Control Systems Integration and Testing

Read revision 3

Revision 3 · Aug 26, 2026 +38 −17

Corpus sync: neutrality remakes, note hygiene, datasheet relocation, transformer-split cross-refs
Showing changes from Rev 2 to Rev 3 in Control Systems Integration and Testing.
---
title: Control Systems Integration and Testing
93 unchanged lines
- "Cybersecurity configuration plan (ISA/IEC 62443)"
- "Operator and maintenance training plan"
default: [Division-of-responsibility matrix, Control narratives / process control descriptions, Complete I/O list by controller and process system, FAT plan and procedures (ISA-62381), SAT, loop check, PVT, and endurance test plans]
+default:
+ - "Division-of-responsibility matrix"
+ - "Control narratives / process control descriptions"
+ - "Complete I/O list by controller and process system"
+ - "FAT plan and procedures (ISA-62381)"
+ - "SAT, loop check, PVT, and endurance test plans"
```
33 unchanged lines
- "Operation and maintenance manuals"
- "Training records"
default: [As-built control narratives (final tuned values), As-built I/O list and tag database, Signed FAT, SAT, loop check, PVT, and endurance test reports, Instrument calibration records (as-found / as-left), Operation and maintenance manuals]
+default:
+ - "As-built control narratives (final tuned values)"
+ - "As-built I/O list and tag database"
+ - "Signed FAT, SAT, loop check, PVT, and endurance test reports"
+ - "Instrument calibration records (as-found / as-left)"
+ - "Operation and maintenance manuals"
```
42 unchanged lines
## Responsibility Matrix {toc}
### A division-of-responsibility matrix shall be prepared and agreed at the pre-integration conference, assigning for every device and subsystem the furnish, install/wire, program, and test responsibility. {note}
+### A division-of-responsibility matrix shall be prepared and agreed at the pre-integration conference, assigning for every device and subsystem the furnish, install/wire, program, and test responsibility.
```datasheet
6 unchanged lines
default: "Engineer of Record authors the control narratives; integrator implements (typical for design-bid-build)"
```
### The control narrative is the contractual blueprint that the programmer implements; the party who authors it shall be identified in the matrix so that the integrator is not asked to invent process intent that belongs to the Engineer of Record. {note}
+### The control narrative is the contractual blueprint that the programmer implements; the party who authors it shall be identified in the matrix so that the integrator is not asked to invent process intent that belongs to the Engineer of Record.
```datasheet
22 unchanged lines
## Narrative Content {toc}
### Each control narrative shall address, at minimum, the following: {note}
+### Each control narrative shall address, at minimum, the following:
- Process purpose and the equipment served, referenced to the P&ID
21 unchanged lines
- "Off / locked out"
- "Cascade / remote setpoint (where a loop's setpoint is driven by another loop)"
default: [Automatic (closed-loop or sequenced, normal operation), Manual (operator sets output directly at the HMI), Local (control at the field device or local control station, SCADA monitoring only), Off / locked out]
+default:
+ - "Automatic (closed-loop or sequenced, normal operation)"
+ - "Manual (operator sets output directly at the HMI)"
+ - "Local (control at the field device or local control station, SCADA monitoring only)"
+ - "Off / locked out"
```
### Every controlled loop and device shall support, at minimum, automatic, manual, and local/off modes, with the active mode displayed at the operator interface.
75 unchanged lines
### The software shall be verified against the functional requirements (the control narratives and the I/O list) through the FAT and SAT process, consistent with the verification and validation framework of IEEE 1012.
### A function commanded by a control narrative but not demonstrated in a test case is unverified; the test plans shall trace every narrative step and every I/O point to a test case. {note}
+### A function commanded by a control narrative but not demonstrated in a test case is unverified; the test plans shall trace every narrative step and every I/O point to a test case.
# Third-Party and Packaged Equipment Integration {toc}
157 unchanged lines
## Loop Checks and Point-to-Point Checkout {toc}
### A loop check (point-to-point checkout) shall be performed on every I/O point, verifying continuity from the field device through the wiring and controller to the correct, correctly scaled, correctly named indication at the operator interface. {note}
+### A loop check (point-to-point checkout) shall be performed on every I/O point, verifying continuity from the field device through the wiring and controller to the correct, correctly scaled, correctly named indication at the operator interface.
### Each analog input loop shall be verified by injecting or driving a known value at the field device and confirming the reading and scaling at the HMI, and each analog output loop by commanding a known output and confirming the final element responds.
14 unchanged lines
- "Fail-safe position verification (loss of signal and loss of power)"
- "Alarm and interlock verification per point"
default: [Per-loop checkout sheet (tag, signal injected, expected vs. actual, pass/fail, sign-off), Instrument calibration record (as-found / as-left vs. traceable reference), Valve/actuator stroke and travel record vs. command, Fail-safe position verification (loss of signal and loss of power)]
+default:
+ - "Per-loop checkout sheet (tag, signal injected, expected vs. actual, pass/fail, sign-off)"
+ - "Instrument calibration record (as-found / as-left vs. traceable reference)"
+ - "Valve/actuator stroke and travel record vs. command"
+ - "Fail-safe position verification (loss of signal and loss of power)"
```
## Performance Verification Test {toc}
### Following successful loop checks and SAT, a performance verification test (PVT) shall be performed to demonstrate that the integrated system performs its sequences correctly under live process conditions. {note}
+### Following successful loop checks and SAT, a performance verification test (PVT) shall be performed to demonstrate that the integrated system performs its sequences correctly under live process conditions.
### The PVT shall exercise every control narrative under actual operation — automatic control, mode transitions, lead/lag/standby rotation, interlocks, permissives, and the response to induced abnormal conditions — and shall demonstrate control loop stability and tuning under load.
3 unchanged lines
## Endurance Test {toc}
### An endurance test shall be performed after the PVT to demonstrate that the integrated system operates continuously and reliably over a sustained period without unexplained failure. {note}
+### An endurance test shall be performed after the PVT to demonstrate that the integrated system operates continuously and reliably over a sustained period without unexplained failure.
```datasheet
14 unchanged lines
# Startup and Commissioning {toc}
## Commissioning shall proceed in the sequence — FAT, installation, loop checks with calibration and stroking, SAT, PVT, then endurance test — with each phase complete and documented before the next begins. {note}
+## Commissioning shall proceed in the sequence — FAT, installation, loop checks with calibration and stroking, SAT, PVT, then endurance test — with each phase complete and documented before the next begins.
## The integrator shall coordinate commissioning with the electrical and mechanical/process trades, the packaged-equipment vendors, and the Commissioning Authority where one is engaged, so that equipment is available and energized when each phase requires it.
26 unchanged lines
- "Cybersecurity awareness for OT (account, patch, removable-media policy)"
- "Recorded training sessions retained for future staff"
default: [Operator training (narratives, HMI, alarms, modes, routine operation), Maintenance training (I/O, loop diagrams, troubleshooting, calibration), Configuration management and backup/restore training]
+default:
+ - "Operator training (narratives, HMI, alarms, modes, routine operation)"
+ - "Maintenance training (I/O, loop diagrams, troubleshooting, calibration)"
+ - "Configuration management and backup/restore training"
```
### Training sessions should be recorded and the recordings turned over to the Owner so that staff hired after commissioning can be trained on the as-built system. {note}
34 unchanged lines
### The integrator shall turn over to the Owner the licensed development and configuration software, the source configuration for every controller and the SCADA/HMI application, and the documented procedure to restore the system from backup.
### The Owner shall receive the rights and the media necessary to maintain and modify the delivered control system without dependence on the integrator, subject to the platform licensing.
### Turning over only compiled runtime without the source configuration leaves the Owner unable to make even trivial changes; the controlled source configuration is a required deliverable. {note}
```datasheet
label: Software and Configuration Turnover
7 unchanged lines
default: [Licensed development/configuration software for controllers and SCADA, Source configuration for every controller program, Source configuration for the SCADA/HMI application and graphics, Documented backup/restore procedure and verified backup media]
```
+
+### The Owner shall receive the rights and the media necessary to maintain and modify the delivered control system without dependence on the integrator, subject to the platform licensing.
+
+### Turning over only compiled runtime without the source configuration leaves the Owner unable to make even trivial changes; the controlled source configuration is a required deliverable. {note}

View current revision