Productization
← Back to SOPs catalog
Keedian operations · Standard procedure

Sequence fault — Chiller → CHW (CP) pump.

A chiller is proven ON but no chilled-water (CP / primary) pump is proven running — the chiller is producing cooling with no chilled-water flow through its evaporator. The most safety-critical of the plant interlocks: sustained, it risks a low-flow trip or a frozen, physically damaged evaporator.

01 Detail

Trigger, action plan, and escalation criteria.

optimization_metric hvac urgent essential tier AI: hybrid
Related metric
chiller_plant_operational_compliance
Trigger
system_on=1 AND cp_any_on=0 sustained ≥ seq_fail_duration (raises SEQ-FAIL Chiller→CP)
Value drivers
Asset lifespan Energy savings Avoided truck rolls
Preconditions
Chiller ON/OFF and CP-pump run/proven status mapped as Modbus binary points and rolled up into the derived system_on and cp_any_on booleans. Interlock #01 confirmed to apply to the plant's topology (dedicated vs headered pumps) before the alarm is armed. The sustained-fault window (seq_fail_duration, e.g. 5 min) is a configurable server-side attribute; the chiller ON/OFF Modbus mapping is confirmed per plant.
Human role
Primary — Keedian reads the interlock and raises the alarm; the correction to the BMS sequence logic is the customer's plant-service vendor's. Operators confirm the fault is real, notify the customer, and coordinate the vendor referral.
Action plan
(1) Point-mapping sanity check first — confirm the chiller-ON and CP-pump-proven points are current and correctly mapped before treating the fault as real; a stale or mis-mapped status point manufactures a false SEQ-FAIL. Do not report the plant non-compliant on an unconfirmed point. (2) Confirm the condition is sustained past seq_fail_duration, not a start-up transient during normal pump staging. (3) Once confirmed, treat it as an unprotected running chiller — notify the customer and the plant-service vendor out of cycle; the exposure is a low-flow trip or evaporator freeze in the moment, not a monthly reading. (4) Attribute the fault to the specific chiller / pump pair so the vendor is pointed at the exact interlock, not the whole plant. Keedian surfaces the finding and the recommended correction; the sequence-logic change is made on the BMS side.
Escalation
(1) Chiller confirmed running with no proven CP-pump flow → direct customer + plant-vendor alert before a trip or evaporator damage; do not hold for the MBR. (2) Same interlock keeps failing on the same plant after a vendor correction → flag the controls or sensor fault (stuck status point, mis-mapped command, failing starter) for a deeper vendor engagement. (3) Point mapping cannot be confirmed / the status feed is unreliable → pause compliance reporting for the plant until the mapping is reconciled rather than reporting false breaches.
Prevention
(1) Verify every chiller-ON and CP-pump-proven point at onboarding, and confirm interlock #01 applies to the plant's staging, before arming the alarm. (2) Set seq_fail_duration to ride through normal staging transients but still catch a genuine loss of flow while the chiller runs. (3) Maintain a per-plant log of recurring sequence faults so a developing controls or sensor fault surfaces for the vendor before it becomes a plant trip.