The short answer
Startup Checklist
A startup is a sequence: confirm the plant is physically ready and the people are in place; verify the control system before it controls anything, with power and control power checked, I/O verified, communications proven, alarms enabled, setpoints entered and checked against the functional description, forces and simulation removed, and a backup taken; energize in stages from the panels to the controllers to the SCADA; start each process in manual under the operator with the automation watching, then hand it to automatic one process at a time; watch the trends and the alarm list through the first cycles and the first shift; and record what was done, what was found, and what was left to fix. The checklist turns a stressful morning into a procedure that two people can walk through in order.
Key points
- Verify before energizing: power, I/O, communications, setpoints, forces, simulation, backups.
- Energize in stages: panels, controllers, network, SCADA, then the process.
- Start in manual with the automation watching; hand to automatic one process at a time.
- A force or a simulation left on is the classic startup failure; the checklist removes every one.
- Watch the first cycles and the first shift on the trends; a startup is not over when the pump starts.
- Record the startup: who, when, what was found, what remains, and the backup taken afterward.
Before startup
- The plant is physically ready: valves in their startup positions, tanks at the levels the sequence expects, chemicals available, equipment released from lockout, and the process engineer agrees it can start.
- The people are in place: an operator at the HMI, a technician at the equipment, a radio between them, and the engineer available.
- The functional description revision that the program was built from is at hand, with the setpoint list.
- The manual operation procedure is at hand in case the startup has to be abandoned.
- Operations and any downstream users have been told the startup is happening and when.
Control system verification
| Item | Check | Done by |
|---|---|---|
| Power | Feeders energized; phase rotation checked on three-phase equipment; control power present at every panel; UPS online and charged | Electrician |
| Controllers | In run mode with no faults; the correct program revision loaded and compared with the backup; the clock synchronized | Engineer |
| I/O | Every input read at the controller with the field device exercised; every output driven and confirmed at the device; loop check records complete | Technician and engineer |
| Forces and simulation | No forced I/O; no simulation blocks or test tags active; the force list on the HMI empty | Engineer |
| Communications | Every controller polled by the SCADA with good quality; every remote site online; every drive and instrument on the network responding | Engineer |
| Setpoints | Every setpoint entered and checked against the setpoint list; limits in place; alarm limits in place | Engineer and operator |
| Alarms | Alarms enabled; suppressions and shelves cleared unless deliberate; notification on and the roster current | Engineer |
| Modes | Every device in the mode the startup sequence expects, usually off or manual | Operator |
| Interlocks and permissives | Verified at the acceptance test; the ones that could have changed since re-checked | Engineer |
| Backup | A backup of every controller and the SCADA taken before startup, so the pre-startup state can be recovered | Engineer |
| Local control | The backup floats, the local controls, and the hand positions proven, so the process is safe if the automation misbehaves | Technician |
Energizing in stages
- 1
Panels
Control power on at each panel; power supplies at voltage; indicator lights as expected; nothing running yet.
- 2
Controllers and I/O
Controllers to run; module status lights good; the I/O reading the field.
- 3
Network
Switches up, links up at the expected speeds, the firewall passing the conduits, remote links established.
- 4
SCADA
Servers up, clients connected, communication status good on every controller, displays showing the plant, the alarm list quiet or explained.
- 5
Drives and starters
Control power to drives; drives ready with no faults; parameters checked against the drive schedule.
Starting the process
- 6
Manual first
The operator starts each piece of equipment in manual from the HMI or the local control, with the technician watching it: rotation, flow, pressure, sound, leaks. The controller sees the running feedback and the process variables change.
- 7
Watch the loops respond
With equipment running in manual, the process variables move; the operator confirms that each reads correctly and each trend moves the right way.
- 8
Hand to automatic, one process at a time
The process most independent of the others first. Place its equipment in auto, watch the controller take it through a cycle, confirm the staging, the setpoints, and the alarms behave per the functional description. Then the next process.
- 9
Sequences
Run any sequence, a backwash or a startup sequence, under observation the first time, step by step, with the supervisor advance available.
- 10
Chemical feeds
Started last in manual at a known dose, verified by drawdown and residual, then to flow pacing with the residual watched.
The watch
- The first cycles of every level and pressure loop trended and watched for staging, cycling, and overshoot.
- The alarm list reviewed every hour for the first shift: every alarm explained, nuisance alarms noted for rationalization.
- Chemical residuals and process quality checked by grab sample against the analyzers.
- Communication statistics reviewed for retries and timeouts.
- Equipment walked for heat, noise, vibration, and leaks after the first hour and the first shift.
- The historian confirmed collecting, and the backfill from remote sites confirmed.
Record
The startup record lists the date, the people, the revision of the program and the functional description, the checklist as completed with initials, the findings and their disposition, the items left open with owners and dates, and the backup taken after the plant settled. It goes in the project file with the acceptance test records, and it is what the next startup, after the next outage, is planned from.
Frequently asked questions
- How is this different from commissioning?
- Commissioning proves the system piece by piece: loop checks, factory and site tests, sequence tests. Startup is the day the process runs on it. Commissioning produces the records that the startup checklist verifies; startup is shorter and repeated after every outage or major change.
- Do we need the full checklist after a power outage?
- The verification section, shortened: controllers in run with the right program, no faults, communications good, forces none, setpoints retained, alarms enabled, modes as expected. Then the process in manual and back to auto. Retentive data lost in an outage is the usual finding, and the setpoint check catches it.
- Who says the process may start?
- The operations supervisor, on the word of the engineer that the control system is verified and of the process engineer that the plant is ready. The control system engineer does not start the process; the operator does, and the checklist is what they agree on before it happens.
- What if the startup goes wrong?
- The operator takes the affected equipment to manual or off, the plant runs on the manual operation procedure, and the engineer diagnoses with the trends and the alarm journal from the startup. The pre-startup backup lets the controller be returned to the state before any last-minute change. The record says what happened and the startup is repeated when the cause is fixed.
Related topics
- Commissioning ChecklistFrom energization to handover: the sequence of commissioning activities for a control system, the prerequisites and records for each, who signs what, and the checklist that keeps a project from being declared finished while half of it has never been tested.
- Site Acceptance TestingProving the installed system with the real field: loop checks first, then end-to-end I/O, real communications, sequences on real equipment, alarms to real recipients, and failure modes on the real network, with the record that becomes the as-built.
- Functional DescriptionsThe system-level document that states what a control system does, organized from the overview down to each piece of equipment in one format: modes, control, setpoints, permissives, interlocks, alarms, sequences, and failure behavior, and how it is used.
- Loop ChecksProving every I/O point end to end before a system goes live: what a loop check is and is not, the three-point analog check, discrete and output checks, the two-person method with the sheet that records it, what to do with a point that fails, and why a loop check is not a calibration.
- Manual Operation ProceduresWritten procedures for running the plant and the remote sites without the SCADA or the controllers: what to read and set by hand, how often to check, what to log, chemical dosing from a flow reading, when to stop, staffing, and the drill that proves them.
- Retentive MemoryWhat survives a power cycle in a controller and what does not, how retention is backed up by battery, capacitor, or nonvolatile storage, what should be retentive, and how retained data gets lost.
Direct contact
Have a controls question?
Reach Eric Sullivan directly about anything on this site, a controls or automation topic, or one of his personal projects.