal practice and it carries specific risks: provenance, revision mismatch, and units that have already had a long service life.

Buying while availability is good, testing on receipt, and using established suppliers mitigates most of it. Waiting until the part is needed means paying whatever is asked for whatever is available.

Reviewing the holding

Spares holdings drift out of alignment with the plant: modules for equipment that has been removed, gaps for equipment that has been added, quantities set years ago against a different criticality assessment.

An annual review against the current installed base and the current lifecycle position keeps it aligned, and it is the natural point to decide whether to buy ahead of a component going out of production.

Where the spares are

A spare that exists and cannot be located at three in the morning is not available. Storage location, labelling and an accurate register matter as much as the holding itself.

Environmental conditions matter too: electronic modules stored in an unheated store, or without antistatic protection, may not work when needed.

Pooling with other sites

Organisations with several plants running the same platform frequently hold spares independently, which is expensive and produces gaps in some locations and surplus in others.

A shared register, with an agreed transfer arrangement, reduces the total holding required. The practical barriers are usually organisational rather than technical: whose budget bought it, and who gets it when two sites need it simultaneously.

Repair as an alternative

For obsolete equipment, specialist repair of failed modules is often available and is worth establishing before it is needed.

Knowing which repairer handles your platform, what the turnaround is, and whether they can test the repaired unit properly, converts a possible option into a usable one. A failed module sent to an unknown repairer during an outage is a poor position.

Recording what the spare is for

Spares registers frequently list part numbers and not applications. When a module fails, the question is which spare fits, and answering it requires cross-referencing to the installed base.

Recording the application alongside the part — which systems use this module, how many are installed, how many spares are held — makes the register usable under pressure and makes the annual review meaningful.

Spares for the engineering environment

Spares planning covers control hardware and frequently omits the engineering environment: the workstation that runs the configuration software, its operating system, the licence dongle, the installation media.

A site with full control system spares and no working engineering workstation cannot make a change or restore a controller. The engineering environment deserves the same treatment as the control layer, including a tested spare or a virtual image.

Consumables and the things that are not modules

Spares planning concentrates on electronic modules and omits items with a shelf life or a wear characteristic: batteries in controllers and UPS units, filters in enclosures, fans, and the media used for backups.

Several of these fail predictably with age and are cheap to replace on a schedule, which makes them a poor candidate for run-to-failure and a common cause of avoidable outages.

Recording what a failure actually required

When a module fails and is replaced, recording what was needed — the part, the configuration, the tools, the time taken, what was missing — improves the spares holding more reliably than any theoretical review.

Over several years this record becomes an accurate description of what the site actually needs to hold.

General information. Nothing here is accounting, tax or legal advice. Stock valuation methods, write-off evidence requirements, the tax treatment of losses and the rules on monitoring staff differ substantially between jurisdictions and change over time. Take qualified advice on your own situation.

Related

Continue reading