- MozGlobal Engineering
- Planning
- 6 min read
Shutdowns rarely overrun because the work was hard. They overrun because the scope grew after the window was fixed.
A planned shutdown is the most expensive maintenance window an operation buys. Everything that cannot be done with the plant running has to happen inside it, and the cost of overrunning is measured in lost production rather than in labour hours. Shutdowns rarely overrun because the work turned out to be technically hard. They overrun because the scope grew after the window was fixed.
Freeze the scope before you fix the date
The sequence matters. A scope agreed against a date already announced to production will be squeezed to fit, and the things that get dropped are usually the inspections rather than the visible repairs — which is how the next shutdown inherits a surprise.
A scope worth committing to lists each job with the access it needs, the trades involved, the parts required, and an honest duration. Jobs that depend on what an inspection finds should be identified as such, with a decision point and a contingency, rather than assumed to be quick.
Parts on site, verified, before the plant stops
The most common cause of a stalled shutdown is a part that was ordered but not checked. It arrived late, or arrived wrong, or arrived correct but incomplete. None of these are discovered at a useful moment if the first time anyone opens the crate is during the outage.
- Every part physically on site and unpacked before the shutdown begins
- Dimensions and specifications verified against the component being replaced
- Consumables — gaskets, fasteners, welding consumables — counted, not assumed
- Long-lead items ordered against the shutdown date, not the request date
Sequence around access, not around trades
Plans built by discipline — all the mechanical work, then all the electrical — look tidy and waste time. Real sequencing is governed by physical access: what has to come out before something else can be reached, which lifts share a crane, which jobs cannot proceed while an adjacent one is live.
The critical path in a shutdown is almost never the longest job. It is the job that blocks access to three others.
Decide in advance who can add work
Additional work will be discovered once equipment is opened; that is partly the point of opening it. What causes overruns is not the discovery but the absence of a rule for handling it. Agreeing beforehand who authorises additional scope, and against what criteria, converts a disruptive argument into a short decision.
A useful default: anything discovered that is not a safety issue and does not prevent restart gets recorded and scheduled for the next window, not absorbed into this one.
Restart is part of the scope
Reassembly, functional testing and the checks required before equipment returns to service take time, and plans that end at "work complete" consistently underestimate them. The shutdown is not over when the last bolt is torqued. It is over when the plant is running and the readings are where they should be.



