Factory acceptance testing and site acceptance testing answer different questions. FAT asks whether the engineered package behaves correctly before it reaches the operating site. SAT asks whether the installed system, real field devices and process interfaces work together under site conditions.
A strong test strategy moves defects to the earliest practical stage without pretending that simulation proves installed behaviour. It also prevents SAT from repeating every factory check while overlooking wiring, process, network and operational risks that exist only at site.
The contract should define the test boundary as clearly as the technical design. State what equipment will be present, which interfaces will be simulated, who provides test tools and product, and what constitutes a pass, deviation or blocked test. Without those decisions, the team can complete many test steps while still disagreeing about whether the system is ready to ship or operate.
Traceability is the connecting mechanism. Every important functional or performance requirement should point to an FAT result, SAT result or another accepted verification method. Every changed software revision should point back to the affected tests. This relationship allows the final package to explain not only that testing occurred, but why the retained evidence supports acceptance of the installed configuration.
What FAT should prove
Factory acceptance testing should confirm that the engineered solution behaves correctly before site conditions and installation issues are introduced.
Prepare FAT from the functional requirements and approved design, not from whichever features are easiest to demonstrate. Confirm the panel configuration, drawing and BOM status, PLC and HMI versions, user roles, alarms, modes, sequence transitions and communication interfaces. Simulated I/O should be traceable and clearly distinguished from real devices. Exceptions are logged with an owner, planned correction and the tests affected by the change.
- Drawing and BOM review
- Panel inspection and electrical checks
- PLC and HMI sequence simulation
- Alarm, interlock and user-access testing
- Software backup and version identification
What SAT should prove
Site acceptance testing should confirm correct installation, field interfaces and integrated operation in the actual process environment.
SAT begins with installation evidence. Check panel identity, field wiring, device configuration, network paths, instrument scaling, motor direction and actual feedback before integrated sequences. Site testing includes utilities, mechanical loads, local controls, environmental conditions and external systems that were unavailable at FAT. The team should also verify recovery after realistic interruptions because a system can pass normal operation while failing to restart safely.
- Field I/O and device checkout
- Network and third-party interfaces
- Actual motor, valve and instrument behaviour
- Safety and recovery sequences
- Performance under operating conditions
Avoid duplicated testing
Use FAT to remove software and panel defects early. Reserve SAT for site-specific behaviour that cannot be proven realistically before installation.
Build a traceability matrix that assigns each requirement to FAT, SAT or both. Repeat a factory test at site only when installation, software revision or real equipment can change the result. For example, alarm text can be reviewed at FAT, while the real initiating condition and operator response are confirmed at SAT. This approach preserves coverage while keeping the site schedule focused on evidence that cannot be created elsewhere.
Manage exceptions
Every exception needs a clear description, owner, due date, retest method and impact on release. An unresolved exception should not disappear into meeting notes.
A passed test record should identify the requirement, configuration, prerequisites, steps, expected result, actual evidence, executor and approver. Screenshots alone rarely prove sequence timing or field response, so use trends, controller values, measurements or signed observations appropriate to the function. Deviations are linked to correction and retest. If a temporary workaround remains, its risk, expiry and owner must be visible at acceptance.
Define completion
Agree in advance which results authorize shipment, energization, production trial and final handover. Different milestones can have different acceptance criteria.
Agree on the acceptance gate before testing starts. Define which failures block shipment, energization, production trial or final handover; which open items may be conditionally accepted; and who has authority to decide. Preserve the exact software and documentation revision associated with the accepted result. A test campaign is complete when requirements, deviations and configuration agree—not when the scheduled test days have ended.
Frequently asked questions
Can FAT replace site commissioning?
No. FAT can prove design and simulated behaviour, but it cannot prove field wiring, actual device response, process conditions or installed network performance.
Should safety functions be tested at FAT and SAT?
Relevant logic, configuration and simulated response may be tested at FAT, while the installed protective function and machine response require the project’s approved site validation method.
Who approves FAT and SAT results?
The contract and responsibility matrix should name executors, witnesses and authorized approvers. Different stakeholders may approve panel, controls, safety, process and operational acceptance.
What happens when software changes after FAT?
Record the change, assess which requirements are affected and repeat the relevant FAT or SAT tests. The accepted as-left version must match the retained evidence.
Use the guide inside an approved work process
This guide supports planning and technical review; it does not authorize a change to live equipment. Before applying it, identify the system owner, production boundary, electrical and machine hazards, required permits, current backups and the person authorized to approve testing. Keep confirmed evidence separate from assumptions, and record any temporary simulation, force, inhibit or workaround under the site’s approved method.
If the installed condition does not match the available drawings or software, preserve the discrepancy and resolve ownership before downloading, energizing or bypassing a protective function. Final acceptance should reference the actual as-left configuration, executed test evidence, open actions and responsible approver.
Planning a related controls project?