Plant Shutdown Checklist
Plan it, run it, and get it back on. Scope frozen before anything stops, the critical path named, progress measured daily against plan, and a startup review that has to pass before a single thing is energized.
- Sixteen preparation tasks, grouped by 30 days, 7 days and 24 hours
- A predecessor against every job, so the critical path is visible
- Fourteen pre-startup checks, and one Fail stops the restart
- Planned against actual hours, cost and jobs, shutdown after shutdown
Plant Shutdown Checklist
Plan, run, restart
| # | Preparation task | Done | When | By |
|---|---|---|---|---|
| 1 | Scope frozen, no new work accepted after this point | |||
| 2 | Every job on the work list has a written scope and a duration | |||
| 3 | Critical path identified and agreed |
The document you will get. Download for the full, editable file.
Who this plant shutdown checklist is for
A shutdown is the one job where planning, trades, operations and safety all sign the same document, and each of them reads a different section of it.
The shutdown manager
You own the work list, the critical path and the finish time. The preparation table grouped by deadline is your document, because nothing on the thirty-day list can be recovered in the final week.
Trade and contractor supervisors
You are working inside a window somebody else set. What you need is the sequence, your predecessor jobs, and the permit and isolation that let you start, rather than the whole plan.
Operations and the people who live with it
You care about the services table: what goes off, when it comes back, and what covers the gap. For a building shutdown that section is the one occupants and tenants actually read.
Whoever signs the pre-startup review
You are the last gate before energizing. Fourteen checks with evidence against each, and the authority to hold the restart on a single Fail, is the whole of your job on this document.
Which section matters the most in your sector
The sequence is much the same whether you are stopping a chiller plant or a production line. What changes is what the outage costs and who notices it, and that decides how much of this document you can afford to skip. If you run one of these, the sector page goes further than the template does.
- Data centres
The temporary provision step. Proving the standby supply is live and stable before releasing the primary is not a formality in a data hall, it is the whole shutdown.
Data centre maintenance software - Healthcare
The services and utilities table. Chilled water, medical gases and lifts each come back at a different time, and clinical areas need those times individually rather than a window.
Healthcare maintenance software - Commercial real estate
Occupant notification and continuity. A tenant told in writing three weeks ahead is a different relationship from a tenant who finds out when the cooling stops.
Portfolio maintenance software - FM service providers
Contractors appointed, insured, inducted and briefed. When the work is subcontracted, the induction line is the one that slips and the one an incident will be traced back to.
FM service provider software - Retail and malls
The finish time. A shutdown that overruns into trading hours costs more than the work saved, which is why the contingency and who calls it are agreed in advance.
Retail maintenance software - Education
Statutory inspection timing. Term dates give a fixed window that cannot move, so the thirty-day preparation list is the only place slippage can be absorbed.
Campus maintenance software
What a plant shutdown checklist should contain
A plant shutdown checklist is the document that plans, runs and closes out a planned outage of plant, a system or an area. It holds the work list and its sequence, the preparation due at each deadline, the services affected, the shutdown and startup sequences, daily progress against plan, and the pre-startup review that gates the restart.
A. Fields specific to a plant shutdown
| Field | What goes in it | Why it earns its place |
|---|---|---|
| Type of shutdown | Annual, statutory inspection, turnaround, seasonal, emergency or tie-in | A statutory inspection shutdown may need a competent person or an insurer surveyor booked months ahead, which is a lead time no other type carries. |
| Planned finish, set first | Date and time at both ends, and the planned duration in hours | The finish is agreed before the start, because a shutdown with an open end will find work to fill it. Every other estimate on the document is measured against this one. |
| Point of no return | The moment stopping costs more than continuing, and who can call it | Naming it in advance turns the hardest decision of the shutdown into a threshold somebody has authority to declare, rather than an argument held at two in the morning. |
| Work list with predecessors | Job number, description, trade, hours, the job it follows, critical flag | The predecessor column is the one people skip. Shutdowns overrun on sequencing rather than effort, and the critical path does not exist until that column is filled in. |
| Preparation by deadline | Sixteen tasks, each tagged 30 days, 7 days or 24 hours | Grouping by deadline is what makes this useful. The thirty-day column is where a shutdown is won or lost, because nothing on it can be recovered in the last week. |
| Services and utilities affected | Each service, areas, off and back times, and the temporary cover | One row per service rather than a single outage window. Water, power, cooling, lifts, fire detection and IT cooling all return at different times and different people care about each. |
| Shutdown sequence | Eleven steps from the go decision to handing areas over | The order matters more than the content. Transferring critical load and then proving the temporary supply before releasing the primary are two steps that must not swap places. |
| Daily progress | Planned and actual percentage, variance, jobs done and slipped | Variance calculates itself, so the value is the trigger: two consecutive negative days on the critical path means invoking the contingency rather than hoping for a better shift. |
| Pre-startup safety review | Fourteen checks, each pass, fail or not applicable, with evidence | This is the gate. Guards refitted, permits canceled, bypasses removed, interlocks function tested, isolations removed in reverse. One Fail holds the restart until it is cleared. |
| Startup sequence | Twelve steps, energizing in the reverse of the isolation order | Restarting is not simply undoing the shutdown. Low load first, baseline readings compared against pre-shutdown values, ramping in stages, and a settling period before handback. |
| Plan against actual | Hours, cost and job counts, with variance and unplanned work found | Unplanned work found is the number that improves the next shutdown. A high figure is not a failure of this one, it is a gap in inspection between shutdowns. |
| Lessons learned | What happened, why, what to change, an owner and a date | Written in the week after rather than when the next shutdown is being planned. This is the only table in the document that makes the following shutdown better. |
If you cut this down, keep the predecessor column and the pre-startup review. They protect against the two ways a shutdown actually fails. Without predecessors there is a work list but no critical path, so every job looks equally urgent, slippage is invisible until the end, and the overrun is discovered rather than predicted. Without the review as a hard gate the restart becomes a judgment made by whoever is most tired and most under pressure to hand the plant back, which is precisely when a bypass gets left in or a guard stays off. Everything else on the form is useful. Those two are the parts that stop a bad shutdown becoming a dangerous one.
B. What it looks like filled in
Three days of one annual shutdown, read off the daily progress table. It finished eighteen hours over plan, and the table shows exactly where that went.
| Day | Planned | Actual | Slipped | Issue or decision |
|---|---|---|---|---|
| 1 | 25% | 18% | 1 | Bearing arrived to the wrong specification, courier booked |
| 2 | 50% | 38% | 2 | Second negative day on the critical path, contingency invoked |
| 3 | 75% | 71% | 0 | Extra shift added, sequencing reworked around the AHU |
| Restart | n/a | n/a | 0 | Pre-startup review: one Fail, bypass left in on trip circuit |
| Restart | n/a | n/a | 0 | Bypass removed, interlock retested, review re-signed |
| Close | 148 hrs | 166 hrs | 1 | Four items of unplanned work found, one job deferred |
The two bold rows are the document working as intended. Day two was the second consecutive negative day on the critical path, which is the written trigger to invoke the contingency rather than to hope the next shift goes better. That decision on day two is why the overrun was eighteen hours instead of a week: an extra shift and reworked sequencing recovered most of it by day three. The restart row is the more important one. The pre-startup review caught a bypass left in on a trip circuit, which is exactly the thing that gets missed at the end of a long shutdown by people under pressure to hand the plant back. One Fail held the restart, the bypass came out, the interlock was retested and the review was re-signed. Had that review been treated as a signature rather than a gate, the plant would have gone back into service with a disabled trip.
Word to adapt the preparation list and the review to your plant, Excel for the work list with predecessors, the daily progress table that calculates variance and the log that compares shutdowns over time, PDF for the copy on the wall in the shutdown office. Free, and yours to rebrand.
How do you plan and run a plant shutdown?
Part A is done weeks out, part B during, part C before anything is energized. The order is not negotiable, and the thirty-day list is the part that decides the rest. Six steps.
Fix the type, the finish time and the point of no return
Reference, plant or area, type of shutdown, the reason, and the planned finish agreed before the start time. Then the shutdown manager, who authorized it, and the point of no return: the moment stopping costs more than continuing, and who has the authority to call it.
Build the work list, and give every job a predecessor
Job number, description, trade, estimated hours, the job it has to follow and whether it is on the critical path. Fill in the predecessor column even where it looks obvious, because the critical path does not exist as a fact until that column is complete.
Work the preparation list by deadline
Sixteen tasks grouped at thirty days, seven days and twenty-four hours: scope frozen, permits pre-authorized, lockout procedures available, parts on site and checked against drawings, contractors inducted, occupants notified in writing, temporary provision arranged, startup plan written, contingency agreed.
Ramp down in sequence, proving the temporary supply first
Record the go decision, notify everyone, ramp load down rather than tripping it, transfer critical loads, and confirm the temporary provision is live and stable before the primary is removed. Then drain, vent and purge, allow run-down, isolate under the lockout procedure and verify zero energy.
Track progress daily and act on two negative days
Planned against actual percentage each day, with jobs done, jobs slipped and the decision taken. Variance works itself out on the sheet. Two consecutive negative days on the critical path is the trigger to invoke the contingency rather than to wait for a better shift.
Pass the review, then start up in reverse order
All fourteen pre-startup checks with evidence against each, and a single Fail holds the restart. Then energize in the reverse of the isolation order, run at low load, compare baseline readings against pre-shutdown values, ramp in stages, hold a settling period and hand back formally.
A planned shutdown versus an emergency one
Every site has both, and the second one borrows this document in a hurry. What changes between them is less than people assume, and the part that must not change is the part that usually does.
| Aspect | Planned shutdown | Emergency shutdown |
|---|---|---|
| Why it starts | A date agreed weeks or months ahead | A failure, and the decision is already made |
| Scope | Frozen before anything stops | Discovered as the work opens up |
| Finish time | Set before the start time is agreed | Unknown, and estimated under pressure |
| Permits and isolations | Raised and pre-authorized in advance | Raised on the spot, which is where corners appear |
| Preparation list | Worked at 30 days, 7 days and 24 hours | Compressed into whatever time exists |
| Pre-startup review | All fourteen checks, evidenced and signed | The same fourteen checks, and the pressure to skip them |
The last row is the one that matters, because it does not change and everybody wishes it would. Almost everything about an emergency shutdown is worse: the scope is unknown, the parts are not on site, the contractors were not inducted and the finish time is a guess. Those are real constraints and the document flexes around them. The pre-startup safety review does not flex. The plant is either safe to energize or it is not, and a failure has usually left the area in a messier state than planned work would: more temporary modifications, more bypasses fitted to keep something running, more tools in places they should not be. That makes the review more necessary during an emergency and simultaneously the moment when a plant manager is under the most pressure to sign it and get production back. If you take one thing from this template into an unplanned outage, take the fourteen checks and the rule that one Fail stops the restart.
When the template starts to feel limiting
The document plans one shutdown well. It runs a live one badly, and it improves the next one hardly at all, in four predictable ways.
Deadlines that cannot chase themselves
Sixteen preparation tasks across three deadlines, each with an owner, living in a document somebody opens when they remember to. The thirty-day tasks are the ones that slip, and they are the ones that cannot be recovered.
No live view of where the shutdown actually is
Percentage complete is entered once a day by one person from a walk round and a conversation. By the time two negative days are visible on the sheet, the second of them is already over.
The work list and the actual work live apart
Fourteen jobs on this sheet exist somewhere else as work orders, with their own permits and isolations. Keeping both means a job can be signed off here and still open there, or the reverse.
Shutdowns cannot be compared with each other
Planned against actual is the number that makes the next estimate credible, and it only means something across several shutdowns. In separate documents each one is an anecdote rather than a trend.
What running this in Facilio looks like
The template is the paper version of this shutdown. The sections are the same ones; the difference is that a work list becomes live jobs with permits attached, and daily variance becomes something the system reports rather than something a person compiles.
Work Completion Validator
The restart cannot be signed with a review item open
On paper the pre-startup review is fourteen ticks and a signature. Work Completion Validator holds each check against its evidence, so a bypass recorded as removed without anything to show it stays a Fail and the restart stays held.
Ops Performance Intelligence
Preparation deadlines chase their owners
The thirty day, seven day and twenty-four hour tasks carry owners and dates, so an uninducted contractor or an unconfirmed long-lead part surfaces while there is still time to fix it rather than in the final week.
Audit Report Intelligence
Plan against actual becomes a trend
Hours, cost, jobs deferred and unplanned work found are held per shutdown, so the next estimate rests on what the last four actually took rather than on what the last one was supposed to take.
Contractor Work Tracker
Induction and insurance are checked before the gate
Who is appointed, whether their insurance and induction are current and what they are approved to do sits against the contractor record, so the preparation line is evidenced rather than assumed on day one.
Hallucination-free by design. Atom AI answers from the records in your tenant rather than generating plausible text, so an empty field reads as empty rather than filled in for you.
Frequently asked questions
What is a plant shutdown checklist?
A plant shutdown checklist is the document that plans, runs and closes out a planned outage of plant, a system or an area. It holds the shutdown reference, type and agreed finish time, the work list with the sequence between jobs, the preparation due at each deadline, the services affected with their off and back times, and the sequences for stopping and restarting.
It also holds the two things that make a shutdown reviewable afterwards: daily progress measured against plan, and a pre-startup safety review that has to pass in full before anything is energized. Plan against actual and lessons learned close it out.
What should a plant shutdown checklist include?
The shutdown details with the type, the planned start and finish, the manager, the authorization and the point of no return. Then the work list with a predecessor and a critical flag against every job, sixteen preparation tasks grouped at thirty days, seven days and twenty-four hours, and a services table with one row per utility.
For running it: an eleven-step shutdown sequence, daily progress against plan, a fourteen-check pre-startup safety review, and a twelve-step startup sequence. Then plan against actual for hours, cost and job counts, lessons learned, and sign-off including the formal handback to operations.
What is a pre-startup safety review?
It is the gate between the work finishing and the plant being energized. In this template it is fourteen checks: every job signed off or formally deferred, deferred work assessed as safe to run with, guards and panels refitted, tools and waste removed, everyone accounted for, permits canceled, temporary modifications and bypasses removed, instruments recalibrated, interlocks and trips function tested, relief valves certified, isolations removed in reverse order, records updated, staff briefed and the startup sequence agreed.
The point is that it is a gate rather than a formality. A single Fail stops the restart until it is cleared, and the signature means the person checked rather than that they were told.
How far in advance should a shutdown be planned?
Work backwards from the three deadlines in the preparation section: thirty days, seven days and twenty-four hours. The thirty-day list is where a shutdown is won or lost, because none of it can be recovered in the final week: parts on site and checked against drawings, long-lead items confirmed, contractors appointed and inducted, access and lifting plant booked, and specialist testing or certification arranged.
Statutory inspection shutdowns usually need longer, because a competent person or an insurer surveyor may have to be booked months ahead. That lead time belongs in the plan before the start date is promised to anyone.
What is the point of no return in a shutdown?
The moment after which stopping and reversing costs more than continuing. Once plant is drained, stripped or dismantled, abandoning the shutdown and restoring service is often slower and more expensive than finishing the work.
The template asks you to state it in advance and to name who has the authority to call it. That turns the hardest decision of the shutdown into a threshold somebody owns, rather than a debate held late at night by tired people with different priorities.
Why do planned shutdowns overrun?
Sequencing, far more often than effort. If two jobs need the same crane, the same isolation or the same access, and nothing records that one has to follow the other, then every job looks independently schedulable and the conflict is discovered on site. That is what the predecessor column exists to prevent, and it is the column people skip because the dependencies feel obvious while they are planning.
The second cause is not acting on early slippage. Variance on day one is noise. Two consecutive negative days on the critical path is a pattern, and the template treats it as the trigger to invoke the contingency rather than as a reason to hope the next shift is better.
Does this work for a building shutdown as well as a plant one?
Yes, and the services and utilities table is the section that carries it. For a building the outage is felt by occupants rather than by production, so each service is listed separately with the areas affected, the time it goes off, the time it is restored and the temporary provision covering the gap.
Chilled water, heating, power, water, lifts, fire detection, IT cooling and catering all come back at different times, and tenants need those times individually rather than as one window. The rest of the document, including the pre-startup review and the reverse-order restart, applies unchanged.
Can I edit and rebrand this template?
Yes. It is free to use, edit, rename and put your own logo on, internally or for clients. No attribution required.
The Word version is the one to edit if you want to adapt the preparation list or the pre-startup review to your own plant and authorization levels. The Excel version is the one to use if you want the work list to total planned hours, the daily progress table to calculate variance, and the Shutdown Log tab that compares planned against actual across several shutdowns.
In one paragraph
A planned shutdown is decided in the weeks before it starts rather than in the days it runs. Set the finish time before the start time is agreed, because an open-ended shutdown will find work to fill it, and name the point of no return along with whoever can call it. Build the work list and fill in the predecessor column for every job, since shutdowns overrun on sequencing and the critical path does not exist until that column is complete. Work the preparation list by deadline and treat the thirty-day group as immovable, because nothing on it can be recovered in the last week. When you stop the plant, prove the temporary supply is live and stable before releasing the primary. Track progress daily and invoke the contingency after two negative days on the critical path rather than hoping for a better shift. Then treat the pre-startup review as a gate: fourteen checks with evidence, one Fail holds the restart, and energizing happens in the reverse of the isolation order.
The template is the floor, not the ceiling
Take the checklist; it will plan one shutdown properly and give the restart a real gate. When a spreadsheet stops keeping up with a live shutdown, a connected CMMS runs it: the work list as scheduled jobs with their permits and isolations attached, preparation deadlines that chase their owners, variance visible the same day rather than the next morning, and planned against actual trended across shutdowns so the next estimate is credible.