Productization
HVAC

HVAC Chiller Plant Operational Compliance

Weighted score of the six operating sequences the plant's BMS is supposed to hold — a chiller running with its chilled-water pump, its condenser-water pump, and a cooling tower, distribution following production, and everything off together when the plant is off. A low score means the plant is being run out of sequence: auxiliaries burning energy with no chiller behind them, or a chiller running unprotected. Target ≥ 95%.

01 Metric Definition

What it measures and how it is calculated

What it measures

A weighted compliance score across the six operating sequences (BMS interlocks) that a central chiller plant should hold at all times. It measures whether the plant is being operated the way it was designed to run — production and heat-rejection equipment staged together, distribution following production, and auxiliaries shut down when no chiller is calling. It is an operational-discipline signal about how the plant is run, not a mechanical-health signal about any single machine.

How it is calculated

Each sequence N is scored over the period as the share of valid intervals in which the interlock held — seq_N_compliance = count(sequence satisfied) / count(sequence evaluable) × 100 — evaluated only when the antecedent equipment is ON (a chiller-to-pump interlock is not scored while every chiller is off).

The plant score is the weighted average of the six sequences, weighted by criticality. The three critical interlocks protect the running chiller; the three high interlocks cover distribution and shut-down discipline.

Sequence weights: 01 Chiller to chilled-water (CP) pump — 0.25, critical; 02 Chiller to condenser-water (CC) pump — 0.20, critical; 03 Chiller to cooling tower — 0.20, critical; 04 CHW (CP) pump to distribution (CS) pump — 0.15, high; 05 Tower to condenser-water (CC) pump — 0.10, high; 06 System-off consistency, all chillers off implies pumps and towers off — 0.10, high.

The metric is read from the BMS interlock and run states only — it reads the plant, it does not command it. A breach is surfaced with the sequence that failed and how often; the correction is a change to the BMS sequence logic, which is made by the customer's plant-service vendor, not by Keedian.

Reference thresholds

RangeClassificationInterpretation
Plant score ≥ 95% (and each critical sequence ≥ 95%)Expected — in sequenceThe BMS is holding its interlocks; production, heat rejection, and distribution are staged together and auxiliaries shut down with the plant.
Plant score 80 – 94%, or any critical sequence below 95%Intermittent breaches — monitorThe plant leaves sequence often enough to waste auxiliary energy or run a chiller with thin protection; scope the failing interlock with the plant vendor.
Plant score below 80%, or a critical sequence persistently failingOut of sequence — investigateThe plant is regularly run outside its intended sequence — pumps or towers running with no chiller, or a chiller running without full flow or heat rejection; a sequence-logic review is due.

Reference bands only. The six sequences and their weights are the chilled-water-plant reference pattern; confirm the interlock map and criticality per plant before activating compliance reporting, because plant topology (number of chillers, dedicated vs headered pumps, tower staging) changes which interlocks apply.

Portfolio compliance target

The plant-level target is a weighted operational-compliance score of ≥ 95%, with each of the three critical interlocks (chiller to CHW pump, chiller to condenser-water pump, chiller to tower) held at ≥ 95% on its own so a strong distribution score cannot mask an unprotected chiller. Agree the floor per plant before reporting against it.

02 Impact

How this metric moves the customer value drivers

The table below shows how moving Chiller Plant Operational Compliance impacts each customer value driver the product is designed to improve — the metric page explains the mechanism; the product pages express the magnitude.

Value driverImpact strengthHow Chiller Plant Operational Compliance moves this lever
Energy savingsDirect, primaryEvery interval a pump or tower fan runs with no chiller behind it is auxiliary energy spent moving water and rejecting heat that is not being produced. Surfacing the off-sequence run-time — especially the system-off-consistency breaches — is the most direct no-capex lever on the plant's auxiliary load. Per-plant magnitude is expected (pending validation) — offices have no named Keedian reference deployment yet.
Asset lifespanDirectRunning a chiller without its full chilled-water flow, condenser-water flow, or heat rejection is exactly the condition the interlocks exist to prevent — it drives the compressor toward low-flow trips, high head pressure, and thermal stress. Catching a chronically failing critical interlock protects the plant's most expensive machine before the exposure becomes damage.
Avoided truck rollsIndirect, leading indicatorA critical interlock that fails repeatedly is a controls or sensor fault developing in the open — a stuck status point, a mis-mapped command, a failing pump starter. Flagging it as a scoped item for the plant vendor turns what would become an unplanned plant trip into a planned sequence-logic visit.
03 Detection

How it surfaces and when it is reviewed

How it surfaces

Alarm
Can be configured to fire when a critical interlock is breached in real time (a chiller ON with no chilled-water or condenser-water pump proven, or no tower), so the exposure is caught while the chiller is running rather than after a trip.
Equipment
The failing sequence is attributed to the equipment pair involved (which chiller, which pump or tower), so the plant vendor is pointed at the exact interlock rather than the whole plant.
Site
The six sequence scores and the weighted plant score shown on the plant view, with the off-sequence run-time broken out by sequence.
Portfolio
Buildings whose plant score sits below target surface in the Executive Summary, ranked by the weighted score so the least-disciplined plants are worked first.

Review cadence

Monthly
Reviewed in the MBR against the plant's own trend — plant score, the count of sequences at or above 95%, and any critical interlock below target.
Weekly
Operations reviews plants trending down and any new critical-interlock breaches for a vendor referral.
Real-time
Critical-interlock alert where configured, so an unprotected chiller or a running auxiliary with no chiller is caught in the moment.
04 Alarms

Principal alarms derived from this metric

The table below summarizes the alarms that fire directly from Chiller Plant Operational Compliance. Each row links to the full operational detail (trigger, preconditions, action plan, human role, escalation, prevention) in the SOPs catalog.

AlarmDescriptionSeverityTierAI executes?Value driversSOP
Sequence fault — Chiller → CHW (CP) pump A chiller is proven ON but no chilled-water (CP / primary) pump is proven running — the chiller is producing cooling with no chilled-water flow through its evaporator. The most safety-critical of the plant interlocks: sustained, it risks a low-flow trip or a frozen, physically damaged evaporator. Urgent Essential Hybrid Asset lifespan · Energy savings · Avoided truck rolls Open SOP →
Sequence fault — Chiller → CW (CC) pump A chiller is proven ON but no condenser-water (CC) pump is proven running — no condenser flow to carry heat from the condenser out to the tower. Sustained, condensing pressure and temperature climb, the chiller loses efficiency, and it eventually trips on high-pressure protection or shuts down. Urgent Essential Hybrid Asset lifespan · Energy savings · Avoided truck rolls Open SOP →
Sequence fault — Chiller → cooling tower A chiller is proven ON but no cooling tower is running — the plant has no path to reject heat to the atmosphere. Sustained, condenser water just recirculates and heats up, driving condensing temperature up and efficiency down until the chiller protects itself. Urgent Essential Hybrid Asset lifespan · Energy savings · Avoided truck rolls Open SOP →
More alarms in development

More alarms in development (single-metric): per-sequence trend alerts that flag a critical interlock drifting before it breaches, and a system-off-consistency watch for auxiliaries left running after hours. Composite plant alarms that combine operational compliance with Cooling ΔT and plant efficiency to separate an operating-discipline problem from a mechanical one will appear in a future release.

05 Actions

What to do based on the alarm

The action plan for each alarm lives on its own SOP page in the SOPs catalog — with the diagnostic steps, human role, value drivers, escalation, and prevention specific to that alarm. The list below maps each alarm to its SOP.

  • Sequence fault — Chiller → CHW (CP) pump → — A chiller is proven ON but no chilled-water (CP / primary) pump is proven running — the chiller is producing cooling with no chilled-water flow through its evaporator. The most safety-critical of the plant interlocks: sustained, it risks a low-flow trip or a frozen, physically damaged evaporator.
  • Sequence fault — Chiller → CW (CC) pump → — A chiller is proven ON but no condenser-water (CC) pump is proven running — no condenser flow to carry heat from the condenser out to the tower. Sustained, condensing pressure and temperature climb, the chiller loses efficiency, and it eventually trips on high-pressure protection or shuts down.
  • Sequence fault — Chiller → cooling tower → — A chiller is proven ON but no cooling tower is running — the plant has no path to reject heat to the atmosphere. Sustained, condenser water just recirculates and heats up, driving condensing temperature up and efficiency down until the chiller protects itself.

Read-only interlock, correction on the plant vendor (metric-level — not a single alarm)

Operational compliance is read from the BMS interlock states; Keedian does not change the plant's sequence logic. When a sequence is breached, Keedian surfaces the failing interlock, how often it failed, and the equipment pair involved, and hands it to the customer's plant-service vendor with a recommended correction. Do not report a plant as non-compliant on a breach that traces to a stale or mis-mapped status point before the point mapping is confirmed.

Responsible
Keedian operations team, referred to the customer's plant-service vendor
Urgency
Medium — an intermittent breach wastes energy; a persistent critical breach risks the chiller
Client approval
No for surfacing the finding — the sequence-logic change is the vendor's, on the customer's approval

Confirm the interlock map before scoring a new plant (metric-level)

The six sequences and their weights are the reference pattern for a chilled-water plant; the actual interlocks depend on plant topology — number of chillers, dedicated versus headered pumps, how towers stage. Confirm the point mapping and which interlocks apply for each plant before activating compliance reporting, so a sequence that does not exist on that plant is not scored as a failure.

Responsible
Keedian operations team
Urgency
High — an unconfirmed interlock map manufactures false breaches
Client approval
No

Critical interlock failing with a chiller running (metric-level — protective)

A chiller proven ON with no chilled-water flow, no condenser-water flow, or no tower is the exposure the critical interlocks exist to prevent. Escalate it out of cycle to the customer and the plant vendor rather than holding it for the MBR — the risk is a low-flow trip or compressor damage in the moment, not a monthly efficiency reading.

Responsible
Keedian operations team, direct to customer + plant vendor
Urgency
High — unprotected chiller operation
Client approval
No for the alert — remediation is the vendor's
06 Escalation

When and how to escalate

Per-alarm escalation criteria live in the Escalation block of each SOP in the SOPs catalog. The patterns below are metric-level — read from the portfolio view, not from any single alarm firing.

Portfolio-level patterns — typically communicated in the MBR
  • Plants whose weighted score stays below target for two or more consecutive months despite a vendor referral — a sequence-logic review candidate
  • Recurring system-off-consistency breaches across several plants — auxiliaries left running after hours, a portfolio-wide close-down discipline issue
  • A critical interlock that keeps failing on the same plant after correction — flag the controls or sensor fault for a deeper vendor engagement
Cross-alarm urgency — typically requires out-of-cycle communication
  • A chiller running with a failed critical interlock (no proven flow or heat rejection) — direct customer and plant-vendor alert before a trip or damage
  • A plant-wide interlock or status-mapping fault that makes the compliance score unreliable — pause plant reporting until the point mapping is reconciled
  • Any off-sequence pattern with direct energy-cost or equipment-risk impact material to the client
07 Prevention

Controls to avoid recurring issues

Configuration controls

  • Map every interlock and confirm which of the six sequences apply to the plant's topology before activating the metric
  • Verify each status and command point (chiller ON, pump proven, tower ON) at onboarding so a breach reflects the plant, not a mis-mapped point
  • Record the plant's design staging (lead/lag, dedicated vs headered pumps) as the reference for what "in sequence" means

Monitoring controls

  • Configure real-time alerts on the three critical interlocks so an unprotected chiller is caught while it is running
  • Trend the weighted plant score and the count of sequences at or above 95% so a slow drift is visible before it breaches
  • Watch system-off consistency after hours to catch auxiliaries left running with no chiller call

Reporting controls

  • Include the plant score and the per-sequence breakdown in every MBR, against the plant's own trend
  • Flag any critical interlock below 95% explicitly, even when the overall plant score is above target
  • Maintain a log of recurring breaches per plant to surface controls or sensor faults for the plant vendor