Machine Design #76: Machine Decommissioning — End of Life Must Be Designed Too
A machine that has stopped producing still holds energy, data, chemicals, accounts, materials and components. Every one of them becomes a risk if the machine is taken apart on improvisation. The end of life deserves the same treatment as commissioning: a defined scope, a defined end state, and evidence that it was reached.
Decide the scope and the final state first
The work is completely different depending on the outcome. Ask which one applies before anyone touches a bolt:
| Outcome | What it demands |
|---|
| Resold as a working machine | Documentation, safety condition, data cleared, transfer of the technical file |
| Relocated within the group | Lifting plan, reinstallation requirements, re-commissioning and re-validation |
| Stripped for spare parts | Which parts are kept, how they are identified, where the traceability goes |
| Scrapped | Waste routes, hazardous materials, certificates of disposal |
Each outcome carries its own record, its own safety requirements and its own data obligations. Choosing late means doing some of the work twice.
Inventory every form of energy
Electrical, pneumatic, hydraulic, spring, gravity, thermal, vacuum and battery energy all belong in the isolation plan. Turning off the main breaker is not lockout: a machine can hold a suspended load, a charged accumulator, a compressed spring or a capacitor bank long after the panel is dark.
Work from the drawings rather than from what is visible. Sources added during a rebuild are the ones most often missing from the original diagram.
Handle data and credentials
This is the part most often forgotten, because it leaves no trace on the floor.
- Withdraw accounts, certificates, VPN access, API keys and licences tied to the machine.
- Back up the records that have to be retained — as-built configuration, program versions, validation evidence, maintenance history.
- Delete recipes, customer data and logs according to the retention policy, and record that the deletion happened.
- Remove the machine from the network inventory, the monitoring system and any remote-access list.
A decommissioned machine that still holds a live VPN certificate is an open door with nobody watching it.
Hazardous materials and the environment
Identify oil, grease, coolant, batteries, capacitors, chemicals, insulation materials and electronic components before disassembly begins, not while the machine is on the floor in pieces. Use an appropriate disposal contractor and keep the documentation: the chain of custody is the evidence that the waste went where it was supposed to go.
Handover and evidence of completion
Record the serial number, the final configuration, what was removed, any residual hazard and the lifting points. Then confirm that the asset register, the CMMS, the network inventory and the backup repository have all been updated. A machine that is gone from the floor but still open in four systems will keep generating work orders, alarms and audit findings.
Review checklist
- The scope and the final state are defined and approved.
- Every energy source is in the isolation plan, including those added during rebuilds.
- Data retention, deletion and credential withdrawal are all recorded.
- Hazardous materials have a route and a certificate.
- The disassembly sequence, lifting points and site protection are planned.
- The asset register, CMMS, network inventory and backups are updated.
- Residual hazards are documented for whoever handles the machine next.
Conclusion
Machine decommissioning is a question of architecture and lifecycle, not a block of logic added at the end of a project. When state, identity, operating rights, data and recovery each have a clear contract, the machine is easier to run, to investigate and to change, without depending on the memory of whoever wrote the original program.
Public references
- ISO 12100:2010
- ISO 14001:2015
- IEC 62443-2-1
- ISO/IEC/IEEE 15288:2023
View all MINATA technical articles