Brownfield Control System Modernization | Lessons from a Recent Project
Introduction | Our Lessons Learned Debrief
October 2026 - aeSolutions Technical Team — Many companies run a lessons learned debrief after a difficult project. Very few publish what comes out of it.
aeSolutions recently closed out a large brownfield modernization project. The scope covered control system migration, safety system upgrades, electrical infrastructure modifications, and startup support. Several phases of the work were more difficult than they should have been, and our team held a debrief afterward to understand why.

Validate Existing Documentation Before Design
One of the most notable lessons from our debrief was the importance of thorough front-end planning, particularly validating existing documentation against actual field conditions.
In operating facilities, modifications are often made under time pressure and never added to the drawings. Devices get swapped for whatever is available. Wiring gets rerouted during a turnaround, and the only person who knows about the change is the electrician who did the work. Each of these is a gap in change management, and over years of operation they accumulate.
Proposals, budgets, and schedules are all built on documentation. When the documentation is inaccurate, the estimates based on it are inaccurate too. Field teams then spend days, or weeks, tracing wire, verifying device function, and reconciling drawings against field conditions, time that was never in the plan.
Like most effective solutions, the fix is unglamorous. Before detailed design begins, assess the site and validate the existing documentation against what is installed in the field. Verifying documentation ahead of time costs money, but doing so during an unplanned, extended outage with the clock running and the client’s leadership team asking, every day, when they can have their plant back is far more costly. This work belongs in front end project development, before optimistic assumptions get locked into a budget.
Identify and resolve all interfaces with systems that are staying in place. Confirm how equipment is operated today, which devices and equipment function properly, which do not, and which are running in bypass. Then understand what new functionality operations desires from the new system, which of those functions are proven through experience from other production lines, and which are going to be mini-R&D efforts during startup. Establish clear project boundaries and decide whether the work will be phased.
Build the Shutdown Schedule from Field Conditions
Shutdown windows are coordinated with production planning, sometimes years ahead. That is a legitimate business constraint. The trouble starts when the shutdown duration is reverse engineered to fit an artificial production condition without regard for the actual field conditions.
A control system migration cutover schedule has to account for wiring migration, field verification, I/O checkout, device troubleshooting, commissioning, startup testing, and punch list resolution. Each of these has a duration that can be estimated from measurable work: points to check, terminations to make, and loops to verify. When schedules are built from those metrics, the shutdown duration presented to production is based on the actual scope of work.
Reserve time for discovery, since brownfield projects often uncover unexpected conditions. A schedule with no room to absorb surprises will absorb them out of testing.
Readiness Is a Decision
A recurring issue during the project was that multiple prerequisite activities had not been completed before startup support arrived on site.
A formal readiness review before mobilization can prevent this. The review should verify installation completion, cable routing and termination, device calibration, conduit installation, power availability, contractor readiness, and safety system verification. It should produce a documented and approved go- or no-go decision.
Facilities operating under OSHA Process Safety Management already have a version of this in the pre-startup safety review (PSSR) required by 1910.119(i), which confirms that construction and equipment match design specifications and that procedures and training are in place before highly hazardous chemicals are introduced. An established PSSR process within your PSM program can serve as a model. A commissioning readiness checklist applies the same logic earlier, before the decision to mobilize.
A checklist moves the difficult conversation earlier, when the plant is still running and delaying the shutdown, if necessary, is still an option.
Define Ownership, Especially During Startup
Brownfield modernizations involve plant personnel, engineering contractors, electricians, system integrators, and specialty subcontractors, often working in the same areas at the same time. Without clearly assigned ownership, the results can include duplicated effort, tasks left undone because each party assumed another had them, conflicting work in the same area, and miscommunication during startup. Responsibility for construction, testing, troubleshooting, documentation, and startup support should be defined before mobilization.
Configuration control is especially important during commissioning. When several people can modify the control system configuration, system integrity becomes difficult to guarantee. Controlled access procedures, configuration management, a single owner for programming changes, tracked forces and bypasses, and defined startup authorization reduce that risk.
The same discipline applies to scope changes, which are common on brownfield projects as field conditions become known. Additional instrumentation, revised control strategies, changed operational expectations, and unexpected interfaces are typical examples. A structured change process keeps design, documentation, programming, and field work aligned as changes occur. Changes made informally during commissioning, agreed to verbally and never documented, create confusion and increase risk. Sites with PSM covered processes already have a framework for this in the management of change requirement at 1910.119(l), and the same rigor is worth applying to the automation scope even if the process is not covered.
Make Factory Acceptance Testing Reflect Plant Conditions
Factory acceptance testing (FAT) is an important quality check before installation. A FAT limited to the expected sequence only confirms that the system works under normal conditions.
Effective factory acceptance testing includes failure scenarios, device fault conditions, restart behavior, interlock verification, and abnormal operating situations. Where practical, include operations and maintenance personnel in the test. They are likely to test conditions the design team did not consider, and problems found during FAT are easier to correct than problems found during startup.
The closer factory acceptance testing comes to real plant conditions, the fewer surprises during startup.
Safety Considerations for Brownfield Work
Legacy facilities can contain unknown wiring conditions, undocumented modifications, and equipment that has evolved over decades. The conditions that complicate the schedule also increase risk to personnel during execution.
Formal lockout and tagout procedures, clearly defined startup authority, an actively reinforced stop work authority, verification of field device status before work begins, and validation of safety instrumented functions all carry more weight here than on a new build where energy sources have not yet been introduced. Establish these expectations at kickoff and reinforce them through commissioning and startup.
Commissioning Readiness Checklist
Before startup support mobilizes, confirm and document each of the following:
• Installation work is complete and verified against approved drawings
• Cable routing and terminations are finished and checked
• Conduit installation is complete
• Field devices are calibrated and their status is documented
• Power is available and stable to all new equipment
• Contractors are staffed, briefed, and on site
• Safety systems are verified and functional
• Roles for testing, troubleshooting, and startup are assigned by name
• Control system access and configuration ownership are defined
• Forces and bypasses have a tracking mechanism in place
• A named individual holds go- or no-go authority
Any item that cannot be confirmed should be resolved before mobilization.
The Takeaway | Address Execution Risk Before Field Work
Complex brownfield modernizations rarely unfold as planned. Existing infrastructure, incomplete documentation, evolving scope, and field discoveries all introduce conditions that are difficult to fully anticipate at the proposal stage.
Our debrief found that most of the challenges on this project were execution challenges: insufficient planning depth, optimistic scheduling, and inadequate readiness verification, ownership clarity, and communication. Each of these can be addressed before the field work begins.
Projects like this depend on everyone involved being open about schedule risk, resource constraints, technical obstacles, scope limits, and what is being found in the field. Open communication lets a project team make good decisions quickly.
We published this article because we hope your next project can benefit from what this one taught us. If you are scoping a brownfield modernization and would like a review of the plan before the schedule is set, our project development and automation and control teams can help. Reach out and we will talk through it with you.



