Shutdown Process · Phase 2 · MU-STO-002

Plan

Capture, challenge and validate the scope, build the work packs, the master schedule and the baselines — then freeze it.

Purpose

Define, justify, plan, estimate, schedule and control all work required to achieve the event objectives.

Scope

  • Scope candidate capture, technical validation and challenge
  • Execution window determination and duration modelling
  • Field walk-downs, job plans and approved work packs
  • Materials, services and contract planning
  • Integrated master schedule, cost and performance baselines
  • Risk and contingency controls, scope freeze and Phase 02 gate

Phase Gate

Every phase closes at a formal phase gate. Work may proceed to the next phase only when the accountable authority accepts the required outputs, the outstanding conditions and the residual risks. The gate is a decision, not a formality — an unaccepted gate means the event is not ready to move on.

Process Steps

  1. 01

    Capture Shutdown Scope Candidates

    Intent

    Create one complete and traceable register of all potential work requiring consideration for the shutdown.

    Inputs
    • Event Charter
    • CMMS maintenance backlog
    • Preventive maintenance forecasts
    • Defects and operator notifications
    • Condition-monitoring findings
    • Inspection reports
    • FMECA, RCM and RCFA actions
    • Statutory work
    • Capital project and modification requirements
    • Deferred work from previous shutdowns
    Actions
    • Extract candidate work from approved information sources
    • Create or verify a work request for every candidate
    • Assign the correct asset and functional location
    • Record the problem, evidence, consequence and required outcome
    • Identify the source and accountable scope owner
    • Classify the candidate by maintenance, statutory, project, operational or opportunity work
    • Attach photographs, readings, drawings and inspection evidence
    • Identify known access, isolation and production constraints
    • Remove duplicate requests without losing history
    • Enter every candidate in the controlled scope register
    People

    Shutdown Planner coordinates capture. Operations, Maintenance, Reliability, Inspection, Engineering, Projects and HSE submit and validate candidate work.

    Process

    No candidate enters scope through an email, verbal request or uncontrolled spreadsheet alone. Every candidate must be traceable to a controlled work request or approved project requirement.

    Technology

    CMMS, inspection system, project management system, mobile work-request tools and controlled scope register.

    What Good Looks Like
    • One visible register contains all candidates
    • Each candidate identifies the asset, problem and evidence
    • Duplicate work is controlled
    • Scope source and owner are traceable
    What Bad Looks Like
    • Hidden scope lists exist outside the CMMS
    • Requests state only “inspect” or “repair as required”
    • Work is raised at plant level with no functional location
    • Scope appears after freeze because it was not captured
    Outputs
    • Complete Scope Candidate Register
    • Traceable work requests
    • Candidate classification
    • Duplicate and rejected-request record
    • Initial scope data-quality report
  2. 02

    Validate the Technical Need

    Intent

    Confirm that each candidate addresses a real defect, risk, compliance requirement or value opportunity and that the proposed intervention is technically appropriate.

    Inputs
    • Scope Candidate Register
    • Work-request evidence
    • Asset condition and failure history
    • Inspection and test findings
    • Equipment criticality
    • FMECA, RCM and maintenance strategy
    • Vendor and engineering information
    • Statutory requirements
    Actions
    • Confirm the reported condition exists
    • Confirm the affected asset and failure mode
    • Assess the current and forecast condition at the event date
    • Determine the consequence and likelihood of failure
    • Verify statutory or regulatory requirements
    • Review previous repairs and recurring failures
    • Determine whether inspection, repair, overhaul, replacement or redesign is appropriate
    • Identify additional engineering or diagnostic work
    • Record the technical basis and recommended disposition
    • Reject unsupported candidates or return them for more evidence
    People

    Reliability or responsible Engineer validates technical need. Operations and Maintenance provide operating and failure context. HSE and statutory specialists validate compliance needs.

    Process

    Technical validation must occur before detailed planning effort is committed. Validation does not automatically approve inclusion in the shutdown.

    Technology

    CMMS, asset health platform, engineering document system, inspection database and reliability analysis tools.

    What Good Looks Like
    • Each candidate has a defensible technical basis
    • Failure modes and consequences are understood
    • Proposed work addresses the actual problem
    • Unsupported work is removed early
    What Bad Looks Like
    • Jobs are included because someone senior requested them
    • Symptoms are treated without understanding failure causes
    • Repeat work is copied from the previous event without review
    • Statutory claims are not verified
    Outputs
    • Technically Validated Scope Register
    • Technical disposition for each candidate
    • Engineering action list
    • Rejected-candidate register
    • Updated asset risk information
  3. 03

    Determine the Execution Window

    Intent

    Confirm whether each validated job requires the shutdown window or can be completed online, during a minor opportunity, or through an alternative strategy.

    Inputs
    • Technically Validated Scope Register
    • Operating requirements
    • Isolation and access constraints
    • Redundancy and bypass capability
    • Risk assessments
    • Production schedule
    • Maintenance and project opportunities
    Actions
    • Determine whether work can be safely performed online
    • Determine whether redundancy or bypass permits intervention
    • Assess whether the work requires total, partial or local shutdown
    • Identify work that can be completed before the event
    • Identify work that can be completed after start-up
    • Identify work suited to a smaller maintenance window
    • Compare shutdown and non-shutdown execution risk and cost
    • Document the recommended execution window
    • Transfer online work to the appropriate maintenance programme
    • Retain only work that genuinely requires or benefits from the event
    People

    Operations and Maintenance jointly determine plant availability. HSE, Reliability, Engineering and Planners assess execution alternatives.

    Process

    Shutdown time is treated as a constrained business resource. Work must not enter the event merely because access appears convenient.

    Technology

    CMMS, isolation planning tools, production-planning system and risk assessment platform.

    What Good Looks Like
    • Shutdown scope contains work that genuinely requires the outage
    • Pre-work reduces event duration
    • Online opportunities are actively used
    • Decisions are supported by risk and value
    What Bad Looks Like
    • Routine online work congests the shutdown
    • Jobs are included for convenience
    • Pre-work is identified too late
    • Execution alternatives are not considered
    Outputs
    • Shutdown-required scope list
    • Pre-shutdown work list
    • Post-shutdown work list
    • Online and opportunity-work list
    • Execution-window decision record
  4. 04

    Prioritise and Challenge the Scope

    Intent

    Select the smallest credible scope that achieves event objectives while controlling asset, safety, environmental, production and compliance risks.

    Inputs
    • Shutdown-required scope list
    • Event objectives and charter
    • Technical validation
    • Asset criticality and risk ratings
    • Preliminary duration and resource information
    • Budget constraints
    • Deferral consequences
    Actions
    • Present each candidate at a cross-functional scope challenge
    • Confirm the technical need and shutdown requirement
    • Test alignment with event objectives
    • Assess the consequence of inclusion and deferral
    • Assign an approved priority and scope category
    • Identify jobs dependent on discovery or inspection findings
    • Identify mandatory, base, opportunity and contingency scope
    • Remove duplicates, low-value work and unjustified improvements
    • Record accepted, rejected, deferred and conditional decisions
    • Assign an owner and action date to unresolved candidates
    • Obtain approval of the challenged scope baseline
    People

    Shutdown Manager chairs the challenge. Operations, Maintenance, Reliability, Engineering, HSE, Projects, Planning and Finance provide decisions and evidence.

    Process

    Every job receives an explicit disposition. Silence or lack of review is not approval. Deferred work must return to the backlog with an owner and risk treatment.

    Technology

    CMMS, scope-management dashboard, decision register, risk system and benefits model.

    What Good Looks Like
    • Scope directly supports event objectives
    • Mandatory and optional work are clearly separated
    • Deferrals are risk assessed
    • Decisions are documented and traceable
    What Bad Looks Like
    • Scope challenge is a meeting that approves everything
    • Seniority overrides evidence
    • Rejected jobs disappear rather than returning to backlog
    • Contingency work is mixed into base scope
    Outputs
    • Challenged Scope Baseline
    • Approved scope priority
    • Deferred-work register
    • Conditional and contingency scope register
    • Scope challenge decision record
  5. 05

    Conduct Field Walk-Downs

    Intent

    Verify actual worksite conditions and collect the information required to develop safe, accurate and executable job plans.

    Inputs
    • Challenged Scope Baseline
    • Asset and functional location details
    • Existing job plans and drawings
    • Defect evidence
    • Preliminary isolation information
    • Historical work records
    Actions
    • Visit each work location with appropriate representatives
    • Confirm equipment identity and physical boundaries
    • Verify defect condition where visible
    • Confirm access, egress and emergency routes
    • Identify isolation points and stored-energy hazards
    • Identify work-at-height, lifting, confined-space and excavation requirements
    • Assess congestion and simultaneous-operations interfaces
    • Verify dimensions, quantities and connection details
    • Identify scaffold, crane, lighting, ventilation and temporary-service needs
    • Identify environmental and housekeeping controls
    • Capture photographs, measurements and marked-up drawings
    • Record uncertainties requiring additional investigation
    People

    Planner leads the walk-down. Supervisor, Operator, Maintainer, Engineer, HSE representative and specialist contractor attend where relevant.

    Process

    Planning from drawings alone is not acceptable where physical verification is reasonably possible. Walk-down findings must be attached to the work order.

    Technology

    Mobile CMMS, digital camera, drawing markup tools, laser measurement tools and site information system.

    What Good Looks Like
    • Job plans reflect actual site conditions
    • Access and isolation needs are known
    • Work-front conflicts are identified early
    • Photographs and measurements support planning
    What Bad Looks Like
    • Incorrect drawings are accepted without field verification
    • Crane or scaffold needs are discovered during execution
    • Work packs omit nearby hazards
    • Planners cannot identify the physical work location
    Outputs
    • Completed Walk-Down Record
    • Verified field measurements
    • Marked-up drawings and photographs
    • Access and isolation requirements
    • Planning-query register
  6. 06

    Develop Detailed Job Plans

    Intent

    Define how each approved job will be safely and efficiently executed, inspected, tested and returned to service.

    Inputs
    • Approved scope item
    • Walk-down record
    • Technical specifications and drawings
    • Maintenance history
    • Safety and environmental requirements
    • Quality and commissioning requirements
    • Standard job plans and vendor information
    Actions
    • Define the required starting condition
    • Break the job into logical execution tasks
    • Define task sequence and dependencies
    • Estimate labour by trade, skill and task
    • Identify materials, parts and consumables
    • Identify tools, lifting equipment and temporary services
    • Define permits, isolations and safety controls
    • Define hold, witness and inspection points
    • Define measurements, tolerances and acceptance criteria
    • Define test and commissioning requirements
    • Identify expected and possible discovery conditions
    • Define completion records and equipment-history requirements
    • Conduct technical and execution review of the plan
    People

    Planner develops the plan. Supervisor, Maintainer, Operations, Engineering, HSE, Quality and Commissioning personnel review applicable content.

    Process

    A competent work team must be able to understand the required work without relying on undocumented local knowledge. Job plans must distinguish instructions from acceptance criteria.

    Technology

    CMMS job-planning module, controlled document system, digital work-pack platform and estimating database.

    What Good Looks Like
    • Scope, sequence and acceptance criteria are unambiguous
    • Labour and duration estimates are task based
    • Safety controls are integrated with execution steps
    • Findings and measurements can be recorded
    What Bad Looks Like
    • The job plan states only “repair as required”
    • No measurable completion standard exists
    • Estimated hours are copied without review
    • Commissioning is assumed to be someone else’s responsibility
    Outputs
    • Detailed Job Plan
    • Labour and duration estimate
    • Task-level resource requirements
    • Quality and completion criteria
    • Planning review approval
  7. 07

    Develop and Approve Work Packs

    Intent

    Assemble all information needed to authorise, execute, control, verify and close each shutdown job.

    Inputs
    • Detailed Job Plan
    • Current drawings and specifications
    • Risk assessments
    • Permit and isolation requirements
    • Material and tool lists
    • Inspection and quality documentation
    • Commissioning requirements
    Actions
    • Compile the approved scope and task instructions
    • Include asset, work-order and location identifiers
    • Include drawings, photographs and technical specifications
    • Include hazards, controls, permits and isolation references
    • Include labour, materials, tools and equipment requirements
    • Include lifting, scaffold and access plans where required
    • Include quality plans and inspection/test records
    • Include hold points and approval authorities
    • Include completion, defect and history-recording fields
    • Include commissioning and handback requirements
    • Verify revision status of every controlled attachment
    • Conduct work-pack quality review and approval
    • Place the approved pack under document control
    People

    Planner compiles the work pack. Supervisor confirms executability. Engineering, HSE, Quality, Operations and Commissioning approve specialist content.

    Process

    Only the current approved work pack may be issued for execution. Superseded packs must be withdrawn and prevented from unintended use.

    Technology

    CMMS, electronic document management, digital work-pack system, revision control and mobile field devices.

    What Good Looks Like
    • All required information is available in one controlled pack
    • Attachments are current and traceable
    • Field records can be completed within the pack
    • Approval status is immediately visible
    What Bad Looks Like
    • Crews search multiple systems for instructions
    • Superseded drawings remain in circulation
    • Generic risk controls replace job-specific planning
    • Work starts using an unapproved draft pack
    Outputs
    • Approved Work Pack
    • Work-pack quality status
    • Controlled attachment register
    • Hold-point and inspection register
    • Work-pack approval record
  8. 08

    Plan Materials, Services and Contracts

    Intent

    Identify, source and control all parts, consumables, specialist services and contracted resources required to execute the approved scope.

    Inputs
    • Approved Work Packs
    • Bills of materials
    • Inventory records
    • Vendor information
    • Repairable and rotable inventory
    • Contractor capability information
    • Procurement policies
    • Required-on-site dates
    Actions
    • Validate part numbers, specifications and quantities
    • Check stock condition, reservation and availability
    • Identify long-lead, obsolete and critical items
    • Decide whether to purchase, repair, fabricate, hire or substitute
    • Prepare technical scopes of work for external services
    • Define contractor competence, mobilisation and deliverable requirements
    • Establish required delivery and inspection dates
    • Include freight, preservation, storage and warranty requirements
    • Define spare and contingency material strategy
    • Raise and track purchase and contract commitments
    • Escalate threats to required-on-site dates
    • Link procurement status to work-pack readiness
    People

    Planner defines requirements. Supply and Procurement source them. Engineering approves technical substitutions. Warehouse manages receipt and preservation. Commercial manages contractual controls.

    Process

    A purchase order is not evidence of readiness. Required items must be received, inspected, correctly identified and available before being declared ready.

    Technology

    CMMS, inventory and warehouse system, procurement platform, contract management system and materials-readiness dashboard.

    What Good Looks Like
    • Critical items are identified early
    • Parts are reserved against specific work orders
    • Contractor deliverables are measurable
    • Substitutions receive technical approval
    What Bad Looks Like
    • Material status is reported only as “ordered”
    • Incorrect or damaged parts are discovered during execution
    • Contract scopes contain unclear deliverables
    • Uncontrolled substitutions are accepted
    Outputs
    • Materials Requirement Register
    • Long-Lead Item Register
    • Contracting and Services Plan
    • Purchase and repair commitments
    • Material and service readiness criteria
  9. 09

    Develop the Integrated Master Schedule

    Intent

    Arrange all event activities into a logic-linked and resource-feasible schedule covering run-down, isolation, execution, commissioning, start-up and ramp-up.

    Inputs
    • Approved scope and work packs
    • Task durations and dependencies
    • Resource requirements
    • Isolation and permit sequence
    • Materials and contractor dates
    • Production constraints
    • Commissioning and start-up requirements
    Actions
    • Create schedule activities at a controllable level
    • Link activities using valid technical and operational logic
    • Include pre-shutdown and enabling work
    • Include plant run-down and clean-out
    • Include isolations and work-front release
    • Include inspection, repair, quality and discovery activities
    • Include mechanical completion and system turnover
    • Include de-isolation, commissioning, start-up and ramp-up
    • Identify milestones and decision points
    • Calculate and review the critical and near-critical paths
    • Resource-load and level the schedule
    • Resolve trade, access, crane, scaffold and supervision conflicts
    • Conduct schedule review and obtain baseline approval
    People

    Scheduler develops the schedule. Shutdown Manager owns the baseline. Planners, Supervisors, Operations, Engineering, HSE, Contractors and Commissioning validate logic and resources.

    Process

    Activities must be logic linked. Artificial constraints must not be used to hide missing logic. The schedule must cover the complete event, not only maintenance execution.

    Technology

    Enterprise scheduling software, CMMS, resource-management system and schedule analytics dashboard.

    What Good Looks Like
    • Critical path is technically credible
    • Resource demand is achievable
    • Commissioning and handback are fully scheduled
    • Supervisors understand work-front sequence
    What Bad Looks Like
    • The schedule is a list of dates without logic
    • Every activity is declared critical
    • Resource overloads remain unresolved
    • Start-up is represented by a single milestone
    Outputs
    • Integrated Master Schedule
    • Approved schedule baseline
    • Critical and near-critical path report
    • Resource histograms
    • Milestone and interface register
  10. 10

    Establish Cost and Performance Baselines

    Intent

    Create an approved basis for controlling event cost, schedule, scope, progress and benefits.

    Inputs
    • Approved scope
    • Integrated Master Schedule
    • Labour and contractor estimates
    • Materials and hire costs
    • Production-loss assumptions
    • Contingency and risk information
    • Event objectives and KPIs
    Actions
    • Develop cost estimates by work order and control account
    • Separate labour, materials, contracts, hire and indirect costs
    • Identify capital and operating expenditure
    • Develop time-phased cost and labour forecasts
    • Define approved contingency and its release authority
    • Define progress measurement rules
    • Define schedule, cost and scope reporting thresholds
    • Establish KPI definitions, sources and owners
    • Reconcile the estimate with authorised funding
    • Baseline approved cost, schedule and performance measures
    • Implement forecast-at-completion reporting
    People

    Shutdown Manager owns event performance. Cost Controller develops cost controls. Scheduler, Finance, Commercial, Planners and functional owners validate the baseline.

    Process

    Costs must be coded consistently with scope and schedule. Baseline changes require formal approval and must not overwrite original performance history.

    Technology

    Cost-control system, scheduling software, CMMS, finance platform and business intelligence dashboard.

    What Good Looks Like
    • Cost, schedule and scope use aligned coding
    • Forecasts identify emerging overruns early
    • Contingency is controlled
    • KPI definitions remain stable throughout the event
    What Bad Looks Like
    • Budget is one total without work-level visibility
    • Commitments are omitted from forecasting
    • Baselines are repeatedly reset to hide variance
    • Progress is based on subjective percentages
    Outputs
    • Approved Cost Baseline
    • Time-phased expenditure forecast
    • KPI and performance framework
    • Progress measurement rules
    • Cost and schedule control accounts
  11. 11

    Develop Event Risk and Contingency Controls

    Intent

    Identify and treat threats and opportunities that could affect safety, environment, quality, cost, duration, production or successful start-up.

    Inputs
    • Event Charter
    • Approved scope
    • Integrated Master Schedule
    • Worksite and SIMOPS information
    • Historical event lessons
    • Contractor and supply risks
    • Commissioning requirements
    • Business risk criteria
    Actions
    • Conduct cross-functional event risk workshops
    • Identify risks across all event phases
    • Assess causes, consequences, likelihood and current controls
    • Identify schedule and critical-path threats
    • Identify high-risk work and simultaneous-operations interfaces
    • Identify supply, contractor and specialist-resource threats
    • Identify discovery and emergent-work scenarios
    • Identify commissioning and start-up failure scenarios
    • Assign preventive and recovery controls
    • Define contingency scope, materials, resources and decision triggers
    • Assign owners and target dates
    • Review residual risk against acceptance authority
    People

    Shutdown Manager owns the event risk process. HSE facilitates where appropriate. Operations, Maintenance, Reliability, Engineering, Projects, Supply, Contractors and Commissioning contribute.

    Process

    A contingency is not unplanned scope. Each contingency must have a defined trigger, prepared response and approval pathway.

    Technology

    Enterprise risk system, schedule risk tools, CMMS, incident database and action-tracking system.

    What Good Looks Like
    • Risks are connected to schedule and work controls
    • Contingencies have triggers and owners
    • Start-up risks receive the same attention as execution risks
    • Risk actions are completed before readiness approval
    What Bad Looks Like
    • The risk register contains generic statements
    • Mitigation actions have no owner
    • Contingency is only a financial allowance
    • Known discovery risks are treated as surprises
    Outputs
    • Event Risk and Opportunity Register
    • Contingency Plan
    • High-Risk Work Register
    • SIMOPS control requirements
    • Residual-risk acceptance record
  12. 12

    Freeze the Scope and Approve the Plan

    Intent

    Establish the controlled event baseline and prevent uncontrolled work additions from destabilising safety, readiness, cost, resources or duration.

    Inputs
    • Challenged and planned scope
    • Approved Work Packs
    • Integrated Master Schedule
    • Cost and resource baselines
    • Materials and contract status
    • Event risk register
    • Outstanding planning actions
    Actions
    • Confirm all base-scope items meet the planning standard
    • Confirm unresolved scope has an approved disposition
    • Confirm work-package, schedule, cost and resource alignment
    • Confirm contingency and opportunity scope are separately identified
    • Record the approved scope-freeze date
    • Record exceptions and conditions
    • Activate formal change-control requirements
    • Define emergency and mandatory-change pathways
    • Communicate scope-freeze rules to all stakeholders
    • Obtain Plan Phase Gate approval
    People

    Event Sponsor approves the baseline. Shutdown Manager recommends approval. Operations, Maintenance, Engineering, HSE, Projects, Finance, Supply and Planning endorse applicable elements.

    Process

    After freeze, no work may enter the event without documented justification, impact assessment and approval. Scope removal is also controlled where removal changes risk or objectives.

    Technology

    Scope-management system, CMMS workflow, schedule and cost systems, electronic approval workflow and change register.

    What Good Looks Like
    • The baseline is stable and understood
    • Late additions are rare and evidence based
    • Change impacts are assessed before approval
    • Opportunity and contingency scope remain separately controlled
    What Bad Looks Like
    • Freeze is a date with no behavioural change
    • Work is added directly to the schedule
    • Senior requests bypass change control
    • Scope is removed to protect schedule without risk review
    Outputs
    • Frozen Scope Baseline
    • Approved Event Plan
    • Scope Change Procedure
    • Baseline exception register
    • Phase 02 Gate Approval

Key Performance Indicators

KPIWhy It MattersHow To MeasureWorld ClassBenchmarkTypical
Scope frozen on the planned freeze dateEvery week the freeze slips removes a week of preparation and pushes work into discovery.Compare actual freeze approval date to the date set in the charter milestone plan.On date100% of events2–6 weeks late
Scope challenge rejection rateA challenge process that rejects nothing is not a challenge process — it is a rubber stamp.Rejected or deferred candidates ÷ total candidates submitted.15–30% of candidates
Work packs complete at freezePacks finished after freeze cannot be walked down, resourced or costed accurately.Approved packs ÷ frozen scope items, measured at the freeze gate.>98%>95%60–80%
Jobs walked down before planning sign-offDesktop planning is the root cause of most access, isolation and fit-up surprises.Walked-down jobs ÷ jobs above the defined complexity threshold.100% of major jobs
Schedule resource-levelled before baselineAn unlevelled schedule promises headcount the site cannot physically supply.Confirm the baselined schedule passes resource-histogram review.100%

Best Practices

  • One visible register contains all candidates
  • Each candidate has a defensible technical basis
  • Shutdown scope contains work that genuinely requires the outage
  • Scope directly supports event objectives
  • Job plans reflect actual site conditions
  • Scope, sequence and acceptance criteria are unambiguous
  • All required information is available in one controlled pack
  • Critical items are identified early
  • Critical path is technically credible
  • Cost, schedule and scope use aligned coding
  • Risks are connected to schedule and work controls
  • The baseline is stable and understood

Common Pitfalls

  • Hidden scope lists exist outside the CMMS
  • Jobs are included because someone senior requested them
  • Routine online work congests the shutdown
  • Scope challenge is a meeting that approves everything
  • Incorrect drawings are accepted without field verification
  • The job plan states only “repair as required”
  • Crews search multiple systems for instructions
  • Material status is reported only as “ordered”
  • The schedule is a list of dates without logic
  • Budget is one total without work-level visibility
  • The risk register contains generic statements
  • Freeze is a date with no behavioural change